Windows Server 2008, Sirfef.b/y and zeroaccess

Solved
By avenged187
Aug 9, 2012
  1. Yesterday MSE detected an infection of Sirefef.b and Sirefef.y in one of our administrators folders. Services.exe seems to be infected, and MSE crashes the server every time it tries to clean the files (probably because it's trying to quarantine and delete important system files). Ran MBAM, which attempted to clean infection, but did not seem to help. Ran FRST to confirm infection, which showed ZeroAccess. GMER did not find anything, nor TDSSKiller. DDS will not run on Windows Server 2008. Logs to be posted.
  2. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Initial MBAM Scan Log

    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.08.08.08

    Windows Server 2008 R2 x64 NTFS
    Internet Explorer 9.0.8112.16421
    frank :: WINDOWS-WQH0732 [administrator]

    8/8/2012 12:33:27 PM
    mbam-log-2012-08-08 (12-33-27).txt

    Scan type: Full scan (C:\|D:\|E:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 795620
    Time elapsed: 1 hour(s), 5 minute(s), 34 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 26
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR124\1ind[1].jpg (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR143\alisha2[1].jpg (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR144\lexi1[1].jpg (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR149\pubbannr.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR235\Log\4326f31b.LOG (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR26\carman4[1].jpg (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR26\inescap3[1].jpg (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR26\taylor2[1].jpg (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\LOSTFILE\DIR270\buttonslaunch_02-sel[1].gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks 2005\Components\DownloadQB15\NewFeatures\.update\.target\accmax.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\DecisionTools\Images\CE_b2_off.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\DecisionTools\Images\weblinks-ratio.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\ECredit\Pages\Images\misc1_btn.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\ECredit\Pages\Images\misc2_btn.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Help\Images\com_header.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\com_11.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\master_overview.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\merchant_head.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\order_cache_exp_r4_c3.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\order_cache_exp_r5_c2.gif (Extension.Mismatch) -> No action taken.
    D:\Share\EHD\Compusa Backup\Program Files\Intuit\QuickBooks Pro\Components\Services\Images\payreferral_head.gif (Extension.Mismatch) -> No action taken.
    C:\Users\frank\AppData\Local\Temp\2\2E86.tmp (Trojan.LameShield) -> Quarantined and deleted successfully.
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\n (Trojan.Sirefef) -> Delete on reboot.
    C:\Users\Rick\AppData\Local\Temp\5\sdhttt.exe (Exploit.Drop.COD) -> Quarantined and deleted successfully.
    C:\Users\Rick\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\77c33b52-4131f7d0 (Exploit.Drop.COD) -> Quarantined and deleted successfully.
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\n (Trojan.Sirefef) -> Quarantined and deleted successfully.

    (end)
  3. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Second scan later in day.

    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.08.08.08

    Windows Server 2008 R2 x64 NTFS
    Internet Explorer 9.0.8112.16421
    frank :: WINDOWS-WQH0732 [administrator]

    8/8/2012 1:48:28 PM
    mbam-log-2012-08-08 (13-48-28).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 54152
    Time elapsed: 5 minute(s), 6 second(s) [aborted]

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
  4. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Log from FRST this morning.

    Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
    Ran by frank at 09-08-2012 08:58:48
    Running from F:\
    (X64) OS Language: English(US)
    Attention: Could not load system hive.'reg' is not recognized as an internal or external command,
    operable program or batch file.
    ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY.


    ============ One Month Created Files and Folders ==============

    2012-08-09 08:58 - 2012-08-09 08:58 - 00000000 ____D C:\FRST
    2012-08-09 08:40 - 2012-08-09 08:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6639107541643CB4
    2012-08-09 08:36 - 2012-08-09 08:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
    2012-08-09 08:33 - 2012-08-09 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
    2012-08-09 08:29 - 2012-08-09 08:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
    2012-08-09 08:25 - 2012-08-09 08:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
    2012-08-09 08:21 - 2012-08-09 08:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
    2012-08-09 08:18 - 2012-08-09 08:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
    2012-08-09 08:14 - 2012-08-09 08:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
    2012-08-09 08:10 - 2012-08-09 08:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
    2012-08-09 08:07 - 2012-08-09 08:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
    2012-08-09 08:03 - 2012-08-09 08:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
    2012-08-09 07:59 - 2012-08-09 07:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
    2012-08-09 07:55 - 2012-08-09 07:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
    2012-08-09 07:52 - 2012-08-09 07:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
    2012-08-09 07:48 - 2012-08-09 07:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
    2012-08-09 07:44 - 2012-08-09 07:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
    2012-08-09 07:40 - 2012-08-09 07:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
    2012-08-09 07:37 - 2012-08-09 07:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
    2012-08-09 07:33 - 2012-08-09 07:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
    2012-08-09 07:29 - 2012-08-09 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
    2012-08-09 07:26 - 2012-08-09 07:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
    2012-08-09 07:22 - 2012-08-09 07:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
    2012-08-09 07:18 - 2012-08-09 07:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
    2012-08-09 07:14 - 2012-08-09 07:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
    2012-08-09 07:11 - 2012-08-09 07:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
    2012-08-09 07:07 - 2012-08-09 07:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
    2012-08-09 07:03 - 2012-08-09 07:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
    2012-08-09 07:00 - 2012-08-09 07:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
    2012-08-09 06:56 - 2012-08-09 06:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
    2012-08-09 06:52 - 2012-08-09 06:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
    2012-08-09 06:48 - 2012-08-09 06:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
    2012-08-09 06:45 - 2012-08-09 06:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
    2012-08-09 06:41 - 2012-08-09 06:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
    2012-08-09 06:37 - 2012-08-09 06:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
    2012-08-09 06:33 - 2012-08-09 06:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
    2012-08-09 06:30 - 2012-08-09 06:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
    2012-08-09 06:26 - 2012-08-09 06:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
    2012-08-09 06:22 - 2012-08-09 06:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
    2012-08-09 06:19 - 2012-08-09 06:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
    2012-08-09 06:15 - 2012-08-09 06:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
    2012-08-09 06:11 - 2012-08-09 06:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
    2012-08-09 06:07 - 2012-08-09 06:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
    2012-08-09 06:04 - 2012-08-09 06:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
    2012-08-09 06:00 - 2012-08-09 06:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
    2012-08-09 05:56 - 2012-08-09 05:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
    2012-08-09 05:53 - 2012-08-09 05:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
    2012-08-09 05:49 - 2012-08-09 05:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
    2012-08-09 05:45 - 2012-08-09 05:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
    2012-08-09 05:41 - 2012-08-09 05:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
    2012-08-09 05:38 - 2012-08-09 05:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
    2012-08-09 05:34 - 2012-08-09 05:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
    2012-08-09 05:30 - 2012-08-09 05:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
    2012-08-09 05:26 - 2012-08-09 05:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
    2012-08-09 05:23 - 2012-08-09 05:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
    2012-08-09 05:19 - 2012-08-09 05:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
    2012-08-09 05:15 - 2012-08-09 05:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
    2012-08-09 05:12 - 2012-08-09 05:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
    2012-08-09 05:08 - 2012-08-09 05:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
    2012-08-09 05:04 - 2012-08-09 05:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
    2012-08-09 05:00 - 2012-08-09 05:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
    2012-08-09 04:57 - 2012-08-09 04:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
    2012-08-09 04:53 - 2012-08-09 04:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
    2012-08-09 04:49 - 2012-08-09 04:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
    2012-08-09 04:46 - 2012-08-09 04:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
    2012-08-09 04:42 - 2012-08-09 04:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
    2012-08-09 04:38 - 2012-08-09 04:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
    2012-08-09 04:34 - 2012-08-09 04:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
    2012-08-09 04:31 - 2012-08-09 04:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
    2012-08-09 04:27 - 2012-08-09 04:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
    2012-08-09 04:23 - 2012-08-09 04:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
    2012-08-09 04:19 - 2012-08-09 04:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
    2012-08-09 04:16 - 2012-08-09 04:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
    2012-08-09 04:12 - 2012-08-09 04:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
    2012-08-09 04:08 - 2012-08-09 04:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
    2012-08-09 04:05 - 2012-08-09 04:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
    2012-08-09 04:01 - 2012-08-09 04:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
    2012-08-09 03:57 - 2012-08-09 03:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
    2012-08-09 03:53 - 2012-08-09 03:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
    2012-08-09 03:50 - 2012-08-09 03:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
    2012-08-09 03:46 - 2012-08-09 03:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
    2012-08-09 03:42 - 2012-08-09 03:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
    2012-08-09 03:39 - 2012-08-09 03:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
    2012-08-09 03:35 - 2012-08-09 03:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
    2012-08-09 03:31 - 2012-08-09 03:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
    2012-08-09 03:27 - 2012-08-09 03:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
    2012-08-09 03:24 - 2012-08-09 03:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
    2012-08-09 03:20 - 2012-08-09 03:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
    2012-08-09 03:16 - 2012-08-09 03:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
    2012-08-09 03:12 - 2012-08-09 03:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
    2012-08-09 03:09 - 2012-08-09 03:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
    2012-08-09 03:05 - 2012-08-09 03:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
    2012-08-09 03:01 - 2012-08-09 03:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
    2012-08-09 02:58 - 2012-08-09 02:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
    2012-08-09 02:54 - 2012-08-09 02:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
    2012-08-09 02:50 - 2012-08-09 02:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
    2012-08-09 02:46 - 2012-08-09 02:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
    2012-08-09 02:43 - 2012-08-09 02:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
    2012-08-09 02:39 - 2012-08-09 02:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
    2012-08-09 02:35 - 2012-08-09 02:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
    2012-08-09 02:31 - 2012-08-09 02:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
    2012-08-09 02:28 - 2012-08-09 02:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
    2012-08-09 02:24 - 2012-08-09 02:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
    2012-08-09 02:20 - 2012-08-09 02:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
    2012-08-09 02:17 - 2012-08-09 02:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
    2012-08-09 02:13 - 2012-08-09 02:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
    2012-08-09 02:09 - 2012-08-09 02:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
    2012-08-09 02:05 - 2012-08-09 02:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
    2012-08-09 02:02 - 2012-08-09 02:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
    2012-08-09 01:58 - 2012-08-09 01:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
    2012-08-09 01:54 - 2012-08-09 01:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
    2012-08-09 01:51 - 2012-08-09 01:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
    2012-08-09 01:47 - 2012-08-09 01:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
    2012-08-09 01:43 - 2012-08-09 01:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
    2012-08-09 01:39 - 2012-08-09 01:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
    2012-08-09 01:36 - 2012-08-09 01:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
    2012-08-09 01:32 - 2012-08-09 01:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
    2012-08-09 01:28 - 2012-08-09 01:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
    2012-08-09 01:24 - 2012-08-09 01:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
    2012-08-09 01:21 - 2012-08-09 01:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
    2012-08-09 01:17 - 2012-08-09 01:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
    2012-08-09 01:13 - 2012-08-09 01:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
    2012-08-09 01:10 - 2012-08-09 01:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
    2012-08-09 01:06 - 2012-08-09 01:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
    2012-08-09 01:02 - 2012-08-09 01:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
    2012-08-09 00:58 - 2012-08-09 00:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
    2012-08-09 00:55 - 2012-08-09 00:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
    2012-08-09 00:51 - 2012-08-09 00:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
    2012-08-09 00:47 - 2012-08-09 00:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
    2012-08-09 00:44 - 2012-08-09 00:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
    2012-08-09 00:40 - 2012-08-09 00:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
    2012-08-09 00:36 - 2012-08-09 00:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
    2012-08-09 00:32 - 2012-08-09 00:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
    2012-08-09 00:29 - 2012-08-09 00:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
    2012-08-09 00:25 - 2012-08-09 00:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
    2012-08-09 00:21 - 2012-08-09 00:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
    2012-08-09 00:17 - 2012-08-09 00:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
    2012-08-09 00:14 - 2012-08-09 00:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
    2012-08-09 00:10 - 2012-08-09 00:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
    2012-08-09 00:06 - 2012-08-09 00:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
    2012-08-09 00:03 - 2012-08-09 00:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
    2012-08-08 23:59 - 2012-08-08 23:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
    2012-08-08 23:55 - 2012-08-08 23:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
    2012-08-08 23:52 - 2012-08-08 23:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
    2012-08-08 23:48 - 2012-08-08 23:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
    2012-08-08 23:44 - 2012-08-08 23:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
    2012-08-08 23:40 - 2012-08-08 23:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
    2012-08-08 23:37 - 2012-08-08 23:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
    2012-08-08 23:33 - 2012-08-08 23:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
    2012-08-08 23:29 - 2012-08-08 23:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
    2012-08-08 23:26 - 2012-08-08 23:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
    2012-08-08 23:22 - 2012-08-08 23:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
    2012-08-08 23:18 - 2012-08-08 23:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
    2012-08-08 23:15 - 2012-08-08 23:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
    2012-08-08 23:11 - 2012-08-08 23:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
    2012-08-08 23:07 - 2012-08-08 23:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
    2012-08-08 23:03 - 2012-08-08 23:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
    2012-08-08 23:00 - 2012-08-08 23:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
    2012-08-08 22:56 - 2012-08-08 22:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
    2012-08-08 22:52 - 2012-08-08 22:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
    2012-08-08 22:49 - 2012-08-08 22:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
    2012-08-08 22:45 - 2012-08-08 22:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
    2012-08-08 22:41 - 2012-08-08 22:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
    2012-08-08 22:38 - 2012-08-08 22:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
    2012-08-08 22:34 - 2012-08-08 22:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
    2012-08-08 22:30 - 2012-08-08 22:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
    2012-08-08 22:27 - 2012-08-08 22:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
    2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
    2012-08-08 20:05 - 2012-08-08 20:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
    2012-08-08 19:26 - 2012-08-08 19:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
    2012-08-08 18:48 - 2012-08-08 18:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
    2012-08-08 16:51 - 2012-08-08 16:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
    2012-08-08 16:50 - 2012-08-08 16:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
    2012-08-08 16:43 - 2012-08-08 16:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
    2012-08-08 15:02 - 2012-08-08 15:02 - 00000000 ____D C:\Users\frank\AppData\Local\Macromedia
    2012-08-08 14:51 - 2012-08-08 14:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.349AEC5204EBA773
    2012-08-08 14:47 - 2012-08-08 14:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4B1FF6622C08F08
    2012-08-08 14:44 - 2012-08-08 14:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B676A461F41E7A
    2012-08-08 14:41 - 2012-08-08 14:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7CEB3957CE766A8A
    2012-08-08 14:37 - 2012-08-08 14:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89FF8A9A97317FFE
    2012-08-08 14:37 - 2012-08-08 14:37 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uwmbzbaf.sys
    2012-08-08 14:34 - 2012-08-08 14:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E8C07ED33CE05A6
    2012-08-08 14:31 - 2012-08-08 14:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E6A751AE46DA9A1
    2012-08-08 14:30 - 2012-08-08 14:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
    2012-08-08 14:23 - 2012-08-08 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A911C064868CAD
    2012-08-08 14:17 - 2012-08-08 14:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FF333A3177CB21
    2012-08-08 14:14 - 2012-08-08 14:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.399D3E0F3FB865AB
    2012-08-08 14:11 - 2012-08-08 14:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB91755D859AF796
    2012-08-08 14:07 - 2012-08-08 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F93FF9FD3B95AF9
    2012-08-08 14:03 - 2012-08-08 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.216AEC2C1AD8CA1D
    2012-08-08 13:54 - 2012-08-08 13:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-08-08 13:54 - 2012-08-08 13:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-08-08 13:52 - 2012-08-08 13:52 - 00000000 ____D C:\Windows\System32\SPReview
    2012-08-08 13:45 - 2012-08-08 13:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
    2012-08-08 12:56 - 2012-08-08 12:57 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
    2012-08-08 12:51 - 2012-08-08 12:51 - 00000000 ____D C:\Users\Rick\AppData\Roaming\Malwarebytes
    2012-08-08 12:32 - 2012-08-08 12:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-08 12:32 - 2012-08-08 12:32 - 00000000 ____D C:\Users\frank\AppData\Roaming\Malwarebytes
    2012-08-08 12:32 - 2012-08-08 12:32 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-08-08 12:32 - 2012-08-08 12:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-08-08 12:32 - 2012-07-03 13:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-08-08 12:30 - 2012-08-08 12:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
    2012-08-08 12:23 - 2012-08-08 12:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-08-08 12:22 - 2012-08-08 12:22 - 00000000 ____A C:\extensions.sqlite
    2012-08-06 18:19 - 2012-08-06 18:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
    2012-08-02 09:17 - 2012-08-02 09:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
    2012-08-02 09:16 - 2012-08-02 09:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
    2012-08-02 09:16 - 2012-08-02 09:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
    2012-07-27 11:03 - 2012-07-27 17:58 - 00000000 ____D C:\imagetmp
    2012-07-27 10:14 - 2012-07-27 10:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
    2012-07-25 15:08 - 2012-07-25 15:08 - 00000000 ____D C:\Users\frank\AppData\Roaming\SQL Anywhere 12
    2012-07-24 10:30 - 2012-07-24 10:30 - 00000000 ____D C:\Users\Rick\AppData\Local\Help
    2012-07-24 10:29 - 2012-07-24 10:29 - 00000000 ____D C:\Users\Rick\AppData\Roaming\SQL Anywhere 12
    2012-07-19 16:34 - 2012-07-19 16:34 - 00000000 ____D C:\Users\Install\AppData\Local\Adobe
    2012-07-19 15:35 - 2012-07-19 15:36 - 00000000 ____D C:\Users\Install\AppData\Roaming\Mozilla
    2012-07-19 15:35 - 2012-07-19 15:35 - 00000000 ____D C:\Users\Install\AppData\Local\Mozilla
    2012-07-18 15:48 - 2012-07-18 15:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
    2012-07-18 15:38 - 2012-07-18 15:38 - 00000000 ____D C:\Users\Install\AppData\Roaming\Help
    2012-07-18 15:38 - 2012-07-18 15:38 - 00000000 ____D C:\Users\Install\AppData\Local\Help
    2012-07-18 15:37 - 2012-07-24 10:32 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
    2012-07-18 15:36 - 2012-07-19 16:34 - 00000000 ____D C:\Users\Install\AppData\Roaming\Adobe
    2012-07-18 15:36 - 2009-08-04 12:56 - 00296960 ____A (Microsoft Corporation) C:\Windows\winhlp32.exe
    2012-07-18 15:36 - 2009-08-04 12:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftsrch.dll
    2012-07-18 15:36 - 2009-08-04 12:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\System32\ftsrch.dll
    2012-07-18 15:36 - 2009-08-04 12:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx041e.dll
    2012-07-18 15:36 - 2009-08-04 12:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\System32\ftlx041e.dll
    2012-07-18 15:36 - 2009-08-04 12:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx0411.dll
    2012-07-18 15:36 - 2009-08-04 12:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\ftlx0411.dll
    2012-07-18 15:11 - 2012-07-18 15:11 - 00000000 ____D C:\Users\Install\AppData\Roaming\WinRAR
    2012-07-18 13:28 - 2012-07-18 15:32 - 00000000 ____D C:\Users\Public\Documents\Sybase Central 6.1.0
    2012-07-18 13:27 - 2012-07-18 13:31 - 00000166 ____A C:\Windows\ODBC.INI
    2012-07-18 13:27 - 2012-07-18 13:31 - 00000000 ____D C:\Users\Install\AppData\Roaming\SQL Anywhere 12
    2012-07-18 13:25 - 2012-07-18 15:30 - 00000000 ____D C:\Users\Install\sybase
    2012-07-18 13:25 - 2012-07-18 13:25 - 00000000 ____D C:\Users\Public\Documents\DBISQL 12.0.1
    2012-07-18 13:06 - 2012-07-18 13:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
    2012-07-18 13:06 - 2012-07-18 13:06 - 00000000 ____D C:\Users\Install\AppData\Local\Deployment
    2012-07-18 13:06 - 2012-07-18 13:06 - 00000000 ____D C:\Users\Install\AppData\Local\Citrix
    2012-07-18 13:06 - 2012-07-18 13:06 - 00000000 ____D C:\Users\Install\AppData\Local\Apps\2.0
    2012-07-18 13:03 - 2012-07-18 13:25 - 00000000 ____D C:\users\Install
    2012-07-18 13:03 - 2012-07-18 13:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 13:03 - 2012-07-18 13:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
    2012-07-18 13:03 - 2012-07-18 13:03 - 00000000 ____D C:\Users\Install\AppData\Roaming\Apple Computer
    2012-07-18 13:03 - 2012-07-18 13:03 - 00000000 ____D C:\Users\Install\AppData\Local\Intuit
    2012-07-18 13:03 - 2012-07-18 13:03 - 00000000 ____D C:\Users\Install\AppData\Local\Apple Computer
    2012-07-18 13:03 - 2011-10-11 03:01 - 00000000 ____D C:\Users\Install\AppData\Local\Microsoft Help
    2012-07-18 13:03 - 2011-02-23 11:42 - 00000000 ____D C:\Users\Install\AppData\Roaming\Macromedia
    2012-07-18 12:53 - 2012-07-18 15:12 - 00000000 ____D C:\Users\All Users\SQL Anywhere 12
    2012-07-18 12:30 - 2004-07-12 13:50 - 00155648 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JavaAccessBridge.dll
    2012-07-18 12:30 - 2004-07-12 13:50 - 00081920 ____A (Sun Microsystems©) C:\Windows\SysWOW64\WindowsAccessBridge.dll
    2012-07-18 12:30 - 2004-07-12 13:50 - 00032768 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JAWTAccessBridge.dll
    2012-07-18 12:29 - 2012-07-18 12:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2012-07-18 11:06 - 2012-07-18 11:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
    2012-07-18 11:06 - 2012-07-18 11:06 - 00000000 ____D C:\Users\frank\AppData\Local\Deployment
    2012-07-18 11:06 - 2012-07-18 11:06 - 00000000 ____D C:\Users\frank\AppData\Local\Citrix
    2012-07-18 11:06 - 2012-07-18 11:06 - 00000000 ____D C:\Users\frank\AppData\Local\Apps\2.0
    2012-07-12 10:59 - 2012-07-12 10:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
    2012-07-12 10:53 - 2012-07-12 10:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
    2012-07-12 10:52 - 2012-07-12 10:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
    2012-07-11 03:05 - 2012-06-02 07:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-07-11 03:05 - 2012-06-02 07:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-07-11 03:05 - 2012-06-02 07:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-07-11 03:05 - 2012-06-02 07:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-07-11 03:05 - 2012-06-02 07:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-07-11 03:05 - 2012-06-02 07:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-07-11 03:05 - 2012-06-02 07:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-07-11 03:05 - 2012-06-02 07:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-07-11 03:05 - 2012-06-02 07:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-07-11 03:05 - 2012-06-02 07:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-07-11 03:05 - 2012-06-02 06:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-07-11 03:05 - 2012-06-02 06:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-07-11 03:05 - 2012-06-02 06:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-07-11 03:05 - 2012-06-02 06:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-07-11 03:05 - 2012-06-02 04:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-07-11 03:05 - 2012-06-02 03:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-07-11 03:05 - 2012-06-02 03:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-07-11 03:05 - 2012-06-02 03:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-07-11 03:05 - 2012-06-02 03:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-07-11 03:05 - 2012-06-02 03:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-07-11 03:05 - 2012-06-02 03:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-07-11 03:05 - 2012-06-02 03:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-07-11 03:05 - 2012-06-02 03:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-07-11 03:05 - 2012-06-02 03:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-07-11 03:05 - 2012-06-02 03:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-07-11 03:05 - 2012-06-02 03:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-07-11 03:05 - 2012-06-02 03:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-07-11 03:05 - 2012-06-02 03:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-07-11 03:01 - 2012-06-11 22:02 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-07-10 15:40 - 2012-06-09 00:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-07-10 15:40 - 2012-06-08 23:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-07-10 15:40 - 2012-06-06 00:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-07-10 15:40 - 2012-06-06 00:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-07-10 15:40 - 2012-06-06 00:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-07-10 15:40 - 2012-06-06 00:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-07-10 15:40 - 2012-06-02 00:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2012-07-10 15:40 - 2012-06-02 00:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-07-10 15:40 - 2012-06-02 00:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2012-07-10 15:40 - 2012-06-02 00:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-07-10 15:40 - 2012-06-02 00:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-07-10 15:40 - 2012-06-01 23:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2012-07-10 15:40 - 2012-06-01 23:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2012-07-10 15:40 - 2012-06-01 23:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2012-07-10 15:40 - 2012-06-01 23:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll

