I see that LOTS of poeple are having this same problem. My problem seems to be the same as:
https://www.techspot.com/community/topics/help-removing-trojan-win64-sirefef-y.181701/
https://www.techspot.com/community/topics/help-removing-trojan-win64-sirefef-y.181702/
My wife's computer seems to have caught this one. When she finally notified me it was acting funny, it noticed that all the windows security services (firewall, mse, defender) were not only not running but no longer installed. I ran msert.exe which found and tried to remove it, but the virus causes a reboot which prevents it. I also tried re-installing mse, which re-installed fine, but again, a reboot is forced whenever it tries to remove the viruses. I've already run Farbar and here are the results. If someone could help me get rid of this nasty sucker I'd be very appreciative.
Scan result of Farbar Recovery Scan Tool Version: 12-06-2012 02
Ran by SYSTEM at 13-06-2012 16:38:28
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [489472 2010-09-27] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2281256 2010-09-13] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2010-07-21] (Hewlett-Packard Company)
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [611896 2010-08-31] ()
HKLM\...\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1238528 2007-08-29] (Marvell Semiconductor, Inc.)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-09-09] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-24] (Intel Corporation)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [584760 2010-09-28] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Envy Guides AutoPlay] C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\hpdocstart.exe [76584 2010-03-24] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [QuickFinder Scheduler] "c:\Program Files (x86)\Corel\WordPerfect Office X5\Programs\QFSCHD150.EXE" [136600 2010-03-11] (Corel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [249064 2010-10-29] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-08-18] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKU\Shanda\...\Run: [Google Update] "C:\Users\Shanda\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-02-04] (Google Inc.)
HKU\Shanda\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4283256 2011-05-13] (Microsoft Corporation)
HKU\Shanda\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-10-31] (Google Inc.)
HKU\Shanda\...\Policies\system: [DisableChangePassword] 0
HKU\Shanda\...\Policies\system: [DisableLockWorkstation] 0
Winlogon\Notify\WB: C:\Program Files (x86)\Stardock\MyColors\fast64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 212.219.59.200 128.86.163.243 128.86.163.242
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Stardock MyColors.lnk
ShortcutTarget: Stardock MyColors.lnk -> C:\Program Files (x86)\Stardock\MyColors\SDDelayedLaunch.exe ()
Startup: C:\Users\Default\Start Menu\Programs\Startup\IconPackager.lnk
ShortcutTarget: IconPackager.lnk -> C:\Program Files (x86)\Stardock\MyColors\IconPackager.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\IconPackager.lnk
ShortcutTarget: IconPackager.lnk -> C:\Program Files (x86)\Stardock\MyColors\IconPackager.exe (Stardock Corporation)
Startup: C:\Users\Shanda\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 BBSvc; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [193816 2012-02-10] (Microsoft Corporation.)
3 BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [240408 2012-02-10] (Microsoft Corporation.)
3 hpdoccardsvc; C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\doccardsvc.exe [83240 2010-03-24] (Hewlett-Packard Developement Company, L.P.)
2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [26680 2010-09-28] (Hewlett-Packard Development Company, L.P.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PSI_SVC_2; "C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe" [185632 2007-07-24] (Protexis Inc.)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2533400 2010-06-08] (Intel Corporation)
2 WindowBlinds; C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe [x]
========================== Drivers (Whitelisted) =============
3 clwvd; C:\Windows\System32\Drivers\clwvd.sys [31088 2010-09-03] (CyberLink Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-13 16:38 - 2012-06-13 16:38 - 00000000 ____D C:\FRST
2012-06-13 06:55 - 2012-06-13 06:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 06:55 - 2012-06-13 06:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-13 06:54 - 2012-06-13 06:54 - 00000000 ____D C:\Users\Shanda\AppData\Local\{046CA43C-01A5-4DE5-80C3-6054BBE3B799}
2012-06-13 05:17 - 2012-06-13 05:18 - 00129876 ____A C:\TDSSKiller.2.7.36.0_13.06.2012_14.17.32_log.txt
2012-06-13 05:14 - 2012-06-13 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4199608C-58B5-4368-82EF-ADA59202A938}
2012-06-13 04:34 - 2012-06-13 04:34 - 00000000 ____D C:\Users\Shanda\AppData\Local\{45118442-DA19-416C-AAB5-143EE590C551}
2012-06-13 03:16 - 2012-06-13 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\{8C728621-0DC2-451F-86DD-0C6F49201020}
2012-06-13 03:16 - 2012-06-13 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\{3781C47E-93E0-4E1A-976C-3EF780180CF5}
2012-06-13 03:09 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 03:09 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 03:09 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 03:09 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-13 03:09 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 03:09 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 03:09 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 03:09 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 03:09 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 03:09 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 03:09 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 03:09 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-13 03:09 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 03:09 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 03:09 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 03:09 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 03:08 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 03:08 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 03:08 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-13 03:08 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-13 03:08 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 03:08 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-13 03:08 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 03:08 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 03:08 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-13 03:08 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-13 03:08 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 03:08 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-13 03:08 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 03:08 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 03:08 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 03:08 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 03:08 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 03:08 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 03:08 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 03:08 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 03:08 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 03:08 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 03:08 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 03:08 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 03:08 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 03:08 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 03:08 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 03:08 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 03:08 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-13 02:52 - 2012-06-13 02:52 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-30 10:57 - 2012-05-30 10:58 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9FF0D113-9003-4154-8964-BCAA74FBFC57}
2012-05-30 10:57 - 2012-05-30 10:57 - 00000000 ____D C:\Users\Shanda\AppData\Local\{ED8CF29B-2085-4FA9-BEAF-562961C396D7}
2012-05-30 05:14 - 2012-05-30 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9B60843C-2753-4C96-A09F-D685BAE06254}
