Thanks. I uninstalled AVG and got rid of the Panda Cleaner and downloaded Microsoft Security Essentials and did the Quick Scan. Here are the logs:
Malwarebytes:
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
22/01/2012 7:53:09 pm
mbam-log-2012-01-22 (19-53-09).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 238099
Time elapsed: 55 minute(s), 56 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER LOG:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit quick scan 2012-01-22 21:02:46
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.11.0
Running: g0lo314p.exe; Driver: C:\Users\SHARIB~1\AppData\Local\Temp\kfddypow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS TXT LOG:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by ShariBlackVelvet at 21:06:42 on 2012-01-22
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.44.1033.18.2939.1511 [GMT 0:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Toshiba TEMPRO\TemproSvc.exe
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Toshiba TEMPRO\TemproTray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\AOL\1287764634\ee\aolsoftware.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe
C:\Program Files\Common Files\AOL\1287764634\ee\aolsoftware.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\ShariBlackVelvet\Desktop\g0lo314p.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA;
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\TOSCDSPD.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [gfUomFNvRQL.exe] c:\programdata\gfUomFNvRQL.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [NDSTray.exe] NDSTray.exe
mRun: [cfFncEnabler.exe] cfFncEnabler.exe
mRun: [topi] c:\program files\toshiba\toshiba online product information\topi.exe -startup
mRun: [Toshiba TEMPO] c:\program files\toshiba tempro\Toshiba.Tempo.UI.TrayApplication.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Camera Assistant Software] "c:\program files\camera assistant software for toshiba\traybar.exe" /start
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [Toshiba Registration] c:\program files\toshiba\registration\ToshibaRegistration.exe
mRun: [jswtrayutil] "c:\program files\jumpstart\jswtrayutil.exe"
mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [<NO NAME>]
mRun: [Toshiba TEMPRO] c:\program files\toshiba tempro\TemproTray.exe
mRun: [Skytel] Skytel.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [HostManager] c:\program files\common files\aol\1287764634\ee\AOLSoftware.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Plugin Install] c:\program files\quicktime\plugins\DeleteMe1.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
mRun: [Google EULA Launcher] c:\program files\google\google eula\GoogleEULALauncher.exe IE PA
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
StartupFolder: c:\users\sharib~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\aoldes~1.lnk - c:\program files\common files\aol\1287764634\ee\aolsoftware.exe
StartupFolder: c:\users\sharib~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\_unins~1.lnk - c:\users\shariblackvelvet\appdata\local\temp\_uninst_23372510.bat
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\imagem~1.lnk - c:\program files\pixela\imagemixer 3 se\CameraMonitor.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office11\EXCEL.EXE/3000
IE: {76577871-04EC-495E-A12B-91F7C3600AFA} -
http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {8A918C1D-E123-4E36-B562-5C1519E434CE} -
http://www.amazon.co.uk/exec/obidos/redirect-home?tag=Toshibaukbholink-21&site=home
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
TCP: Interfaces\{35594759-A864-4F40-8CDF-600825668E4A} : NameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\shariblackvelvet\appdata\roaming\mozilla\firefox\profiles\x97wkle1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?query={searchTerms}&invocationType=tb50ffaoldesktop-chromesbox-en-us&tb_uuid=20110306000852167&tb_oid=06-03-2011&tb_mrud=06-03-2011
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.nectar.com
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?ourmark=1&ei=utf-8&fr=chr-nectar&slv8-&type=61465&p=
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\users\shariblackvelvet\appdata\roaming\mozilla\firefox\profiles\x97wkle1.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\users\shariblackvelvet\appdata\roaming\mozilla\firefox\profiles\x97wkle1.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll
FF - component: c:\users\shariblackvelvet\appdata\roaming\mozilla\firefox\profiles\x97wkle1.default\extensions\twitternotifier@naan.net\platform\winnt\components\nsTwitterFoxSign.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\picasa2\npPicasa3.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\shariblackvelvet\appdata\roaming\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\users\shariblackvelvet\appdata\roaming\facebook\npfbplugin_1_0_3.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-9-2 64512]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2009-6-9 20352]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl6299086f;MpKsl6299086f;c:\programdata\microsoft\microsoft antimalware\definition updates\{ea69181b-1a19-49b7-9528-240626abad44}\MpKsl6299086f.sys [2012-1-22 29904]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2008-4-16 40960]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\toshiba tempro\TemproSvc.exe [2009-4-21 116104]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-7-1 7168]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\toshiba\smartfacev\SmartFaceVWatchSrv.exe [2008-4-24 73728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2152152]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2009-6-9 937984]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-01-22 19:40:56 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{ea69181b-1a19-49b7-9528-240626abad44}\offreg.dll
2012-01-22 19:40:56 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{ea69181b-1a19-49b7-9528-240626abad44}\MpKsl6299086f.sys
2012-01-22 19:32:17 703824 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{1545967a-82c4-4793-b821-b094890f36e0}\gapaengine.dll
2012-01-22 19:31:54 6557240 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{ea69181b-1a19-49b7-9528-240626abad44}\mpengine.dll
2012-01-22 19:21:12 -------- d-----w- c:\program files\Microsoft Security Client
2012-01-22 19:20:12 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2012-01-22 15:47:18 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{53D74D6C-88CC-46DA-9546-3BEF15BF963C}
2012-01-22 15:47:08 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3F53012E-F14F-4B8C-9155-03402D752C1B}
2012-01-21 22:32:54 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{C2C8570B-1184-4B85-A9C7-BDC58ACB08E3}
2012-01-21 22:32:45 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{9FA5FB70-B5EE-4867-99A9-6B829532A02D}
2012-01-21 22:32:35 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{36E5AA70-6740-404B-B169-02C7D43DDABB}
2012-01-21 22:32:22 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{7827AF63-D31B-47B2-83FA-6E692D53DAF7}
2012-01-21 10:31:54 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{C72025E9-D6F9-4503-870F-31712928B1D9}
2012-01-21 10:31:43 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{01E2A91E-B125-4B5E-9828-DF06AC94F7BC}
2012-01-20 15:49:14 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3821DA62-CCC7-4238-9EDF-1A411124955F}
2012-01-20 15:49:04 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{584B6187-904D-47B9-B9FF-4A53D382F895}
2012-01-19 20:24:23 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{5E36AF94-1174-42BE-B4A5-2EE6003DAB40}
2012-01-19 20:24:13 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{38A0CD74-9C00-4EA3-BCDD-D1F43FEE918E}
2012-01-19 20:24:02 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{9FD28A24-3CAB-4A93-A980-28660C32B038}
2012-01-19 20:23:45 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{58DC4FF8-696F-4110-801C-8C6FDF78B176}
2012-01-19 17:49:41 -------- d-----w- c:\program files\Panda Security
2012-01-19 08:23:18 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{B018732F-DDFF-4C9B-A1C0-2B416C761E15}
2012-01-19 08:23:09 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{E32EFEC9-D0ED-402B-BC84-70594B9C3B8E}
2012-01-19 08:22:59 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3906C031-DDC7-450C-A5B2-66B70D259DA9}
2012-01-19 08:22:48 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{B68F3ABE-995E-42F3-A483-FBA91326942F}
2012-01-18 20:22:22 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{324F9DF9-7B6A-4652-9283-1BE583D9466A}
2012-01-18 20:22:11 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{87AAC18E-7B3C-49B5-A354-6084BCA6137F}
2012-01-18 19:52:42 6823496 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{28d0e58b-d0bf-447b-bf43-22d064460452}\mpengine.dll
2012-01-18 16:57:37 278528 ----a-w- c:\windows\system32\schannel.dll
