Okay, here it is..... BTW, would running farbar be a good idea on the
other machine that won't connect to the internet... the one that says 'failed to connect to systems event manager' 'the dependency group failed to start' 'windows could not automatically detect this networks proxy setting'??? okay, so I am probably pushing a friendship here .....
Scan result of Farbar Recovery Scan Tool Version: 01-07-2012 01
Ran by SYSTEM at 02-07-2012 19:14:22
Running from G:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6468712 2012-03-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORDTSUPTBT [1158248 2012-03-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORDTSUPTBT [1158248 2012-03-08] (Realtek Semiconductor)
HKLM\...\Run: [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE [406944 2008-09-04] (CANON INC.)
HKLM\...\Run: [cctray] "C:\Program Files\Total Defense\Internet Security Suite\casc.exe" [2710608 2012-06-13] (Total Defense, Inc.)
HKLM-x32\...\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [113288 2010-04-26] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml [10752 2012-02-20] ()
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKU\User\...\Run: [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE [406944 2008-09-04] (CANON INC.)
HKLM\...\Runonce: [Qurb {EBA5BE5C}] [x]
HKLM\...\RunOnce: [ccube_Uninstall_Lock] "C:\ProgramData\CA\cacu_001.exe" /cleanup /RunOnce [2578512 2012-06-13] (Total Defense, Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [462408 2012-04-03] (Malwarebytes Corporation)
Winlogon\Notify\PFW:
Tcpip\Parameters: [DhcpNameServer] 10.1.1.1
AppInit_DLLs: C:\Windows\System32\UmxSbxExA64.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
==================== Services (Whitelisted) ======
3 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [52896 2010-10-27] (Atheros Commnucations)
3 CaCCProvSP; "C:\Program Files\Total Defense\Internet Security Suite\ccprovsp.exe" [365136 2012-06-13] (Total Defense, Inc.)
2 ccSchedulerSVC; C:\Program Files\Total Defense\Internet Security Suite\ccschedulersvc.exe [288336 2012-06-13] (Total Defense, Inc.)
2 DTSAudioService; "C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe" [210024 2011-05-30] (DTS)
2 ExtremeVSSService; C:\Program Files (x86)\SuperFlexible\ExtremeVSS.exe [3196800 2011-09-20] (Super Flexible Software Ltd. & Co. KG)
2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [108392 2012-06-26] (SurfRight B.V.)
2 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service [994360 2011-10-13] (Secunia)
2 Secunia Update Agent; "C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service [399416 2011-10-13] (Secunia)
2 UmxEngine; "C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe" [920656 2011-04-03] (CA)
3 WinSvchostManagerSrv; C:\Windows\SysWOW64\cfgmig32.exe [263504 2011-07-01] ()
2 PCPitstop Scheduling; C:\Program Files (x86)\CA\PCPitstopScheduleService.exe [x]
========================== Drivers (Whitelisted) =============
3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [38248 2010-10-26] (Atheros)
3 ATHDFU; C:\Windows\System32\Drivers\ATHDFU.sys [55336 2010-10-26] (Windows (R) Win 7 DDK provider)
3 BTATH_A2DP; C:\Windows\System32\Drivers\BTATH_A2DP.sys [301680 2010-10-26] (Atheros)
3 BTATH_BUS; C:\Windows\System32\Drivers\BTATH_BUS.sys [31080 2010-10-26] (Atheros)
3 BTATH_HCRP; C:\Windows\System32\Drivers\BTATH_HCRP.sys [203624 2010-10-26] (Atheros)
3 BTATH_LWFLT; C:\Windows\System32\Drivers\BTATH_LWFLT.sys [58992 2010-10-26] (Atheros)
3 BTATH_RCP; C:\Windows\System32\Drivers\BTATH_RCP.sys [156520 2010-10-26] (Atheros)
3 BtFilter; C:\Windows\System32\Drivers\BtFilter.sys [279152 2010-10-26] (Atheros)
3 CAXHWBS2; C:\Windows\System32\Drivers\CAXHWBS2.sys [411136 2009-02-13] (Conexant Systems, Inc.)
0 KmxAMRT; C:\Windows\System32\Drivers\KmxAMRT.sys [182352 2011-10-27] (Total Defense)
2 KmxCF; C:\Windows\System32\Drivers\KmxCF.sys [201936 2011-09-06] (CA)
1 KmxFile; C:\Windows\System32\Drivers\KmxFile.sys [87120 2011-09-06] (CA)
0 KmxFw; C:\Windows\System32\Drivers\KmxFw.sys [143824 2011-09-06] (CA)
2 KmxSbx; C:\Windows\System32\Drivers\KmxSbx.sys [81488 2011-09-06] (CA)
0 mv91xx; C:\Windows\System32\Drivers\mv91xx.sys [297000 2010-08-27] (Marvell Semiconductor, Inc.)