2012-05-30 05:13 - 2012-05-30 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B04EDE55-9F86-40B7-8F4F-90E9B6032937}
2012-05-22 23:45 - 2012-05-22 23:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BC08353C-C1B4-49C0-9F20-F1A7E703E1FE}
2012-05-22 23:45 - 2012-05-22 23:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{1D90F50A-97DE-4BBD-8DEA-F57C4DD92334}
2012-05-22 06:11 - 2012-05-22 06:11 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BDD7EF5F-ED1B-4089-9574-A46C540B2533}
2012-05-20 11:40 - 2012-05-20 11:40 - 00061952 ____A C:\Users\Shanda\Downloads\922.doc
2012-05-19 02:43 - 2012-05-19 02:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{5B1A7192-9E09-442F-9E6A-621347D4540B}
2012-05-19 02:43 - 2012-05-19 02:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0F772551-3521-4EA0-8246-D6357F0818A0}
2012-05-18 06:05 - 2012-05-18 06:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9E300797-CD87-4B5D-9BD9-92356F908124}
2012-05-18 06:04 - 2012-05-18 06:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{E3030066-8C30-4EA4-BDC1-63EC1E3ABEE5}
2012-05-18 01:57 - 2012-05-18 01:57 - 00332075 ____A C:\Users\Shanda\Downloads\8878_ICSIDAnnulmentAwardsthefourthgeneration_d3[1].pdf
2012-05-18 01:03 - 2012-05-18 01:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0A857770-5615-4130-BE43-9C65927C70E2}
2012-05-18 01:02 - 2012-05-18 01:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C258C946-4F58-4167-8E01-E84B42D75FE9}
2012-05-18 01:01 - 2012-05-18 01:01 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B8B38AFB-6763-43BA-9A09-7AFDC4AB5891}
2012-05-18 01:00 - 2012-05-18 01:01 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C2651A90-B285-482E-91AC-B9FAF0AAC18B}
2012-05-14 12:30 - 2012-05-29 05:49 - 00010956 ____A C:\Users\Shanda\Desktop\beach trip planning.docx
============ 3 Months Modified Files and Folders =============
2012-06-13 16:38 - 2012-06-13 16:38 - 00000000 ____D C:\FRST
2012-06-13 07:06 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-13 07:06 - 2009-07-13 20:51 - 00051128 ____A C:\Windows\setupact.log
2012-06-13 07:02 - 2011-07-28 09:55 - 00516384 ____A C:\Windows\ntbtlog.txt
2012-06-13 07:00 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-13 07:00 - 2009-07-13 20:45 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-13 07:00 - 2009-07-13 20:45 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-13 06:55 - 2012-06-13 06:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 06:55 - 2012-06-13 06:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-13 06:55 - 2011-02-04 16:38 - 00744030 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-13 06:55 - 2011-02-04 16:38 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-13 06:55 - 2011-02-04 14:11 - 01359539 ____A C:\Windows\WindowsUpdate.log
2012-06-13 06:54 - 2012-06-13 06:54 - 00000000 ____D C:\Users\Shanda\AppData\Local\{046CA43C-01A5-4DE5-80C3-6054BBE3B799}
2012-06-13 06:53 - 2011-10-31 06:26 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-13 06:53 - 2011-02-04 18:41 - 00000000 ____D C:\Users\Shanda\Tracing
2012-06-13 06:44 - 2011-02-04 17:44 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1159001608-2695117915-1753991618-1000UA.job
2012-06-13 06:44 - 2011-02-04 17:44 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1159001608-2695117915-1753991618-1000Core.job
2012-06-13 05:51 - 2011-10-31 06:26 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-13 05:43 - 2012-04-23 02:47 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-13 05:18 - 2012-06-13 05:17 - 00129876 ____A C:\TDSSKiller.2.7.36.0_13.06.2012_14.17.32_log.txt
2012-06-13 05:14 - 2012-06-13 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4199608C-58B5-4368-82EF-ADA59202A938}
2012-06-13 04:55 - 2012-01-11 06:22 - 00000000 __SHD C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}
2012-06-13 04:34 - 2012-06-13 04:34 - 00000000 ____D C:\Users\Shanda\AppData\Local\{45118442-DA19-416C-AAB5-143EE590C551}
2012-06-13 04:33 - 2011-02-04 15:04 - 00017462 ____A C:\Windows\PFRO.log
2012-06-13 03:33 - 2011-02-07 08:40 - 00000000 ____D C:\Users\Shanda\AppData\Local\ElevatedDiagnostics
2012-06-13 03:16 - 2012-06-13 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\{8C728621-0DC2-451F-86DD-0C6F49201020}
2012-06-13 03:16 - 2012-06-13 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\{3781C47E-93E0-4E1A-976C-3EF780180CF5}
2012-06-13 03:16 - 2012-04-23 02:47 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-13 03:16 - 2011-05-14 04:49 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-13 03:15 - 2009-07-13 20:45 - 00328048 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 03:12 - 2011-02-04 14:57 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-13 02:52 - 2012-06-13 02:52 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-13 02:22 - 2011-11-21 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Roaming\Spotify
2012-06-13 02:22 - 2011-11-21 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\Spotify
2012-05-30 10:58 - 2012-05-30 10:57 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9FF0D113-9003-4154-8964-BCAA74FBFC57}
2012-05-30 10:57 - 2012-05-30 10:57 - 00000000 ____D C:\Users\Shanda\AppData\Local\{ED8CF29B-2085-4FA9-BEAF-562961C396D7}
2012-05-30 05:14 - 2012-05-30 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9B60843C-2753-4C96-A09F-D685BAE06254}
2012-05-30 05:14 - 2012-05-30 05:13 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B04EDE55-9F86-40B7-8F4F-90E9B6032937}
2012-05-29 05:49 - 2012-05-14 12:30 - 00010956 ____A C:\Users\Shanda\Desktop\beach trip planning.docx
2012-05-22 23:45 - 2012-05-22 23:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BC08353C-C1B4-49C0-9F20-F1A7E703E1FE}
2012-05-22 23:45 - 2012-05-22 23:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{1D90F50A-97DE-4BBD-8DEA-F57C4DD92334}
2012-05-22 06:21 - 2011-11-30 08:32 - 00000000 ____D C:\Users\Shanda\AppData\Roaming\Mozilla
2012-05-22 06:11 - 2012-05-22 06:11 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BDD7EF5F-ED1B-4089-9574-A46C540B2533}
2012-05-22 06:10 - 2009-07-13 21:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-20 11:40 - 2012-05-20 11:40 - 00061952 ____A C:\Users\Shanda\Downloads\922.doc
2012-05-19 02:43 - 2012-05-19 02:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{5B1A7192-9E09-442F-9E6A-621347D4540B}
2012-05-19 02:43 - 2012-05-19 02:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0F772551-3521-4EA0-8246-D6357F0818A0}
2012-05-18 06:05 - 2012-05-18 06:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9E300797-CD87-4B5D-9BD9-92356F908124}
2012-05-18 06:05 - 2012-05-18 06:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{E3030066-8C30-4EA4-BDC1-63EC1E3ABEE5}
2012-05-18 02:52 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-05-18 01:57 - 2012-05-18 01:57 - 00332075 ____A C:\Users\Shanda\Downloads\8878_ICSIDAnnulmentAwardsthefourthgeneration_d3[1].pdf
2012-05-18 01:03 - 2012-05-18 01:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0A857770-5615-4130-BE43-9C65927C70E2}
2012-05-18 01:03 - 2012-05-18 01:02 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C258C946-4F58-4167-8E01-E84B42D75FE9}
2012-05-18 01:01 - 2012-05-18 01:01 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B8B38AFB-6763-43BA-9A09-7AFDC4AB5891}
2012-05-18 01:01 - 2012-05-18 01:00 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C2651A90-B285-482E-91AC-B9FAF0AAC18B}