    ============ 3 Months Modified Files ========================

    2012-08-09 08:55 - 2009-09-22 14:32 - 00851644 ____A C:\Windows\System32\perfh00A.dat
    2012-08-09 08:55 - 2009-09-22 14:32 - 00195538 ____A C:\Windows\System32\perfc00A.dat
    2012-08-09 08:55 - 2009-09-22 14:18 - 00845594 ____A C:\Windows\System32\perfh010.dat
    2012-08-09 08:55 - 2009-09-22 14:18 - 00182856 ____A C:\Windows\System32\perfc010.dat
    2012-08-09 08:55 - 2009-09-22 14:06 - 00808956 ____A C:\Windows\System32\perfh007.dat
    2012-08-09 08:55 - 2009-09-22 14:06 - 00183696 ____A C:\Windows\System32\perfc007.dat
    2012-08-09 08:55 - 2009-09-22 13:53 - 00856886 ____A C:\Windows\System32\perfh00C.dat
    2012-08-09 08:55 - 2009-09-22 13:53 - 00187520 ____A C:\Windows\System32\perfc00C.dat
    2012-08-09 08:55 - 2009-07-14 00:10 - 05006346 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-08-09 08:54 - 2009-07-13 23:56 - 00039600 ____A C:\Windows\setupact.log
    2012-08-09 08:43 - 2009-07-14 00:06 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-08-09 08:40 - 2012-08-09 08:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6639107541643CB4
    2012-08-09 08:40 - 2011-02-18 13:42 - 01534403 ____A C:\Windows\WindowsUpdate.log
    2012-08-09 08:36 - 2012-08-09 08:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
    2012-08-09 08:33 - 2012-08-09 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
    2012-08-09 08:29 - 2012-08-09 08:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
    2012-08-09 08:25 - 2012-08-09 08:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
    2012-08-09 08:21 - 2012-08-09 08:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
    2012-08-09 08:18 - 2012-08-09 08:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
    2012-08-09 08:14 - 2012-08-09 08:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
    2012-08-09 08:10 - 2012-08-09 08:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
    2012-08-09 08:07 - 2012-08-09 08:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
    2012-08-09 08:03 - 2012-08-09 08:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
    2012-08-09 07:59 - 2012-08-09 07:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
    2012-08-09 07:55 - 2012-08-09 07:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
    2012-08-09 07:52 - 2012-08-09 07:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
    2012-08-09 07:48 - 2012-08-09 07:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
    2012-08-09 07:44 - 2012-08-09 07:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
    2012-08-09 07:40 - 2012-08-09 07:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
    2012-08-09 07:37 - 2012-08-09 07:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
    2012-08-09 07:33 - 2012-08-09 07:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
    2012-08-09 07:29 - 2012-08-09 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
    2012-08-09 07:26 - 2012-08-09 07:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
    2012-08-09 07:22 - 2012-08-09 07:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
    2012-08-09 07:18 - 2012-08-09 07:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
    2012-08-09 07:14 - 2012-08-09 07:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
    2012-08-09 07:11 - 2012-08-09 07:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
    2012-08-09 07:07 - 2012-08-09 07:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
    2012-08-09 07:03 - 2012-08-09 07:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
    2012-08-09 07:00 - 2012-08-09 07:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
    2012-08-09 06:56 - 2012-08-09 06:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
    2012-08-09 06:52 - 2012-08-09 06:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
    2012-08-09 06:48 - 2012-08-09 06:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
    2012-08-09 06:45 - 2012-08-09 06:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
    2012-08-09 06:41 - 2012-08-09 06:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
    2012-08-09 06:37 - 2012-08-09 06:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
    2012-08-09 06:33 - 2012-08-09 06:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
    2012-08-09 06:30 - 2012-08-09 06:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
    2012-08-09 06:26 - 2012-08-09 06:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
    2012-08-09 06:22 - 2012-08-09 06:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
    2012-08-09 06:19 - 2012-08-09 06:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
    2012-08-09 06:15 - 2012-08-09 06:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
    2012-08-09 06:11 - 2012-08-09 06:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
    2012-08-09 06:07 - 2012-08-09 06:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
    2012-08-09 06:04 - 2012-08-09 06:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
    2012-08-09 06:00 - 2012-08-09 06:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
    2012-08-09 05:56 - 2012-08-09 05:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
    2012-08-09 05:53 - 2012-08-09 05:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
    2012-08-09 05:49 - 2012-08-09 05:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
    2012-08-09 05:45 - 2012-08-09 05:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
    2012-08-09 05:41 - 2012-08-09 05:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
    2012-08-09 05:38 - 2012-08-09 05:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
    2012-08-09 05:34 - 2012-08-09 05:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
    2012-08-09 05:30 - 2012-08-09 05:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
    2012-08-09 05:26 - 2012-08-09 05:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
    2012-08-09 05:23 - 2012-08-09 05:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
    2012-08-09 05:19 - 2012-08-09 05:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
    2012-08-09 05:15 - 2012-08-09 05:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
    2012-08-09 05:12 - 2012-08-09 05:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
    2012-08-09 05:08 - 2012-08-09 05:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
    2012-08-09 05:04 - 2012-08-09 05:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
    2012-08-09 05:00 - 2012-08-09 05:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
    2012-08-09 04:57 - 2012-08-09 04:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
    2012-08-09 04:53 - 2012-08-09 04:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
    2012-08-09 04:49 - 2012-08-09 04:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
    2012-08-09 04:46 - 2012-08-09 04:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
    2012-08-09 04:42 - 2012-08-09 04:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
    2012-08-09 04:38 - 2012-08-09 04:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
    2012-08-09 04:34 - 2012-08-09 04:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
    2012-08-09 04:33 - 2012-05-02 10:49 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-08-09 04:31 - 2012-08-09 04:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
    2012-08-09 04:27 - 2012-08-09 04:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
    2012-08-09 04:23 - 2012-08-09 04:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
    2012-08-09 04:19 - 2012-08-09 04:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
    2012-08-09 04:16 - 2012-08-09 04:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
    2012-08-09 04:12 - 2012-08-09 04:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
    2012-08-09 04:08 - 2012-08-09 04:08 - 00328704 ____A (Microsoft Corporation)
  5. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
    2012-08-09 04:05 - 2012-08-09 04:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
    2012-08-09 04:01 - 2012-08-09 04:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
    2012-08-09 03:57 - 2012-08-09 03:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
    2012-08-09 03:53 - 2012-08-09 03:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
    2012-08-09 03:50 - 2012-08-09 03:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
    2012-08-09 03:46 - 2012-08-09 03:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
    2012-08-09 03:42 - 2012-08-09 03:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
    2012-08-09 03:39 - 2012-08-09 03:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
    2012-08-09 03:35 - 2012-08-09 03:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
    2012-08-09 03:31 - 2012-08-09 03:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
    2012-08-09 03:27 - 2012-08-09 03:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
    2012-08-09 03:24 - 2012-08-09 03:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
    2012-08-09 03:20 - 2012-08-09 03:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
    2012-08-09 03:16 - 2012-08-09 03:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
    2012-08-09 03:12 - 2012-08-09 03:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
    2012-08-09 03:09 - 2012-08-09 03:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
    2012-08-09 03:05 - 2012-08-09 03:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
    2012-08-09 03:01 - 2012-08-09 03:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
    2012-08-09 02:58 - 2012-08-09 02:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
    2012-08-09 02:54 - 2012-08-09 02:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
    2012-08-09 02:50 - 2012-08-09 02:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
    2012-08-09 02:46 - 2012-08-09 02:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
    2012-08-09 02:43 - 2012-08-09 02:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
    2012-08-09 02:39 - 2012-08-09 02:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
    2012-08-09 02:35 - 2012-08-09 02:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
    2012-08-09 02:31 - 2012-08-09 02:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
    2012-08-09 02:28 - 2012-08-09 02:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
    2012-08-09 02:24 - 2012-08-09 02:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
    2012-08-09 02:20 - 2012-08-09 02:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
    2012-08-09 02:17 - 2012-08-09 02:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
    2012-08-09 02:13 - 2012-08-09 02:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
    2012-08-09 02:09 - 2012-08-09 02:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
    2012-08-09 02:05 - 2012-08-09 02:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
    2012-08-09 02:02 - 2012-08-09 02:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
    2012-08-09 01:58 - 2012-08-09 01:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
    2012-08-09 01:54 - 2012-08-09 01:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
    2012-08-09 01:51 - 2012-08-09 01:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
    2012-08-09 01:47 - 2012-08-09 01:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
    2012-08-09 01:43 - 2012-08-09 01:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
    2012-08-09 01:39 - 2012-08-09 01:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
    2012-08-09 01:36 - 2012-08-09 01:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
    2012-08-09 01:32 - 2012-08-09 01:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
    2012-08-09 01:28 - 2012-08-09 01:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
    2012-08-09 01:24 - 2012-08-09 01:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
    2012-08-09 01:21 - 2012-08-09 01:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
    2012-08-09 01:20 - 2009-07-14 00:06 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-08-09 01:17 - 2012-08-09 01:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
    2012-08-09 01:13 - 2012-08-09 01:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
    2012-08-09 01:10 - 2012-08-09 01:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
    2012-08-09 01:06 - 2012-08-09 01:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
    2012-08-09 01:02 - 2012-08-09 01:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
    2012-08-09 00:58 - 2012-08-09 00:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
    2012-08-09 00:55 - 2012-08-09 00:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
    2012-08-09 00:51 - 2012-08-09 00:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
    2012-08-09 00:47 - 2012-08-09 00:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
    2012-08-09 00:44 - 2012-08-09 00:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
    2012-08-09 00:40 - 2012-08-09 00:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
    2012-08-09 00:36 - 2012-08-09 00:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
    2012-08-09 00:32 - 2012-08-09 00:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
    2012-08-09 00:29 - 2012-08-09 00:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
    2012-08-09 00:25 - 2012-08-09 00:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
    2012-08-09 00:21 - 2012-08-09 00:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
    2012-08-09 00:17 - 2012-08-09 00:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
    2012-08-09 00:14 - 2012-08-09 00:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
    2012-08-09 00:10 - 2012-08-09 00:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
    2012-08-09 00:06 - 2012-08-09 00:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
    2012-08-09 00:03 - 2012-08-09 00:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
    2012-08-08 23:59 - 2012-08-08 23:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
    2012-08-08 23:55 - 2012-08-08 23:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
    2012-08-08 23:52 - 2012-08-08 23:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
    2012-08-08 23:48 - 2012-08-08 23:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
    2012-08-08 23:44 - 2012-08-08 23:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
    2012-08-08 23:40 - 2012-08-08 23:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
    2012-08-08 23:37 - 2012-08-08 23:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
    2012-08-08 23:33 - 2012-08-08 23:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
    2012-08-08 23:29 - 2012-08-08 23:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
    2012-08-08 23:26 - 2012-08-08 23:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
    2012-08-08 23:22 - 2012-08-08 23:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
    2012-08-08 23:18 - 2012-08-08 23:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
    2012-08-08 23:15 - 2012-08-08 23:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
    2012-08-08 23:11 - 2012-08-08 23:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
    2012-08-08 23:07 - 2012-08-08 23:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
    2012-08-08 23:03 - 2012-08-08 23:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
    2012-08-08 23:00 - 2012-08-08 23:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
    2012-08-08 22:56 - 2012-08-08 22:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
    2012-08-08 22:52 - 2012-08-08 22:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
    2012-08-08 22:49 - 2012-08-08 22:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
    2012-08-08 22:45 - 2012-08-08 22:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
    2012-08-08 22:41 - 2012-08-08 22:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
    2012-08-08 22:38 - 2012-08-08 22:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
    2012-08-08 22:34 - 2012-08-08 22:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
    2012-08-08 22:30 - 2012-08-08 22:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
    2012-08-08 22:27 - 2012-08-08 22:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
    2012-08-08 22:23 - 2009-07-13 18:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
    2012-08-08 21:54 - 2009-07-13 23:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-08-08 21:54 - 2009-07-13 23:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
    2012-08-08 20:05 - 2012-08-08 20:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
    2012-08-08 19:26 - 2012-08-08 19:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
    2012-08-08 19:01 - 2011-03-25 21:19 - 00000402 ___AH C:\Windows\Tasks\GG Logistics Corp. 1301105924.job
    2012-08-08 18:48 - 2012-08-08 18:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
    2012-08-08 17:07 - 2011-02-22 13:47 - 00053828 ____A C:\Windows\PFRO.log
    2012-08-08 16:51 - 2012-08-08 16:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
    2012-08-08 16:50 - 2012-08-08 16:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
    2012-08-08 16:43 - 2012-08-08 16:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
    2012-08-08 15:50 - 2011-02-21 17:24 - 00000072 ____A C:\Users\Public\LMDebug.log
    2012-08-08 14:51 - 2012-08-08 14:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.349AEC5204EBA773
    2012-08-08 14:47 - 2012-08-08 14:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4B1FF6622C08F08
    2012-08-08 14:44 - 2012-08-08 14:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B676A461F41E7A
    2012-08-08 14:41 - 2012-08-08 14:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7CEB3957CE766A8A
    2012-08-08 14:37 - 2012-08-08 14:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89FF8A9A97317FFE
    2012-08-08 14:37 - 2012-08-08 14:37 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uwmbzbaf.sys
    2012-08-08 14:34 - 2012-08-08 14:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E8C07ED33CE05A6
    2012-08-08 14:31 - 2012-08-08 14:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E6A751AE46DA9A1
    2012-08-08 14:30 - 2012-08-08 14:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
    2012-08-08 14:27 - 2011-02-22 17:29 - 00002243 ____A C:\Windows\epplauncher.mif
    2012-08-08 14:23 - 2012-08-08 14:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A911C064868CAD
    2012-08-08 14:17 - 2012-08-08 14:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FF333A3177CB21
    2012-08-08 14:14 - 2012-08-08 14:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.399D3E0F3FB865AB
    2012-08-08 14:11 - 2012-08-08 14:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB91755D859AF796
    2012-08-08 14:07 - 2012-08-08 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F93FF9FD3B95AF9
    2012-08-08 14:03 - 2012-08-08 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.216AEC2C1AD8CA1D
    2012-08-08 13:54 - 2011-02-21 16:48 - 05074708 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-08-08 13:45 - 2012-08-08 13:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
    2012-08-08 12:57 - 2012-08-08 12:56 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
    2012-08-08 12:32 - 2012-08-08 12:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-08 12:30 - 2012-08-08 12:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
    2012-08-08 12:22 - 2012-08-08 12:22 - 00000000 ____A C:\extensions.sqlite
    2012-08-08 12:20 - 2011-02-23 10:05 - 00000462 _RASH C:\Users\All Users\ntuser.pol
    2012-08-06 18:19 - 2012-08-06 18:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
    2012-08-02 13:32 - 2012-05-02 10:49 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-08-02 13:32 - 2011-06-29 08:53 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-08-02 09:17 - 2012-08-02 09:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
    2012-08-02 09:16 - 2012-08-02 09:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
    2012-08-02 09:16 - 2012-08-02 09:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
    2012-07-27 10:14 - 2012-07-27 10:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
    2012-07-24 10:32 - 2012-07-18 15:37 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
    2012-07-18 15:48 - 2012-07-18 15:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
    2012-07-18 13:31 - 2012-07-18 13:27 - 00000166 ____A C:\Windows\ODBC.INI
    2012-07-18 13:18 - 2011-02-21 17:07 - 00113664 ____A C:\Users\Rick\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 13:06 - 2012-07-18 13:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
    2012-07-18 13:03 - 2012-07-18 13:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 13:03 - 2012-07-18 13:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
    2012-07-18 12:55 - 2011-03-18 11:09 - 00113664 ____A C:\Users\MaryBeth\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 12:54 - 2011-07-06 16:15 - 00113664 ____A C:\Users\frank\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 12:53 - 2009-07-13 23:49 - 00422368 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-07-18 11:06 - 2012-07-18 11:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
    2012-07-16 10:29 - 2012-01-26 11:04 - 00000036 ___AH C:\Windows\SysWOW64\f9t.dat
    2012-07-12 10:59 - 2012-07-12 10:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
    2012-07-12 10:53 - 2012-07-12 10:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
    2012-07-12 10:52 - 2012-07-12 10:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
    2012-07-11 03:02 - 2011-02-21 11:49 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-07-03 13:46 - 2012-08-08 12:32 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-26 16:12 - 2012-06-26 16:12 - 00008467 ____A C:\Users\Rick\Documents\06262012.xls
    2012-06-19 13:17 - 2012-06-19 13:17 - 00000000 ___AH C:\Users\Rick\Documents\Default.rdp
    2012-06-13 17:32 - 2012-05-25 14:59 - 00011819 ____A C:\Users\nick\Documents\Budget.xlsx
    2012-06-11 22:02 - 2012-07-11 03:01 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-06-09 00:30 - 2012-07-10 15:40 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-06-08 23:46 - 2012-07-10 15:40 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-06-08 08:39 - 2012-06-08 08:39 - 00026112 ____A C:\Users\frank\Desktop\vacation.oft
    2012-06-06 11:31 - 2012-06-06 11:31 - 00741744 ____A (RealVNC Ltd. ) C:\Users\frank\Downloads\vnc-4_1_3-x86_win32.exe
    2012-06-06 00:50 - 2012-07-10 15:40 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-06-06 00:50 - 2012-07-10 15:40 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-06-06 00:09 - 2012-07-10 15:40 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-06-06 00:09 - 2012-07-10 15:40 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-06-05 13:56 - 2012-06-05 13:55 - 01636224 ____A (Inbox.com, Inc. ) C:\Users\Rick\Downloads\MapsSetup.exe
    2012-06-02 17:19 - 2012-06-21 08:05 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 17:19 - 2012-06-21 08:05 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-02 17:19 - 2012-06-21 08:05 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 17:19 - 2012-06-21 08:05 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 17:19 - 2012-06-21 08:05 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-02 17:15 - 2012-06-21 08:05 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-02 17:15 - 2012-06-21 08:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-02 15:19 - 2012-06-21 08:05 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 15:15 - 2012-06-21 08:05 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-02 07:49 - 2012-07-11 03:05 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-02 07:17 - 2012-07-11 03:05 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-02 07:12 - 2012-07-11 03:05 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-02 07:05 - 2012-07-11 03:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-02 07:05 - 2012-07-11 03:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-02 07:04 - 2012-07-11 03:05 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-02 07:04 - 2012-07-11 03:05 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-02 07:03 - 2012-07-11 03:05 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-02 07:01 - 2012-07-11 03:05 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-02 07:00 - 2012-07-11 03:05 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-02 06:59 - 2012-07-11 03:05 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-02 06:57 - 2012-07-11 03:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-02 06:57 - 2012-07-11 03:05 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-02 06:54 - 2012-07-11 03:05 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-02 04:07 - 2012-07-11 03:05 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-02 03:43 - 2012-07-11 03:05 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-02 03:33 - 2012-07-11 03:05 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-02 03:26 - 2012-07-11 03:05 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-02 03:25 - 2012-07-11 03:05 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-02 03:25 - 2012-07-11 03:05 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-02 03:23 - 2012-07-11 03:05 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-02 03:21 - 2012-07-11 03:05 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-02 03:20 - 2012-07-11 03:05 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-02 03:19 - 2012-07-11 03:05 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-02 03:19 - 2012-07-11 03:05 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-02 03:17 - 2012-07-11 03:05 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-02 03:16 - 2012-07-11 03:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-02 03:14 - 2012-07-11 03:05 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-02 00:38 - 2012-07-10 15:40 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2012-06-02 00:38 - 2012-07-10 15:40 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-06-02 00:37 - 2012-07-10 15:40 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2012-06-02 00:27 - 2012-07-10 15:40 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-06-02 00:27 - 2012-07-10 15:40 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-06-01 23:48 - 2012-07-10 15:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2012-06-01 23:48 - 2012-07-10 15:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2012-06-01 23:47 - 2012-07-10 15:40 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2012-06-01 23:42 - 2012-07-10 15:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2012-05-31 12:25 - 2011-02-21 13:46 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
    2012-05-25 17:19 - 2012-05-25 17:19 - 00009101 ____A C:\Users\Rick\Documents\nate.xlsx
    2012-05-14 14:46 - 2012-05-14 14:46 - 00897520 ____A (Dyn, Inc.) C:\Users\frank\Downloads\DynUpSetup.exe