3 VST64HWBS2; C:\Windows\System32\DRIVERS\VSTBS26.SYS [411136 2009-06-10] (Conexant Systems, Inc.)
3 VST64_DPV; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Conexant Systems, Inc.)
3 catchme; \??\C:\ComboFix\catchme.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-27 03:19 - 2012-06-27 03:19 - 00027639 ____A C:\ComboFix.txt
2012-06-27 03:02 - 2012-07-01 02:11 - 00001118 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-27 03:02 - 2012-04-03 23:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-27 02:51 - 2012-06-27 02:54 - 00000000 ____D C:\Program Files (x86)\Advanced Fix 2012
2012-06-26 22:01 - 2012-06-26 22:01 - 02524176 ____A () C:\Windows\System32\winsflt.dll
2012-06-26 22:01 - 2012-06-26 22:01 - 01744912 ____A () C:\Windows\SysWOW64\winsflt.dll
2012-06-26 22:01 - 2011-06-28 22:23 - 00289296 ____A C:\Windows\SysWOW64\winsfinst_x64.exe
2012-06-26 21:46 - 2012-06-26 21:46 - 00000000 ____D C:\Program Files\Total Defense
2012-06-26 21:38 - 2012-06-26 21:45 - 180769088 ____A (Total Defense, Inc.) C:\Users\User\Downloads\issdm_td_en.exe
2012-06-26 21:19 - 2012-06-26 21:25 - 156720112 ____A (CA, inc) C:\Users\User\Desktop\issdm_ca_en2.exe
2012-06-23 23:32 - 2012-06-23 23:07 - 02322184 ____A (ESET) C:\Users\User\Desktop\esetsmartinstaller_enu.exe
2012-06-23 22:03 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-23 22:03 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-23 22:03 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-23 22:03 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-23 22:02 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-23 22:02 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-23 22:02 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-23 22:02 - 2012-06-01 23:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-23 22:02 - 2012-06-01 23:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-22 23:16 - 2012-06-22 23:17 - 00001136 ____A C:\Users\User\Desktop\Super Flexible File Synchronizer.lnk
2012-06-22 22:12 - 2012-06-22 22:12 - 00001139 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-06-22 22:12 - 2012-06-22 22:12 - 00000000 ____D C:\Users\User\AppData\Local\Mozilla
2012-06-22 22:12 - 2012-06-22 22:12 - 00000000 ____D C:\Users\All Users\Mozilla
2012-06-22 22:12 - 2012-06-22 22:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-22 22:12 - 2012-06-22 22:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-19 22:20 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-06-19 22:20 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-06-19 22:20 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-06-19 22:20 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-06-19 22:20 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-06-19 22:20 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-06-19 22:20 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-06-19 22:20 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-06-19 21:33 - 2012-06-19 21:16 - 10142944 ____A (OPSWAT, Inc.) C:\Users\User\Desktop\AppRemover.exe
2012-06-19 21:06 - 2012-06-27 03:19 - 00000000 ____D C:\Qoobox
2012-06-19 21:05 - 2012-06-27 03:09 - 00000000 ____D C:\Users\User\Desktop\broni-north
2012-06-18 19:04 - 2012-06-18 19:04 - 00302592 ____A C:\Users\User\Desktop\gcp548hq.exe.3nwfd2c.partial
2012-06-18 18:42 - 2012-06-18 22:02 - 00000000 ____D C:\Users\User\Desktop\northlog
2012-06-18 06:10 - 2012-06-18 06:10 - 00000000 ____D C:\Users\Public\EmailTransfer
2012-06-15 05:11 - 2012-03-27 03:16 - 00272629 ____A C:\Windows\System32\Drivers\RTAIODAT.DAT
2012-06-15 05:11 - 2012-03-27 01:03 - 04015592 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\Drivers\RTKVHD64.sys
2012-06-15 05:11 - 2012-03-20 23:55 - 02886656 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RCoRes64.dat
2012-06-15 05:11 - 2012-03-19 18:47 - 03608680 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RtkAPO64.dll
2012-06-15 05:11 - 2012-03-19 03:01 - 00102504 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RCoInstII64.dll
2012-06-15 05:11 - 2012-03-16 00:25 - 02670696 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RtPgEx64.dll
2012-06-15 05:11 - 2012-03-12 19:21 - 01251432 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RTCOM64.dll
2012-06-15 05:11 - 2012-03-07 19:47 - 00202336 ____A (Andrea Electronics Corporation) C:\Windows\System32\AERTAC64.dll
2012-06-15 05:11 - 2012-03-07 19:47 - 00108640 ____A (Andrea Electronics Corporation) C:\Windows\System32\AERTAR64.dll
2012-06-15 05:11 - 2012-03-06 19:09 - 00824424 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RtkApi64.dll
