I am trying to clean this virus from my laptop but I am needing some assistance in getting a fixlist.txt that I can run on Farbar.
frst.txt
Scan result of Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by Michele at 14-07-2012 13:46:55
Running from F:\
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-14 13:46 - 2012-07-14 13:46 - 00000000 ____D C:\FRST
2012-07-14 11:31 - 2012-07-14 11:31 - 00003416 ____N C:\bootsqm.dat
2012-07-14 11:30 - 2012-07-14 11:30 - 00000000 __SHD C:\found.000
2012-07-13 09:50 - 2012-07-13 09:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.61C71132CD9D040D
2012-07-13 09:35 - 2012-07-13 09:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C19059AF27730AC8
2012-07-13 09:31 - 2012-07-13 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2D3440776D72ECB5
2012-07-13 09:28 - 2012-07-13 09:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9A282AB65C2C02C
2012-07-13 09:23 - 2012-07-13 09:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0CBE32345F421889
2012-07-13 09:19 - 2012-07-13 09:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B12FAF4B706317DB
2012-07-13 09:16 - 2012-07-13 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F272255738D5DF7
2012-07-13 09:13 - 2012-07-13 09:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4C8BBBA8428029F
2012-07-13 09:10 - 2012-07-13 09:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC3D6FA7FAB62AF7
2012-07-13 09:07 - 2012-07-13 09:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7E70B5A4069803A5
2012-07-13 09:04 - 2012-07-13 09:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7197B8409AC9D2BC
2012-07-13 09:01 - 2012-07-13 09:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EC667CCD6A1E776D
2012-07-13 08:58 - 2012-07-13 08:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.78F08B6192608756
2012-07-13 08:55 - 2012-07-13 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F12979FFE3AB947C
2012-07-13 08:51 - 2012-07-13 08:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8C223D635B6743B6
2012-07-13 08:48 - 2012-07-13 08:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A2A92DC29A0E9421
2012-07-13 08:45 - 2012-07-13 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9EB4F6B2F3CC9E39
2012-07-13 08:42 - 2012-07-13 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C975685C3338D77
2012-07-13 08:38 - 2012-07-13 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EDA0F9F51325B9C8
2012-07-13 08:33 - 2012-07-13 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FC6F8F53C0C5366
2012-07-13 08:29 - 2012-07-13 08:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AA13565E813A8405
2012-07-13 08:26 - 2012-07-13 08:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63460CDCB06FDD10
2012-07-12 23:18 - 2012-07-12 23:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.959EFCE6CB361FDA
2012-07-12 23:14 - 2012-07-12 23:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B9F81661DDCEEB69
2012-07-12 23:07 - 2012-07-12 23:07 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-12 23:07 - 2012-07-12 23:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-12 23:04 - 2012-07-12 23:04 - 12621696 ____A (Microsoft Corporation) C:\Users\Michele\Downloads\mseinstall.exe
2012-07-11 19:36 - 2012-07-11 19:36 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-11 15:09 - 2012-07-11 20:23 - 00000000 ____D C:\Users\Michele\Desktop\2011 photobook
2012-07-11 08:24 - 2012-06-11 23:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 08:20 - 2012-06-02 08:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 08:20 - 2012-06-02 08:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 08:20 - 2012-06-02 08:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 08:20 - 2012-06-02 08:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 08:20 - 2012-06-02 08:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 08:20 - 2012-06-02 08:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 08:20 - 2012-06-02 08:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 08:20 - 2012-06-02 08:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 08:20 - 2012-06-02 08:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 08:20 - 2012-06-02 08:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 08:20 - 2012-06-02 07:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 08:20 - 2012-06-02 07:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 08:20 - 2012-06-02 07:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 08:20 - 2012-06-02 07:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 08:20 - 2012-06-02 05:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 08:20 - 2012-06-02 04:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 08:20 - 2012-06-02 04:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 08:20 - 2012-06-02 04:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 08:20 - 2012-06-02 04:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 08:20 - 2012-06-02 04:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 08:20 - 2012-06-02 04:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 08:20 - 2012-06-02 04:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 08:20 - 2012-06-02 04:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 08:20 - 2012-06-02 04:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 08:20 - 2012-06-02 04:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 08:20 - 2012-06-02 04:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 08:20 - 2012-06-02 04:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 08:20 - 2012-06-02 04:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 18:37 - 2012-06-09 01:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 18:37 - 2012-06-09 00:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 18:37 - 2012-06-06 02:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 18:37 - 2012-06-06 02:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 18:37 - 2012-06-06 02:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 18:37 - 2012-06-06 01:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 18:37 - 2012-06-06 01:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 18:37 - 2012-06-06 01:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 18:37 - 2012-06-02 01:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 18:37 - 2012-06-02 01:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 18:37 - 2012-06-02 01:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 18:37 - 2012-06-02 01:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 18:37 - 2012-06-02 01:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 18:37 - 2012-06-02 00:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 18:37 - 2012-06-02 00:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 18:37 - 2012-06-02 00:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 18:37 - 2012-06-02 00:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 18:37 - 2010-06-25 23:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 18:37 - 2010-06-25 23:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-08 19:25 - 2012-07-08 19:25 - 00000000 ____D C:\Users\Michele\AppData\Local\{F24143AC-E2F7-4DCC-B4AE-64C5F0632893}
2012-07-08 19:25 - 2012-07-08 19:25 - 00000000 ____D C:\Users\Michele\AppData\Local\{B9BF7CDF-44CC-4FD5-A7B5-64FDAC1E92A4}
2012-07-02 10:09 - 2012-07-02 10:13 - 00000000 ____D C:\Users\Michele\Desktop\tattoo ideas
2012-06-27 13:13 - 2012-07-14 12:46 - 00000000 ____D C:\Users\Michele\AppData\Roaming\Spotify
2012-06-27 13:13 - 2012-07-14 11:33 - 00000000 ____D C:\Users\Michele\AppData\Local\Spotify
2012-06-27 13:13 - 2012-06-27 13:13 - 00085784 ____A (Spotify Ltd) C:\Users\Michele\Downloads\spotify.exe
2012-06-27 13:13 - 2012-06-27 13:13 - 00001779 ____A C:\Users\Michele\Desktop\Spotify.lnk
2012-06-23 10:03 - 2012-06-23 10:03 - 00076017 ____A C:\Users\Michele\Documents\Drew Flyer.odt
2012-06-21 07:58 - 2012-06-02 18:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 07:58 - 2012-06-02 18:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 07:58 - 2012-06-02 18:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 07:58 - 2012-06-02 18:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 07:58 - 2012-06-02 18:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 07:58 - 2012-06-02 18:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 07:58 - 2012-06-02 18:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 07:58 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 07:58 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
============ 3 Months Modified Files ========================
2012-07-14 13:44 - 2009-07-14 01:13 - 00798570 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-14 12:44 - 2012-05-14 09:26 - 00045056 ____A C:\Windows\SysWOW64\acovcnt.exe
2012-07-14 12:44 - 2009-07-14 01:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-14 12:44 - 2009-07-14 00:51 - 00053287 ____A C:\Windows\setupact.log
2012-07-14 11:31 - 2012-07-14 11:31 - 00003416 ____N C:\bootsqm.dat
2012-07-13 09:50 - 2012-07-13 09:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.61C71132CD9D040D
2012-07-13 09:44 - 2012-02-27 21:15 - 01086725 ____A C:\Windows\WindowsUpdate.log
2012-07-13 09:35 - 2012-07-13 09:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C19059AF27730AC8
2012-07-13 09:31 - 2012-07-13 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2D3440776D72ECB5
2012-07-13 09:28 - 2012-07-13 09:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9A282AB65C2C02C
2012-07-13 09:23 - 2012-07-13 09:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0CBE32345F421889
2012-07-13 09:19 - 2012-07-13 09:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B12FAF4B706317DB
2012-07-13 09:16 - 2012-07-13 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F272255738D5DF7
2012-07-13 09:13 - 2012-07-13 09:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4C8BBBA8428029F
2012-07-13 09:10 - 2012-07-13 09:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC3D6FA7FAB62AF7
2012-07-13 09:07 - 2012-07-13 09:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7E70B5A4069803A5
2012-07-13 09:04 - 2012-07-13 09:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7197B8409AC9D2BC
2012-07-13 09:01 - 2012-07-13 09:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EC667CCD6A1E776D
2012-07-13 08:58 - 2012-07-13 08:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.78F08B6192608756
2012-07-13 08:55 - 2012-07-13 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F12979FFE3AB947C
2012-07-13 08:51 - 2012-07-13 08:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8C223D635B6743B6
2012-07-13 08:51 - 2012-05-16 07:59 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-13 08:48 - 2012-07-13 08:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A2A92DC29A0E9421
2012-07-13 08:45 - 2012-07-13 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9EB4F6B2F3CC9E39
2012-07-13 08:42 - 2012-07-13 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C975685C3338D77
2012-07-13 08:38 - 2012-07-13 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EDA0F9F51325B9C8
2012-07-13 08:33 - 2012-07-13 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FC6F8F53C0C5366
2012-07-13 08:29 - 2012-07-13 08:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AA13565E813A8405
2012-07-13 08:26 - 2012-07-13 08:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63460CDCB06FDD10
2012-07-13 07:46 - 2009-07-13 19:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-12 23:18 - 2012-07-12 23:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.959EFCE6CB361FDA