    ZeroAccess:
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\@
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\L
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\00000001.@
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\80000000.@
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\800000cb.@

    ZeroAccess:
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\@
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\L
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\U

    ========================= Bamital & volsnap Check ============

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ========================= Memory info ======================

    Percentage of memory in use: 24%
    Total physical RAM: 6135.23 MB
    Available physical RAM: 4610.82 MB
    Total Pagefile: 12268.57 MB
    Available Pagefile: 10409.61 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.88 MB

    ======================= Partitions =========================

    1 Drive c: () (Fixed) (Total:98.13 GB) (Free:23.24 GB) NTFS
    2 Drive d: (Data) (Fixed) (Total:738.97 GB) (Free:687.8 GB) NTFS
    3 Drive e: (Iomega HDD) (Fixed) (Total:1863.01 GB) (Free:1734 GB) NTFS
    4 Drive f: (USB DISK) (Removable) (Total:1.91 GB) (Free:1.91 GB) FAT


    ==========================================================

    Last Boot: 2012-08-08 18:30

    ======================= End Of Log ==========================
  6. Broni

    Broni Malware Annihilator Posts: 45,203   +242

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ============================================

    You ran FRST from within Windows. That won't work with ZeroAccess infection.
    We don't have too many tools for Server 2008 so I'm not sure if it'll work but here is the correct way to do it...

    For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

    Next...

    Re-run FRST again.
    Type the following in the edit box after "Search:".

    services.exe

    Click Search button and post the log (Search.txt) it makes in your reply.

    I'll expect two logs:
    - FRST.txt
    - Search.txt
  7. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
    Ran by SYSTEM at 09-08-2012 11:23:37
    Running from G:\
    Windows Server 2008 R2 Standard (X64) OS Language: English(US)
    The current controlset is ControlSet002

    ========================== Registry (Whitelisted) =============

    HKLM\...\Run: [QLogicSaveSystemInfo] rundll32.exe qlco1006.dll,QLSaveSystemInfo [x]
    HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2305912 2012-06-18] (Intuit Inc. All rights reserved.)
    HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
    HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
    HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
    HKU\MaryBeth\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
    HKU\Rick\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
    Tcpip\..\Interfaces\{B0A35114-EF36-4060-B305-19D57C618B96}: [NameServer]208.67.222.222,208.67.220.220
    Lsa: [Notification Packages] scecli
    rassfm
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\Dyn Updater Tray Icon.lnk
    ShortcutTarget: Dyn Updater Tray Icon.lnk -> C:\Program Files (x86)\Dyn Updater\DynTray.exe (Dyn, Inc.)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
    ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
    ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
    ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
    Startup: C:\Users\frank\Start Menu\Programs\Startup\hs_err_pid5788.log ()
    Startup: C:\Users\frank\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\MaryBeth\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\nick\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\Rick\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

    ==================== Services (Whitelisted) ======

    2 atnthost; "C:\ProgramData\webex\MyWebEx\319\atnthost.exe" [16776 2011-11-10] (WebEx Communications, Inc.)
    2 Dyn Updater; C:\Program Files (x86)\Dyn Updater\DynUpSvc.exe [95608 2011-11-15] (Dyn, Inc.)
    3 FCRegSvc; C:\Windows\System32\FCRegSvc.dll [25600 2009-07-13] (Microsoft Corporation)
    2 HP Digital Sending Software; "C:\Program Files (x86)\Hewlett-Packard\HP Digital Sending Software 4.91\Filesystems\Core\bin\XP-x86\Release\HP.Dss.App.WinService.exe" [16440 2011-03-08] (Hewlett-Packard)
    2 McAfee SiteAdvisor Service; C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [103472 2012-06-15] (McAfee, Inc.)
    2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
    2 MSSQL$HPDSS; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sHPDSS [29293408 2010-12-10] (Microsoft Corporation)
    2 NetPipeActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
    2 NetTcpActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
    3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
    3 QuickBooksDB20; C:\PROGRA~2\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [678912 2009-08-18] (Intuit, Inc.)
    3 QuickBooksDB21; C:\PROGRA~2\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB21 [679936 2010-04-27] (Intuit, Inc.)
    3 rqs; C:\Windows\System32\rqs.exe [41472 2009-07-13] (Microsoft Corporation)
    3 RSoPProv; C:\Windows\System32\RSoPProv.exe [91648 2009-07-13] (Microsoft Corporation)
    3 sacsvr; C:\Windows\System32\sacsvr.dll [14848 2009-07-13] (Microsoft Corporation)
    2 SNMP; C:\Windows\System32\snmp.exe [49664 2009-07-13] (Microsoft Corporation)
    2 SNMP; C:\Windows\SysWow64\snmp.exe [47616 2009-07-13] (Microsoft Corporation)
    2 sysdown; C:\Windows\System32\sysdown.exe [17960 2010-01-25] (Hewlett-Packard Company)
    2 TermServLicensing; C:\Windows\System32\lserver.dll [692224 2009-07-13] (Microsoft Corporation)
    2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [451072 2009-07-13] (Microsoft Corporation)
    2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [396288 2009-07-13] (Microsoft Corporation)
    2 WinVNC4; "C:\Program Files (x86)\RealVNC\VNC4\WinVNC4.exe" -service [439632 2008-10-15] (RealVNC Ltd.)
    2 SQLANYs_ptsrv; C:\Program Files\Profit Tools\Sybase\SQLA12\Bin64\dbsrv12.exe -hvSQLANYs_ptsrv [x]

    ========================== Drivers (Whitelisted) =============

    3 aarahci; C:\Windows\System32\Drivers\aarahci.sys [363056 2008-07-31] (Adaptec, Inc.)
    3 b06diag; C:\Windows\system32\DRIVERS\bxdiaga.sys [89128 2010-08-02] (Broadcom Corporation)
    3 bchtsw64; C:\Windows\System32\Drivers\bchtsw64.sys [90936 2009-10-23] (Broadcom Corporation)
    3 be2iscsi; C:\Windows\System32\Drivers\be2iscsi.sys [163376 2010-08-31] (ServerEngines Corporation)
    3 bfad; C:\Windows\System32\Drivers\bfad.sys [1125488 2010-04-20] (Brocade Communications Systems, Inc.)
    0 bfad_up; C:\Windows\System32\Drivers\bfad_up.sys [15472 2010-04-20] (Brocade Communications Systems, Inc.)
    3 BXOIS; C:\Windows\System32\Drivers\BXOIS.sys [524840 2010-08-02] (Broadcom Corporation)
    3 elxcna; C:\Windows\System32\Drivers\elxcna.sys [646664 2010-08-05] (Emulex)
    3 G200e; C:\Windows\System32\DRIVERS\G200em.sys [242176 2011-03-14] (Matrox Graphics Inc.)
    3 HpAHCIsr; C:\Windows\System32\Drivers\HpAHCIsr.sys [223336 2010-05-27] (Hewlett-Packard Company)
    0 HpCISSs2; C:\Windows\System32\Drivers\HpCISSs2.sys [156776 2010-02-21] (Hewlett-Packard Company)
    3 hpqmgmt; C:\Windows\System32\Drivers\hpqmgmt.sys [98856 2009-03-19] (Hewlett-Packard Company)
    3 HPUSBMSC; C:\Windows\system32\DRIVERS\HPUSBXSC.SYS [47144 2009-06-17] (Hewlett-Packard)
    3 ioatdma; C:\Windows\System32\Drivers\qd260x64.sys [35328 2009-06-10] (Intel Corporation)
    3 mlx4_bus; C:\Windows\System32\Drivers\mlx4_bus.sys [291944 2010-09-01] (Hewlett-Packard)
    3 MRxDAV; C:\Windows\SysWow64\Drivers\MRxDAV.sys [115712 2009-07-13] (Microsoft Corporation)
    3 q57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [405544 2010-08-02] (Broadcom Corporation)
    0 sacdrv; C:\Windows\System32\Drivers\sacdrv.sys [96320 2009-07-13] (Microsoft Corporation)
    3 storvsp; C:\Windows\System32\Drivers\storvsp.sys [121856 2009-07-13] (Microsoft Corporation)
    3 Vid; C:\Windows\System32\Drivers\Vid.sys [181248 2009-07-13] (Microsoft Corporation)
    3 KAPFA; \??\C:\Windows\system32\drivers\KAPFA.SYS [x]

    ========================== NetSvcs (Whitelisted) ===========

    NETSVC: sacsvr -> C:\Windows\system32\sacsvr.dll (Microsoft Corporation)