2012-06-15 05:11 - 2012-02-21 03:45 - 02605400 ____A (Waves Audio Ltd.) C:\Windows\System32\WavesGUILib.dll
2012-06-15 05:11 - 2012-02-20 22:26 - 02528832 ____A (Fortemedia Corporation) C:\Windows\System32\FMAPO64.dll
2012-06-15 05:11 - 2012-02-16 23:54 - 00396632 ____A (Waves Audio Ltd.) C:\Windows\System32\MaxxVolumeSDAPO.dll
2012-06-15 05:11 - 2012-02-13 08:05 - 08363864 ____A (Waves Audio Ltd.) C:\Windows\System32\MaxxAudioRealtek.dll
2012-06-15 05:11 - 2012-02-13 06:35 - 00978776 ____A (Waves Audio Ltd.) C:\Windows\System32\MaxxAudioAPOShell64.dll
2012-06-15 05:11 - 2012-01-29 19:43 - 00836544 ____A (TOSHIBA Corporation) C:\Windows\System32\tadefxapo264.dll
2012-06-15 05:11 - 2012-01-23 06:30 - 00537456 ____A (DTS) C:\Windows\System32\DTSU2PLFX64.dll
2012-06-15 05:11 - 2012-01-23 06:30 - 00524656 ____A (DTS) C:\Windows\System32\DTSU2PGFX64.dll
2012-06-15 05:11 - 2012-01-23 06:30 - 00449392 ____A (DTS) C:\Windows\System32\DTSU2PREC64.dll
2012-06-15 05:11 - 2012-01-09 18:20 - 00065944 ____A (TOSHIBA CORPORATION.) C:\Windows\System32\tepeqapo64.dll
2012-06-15 05:11 - 2011-12-19 23:32 - 00331880 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RtlCPAPI64.dll
2012-06-15 05:11 - 2011-12-19 13:43 - 00220776 ____A (Sony Corporation) C:\Windows\System32\SFSS_APO.dll
2012-06-15 05:11 - 2011-12-18 01:58 - 02131288 ____A (Waves Audio Ltd.) C:\Windows\System32\MaxxAudioEQ.dll
2012-06-15 05:11 - 2011-12-18 01:58 - 01247576 ____A (Waves Audio Ltd.) C:\Windows\System32\MaxxAudioRealtek264.dll
2012-06-15 05:11 - 2011-12-14 21:16 - 07163744 ____A (Dolby Laboratories) C:\Windows\System32\R4EEP64A.dll
2012-06-15 05:11 - 2011-12-14 21:16 - 00433504 ____A (Dolby Laboratories) C:\Windows\System32\R4EED64A.dll
2012-06-15 05:11 - 2011-12-14 21:16 - 00137056 ____A (Dolby Laboratories) C:\Windows\System32\R4EEL64A.dll
2012-06-15 05:11 - 2011-12-14 21:16 - 00120160 ____A (Dolby Laboratories) C:\Windows\System32\R4EEA64A.dll
2012-06-15 05:11 - 2011-12-14 21:16 - 00075104 ____A (Dolby Laboratories) C:\Windows\System32\R4EEG64A.dll
2012-06-14 19:42 - 2012-06-26 21:17 - 00000992 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-06-14 19:42 - 2012-06-14 19:42 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-06-14 01:42 - 2012-06-14 01:42 - 00022016 ____A C:\Users\User\Downloads\TRS - 24 04 12 - 26 04 12.xls
2012-06-14 01:15 - 2012-06-14 01:15 - 00000000 ____D C:\Users\User\AppData\Local\Secunia PSI
2012-06-14 01:15 - 2012-06-14 01:15 - 00000000 ____D C:\Program Files (x86)\Secunia
2012-06-13 23:39 - 2012-06-13 23:39 - 00000000 ____D C:\Program Files\WOT
2012-06-13 23:39 - 2012-06-13 23:39 - 00000000 ____D C:\Program Files (x86)\WOT
2012-06-13 23:35 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-06-13 23:35 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-06-13 18:37 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 18:37 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 18:37 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-13 18:37 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 18:37 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 18:37 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-13 18:37 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 18:37 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 18:37 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-13 18:37 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-13 18:37 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 18:37 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 18:37 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 18:37 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 18:37 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 18:37 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 18:37 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-13 18:37 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 18:37 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-13 18:37 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 18:37 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 18:37 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 18:37 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-13 18:37 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-13 18:37 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 18:37 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 18:37 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 18:37 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 07:27 - 2012-06-13 07:27 - 00000000 ____D C:\Program Files (x86)\ESET
2012-06-13 07:20 - 2012-06-14 04:01 - 00446464 ____A (OldTimer Tools) C:\Users\User\Desktop\TFC.exe