2012-07-12 23:14 - 2012-07-12 23:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B9F81661DDCEEB69
2012-07-12 23:08 - 2009-07-14 00:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-12 23:08 - 2009-07-14 00:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-12 23:07 - 2012-05-14 09:47 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-12 23:07 - 2011-11-03 06:19 - 00812720 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-12 23:04 - 2012-07-12 23:04 - 12621696 ____A (Microsoft Corporation) C:\Users\Michele\Downloads\mseinstall.exe
2012-07-12 09:51 - 2012-05-16 07:59 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-12 09:51 - 2012-05-16 07:59 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-12 08:11 - 2012-02-27 21:24 - 00002106 ____A C:\Windows\System32\AutoRunFilter.ini
2012-07-11 08:41 - 2009-07-14 00:45 - 00293304 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 08:21 - 2012-05-14 23:32 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-27 13:13 - 2012-06-27 13:13 - 00085784 ____A (Spotify Ltd) C:\Users\Michele\Downloads\spotify.exe
2012-06-27 13:13 - 2012-06-27 13:13 - 00001779 ____A C:\Users\Michele\Desktop\Spotify.lnk
2012-06-23 10:03 - 2012-06-23 10:03 - 00076017 ____A C:\Users\Michele\Documents\Drew Flyer.odt
2012-06-11 23:08 - 2012-07-11 08:24 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 01:43 - 2012-07-10 18:37 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-09 00:41 - 2012-07-10 18:37 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 16:24 - 2012-05-14 09:25 - 00063568 ____A C:\Users\Michele\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-06 17:36 - 2012-06-06 17:36 - 00485576 ____A (Catalina Marketing Corp. ) C:\Users\Michele\Downloads\CouponActivator.exe
2012-06-06 02:06 - 2012-07-10 18:37 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 02:06 - 2012-07-10 18:37 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 02:02 - 2012-07-10 18:37 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-06 01:05 - 2012-07-10 18:37 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-06 01:05 - 2012-07-10 18:37 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-06 01:03 - 2012-07-10 18:37 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 18:19 - 2012-06-21 07:58 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 18:19 - 2012-06-21 07:58 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 18:19 - 2012-06-21 07:58 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 18:19 - 2012-06-21 07:58 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 18:19 - 2012-06-21 07:58 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 18:15 - 2012-06-21 07:58 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 18:15 - 2012-06-21 07:58 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-21 07:58 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:15 - 2012-06-21 07:58 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 08:49 - 2012-07-11 08:20 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 08:17 - 2012-07-11 08:20 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 08:12 - 2012-07-11 08:20 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 08:05 - 2012-07-11 08:20 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 08:05 - 2012-07-11 08:20 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 08:04 - 2012-07-11 08:20 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 08:04 - 2012-07-11 08:20 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 08:03 - 2012-07-11 08:20 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 08:01 - 2012-07-11 08:20 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 08:00 - 2012-07-11 08:20 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 07:59 - 2012-07-11 08:20 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 07:57 - 2012-07-11 08:20 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 07:57 - 2012-07-11 08:20 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 07:54 - 2012-07-11 08:20 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 05:07 - 2012-07-11 08:20 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 04:43 - 2012-07-11 08:20 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 04:33 - 2012-07-11 08:20 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 04:26 - 2012-07-11 08:20 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 04:25 - 2012-07-11 08:20 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 04:25 - 2012-07-11 08:20 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 04:23 - 2012-07-11 08:20 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 04:21 - 2012-07-11 08:20 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 04:20 - 2012-07-11 08:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 04:19 - 2012-07-11 08:20 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 04:19 - 2012-07-11 08:20 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 04:17 - 2012-07-11 08:20 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 04:16 - 2012-07-11 08:20 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 04:14 - 2012-07-11 08:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-02 01:50 - 2012-07-10 18:37 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 01:48 - 2012-07-10 18:37 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 01:48 - 2012-07-10 18:37 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 01:45 - 2012-07-10 18:37 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 01:44 - 2012-07-10 18:37 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-02 00:40 - 2012-07-10 18:37 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-02 00:40 - 2012-07-10 18:37 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-02 00:39 - 2012-07-10 18:37 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-02 00:34 - 2012-07-10 18:37 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-29 12:59 - 2012-05-29 12:56 - 00012521 ____A C:\Users\Michele\Documents\Sarah Lesson Plan.odt