    ============ One Month Created Files and Folders ==============

    2012-08-09 06:04 - 2012-08-09 05:50 - 00607260 ____R (Swearware) C:\Users\frank\Desktop\dds.com
    2012-08-09 06:04 - 2012-08-09 05:49 - 00302592 ____A C:\Users\frank\Desktop\wy82hjq3.exe
    2012-08-09 05:58 - 2012-08-09 05:58 - 00000000 ____D C:\FRST
    2012-08-09 05:40 - 2012-08-09 05:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6639107541643CB4
    2012-08-09 05:36 - 2012-08-09 05:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
    2012-08-09 05:33 - 2012-08-09 05:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
    2012-08-09 05:29 - 2012-08-09 05:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
    2012-08-09 05:25 - 2012-08-09 05:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
    2012-08-09 05:21 - 2012-08-09 05:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
    2012-08-09 05:18 - 2012-08-09 05:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
    2012-08-09 05:14 - 2012-08-09 05:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
    2012-08-09 05:10 - 2012-08-09 05:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
    2012-08-09 05:07 - 2012-08-09 05:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
    2012-08-09 05:03 - 2012-08-09 05:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
    2012-08-09 04:59 - 2012-08-09 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
    2012-08-09 04:55 - 2012-08-09 04:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
    2012-08-09 04:52 - 2012-08-09 04:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
    2012-08-09 04:48 - 2012-08-09 04:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
    2012-08-09 04:44 - 2012-08-09 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
    2012-08-09 04:40 - 2012-08-09 04:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
    2012-08-09 04:37 - 2012-08-09 04:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
    2012-08-09 04:33 - 2012-08-09 04:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
    2012-08-09 04:29 - 2012-08-09 04:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
    2012-08-09 04:26 - 2012-08-09 04:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
    2012-08-09 04:22 - 2012-08-09 04:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
    2012-08-09 04:18 - 2012-08-09 04:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
    2012-08-09 04:14 - 2012-08-09 04:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
    2012-08-09 04:11 - 2012-08-09 04:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
    2012-08-09 04:07 - 2012-08-09 04:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
    2012-08-09 04:03 - 2012-08-09 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
    2012-08-09 04:00 - 2012-08-09 04:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
    2012-08-09 03:56 - 2012-08-09 03:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
    2012-08-09 03:52 - 2012-08-09 03:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
    2012-08-09 03:48 - 2012-08-09 03:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
    2012-08-09 03:45 - 2012-08-09 03:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
    2012-08-09 03:41 - 2012-08-09 03:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
    2012-08-09 03:37 - 2012-08-09 03:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
    2012-08-09 03:33 - 2012-08-09 03:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
    2012-08-09 03:30 - 2012-08-09 03:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
    2012-08-09 03:26 - 2012-08-09 03:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
    2012-08-09 03:22 - 2012-08-09 03:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
    2012-08-09 03:19 - 2012-08-09 03:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
    2012-08-09 03:15 - 2012-08-09 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
    2012-08-09 03:11 - 2012-08-09 03:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
    2012-08-09 03:07 - 2012-08-09 03:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
    2012-08-09 03:04 - 2012-08-09 03:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
    2012-08-09 03:00 - 2012-08-09 03:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
    2012-08-09 02:56 - 2012-08-09 02:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
    2012-08-09 02:53 - 2012-08-09 02:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
    2012-08-09 02:49 - 2012-08-09 02:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
    2012-08-09 02:45 - 2012-08-09 02:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
    2012-08-09 02:41 - 2012-08-09 02:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
    2012-08-09 02:38 - 2012-08-09 02:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
    2012-08-09 02:34 - 2012-08-09 02:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
    2012-08-09 02:30 - 2012-08-09 02:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
    2012-08-09 02:26 - 2012-08-09 02:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
    2012-08-09 02:23 - 2012-08-09 02:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
    2012-08-09 02:19 - 2012-08-09 02:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
    2012-08-09 02:15 - 2012-08-09 02:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
    2012-08-09 02:12 - 2012-08-09 02:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
    2012-08-09 02:08 - 2012-08-09 02:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
    2012-08-09 02:04 - 2012-08-09 02:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
    2012-08-09 02:00 - 2012-08-09 02:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
    2012-08-09 01:57 - 2012-08-09 01:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
    2012-08-09 01:53 - 2012-08-09 01:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
    2012-08-09 01:49 - 2012-08-09 01:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
    2012-08-09 01:46 - 2012-08-09 01:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
    2012-08-09 01:42 - 2012-08-09 01:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
    2012-08-09 01:38 - 2012-08-09 01:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
    2012-08-09 01:34 - 2012-08-09 01:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
    2012-08-09 01:31 - 2012-08-09 01:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
    2012-08-09 01:27 - 2012-08-09 01:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
    2012-08-09 01:23 - 2012-08-09 01:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
    2012-08-09 01:19 - 2012-08-09 01:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
    2012-08-09 01:16 - 2012-08-09 01:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
    2012-08-09 01:12 - 2012-08-09 01:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
    2012-08-09 01:08 - 2012-08-09 01:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
    2012-08-09 01:05 - 2012-08-09 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
    2012-08-09 01:01 - 2012-08-09 01:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
    2012-08-09 00:57 - 2012-08-09 00:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
    2012-08-09 00:53 - 2012-08-09 00:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
    2012-08-09 00:50 - 2012-08-09 00:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
    2012-08-09 00:46 - 2012-08-09 00:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
    2012-08-09 00:42 - 2012-08-09 00:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
    2012-08-09 00:39 - 2012-08-09 00:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
    2012-08-09 00:35 - 2012-08-09 00:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
    2012-08-09 00:31 - 2012-08-09 00:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
    2012-08-09 00:27 - 2012-08-09 00:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
    2012-08-09 00:24 - 2012-08-09 00:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
    2012-08-09 00:20 - 2012-08-09 00:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
    2012-08-09 00:16 - 2012-08-09 00:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
    2012-08-09 00:12 - 2012-08-09 00:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
    2012-08-09 00:09 - 2012-08-09 00:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
    2012-08-09 00:05 - 2012-08-09 00:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
    2012-08-09 00:01 - 2012-08-09 00:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
    2012-08-08 23:58 - 2012-08-08 23:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
    2012-08-08 23:54 - 2012-08-08 23:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
    2012-08-08 23:50 - 2012-08-08 23:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
    2012-08-08 23:46 - 2012-08-08 23:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
    2012-08-08 23:43 - 2012-08-08 23:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
    2012-08-08 23:39 - 2012-08-08 23:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
    2012-08-08 23:35 - 2012-08-08 23:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
    2012-08-08 23:31 - 2012-08-08 23:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
    2012-08-08 23:28 - 2012-08-08 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
    2012-08-08 23:24 - 2012-08-08 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
    2012-08-08 23:20 - 2012-08-08 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
    2012-08-08 23:17 - 2012-08-08 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
    2012-08-08 23:13 - 2012-08-08 23:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
    2012-08-08 23:09 - 2012-08-08 23:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
    2012-08-08 23:05 - 2012-08-08 23:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
    2012-08-08 23:02 - 2012-08-08 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
    2012-08-08 22:58 - 2012-08-08 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
    2012-08-08 22:54 - 2012-08-08 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
    2012-08-08 22:51 - 2012-08-08 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
    2012-08-08 22:47 - 2012-08-08 22:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
    2012-08-08 22:43 - 2012-08-08 22:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
    2012-08-08 22:39 - 2012-08-08 22:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
    2012-08-08 22:36 - 2012-08-08 22:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
    2012-08-08 22:32 - 2012-08-08 22:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
    2012-08-08 22:28 - 2012-08-08 22:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
    2012-08-08 22:24 - 2012-08-08 22:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
    2012-08-08 22:21 - 2012-08-08 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
    2012-08-08 22:17 - 2012-08-08 22:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
    2012-08-08 22:13 - 2012-08-08 22:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
    2012-08-08 22:10 - 2012-08-08 22:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
    2012-08-08 22:06 - 2012-08-08 22:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
    2012-08-08 22:02 - 2012-08-08 22:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
    2012-08-08 21:58 - 2012-08-08 21:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
    2012-08-08 21:55 - 2012-08-08 21:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
    2012-08-08 21:51 - 2012-08-08 21:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
    2012-08-08 21:47 - 2012-08-08 21:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
    2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
    2012-08-08 21:40 - 2012-08-08 21:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
    2012-08-08 21:36 - 2012-08-08 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
    2012-08-08 21:32 - 2012-08-08 21:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
    2012-08-08 21:29 - 2012-08-08 21:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
    2012-08-08 21:25 - 2012-08-08 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
    2012-08-08 21:21 - 2012-08-08 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
    2012-08-08 21:17 - 2012-08-08 21:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
    2012-08-08 21:14 - 2012-08-08 21:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
    2012-08-08 21:10 - 2012-08-08 21:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
    2012-08-08 21:06 - 2012-08-08 21:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
    2012-08-08 21:03 - 2012-08-08 21:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
    2012-08-08 20:59 - 2012-08-08 20:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
    2012-08-08 20:55 - 2012-08-08 20:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
    2012-08-08 20:52 - 2012-08-08 20:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
    2012-08-08 20:48 - 2012-08-08 20:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
    2012-08-08 20:44 - 2012-08-08 20:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
    2012-08-08 20:40 - 2012-08-08 20:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
    2012-08-08 20:37 - 2012-08-08 20:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
    2012-08-08 20:33 - 2012-08-08 20:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
    2012-08-08 20:29 - 2012-08-08 20:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
    2012-08-08 20:26 - 2012-08-08 20:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
    2012-08-08 20:22 - 2012-08-08 20:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
    2012-08-08 20:18 - 2012-08-08 20:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
    2012-08-08 20:15 - 2012-08-08 20:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
    2012-08-08 20:11 - 2012-08-08 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
    2012-08-08 20:07 - 2012-08-08 20:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
    2012-08-08 20:03 - 2012-08-08 20:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
    2012-08-08 20:00 - 2012-08-08 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
    2012-08-08 19:56 - 2012-08-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
    2012-08-08 19:52 - 2012-08-08 19:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
    2012-08-08 19:49 - 2012-08-08 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
    2012-08-08 19:45 - 2012-08-08 19:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
    2012-08-08 19:41 - 2012-08-08 19:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
    2012-08-08 19:38 - 2012-08-08 19:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
    2012-08-08 19:34 - 2012-08-08 19:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
    2012-08-08 19:30 - 2012-08-08 19:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
    2012-08-08 19:27 - 2012-08-08 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
    2012-08-08 18:44 - 2012-08-08 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
    2012-08-08 17:05 - 2012-08-08 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
    2012-08-08 16:26 - 2012-08-08 16:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
    2012-08-08 15:48 - 2012-08-08 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
  8. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    2012-08-08 13:51 - 2012-08-08 13:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
    2012-08-08 13:50 - 2012-08-08 13:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
    2012-08-08 13:43 - 2012-08-08 13:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
    2012-08-08 12:02 - 2012-08-08 12:02 - 00000000 ____D C:\Users\frank\AppData\Local\Macromedia
    2012-08-08 11:51 - 2012-08-08 11:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.349AEC5204EBA773
    2012-08-08 11:47 - 2012-08-08 11:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4B1FF6622C08F08
    2012-08-08 11:44 - 2012-08-08 11:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B676A461F41E7A
    2012-08-08 11:41 - 2012-08-08 11:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7CEB3957CE766A8A
    2012-08-08 11:37 - 2012-08-08 11:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89FF8A9A97317FFE
    2012-08-08 11:37 - 2012-08-08 11:37 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uwmbzbaf.sys
    2012-08-08 11:34 - 2012-08-08 11:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E8C07ED33CE05A6
    2012-08-08 11:31 - 2012-08-08 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E6A751AE46DA9A1
    2012-08-08 11:30 - 2012-08-08 11:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
    2012-08-08 11:23 - 2012-08-08 11:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A911C064868CAD
    2012-08-08 11:17 - 2012-08-08 11:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FF333A3177CB21
    2012-08-08 11:14 - 2012-08-08 11:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.399D3E0F3FB865AB
    2012-08-08 11:11 - 2012-08-08 11:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB91755D859AF796
    2012-08-08 11:07 - 2012-08-08 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F93FF9FD3B95AF9
    2012-08-08 11:03 - 2012-08-08 11:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.216AEC2C1AD8CA1D
    2012-08-08 10:54 - 2012-08-08 10:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-08-08 10:54 - 2012-08-08 10:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-08-08 10:52 - 2012-08-08 10:52 - 00000000 ____D C:\Windows\System32\SPReview
    2012-08-08 10:45 - 2012-08-08 10:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
    2012-08-08 09:56 - 2012-08-08 09:57 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
    2012-08-08 09:51 - 2012-08-08 09:51 - 00000000 ____D C:\Users\Rick\AppData\Roaming\Malwarebytes
    2012-08-08 09:32 - 2012-08-08 09:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Users\frank\AppData\Roaming\Malwarebytes
    2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-08-08 09:32 - 2012-07-03 10:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-08-08 09:30 - 2012-08-08 09:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
    2012-08-08 09:23 - 2012-08-08 09:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-08-08 09:22 - 2012-08-08 09:22 - 00000000 ____A C:\extensions.sqlite
    2012-08-06 15:19 - 2012-08-06 15:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
    2012-08-02 06:17 - 2012-08-02 06:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
    2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
    2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
    2012-07-27 08:03 - 2012-07-27 14:58 - 00000000 ____D C:\imagetmp
    2012-07-27 07:14 - 2012-07-27 07:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
    2012-07-25 12:08 - 2012-07-25 12:08 - 00000000 ____D C:\Users\frank\AppData\Roaming\SQL Anywhere 12
    2012-07-24 07:30 - 2012-07-24 07:30 - 00000000 ____D C:\Users\Rick\AppData\Local\Help
    2012-07-24 07:29 - 2012-07-24 07:29 - 00000000 ____D C:\Users\Rick\AppData\Roaming\SQL Anywhere 12
    2012-07-19 13:34 - 2012-07-19 13:34 - 00000000 ____D C:\Users\Install\AppData\Local\Adobe
    2012-07-19 12:35 - 2012-07-19 12:36 - 00000000 ____D C:\Users\Install\AppData\Roaming\Mozilla
    2012-07-19 12:35 - 2012-07-19 12:35 - 00000000 ____D C:\Users\Install\AppData\Local\Mozilla
    2012-07-18 12:48 - 2012-07-18 12:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
    2012-07-18 12:38 - 2012-07-18 12:38 - 00000000 ____D C:\Users\Install\AppData\Roaming\Help
    2012-07-18 12:38 - 2012-07-18 12:38 - 00000000 ____D C:\Users\Install\AppData\Local\Help
    2012-07-18 12:37 - 2012-07-24 07:32 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
    2012-07-18 12:36 - 2012-07-19 13:34 - 00000000 ____D C:\Users\Install\AppData\Roaming\Adobe
    2012-07-18 12:36 - 2009-08-04 09:56 - 00296960 ____A (Microsoft Corporation) C:\Windows\winhlp32.exe
    2012-07-18 12:36 - 2009-08-04 09:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftsrch.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\System32\ftsrch.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx041e.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\System32\ftlx041e.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx0411.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\ftlx0411.dll
    2012-07-18 12:11 - 2012-07-18 12:11 - 00000000 ____D C:\Users\Install\AppData\Roaming\WinRAR
    2012-07-18 10:28 - 2012-07-18 12:32 - 00000000 ____D C:\Users\Public\Documents\Sybase Central 6.1.0
    2012-07-18 10:27 - 2012-07-18 10:31 - 00000166 ____A C:\Windows\ODBC.INI
    2012-07-18 10:27 - 2012-07-18 10:31 - 00000000 ____D C:\Users\Install\AppData\Roaming\SQL Anywhere 12
    2012-07-18 10:25 - 2012-07-18 12:30 - 00000000 ____D C:\Users\Install\sybase
    2012-07-18 10:25 - 2012-07-18 10:25 - 00000000 ____D C:\Users\Public\Documents\DBISQL 12.0.1
    2012-07-18 10:06 - 2012-07-18 10:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
    2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Deployment
    2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Citrix
    2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Apps\2.0
    2012-07-18 10:03 - 2012-07-18 10:25 - 00000000 ____D C:\users\Install
    2012-07-18 10:03 - 2012-07-18 10:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Roaming\Apple Computer
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Local\Intuit
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Local\Apple Computer
    2012-07-18 10:03 - 2011-10-11 00:01 - 00000000 ____D C:\Users\Install\AppData\Local\Microsoft Help
    2012-07-18 10:03 - 2011-02-23 08:42 - 00000000 ____D C:\Users\Install\AppData\Roaming\Macromedia
    2012-07-18 09:53 - 2012-07-18 12:12 - 00000000 ____D C:\Users\All Users\SQL Anywhere 12
    2012-07-18 09:30 - 2004-07-12 10:50 - 00155648 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JavaAccessBridge.dll
    2012-07-18 09:30 - 2004-07-12 10:50 - 00081920 ____A (Sun Microsystems©) C:\Windows\SysWOW64\WindowsAccessBridge.dll
    2012-07-18 09:30 - 2004-07-12 10:50 - 00032768 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JAWTAccessBridge.dll
    2012-07-18 09:29 - 2012-07-18 09:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2012-07-18 08:06 - 2012-07-18 08:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
    2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Deployment
    2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Citrix
    2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Apps\2.0
    2012-07-12 07:59 - 2012-07-12 07:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
    2012-07-12 07:53 - 2012-07-12 07:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
    2012-07-12 07:52 - 2012-07-12 07:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
    2012-07-11 00:05 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-07-11 00:05 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-07-11 00:05 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-07-11 00:05 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-07-11 00:05 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-07-11 00:05 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-07-11 00:05 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-07-11 00:05 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-07-11 00:05 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-07-11 00:05 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-07-11 00:05 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-07-11 00:05 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-07-11 00:05 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-07-11 00:05 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-07-11 00:05 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-07-11 00:05 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-07-11 00:05 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-07-11 00:05 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-07-11 00:05 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-07-11 00:05 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-07-11 00:05 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-07-11 00:05 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-07-11 00:05 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-07-11 00:05 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-07-11 00:05 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-07-11 00:05 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-07-11 00:05 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-07-11 00:05 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-07-11 00:01 - 2012-06-11 19:02 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-07-10 12:40 - 2012-06-08 21:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-07-10 12:40 - 2012-06-08 20:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-07-10 12:40 - 2012-06-05 21:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-07-10 12:40 - 2012-06-05 21:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-07-10 12:40 - 2012-06-05 21:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-07-10 12:40 - 2012-06-05 21:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-07-10 12:40 - 2012-06-01 21:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2012-07-10 12:40 - 2012-06-01 21:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-07-10 12:40 - 2012-06-01 21:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2012-07-10 12:40 - 2012-06-01 21:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-07-10 12:40 - 2012-06-01 21:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-07-10 12:40 - 2012-06-01 20:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2012-07-10 12:40 - 2012-06-01 20:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2012-07-10 12:40 - 2012-06-01 20:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2012-07-10 12:40 - 2012-06-01 20:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    ============ 3 Months Modified Files ========================
    2012-08-09 07:39 - 2009-07-13 20:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-08-09 07:39 - 2009-07-13 20:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-08-09 07:34 - 2011-02-18 10:42 - 01543552 ____A C:\Windows\WindowsUpdate.log
    2012-08-09 07:32 - 2012-05-02 07:49 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-08-09 05:55 - 2009-09-22 11:32 - 00851644 ____A C:\Windows\System32\perfh00A.dat
    2012-08-09 05:55 - 2009-09-22 11:32 - 00195538 ____A C:\Windows\System32\perfc00A.dat
    2012-08-09 05:55 - 2009-09-22 11:18 - 00845594 ____A C:\Windows\System32\perfh010.dat
    2012-08-09 05:55 - 2009-09-22 11:18 - 00182856 ____A C:\Windows\System32\perfc010.dat
    2012-08-09 05:55 - 2009-09-22 11:06 - 00808956 ____A C:\Windows\System32\perfh007.dat
    2012-08-09 05:55 - 2009-09-22 11:06 - 00183696 ____A C:\Windows\System32\perfc007.dat
    2012-08-09 05:55 - 2009-09-22 10:53 - 00856886 ____A C:\Windows\System32\perfh00C.dat
    2012-08-09 05:55 - 2009-09-22 10:53 - 00187520 ____A C:\Windows\System32\perfc00C.dat
    2012-08-09 05:55 - 2009-07-13 21:10 - 05006346 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-08-09 05:54 - 2009-07-13 20:56 - 00039600 ____A C:\Windows\setupact.log
    2012-08-09 05:50 - 2012-08-09 06:04 - 00607260 ____R (Swearware) C:\Users\frank\Desktop\dds.com
    2012-08-09 05:49 - 2012-08-09 06:04 - 00302592 ____A C:\Users\frank\Desktop\wy82hjq3.exe
    2012-08-09 05:43 - 2009-07-13 21:06 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-08-09 05:40 - 2012-08-09 05:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6639107541643CB4
    2012-08-09 05:36 - 2012-08-09 05:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
    2012-08-09 05:33 - 2012-08-09 05:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
    2012-08-09 05:29 - 2012-08-09 05:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
    2012-08-09 05:25 - 2012-08-09 05:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
    2012-08-09 05:21 - 2012-08-09 05:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
    2012-08-09 05:18 - 2012-08-09 05:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
    2012-08-09 05:14 - 2012-08-09 05:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
    2012-08-09 05:10 - 2012-08-09 05:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
    2012-08-09 05:07 - 2012-08-09 05:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
    2012-08-09 05:03 - 2012-08-09 05:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
    2012-08-09 04:59 - 2012-08-09 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
    2012-08-09 04:55 - 2012-08-09 04:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
    2012-08-09 04:52 - 2012-08-09 04:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
    2012-08-09 04:48 - 2012-08-09 04:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
    2012-08-09 04:44 - 2012-08-09 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
    2012-08-09 04:40 - 2012-08-09 04:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
    2012-08-09 04:37 - 2012-08-09 04:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
    2012-08-09 04:33 - 2012-08-09 04:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
    2012-08-09 04:29 - 2012-08-09 04:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
    2012-08-09 04:26 - 2012-08-09 04:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
    2012-08-09 04:22 - 2012-08-09 04:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
    2012-08-09 04:18 - 2012-08-09 04:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
    2012-08-09 04:14 - 2012-08-09 04:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
    2012-08-09 04:11 - 2012-08-09 04:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
    2012-08-09 04:07 - 2012-08-09 04:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
    2012-08-09 04:03 - 2012-08-09 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
    2012-08-09 04:00 - 2012-08-09 04:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
    2012-08-09 03:56 - 2012-08-09 03:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
    2012-08-09 03:52 - 2012-08-09 03:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
    2012-08-09 03:48 - 2012-08-09 03:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
    2012-08-09 03:45 - 2012-08-09 03:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
    2012-08-09 03:41 - 2012-08-09 03:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
    2012-08-09 03:37 - 2012-08-09 03:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
    2012-08-09 03:33 - 2012-08-09 03:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
    2012-08-09 03:30 - 2012-08-09 03:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
    2012-08-09 03:26 - 2012-08-09 03:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
    2012-08-09 03:22 - 2012-08-09 03:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
    2012-08-09 03:19 - 2012-08-09 03:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
    2012-08-09 03:15 - 2012-08-09 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
    2012-08-09 03:11 - 2012-08-09 03:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
    2012-08-09 03:07 - 2012-08-09 03:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
    2012-08-09 03:04 - 2012-08-09 03:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
    2012-08-09 03:00 - 2012-08-09 03:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
    2012-08-09 02:56 - 2012-08-09 02:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
    2012-08-09 02:53 - 2012-08-09 02:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
    2012-08-09 02:49 - 2012-08-09 02:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
    2012-08-09 02:45 - 2012-08-09 02:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
    2012-08-09 02:41 - 2012-08-09 02:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
    2012-08-09 02:38 - 2012-08-09 02:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
    2012-08-09 02:34 - 2012-08-09 02:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
    2012-08-09 02:30 - 2012-08-09 02:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
    2012-08-09 02:26 - 2012-08-09 02:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
    2012-08-09 02:23 - 2012-08-09 02:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
    2012-08-09 02:19 - 2012-08-09 02:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
    2012-08-09 02:15 - 2012-08-09 02:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
    2012-08-09 02:12 - 2012-08-09 02:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
    2012-08-09 02:08 - 2012-08-09 02:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
    2012-08-09 02:04 - 2012-08-09 02:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
    2012-08-09 02:00 - 2012-08-09 02:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
    2012-08-09 01:57 - 2012-08-09 01:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
    2012-08-09 01:53 - 2012-08-09 01:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
    2012-08-09 01:49 - 2012-08-09 01:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
    2012-08-09 01:46 - 2012-08-09 01:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
    2012-08-09 01:42 - 2012-08-09 01:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
    2012-08-09 01:38 - 2012-08-09 01:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
    2012-08-09 01:34 - 2012-08-09 01:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
    2012-08-09 01:31 - 2012-08-09 01:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
    2012-08-09 01:27 - 2012-08-09 01:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
    2012-08-09 01:23 - 2012-08-09 01:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
    2012-08-09 01:19 - 2012-08-09 01:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
    2012-08-09 01:16 - 2012-08-09 01:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
    2012-08-09 01:12 - 2012-08-09 01:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
    2012-08-09 01:08 - 2012-08-09 01:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
    2012-08-09 01:05 - 2012-08-09 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
    2012-08-09 01:01 - 2012-08-09 01:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
    2012-08-09 00:57 - 2012-08-09 00:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
    2012-08-09 00:53 - 2012-08-09 00:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
    2012-08-09 00:50 - 2012-08-09 00:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
    2012-08-09 00:46 - 2012-08-09 00:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
    2012-08-09 00:42 - 2012-08-09 00:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
    2012-08-09 00:39 - 2012-08-09 00:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
    2012-08-09 00:35 - 2012-08-09 00:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
    2012-08-09 00:31 - 2012-08-09 00:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
    2012-08-09 00:27 - 2012-08-09 00:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
    2012-08-09 00:24 - 2012-08-09 00:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
    2012-08-09 00:20 - 2012-08-09 00:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
    2012-08-09 00:16 - 2012-08-09 00:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
    2012-08-09 00:12 - 2012-08-09 00:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
    2012-08-09 00:09 - 2012-08-09 00:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
    2012-08-09 00:05 - 2012-08-09 00:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
    2012-08-09 00:01 - 2012-08-09 00:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
    2012-08-08 23:58 - 2012-08-08 23:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
    2012-08-08 23:54 - 2012-08-08 23:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
    2012-08-08 23:50 - 2012-08-08 23:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
    2012-08-08 23:46 - 2012-08-08 23:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
    2012-08-08 23:43 - 2012-08-08 23:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
    2012-08-08 23:39 - 2012-08-08 23:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
    2012-08-08 23:35 - 2012-08-08 23:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
    2012-08-08 23:31 - 2012-08-08 23:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
    2012-08-08 23:28 - 2012-08-08 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
    2012-08-08 23:24 - 2012-08-08 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
    2012-08-08 23:20 - 2012-08-08 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
    2012-08-08 23:17 - 2012-08-08 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
    2012-08-08 23:13 - 2012-08-08 23:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
    2012-08-08 23:09 - 2012-08-08 23:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
    2012-08-08 23:05 - 2012-08-08 23:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
    2012-08-08 23:02 - 2012-08-08 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
    2012-08-08 22:58 - 2012-08-08 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
    2012-08-08 22:54 - 2012-08-08 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
    2012-08-08 22:51 - 2012-08-08 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
    2012-08-08 22:47 - 2012-08-08 22:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
    2012-08-08 22:43 - 2012-08-08 22:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
    2012-08-08 22:39 - 2012-08-08 22:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
    2012-08-08 22:36 - 2012-08-08 22:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
    2012-08-08 22:32 - 2012-08-08 22:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
    2012-08-08 22:28 - 2012-08-08 22:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
    2012-08-08 22:24 - 2012-08-08 22:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
    2012-08-08 22:21 - 2012-08-08 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
    2012-08-08 22:20 - 2009-07-13 21:06 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-08-08 22:17 - 2012-08-08 22:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
    2012-08-08 22:13 - 2012-08-08 22:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
    2012-08-08 22:10 - 2012-08-08 22:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
    2012-08-08 22:06 - 2012-08-08 22:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
    2012-08-08 22:02 - 2012-08-08 22:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
    2012-08-08 21:58 - 2012-08-08 21:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
    2012-08-08 21:55 - 2012-08-08 21:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
    2012-08-08 21:51 - 2012-08-08 21:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
    2012-08-08 21:47 - 2012-08-08 21:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
    2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
    2012-08-08 21:40 - 2012-08-08 21:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
    2012-08-08 21:36 - 2012-08-08 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
    2012-08-08 21:32 - 2012-08-08 21:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
    2012-08-08 21:29 - 2012-08-08 21:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
    2012-08-08 21:25 - 2012-08-08 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
    2012-08-08 21:21 - 2012-08-08 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
    2012-08-08 21:17 - 2012-08-08 21:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
    2012-08-08 21:14 - 2012-08-08 21:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
    2012-08-08 21:10 - 2012-08-08 21:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
    2012-08-08 21:06 - 2012-08-08 21:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
    2012-08-08 21:03 - 2012-08-08 21:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
    2012-08-08 20:59 - 2012-08-08 20:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
    2012-08-08 20:55 - 2012-08-08 20:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
    2012-08-08 20:52 - 2012-08-08 20:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
    2012-08-08 20:48 - 2012-08-08 20:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
    2012-08-08 20:44 - 2012-08-08 20:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
    2012-08-08 20:40 - 2012-08-08 20:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
    2012-08-08 20:37 - 2012-08-08 20:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
    2012-08-08 20:33 - 2012-08-08 20:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
    2012-08-08 20:29 - 2012-08-08 20:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
    2012-08-08 20:26 - 2012-08-08 20:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
    2012-08-08 20:22 - 2012-08-08 20:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
    2012-08-08 20:18 - 2012-08-08 20:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
    2012-08-08 20:15 - 2012-08-08 20:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
    2012-08-08 20:11 - 2012-08-08 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
    2012-08-08 20:07 - 2012-08-08 20:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
    2012-08-08 20:03 - 2012-08-08 20:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
    2012-08-08 20:00 - 2012-08-08 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
    2012-08-08 19:56 - 2012-08-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
    2012-08-08 19:52 - 2012-08-08 19:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
    2012-08-08 19:49 - 2012-08-08 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
    2012-08-08 19:45 - 2012-08-08 19:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
    2012-08-08 19:41 - 2012-08-08 19:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
    2012-08-08 19:38 - 2012-08-08 19:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
    2012-08-08 19:34 - 2012-08-08 19:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
    2012-08-08 19:30 - 2012-08-08 19:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
    2012-08-08 19:27 - 2012-08-08 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
    2012-08-08 19:23 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
    2012-08-08 18:44 - 2012-08-08 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
    2012-08-08 17:05 - 2012-08-08 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
    2012-08-08 16:26 - 2012-08-08 16:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
    2012-08-08 16:01 - 2011-03-25 18:19 - 00000402 ___AH C:\Windows\Tasks\GG Logistics Corp. 1301105924.job
    2012-08-08 15:48 - 2012-08-08 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
    2012-08-08 14:07 - 2011-02-22 10:47 - 00053828 ____A C:\Windows\PFRO.log
    2012-08-08 13:51 - 2012-08-08 13:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
    2012-08-08 13:50 - 2012-08-08 13:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
    2012-08-08 13:43 - 2012-08-08 13:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
    2012-08-08 12:50 - 2011-02-21 14:24 - 00000072 ____A C:\Users\Public\LMDebug.log
    2012-08-08 11:51 - 2012-08-08 11:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.349AEC5204EBA773
    2012-08-08 11:47 - 2012-08-08 11:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A4B1FF6622C08F08
    2012-08-08 11:44 - 2012-08-08 11:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B676A461F41E7A
    2012-08-08 11:41 - 2012-08-08 11:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7CEB3957CE766A8A
    2012-08-08 11:37 - 2012-08-08 11:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89FF8A9A97317FFE
    2012-08-08 11:37 - 2012-08-08 11:37 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\uwmbzbaf.sys
    2012-08-08 11:34 - 2012-08-08 11:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1E8C07ED33CE05A6
    2012-08-08 11:31 - 2012-08-08 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4E6A751AE46DA9A1
    2012-08-08 11:30 - 2012-08-08 11:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
    2012-08-08 11:27 - 2011-02-22 14:29 - 00002243 ____A C:\Windows\epplauncher.mif
    2012-08-08 11:23 - 2012-08-08 11:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8A911C064868CAD
    2012-08-08 11:17 - 2012-08-08 11:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B2FF333A3177CB21
    2012-08-08 11:14 - 2012-08-08 11:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.399D3E0F3FB865AB
    2012-08-08 11:11 - 2012-08-08 11:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB91755D859AF796
    2012-08-08 11:07 - 2012-08-08 11:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F93FF9FD3B95AF9
    2012-08-08 11:03 - 2012-08-08 11:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.216AEC2C1AD8CA1D
    2012-08-08 10:54 - 2011-02-21 13:48 - 05074708 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-08-08 10:45 - 2012-08-08 10:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
    2012-08-08 09:57 - 2012-08-08 09:56 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
    2012-08-08 09:32 - 2012-08-08 09:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-08 09:30 - 2012-08-08 09:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
    2012-08-08 09:22 - 2012-08-08 09:22 - 00000000 ____A C:\extensions.sqlite
    2012-08-08 09:20 - 2011-02-23 07:05 - 00000462 _RASH C:\Users\All Users\ntuser.pol
    2012-08-06 15:19 - 2012-08-06 15:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
    2012-08-02 10:32 - 2012-05-02 07:49 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-08-02 10:32 - 2011-06-29 05:53 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-08-02 06:17 - 2012-08-02 06:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
    2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
    2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
    2012-07-27 07:14 - 2012-07-27 07:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
    2012-07-24 07:32 - 2012-07-18 12:37 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
    2012-07-18 12:48 - 2012-07-18 12:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
    2012-07-18 10:31 - 2012-07-18 10:27 - 00000166 ____A C:\Windows\ODBC.INI
    2012-07-18 10:18 - 2011-02-21 14:07 - 00113664 ____A C:\Users\Rick\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 10:06 - 2012-07-18 10:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
    2012-07-18 10:03 - 2012-07-18 10:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
    2012-07-18 09:55 - 2011-03-18 08:09 - 00113664 ____A C:\Users\MaryBeth\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 09:54 - 2011-07-06 13:15 - 00113664 ____A C:\Users\frank\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 09:53 - 2009-07-13 20:49 - 00422368 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-07-18 08:06 - 2012-07-18 08:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
    2012-07-16 07:29 - 2012-01-26 08:04 - 00000036 ___AH C:\Windows\SysWOW64\f9t.dat
    2012-07-12 07:59 - 2012-07-12 07:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
    2012-07-12 07:53 - 2012-07-12 07:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
    2012-07-12 07:52 - 2012-07-12 07:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
    2012-07-11 00:02 - 2011-02-21 08:49 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-07-03 10:46 - 2012-08-08 09:32 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-26 13:12 - 2012-06-26 13:12 - 00008467 ____A C:\Users\Rick\Documents\06262012.xls
    2012-06-19 10:17 - 2012-06-19 10:17 - 00000000 ___AH C:\Users\Rick\Documents\Default.rdp
    2012-06-13 14:32 - 2012-05-25 11:59 - 00011819 ____A C:\Users\nick\Documents\Budget.xlsx
    2012-06-11 19:02 - 2012-07-11 00:01 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-06-08 21:30 - 2012-07-10 12:40 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-06-08 20:46 - 2012-07-10 12:40 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-06-08 05:39 - 2012-06-08 05:39 - 00026112 ____A C:\Users\frank\Desktop\vacation.oft
    2012-06-06 08:31 - 2012-06-06 08:31 - 00741744 ____A (RealVNC Ltd. ) C:\Users\frank\Downloads\vnc-4_1_3-x86_win32.exe
  9. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    2012-06-05 21:50 - 2012-07-10 12:40 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-06-05 21:50 - 2012-07-10 12:40 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-06-05 21:09 - 2012-07-10 12:40 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-06-05 21:09 - 2012-07-10 12:40 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-06-05 10:56 - 2012-06-05 10:55 - 01636224 ____A (Inbox.com, Inc. ) C:\Users\Rick\Downloads\MapsSetup.exe
    2012-06-02 14:19 - 2012-06-21 05:05 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 14:19 - 2012-06-21 05:05 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-02 14:19 - 2012-06-21 05:05 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 14:19 - 2012-06-21 05:05 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 14:19 - 2012-06-21 05:05 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-02 14:15 - 2012-06-21 05:05 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-02 14:15 - 2012-06-21 05:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-02 12:19 - 2012-06-21 05:05 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 12:15 - 2012-06-21 05:05 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-02 04:49 - 2012-07-11 00:05 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-02 04:17 - 2012-07-11 00:05 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-02 04:12 - 2012-07-11 00:05 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-02 04:05 - 2012-07-11 00:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-02 04:05 - 2012-07-11 00:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-02 04:04 - 2012-07-11 00:05 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-02 04:04 - 2012-07-11 00:05 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-02 04:03 - 2012-07-11 00:05 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-02 04:01 - 2012-07-11 00:05 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-02 04:00 - 2012-07-11 00:05 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-02 03:59 - 2012-07-11 00:05 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-02 03:57 - 2012-07-11 00:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-02 03:57 - 2012-07-11 00:05 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-02 03:54 - 2012-07-11 00:05 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-02 01:07 - 2012-07-11 00:05 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-02 00:43 - 2012-07-11 00:05 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-02 00:33 - 2012-07-11 00:05 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-02 00:26 - 2012-07-11 00:05 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-02 00:25 - 2012-07-11 00:05 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-02 00:25 - 2012-07-11 00:05 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-02 00:23 - 2012-07-11 00:05 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-02 00:21 - 2012-07-11 00:05 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-02 00:20 - 2012-07-11 00:05 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-02 00:19 - 2012-07-11 00:05 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-02 00:19 - 2012-07-11 00:05 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-02 00:17 - 2012-07-11 00:05 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-02 00:16 - 2012-07-11 00:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-02 00:14 - 2012-07-11 00:05 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-01 21:38 - 2012-07-10 12:40 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2012-06-01 21:38 - 2012-07-10 12:40 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-06-01 21:37 - 2012-07-10 12:40 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2012-06-01 21:27 - 2012-07-10 12:40 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-06-01 21:27 - 2012-07-10 12:40 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-06-01 20:48 - 2012-07-10 12:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2012-06-01 20:48 - 2012-07-10 12:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2012-06-01 20:47 - 2012-07-10 12:40 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2012-06-01 20:42 - 2012-07-10 12:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2012-05-31 09:25 - 2011-02-21 10:46 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
    2012-05-25 14:19 - 2012-05-25 14:19 - 00009101 ____A C:\Users\Rick\Documents\nate.xlsx
    2012-05-14 11:46 - 2012-05-14 11:46 - 00897520 ____A (Dyn, Inc.) C:\Users\frank\Downloads\DynUpSetup.exe
    ZeroAccess:
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\@
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\L
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\00000001.@
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\80000000.@
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88}\U\800000cb.@
    ZeroAccess:
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\@
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\L
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88}\U
    ========================= Known DLLs (Whitelisted) ============
    ========================= Bamital & volsnap Check ============
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
    ==================== EXE ASSOCIATION =====================
    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK
    ========================= Memory info ======================
    Percentage of memory in use: 11%
    Total physical RAM: 6135.23 MB
    Available physical RAM: 5415.39 MB
    Total Pagefile: 6133.38 MB
    Available Pagefile: 5415.73 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.91 MB
    ======================= Partitions =========================
    1 Drive c: () (Fixed) (Total:98.13 GB) (Free:23.15 GB) NTFS
    2 Drive e: (Data) (Fixed) (Total:738.97 GB) (Free:687.8 GB) NTFS
    3 Drive f: (Iomega HDD) (Fixed) (Total:1863.01 GB) (Free:1734 GB) NTFS
    4 Drive g: (USB DISK) (Removable) (Total:1.91 GB) (Free:1.91 GB) FAT
    5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    6 Drive y: () (Fixed) (Total:1 GB) (Free:0.95 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 838 GB 1024 KB
    Disk 1 Online 1863 GB 1024 KB
    Disk 2 Online 1961 MB 0 B
    Partitions of Disk 0:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1024 MB 1024 KB
    Partition 2 Primary 98 GB 1025 MB
    Partition 3 Primary 738 GB 99 GB
    ==================================================================================
    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 0 Y NTFS Partition 1024 MB Healthy
    ==================================================================================
    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 C NTFS Partition 98 GB Healthy
    ==================================================================================
    Disk: 0
    Partition 3
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 E Data NTFS Partition 738 GB Healthy
    ==================================================================================
    Partitions of Disk 1:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1863 GB 31 KB
    ==================================================================================
    Disk: 1
    Partition 1
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 F Iomega HDD NTFS Partition 1863 GB Healthy
    ==================================================================================
    Partitions of Disk 2:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1960 MB 248 KB
    ==================================================================================
    Disk: 2
    Partition 1
    Type : 06
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 G USB DISK FAT Removable 1960 MB Healthy
    ==================================================================================
    ==========================================================
    Last Boot: 2012-08-08 15:30
    ======================= End Of Log ==========================
  10. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Farbar Recovery Scan Tool Version: 08-08-2012 02
    Ran by SYSTEM at 2012-08-09 11:31:52
    Running from G:\
    ================== Search: "services.exe" ===================
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
    C:\Windows\System32\services.exe
    [2009-07-13 15:19] - [2012-08-08 19:23] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
    ====== End Of Search ======
  11. Broni