2012-05-17 18:47 - 2012-06-13 03:08 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 03:08 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 03:08 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 03:09 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 03:09 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 03:09 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:58 - 2012-06-13 03:08 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:56 - 2012-06-13 03:08 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 03:09 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:55 - 2012-06-13 03:08 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:54 - 2012-06-13 03:09 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 03:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 03:09 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 03:09 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 03:08 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 03:08 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 03:08 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 03:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 03:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:35 - 2012-06-13 03:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:33 - 2012-06-13 03:09 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 03:08 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 03:09 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:29 - 2012-06-13 03:08 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:27 - 2012-06-13 03:09 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 03:09 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 03:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 03:09 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-13 03:08 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-13 10:07 - 2012-05-13 10:06 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D747D09A-98F1-4B41-BF04-4133BCE97793}
2012-05-13 10:06 - 2012-05-13 10:06 - 00000000 ____D C:\Users\Shanda\AppData\Local\{08EA1959-D6B7-4940-A570-B9D273365F96}
2012-05-13 08:54 - 2011-02-04 16:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-13 08:37 - 2011-02-04 19:12 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-13 08:29 - 2009-07-13 23:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-12 06:04 - 2012-05-12 06:04 - 00048640 ____A C:\Users\Shanda\Downloads\434-10 (1).doc
2012-05-12 06:04 - 2012-05-12 06:04 - 00037888 ____A C:\Users\Shanda\Downloads\435-15.doc
2012-05-12 06:03 - 2012-05-12 06:03 - 00053248 ____A C:\Users\Shanda\Downloads\986.doc
2012-05-12 06:00 - 2012-05-12 06:00 - 00048640 ____A C:\Users\Shanda\Downloads\434-10.doc
2012-05-12 05:58 - 2012-05-12 05:58 - 00054784 ____A C:\Users\Shanda\Downloads\985.doc
2012-05-09 02:05 - 2012-05-09 02:05 - 00228237 ____A C:\Users\Shanda\Downloads\Image (3).jpg
2012-05-09 02:01 - 2012-05-09 02:00 - 00000000 ____D C:\Users\Shanda\AppData\Local\{DE81A086-F979-4CE4-A6ED-466ACBBB89BF}
2012-05-09 02:00 - 2012-05-09 02:00 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C87FF272-1FFE-49F6-B50A-6A71B587BECB}
2012-05-05 05:43 - 2012-05-05 05:43 - 08769696 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-05 05:43 - 2012-05-05 05:43 - 00000000 ____D C:\Windows\System32\Macromed
2012-05-04 08:47 - 2012-05-04 08:35 - 00033280 ____A C:\Users\Shanda\Documents\daniel's writing resume with shanda's design changes.doc
2012-05-04 08:43 - 2012-05-04 08:10 - 00036352 ____A C:\Users\Shanda\Documents\daniel's writing resume with shanda's comments.doc
2012-05-04 03:06 - 2012-06-13 03:08 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 03:08 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 03:08 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-13 03:08 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 11:36 - 2012-04-30 11:36 - 00092925 ____A C:\Users\Shanda\Downloads\photo (2).JPG
2012-04-27 19:55 - 2012-06-13 03:08 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 03:08 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 03:08 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 03:08 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 03:08 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 03:08 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 03:08 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 03:08 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 03:08 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 03:08 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-23 02:46 - 2012-04-23 02:46 - 00000000 ____D C:\Users\Shanda\AppData\Local\{7B1D9DFE-2B05-4F37-B2C2-5805131F1725}
2012-04-23 02:46 - 2011-02-04 20:50 - 00000000 ____D C:\Users\Shanda\AppData\Local\Windows Live
2012-04-12 14:03 - 2012-04-12 14:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{2DD13377-404D-4DCA-A803-E1A911D329CD}
2012-04-12 02:03 - 2012-04-12 02:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0671DA4F-ED7A-4AF1-B351-62E955AE8F00}
2012-04-11 14:03 - 2012-04-11 14:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0A940B44-04A9-453D-9D95-52D5B3855283}
2012-04-11 02:03 - 2012-04-11 02:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{513461EC-F20F-4851-AE91-67742F7858C4}
2012-04-10 14:03 - 2012-04-10 14:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{044C318D-2900-46B5-98B2-8D695FC38B7A}
2012-04-10 09:52 - 2012-04-10 09:52 - 00227650 ____A C:\Users\Shanda\Downloads\EvansEmergingIssuesIPChapter13GIs[1].pdf
2012-04-10 02:03 - 2012-04-10 02:01 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0A05F360-8898-443B-8A3A-9A797BD24373}
2012-04-09 12:56 - 2012-04-09 12:56 - 00000000 ____D C:\Users\Shanda\AppData\Local\{19536CF1-1162-49DC-8F8E-D79781FBBFFA}
2012-04-09 00:56 - 2012-04-09 00:56 - 00000000 ____D C:\Users\Shanda\AppData\Local\{2F1EF056-24A8-41A4-B9EB-E45AACA86E25}
2012-04-08 05:41 - 2012-04-08 05:39 - 00000000 ____D C:\Users\Shanda\AppData\Local\{22C7E72C-EF7B-4515-8699-7E1C7510E7F2}
2012-04-07 04:31 - 2012-06-13 03:08 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 03:08 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-06 01:43 - 2012-04-06 01:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{A987DF0B-B25E-4F33-A5DC-6698219C9C3A}
2012-04-05 13:43 - 2012-04-05 13:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{F7D43D66-BDF9-43C9-8DBE-4C1DAFF9D467}
2012-04-05 01:43 - 2012-04-05 01:42 - 00000000 ____D C:\Users\Shanda\AppData\Local\{206EDD34-4B40-471A-8DBE-6BDBD7674C7D}
2012-04-04 13:26 - 2012-04-04 13:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{F8137105-E793-491B-AF13-499F06CC455E}
2012-04-04 07:36 - 2012-04-04 07:36 - 00031234 ____A C:\Users\Shanda\Downloads\Bugs R Gone ad for San Pedro paper B&W with updated website.docx
2012-04-04 07:33 - 2012-02-13 06:31 - 00000000 ____D C:\Users\Shanda\Documents\Bugs R Gone
2012-04-04 01:26 - 2012-04-04 01:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{6E14EEEF-EC58-4ACA-ACE6-026FDF98DAC6}
2012-04-03 13:26 - 2012-04-03 13:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{09470178-3E00-42B7-B657-CDDECC77A2C3}
2012-04-03 09:06 - 2012-04-03 09:06 - 01872203 ____A C:\Users\Shanda\Downloads\27GaJIntlCompL309.pdf
2012-04-03 09:06 - 2012-04-03 09:06 - 01820856 ____A C:\Users\Shanda\Downloads\1999 Champagne or Champagne, US failure to comply with TRIPS GI.pdf
2012-04-03 01:26 - 2012-04-03 01:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{AEDC1230-A1DE-4961-ABAF-C164904D4083}
2012-04-02 13:02 - 2012-04-02 13:02 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B59FCBF4-E1C4-47B4-BD41-548B93E88E7C}
2012-04-02 09:37 - 2012-04-02 09:37 - 00590993 ____A C:\Users\Shanda\Downloads\59VandLRev873.pdf
2012-04-02 09:25 - 2012-04-02 09:25 - 00084920 ____A C:\Users\Shanda\Downloads\WLDoc 12-4-02 6_25 (PM).pdf
2012-04-02 07:55 - 2012-04-02 07:55 - 00114219 ____A C:\Users\Shanda\Downloads\WLDoc 12-4-02 4_55 (PM).pdf
2012-04-02 07:30 - 2012-04-02 07:30 - 04004832 ____A C:\Users\Shanda\Downloads\18FordhamIntellPropMediaE.pdf
2012-04-02 07:13 - 2012-04-02 07:13 - 01765501 ____A C:\Users\Shanda\Downloads\87JPatTrademarkOffSocy31.pdf
2012-04-02 07:10 - 2012-04-02 07:10 - 00284870 ____A C:\Users\Shanda\Downloads\SSRN-id922267.pdf
2012-04-02 07:07 - 2012-04-02 07:07 - 01860018 ____A C:\Users\Shanda\Downloads\19EmoryIntlLRev427.pdf
2012-04-02 06:59 - 2012-04-02 06:59 - 05917382 ____A C:\Users\Shanda\Downloads\58HastingsLJ299.pdf
2012-04-02 06:53 - 2012-04-02 06:53 - 01390207 ____A C:\Users\Shanda\Downloads\31AIPLAQJ129.pdf
2012-04-02 02:46 - 2012-04-02 02:46 - 00267264 ____A C:\Users\Shanda\Downloads\IPRComp.doc
2012-04-02 01:02 - 2012-04-02 01:02 - 00000000 ____D C:\Users\Shanda\AppData\Local\{06273224-E76B-47DD-97D7-3DC072F979F0}
2012-04-01 03:36 - 2012-04-01 03:35 - 00000000 ____D C:\Users\Shanda\AppData\Local\{53BE4C65-C1FE-4530-BE92-4263A453804B}
2012-03-31 08:55 - 2012-03-31 08:55 - 00136696 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-03-31 08:38 - 2012-03-31 08:38 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D2B41A9B-B54E-4521-8B4E-1DB44AA5AB36}
2012-03-30 04:06 - 2012-03-30 04:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{498D1D7C-D1B8-4E5F-851D-42E72D5AC2EF}