2012-05-29 12:55 - 2012-05-29 12:55 - 00012513 ____A C:\Users\Michele\Documents\Abbey Lesson Plan.odt
2012-05-25 07:49 - 2012-02-27 21:24 - 00001170 ____A C:\Windows\System32\ServiceFilter.ini
2012-05-24 19:54 - 2012-05-24 19:45 - 29548215 ____A C:\Users\Michele\Documents\Photos of house, rooms, and cars.odt
2012-05-24 18:25 - 2012-05-24 18:25 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-05-24 16:18 - 2012-05-24 16:18 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-05-24 16:18 - 2012-05-24 16:18 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-05-24 16:18 - 2012-05-24 16:18 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-05-24 16:18 - 2012-05-24 16:18 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-05-24 16:17 - 2012-05-24 16:17 - 00910112 ____A (Sun Microsystems, Inc.) C:\Users\Michele\Downloads\jxpiinstall.exe
2012-05-17 16:05 - 2012-05-17 16:05 - 24770069 ____A C:\Users\Michele\Downloads\Update_kindle_3.3_B006.bin
2012-05-16 10:13 - 2012-05-16 07:59 - 00002096 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2012-05-15 13:28 - 2009-07-14 01:01 - 00108227 ____A C:\Windows\SysWOW64\license.rtf
2012-05-15 13:28 - 2009-07-14 01:01 - 00108227 ____A C:\Windows\System32\license.rtf
2012-05-15 09:54 - 2012-05-15 09:54 - 01296320 ____A (Coupons.com Incorporated) C:\Users\Michele\Downloads\CouponPrinter.exe
2012-05-15 08:52 - 2012-05-15 08:52 - 00001164 ____A C:\Users\Public\Desktop\NX510 Series Info Center.lnk
2012-05-15 08:52 - 2012-05-15 08:08 - 00000079 ____A C:\Windows\EPNX510.ini
2012-05-15 08:46 - 2012-05-15 08:46 - 04729984 ____A C:\Users\Michele\Downloads\ENPrint250e.exe
2012-05-15 08:31 - 2012-05-15 08:10 - 00000932 ____A C:\Users\Public\Desktop\EPSON Scan.lnk
2012-05-14 23:51 - 2012-02-27 21:24 - 00000080 ____A C:\Windows\System32\Defrag.ini
2012-05-14 22:45 - 2012-05-14 22:45 - 00001168 ____A C:\Users\Public\Desktop\OpenOffice.org 3.4.lnk
2012-05-14 22:40 - 2012-05-14 22:39 - 151801119 ____A C:\Users\Michele\Downloads\Apache_OpenOffice_incubating_3.4.0_Win_x86_install_en-US.exe
2012-05-14 10:36 - 2012-05-14 10:36 - 00002088 ____A C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2012-05-14 10:36 - 2012-05-14 10:35 - 17596136 ____A (Mozilla) C:\Users\Michele\Downloads\Thunderbird Setup 12.0.1.exe
2012-05-14 10:35 - 2012-05-14 10:35 - 00001132 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-14 09:26 - 2011-11-03 06:19 - 02454060 ____A C:\Windows\AsDebug.log
2012-05-14 09:26 - 2011-11-03 06:10 - 00002988 ____A C:\Windows\PQArecord.log
2012-05-14 09:26 - 2011-02-18 16:12 - 00277978 ____A C:\Windows\AsCDProc.log
2012-05-14 09:25 - 2012-05-14 09:25 - 00000192 ____A C:\Windows\FixPatch.log
2012-05-14 09:25 - 2012-05-14 09:25 - 00000020 ___SH C:\Users\Michele\ntuser.ini
2012-05-04 07:06 - 2012-06-13 08:24 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 06:03 - 2012-06-13 08:24 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 06:03 - 2012-06-13 08:24 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 01:40 - 2012-06-13 08:24 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 23:55 - 2012-06-13 08:24 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 01:41 - 2012-06-13 08:25 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 01:41 - 2012-06-13 08:25 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 01:34 - 2012-06-13 08:25 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 01:37 - 2012-06-13 08:24 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-24 01:37 - 2012-06-13 08:24 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-24 01:37 - 2012-06-13 08:24 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-24 00:36 - 2012-06-13 08:24 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-24 00:36 - 2012-06-13 08:24 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-24 00:36 - 2012-06-13 08:24 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\@
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\L
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\U
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\U\00000001.@
ZeroAccess:
C:\Users\Michele\AppData\Local\{3c42eb88-3e76-c42f-e757-e3ec8d556822}
C:\Users\Michele\AppData\Local\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\@
C:\Users\Michele\AppData\Local\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\L
C:\Users\Michele\AppData\Local\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\U
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe FCB084FA3DCB7449F3BAA13312A215B4 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 28%
Total physical RAM: 4000.13 MB
Available physical RAM: 2879.83 MB
Total Pagefile: 7998.44 MB
Available Pagefile: 6881.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:78.12 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (DATA) (Fixed) (Total:153.85 GB) (Free:152.63 GB) NTFS
4 Drive f: () (Removable) (Total:0.94 GB) (Free:0.81 GB) FAT
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
==========================================================
Last Boot: 2012-06-30 09:18
======================= End Of Log ==========================
Services.exe Search
Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by SYSTEM at 2012-07-14 17:22:20
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-14 14:11] - 0328704 ____A (Microsoft Corporation) FCB084FA3DCB7449F3BAA13312A215B4
====== End Of Search ======
Any assistance would be appreciated....
Thanks
Chris
frst.txt
Scan result of Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by Michele at 14-07-2012 13:46:55
Running from F:\
Service Pack 1 (X64) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.
ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNTION PROPERLY.