    Broni Malware Annihilator Posts: 45,203   +242

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    Next....

    Restart normally.

    Update MSE, run full scan, report on any findings.

    Then...

    Please download the below tool named Rkill (courtesy of BleepingComputer.com) to your desktop.

    There are 2 different versions. If one of them won't run then download and try to run the other one.

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    http://download.bleepingcomputer.com/grinler/beta/rkill.exe
    http://download.bleepingcomputer.com/grinler/beta/iExplore.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    If normal mode still doesn't work, run the tool from safe mode.

    When the scan is done Notepad will open with rKill log.
    Post it in your next reply.

    NOTE. rKill.txt log will also be present on your desktop.

    Attached Files:

  12. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 08-08-2012 02
    Ran by SYSTEM at 2012-08-09 11:49:28 Run:1
    Running from G:\

    ==============================================

    HKEY_LOCAL_MACHINE\System\ControlSet002\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
    C:\Windows\System32\consrv.dll not found.
    C:\Windows\System32\services.exe.6639107541643CB4 moved successfully.
    C:\Windows\System32\services.exe.349AEC5204EBA773 moved successfully.
    C:\Windows\System32\services.exe.A4B1FF6622C08F08 moved successfully.
    C:\Windows\System32\services.exe.62B676A461F41E7A moved successfully.
    C:\Windows\System32\services.exe.7CEB3957CE766A8A moved successfully.
    C:\Windows\System32\services.exe.89FF8A9A97317FFE moved successfully.
    C:\Windows\System32\Drivers\uwmbzbaf.sys moved successfully.
    C:\Windows\System32\services.exe.1E8C07ED33CE05A6 moved successfully.
    C:\Windows\System32\services.exe.4E6A751AE46DA9A1 moved successfully.
    C:\Windows\System32\services.exe.D8A911C064868CAD moved successfully.
    C:\Windows\System32\services.exe.B2FF333A3177CB21 moved successfully.
    C:\Windows\System32\services.exe.399D3E0F3FB865AB moved successfully.
    C:\Windows\System32\services.exe.FB91755D859AF796 moved successfully.
    C:\Windows\System32\services.exe.0F93FF9FD3B95AF9 moved successfully.
    C:\Windows\System32\services.exe.216AEC2C1AD8CA1D moved successfully.
    C:\Windows\Installer\{72a5a74b-8002-844d-644c-f60ea090ba88} moved successfully.
    C:\Users\frank\AppData\Local\{72a5a74b-8002-844d-644c-f60ea090ba88} moved successfully.
    C:\Windows\System32\services.exe moved successfully.
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe copied successfully to C:\Windows\System32\services.exe

    ==== End of Fixlog ====
  13. Broni

    Broni Malware Annihilator Posts: 45,203   +242

    Not everything has been removed.

    Please post new FRST log.
     
  14. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    restarting computer normally now. Will post results in a moment.
  15. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    ok. restarting to rescan with frst
  16. Broni