2012-03-30 03:35 - 2012-05-12 03:45 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-28 03:27 - 2012-03-28 03:27 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D7558927-50CB-4592-A24A-8031E0AEE55D}
2012-03-28 03:27 - 2012-03-28 03:27 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BDE33042-AFB6-4256-BA93-2DC101D798D7}
2012-03-27 01:14 - 2012-03-27 01:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BBD7ABF5-A3FD-4B4F-AF0D-3E551C6FDAA3}
2012-03-27 01:14 - 2012-03-27 01:13 - 00000000 ____D C:\Users\Shanda\AppData\Local\{A7163202-91F7-4298-A03D-77F256406E9E}
2012-03-26 13:13 - 2012-03-26 13:13 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B8D511AE-6DBF-4FBD-AF3B-2891109647B5}
2012-03-26 13:13 - 2012-03-26 13:13 - 00000000 ____D C:\Users\Shanda\AppData\Local\{1C6E09D5-5F40-43B3-B794-9713CEF1BAE9}
2012-03-26 07:36 - 2012-03-26 07:36 - 00000000 ____D C:\Users\Shanda\AppData\Local\{676E4C37-7E51-4889-85F3-009749881157}
2012-03-25 04:28 - 2012-03-25 04:28 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D071DE22-8C69-47C2-8E06-C26444D835F4}
2012-03-25 04:28 - 2012-03-25 04:28 - 00000000 ____D C:\Users\Shanda\AppData\Local\{A48FAD2D-7C6B-4A69-82E3-EE9990F30FB6}
2012-03-24 16:28 - 2012-03-24 16:28 - 00000000 ____D C:\Users\Shanda\AppData\Local\{CA224079-B7B6-452D-BE09-C9A455F53820}
2012-03-24 16:28 - 2012-03-24 16:27 - 00000000 ____D C:\Users\Shanda\AppData\Local\{A5631D6C-0014-47F0-89AF-293EF3EC2C9C}
2012-03-24 04:27 - 2012-03-24 04:27 - 00000000 ____D C:\Users\Shanda\AppData\Local\{40DD91E7-FC89-48A5-BF23-D23D5D03B7C5}
2012-03-24 04:27 - 2012-03-24 04:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{7E275334-EFE2-42FE-B532-196CCF7C3E20}
2012-03-23 16:23 - 2012-03-23 16:23 - 00000000 ____D C:\Users\Shanda\AppData\Local\{F0178BC8-54A4-4EA0-B94B-ABF5CC47B113}
2012-03-23 16:23 - 2012-03-23 16:22 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C7057FD7-86CE-4403-A7E4-6E3AFAF91EF0}
2012-03-23 04:23 - 2012-03-23 04:23 - 00000000 ____D C:\Users\Shanda\AppData\Local\{92936341-2076-415D-AAE6-91BD2F2BB331}
2012-03-22 02:38 - 2012-03-22 02:38 - 00000000 ____D C:\Users\Shanda\AppData\Local\{643BADBA-2082-4F92-8934-309C1F1E86F5}
2012-03-22 02:38 - 2012-03-22 02:38 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4909E4BB-9BA1-4343-AE69-CD656AA8F34C}
2012-03-21 03:22 - 2012-03-21 03:22 - 00000000 ____D C:\Users\Shanda\AppData\Local\{DD52CF20-C859-4B38-B52B-807469E58FC1}
2012-03-21 03:22 - 2012-03-21 03:21 - 00000000 ____D C:\Users\Shanda\AppData\Local\{DB417292-E85E-4065-9958-8240624B4045}
2012-03-20 14:37 - 2012-02-22 17:16 - 00013467 ____A C:\Users\Shanda\Desktop\Jobs to apply for.docx
2012-03-20 14:36 - 2012-03-20 03:29 - 00014554 ____A C:\Users\Shanda\Desktop\Fellowship opportunities.docx
2012-03-20 11:44 - 2012-03-20 11:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 11:44 - 2012-03-20 11:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-03-20 09:38 - 2012-03-20 09:38 - 00805634 ____A C:\Users\Shanda\Desktop\The Art of Writing Proposals.pdf
2012-03-20 07:19 - 2012-03-20 07:19 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D00831D0-DB1D-4534-8A54-57242C1C42F2}
2012-03-20 07:19 - 2012-03-20 07:18 - 00000000 ____D C:\Users\Shanda\AppData\Local\{225938C2-AE63-41DC-89FF-136C20608299}
2012-03-20 04:17 - 2012-03-20 04:17 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0678F3CC-DC71-4FB9-9406-85DE36C4C9D1}
2012-03-19 16:05 - 2012-03-19 16:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{F683441B-46EC-4488-AC41-A2FBD5605915}
2012-03-19 16:05 - 2012-03-19 16:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D6DA8827-B26A-4566-9878-58747E3BDA3C}
2012-03-19 04:05 - 2012-03-19 04:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{1C2CBD95-9A8A-4570-95C8-065D6D6056D7}
2012-03-19 04:05 - 2012-03-19 04:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{052DF173-933D-4C43-84F0-42555F2A28F9}
2012-03-18 16:04 - 2012-03-18 16:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{6C6DD760-A6E3-44F3-AC60-F25EF14C356B}
2012-03-18 16:04 - 2012-03-18 16:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{2CD1EBCE-6D9E-419E-8AF2-2911355163DF}
2012-03-18 11:50 - 2012-03-18 11:50 - 00076913 ____A C:\Users\Shanda\Downloads\WLDoc 12-3-18 7_50 (PM).pdf
2012-03-18 08:25 - 2012-03-18 08:25 - 08009831 ____A C:\Users\Shanda\Downloads\73FordhamLRev.pdf
2012-03-18 05:19 - 2012-03-18 05:19 - 02273552 ____A C:\Users\Shanda\Downloads\12UCDavisJIntlLPoly157.pdf
2012-03-18 05:14 - 2012-03-18 05:14 - 01246935 ____A C:\Users\Shanda\Downloads\91VaLRev.pdf
2012-03-18 04:33 - 2012-03-18 04:33 - 01299104 ____A C:\Users\Shanda\Downloads\68AmJIntlL51.pdf
2012-03-18 04:16 - 2012-03-18 04:16 - 01578547 ____A C:\Users\Shanda\Downloads\65AmJIntlL736.pdf
2012-03-18 04:04 - 2012-03-18 04:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{E130A3B3-718E-466B-8F57-E3BB17BBE0E7}
2012-03-18 04:04 - 2012-03-18 04:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C761532F-8D22-49FC-AE0F-046F89C3ABD0}
2012-03-17 16:04 - 2012-03-17 16:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{27C86A21-CFE9-47F9-B8F2-16FBB06EE0D2}
2012-03-17 16:03 - 2012-03-17 16:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4D2B652F-98A4-4BA9-8EA7-C551E96DF6E8}
2012-03-17 11:51 - 2012-03-17 11:51 - 00292086 ____A C:\Users\Shanda\Downloads\SSRN-id1935625.pdf
2012-03-17 07:44 - 2012-03-17 07:44 - 03258640 ____A C:\Users\Shanda\Downloads\34BrookJIntlL303.pdf
2012-03-17 04:03 - 2012-03-17 04:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{41EDFD98-AEDC-402C-B512-1852F61DB831}
2012-03-17 04:03 - 2012-03-17 04:02 - 00000000 ____D C:\Users\Shanda\AppData\Local\{3AAB4E44-6E2B-4A81-B4F3-0B262F7230A8}
2012-03-16 23:58 - 2012-05-12 03:46 - 00075120 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2012-03-16 07:11 - 2012-03-16 07:11 - 00000000 ____D C:\Users\Shanda\AppData\Local\{3FBC11AC-34E8-44F6-BC9F-BC53257B46DC}
2012-03-16 07:11 - 2012-03-16 07:10 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BF6329B7-D635-4509-A874-875651B40283}
2012-03-16 04:04 - 2012-03-16 04:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4C6F1B2C-8A4C-42F3-9531-C746FA14C6C0}
2012-03-16 02:45 - 2012-03-16 02:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{409AED73-E72C-46F7-AC40-4BEBAEFE3D37}
ZeroAccess:
C:\Windows\Installer\{d5481b92-9c76-c594-8dbe-ee9407b0f122}
C:\Windows\Installer\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\@
C:\Windows\Installer\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\L
C:\Windows\Installer\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\U
ZeroAccess:
C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}
C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\@
C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\L
C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 8125.61 MB
Available physical RAM: 7329.44 MB
Total Pagefile: 8123.76 MB
Available Pagefile: 7321.57 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.69 GB) (Free:12.63 GB) NTFS
3 Drive f: () (Removable) (Total:3.76 GB) (Free:3.52 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 111 GB 0 B
Disk 1 Online 3853 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 111 GB 101 MB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 111 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 3853 MB 0 B
======================================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
======================================================================================================
==========================================================
Last Boot: 2012-06-08 03:01
======================= End Of Log ==========================
https://www.techspot.com/community/topics/help-removing-trojan-win64-sirefef-y.181701/
https://www.techspot.com/community/topics/help-removing-trojan-win64-sirefef-y.181702/
My wife's computer seems to have caught this one. When she finally notified me it was acting funny, it noticed that all the windows security services (firewall, mse, defender) were not only not running but no longer installed. I ran msert.exe which found and tried to remove it, but the virus causes a reboot which prevents it. I also tried re-installing mse, which re-installed fine, but again, a reboot is forced whenever it tries to remove the viruses. I've already run Farbar and here are the results. If someone could help me get rid of this nasty sucker I'd be very appreciative.