2012-06-13 07:08 - 2012-06-13 07:08 - 00000000 ____D C:\Users\User\Desktop\JavaRa-1.16-16-12-11
2012-06-13 07:08 - 2012-06-13 06:59 - 00160639 ____A C:\Users\User\Desktop\JavaRa-1.16-16-12-11.zip
2012-06-13 07:03 - 2012-06-13 07:03 - 00000000 ____D C:\Program Files (x86)\Oracle
2012-06-13 07:01 - 2012-05-04 03:29 - 00772504 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-06-13 07:01 - 2012-05-04 03:29 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-06-13 06:54 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 06:54 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 06:54 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 06:54 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 06:54 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 06:54 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 06:54 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 06:53 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 06:53 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 06:53 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 06:53 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 06:53 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 06:53 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 06:53 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 06:53 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 06:53 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 06:53 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-11 10:40 - 2012-06-27 02:36 - 00000000 ____D C:\Windows\ERDNT
2012-06-10 19:42 - 2012-06-11 01:43 - 04731392 ____A (AVAST Software) C:\Users\User\Desktop\aswMBR.exe
2012-06-10 19:41 - 2012-06-10 19:41 - 00008070 ____A C:\Users\User\Desktop\bookkit.txt
2012-06-10 19:36 - 2012-06-10 19:33 - 00044607 ____A C:\Users\User\Desktop\bootkit_remover.zip
2012-06-10 19:34 - 2012-06-10 19:34 - 00044607 ____A C:\Users\User\Desktop\bootkit_remover.zip.02iy8t2.partial
2012-06-10 19:33 - 2012-06-10 19:33 - 00044607 ____A C:\Users\User\Downloads\bootkit_remover.zip
2012-06-10 19:32 - 2012-06-10 19:32 - 00044607 ____A C:\Users\User\Desktop\bootkit_remover.zip.xv05p77.partial
2012-06-10 18:34 - 2012-06-10 18:37 - 00000000 ____D C:\Users\User\Desktop\CA probelms
2012-06-10 10:34 - 2012-06-22 22:10 - 00000000 ____D C:\Program Files\HitmanPro
2012-06-10 10:34 - 2012-06-10 10:34 - 00001902 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2012-06-10 10:12 - 2012-06-10 10:12 - 00012872 ____A (SurfRight B.V.) C:\Windows\System32\bootdelete.exe
2012-06-10 10:00 - 2012-06-11 23:21 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-06-10 09:13 - 2012-06-10 09:13 - 00065736 ____A (Prevx) C:\Windows\System32\Drivers\pxrts.sys
2012-06-10 09:13 - 2012-06-10 09:13 - 00000000 ____D C:\Program Files\Prevx
2012-06-10 09:12 - 2012-06-11 01:32 - 00000000 ____D C:\Users\All Users\PrevxCSI
2012-06-10 09:12 - 2012-06-10 09:13 - 00000049 ____A C:\Windows\wininit.ini
2012-06-10 09:12 - 2012-02-22 18:18 - 00237072 ____N (Microsoft Corporation) C:\Windows\SysWOW64\MpSigStub.exe
2012-06-10 08:43 - 2012-06-27 03:09 - 00002243 ____A C:\Windows\epplauncher.mif
2012-06-08 03:05 - 2012-07-01 02:11 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-08 03:05 - 2012-06-08 03:05 - 00000000 ____D C:\Users\User\AppData\Roaming\Malwarebytes
2012-06-08 03:05 - 2012-06-08 03:05 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-08 03:03 - 2012-06-11 01:23 - 00000000 ____D C:\TDSSKiller_Quarantine
2012-06-08 03:02 - 2012-06-26 03:57 - 00749796 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-08 02:48 - 2012-06-08 02:48 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-08 02:20 - 2012-06-08 02:26 - 00000000 ____D C:\Users\All Users\B7E858A7000083BB00006F7BB4EB2331
2012-06-04 19:07 - 2012-06-04 19:07 - 00001286 ____A C:\Users\User\Desktop\MyPublisher.lnk
2012-06-04 19:06 - 2012-06-04 19:06 - 00000000 ____D C:\Users\User\AppData\Roaming\MyPublisher
2012-06-04 19:06 - 2012-06-04 19:06 - 00000000 ____D C:\Program Files (x86)\MyPublisher
============ 3 Months Modified Files ========================
2012-07-01 02:11 - 2012-06-27 03:02 - 00001118 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-30 18:47 - 2009-07-13 21:13 - 00730448 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-30 18:43 - 2010-11-20 19:47 - 00156966 ____A C:\Windows\PFRO.log
2012-06-27 03:19 - 2012-06-27 03:19 - 00027639 ____A C:\ComboFix.txt
2012-06-27 03:17 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini
2012-06-27 03:09 - 2012-06-10 08:43 - 00002243 ____A C:\Windows\epplauncher.mif