============ One Month Created Files and Folders ==============
2012-07-14 13:46 - 2012-07-14 13:46 - 00000000 ____D C:\FRST
2012-07-14 11:31 - 2012-07-14 11:31 - 00003416 ____N C:\bootsqm.dat
2012-07-14 11:30 - 2012-07-14 11:30 - 00000000 __SHD C:\found.000
2012-07-13 09:50 - 2012-07-13 09:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.61C71132CD9D040D
2012-07-13 09:35 - 2012-07-13 09:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C19059AF27730AC8
2012-07-13 09:31 - 2012-07-13 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2D3440776D72ECB5
2012-07-13 09:28 - 2012-07-13 09:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9A282AB65C2C02C
2012-07-13 09:23 - 2012-07-13 09:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0CBE32345F421889
2012-07-13 09:19 - 2012-07-13 09:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B12FAF4B706317DB
2012-07-13 09:16 - 2012-07-13 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F272255738D5DF7
2012-07-13 09:13 - 2012-07-13 09:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4C8BBBA8428029F
2012-07-13 09:10 - 2012-07-13 09:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC3D6FA7FAB62AF7
2012-07-13 09:07 - 2012-07-13 09:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7E70B5A4069803A5
2012-07-13 09:04 - 2012-07-13 09:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7197B8409AC9D2BC
2012-07-13 09:01 - 2012-07-13 09:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EC667CCD6A1E776D
2012-07-13 08:58 - 2012-07-13 08:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.78F08B6192608756
2012-07-13 08:55 - 2012-07-13 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F12979FFE3AB947C
2012-07-13 08:51 - 2012-07-13 08:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8C223D635B6743B6
2012-07-13 08:48 - 2012-07-13 08:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A2A92DC29A0E9421
2012-07-13 08:45 - 2012-07-13 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9EB4F6B2F3CC9E39
2012-07-13 08:42 - 2012-07-13 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C975685C3338D77
2012-07-13 08:38 - 2012-07-13 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EDA0F9F51325B9C8
2012-07-13 08:33 - 2012-07-13 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FC6F8F53C0C5366
2012-07-13 08:29 - 2012-07-13 08:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AA13565E813A8405
2012-07-13 08:26 - 2012-07-13 08:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63460CDCB06FDD10
2012-07-12 23:18 - 2012-07-12 23:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.959EFCE6CB361FDA
2012-07-12 23:14 - 2012-07-12 23:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B9F81661DDCEEB69
2012-07-12 23:07 - 2012-07-12 23:07 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-12 23:07 - 2012-07-12 23:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-12 23:04 - 2012-07-12 23:04 - 12621696 ____A (Microsoft Corporation) C:\Users\Michele\Downloads\mseinstall.exe
2012-07-11 19:36 - 2012-07-11 19:36 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-11 15:09 - 2012-07-11 20:23 - 00000000 ____D C:\Users\Michele\Desktop\2011 photobook
2012-07-11 08:24 - 2012-06-11 23:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 08:20 - 2012-06-02 08:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 08:20 - 2012-06-02 08:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 08:20 - 2012-06-02 08:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 08:20 - 2012-06-02 08:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 08:20 - 2012-06-02 08:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 08:20 - 2012-06-02 08:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 08:20 - 2012-06-02 08:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 08:20 - 2012-06-02 08:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 08:20 - 2012-06-02 08:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 08:20 - 2012-06-02 08:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 08:20 - 2012-06-02 07:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 08:20 - 2012-06-02 07:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 08:20 - 2012-06-02 07:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 08:20 - 2012-06-02 07:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 08:20 - 2012-06-02 05:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 08:20 - 2012-06-02 04:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 08:20 - 2012-06-02 04:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 08:20 - 2012-06-02 04:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 08:20 - 2012-06-02 04:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 08:20 - 2012-06-02 04:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 08:20 - 2012-06-02 04:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 08:20 - 2012-06-02 04:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 08:20 - 2012-06-02 04:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 08:20 - 2012-06-02 04:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 08:20 - 2012-06-02 04:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 08:20 - 2012-06-02 04:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 08:20 - 2012-06-02 04:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 08:20 - 2012-06-02 04:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 18:37 - 2012-06-09 01:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 18:37 - 2012-06-09 00:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 18:37 - 2012-06-06 02:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 18:37 - 2012-06-06 02:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 18:37 - 2012-06-06 02:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 