Scan result of Farbar Recovery Scan Tool Version: 12-06-2012 02
Ran by SYSTEM at 13-06-2012 16:38:28
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [489472 2010-09-27] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2281256 2010-09-13] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2010-07-21] (Hewlett-Packard Company)
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [611896 2010-08-31] ()
HKLM\...\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1238528 2007-08-29] (Marvell Semiconductor, Inc.)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-09-09] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-24] (Intel Corporation)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [584760 2010-09-28] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Envy Guides AutoPlay] C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\hpdocstart.exe [76584 2010-03-24] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [QuickFinder Scheduler] "c:\Program Files (x86)\Corel\WordPerfect Office X5\Programs\QFSCHD150.EXE" [136600 2010-03-11] (Corel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [249064 2010-10-29] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-08-18] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKU\Shanda\...\Run: [Google Update] "C:\Users\Shanda\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-02-04] (Google Inc.)
HKU\Shanda\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4283256 2011-05-13] (Microsoft Corporation)
HKU\Shanda\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-10-31] (Google Inc.)
HKU\Shanda\...\Policies\system: [DisableChangePassword] 0
HKU\Shanda\...\Policies\system: [DisableLockWorkstation] 0
Winlogon\Notify\WB: C:\Program Files (x86)\Stardock\MyColors\fast64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 212.219.59.200 128.86.163.243 128.86.163.242
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Stardock MyColors.lnk
ShortcutTarget: Stardock MyColors.lnk -> C:\Program Files (x86)\Stardock\MyColors\SDDelayedLaunch.exe ()
Startup: C:\Users\Default\Start Menu\Programs\Startup\IconPackager.lnk
ShortcutTarget: IconPackager.lnk -> C:\Program Files (x86)\Stardock\MyColors\IconPackager.exe (Stardock Corporation)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\IconPackager.lnk
ShortcutTarget: IconPackager.lnk -> C:\Program Files (x86)\Stardock\MyColors\IconPackager.exe (Stardock Corporation)
Startup: C:\Users\Shanda\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 BBSvc; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [193816 2012-02-10] (Microsoft Corporation.)
3 BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [240408 2012-02-10] (Microsoft Corporation.)
3 hpdoccardsvc; C:\Program Files (x86)\Hewlett-Packard\HP ENVY Document Card Utilities\doccardsvc.exe [83240 2010-03-24] (Hewlett-Packard Developement Company, L.P.)
2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [26680 2010-09-28] (Hewlett-Packard Development Company, L.P.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PSI_SVC_2; "C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe" [185632 2007-07-24] (Protexis Inc.)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2533400 2010-06-08] (Intel Corporation)
2 WindowBlinds; C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe [x]
========================== Drivers (Whitelisted) =============
3 clwvd; C:\Windows\System32\Drivers\clwvd.sys [31088 2010-09-03] (CyberLink Corporation)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-13 16:38 - 2012-06-13 16:38 - 00000000 ____D C:\FRST
2012-06-13 06:55 - 2012-06-13 06:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 06:55 - 2012-06-13 06:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-13 06:54 - 2012-06-13 06:54 - 00000000 ____D C:\Users\Shanda\AppData\Local\{046CA43C-01A5-4DE5-80C3-6054BBE3B799}
2012-06-13 05:17 - 2012-06-13 05:18 - 00129876 ____A C:\TDSSKiller.2.7.36.0_13.06.2012_14.17.32_log.txt
2012-06-13 05:14 - 2012-06-13 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4199608C-58B5-4368-82EF-ADA59202A938}
2012-06-13 04:34 - 2012-06-13 04:34 - 00000000 ____D C:\Users\Shanda\AppData\Local\{45118442-DA19-416C-AAB5-143EE590C551}
2012-06-13 03:16 - 2012-06-13 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\{8C728621-0DC2-451F-86DD-0C6F49201020}
2012-06-13 03:16 - 2012-06-13 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\{3781C47E-93E0-4E1A-976C-3EF780180CF5}
2012-06-13 03:09 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 03:09 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 03:09 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 03:09 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-13 03:09 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 03:09 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 03:09 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 03:09 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 03:09 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 03:09 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 03:09 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 03:09 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-13 03:09 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 03:09 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 03:09 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 03:09 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-13 03:08 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 03:08 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 03:08 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-13 03:08 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-13 03:08 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 03:08 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-13 03:08 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 03:08 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 03:08 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-13 03:08 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-13 03:08 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 03:08 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-13 03:08 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-13 03:08 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-13 03:08 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-13 03:08 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-13 03:08 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-13 03:08 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-13 03:08 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-13 03:08 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-13 03:08 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-13 03:08 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-13 03:08 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-13 03:08 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-13 03:08 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-13 03:08 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-13 03:08 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-13 03:08 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-13 03:08 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-13 02:52 - 2012-06-13 02:52 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-05-30 10:57 - 2012-05-30 10:58 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9FF0D113-9003-4154-8964-BCAA74FBFC57}
2012-05-30 10:57 - 2012-05-30 10:57 - 00000000 ____D C:\Users\Shanda\AppData\Local\{ED8CF29B-2085-4FA9-BEAF-562961C396D7}
2012-05-30 05:14 - 2012-05-30 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9B60843C-2753-4C96-A09F-D685BAE06254}
2012-05-30 05:13 - 2012-05-30 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B04EDE55-9F86-40B7-8F4F-90E9B6032937}
2012-05-22 23:45 - 2012-05-22 23:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BC08353C-C1B4-49C0-9F20-F1A7E703E1FE}
2012-05-22 23:45 - 2012-05-22 23:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{1D90F50A-97DE-4BBD-8DEA-F57C4DD92334}