2012-06-27 03:05 - 2011-08-04 19:07 - 02024441 ____A C:\Windows\WindowsUpdate.log
2012-06-27 02:37 - 2009-07-13 18:34 - 75497472 ____A C:\Windows\System32\config\software.bak
2012-06-27 02:37 - 2009-07-13 18:34 - 21495808 ____A C:\Windows\System32\config\system.bak
2012-06-27 02:37 - 2009-07-13 18:34 - 01048576 ____A C:\Windows\System32\config\default.bak
2012-06-27 02:37 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\security.bak
2012-06-27 02:37 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\sam.bak
2012-06-26 22:01 - 2012-06-26 22:01 - 02524176 ____A () C:\Windows\System32\winsflt.dll
2012-06-26 22:01 - 2012-06-26 22:01 - 01744912 ____A () C:\Windows\SysWOW64\winsflt.dll
2012-06-26 22:01 - 2011-08-17 06:14 - 00015261 ____A C:\Windows\System32\FDInstall.log
2012-06-26 21:55 - 2009-07-13 20:45 - 00022096 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-26 21:55 - 2009-07-13 20:45 - 00022096 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-26 21:48 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-26 21:48 - 2009-07-13 20:51 - 00053761 ____A C:\Windows\setupact.log
2012-06-26 21:45 - 2012-06-26 21:38 - 180769088 ____A (Total Defense, Inc.) C:\Users\User\Downloads\issdm_td_en.exe
2012-06-26 21:25 - 2012-06-26 21:19 - 156720112 ____A (CA, inc) C:\Users\User\Desktop\issdm_ca_en2.exe
2012-06-26 21:17 - 2012-06-14 19:42 - 00000992 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-06-26 03:57 - 2012-06-08 03:02 - 00749796 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-23 23:07 - 2012-06-23 23:32 - 02322184 ____A (ESET) C:\Users\User\Desktop\esetsmartinstaller_enu.exe
2012-06-22 23:17 - 2012-06-22 23:16 - 00001136 ____A C:\Users\User\Desktop\Super Flexible File Synchronizer.lnk
2012-06-22 22:12 - 2012-06-22 22:12 - 00001139 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-06-20 03:00 - 2011-08-17 04:55 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-19 21:16 - 2012-06-19 21:33 - 10142944 ____A (OPSWAT, Inc.) C:\Users\User\Desktop\AppRemover.exe
2012-06-19 06:25 - 2011-08-22 05:54 - 02813473 ____A C:\Windows\System32\Drivers\kmxcfg.u2k0
2012-06-19 06:25 - 2011-08-22 05:54 - 00000341 ____A C:\Windows\System32\Drivers\kmxzone.u2k0
2012-06-19 06:25 - 2011-08-22 05:54 - 00000085 ____A C:\Windows\System32\Drivers\kmxcfg.u2k7
2012-06-19 06:25 - 2011-08-22 05:54 - 00000085 ____A C:\Windows\System32\Drivers\kmxcfg.u2k6
2012-06-19 06:25 - 2011-08-22 05:54 - 00000085 ____A C:\Windows\System32\Drivers\kmxcfg.u2k5
2012-06-19 06:25 - 2011-08-22 05:54 - 00000085 ____A C:\Windows\System32\Drivers\kmxcfg.u2k4
2012-06-19 06:25 - 2011-08-22 05:54 - 00000085 ____A C:\Windows\System32\Drivers\kmxcfg.u2k3
2012-06-19 06:25 - 2011-08-22 05:54 - 00000085 ____A C:\Windows\System32\Drivers\kmxcfg.u2k2
2012-06-19 06:25 - 2011-08-22 05:54 - 00000085 ____A C:\Windows\System32\Drivers\kmxcfg.u2k1
2012-06-19 06:25 - 2011-08-22 05:54 - 00000049 ____A C:\Windows\System32\Drivers\kmxzone.u2k7
2012-06-19 06:25 - 2011-08-22 05:54 - 00000049 ____A C:\Windows\System32\Drivers\kmxzone.u2k6
2012-06-19 06:25 - 2011-08-22 05:54 - 00000049 ____A C:\Windows\System32\Drivers\kmxzone.u2k5
2012-06-19 06:25 - 2011-08-22 05:54 - 00000049 ____A C:\Windows\System32\Drivers\kmxzone.u2k3
2012-06-19 06:25 - 2011-08-22 05:54 - 00000049 ____A C:\Windows\System32\Drivers\kmxzone.u2k2
2012-06-19 06:25 - 2011-08-22 05:54 - 00000049 ____A C:\Windows\System32\Drivers\kmxzone.u2k1
2012-06-19 06:25 - 2011-08-18 23:26 - 00000049 ____A C:\Windows\System32\Drivers\kmxzone.u2k4
2012-06-19 06:25 - 2011-08-17 06:26 - 00754164 ____A C:\Windows\System32\Drivers\KmxAgent.asc
2012-06-18 19:04 - 2012-06-18 19:04 - 00302592 ____A C:\Users\User\Desktop\gcp548hq.exe.3nwfd2c.partial
2012-06-15 05:11 - 2011-09-04 22:57 - 00004770 ____A C:\Windows\DPINST.LOG
2012-06-14 04:07 - 2011-09-30 02:47 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-06-14 04:01 - 2012-06-13 07:20 - 00446464 ____A (OldTimer Tools) C:\Users\User\Desktop\TFC.exe
2012-06-14 01:42 - 2012-06-14 01:42 - 00022016 ____A C:\Users\User\Downloads\TRS - 24 04 12 - 26 04 12.xls
2012-06-13 23:10 - 2009-07-13 20:45 - 04969504 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 07:01 - 2012-02-10 01:57 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-06-13 07:01 - 2012-02-10 01:57 - 00174064 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-06-13 06:59 - 2012-06-13 07:08 - 00160639 ____A C:\Users\User\Desktop\JavaRa-1.16-16-12-11.zip
2012-06-11 10:37 - 2009-07-13 21:08 - 00032564 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-11 01:43 - 2012-06-10 19:42 - 04731392 ____A (AVAST Software) C:\Users\User\Desktop\aswMBR.exe