    Broni Malware Annihilator Posts: 45,203   +242

  17. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 02
    Ran by SYSTEM at 09-08-2012 12:02:48
    Running from F:\
    Windows Server 2008 R2 Standard (X64) OS Language: English(US)
    The current controlset is ControlSet002
    ========================== Registry (Whitelisted) =============
    HKLM\...\Run: [QLogicSaveSystemInfo] rundll32.exe qlco1006.dll,QLSaveSystemInfo [x]
    HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [2305912 2012-06-18] (Intuit Inc. All rights reserved.)
    HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
    HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
    HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
    HKU\MaryBeth\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
    HKU\Rick\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
    Tcpip\Parameters: [DhcpNameServer] 68.94.156.1
    Tcpip\..\Interfaces\{B0A35114-EF36-4060-B305-19D57C618B96}: [NameServer]208.67.222.222,208.67.220.220
    Lsa: [Notification Packages] scecli
    rassfm
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\Dyn Updater Tray Icon.lnk
    ShortcutTarget: Dyn Updater Tray Icon.lnk -> C:\Program Files (x86)\Dyn Updater\DynTray.exe (Dyn, Inc.)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk
    ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
    ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
    ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2011\QBW32.EXE (Intuit Inc.)
    Startup: C:\Users\frank\Start Menu\Programs\Startup\hs_err_pid5788.log ()
    Startup: C:\Users\frank\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\MaryBeth\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\nick\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\Rick\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    ==================== Services (Whitelisted) ======
    2 atnthost; "C:\ProgramData\webex\MyWebEx\319\atnthost.exe" [16776 2011-11-10] (WebEx Communications, Inc.)
    2 Dyn Updater; C:\Program Files (x86)\Dyn Updater\DynUpSvc.exe [95608 2011-11-15] (Dyn, Inc.)
    3 FCRegSvc; C:\Windows\System32\FCRegSvc.dll [25600 2009-07-13] (Microsoft Corporation)
    2 HP Digital Sending Software; "C:\Program Files (x86)\Hewlett-Packard\HP Digital Sending Software 4.91\Filesystems\Core\bin\XP-x86\Release\HP.Dss.App.WinService.exe" [16440 2011-03-08] (Hewlett-Packard)
    2 McAfee SiteAdvisor Service; C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [103472 2012-06-15] (McAfee, Inc.)
    2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
    2 MSSQL$HPDSS; "C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sHPDSS [29293408 2010-12-10] (Microsoft Corporation)
    2 NetPipeActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
    2 NetTcpActivator; "C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe" [116560 2009-06-10] (Microsoft Corporation)
    3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
    3 QuickBooksDB20; C:\PROGRA~2\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [678912 2009-08-18] (Intuit, Inc.)
    3 QuickBooksDB21; C:\PROGRA~2\Intuit\QUICKB~2\QBDBMgrN.exe -hvQuickBooksDB21 [679936 2010-04-27] (Intuit, Inc.)
    3 rqs; C:\Windows\System32\rqs.exe [41472 2009-07-13] (Microsoft Corporation)
    3 RSoPProv; C:\Windows\System32\RSoPProv.exe [91648 2009-07-13] (Microsoft Corporation)
    3 sacsvr; C:\Windows\System32\sacsvr.dll [14848 2009-07-13] (Microsoft Corporation)
    2 SNMP; C:\Windows\System32\snmp.exe [49664 2009-07-13] (Microsoft Corporation)
    2 SNMP; C:\Windows\SysWow64\snmp.exe [47616 2009-07-13] (Microsoft Corporation)
    2 sysdown; C:\Windows\System32\sysdown.exe [17960 2010-01-25] (Hewlett-Packard Company)
    2 TermServLicensing; C:\Windows\System32\lserver.dll [692224 2009-07-13] (Microsoft Corporation)
    2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [451072 2009-07-13] (Microsoft Corporation)
    2 W3SVC; C:\Windows\SysWow64\inetsrv\iisw3adm.dll [396288 2009-07-13] (Microsoft Corporation)
    2 WinVNC4; "C:\Program Files (x86)\RealVNC\VNC4\WinVNC4.exe" -service [439632 2008-10-15] (RealVNC Ltd.)
    2 SQLANYs_ptsrv; C:\Program Files\Profit Tools\Sybase\SQLA12\Bin64\dbsrv12.exe -hvSQLANYs_ptsrv [x]
    ========================== Drivers (Whitelisted) =============
    3 aarahci; C:\Windows\System32\Drivers\aarahci.sys [363056 2008-07-31] (Adaptec, Inc.)
    3 b06diag; C:\Windows\system32\DRIVERS\bxdiaga.sys [89128 2010-08-02] (Broadcom Corporation)
    3 bchtsw64; C:\Windows\System32\Drivers\bchtsw64.sys [90936 2009-10-23] (Broadcom Corporation)
    3 be2iscsi; C:\Windows\System32\Drivers\be2iscsi.sys [163376 2010-08-31] (ServerEngines Corporation)
    3 bfad; C:\Windows\System32\Drivers\bfad.sys [1125488 2010-04-20] (Brocade Communications Systems, Inc.)
    0 bfad_up; C:\Windows\System32\Drivers\bfad_up.sys [15472 2010-04-20] (Brocade Communications Systems, Inc.)
    3 BXOIS; C:\Windows\System32\Drivers\BXOIS.sys [524840 2010-08-02] (Broadcom Corporation)
    3 elxcna; C:\Windows\System32\Drivers\elxcna.sys [646664 2010-08-05] (Emulex)
    3 G200e; C:\Windows\System32\DRIVERS\G200em.sys [242176 2011-03-14] (Matrox Graphics Inc.)
    3 HpAHCIsr; C:\Windows\System32\Drivers\HpAHCIsr.sys [223336 2010-05-27] (Hewlett-Packard Company)
    0 HpCISSs2; C:\Windows\System32\Drivers\HpCISSs2.sys [156776 2010-02-21] (Hewlett-Packard Company)
    3 hpqmgmt; C:\Windows\System32\Drivers\hpqmgmt.sys [98856 2009-03-19] (Hewlett-Packard Company)
    3 HPUSBMSC; C:\Windows\system32\DRIVERS\HPUSBXSC.SYS [47144 2009-06-17] (Hewlett-Packard)
    3 ioatdma; C:\Windows\System32\Drivers\qd260x64.sys [35328 2009-06-10] (Intel Corporation)
    3 mlx4_bus; C:\Windows\System32\Drivers\mlx4_bus.sys [291944 2010-09-01] (Hewlett-Packard)
    3 MRxDAV; C:\Windows\SysWow64\Drivers\MRxDAV.sys [115712 2009-07-13] (Microsoft Corporation)
    3 q57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [405544 2010-08-02] (Broadcom Corporation)
    0 sacdrv; C:\Windows\System32\Drivers\sacdrv.sys [96320 2009-07-13] (Microsoft Corporation)
    3 storvsp; C:\Windows\System32\Drivers\storvsp.sys [121856 2009-07-13] (Microsoft Corporation)
    3 Vid; C:\Windows\System32\Drivers\Vid.sys [181248 2009-07-13] (Microsoft Corporation)
    3 KAPFA; \??\C:\Windows\system32\drivers\KAPFA.SYS [x]
    ========================== NetSvcs (Whitelisted) ===========
    NETSVC: sacsvr -> C:\Windows\system32\sacsvr.dll (Microsoft Corporation)
    ============ One Month Created Files and Folders ==============
    2012-08-09 06:04 - 2012-08-09 05:50 - 00607260 ____R (Swearware) C:\Users\frank\Desktop\dds.com
    2012-08-09 06:04 - 2012-08-09 05:49 - 00302592 ____A C:\Users\frank\Desktop\wy82hjq3.exe
    2012-08-09 05:58 - 2012-08-09 05:58 - 00000000 ____D C:\FRST
    2012-08-09 05:36 - 2012-08-09 05:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
    2012-08-09 05:33 - 2012-08-09 05:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
    2012-08-09 05:29 - 2012-08-09 05:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
    2012-08-09 05:25 - 2012-08-09 05:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
    2012-08-09 05:21 - 2012-08-09 05:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
    2012-08-09 05:18 - 2012-08-09 05:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
    2012-08-09 05:14 - 2012-08-09 05:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
    2012-08-09 05:10 - 2012-08-09 05:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
    2012-08-09 05:07 - 2012-08-09 05:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
    2012-08-09 05:03 - 2012-08-09 05:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
    2012-08-09 04:59 - 2012-08-09 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
    2012-08-09 04:55 - 2012-08-09 04:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
    2012-08-09 04:52 - 2012-08-09 04:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
    2012-08-09 04:48 - 2012-08-09 04:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
    2012-08-09 04:44 - 2012-08-09 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
    2012-08-09 04:40 - 2012-08-09 04:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
    2012-08-09 04:37 - 2012-08-09 04:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
    2012-08-09 04:33 - 2012-08-09 04:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
    2012-08-09 04:29 - 2012-08-09 04:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
    2012-08-09 04:26 - 2012-08-09 04:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
    2012-08-09 04:22 - 2012-08-09 04:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
    2012-08-09 04:18 - 2012-08-09 04:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
    2012-08-09 04:14 - 2012-08-09 04:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
    2012-08-09 04:11 - 2012-08-09 04:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
    2012-08-09 04:07 - 2012-08-09 04:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
    2012-08-09 04:03 - 2012-08-09 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
    2012-08-09 04:00 - 2012-08-09 04:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
    2012-08-09 03:56 - 2012-08-09 03:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
    2012-08-09 03:52 - 2012-08-09 03:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
    2012-08-09 03:48 - 2012-08-09 03:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
    2012-08-09 03:45 - 2012-08-09 03:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
    2012-08-09 03:41 - 2012-08-09 03:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
    2012-08-09 03:37 - 2012-08-09 03:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
    2012-08-09 03:33 - 2012-08-09 03:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
    2012-08-09 03:30 - 2012-08-09 03:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
    2012-08-09 03:26 - 2012-08-09 03:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
    2012-08-09 03:22 - 2012-08-09 03:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
    2012-08-09 03:19 - 2012-08-09 03:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
    2012-08-09 03:15 - 2012-08-09 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
    2012-08-09 03:11 - 2012-08-09 03:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
    2012-08-09 03:07 - 2012-08-09 03:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
    2012-08-09 03:04 - 2012-08-09 03:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
    2012-08-09 03:00 - 2012-08-09 03:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
    2012-08-09 02:56 - 2012-08-09 02:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
    2012-08-09 02:53 - 2012-08-09 02:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
    2012-08-09 02:49 - 2012-08-09 02:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
    2012-08-09 02:45 - 2012-08-09 02:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
    2012-08-09 02:41 - 2012-08-09 02:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
    2012-08-09 02:38 - 2012-08-09 02:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
    2012-08-09 02:34 - 2012-08-09 02:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
    2012-08-09 02:30 - 2012-08-09 02:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
    2012-08-09 02:26 - 2012-08-09 02:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
    2012-08-09 02:23 - 2012-08-09 02:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
    2012-08-09 02:19 - 2012-08-09 02:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
    2012-08-09 02:15 - 2012-08-09 02:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
    2012-08-09 02:12 - 2012-08-09 02:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
    2012-08-09 02:08 - 2012-08-09 02:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
    2012-08-09 02:04 - 2012-08-09 02:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
    2012-08-09 02:00 - 2012-08-09 02:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
    2012-08-09 01:57 - 2012-08-09 01:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
    2012-08-09 01:53 - 2012-08-09 01:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
    2012-08-09 01:49 - 2012-08-09 01:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
    2012-08-09 01:46 - 2012-08-09 01:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
    2012-08-09 01:42 - 2012-08-09 01:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
    2012-08-09 01:38 - 2012-08-09 01:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
    2012-08-09 01:34 - 2012-08-09 01:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
    2012-08-09 01:31 - 2012-08-09 01:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
    2012-08-09 01:27 - 2012-08-09 01:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
    2012-08-09 01:23 - 2012-08-09 01:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
    2012-08-09 01:19 - 2012-08-09 01:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
    2012-08-09 01:16 - 2012-08-09 01:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
    2012-08-09 01:12 - 2012-08-09 01:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
    2012-08-09 01:08 - 2012-08-09 01:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
    2012-08-09 01:05 - 2012-08-09 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
    2012-08-09 01:01 - 2012-08-09 01:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
    2012-08-09 00:57 - 2012-08-09 00:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
    2012-08-09 00:53 - 2012-08-09 00:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
    2012-08-09 00:50 - 2012-08-09 00:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
    2012-08-09 00:46 - 2012-08-09 00:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
    2012-08-09 00:42 - 2012-08-09 00:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
    2012-08-09 00:39 - 2012-08-09 00:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
    2012-08-09 00:35 - 2012-08-09 00:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
    2012-08-09 00:31 - 2012-08-09 00:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
    2012-08-09 00:27 - 2012-08-09 00:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
    2012-08-09 00:24 - 2012-08-09 00:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
    2012-08-09 00:20 - 2012-08-09 00:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
    2012-08-09 00:16 - 2012-08-09 00:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
    2012-08-09 00:12 - 2012-08-09 00:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
    2012-08-09 00:09 - 2012-08-09 00:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
    2012-08-09 00:05 - 2012-08-09 00:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
    2012-08-09 00:01 - 2012-08-09 00:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
    2012-08-08 23:58 - 2012-08-08 23:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
    2012-08-08 23:54 - 2012-08-08 23:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
    2012-08-08 23:50 - 2012-08-08 23:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
    2012-08-08 23:46 - 2012-08-08 23:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
    2012-08-08 23:43 - 2012-08-08 23:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
    2012-08-08 23:39 - 2012-08-08 23:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
    2012-08-08 23:35 - 2012-08-08 23:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
    2012-08-08 23:31 - 2012-08-08 23:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
    2012-08-08 23:28 - 2012-08-08 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
    2012-08-08 23:24 - 2012-08-08 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
    2012-08-08 23:20 - 2012-08-08 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
    2012-08-08 23:17 - 2012-08-08 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
    2012-08-08 23:13 - 2012-08-08 23:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
    2012-08-08 23:09 - 2012-08-08 23:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
    2012-08-08 23:05 - 2012-08-08 23:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
    2012-08-08 23:02 - 2012-08-08 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
    2012-08-08 22:58 - 2012-08-08 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
    2012-08-08 22:54 - 2012-08-08 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
    2012-08-08 22:51 - 2012-08-08 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
    2012-08-08 22:47 - 2012-08-08 22:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
    2012-08-08 22:43 - 2012-08-08 22:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
    2012-08-08 22:39 - 2012-08-08 22:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
    2012-08-08 22:36 - 2012-08-08 22:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
    2012-08-08 22:32 - 2012-08-08 22:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
    2012-08-08 22:28 - 2012-08-08 22:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
    2012-08-08 22:24 - 2012-08-08 22:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
    2012-08-08 22:21 - 2012-08-08 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
    2012-08-08 22:17 - 2012-08-08 22:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
    2012-08-08 22:13 - 2012-08-08 22:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
    2012-08-08 22:10 - 2012-08-08 22:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
    2012-08-08 22:06 - 2012-08-08 22:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
    2012-08-08 22:02 - 2012-08-08 22:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
    2012-08-08 21:58 - 2012-08-08 21:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
    2012-08-08 21:55 - 2012-08-08 21:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
    2012-08-08 21:51 - 2012-08-08 21:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
    2012-08-08 21:47 - 2012-08-08 21:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
    2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
    2012-08-08 21:40 - 2012-08-08 21:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
    2012-08-08 21:36 - 2012-08-08 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
    2012-08-08 21:32 - 2012-08-08 21:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
    2012-08-08 21:29 - 2012-08-08 21:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
    2012-08-08 21:25 - 2012-08-08 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
    2012-08-08 21:21 - 2012-08-08 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
    2012-08-08 21:17 - 2012-08-08 21:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
    2012-08-08 21:14 - 2012-08-08 21:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
    2012-08-08 21:10 - 2012-08-08 21:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
    2012-08-08 21:06 - 2012-08-08 21:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
    2012-08-08 21:03 - 2012-08-08 21:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
    2012-08-08 20:59 - 2012-08-08 20:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
    2012-08-08 20:55 - 2012-08-08 20:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
    2012-08-08 20:52 - 2012-08-08 20:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
    2012-08-08 20:48 - 2012-08-08 20:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
    2012-08-08 20:44 - 2012-08-08 20:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
    2012-08-08 20:40 - 2012-08-08 20:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
    2012-08-08 20:37 - 2012-08-08 20:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
    2012-08-08 20:33 - 2012-08-08 20:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
    2012-08-08 20:29 - 2012-08-08 20:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
    2012-08-08 20:26 - 2012-08-08 20:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
    2012-08-08 20:22 - 2012-08-08 20:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
    2012-08-08 20:18 - 2012-08-08 20:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
    2012-08-08 20:15 - 2012-08-08 20:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
    2012-08-08 20:11 - 2012-08-08 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
    2012-08-08 20:07 - 2012-08-08 20:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
    2012-08-08 20:03 - 2012-08-08 20:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
    2012-08-08 20:00 - 2012-08-08 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
    2012-08-08 19:56 - 2012-08-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
    2012-08-08 19:52 - 2012-08-08 19:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
    2012-08-08 19:49 - 2012-08-08 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
    2012-08-08 19:45 - 2012-08-08 19:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
    2012-08-08 19:41 - 2012-08-08 19:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
    2012-08-08 19:38 - 2012-08-08 19:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
    2012-08-08 19:34 - 2012-08-08 19:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
    2012-08-08 19:30 - 2012-08-08 19:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
    2012-08-08 19:27 - 2012-08-08 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
    2012-08-08 18:44 - 2012-08-08 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
    2012-08-08 17:05 - 2012-08-08 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
    2012-08-08 16:26 - 2012-08-08 16:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
    2012-08-08 15:48 - 2012-08-08 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
    2012-08-08 13:51 - 2012-08-08 13:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
    2012-08-08 13:50 - 2012-08-08 13:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
    2012-08-08 13:43 - 2012-08-08 13:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
    2012-08-08 12:02 - 2012-08-08 12:02 - 00000000 ____D C:\Users\frank\AppData\Local\Macromedia
    2012-08-08 11:30 - 2012-08-08 11:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
    2012-08-08 10:54 - 2012-08-08 10:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-08-08 10:54 - 2012-08-08 10:54 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-08-08 10:52 - 2012-08-08 10:52 - 00000000 ____D C:\Windows\System32\SPReview
    2012-08-08 10:45 - 2012-08-08 10:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
    2012-08-08 09:56 - 2012-08-08 09:57 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
    2012-08-08 09:51 - 2012-08-08 09:51 - 00000000 ____D C:\Users\Rick\AppData\Roaming\Malwarebytes
    2012-08-08 09:32 - 2012-08-08 09:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Users\frank\AppData\Roaming\Malwarebytes
    2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-08-08 09:32 - 2012-08-08 09:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-08-08 09:32 - 2012-07-03 10:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-08-08 09:30 - 2012-08-08 09:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
    2012-08-08 09:23 - 2012-08-08 09:23 - 00000000 __SHD C:\Windows\System32\%APPDATA%
    2012-08-08 09:22 - 2012-08-08 09:22 - 00000000 ____A C:\extensions.sqlite
  18. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    2012-08-06 15:19 - 2012-08-06 15:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
    2012-08-02 06:17 - 2012-08-02 06:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
    2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
    2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
    2012-07-27 08:03 - 2012-07-27 14:58 - 00000000 ____D C:\imagetmp
    2012-07-27 07:14 - 2012-07-27 07:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
    2012-07-25 12:08 - 2012-07-25 12:08 - 00000000 ____D C:\Users\frank\AppData\Roaming\SQL Anywhere 12
    2012-07-24 07:30 - 2012-07-24 07:30 - 00000000 ____D C:\Users\Rick\AppData\Local\Help
    2012-07-24 07:29 - 2012-07-24 07:29 - 00000000 ____D C:\Users\Rick\AppData\Roaming\SQL Anywhere 12
    2012-07-19 13:34 - 2012-07-19 13:34 - 00000000 ____D C:\Users\Install\AppData\Local\Adobe
    2012-07-19 12:35 - 2012-07-19 12:36 - 00000000 ____D C:\Users\Install\AppData\Roaming\Mozilla
    2012-07-19 12:35 - 2012-07-19 12:35 - 00000000 ____D C:\Users\Install\AppData\Local\Mozilla
    2012-07-18 12:48 - 2012-07-18 12:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
    2012-07-18 12:38 - 2012-07-18 12:38 - 00000000 ____D C:\Users\Install\AppData\Roaming\Help
    2012-07-18 12:38 - 2012-07-18 12:38 - 00000000 ____D C:\Users\Install\AppData\Local\Help
    2012-07-18 12:37 - 2012-07-24 07:32 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
    2012-07-18 12:36 - 2012-07-19 13:34 - 00000000 ____D C:\Users\Install\AppData\Roaming\Adobe
    2012-07-18 12:36 - 2009-08-04 09:56 - 00296960 ____A (Microsoft Corporation) C:\Windows\winhlp32.exe
    2012-07-18 12:36 - 2009-08-04 09:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftsrch.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00195072 ____A (Microsoft Corporation) C:\Windows\System32\ftsrch.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx041e.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00010240 ____A (Microsoft Corporation) C:\Windows\System32\ftlx041e.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ftlx0411.dll
    2012-07-18 12:36 - 2009-08-04 09:55 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\ftlx0411.dll
    2012-07-18 12:11 - 2012-07-18 12:11 - 00000000 ____D C:\Users\Install\AppData\Roaming\WinRAR
    2012-07-18 10:28 - 2012-07-18 12:32 - 00000000 ____D C:\Users\Public\Documents\Sybase Central 6.1.0
    2012-07-18 10:27 - 2012-07-18 10:31 - 00000166 ____A C:\Windows\ODBC.INI
    2012-07-18 10:27 - 2012-07-18 10:31 - 00000000 ____D C:\Users\Install\AppData\Roaming\SQL Anywhere 12
    2012-07-18 10:25 - 2012-07-18 12:30 - 00000000 ____D C:\Users\Install\sybase
    2012-07-18 10:25 - 2012-07-18 10:25 - 00000000 ____D C:\Users\Public\Documents\DBISQL 12.0.1
    2012-07-18 10:06 - 2012-07-18 10:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
    2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Deployment
    2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Citrix
    2012-07-18 10:06 - 2012-07-18 10:06 - 00000000 ____D C:\Users\Install\AppData\Local\Apps\2.0
    2012-07-18 10:03 - 2012-07-18 10:25 - 00000000 ____D C:\users\Install
    2012-07-18 10:03 - 2012-07-18 10:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Roaming\Apple Computer
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Local\Intuit
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000000 ____D C:\Users\Install\AppData\Local\Apple Computer
    2012-07-18 10:03 - 2011-10-11 00:01 - 00000000 ____D C:\Users\Install\AppData\Local\Microsoft Help
    2012-07-18 10:03 - 2011-02-23 08:42 - 00000000 ____D C:\Users\Install\AppData\Roaming\Macromedia
    2012-07-18 09:53 - 2012-07-18 12:12 - 00000000 ____D C:\Users\All Users\SQL Anywhere 12
    2012-07-18 09:30 - 2004-07-12 10:50 - 00155648 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JavaAccessBridge.dll
    2012-07-18 09:30 - 2004-07-12 10:50 - 00081920 ____A (Sun Microsystems©) C:\Windows\SysWOW64\WindowsAccessBridge.dll
    2012-07-18 09:30 - 2004-07-12 10:50 - 00032768 ____A (Sun Microsystems©) C:\Windows\SysWOW64\JAWTAccessBridge.dll
    2012-07-18 09:29 - 2012-07-18 09:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2012-07-18 08:06 - 2012-07-18 08:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
    2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Deployment
    2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Citrix
    2012-07-18 08:06 - 2012-07-18 08:06 - 00000000 ____D C:\Users\frank\AppData\Local\Apps\2.0
    2012-07-12 07:59 - 2012-07-12 07:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
    2012-07-12 07:53 - 2012-07-12 07:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
    2012-07-12 07:52 - 2012-07-12 07:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
    2012-07-11 00:05 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-07-11 00:05 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-07-11 00:05 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-07-11 00:05 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-07-11 00:05 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-07-11 00:05 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-07-11 00:05 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-07-11 00:05 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-07-11 00:05 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-07-11 00:05 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-07-11 00:05 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-07-11 00:05 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-07-11 00:05 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-07-11 00:05 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-07-11 00:05 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-07-11 00:05 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-07-11 00:05 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-07-11 00:05 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-07-11 00:05 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-07-11 00:05 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-07-11 00:05 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-07-11 00:05 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-07-11 00:05 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-07-11 00:05 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-07-11 00:05 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-07-11 00:05 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-07-11 00:05 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-07-11 00:05 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-07-11 00:01 - 2012-06-11 19:02 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-07-10 12:40 - 2012-06-08 21:30 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-07-10 12:40 - 2012-06-08 20:46 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-07-10 12:40 - 2012-06-05 21:50 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-07-10 12:40 - 2012-06-05 21:50 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-07-10 12:40 - 2012-06-05 21:09 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-07-10 12:40 - 2012-06-05 21:09 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-07-10 12:40 - 2012-06-01 21:38 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2012-07-10 12:40 - 2012-06-01 21:38 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-07-10 12:40 - 2012-06-01 21:37 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2012-07-10 12:40 - 2012-06-01 21:27 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-07-10 12:40 - 2012-06-01 21:27 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-07-10 12:40 - 2012-06-01 20:48 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2012-07-10 12:40 - 2012-06-01 20:48 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2012-07-10 12:40 - 2012-06-01 20:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2012-07-10 12:40 - 2012-06-01 20:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    ============ 3 Months Modified Files ========================