2012-05-22 06:11 - 2012-05-22 06:11 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BDD7EF5F-ED1B-4089-9574-A46C540B2533}
2012-05-20 11:40 - 2012-05-20 11:40 - 00061952 ____A C:\Users\Shanda\Downloads\922.doc
2012-05-19 02:43 - 2012-05-19 02:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{5B1A7192-9E09-442F-9E6A-621347D4540B}
2012-05-19 02:43 - 2012-05-19 02:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0F772551-3521-4EA0-8246-D6357F0818A0}
2012-05-18 06:05 - 2012-05-18 06:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9E300797-CD87-4B5D-9BD9-92356F908124}
2012-05-18 06:04 - 2012-05-18 06:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{E3030066-8C30-4EA4-BDC1-63EC1E3ABEE5}
2012-05-18 01:57 - 2012-05-18 01:57 - 00332075 ____A C:\Users\Shanda\Downloads\8878_ICSIDAnnulmentAwardsthefourthgeneration_d3[1].pdf
2012-05-18 01:03 - 2012-05-18 01:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0A857770-5615-4130-BE43-9C65927C70E2}
2012-05-18 01:02 - 2012-05-18 01:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C258C946-4F58-4167-8E01-E84B42D75FE9}
2012-05-18 01:01 - 2012-05-18 01:01 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B8B38AFB-6763-43BA-9A09-7AFDC4AB5891}
2012-05-18 01:00 - 2012-05-18 01:01 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C2651A90-B285-482E-91AC-B9FAF0AAC18B}
2012-05-14 12:30 - 2012-05-29 05:49 - 00010956 ____A C:\Users\Shanda\Desktop\beach trip planning.docx
============ 3 Months Modified Files and Folders =============
2012-06-13 16:38 - 2012-06-13 16:38 - 00000000 ____D C:\FRST
2012-06-13 07:06 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-13 07:06 - 2009-07-13 20:51 - 00051128 ____A C:\Windows\setupact.log
2012-06-13 07:02 - 2011-07-28 09:55 - 00516384 ____A C:\Windows\ntbtlog.txt
2012-06-13 07:00 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-13 07:00 - 2009-07-13 20:45 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-13 07:00 - 2009-07-13 20:45 - 00014816 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-13 06:55 - 2012-06-13 06:55 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-06-13 06:55 - 2012-06-13 06:55 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-06-13 06:55 - 2011-02-04 16:38 - 00744030 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-06-13 06:55 - 2011-02-04 16:38 - 00001945 ____A C:\Windows\epplauncher.mif
2012-06-13 06:55 - 2011-02-04 14:11 - 01359539 ____A C:\Windows\WindowsUpdate.log
2012-06-13 06:54 - 2012-06-13 06:54 - 00000000 ____D C:\Users\Shanda\AppData\Local\{046CA43C-01A5-4DE5-80C3-6054BBE3B799}
2012-06-13 06:53 - 2011-10-31 06:26 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-13 06:53 - 2011-02-04 18:41 - 00000000 ____D C:\Users\Shanda\Tracing
2012-06-13 06:44 - 2011-02-04 17:44 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1159001608-2695117915-1753991618-1000UA.job
2012-06-13 06:44 - 2011-02-04 17:44 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1159001608-2695117915-1753991618-1000Core.job
2012-06-13 05:51 - 2011-10-31 06:26 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-13 05:43 - 2012-04-23 02:47 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-13 05:18 - 2012-06-13 05:17 - 00129876 ____A C:\TDSSKiller.2.7.36.0_13.06.2012_14.17.32_log.txt
2012-06-13 05:14 - 2012-06-13 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4199608C-58B5-4368-82EF-ADA59202A938}
2012-06-13 04:55 - 2012-01-11 06:22 - 00000000 __SHD C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}
2012-06-13 04:34 - 2012-06-13 04:34 - 00000000 ____D C:\Users\Shanda\AppData\Local\{45118442-DA19-416C-AAB5-143EE590C551}
2012-06-13 04:33 - 2011-02-04 15:04 - 00017462 ____A C:\Windows\PFRO.log
2012-06-13 03:33 - 2011-02-07 08:40 - 00000000 ____D C:\Users\Shanda\AppData\Local\ElevatedDiagnostics
2012-06-13 03:16 - 2012-06-13 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\{8C728621-0DC2-451F-86DD-0C6F49201020}
2012-06-13 03:16 - 2012-06-13 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\{3781C47E-93E0-4E1A-976C-3EF780180CF5}
2012-06-13 03:16 - 2012-04-23 02:47 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-13 03:16 - 2011-05-14 04:49 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-13 03:15 - 2009-07-13 20:45 - 00328048 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 03:12 - 2011-02-04 14:57 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-13 02:52 - 2012-06-13 02:52 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-06-13 02:22 - 2011-11-21 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Roaming\Spotify
2012-06-13 02:22 - 2011-11-21 03:16 - 00000000 ____D C:\Users\Shanda\AppData\Local\Spotify
2012-05-30 10:58 - 2012-05-30 10:57 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9FF0D113-9003-4154-8964-BCAA74FBFC57}
2012-05-30 10:57 - 2012-05-30 10:57 - 00000000 ____D C:\Users\Shanda\AppData\Local\{ED8CF29B-2085-4FA9-BEAF-562961C396D7}
2012-05-30 05:14 - 2012-05-30 05:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9B60843C-2753-4C96-A09F-D685BAE06254}
2012-05-30 05:14 - 2012-05-30 05:13 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B04EDE55-9F86-40B7-8F4F-90E9B6032937}
2012-05-29 05:49 - 2012-05-14 12:30 - 00010956 ____A C:\Users\Shanda\Desktop\beach trip planning.docx
2012-05-22 23:45 - 2012-05-22 23:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BC08353C-C1B4-49C0-9F20-F1A7E703E1FE}
2012-05-22 23:45 - 2012-05-22 23:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{1D90F50A-97DE-4BBD-8DEA-F57C4DD92334}
2012-05-22 06:21 - 2011-11-30 08:32 - 00000000 ____D C:\Users\Shanda\AppData\Roaming\Mozilla
2012-05-22 06:11 - 2012-05-22 06:11 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BDD7EF5F-ED1B-4089-9574-A46C540B2533}
2012-05-22 06:10 - 2009-07-13 21:08 - 00032640 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-20 11:40 - 2012-05-20 11:40 - 00061952 ____A C:\Users\Shanda\Downloads\922.doc
2012-05-19 02:43 - 2012-05-19 02:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{5B1A7192-9E09-442F-9E6A-621347D4540B}
2012-05-19 02:43 - 2012-05-19 02:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0F772551-3521-4EA0-8246-D6357F0818A0}
2012-05-18 06:05 - 2012-05-18 06:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{9E300797-CD87-4B5D-9BD9-92356F908124}
2012-05-18 06:05 - 2012-05-18 06:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{E3030066-8C30-4EA4-BDC1-63EC1E3ABEE5}
2012-05-18 02:52 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-05-18 01:57 - 2012-05-18 01:57 - 00332075 ____A C:\Users\Shanda\Downloads\8878_ICSIDAnnulmentAwardsthefourthgeneration_d3[1].pdf
2012-05-18 01:03 - 2012-05-18 01:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0A857770-5615-4130-BE43-9C65927C70E2}
2012-05-18 01:03 - 2012-05-18 01:02 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C258C946-4F58-4167-8E01-E84B42D75FE9}
2012-05-18 01:01 - 2012-05-18 01:01 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B8B38AFB-6763-43BA-9A09-7AFDC4AB5891}
2012-05-18 01:01 - 2012-05-18 01:00 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C2651A90-B285-482E-91AC-B9FAF0AAC18B}