2012-06-10 19:41 - 2012-06-10 19:41 - 00008070 ____A C:\Users\User\Desktop\bookkit.txt
2012-06-10 19:34 - 2012-06-10 19:34 - 00044607 ____A C:\Users\User\Desktop\bootkit_remover.zip.02iy8t2.partial
2012-06-10 19:33 - 2012-06-10 19:36 - 00044607 ____A C:\Users\User\Desktop\bootkit_remover.zip
2012-06-10 19:33 - 2012-06-10 19:33 - 00044607 ____A C:\Users\User\Downloads\bootkit_remover.zip
2012-06-10 19:32 - 2012-06-10 19:32 - 00044607 ____A C:\Users\User\Desktop\bootkit_remover.zip.xv05p77.partial
2012-06-10 10:34 - 2012-06-10 10:34 - 00001902 ____A C:\Users\Public\Desktop\HitmanPro.lnk
2012-06-10 10:12 - 2012-06-10 10:12 - 00012872 ____A (SurfRight B.V.) C:\Windows\System32\bootdelete.exe
2012-06-10 09:13 - 2012-06-10 09:13 - 00065736 ____A (Prevx) C:\Windows\System32\Drivers\pxrts.sys
2012-06-10 09:13 - 2012-06-10 09:12 - 00000049 ____A C:\Windows\wininit.ini
2012-06-04 19:07 - 2012-06-04 19:07 - 00001286 ____A C:\Users\User\Desktop\MyPublisher.lnk
2012-06-03 21:50 - 2011-08-22 06:55 - 00001015 ____A C:\Users\User\Desktop\Dropbox.lnk
2012-06-02 14:19 - 2012-06-23 22:03 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-23 22:03 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-23 22:03 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-23 22:02 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-23 22:02 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-23 22:03 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-23 22:02 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-01 23:19 - 2012-06-23 22:02 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-01 23:15 - 2012-06-23 22:02 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 01:08 - 2012-06-01 01:08 - 18651832 ____A (Experience In Software ) C:\Users\User\Downloads\PKS4Setup.exe
2012-05-21 07:06 - 2011-08-15 22:16 - 00109800 ____A C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-17 18:47 - 2012-06-13 18:37 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 18:37 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 18:37 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 18:37 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 18:37 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 18:37 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-13 18:37 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-13 18:37 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 18:37 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-13 18:37 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-13 18:37 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 18:37 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 18:37 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 18:37 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 18:37 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 18:37 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 18:37 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 18:37 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 18:37 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 18:37 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-13 18:37 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 18:37 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 18:37 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-13 18:37 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-13 18:37 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 18:37 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 18:37 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 18:37 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-16 18:50 - 2012-05-16 18:50 - 00001276 ____A C:\Users\User\Desktop\aaaREPORT Literature - Shortcut.lnk
2012-05-14 17:32 - 2012-06-13 06:53 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-05 02:39 - 2012-05-05 02:39 - 00013824 ____A C:\Users\Public\AmercianExpree.xls
2012-05-05 01:51 - 2012-04-13 19:35 - 08769696 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 03:29 - 2012-06-13 07:01 - 00772504 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-05-04 03:29 - 2012-06-13 07:01 - 00227720 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-05-04 03:29 - 2011-09-14 04:05 - 00687504 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-05-04 03:06 - 2012-06-13 06:54 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 03:00 - 2012-06-13 23:35 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-05-04 02:03 - 2012-06-13 06:54 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 06:54 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 01:59 - 2012-06-13 