18:37 - 2012-06-06 01:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 18:37 - 2012-06-06 01:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 18:37 - 2012-06-06 01:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 18:37 - 2012-06-02 01:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 18:37 - 2012-06-02 01:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 18:37 - 2012-06-02 01:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 18:37 - 2012-06-02 01:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 18:37 - 2012-06-02 01:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 18:37 - 2012-06-02 00:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 18:37 - 2012-06-02 00:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 18:37 - 2012-06-02 00:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 18:37 - 2012-06-02 00:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 18:37 - 2010-06-25 23:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 18:37 - 2010-06-25 23:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-08 19:25 - 2012-07-08 19:25 - 00000000 ____D C:\Users\Michele\AppData\Local\{F24143AC-E2F7-4DCC-B4AE-64C5F0632893}
2012-07-08 19:25 - 2012-07-08 19:25 - 00000000 ____D C:\Users\Michele\AppData\Local\{B9BF7CDF-44CC-4FD5-A7B5-64FDAC1E92A4}
2012-07-02 10:09 - 2012-07-02 10:13 - 00000000 ____D C:\Users\Michele\Desktop\tattoo ideas
2012-06-27 13:13 - 2012-07-14 12:46 - 00000000 ____D C:\Users\Michele\AppData\Roaming\Spotify
2012-06-27 13:13 - 2012-07-14 11:33 - 00000000 ____D C:\Users\Michele\AppData\Local\Spotify
2012-06-27 13:13 - 2012-06-27 13:13 - 00085784 ____A (Spotify Ltd) C:\Users\Michele\Downloads\spotify.exe
2012-06-27 13:13 - 2012-06-27 13:13 - 00001779 ____A C:\Users\Michele\Desktop\Spotify.lnk
2012-06-23 10:03 - 2012-06-23 10:03 - 00076017 ____A C:\Users\Michele\Documents\Drew Flyer.odt
2012-06-21 07:58 - 2012-06-02 18:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 07:58 - 2012-06-02 18:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 07:58 - 2012-06-02 18:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 07:58 - 2012-06-02 18:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 07:58 - 2012-06-02 18:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 07:58 - 2012-06-02 18:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 07:58 - 2012-06-02 18:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 07:58 - 2012-06-02 15:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 07:58 - 2012-06-02 15:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
============ 3 Months Modified Files ========================
2012-07-14 13:44 - 2009-07-14 01:13 - 00798570 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-14 12:44 - 2012-05-14 09:26 - 00045056 ____A C:\Windows\SysWOW64\acovcnt.exe
2012-07-14 12:44 - 2009-07-14 01:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-14 12:44 - 2009-07-14 00:51 - 00053287 ____A C:\Windows\setupact.log
2012-07-14 11:31 - 2012-07-14 11:31 - 00003416 ____N C:\bootsqm.dat
2012-07-13 09:50 - 2012-07-13 09:50 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.61C71132CD9D040D
2012-07-13 09:44 - 2012-02-27 21:15 - 01086725 ____A C:\Windows\WindowsUpdate.log
2012-07-13 09:35 - 2012-07-13 09:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C19059AF27730AC8
2012-07-13 09:31 - 2012-07-13 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2D3440776D72ECB5
2012-07-13 09:28 - 2012-07-13 09:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A9A282AB65C2C02C
2012-07-13 09:23 - 2012-07-13 09:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0CBE32345F421889
2012-07-13 09:19 - 2012-07-13 09:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B12FAF4B706317DB
2012-07-13 09:16 - 2012-07-13 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0F272255738D5DF7
2012-07-13 09:13 - 2012-07-13 09:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E4C8BBBA8428029F
2012-07-13 09:10 - 2012-07-13 09:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC3D6FA7FAB62AF7
2012-07-13 09:07 - 2012-07-13 09:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7E70B5A4069803A5
2012-07-13 09:04 - 2012-07-13 09:04 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7197B8409AC9D2BC
2012-07-13 09:01 - 2012-07-13 09:01 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EC667CCD6A1E776D
2012-07-13 08:58 - 2012-07-13 08:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.78F08B6192608756
2012-07-13 08:55 - 2012-07-13 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F12979FFE3AB947C
2012-07-13 08:51 - 2012-07-13 08:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8C223D635B6743B6
2012-07-13 08:51 - 2012-05-16 07:59 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-13 08:48 - 2012-07-13 08:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A2A92DC29A0E9421
2012-07-13 08:45 - 2012-07-13 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9EB4F6B2F3CC9E39
2012-07-13 08:42 - 2012-07-13 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C975685C3338D77
2012-07-13 08:38 - 2012-07-13 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EDA0F9F51325B9C8
2012-07-13 08:33 - 2012-07-13 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FC6F8F53C0C5366
2012-07-13 08:29 - 2012-07-13 08:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AA13565E813A8405
2012-07-13 08:26 - 2012-07-13 08:26 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63460CDCB06FDD10
2012-07-13 07:46 - 2009-07-13 19:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-12 23:18 - 2012-07-12 23:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.959EFCE6CB361FDA
2012-07-12 23:14 - 2012-07-12 23:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B9F81661DDCEEB69