    2012-08-09 09:00 - 2009-07-13 20:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-08-09 09:00 - 2009-07-13 20:49 - 00014048 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-08-09 08:59 - 2011-02-18 10:42 - 01551283 ____A C:\Windows\WindowsUpdate.log
    2012-08-09 08:59 - 2009-09-22 11:32 - 00851644 ____A C:\Windows\System32\perfh00A.dat
    2012-08-09 08:59 - 2009-09-22 11:32 - 00195538 ____A C:\Windows\System32\perfc00A.dat
    2012-08-09 08:59 - 2009-09-22 11:18 - 00845594 ____A C:\Windows\System32\perfh010.dat
    2012-08-09 08:59 - 2009-09-22 11:18 - 00182856 ____A C:\Windows\System32\perfc010.dat
    2012-08-09 08:59 - 2009-09-22 11:06 - 00808956 ____A C:\Windows\System32\perfh007.dat
    2012-08-09 08:59 - 2009-09-22 11:06 - 00183696 ____A C:\Windows\System32\perfc007.dat
    2012-08-09 08:59 - 2009-09-22 10:53 - 00856886 ____A C:\Windows\System32\perfh00C.dat
    2012-08-09 08:59 - 2009-09-22 10:53 - 00187520 ____A C:\Windows\System32\perfc00C.dat
    2012-08-09 08:59 - 2009-07-13 21:10 - 05006346 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-08-09 08:53 - 2009-07-13 21:06 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-08-09 08:53 - 2009-07-13 20:56 - 00039656 ____A C:\Windows\setupact.log
    2012-08-09 07:32 - 2012-05-02 07:49 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-08-09 05:50 - 2012-08-09 06:04 - 00607260 ____R (Swearware) C:\Users\frank\Desktop\dds.com
    2012-08-09 05:49 - 2012-08-09 06:04 - 00302592 ____A C:\Users\frank\Desktop\wy82hjq3.exe
    2012-08-09 05:36 - 2012-08-09 05:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EB9A1010890AFFEE
    2012-08-09 05:33 - 2012-08-09 05:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.72E5362A0BD14F2F
    2012-08-09 05:29 - 2012-08-09 05:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.44E5779334A7D83E
    2012-08-09 05:25 - 2012-08-09 05:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C216B261A64DDCBC
    2012-08-09 05:21 - 2012-08-09 05:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D5DCF895404AEBB8
    2012-08-09 05:18 - 2012-08-09 05:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.69C9D721940BD4BF
    2012-08-09 05:14 - 2012-08-09 05:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D82F043A8FEC7CEE
    2012-08-09 05:10 - 2012-08-09 05:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D8F4E0834D8EFEBC
    2012-08-09 05:07 - 2012-08-09 05:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3D38393B1BA7246B
    2012-08-09 05:03 - 2012-08-09 05:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8071CB9A75191EEB
    2012-08-09 04:59 - 2012-08-09 04:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C3011F7E4A785767
    2012-08-09 04:55 - 2012-08-09 04:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5EC0E1CF8093BB18
    2012-08-09 04:52 - 2012-08-09 04:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9555716B5A2BBFD
    2012-08-09 04:48 - 2012-08-09 04:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ECBEDE6FCB51C87C
    2012-08-09 04:44 - 2012-08-09 04:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBCDD9B8CFE3F464
    2012-08-09 04:40 - 2012-08-09 04:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5A9CE81858F92C0D
    2012-08-09 04:37 - 2012-08-09 04:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F0698789F4ECFC9
    2012-08-09 04:33 - 2012-08-09 04:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.18B9A90766DC53F5
    2012-08-09 04:29 - 2012-08-09 04:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F76E0F11B73876B
    2012-08-09 04:26 - 2012-08-09 04:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D0844593D2681CF5
    2012-08-09 04:22 - 2012-08-09 04:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B81A047C03CDC542
    2012-08-09 04:18 - 2012-08-09 04:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CEEC5D6C4268E8BC
    2012-08-09 04:14 - 2012-08-09 04:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CFD1A50C9191ED21
    2012-08-09 04:11 - 2012-08-09 04:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.290B7DA9EDF03385
    2012-08-09 04:07 - 2012-08-09 04:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3EC804FF5F0FCB85
    2012-08-09 04:03 - 2012-08-09 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6BAA36DBB942413A
    2012-08-09 04:00 - 2012-08-09 04:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC
    2012-08-09 03:56 - 2012-08-09 03:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.880FD5B52EDAAB2C
    2012-08-09 03:52 - 2012-08-09 03:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D2EB03BE6D52EB3
    2012-08-09 03:48 - 2012-08-09 03:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E65AE579A6C2D61
    2012-08-09 03:45 - 2012-08-09 03:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AEDCC9B8D34C361D
    2012-08-09 03:41 - 2012-08-09 03:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9C2DC445AF4CAA2
    2012-08-09 03:37 - 2012-08-09 03:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C621C95988BA64A
    2012-08-09 03:33 - 2012-08-09 03:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DFEBD18377C0AC
    2012-08-09 03:30 - 2012-08-09 03:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4CBD7315F69B608B
    2012-08-09 03:26 - 2012-08-09 03:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.940A3B643315666D
    2012-08-09 03:22 - 2012-08-09 03:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.14E93EEEDAAABB17
    2012-08-09 03:19 - 2012-08-09 03:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C924DDED6F0FC518
    2012-08-09 03:15 - 2012-08-09 03:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2343B3FE8036872A
    2012-08-09 03:11 - 2012-08-09 03:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11E81B2BECDB7BC1
    2012-08-09 03:07 - 2012-08-09 03:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6B261B290D7888CA
    2012-08-09 03:04 - 2012-08-09 03:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9692C5AFDCD11D02
    2012-08-09 03:00 - 2012-08-09 03:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.77291BE6F1228A36
    2012-08-09 02:56 - 2012-08-09 02:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9E993F14328744BC
    2012-08-09 02:53 - 2012-08-09 02:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7B865B3BC9419F04
    2012-08-09 02:49 - 2012-08-09 02:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.30CAEB12CE87E691
    2012-08-09 02:45 - 2012-08-09 02:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.049F9AF61F17D75C
    2012-08-09 02:41 - 2012-08-09 02:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.09123E38065282F7
    2012-08-09 02:38 - 2012-08-09 02:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.876360F33C92B2C5
    2012-08-09 02:34 - 2012-08-09 02:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7C527C7A8B6F50B
    2012-08-09 02:30 - 2012-08-09 02:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1D21B448BF10CBA
    2012-08-09 02:26 - 2012-08-09 02:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F8E9B38B76A8B0D
    2012-08-09 02:23 - 2012-08-09 02:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.129B404282E5AE3C
    2012-08-09 02:19 - 2012-08-09 02:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F2B916F13308CA13
    2012-08-09 02:15 - 2012-08-09 02:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4BD5DEF9F7587255
    2012-08-09 02:12 - 2012-08-09 02:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.94DDAA4175F314B1
    2012-08-09 02:08 - 2012-08-09 02:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC302FB3D17C0642
    2012-08-09 02:04 - 2012-08-09 02:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DE76FBB01FA45BD3
    2012-08-09 02:00 - 2012-08-09 02:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4A87AC973177E679
    2012-08-09 01:57 - 2012-08-09 01:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCF899EB194B3AD0
    2012-08-09 01:53 - 2012-08-09 01:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1369A8411769F4CD
    2012-08-09 01:49 - 2012-08-09 01:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D86BF51DC13B8230
    2012-08-09 01:46 - 2012-08-09 01:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B55066EB6B9EEE95
    2012-08-09 01:42 - 2012-08-09 01:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87F78F64AC9E978C
    2012-08-09 01:38 - 2012-08-09 01:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.46CE1BF2FE39E10B
    2012-08-09 01:34 - 2012-08-09 01:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.51E9ECFC90321BD5
    2012-08-09 01:31 - 2012-08-09 01:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC3CA10830B61336
    2012-08-09 01:27 - 2012-08-09 01:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D35B473D6428979
    2012-08-09 01:23 - 2012-08-09 01:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A993C76224D14F85
    2012-08-09 01:19 - 2012-08-09 01:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B530A5047C73A16A
    2012-08-09 01:16 - 2012-08-09 01:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63EAEA5537A808B5
    2012-08-09 01:12 - 2012-08-09 01:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD3081176DD59A69
    2012-08-09 01:08 - 2012-08-09 01:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F73A1B4CE90B2A7D
    2012-08-09 01:05 - 2012-08-09 01:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C1A100BAFEECC053
    2012-08-09 01:01 - 2012-08-09 01:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.711EEA03DCC5BF9F
    2012-08-09 00:57 - 2012-08-09 00:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F091C807FAD0E981
    2012-08-09 00:53 - 2012-08-09 00:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9698E79E01BEE1D6
    2012-08-09 00:50 - 2012-08-09 00:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FD0E73D6E48DF2DB
    2012-08-09 00:46 - 2012-08-09 00:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.373F4D971A931FA2
    2012-08-09 00:42 - 2012-08-09 00:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FC02870EA8A73758
    2012-08-09 00:39 - 2012-08-09 00:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0DDA2AE7A9DE7737
    2012-08-09 00:35 - 2012-08-09 00:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33C96B1604B8E4FB
    2012-08-09 00:31 - 2012-08-09 00:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.24D2F2CA5DC1878C
    2012-08-09 00:27 - 2012-08-09 00:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3
    2012-08-09 00:24 - 2012-08-09 00:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BBB1583714D0E53F
    2012-08-09 00:20 - 2012-08-09 00:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0474DDC0F56A6C98
    2012-08-09 00:16 - 2012-08-09 00:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3F747776EEE440CA
    2012-08-09 00:12 - 2012-08-09 00:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47A1588EEADC79D9
    2012-08-09 00:09 - 2012-08-09 00:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE
    2012-08-09 00:05 - 2012-08-09 00:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.155A2A2B10C655C5
    2012-08-09 00:01 - 2012-08-09 00:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0879AB483D626932
    2012-08-08 23:58 - 2012-08-08 23:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.10268C8E76D31502
    2012-08-08 23:54 - 2012-08-08 23:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.834B2828FA183CA3
    2012-08-08 23:50 - 2012-08-08 23:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2142AABD9A6E03D4
    2012-08-08 23:46 - 2012-08-08 23:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7552E461AB63A6C1
    2012-08-08 23:43 - 2012-08-08 23:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B6638D582CB5239D
    2012-08-08 23:39 - 2012-08-08 23:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0397A3428D3804D4
    2012-08-08 23:35 - 2012-08-08 23:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E51DC69051BEA1FC
    2012-08-08 23:31 - 2012-08-08 23:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3069EC68AB2E7B57
    2012-08-08 23:28 - 2012-08-08 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.541103CDEEBBC7B1
    2012-08-08 23:24 - 2012-08-08 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.00546D2F107C88F6
    2012-08-08 23:20 - 2012-08-08 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.59B092850D586002
    2012-08-08 23:17 - 2012-08-08 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.88EAA525011D6CD7
    2012-08-08 23:13 - 2012-08-08 23:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AFE3CD7BE4C6B273
    2012-08-08 23:09 - 2012-08-08 23:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9AE197152C0B6DBE
    2012-08-08 23:05 - 2012-08-08 23:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7D3C9F9D497408C2
    2012-08-08 23:02 - 2012-08-08 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8169ABF06B61C7DC
    2012-08-08 22:58 - 2012-08-08 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4FA4C6DEC7FA457
    2012-08-08 22:54 - 2012-08-08 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F0206D8736558AF0
    2012-08-08 22:51 - 2012-08-08 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FF294788B62887CD
    2012-08-08 22:47 - 2012-08-08 22:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7F729FF837B7E1
    2012-08-08 22:43 - 2012-08-08 22:43 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0A702750A1684A1D
    2012-08-08 22:39 - 2012-08-08 22:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D82152450C119DA
    2012-08-08 22:36 - 2012-08-08 22:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41F7724CB3DB06BB
    2012-08-08 22:32 - 2012-08-08 22:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB932C6E4E8EE438
    2012-08-08 22:28 - 2012-08-08 22:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF6939662C08E42F
    2012-08-08 22:24 - 2012-08-08 22:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.84D746227F91ED91
    2012-08-08 22:21 - 2012-08-08 22:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FFAAB1B4E5F9F605
    2012-08-08 22:20 - 2009-07-13 21:06 - 00032618 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-08-08 22:17 - 2012-08-08 22:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.92D0F8BF84305E11
    2012-08-08 22:13 - 2012-08-08 22:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AB8B992F0731098
    2012-08-08 22:10 - 2012-08-08 22:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AD6D90A9500B7931
    2012-08-08 22:06 - 2012-08-08 22:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1850E1E5AA25B05E
    2012-08-08 22:02 - 2012-08-08 22:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.95653D6E21D04D7A
    2012-08-08 21:58 - 2012-08-08 21:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8157058AD18E7DAD
    2012-08-08 21:55 - 2012-08-08 21:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5D50F07DA5C2D33
    2012-08-08 21:51 - 2012-08-08 21:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F7E07AB1A607A4F6
    2012-08-08 21:47 - 2012-08-08 21:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDF585E84251D56D
    2012-08-08 21:44 - 2012-08-08 21:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1C8B1AFF015DD2B2
    2012-08-08 21:40 - 2012-08-08 21:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4D95452728FAECF1
    2012-08-08 21:36 - 2012-08-08 21:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E487623797CA617C
    2012-08-08 21:32 - 2012-08-08 21:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CB438F6E0B2FA2B3
    2012-08-08 21:29 - 2012-08-08 21:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.36C674D1EB924FBB
    2012-08-08 21:25 - 2012-08-08 21:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD82D5E5B3B3F72E
    2012-08-08 21:21 - 2012-08-08 21:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.67D4F2D8521EED50
    2012-08-08 21:17 - 2012-08-08 21:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B33C0521EDC3A884
    2012-08-08 21:14 - 2012-08-08 21:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFB723BACF41163
    2012-08-08 21:10 - 2012-08-08 21:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E391B3C556D5F42D
    2012-08-08 21:06 - 2012-08-08 21:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A7FE3577CD164308
    2012-08-08 21:03 - 2012-08-08 21:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8A5C086D4CB27A94
    2012-08-08 20:59 - 2012-08-08 20:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BFB4D489EC266F59
    2012-08-08 20:55 - 2012-08-08 20:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E141351D843D5ADB
    2012-08-08 20:52 - 2012-08-08 20:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A851C2C7D67203C9
    2012-08-08 20:48 - 2012-08-08 20:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A1AC6CA500F0B944
    2012-08-08 20:44 - 2012-08-08 20:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.877CC8F7C0654369
    2012-08-08 20:40 - 2012-08-08 20:40 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2ABC066A6CB23ED5
    2012-08-08 20:37 - 2012-08-08 20:37 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E9FA810BD61820A5
    2012-08-08 20:33 - 2012-08-08 20:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D87677A490E90540
    2012-08-08 20:29 - 2012-08-08 20:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15B43CCED18E1D14
    2012-08-08 20:26 - 2012-08-08 20:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FEB8266FBFAE7339
    2012-08-08 20:22 - 2012-08-08 20:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C2D9099DA5002738
    2012-08-08 20:18 - 2012-08-08 20:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2BACC871F522C30B
    2012-08-08 20:15 - 2012-08-08 20:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2
    2012-08-08 20:11 - 2012-08-08 20:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FB744F045A9AE235
    2012-08-08 20:07 - 2012-08-08 20:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8AFD3E376FAC7CB2
    2012-08-08 20:03 - 2012-08-08 20:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6235CC19A79237D3
    2012-08-08 20:00 - 2012-08-08 20:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0E444BD854315046
    2012-08-08 19:56 - 2012-08-08 19:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA421768F2A74BA3
    2012-08-08 19:52 - 2012-08-08 19:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A83BD7A5E23A315A
    2012-08-08 19:49 - 2012-08-08 19:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C641E19DDEE2810
    2012-08-08 19:45 - 2012-08-08 19:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BD1E6FA221046C63
    2012-08-08 19:41 - 2012-08-08 19:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E190B06FB01BE3D0
    2012-08-08 19:38 - 2012-08-08 19:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9160897B82EC0185
    2012-08-08 19:34 - 2012-08-08 19:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6D46D985EE0FDAD1
    2012-08-08 19:30 - 2012-08-08 19:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1457FD0B1E7100F5
    2012-08-08 19:27 - 2012-08-08 19:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F1798DADE265F227
    2012-08-08 18:44 - 2012-08-08 18:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C6A2AF826E71567D
    2012-08-08 17:05 - 2012-08-08 17:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E6079324380AA7FD
    2012-08-08 16:26 - 2012-08-08 16:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7DAC7B56D306001E
    2012-08-08 16:01 - 2011-03-25 18:19 - 00000402 ___AH C:\Windows\Tasks\GG Logistics Corp. 1301105924.job
    2012-08-08 15:48 - 2012-08-08 15:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74F55DFF4C3A075E
    2012-08-08 14:07 - 2011-02-22 10:47 - 00053828 ____A C:\Windows\PFRO.log
    2012-08-08 13:51 - 2012-08-08 13:51 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\frank\Desktop\tdsskiller.exe
    2012-08-08 13:50 - 2012-08-08 13:50 - 04727110 ____A (Swearware) C:\Users\frank\Desktop\ComboFix.exe
    2012-08-08 13:43 - 2012-08-08 13:43 - 00881494 ____A C:\Users\frank\Desktop\SecurityCheck.exe
    2012-08-08 12:50 - 2011-02-21 14:24 - 00000072 ____A C:\Users\Public\LMDebug.log
    2012-08-08 11:30 - 2012-08-08 11:30 - 00017668 ____A C:\Users\frank\TsAllUsr.Dat
    2012-08-08 11:27 - 2011-02-22 14:29 - 00002243 ____A C:\Windows\epplauncher.mif
    2012-08-08 10:54 - 2011-02-21 13:48 - 05074708 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-08-08 10:45 - 2012-08-08 10:45 - 00000017 ____A C:\Users\Rick\AppData\Local\resmon.resmoncfg
    2012-08-08 09:57 - 2012-08-08 09:56 - 12621696 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\mseinstall.exe
    2012-08-08 09:32 - 2012-08-08 09:32 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-08 09:30 - 2012-08-08 09:30 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\frank\Downloads\mbam-setup-1.62.0.1300.exe
    2012-08-08 09:22 - 2012-08-08 09:22 - 00000000 ____A C:\extensions.sqlite
    2012-08-08 09:20 - 2011-02-23 07:05 - 00000462 _RASH C:\Users\All Users\ntuser.pol
    2012-08-06 15:19 - 2012-08-06 15:19 - 00007607 ____A C:\Users\frank\AppData\Local\Resmon.ResmonCfg
    2012-08-02 10:32 - 2012-05-02 07:49 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-08-02 10:32 - 2011-06-29 05:53 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-08-02 06:17 - 2012-08-02 06:17 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (3).lnk
    2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut.lnk
    2012-08-02 06:16 - 2012-08-02 06:16 - 00001041 ____A C:\Users\frank\Desktop\Documents - Shortcut (2).lnk
    2012-07-27 07:14 - 2012-07-27 07:14 - 00034770 ____A C:\Users\frank\Desktop\custlist.TXT
    2012-07-24 07:32 - 2012-07-18 12:37 - 00000755 ____A C:\Users\Install\Desktop\Profit Tools Help.lnk
    2012-07-18 12:48 - 2012-07-18 12:48 - 00001349 ____A C:\Users\Install\Desktop\Profit Tools.lnk
    2012-07-18 10:31 - 2012-07-18 10:27 - 00000166 ____A C:\Windows\ODBC.INI
    2012-07-18 10:18 - 2011-02-21 14:07 - 00113664 ____A C:\Users\Rick\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 10:06 - 2012-07-18 10:06 - 00103272 ____A C:\Users\Install\GoToAssistDownloadHelper.exe
    2012-07-18 10:03 - 2012-07-18 10:03 - 00113664 ____A C:\Users\Install\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 10:03 - 2012-07-18 10:03 - 00000020 __ASH C:\Users\Install\ntuser.ini
    2012-07-18 09:55 - 2011-03-18 08:09 - 00113664 ____A C:\Users\MaryBeth\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 09:54 - 2011-07-06 13:15 - 00113664 ____A C:\Users\frank\AppData\Local\GDIPFONTCACHEV1.DAT
    2012-07-18 09:53 - 2009-07-13 20:49 - 00422368 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-07-18 08:06 - 2012-07-18 08:06 - 00103272 ____A C:\Users\frank\GoToAssistDownloadHelper.exe
    2012-07-16 07:29 - 2012-01-26 08:04 - 00000036 ___AH C:\Windows\SysWOW64\f9t.dat
    2012-07-12 07:59 - 2012-07-12 07:59 - 00318904 ____A (Microsoft Corporation) C:\Users\frank\Downloads\wmpfirefoxplugin.exe
    2012-07-12 07:53 - 2012-07-12 07:53 - 00318904 ____A (Microsoft Corporation) C:\Users\Rick\Downloads\wmpfirefoxplugin(1).exe
    2012-07-12 07:52 - 2012-07-12 07:52 - 00000195 ____A C:\Users\Rick\Downloads\wmpfirefoxplugin.exe
    2012-07-11 00:02 - 2011-02-21 08:49 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-07-03 10:46 - 2012-08-08 09:32 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-26 13:12 - 2012-06-26 13:12 - 00008467 ____A C:\Users\Rick\Documents\06262012.xls
    2012-06-19 10:17 - 2012-06-19 10:17 - 00000000 ___AH C:\Users\Rick\Documents\Default.rdp
    2012-06-13 14:32 - 2012-05-25 11:59 - 00011819 ____A C:\Users\nick\Documents\Budget.xlsx
    2012-06-11 19:02 - 2012-07-11 00:01 - 03147264 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-06-08 21:30 - 2012-07-10 12:40 - 14165504 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
    2012-06-08 20:46 - 2012-07-10 12:40 - 12868608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2012-06-08 05:39 - 2012-06-08 05:39 - 00026112 ____A C:\Users\frank\Desktop\vacation.oft
    2012-06-06 08:31 - 2012-06-06 08:31 - 00741744 ____A (RealVNC Ltd. ) C:\Users\frank\Downloads\vnc-4_1_3-x86_win32.exe
    2012-06-05 21:50 - 2012-07-10 12:40 - 02003968 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
    2012-06-05 21:50 - 2012-07-10 12:40 - 01880064 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
    2012-06-05 21:09 - 2012-07-10 12:40 - 01389568 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2012-06-05 21:09 - 2012-07-10 12:40 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2012-06-05 10:56 - 2012-06-05 10:55 - 01636224 ____A (Inbox.com, Inc. ) C:\Users\Rick\Downloads\MapsSetup.exe
    2012-06-02 14:19 - 2012-06-21 05:05 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 14:19 - 2012-06-21 05:05 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-02 14:19 - 2012-06-21 05:05 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 14:19 - 2012-06-21 05:05 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 14:19 - 2012-06-21 05:05 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-02 14:15 - 2012-06-21 05:05 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-02 14:15 - 2012-06-21 05:05 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-02 12:19 - 2012-06-21 05:05 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 12:15 - 2012-06-21 05:05 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-02 04:49 - 2012-07-11 00:05 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-02 04:17 - 2012-07-11 00:05 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-02 04:12 - 2012-07-11 00:05 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-02 04:05 - 2012-07-11 00:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-02 04:05 - 2012-07-11 00:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-02 04:04 - 2012-07-11 00:05 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-02 04:04 - 2012-07-11 00:05 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-02 04:03 - 2012-07-11 00:05 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-02 04:01 - 2012-07-11 00:05 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-02 04:00 - 2012-07-11 00:05 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-02 03:59 - 2012-07-11 00:05 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-02 03:57 - 2012-07-11 00:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-02 03:57 - 2012-07-11 00:05 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-02 03:54 - 2012-07-11 00:05 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-02 01:07 - 2012-07-11 00:05 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-02 00:43 - 2012-07-11 00:05 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-02 00:33 - 2012-07-11 00:05 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-02 00:26 - 2012-07-11 00:05 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-02 00:25 - 2012-07-11 00:05 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-02 00:25 - 2012-07-11 00:05 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-02 00:23 - 2012-07-11 00:05 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-02 00:21 - 2012-07-11 00:05 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-02 00:20 - 2012-07-11 00:05 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-02 00:19 - 2012-07-11 00:05 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-02 00:19 - 2012-07-11 00:05 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-02 00:17 - 2012-07-11 00:05 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-02 00:16 - 2012-07-11 00:05 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-02 00:14 - 2012-07-11 00:05 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-01 21:38 - 2012-07-10 12:40 - 00152432 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
    2012-06-01 21:38 - 2012-07-10 12:40 - 00095088 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
    2012-06-01 21:37 - 2012-07-10 12:40 - 00459216 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
    2012-06-01 21:27 - 2012-07-10 12:40 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
    2012-06-01 21:27 - 2012-07-10 12:40 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
    2012-06-01 20:48 - 2012-07-10 12:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2012-06-01 20:48 - 2012-07-10 12:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2012-06-01 20:47 - 2012-07-10 12:40 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2012-06-01 20:42 - 2012-07-10 12:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2012-05-31 09:25 - 2011-02-21 10:46 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
    2012-05-25 14:19 - 2012-05-25 14:19 - 00009101 ____A C:\Users\Rick\Documents\nate.xlsx
    2012-05-14 11:46 - 2012-05-14 11:46 - 00897520 ____A (Dyn, Inc.) C:\Users\frank\Downloads\DynUpSetup.exe
    ========================= Known DLLs (Whitelisted) ============
    ========================= Bamital & volsnap Check ============
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
    ==================== EXE ASSOCIATION =====================
    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK
    ========================= Memory info ======================
    Percentage of memory in use: 11%
    Total physical RAM: 6135.23 MB
    Available physical RAM: 5413.29 MB
    Total Pagefile: 6133.38 MB
    Available Pagefile: 5415 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.91 MB
    ======================= Partitions =========================
    1 Drive c: () (Fixed) (Total:98.13 GB) (Free:23.01 GB) NTFS
    2 Drive e: (Data) (Fixed) (Total:738.97 GB) (Free:687.8 GB) NTFS
    3 Drive f: (USB DISK) (Removable) (Total:1.91 GB) (Free:1.91 GB) FAT
    4 Drive g: (Iomega HDD) (Fixed) (Total:1863.01 GB) (Free:1734 GB) NTFS
    5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    6 Drive y: () (Fixed) (Total:1 GB) (Free:0.95 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 838 GB 1024 KB
    Disk 1 Online 1961 MB 0 B
    Disk 2 Online 1863 GB 1024 KB
    Partitions of Disk 0:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1024 MB 1024 KB
    Partition 2 Primary 98 GB 1025 MB
    Partition 3 Primary 738 GB 99 GB
    ==================================================================================
    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 0 Y NTFS Partition 1024 MB Healthy
    ==================================================================================
    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 C NTFS Partition 98 GB Healthy
    ==================================================================================
    Disk: 0
    Partition 3
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 E Data NTFS Partition 738 GB Healthy
    ==================================================================================
    Partitions of Disk 1:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1960 MB 248 KB
    ==================================================================================
    Disk: 1
    Partition 1
    Type : 06
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 F USB DISK FAT Removable 1960 MB Healthy
    ==================================================================================
    Partitions of Disk 2:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1863 GB 31 KB
    ==================================================================================
    Disk: 2
    Partition 1
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 G Iomega HDD NTFS Partition 1863 GB Healthy
    ==================================================================================
    ==========================================================
    Last Boot: 2012-08-08 15:30
    ======================= End Of Log ==========================
  19. Broni