2012-01-18 16:57:36 440192 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-18 16:57:35 9728 ----a-w- c:\windows\system32\lsass.exe
2012-01-18 16:57:35 72704 ----a-w- c:\windows\system32\secur32.dll
2012-01-18 16:57:35 377344 ----a-w- c:\windows\system32\winhttp.dll
2012-01-18 16:57:35 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-18 08:18:54 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{737A210E-1AEE-4A98-A6E6-FAC688F5F70B}
2012-01-18 08:18:44 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{91EC7AFA-6396-4384-8FF7-515AC6FFD803}
2012-01-18 08:18:35 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{B5C3E514-1E2D-4409-8092-0980EC5C6F6E}
2012-01-18 08:18:24 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{9900F514-B827-4C60-881F-E5A6F870AE0F}
2012-01-17 20:17:48 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{30E415F8-B024-4CD7-AB3C-C0C2638DD221}
2012-01-17 20:17:33 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{26E07204-AB28-4F0C-97FD-6397DD7FAAAC}
2012-01-17 19:13:23 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-17 07:50:49 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{A9CC87D8-1286-4520-AA9A-2ED7E69C323A}
2012-01-17 07:50:38 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{4980347A-CBD9-4459-B05C-A736F59E5C54}
2012-01-17 07:49:58 -------- d-----w- c:\users\shariblackvelvet\appdata\local\dbMobileInit
2012-01-16 15:20:53 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{FB9B9C1D-39C5-4384-9346-7940E75E853B}
2012-01-16 15:20:25 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{E63320BC-A614-417E-8ADA-4D5EE70B14C3}
2012-01-16 15:20:07 -------- d-----w- c:\users\shariblackvelvet\appdata\local\QuickGL.NET
2012-01-16 07:47:43 -------- d-----w- c:\users\shariblackvelvet\appdata\local\AppleHelp64
2012-01-16 03:00:45 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{A6C3816F-812A-4CD3-A700-8756BEAA473B}
2012-01-16 03:00:12 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{CED94EBA-94DF-40F5-8F12-A7B3BAFEC13E}
2012-01-15 14:59:53 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{0740BBF3-0946-4BDC-84BB-562B11766367}
2012-01-15 14:57:47 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{99F5A107-EC88-49C4-88F2-0DBDA9387FFF}
2012-01-15 14:57:34 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{2B7F77EA-7E7C-4143-AC7C-9A635CD5D277}
2012-01-15 14:57:20 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{51822A4F-C133-4AA8-A940-3FACAFE742C6}
2012-01-14 22:08:43 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{7ACE9507-8C77-4BC3-9FEE-8BF42788EEFF}
2012-01-14 22:08:33 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1E748363-558E-4EA7-B808-5E0E18DC3D46}
2012-01-14 22:08:21 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{FFD44CAB-6BA3-478F-A7D2-50469260F313}
2012-01-14 22:08:10 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1A072029-0B6D-4543-BAD3-3680D27E0123}
2012-01-14 10:07:40 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{36D74619-9610-4186-8818-CF237F6AAB7E}
2012-01-14 10:07:27 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3B7CEEE8-0E31-4E1A-964D-2A2A352F10DA}
2012-01-13 15:50:17 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3E65C8C9-77D8-4407-B7B8-4B197A11E0B1}
2012-01-13 15:50:05 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{4EA451CE-ACF5-4E5D-B21E-78B1F2621476}
2012-01-12 19:54:48 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{BFE4D8E3-CB17-453F-A8C8-DB38B5F0CD40}
2012-01-12 19:54:38 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{C8A813C2-D8B3-4623-AEC2-66896B345357}
2012-01-12 19:54:29 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{5E90CD99-CAFE-4FF9-9101-6D6F8841D3EF}
2012-01-12 19:54:17 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{D2A73B7B-2D52-4807-99A0-24D057C4829D}
2012-01-12 07:53:45 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{67053AFF-9CB0-4758-A484-F6720F558D01}
2012-01-12 07:53:29 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1F1DF292-7BE2-4DC7-9EC0-3E7322833111}
2012-01-12 07:53:14 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{A915025E-E84A-4599-B5D3-A94856461750}
2012-01-12 07:53:00 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{7BEE6133-02B6-4E50-A85C-C6DB50636036}
2012-01-11 19:52:29 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{5FE07F5A-6156-451A-A647-69222796D352}
2012-01-11 19:52:18 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{767C58FC-6FD8-4C4C-A4AA-EC1CC19CC001}
2012-01-11 19:52:06 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{7F509DF4-28D1-461D-AEFD-3D83130B5C10}