2012-07-12 23:08 - 2009-07-14 00:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-12 23:08 - 2009-07-14 00:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-12 23:07 - 2012-05-14 09:47 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-12 23:07 - 2011-11-03 06:19 - 00812720 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-12 23:04 - 2012-07-12 23:04 - 12621696 ____A (Microsoft Corporation) C:\Users\Michele\Downloads\mseinstall.exe
2012-07-12 09:51 - 2012-05-16 07:59 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-12 09:51 - 2012-05-16 07:59 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-12 08:11 - 2012-02-27 21:24 - 00002106 ____A C:\Windows\System32\AutoRunFilter.ini
2012-07-11 08:41 - 2009-07-14 00:45 - 00293304 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 08:21 - 2012-05-14 23:32 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-27 13:13 - 2012-06-27 13:13 - 00085784 ____A (Spotify Ltd) C:\Users\Michele\Downloads\spotify.exe
2012-06-27 13:13 - 2012-06-27 13:13 - 00001779 ____A C:\Users\Michele\Desktop\Spotify.lnk
2012-06-23 10:03 - 2012-06-23 10:03 - 00076017 ____A C:\Users\Michele\Documents\Drew Flyer.odt
2012-06-11 23:08 - 2012-07-11 08:24 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 01:43 - 2012-07-10 18:37 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-09 00:41 - 2012-07-10 18:37 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 16:24 - 2012-05-14 09:25 - 00063568 ____A C:\Users\Michele\AppData\Local\GDIPFONTCACHEV1.DAT
2012-06-06 17:36 - 2012-06-06 17:36 - 00485576 ____A (Catalina Marketing Corp. ) C:\Users\Michele\Downloads\CouponActivator.exe
2012-06-06 02:06 - 2012-07-10 18:37 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-06 02:06 - 2012-07-10 18:37 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-06 02:02 - 2012-07-10 18:37 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-06 01:05 - 2012-07-10 18:37 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-06 01:05 - 2012-07-10 18:37 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-06 01:03 - 2012-07-10 18:37 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 18:19 - 2012-06-21 07:58 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 18:19 - 2012-06-21 07:58 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 18:19 - 2012-06-21 07:58 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 18:19 - 2012-06-21 07:58 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 18:19 - 2012-06-21 07:58 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 18:15 - 2012-06-21 07:58 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 18:15 - 2012-06-21 07:58 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 15:19 - 2012-06-21 07:58 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 15:15 - 2012-06-21 07:58 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 08:49 - 2012-07-11 08:20 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 08:17 - 2012-07-11 08:20 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 08:12 - 2012-07-11 08:20 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 08:05 - 2012-07-11 08:20 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 08:05 - 2012-07-11 08:20 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 08:04 - 2012-07-11 08:20 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 08:04 - 2012-07-11 08:20 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 08:03 - 2012-07-11 08:20 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 08:01 - 2012-07-11 08:20 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 08:00 - 2012-07-11 08:20 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 07:59 - 2012-07-11 08:20 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 07:57 - 2012-07-11 08:20 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 07:57 - 2012-07-11 08:20 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 07:54 - 2012-07-11 08:20 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 05:07 - 2012-07-11 08:20 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 04:43 - 2012-07-11 08:20 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 04:33 - 2012-07-11 08:20 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 04:26 - 2012-07-11 08:20 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 04:25 - 2012-07-11 08:20 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 04:25 - 2012-07-11 08:20 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 04:23 - 2012-07-11 08:20 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 04:21 - 2012-07-11 08:20 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 04:20 - 2012-07-11 08:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 04:19 - 2012-07-11 08:20 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 04:19 - 2012-07-11 08:20 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 04:17 - 2012-07-11 08:20 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 04:16 - 2012-07-11 08:20 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 04:14 - 2012-07-11 08:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-02 01:50 - 2012-07-10 18:37 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-02 01:48 - 2012-07-10 18:37 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-02 01:48 - 2012-07-10 18:37 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-02 01:45 - 2012-07-10 18:37 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-02 01:44 - 2012-07-10 18:37 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-02 00:40 - 2012-07-10 18:37 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-02 00:40 - 2012-07-10 18:37 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-02 00:39 - 2012-07-10 18:37 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-02 00:34 - 2012-07-10 18:37 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-29 12:59 - 2012-05-29 12:56 - 00012521 ____A C:\Users\Michele\Documents\Sarah Lesson Plan.odt