2012-05-17 18:47 - 2012-06-13 03:08 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 03:08 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 03:08 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 03:09 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 03:09 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 03:09 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:58 - 2012-06-13 03:08 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:56 - 2012-06-13 03:08 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 03:09 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:55 - 2012-06-13 03:08 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:54 - 2012-06-13 03:09 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 03:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 03:09 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 03:09 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 15:11 - 2012-06-13 03:08 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 03:08 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 03:08 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 03:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 03:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:35 - 2012-06-13 03:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:33 - 2012-06-13 03:09 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 03:08 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 03:09 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:29 - 2012-06-13 03:08 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:27 - 2012-06-13 03:09 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 03:09 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 03:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 03:09 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-14 17:32 - 2012-06-13 03:08 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-13 10:07 - 2012-05-13 10:06 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D747D09A-98F1-4B41-BF04-4133BCE97793}
2012-05-13 10:06 - 2012-05-13 10:06 - 00000000 ____D C:\Users\Shanda\AppData\Local\{08EA1959-D6B7-4940-A570-B9D273365F96}
2012-05-13 08:54 - 2011-02-04 16:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-13 08:37 - 2011-02-04 19:12 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-13 08:29 - 2009-07-13 23:45 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-12 06:04 - 2012-05-12 06:04 - 00048640 ____A C:\Users\Shanda\Downloads\434-10 (1).doc
2012-05-12 06:04 - 2012-05-12 06:04 - 00037888 ____A C:\Users\Shanda\Downloads\435-15.doc
2012-05-12 06:03 - 2012-05-12 06:03 - 00053248 ____A C:\Users\Shanda\Downloads\986.doc
2012-05-12 06:00 - 2012-05-12 06:00 - 00048640 ____A C:\Users\Shanda\Downloads\434-10.doc
2012-05-12 05:58 - 2012-05-12 05:58 - 00054784 ____A C:\Users\Shanda\Downloads\985.doc
2012-05-09 02:05 - 2012-05-09 02:05 - 00228237 ____A C:\Users\Shanda\Downloads\Image (3).jpg
2012-05-09 02:01 - 2012-05-09 02:00 - 00000000 ____D C:\Users\Shanda\AppData\Local\{DE81A086-F979-4CE4-A6ED-466ACBBB89BF}
2012-05-09 02:00 - 2012-05-09 02:00 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C87FF272-1FFE-49F6-B50A-6A71B587BECB}
2012-05-05 05:43 - 2012-05-05 05:43 - 08769696 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-05 05:43 - 2012-05-05 05:43 - 00000000 ____D C:\Windows\System32\Macromed
2012-05-04 08:47 - 2012-05-04 08:35 - 00033280 ____A C:\Users\Shanda\Documents\daniel's writing resume with shanda's design changes.doc
2012-05-04 08:43 - 2012-05-04 08:10 - 00036352 ____A C:\Users\Shanda\Documents\daniel's writing resume with shanda's comments.doc
2012-05-04 03:06 - 2012-06-13 03:08 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 03:08 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 03:08 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-13 03:08 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-30 11:36 - 2012-04-30 11:36 - 00092925 ____A C:\Users\Shanda\Downloads\photo (2).JPG
2012-04-27 19:55 - 2012-06-13 03:08 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 03:08 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 03:08 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 03:08 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 03:08 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 03:08 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 03:08 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 03:08 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 03:08 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 03:08 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-23 02:46 - 2012-04-23 02:46 - 00000000 ____D C:\Users\Shanda\AppData\Local\{7B1D9DFE-2B05-4F37-B2C2-5805131F1725}
2012-04-23 02:46 - 2011-02-04 20:50 - 00000000 ____D C:\Users\Shanda\AppData\Local\Windows Live
2012-04-12 14:03 - 2012-04-12 14:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{2DD13377-404D-4DCA-A803-E1A911D329CD}
2012-04-12 02:03 - 2012-04-12 02:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0671DA4F-ED7A-4AF1-B351-62E955AE8F00}
2012-04-11 14:03 - 2012-04-11 14:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0A940B44-04A9-453D-9D95-52D5B3855283}
2012-04-11 02:03 - 2012-04-11 02:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{513461EC-F20F-4851-AE91-67742F7858C4}
2012-04-10 14:03 - 2012-04-10 14:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{044C318D-2900-46B5-98B2-8D695FC38B7A}
2012-04-10 09:52 - 2012-04-10 09:52 - 00227650 ____A C:\Users\Shanda\Downloads\EvansEmergingIssuesIPChapter13GIs[1].pdf
2012-04-10 02:03 - 2012-04-10 02:01 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0A05F360-8898-443B-8A3A-9A797BD24373}
2012-04-09 12:56 - 2012-04-09 12:56 - 00000000 ____D C:\Users\Shanda\AppData\Local\{19536CF1-1162-49DC-8F8E-D79781FBBFFA}
2012-04-09 00:56 - 2012-04-09 00:56 - 00000000 ____D C:\Users\Shanda\AppData\Local\{2F1EF056-24A8-41A4-B9EB-E45AACA86E25}
2012-04-08 05:41 - 2012-04-08 05:39 - 00000000 ____D C:\Users\Shanda\AppData\Local\{22C7E72C-EF7B-4515-8699-7E1C7510E7F2}
2012-04-07 04:31 - 2012-06-13 03:08 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-13 03:08 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-06 01:43 - 2012-04-06 01:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{A987DF0B-B25E-4F33-A5DC-6698219C9C3A}
2012-04-05 13:43 - 2012-04-05 13:43 - 00000000 ____D C:\Users\Shanda\AppData\Local\{F7D43D66-BDF9-43C9-8DBE-4C1DAFF9D467}
2012-04-05 01:43 - 2012-04-05 01:42 - 00000000 ____D C:\Users\Shanda\AppData\Local\{206EDD34-4B40-471A-8DBE-6BDBD7674C7D}
2012-04-04 13:26 - 2012-04-04 13:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{F8137105-E793-491B-AF13-499F06CC455E}
2012-04-04 07:36 - 2012-04-04 07:36 - 00031234 ____A C:\Users\Shanda\Downloads\Bugs R Gone ad for San Pedro paper B&W with updated website.docx
2012-04-04 07:33 - 2012-02-13 06:31 - 00000000 ____D C:\Users\Shanda\Documents\Bugs R Gone
2012-04-04 01:26 - 2012-04-04 01:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{6E14EEEF-EC58-4ACA-ACE6-026FDF98DAC6}
2012-04-03 13:26 - 2012-04-03 13:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{09470178-3E00-42B7-B657-CDDECC77A2C3}
2012-04-03 09:06 - 2012-04-03 09:06 - 01872203 ____A C:\Users\Shanda\Downloads\27GaJIntlCompL309.pdf
2012-04-03 09:06 - 2012-04-03 09:06 - 01820856 ____A C:\Users\Shanda\Downloads\1999 Champagne or Champagne, US failure to comply with TRIPS GI.pdf
2012-04-03 01:26 - 2012-04-03 01:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{AEDC1230-A1DE-4961-ABAF-C164904D4083}
2012-04-02 13:02 - 2012-04-02 13:02 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B59FCBF4-E1C4-47B4-BD41-548B93E88E7C}
2012-04-02 09:37 - 2012-04-02 09:37 - 00590993 ____A C:\Users\Shanda\Downloads\59VandLRev873.pdf
2012-04-02 09:25 - 2012-04-02 09:25 - 00084920 ____A C:\Users\Shanda\Downloads\WLDoc 12-4-02 6_25 (PM).pdf
2012-04-02 07:55 - 2012-04-02 07:55 - 00114219 ____A C:\Users\Shanda\Downloads\WLDoc 12-4-02 4_55 (PM).pdf
2012-04-02 07:30 - 2012-04-02 07:30 - 04004832 ____A C:\Users\Shanda\Downloads\18FordhamIntellPropMediaE.pdf
2012-04-02 07:13 - 2012-04-02 07:13 - 01765501 ____A C:\Users\Shanda\Downloads\87JPatTrademarkOffSocy31.pdf
2012-04-02 07:10 - 2012-04-02 07:10 - 00284870 ____A C:\Users\Shanda\Downloads\SSRN-id922267.pdf
2012-04-02 07:07 - 2012-04-02 07:07 - 01860018 ____A C:\Users\Shanda\Downloads\19EmoryIntlLRev427.pdf
2012-04-02 06:59 - 2012-04-02 06:59 - 05917382 ____A C:\Users\Shanda\Downloads\58HastingsLJ299.pdf
2012-04-02 06:53 - 2012-04-02 06:53 - 01390207 ____A C:\Users\Shanda\Downloads\31AIPLAQJ129.pdf
2012-04-02 02:46 - 2012-04-02 02:46 - 00267264 ____A C:\Users\Shanda\Downloads\IPRComp.doc
2012-04-02 01:02 - 2012-04-02 01:02 - 00000000 ____D C:\Users\Shanda\AppData\Local\{06273224-E76B-47DD-97D7-3DC072F979F0}
2012-04-01 03:36 - 2012-04-01 03:35 - 00000000 ____D C:\Users\Shanda\AppData\Local\{53BE4C65-C1FE-4530-BE92-4263A453804B}
2012-03-31 08:55 - 2012-03-31 08:55 - 00136696 ___AH C:\Windows\SysWOW64\mlfcache.dat