2012-01-11 19:51:53 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{7516BB9B-4258-4E1E-8792-F433E60D68DC}
2012-01-11 19:13:38 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-01-11 19:13:38 189952 ----a-w- c:\windows\system32\winmm.dll
2012-01-11 19:13:35 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 19:13:33 66560 ----a-w- c:\windows\system32\packager.dll
2012-01-11 19:13:32 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-01-11 19:13:31 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2012-01-11 19:13:18 497152 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 19:13:18 1314816 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 07:51:25 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{4E4321B9-7A95-4E0A-925F-05E2AED2511D}
2012-01-11 07:51:15 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{71CB32F4-CED7-43FA-9101-24752F76568A}
2012-01-10 19:50:50 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1B9D4E05-DB7A-4295-822C-1B8B63B1C783}
2012-01-10 19:50:41 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{6FD86E27-A448-4EDF-A012-7C8138FE4B3F}
2012-01-10 19:50:31 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{CC475545-867F-431A-A035-692A53507C46}
2012-01-10 19:50:20 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{25184834-8194-4DAE-A124-4AEA70A2B47C}
2012-01-10 07:49:55 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{0F25ABCE-6C49-48A6-AF0E-3F3A7DBD339D}
2012-01-10 07:49:45 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{7049BF41-516C-4941-9DBE-B90850FA42C3}
2012-01-09 19:48:43 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{D439DBB2-36D2-4B1B-B35A-7837FFDB4D47}
2012-01-09 19:48:25 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{43F8282E-8CCF-4E09-B29E-A455EAF7DCFD}
2012-01-09 07:47:53 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{FD71D796-961F-4CFC-B264-A69C6602F1BA}
2012-01-09 07:47:42 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{43892745-C074-40F8-99BB-32486F204EEB}
2012-01-08 15:49:35 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{6E4A398E-E033-4278-86B5-04020306EAD0}
2012-01-08 15:49:24 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1D9F2964-4297-4337-8A15-168384FD37A6}
2012-01-07 17:24:35 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3B093EE1-6B83-4FD0-858E-514066B144CF}
2012-01-07 17:24:25 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{C15D5155-A7B0-4409-8979-6C9B7E03CD6B}
2012-01-07 17:24:15 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{BC859FCF-5705-4495-BDC1-8933A6807D20}
2012-01-07 17:24:03 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{8EF038F4-4BF2-4EE3-B240-3F58ABA9ABFD}
2012-01-07 16:32:57 774144 ----a-w- c:\windows\system32\htmlayout.dll
2012-01-07 16:32:57 11137024 ----a-w- c:\windows\system32\libmfxsw32.dll
2012-01-07 16:32:57 1003008 ----a-w- c:\windows\system32\libeay32.dll
2012-01-07 05:23:12 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{8F95A61C-43E8-487A-8BB3-81C2AA2A0E79}
2012-01-07 05:22:50 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{34032A14-99FB-4FEB-A221-88F93EBD71E1}
2012-01-07 05:22:33 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{D06BC12B-3D32-4E31-B400-AC4C755413D0}
2012-01-07 05:22:17 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{BBD4D5A5-B563-474D-8163-3DE4B932EC13}
2012-01-07 04:56:59 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{B4CC4388-5C0F-4F2F-A58B-2DCE042808C4}
2012-01-07 04:38:35 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{82FB21FA-63F5-4B77-A721-7EAA4A439F8A}
2012-01-07 04:33:02 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{77FCB351-C23D-4630-8B8B-BE2F2CA809F9}
2012-01-07 04:25:51 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{B3D785CB-AF0F-42AC-80F5-375B837194EF}
2012-01-07 03:54:01 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{9B44C6D0-D81C-46FB-B521-81D5FB6647EC}
2012-01-07 03:14:59 -------- d-----w- c:\program files\DriverTuner
2012-01-07 02:45:36 -------- d-----w- c:\program files\WinZip(156)
2012-01-06 15:53:31 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{D85C2C5F-48CC-4B53-8505-7E8B31112EB1}
2012-01-06 15:53:21 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3E3F2264-B200-478F-A0EF-08A5FE6CF65E}
2012-01-05 19:53:39 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3E84F77A-783E-4963-BCA9-571AABF32CFD}
2012-01-05 19:53:30 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{7BD64C57-731E-455C-B393-4E4E8B12AF5A}