23:35 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-04-30 21:40 - 2012-06-13 06:54 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-13 06:53 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 06:54 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 06:54 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 06:54 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 06:53 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 06:53 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 06:53 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 06:53 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 06:53 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 06:53 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-21 20:20 - 2011-09-18 06:32 - 00231424 __ASH C:\Users\User\Documents\Thumbs.db
2012-04-18 04:56 - 2012-04-18 04:56 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx
2012-04-18 04:56 - 2012-04-18 04:56 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts
2012-04-17 20:43 - 2012-04-17 20:43 - 00001364 ____A C:\Users\User\Documents\Bibliography UWA+research files - Shortcut.lnk
2012-04-16 01:53 - 2011-08-22 06:22 - 00002031 ____A C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
2012-04-14 21:22 - 2012-04-14 21:22 - 00001276 ____A C:\Users\User\Documents\REPORT Literature - Shortcut.lnk
2012-04-11 02:09 - 2009-07-13 18:34 - 00000499 ____A C:\Windows\win.ini
2012-04-07 04:31 - 2012-06-13 06:53 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 06:53 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-05 21:22 - 2012-04-05 21:22 - 11174400 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmdag.sys
2012-04-05 18:23 - 2012-04-05 18:23 - 00245896 ____A C:\Windows\SysWOW64\atiapfxx.blb
2012-04-05 18:23 - 2012-04-05 18:23 - 00245896 ____A C:\Windows\System32\atiapfxx.blb
2012-04-05 18:22 - 2012-04-05 18:22 - 00159744 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiapfxx.exe
2012-04-05 18:21 - 2011-12-23 06:21 - 00909312 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2012-04-05 18:20 - 2012-04-05 18:20 - 01067520 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\aticfx64.dll
2012-04-05 18:16 - 2012-04-05 18:16 - 00503808 ____A (AMD) C:\Windows\System32\atieclxx.exe
2012-04-05 18:16 - 2012-04-05 18:16 - 00442368 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\ATIDEMGX.dll
2012-04-05 18:16 - 2012-04-05 18:16 - 00236544 ____A (AMD) C:\Windows\System32\atiesrxx.exe
2012-04-05 18:14 - 2012-04-05 18:14 - 00120320 ____A (AMD) C:\Windows\System32\atitmm64.dll
2012-04-05 18:14 - 2012-04-05 18:14 - 00059392 ____A (ATI Technologies, Inc.) C:\Windows\System32\atiedu64.dll
2012-04-05 18:14 - 2012-04-05 18:14 - 00043520 ____A (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2012-04-05 18:14 - 2012-04-05 18:14 - 00021504 ____A (AMD) C:\Windows\System32\atimuixx.dll
2012-04-05 18:13 - 2011-12-23 06:21 - 06800896 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2012-04-05 18:10 - 2012-04-05 18:10 - 26181632 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atio6axx.dll
2012-04-05 18:00 - 2011-08-04 22:37 - 00064000 ____A (AMD) C:\Windows\System32\coinst.dll
2012-04-05 17:54 - 2012-04-05 17:54 - 07479296 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atidxx64.dll
2012-04-05 17:50 - 2012-04-05 17:50 - 19753984 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2012-04-05 17:35 - 2012-04-05 17:35 - 01120768 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6v.dll
2012-04-05 17:34 - 2012-04-05 17:34 - 04731904 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd6a.dll
2012-04-05 17:34 - 2012-04-05 17:34 - 01831424 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll
2012-04-05 17:34 - 2011-12-23 06:21 - 06203392 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2012-04-05 17:30 - 2012-04-05 17:30 - 00051200 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalrt64.dll
2012-04-05 17:30 - 2012-04-05 17:30 - 00046080 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2012-04-05 17:30 - 2012-04-05 17:30 - 00044544 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticalcl64.dll
2012-04-05 17:30 - 2012-04-05 17:30 - 00044032 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2012-04-05 17:29 - 2012-04-05 17:29 - 16090624 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\aticaldd64.dll
2012-04-05 17:29 - 2012-04-05 17:29 - 02631008 ____A C:\Windows\System32\atiumd6a.cap
2012-04-05 17:29 - 2012-04-05 17:29 - 00204952 ____A C:\Windows\SysWOW64\ativvsvl.dat
2012-04-05 17:29 - 2012-04-05 17:29 - 00204952 ____A C:\Windows\System32\ativvsvl.dat