2012-03-31 08:38 - 2012-03-31 08:38 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D2B41A9B-B54E-4521-8B4E-1DB44AA5AB36}
2012-03-30 04:06 - 2012-03-30 04:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{498D1D7C-D1B8-4E5F-851D-42E72D5AC2EF}
2012-03-30 03:35 - 2012-05-12 03:45 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-28 03:27 - 2012-03-28 03:27 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D7558927-50CB-4592-A24A-8031E0AEE55D}
2012-03-28 03:27 - 2012-03-28 03:27 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BDE33042-AFB6-4256-BA93-2DC101D798D7}
2012-03-27 01:14 - 2012-03-27 01:14 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BBD7ABF5-A3FD-4B4F-AF0D-3E551C6FDAA3}
2012-03-27 01:14 - 2012-03-27 01:13 - 00000000 ____D C:\Users\Shanda\AppData\Local\{A7163202-91F7-4298-A03D-77F256406E9E}
2012-03-26 13:13 - 2012-03-26 13:13 - 00000000 ____D C:\Users\Shanda\AppData\Local\{B8D511AE-6DBF-4FBD-AF3B-2891109647B5}
2012-03-26 13:13 - 2012-03-26 13:13 - 00000000 ____D C:\Users\Shanda\AppData\Local\{1C6E09D5-5F40-43B3-B794-9713CEF1BAE9}
2012-03-26 07:36 - 2012-03-26 07:36 - 00000000 ____D C:\Users\Shanda\AppData\Local\{676E4C37-7E51-4889-85F3-009749881157}
2012-03-25 04:28 - 2012-03-25 04:28 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D071DE22-8C69-47C2-8E06-C26444D835F4}
2012-03-25 04:28 - 2012-03-25 04:28 - 00000000 ____D C:\Users\Shanda\AppData\Local\{A48FAD2D-7C6B-4A69-82E3-EE9990F30FB6}
2012-03-24 16:28 - 2012-03-24 16:28 - 00000000 ____D C:\Users\Shanda\AppData\Local\{CA224079-B7B6-452D-BE09-C9A455F53820}
2012-03-24 16:28 - 2012-03-24 16:27 - 00000000 ____D C:\Users\Shanda\AppData\Local\{A5631D6C-0014-47F0-89AF-293EF3EC2C9C}
2012-03-24 04:27 - 2012-03-24 04:27 - 00000000 ____D C:\Users\Shanda\AppData\Local\{40DD91E7-FC89-48A5-BF23-D23D5D03B7C5}
2012-03-24 04:27 - 2012-03-24 04:26 - 00000000 ____D C:\Users\Shanda\AppData\Local\{7E275334-EFE2-42FE-B532-196CCF7C3E20}
2012-03-23 16:23 - 2012-03-23 16:23 - 00000000 ____D C:\Users\Shanda\AppData\Local\{F0178BC8-54A4-4EA0-B94B-ABF5CC47B113}
2012-03-23 16:23 - 2012-03-23 16:22 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C7057FD7-86CE-4403-A7E4-6E3AFAF91EF0}
2012-03-23 04:23 - 2012-03-23 04:23 - 00000000 ____D C:\Users\Shanda\AppData\Local\{92936341-2076-415D-AAE6-91BD2F2BB331}
2012-03-22 02:38 - 2012-03-22 02:38 - 00000000 ____D C:\Users\Shanda\AppData\Local\{643BADBA-2082-4F92-8934-309C1F1E86F5}
2012-03-22 02:38 - 2012-03-22 02:38 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4909E4BB-9BA1-4343-AE69-CD656AA8F34C}
2012-03-21 03:22 - 2012-03-21 03:22 - 00000000 ____D C:\Users\Shanda\AppData\Local\{DD52CF20-C859-4B38-B52B-807469E58FC1}
2012-03-21 03:22 - 2012-03-21 03:21 - 00000000 ____D C:\Users\Shanda\AppData\Local\{DB417292-E85E-4065-9958-8240624B4045}
2012-03-20 14:37 - 2012-02-22 17:16 - 00013467 ____A C:\Users\Shanda\Desktop\Jobs to apply for.docx
2012-03-20 14:36 - 2012-03-20 03:29 - 00014554 ____A C:\Users\Shanda\Desktop\Fellowship opportunities.docx
2012-03-20 11:44 - 2012-03-20 11:44 - 00203888 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\MpFilter.sys
2012-03-20 11:44 - 2012-03-20 11:44 - 00098688 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\NisDrvWFP.sys
2012-03-20 09:38 - 2012-03-20 09:38 - 00805634 ____A C:\Users\Shanda\Desktop\The Art of Writing Proposals.pdf
2012-03-20 07:19 - 2012-03-20 07:19 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D00831D0-DB1D-4534-8A54-57242C1C42F2}
2012-03-20 07:19 - 2012-03-20 07:18 - 00000000 ____D C:\Users\Shanda\AppData\Local\{225938C2-AE63-41DC-89FF-136C20608299}
2012-03-20 04:17 - 2012-03-20 04:17 - 00000000 ____D C:\Users\Shanda\AppData\Local\{0678F3CC-DC71-4FB9-9406-85DE36C4C9D1}
2012-03-19 16:05 - 2012-03-19 16:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{F683441B-46EC-4488-AC41-A2FBD5605915}
2012-03-19 16:05 - 2012-03-19 16:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{D6DA8827-B26A-4566-9878-58747E3BDA3C}
2012-03-19 04:05 - 2012-03-19 04:05 - 00000000 ____D C:\Users\Shanda\AppData\Local\{1C2CBD95-9A8A-4570-95C8-065D6D6056D7}
2012-03-19 04:05 - 2012-03-19 04:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{052DF173-933D-4C43-84F0-42555F2A28F9}
2012-03-18 16:04 - 2012-03-18 16:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{6C6DD760-A6E3-44F3-AC60-F25EF14C356B}
2012-03-18 16:04 - 2012-03-18 16:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{2CD1EBCE-6D9E-419E-8AF2-2911355163DF}
2012-03-18 11:50 - 2012-03-18 11:50 - 00076913 ____A C:\Users\Shanda\Downloads\WLDoc 12-3-18 7_50 (PM).pdf
2012-03-18 08:25 - 2012-03-18 08:25 - 08009831 ____A C:\Users\Shanda\Downloads\73FordhamLRev.pdf
2012-03-18 05:19 - 2012-03-18 05:19 - 02273552 ____A C:\Users\Shanda\Downloads\12UCDavisJIntlLPoly157.pdf
2012-03-18 05:14 - 2012-03-18 05:14 - 01246935 ____A C:\Users\Shanda\Downloads\91VaLRev.pdf
2012-03-18 04:33 - 2012-03-18 04:33 - 01299104 ____A C:\Users\Shanda\Downloads\68AmJIntlL51.pdf
2012-03-18 04:16 - 2012-03-18 04:16 - 01578547 ____A C:\Users\Shanda\Downloads\65AmJIntlL736.pdf
2012-03-18 04:04 - 2012-03-18 04:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{E130A3B3-718E-466B-8F57-E3BB17BBE0E7}
2012-03-18 04:04 - 2012-03-18 04:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{C761532F-8D22-49FC-AE0F-046F89C3ABD0}
2012-03-17 16:04 - 2012-03-17 16:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{27C86A21-CFE9-47F9-B8F2-16FBB06EE0D2}
2012-03-17 16:03 - 2012-03-17 16:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4D2B652F-98A4-4BA9-8EA7-C551E96DF6E8}
2012-03-17 11:51 - 2012-03-17 11:51 - 00292086 ____A C:\Users\Shanda\Downloads\SSRN-id1935625.pdf
2012-03-17 07:44 - 2012-03-17 07:44 - 03258640 ____A C:\Users\Shanda\Downloads\34BrookJIntlL303.pdf
2012-03-17 04:03 - 2012-03-17 04:03 - 00000000 ____D C:\Users\Shanda\AppData\Local\{41EDFD98-AEDC-402C-B512-1852F61DB831}
2012-03-17 04:03 - 2012-03-17 04:02 - 00000000 ____D C:\Users\Shanda\AppData\Local\{3AAB4E44-6E2B-4A81-B4F3-0B262F7230A8}
2012-03-16 23:58 - 2012-05-12 03:46 - 00075120 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2012-03-16 07:11 - 2012-03-16 07:11 - 00000000 ____D C:\Users\Shanda\AppData\Local\{3FBC11AC-34E8-44F6-BC9F-BC53257B46DC}
2012-03-16 07:11 - 2012-03-16 07:10 - 00000000 ____D C:\Users\Shanda\AppData\Local\{BF6329B7-D635-4509-A874-875651B40283}
2012-03-16 04:04 - 2012-03-16 04:04 - 00000000 ____D C:\Users\Shanda\AppData\Local\{4C6F1B2C-8A4C-42F3-9531-C746FA14C6C0}
2012-03-16 02:45 - 2012-03-16 02:45 - 00000000 ____D C:\Users\Shanda\AppData\Local\{409AED73-E72C-46F7-AC40-4BEBAEFE3D37}
ZeroAccess:
C:\Windows\Installer\{d5481b92-9c76-c594-8dbe-ee9407b0f122}
C:\Windows\Installer\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\@
C:\Windows\Installer\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\L
C:\Windows\Installer\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\U
ZeroAccess:
C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}
C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\@
C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\L
C:\Users\Shanda\AppData\Local\{d5481b92-9c76-c594-8dbe-ee9407b0f122}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 8125.61 MB
Available physical RAM: 7329.44 MB
Total Pagefile: 8123.76 MB
Available Pagefile: 7321.57 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:111.69 GB) (Free:12.63 GB) NTFS
3 Drive f: () (Removable) (Total:3.76 GB) (Free:3.52 GB) FAT32
4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
5 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 111 GB 0 B
Disk 1 Online 3853 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 111 GB 101 MB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 111 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 3853 MB 0 B
======================================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
======================================================================================================
==========================================================
Last Boot: 2012-06-08 03:01
======================= End Of Log ==========================