2012-01-05 19:53:20 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{F824848C-EA94-4E83-9363-130B4215C93A}
2012-01-05 19:53:10 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3DC01E2F-34F0-4914-8682-11F2D9AB0FA0}
2012-01-05 07:52:46 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{DFDD7D63-797A-4552-B036-32BF654AD273}
2012-01-05 07:52:36 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{FF110B2B-E48A-457D-8378-5445FF8B6AA5}
2012-01-05 07:52:26 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{9B4B18E4-989B-4C45-90DA-DF427277EDF5}
2012-01-05 07:52:16 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{7692FD85-EEB8-4E85-BB2A-99F18AFBE675}
2012-01-04 19:51:51 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{4DAD05D3-0CD8-4631-92C4-BB8A064882A5}
2012-01-04 19:51:40 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{D82AB3D3-70C5-467D-B6F7-EBB9DE333C54}
2012-01-04 19:51:30 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{66FC5418-1594-4390-8825-9C88796CE13E}
2012-01-04 19:51:17 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{0E897A90-20A0-4855-8AD4-022A8C3787A6}
2012-01-04 07:50:50 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{241B0EAC-7B5D-4E63-8012-0FE02AD339D5}
2012-01-04 07:50:38 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{433C3B9A-818E-4B24-8F07-F6B03C362F79}
2012-01-03 16:16:10 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1FB91562-F9D9-41B0-BBE9-8F92372AEAF0}
2012-01-03 16:16:00 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{491B70E5-9AFF-4374-9E50-4FF5B7176604}
2012-01-03 16:15:51 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{DA62B758-B506-4DA2-AF34-0F320421629C}
2012-01-03 16:15:40 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{645DA7FB-2056-4997-AF70-705CE5076320}
2012-01-03 04:14:49 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{64C88A22-341F-4622-B64A-DEC85B7294BC}
2012-01-03 04:14:23 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3FA331D0-99AB-4B30-8082-93ECC5E744DD}
2012-01-03 04:14:12 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{9F4C599D-A355-41B2-BBC5-75101EE2F3D1}
2012-01-03 04:13:48 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{E239FCAE-29E4-4DFD-A778-13DD616AD23D}
2012-01-02 15:50:07 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{FEF72B63-2AF8-4821-8034-963EEA15CDAD}
2012-01-02 15:49:57 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{F470585E-BDCA-412C-B844-C5EA40D0FE9F}
2012-01-02 03:48:44 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{F1BC9253-D74E-48DA-B8F0-9922ACD5B32A}
2012-01-02 03:48:34 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{83782D6F-E6E4-48EA-81DB-693F42EBEDE9}
2012-01-01 15:48:19 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{B2B303F7-E077-4BFE-AED4-30FF4A011F98}
2012-01-01 15:48:09 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{5213736C-8259-44E1-AC66-5E45308B03A1}
2011-12-31 15:49:02 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1D48FDBC-F362-4EA1-B9F8-97EBCF369F64}
2011-12-31 15:48:52 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{6B3D82E9-10CD-41FD-866C-0958E4F52B3F}
2011-12-30 21:01:06 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{BD81F659-B3B5-4632-8FED-0B055C825082}
2011-12-30 21:00:56 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{F24F9460-5F29-40A8-B234-B91732B4B79F}
2011-12-30 21:00:46 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{A0FFA13D-4E9F-41B3-95FA-373135106D0C}
2011-12-30 21:00:36 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{34897425-17F1-4B7F-843D-F9A520D9A5B9}
2011-12-30 09:06:28 626688 ----a-w- c:\program files\mozilla firefox\msvcr80.dll
2011-12-30 09:06:28 548864 ----a-w- c:\program files\mozilla firefox\msvcp80.dll
2011-12-30 09:06:28 479232 ----a-w- c:\program files\mozilla firefox\msvcm80.dll
2011-12-30 09:06:28 43992 ----a-w- c:\program files\mozilla firefox\mozutils.dll
2011-12-30 09:00:08 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1D5D9E17-F2F3-4499-B0A8-B79E866AE8CC}
2011-12-30 08:59:57 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{0CB6AF68-72E3-4C84-84AA-98BDDC69A089}
2011-12-30 08:59:11 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{9CA9E838-81DC-46D6-AE88-E9D4CE44BA03}
2011-12-30 08:58:53 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{B35C50DF-9186-4F5E-B33B-B15E624E58DC}
2011-12-29 15:50:46 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{4EF2C0AD-C7F8-4272-9E9E-34010DA3CB5B}