    Broni Malware Annihilator Posts: 45,203   +242

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    Then continue with my reply #11.

    Attached Files:

  20. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Running back and forth between the server terminal and my laptop to send this info, but when I did try and restart and run a scan, I was getting an error that the MSE could not connect to the update server, even though there was an active network connecction (which has since been disconnected again). Haven't seen if the firewall is still blocked, or windows update, since both of those were giving problems as well.
  21. Broni

    Broni Malware Annihilator Posts: 45,203   +242

    You should be able to operate normally by now.

    MSE could have got corrupted.
    If it doesn't work properly reinstall it.
  22. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Ok. posting fixlog first. I'll wait for your reply then try to restart, just to make sure that I don't have to re-run FRST.
  23. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 08-08-2012 02
    Ran by SYSTEM at 2012-08-09 12:17:01 Run:2
    Running from F:\
    ==============================================
    C:\Windows\System32\services.exe.EB9A1010890AFFEE moved successfully.
    C:\Windows\System32\services.exe.72E5362A0BD14F2F moved successfully.
    C:\Windows\System32\services.exe.44E5779334A7D83E moved successfully.
    C:\Windows\System32\services.exe.C216B261A64DDCBC moved successfully.
    C:\Windows\System32\services.exe.D5DCF895404AEBB8 moved successfully.
    C:\Windows\System32\services.exe.69C9D721940BD4BF moved successfully.
    C:\Windows\System32\services.exe.D82F043A8FEC7CEE moved successfully.
    C:\Windows\System32\services.exe.D8F4E0834D8EFEBC moved successfully.
    C:\Windows\System32\services.exe.3D38393B1BA7246B moved successfully.
    C:\Windows\System32\services.exe.8071CB9A75191EEB moved successfully.
    C:\Windows\System32\services.exe.C3011F7E4A785767 moved successfully.
    C:\Windows\System32\services.exe.5EC0E1CF8093BB18 moved successfully.
    C:\Windows\System32\services.exe.A9555716B5A2BBFD moved successfully.
    C:\Windows\System32\services.exe.ECBEDE6FCB51C87C moved successfully.
    C:\Windows\System32\services.exe.EBCDD9B8CFE3F464 moved successfully.
    C:\Windows\System32\services.exe.5A9CE81858F92C0D moved successfully.
    C:\Windows\System32\services.exe.3F0698789F4ECFC9 moved successfully.
    C:\Windows\System32\services.exe.18B9A90766DC53F5 moved successfully.
    C:\Windows\System32\services.exe.3F76E0F11B73876B moved successfully.
    C:\Windows\System32\services.exe.D0844593D2681CF5 moved successfully.
    C:\Windows\System32\services.exe.B81A047C03CDC542 moved successfully.
    C:\Windows\System32\services.exe.CEEC5D6C4268E8BC moved successfully.
    C:\Windows\System32\services.exe.CFD1A50C9191ED21 moved successfully.
    C:\Windows\System32\services.exe.290B7DA9EDF03385 moved successfully.
    C:\Windows\System32\services.exe.3EC804FF5F0FCB85 moved successfully.
    C:\Windows\System32\services.exe.6BAA36DBB942413A moved successfully.
    C:\Windows\System32\services.exe.51DEDEC7ECAFFEFC moved successfully.
    C:\Windows\System32\services.exe.880FD5B52EDAAB2C moved successfully.
    C:\Windows\System32\services.exe.4D2EB03BE6D52EB3 moved successfully.
    C:\Windows\System32\services.exe.6E65AE579A6C2D61 moved successfully.
    C:\Windows\System32\services.exe.AEDCC9B8D34C361D moved successfully.
    C:\Windows\System32\services.exe.A9C2DC445AF4CAA2 moved successfully.
    C:\Windows\System32\services.exe.5C621C95988BA64A moved successfully.
    C:\Windows\System32\services.exe.C9DFEBD18377C0AC moved successfully.
    C:\Windows\System32\services.exe.4CBD7315F69B608B moved successfully.
    C:\Windows\System32\services.exe.940A3B643315666D moved successfully.
    C:\Windows\System32\services.exe.14E93EEEDAAABB17 moved successfully.
    C:\Windows\System32\services.exe.C924DDED6F0FC518 moved successfully.
    C:\Windows\System32\services.exe.2343B3FE8036872A moved successfully.
    C:\Windows\System32\services.exe.11E81B2BECDB7BC1 moved successfully.
    C:\Windows\System32\services.exe.6B261B290D7888CA moved successfully.
    C:\Windows\System32\services.exe.9692C5AFDCD11D02 moved successfully.
    C:\Windows\System32\services.exe.77291BE6F1228A36 moved successfully.
    C:\Windows\System32\services.exe.9E993F14328744BC moved successfully.
    C:\Windows\System32\services.exe.7B865B3BC9419F04 moved successfully.
    C:\Windows\System32\services.exe.30CAEB12CE87E691 moved successfully.
    C:\Windows\System32\services.exe.049F9AF61F17D75C moved successfully.
    C:\Windows\System32\services.exe.09123E38065282F7 moved successfully.
    C:\Windows\System32\services.exe.876360F33C92B2C5 moved successfully.
    C:\Windows\System32\services.exe.A7C527C7A8B6F50B moved successfully.
    C:\Windows\System32\services.exe.F1D21B448BF10CBA moved successfully.
    C:\Windows\System32\services.exe.0F8E9B38B76A8B0D moved successfully.
    C:\Windows\System32\services.exe.129B404282E5AE3C moved successfully.
    C:\Windows\System32\services.exe.F2B916F13308CA13 moved successfully.
    C:\Windows\System32\services.exe.4BD5DEF9F7587255 moved successfully.
    C:\Windows\System32\services.exe.94DDAA4175F314B1 moved successfully.
    C:\Windows\System32\services.exe.BC302FB3D17C0642 moved successfully.
    C:\Windows\System32\services.exe.DE76FBB01FA45BD3 moved successfully.
    C:\Windows\System32\services.exe.4A87AC973177E679 moved successfully.
    C:\Windows\System32\services.exe.FCF899EB194B3AD0 moved successfully.
    C:\Windows\System32\services.exe.1369A8411769F4CD moved successfully.
    C:\Windows\System32\services.exe.D86BF51DC13B8230 moved successfully.
    C:\Windows\System32\services.exe.B55066EB6B9EEE95 moved successfully.
    C:\Windows\System32\services.exe.87F78F64AC9E978C moved successfully.
    C:\Windows\System32\services.exe.46CE1BF2FE39E10B moved successfully.
    C:\Windows\System32\services.exe.51E9ECFC90321BD5 moved successfully.
    C:\Windows\System32\services.exe.FC3CA10830B61336 moved successfully.
    C:\Windows\System32\services.exe.5D35B473D6428979 moved successfully.
    C:\Windows\System32\services.exe.A993C76224D14F85 moved successfully.
    C:\Windows\System32\services.exe.B530A5047C73A16A moved successfully.
    C:\Windows\System32\services.exe.63EAEA5537A808B5 moved successfully.
    C:\Windows\System32\services.exe.DD3081176DD59A69 moved successfully.
    C:\Windows\System32\services.exe.F73A1B4CE90B2A7D moved successfully.
    C:\Windows\System32\services.exe.C1A100BAFEECC053 moved successfully.
    C:\Windows\System32\services.exe.711EEA03DCC5BF9F moved successfully.
    C:\Windows\System32\services.exe.F091C807FAD0E981 moved successfully.
    C:\Windows\System32\services.exe.9698E79E01BEE1D6 moved successfully.
    C:\Windows\System32\services.exe.FD0E73D6E48DF2DB moved successfully.
    C:\Windows\System32\services.exe.373F4D971A931FA2 moved successfully.
    C:\Windows\System32\services.exe.FC02870EA8A73758 moved successfully.
    C:\Windows\System32\services.exe.0DDA2AE7A9DE7737 moved successfully.
    C:\Windows\System32\services.exe.33C96B1604B8E4FB moved successfully.
    C:\Windows\System32\services.exe.24D2F2CA5DC1878C moved successfully.
    C:\Windows\System32\services.exe.AAD55A0BD1D3ACB3 moved successfully.
    C:\Windows\System32\services.exe.BBB1583714D0E53F moved successfully.
    C:\Windows\System32\services.exe.0474DDC0F56A6C98 moved successfully.
    C:\Windows\System32\services.exe.3F747776EEE440CA moved successfully.
    C:\Windows\System32\services.exe.47A1588EEADC79D9 moved successfully.
    C:\Windows\System32\services.exe.CA4A3BC2F6AC12CE moved successfully.
    C:\Windows\System32\services.exe.155A2A2B10C655C5 moved successfully.
    C:\Windows\System32\services.exe.0879AB483D626932 moved successfully.
    C:\Windows\System32\services.exe.10268C8E76D31502 moved successfully.
    C:\Windows\System32\services.exe.834B2828FA183CA3 moved successfully.
    C:\Windows\System32\services.exe.2142AABD9A6E03D4 moved successfully.
    C:\Windows\System32\services.exe.7552E461AB63A6C1 moved successfully.
    C:\Windows\System32\services.exe.B6638D582CB5239D moved successfully.
    C:\Windows\System32\services.exe.0397A3428D3804D4 moved successfully.
    C:\Windows\System32\services.exe.E51DC69051BEA1FC moved successfully.
    C:\Windows\System32\services.exe.3069EC68AB2E7B57 moved successfully.
    C:\Windows\System32\services.exe.541103CDEEBBC7B1 moved successfully.
    C:\Windows\System32\services.exe.00546D2F107C88F6 moved successfully.
    C:\Windows\System32\services.exe.59B092850D586002 moved successfully.
    C:\Windows\System32\services.exe.88EAA525011D6CD7 moved successfully.
    C:\Windows\System32\services.exe.AFE3CD7BE4C6B273 moved successfully.
    C:\Windows\System32\services.exe.9AE197152C0B6DBE moved successfully.
    C:\Windows\System32\services.exe.7D3C9F9D497408C2 moved successfully.
    C:\Windows\System32\services.exe.8169ABF06B61C7DC moved successfully.
    C:\Windows\System32\services.exe.E4FA4C6DEC7FA457 moved successfully.
    C:\Windows\System32\services.exe.F0206D8736558AF0 moved successfully.
    C:\Windows\System32\services.exe.FF294788B62887CD moved successfully.
    C:\Windows\System32\services.exe.0D7F729FF837B7E1 moved successfully.
    C:\Windows\System32\services.exe.0A702750A1684A1D moved successfully.
    C:\Windows\System32\services.exe.6D82152450C119DA moved successfully.
    C:\Windows\System32\services.exe.41F7724CB3DB06BB moved successfully.
    C:\Windows\System32\services.exe.AB932C6E4E8EE438 moved successfully.
    C:\Windows\System32\services.exe.CF6939662C08E42F moved successfully.
    C:\Windows\System32\services.exe.84D746227F91ED91 moved successfully.
    C:\Windows\System32\services.exe.FFAAB1B4E5F9F605 moved successfully.
    C:\Windows\System32\services.exe.92D0F8BF84305E11 moved successfully.
    C:\Windows\System32\services.exe.6AB8B992F0731098 moved successfully.
    C:\Windows\System32\services.exe.AD6D90A9500B7931 moved successfully.
    C:\Windows\System32\services.exe.1850E1E5AA25B05E moved successfully.
    C:\Windows\System32\services.exe.95653D6E21D04D7A moved successfully.
    C:\Windows\System32\services.exe.8157058AD18E7DAD moved successfully.
    C:\Windows\System32\services.exe.A5D50F07DA5C2D33 moved successfully.
    C:\Windows\System32\services.exe.F7E07AB1A607A4F6 moved successfully.
    C:\Windows\System32\services.exe.CDF585E84251D56D moved successfully.
    C:\Windows\System32\services.exe.1C8B1AFF015DD2B2 moved successfully.
    C:\Windows\System32\services.exe.4D95452728FAECF1 moved successfully.
    C:\Windows\System32\services.exe.E487623797CA617C moved successfully.
    C:\Windows\System32\services.exe.CB438F6E0B2FA2B3 moved successfully.
    C:\Windows\System32\services.exe.36C674D1EB924FBB moved successfully.
    C:\Windows\System32\services.exe.CD82D5E5B3B3F72E moved successfully.
    C:\Windows\System32\services.exe.67D4F2D8521EED50 moved successfully.
    C:\Windows\System32\services.exe.B33C0521EDC3A884 moved successfully.
    C:\Windows\System32\services.exe.1BFB723BACF41163 moved successfully.
    C:\Windows\System32\services.exe.E391B3C556D5F42D moved successfully.
    C:\Windows\System32\services.exe.A7FE3577CD164308 moved successfully.
    C:\Windows\System32\services.exe.8A5C086D4CB27A94 moved successfully.
    C:\Windows\System32\services.exe.BFB4D489EC266F59 moved successfully.
    C:\Windows\System32\services.exe.E141351D843D5ADB moved successfully.
    C:\Windows\System32\services.exe.A851C2C7D67203C9 moved successfully.
    C:\Windows\System32\services.exe.A1AC6CA500F0B944 moved successfully.
    C:\Windows\System32\services.exe.877CC8F7C0654369 moved successfully.
    C:\Windows\System32\services.exe.2ABC066A6CB23ED5 moved successfully.
    C:\Windows\System32\services.exe.E9FA810BD61820A5 moved successfully.
    C:\Windows\System32\services.exe.D87677A490E90540 moved successfully.
    C:\Windows\System32\services.exe.15B43CCED18E1D14 moved successfully.
    C:\Windows\System32\services.exe.FEB8266FBFAE7339 moved successfully.
    C:\Windows\System32\services.exe.C2D9099DA5002738 moved successfully.
    C:\Windows\System32\services.exe.2BACC871F522C30B moved successfully.
    C:\Windows\System32\services.exe.8B0AD15D1DF1B2C2 moved successfully.
    C:\Windows\System32\services.exe.FB744F045A9AE235 moved successfully.
    C:\Windows\System32\services.exe.8AFD3E376FAC7CB2 moved successfully.
    C:\Windows\System32\services.exe.6235CC19A79237D3 moved successfully.
    C:\Windows\System32\services.exe.0E444BD854315046 moved successfully.
    C:\Windows\System32\services.exe.FA421768F2A74BA3 moved successfully.
    C:\Windows\System32\services.exe.A83BD7A5E23A315A moved successfully.
    C:\Windows\System32\services.exe.5C641E19DDEE2810 moved successfully.
    C:\Windows\System32\services.exe.BD1E6FA221046C63 moved successfully.
    C:\Windows\System32\services.exe.E190B06FB01BE3D0 moved successfully.
    C:\Windows\System32\services.exe.9160897B82EC0185 moved successfully.
    C:\Windows\System32\services.exe.6D46D985EE0FDAD1 moved successfully.
    C:\Windows\System32\services.exe.1457FD0B1E7100F5 moved successfully.
    C:\Windows\System32\services.exe.F1798DADE265F227 moved successfully.
    C:\Windows\System32\services.exe.C6A2AF826E71567D moved successfully.
    C:\Windows\System32\services.exe.E6079324380AA7FD moved successfully.
    C:\Windows\System32\services.exe.7DAC7B56D306001E moved successfully.
    C:\Windows\System32\services.exe.74F55DFF4C3A075E moved successfully.
    ==== End of Fixlog ====
  24. Broni

    Broni Malware Annihilator Posts: 45,203   +242

    It's good now :)
  25. avenged187

    avenged187 Newcomer, in training Topic Starter Posts: 68

    Still not able to run either Windows Update, nor update MSE.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.