2012-05-29 12:55 - 2012-05-29 12:55 - 00012513 ____A C:\Users\Michele\Documents\Abbey Lesson Plan.odt
2012-05-25 07:49 - 2012-02-27 21:24 - 00001170 ____A C:\Windows\System32\ServiceFilter.ini
2012-05-24 19:54 - 2012-05-24 19:45 - 29548215 ____A C:\Users\Michele\Documents\Photos of house, rooms, and cars.odt
2012-05-24 18:25 - 2012-05-24 18:25 - 00002021 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-05-24 16:18 - 2012-05-24 16:18 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-05-24 16:18 - 2012-05-24 16:18 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-05-24 16:18 - 2012-05-24 16:18 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-05-24 16:18 - 2012-05-24 16:18 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-05-24 16:17 - 2012-05-24 16:17 - 00910112 ____A (Sun Microsystems, Inc.) C:\Users\Michele\Downloads\jxpiinstall.exe
2012-05-17 16:05 - 2012-05-17 16:05 - 24770069 ____A C:\Users\Michele\Downloads\Update_kindle_3.3_B006.bin
2012-05-16 10:13 - 2012-05-16 07:59 - 00002096 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2012-05-15 13:28 - 2009-07-14 01:01 - 00108227 ____A C:\Windows\SysWOW64\license.rtf
2012-05-15 13:28 - 2009-07-14 01:01 - 00108227 ____A C:\Windows\System32\license.rtf
2012-05-15 09:54 - 2012-05-15 09:54 - 01296320 ____A (Coupons.com Incorporated) C:\Users\Michele\Downloads\CouponPrinter.exe
2012-05-15 08:52 - 2012-05-15 08:52 - 00001164 ____A C:\Users\Public\Desktop\NX510 Series Info Center.lnk
2012-05-15 08:52 - 2012-05-15 08:08 - 00000079 ____A C:\Windows\EPNX510.ini
2012-05-15 08:46 - 2012-05-15 08:46 - 04729984 ____A C:\Users\Michele\Downloads\ENPrint250e.exe
2012-05-15 08:31 - 2012-05-15 08:10 - 00000932 ____A C:\Users\Public\Desktop\EPSON Scan.lnk
2012-05-14 23:51 - 2012-02-27 21:24 - 00000080 ____A C:\Windows\System32\Defrag.ini
2012-05-14 22:45 - 2012-05-14 22:45 - 00001168 ____A C:\Users\Public\Desktop\OpenOffice.org 3.4.lnk
2012-05-14 22:40 - 2012-05-14 22:39 - 151801119 ____A C:\Users\Michele\Downloads\Apache_OpenOffice_incubating_3.4.0_Win_x86_install_en-US.exe
2012-05-14 10:36 - 2012-05-14 10:36 - 00002088 ____A C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2012-05-14 10:36 - 2012-05-14 10:35 - 17596136 ____A (Mozilla) C:\Users\Michele\Downloads\Thunderbird Setup 12.0.1.exe
2012-05-14 10:35 - 2012-05-14 10:35 - 00001132 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-14 09:26 - 2011-11-03 06:19 - 02454060 ____A C:\Windows\AsDebug.log
2012-05-14 09:26 - 2011-11-03 06:10 - 00002988 ____A C:\Windows\PQArecord.log
2012-05-14 09:26 - 2011-02-18 16:12 - 00277978 ____A C:\Windows\AsCDProc.log
2012-05-14 09:25 - 2012-05-14 09:25 - 00000192 ____A C:\Windows\FixPatch.log
2012-05-14 09:25 - 2012-05-14 09:25 - 00000020 ___SH C:\Users\Michele\ntuser.ini
2012-05-04 07:06 - 2012-06-13 08:24 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 06:03 - 2012-06-13 08:24 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 06:03 - 2012-06-13 08:24 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-01 01:40 - 2012-06-13 08:24 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 23:55 - 2012-06-13 08:24 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-26 01:41 - 2012-06-13 08:25 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-26 01:41 - 2012-06-13 08:25 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-26 01:34 - 2012-06-13 08:25 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-24 01:37 - 2012-06-13 08:24 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-24 01:37 - 2012-06-13 08:24 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-24 01:37 - 2012-06-13 08:24 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-24 00:36 - 2012-06-13 08:24 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-24 00:36 - 2012-06-13 08:24 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-24 00:36 - 2012-06-13 08:24 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\@
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\L
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\U
C:\Windows\Installer\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\U\00000001.@
ZeroAccess:
C:\Users\Michele\AppData\Local\{3c42eb88-3e76-c42f-e757-e3ec8d556822}
C:\Users\Michele\AppData\Local\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\@
C:\Users\Michele\AppData\Local\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\L
C:\Users\Michele\AppData\Local\{3c42eb88-3e76-c42f-e757-e3ec8d556822}\U
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe FCB084FA3DCB7449F3BAA13312A215B4 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 28%
Total physical RAM: 4000.13 MB
Available physical RAM: 2879.83 MB
Total Pagefile: 7998.44 MB
Available Pagefile: 6881.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:78.12 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive d: (DATA) (Fixed) (Total:153.85 GB) (Free:152.63 GB) NTFS
4 Drive f: () (Removable) (Total:0.94 GB) (Free:0.81 GB) FAT
DiskPart has encountered an error: The RPC server is unavailable.
See the System Event Log for more information.
==========================================================
Last Boot: 2012-06-30 09:18
======================= End Of Log ==========================
Services.exe Search
Farbar Recovery Scan Tool Version: 14-07-2012 01
Ran by SYSTEM at 2012-07-14 17:22:20
Running from F:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-14 14:11] - 0328704 ____A (Microsoft Corporation) FCB084FA3DCB7449F3BAA13312A215B4
====== End Of Search ======
Any assistance would be appreciated....
Thanks
Chris