2011-12-29 15:50:36 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{2033FB4A-4204-4222-A21A-3FEAA751BA34}
2011-12-29 15:50:27 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1F1767DC-8620-4D06-8228-24F042C76A50}
2011-12-29 15:50:16 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1D65533E-895A-4097-9FC2-1904B6F87888}
2011-12-29 03:49:51 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{EF9EFC09-E612-484C-9DB2-D0B15CD30AF7}
2011-12-29 03:49:41 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1A464804-9178-43E1-9E37-866E61B5D7E7}
2011-12-29 03:49:31 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{FB3504F6-0CC7-4CAE-B261-95669DD86B9C}
2011-12-29 03:49:18 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3C2C8A93-0429-4604-8BAD-1E70183DD96B}
2011-12-28 15:49:04 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{E4E817CD-9418-4F0B-BB66-520315660075}
2011-12-28 15:48:49 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{4BC33885-01E7-43D3-9853-8952EB141713}
2011-12-28 03:48:22 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{BAA004AD-F1DC-42AF-A654-C54A584D80F0}
2011-12-28 03:48:12 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{EB065061-98BF-4409-8B1A-0A289235537D}
2011-12-28 03:48:02 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{755F529A-188E-45EA-BD63-A9E6B41CD7DA}
2011-12-28 03:47:51 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{BE1EB036-A0DE-4F86-BB62-9B43E4C60AFF}
2011-12-27 15:47:38 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{14AADC71-E5E5-468D-A3BD-FB951F1B3950}
2011-12-27 15:47:25 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{6B5F150B-289E-4504-9A78-5B2E7456744F}
2011-12-27 03:38:12 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{77787F8E-BECA-4F15-81EB-F2EE051E8D02}
2011-12-27 03:38:02 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{DE7CC7D1-7D3A-424A-860F-296CD284A281}
2011-12-27 03:37:53 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{F340BA1B-0405-43CE-AB9D-8AACC219F982}
2011-12-27 03:37:41 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{3284E2A4-79F7-4FF0-B5D7-C70B058E6D50}
2011-12-26 15:37:27 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{1FE705F6-B9CF-44DE-AB33-B8B7A1F6E442}
2011-12-26 15:37:17 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{521E1C01-400A-4A0C-9CA6-17BF13531471}
2011-12-26 02:34:56 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{EC7E20F2-04CE-421B-990F-01D860909F2F}
2011-12-26 02:34:46 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{70CC13BA-90A6-400F-9468-1B54B0E70E00}
2011-12-26 02:34:37 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{30CC495F-3DE4-4811-B76B-066668135934}
2011-12-26 02:34:24 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{BF4C1009-6504-4441-9651-46088312B5BF}
2011-12-25 14:34:02 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{50F905C5-31D2-4273-9D4F-711DDE86F73D}
2011-12-25 14:33:52 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{080702AE-00D3-4AD6-9D9D-7F1405709299}
2011-12-24 15:53:09 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{A8704FDC-E3EB-457D-BFFD-E4C8CF72B12B}
2011-12-24 15:52:59 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{C61BB952-BF48-4A59-9BC8-1196B993F0B7}
2011-12-24 15:52:47 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{0AB4E894-4BEB-4A74-BED3-D9993121F24E}
2011-12-24 15:52:34 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{A668195D-2DCB-443A-BD17-B833D105F89D}
2011-12-24 03:52:09 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{C297692D-5FA5-46A4-A23A-4F6ABB50B163}
2011-12-24 03:51:59 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{EA856AF0-04BA-4F30-B161-1981B6418CFD}
2011-12-24 03:51:50 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{4CD58ECE-1866-4952-826B-6A23225796E6}
2011-12-24 03:51:40 -------- d-----w- c:\users\shariblackvelvet\appdata\local\{E922DBAC-C2A5-4A08-900D-88C2AE753409}
.
==================== Find3M ====================
.
2011-12-10 15:24:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-23 13:37:27 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-11-17 07:53:41 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-08 14:42:19 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-03 22:47:42 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-27 08:01:53 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-27 08:01:53 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 15:56:04 49152 ----a-w- c:\windows\system32\csrsrv.dll
.
============= FINISH: 21:07:38.77 ===============