2012-04-05 17:29 - 2012-04-05 17:29 - 00157144 ____A C:\Windows\SysWOW64\ativvsva.dat
2012-04-05 17:29 - 2012-04-05 17:29 - 00157144 ____A C:\Windows\System32\ativvsva.dat
2012-04-05 17:25 - 2012-04-05 17:25 - 13764096 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2012-04-05 17:23 - 2012-04-05 17:23 - 07431680 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiumd64.dll
2012-04-05 17:22 - 2011-12-23 06:21 - 04795904 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2012-04-05 17:21 - 2012-04-05 17:21 - 02664704 ____A C:\Windows\SysWOW64\atiumdva.cap
2012-04-05 17:11 - 2012-04-05 17:11 - 00514560 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\atiadlxx.dll
2012-04-05 17:11 - 2012-04-05 17:11 - 00360448 ____A (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2012-04-05 17:11 - 2012-04-05 17:11 - 00041984 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6txx.dll
2012-04-05 17:11 - 2012-04-05 17:11 - 00017408 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atig6pxx.dll
2012-04-05 17:11 - 2012-04-05 17:11 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2012-04-05 17:11 - 2012-04-05 17:11 - 00014848 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiglpxx.dll
2012-04-05 17:10 - 2012-04-05 17:10 - 00343040 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\atikmpag.sys
2012-04-05 17:10 - 2012-04-05 17:10 - 00033280 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2012-04-05 17:09 - 2012-04-05 17:09 - 00053248 ____A (Advanced Micro Devices, Inc.) C:\Windows\System32\Drivers\ati2erec.dll
2012-04-05 17:09 - 2011-12-23 06:21 - 00041984 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2012-04-05 17:09 - 2011-12-23 06:21 - 00032256 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2012-04-05 17:09 - 2011-04-19 09:21 - 00044544 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiu9p64.dll
2012-04-05 17:09 - 2011-04-05 05:20 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atiuxp64.dll
2012-04-05 17:06 - 2012-04-05 17:06 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\atimpc64.dll
2012-04-05 17:06 - 2012-04-05 17:06 - 00054784 ____A (Advanced Micro Devices, Inc. ) C:\Windows\System32\amdpcom64.dll
2012-04-05 17:06 - 2012-04-05 17:06 - 00053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2012-04-05 17:06 - 2012-04-05 17:06 - 00053760 ____A (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2012-04-05 06:34 - 2012-04-05 06:34 - 00187392 ____A C:\Windows\System32\clinfo.exe
2012-04-05 06:34 - 2012-04-05 06:34 - 00074752 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OpenVideo64.dll
2012-04-05 06:34 - 2012-04-05 06:34 - 00064512 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2012-04-05 06:33 - 2012-04-05 06:33 - 16457216 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\amdocl64.dll
2012-04-05 06:33 - 2012-04-05 06:33 - 00063488 ____A (Advanced Micro Devices Inc.) C:\Windows\System32\OVDecode64.dll
2012-04-05 06:33 - 2012-04-05 06:33 - 00056320 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2012-04-05 06:32 - 2012-04-05 06:32 - 13007872 ____A (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2012-04-05 06:32 - 2012-04-05 06:32 - 00054784 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-04-05 06:32 - 2012-04-05 06:32 - 00050176 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
ZeroAccess:
C:\Users\User\AppData\Local\{e6128d5b-2e23-ec19-2331-6b5dd6497188}
C:\Users\User\AppData\Local\{e6128d5b-2e23-ec19-2331-6b5dd6497188}\L
C:\Users\User\AppData\Local\{e6128d5b-2e23-ec19-2331-6b5dd6497188}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 12%
Total physical RAM: 6120.84 MB
Available physical RAM: 5381.05 MB
Total Pagefile: 6119.04 MB
Available Pagefile: 5366.92 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (NORTH) (Fixed) (Total:1863.02 GB) (Free:937.95 GB) NTFS
2 Drive e: (NORTH_E_NHP+DPC_Asstd) (Fixed) (Total:931.41 GB) (Free:795.05 GB) NTFS
4 Drive g: (REDBOW_4GB) (Removable) (Total:3.73 GB) (Free:2.06 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 1024 KB
Disk 1 Online 1863 GB 0 B
Disk 2 Online 3828 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 931 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E NORTH_E_NHP NTFS Partition 931 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1863 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NORTH NTFS Partition 1863 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3824 MB 4032 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G REDBOW_4GB FAT32 Removable 3824 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-06-18 11:00
======================= End Of Log ==========================