Kevin Wynne
Posts: 8 +0
Running Windows 7 Home Premium 64-bit...
I've read through the forums and have already run the Farbar Recovery Scan Tool. Here's the log file...
Scan result of Farbar Recovery Scan Tool Version: 11-07-2012
Ran by SYSTEM at 10-08-2012 04:23:01
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 [2278504 2011-10-13] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE" [3331312 2011-10-17] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-21] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS)
HKLM-x32\...\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [180224 2009-03-15] (PowerISO Computing, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [623880 2008-11-18] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin [611712 2012-05-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [40376 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640440 2012-03-26] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448 2011-09-01] (Research In Motion Limited)
HKLM-x32\...\Run: [PelAstro] C:\ProgramData\HP Wi-Fi Mobile Mouse Config\PelAstro.exe [65536 2011-01-14] (Primax Electronics Ltd.)
HKLM-x32\...\Run: [HPMonitor] C:\Program Files (x86)\Hewlett-Packard\HP Wi-Fi Mobile Mouse\hpMonitor23.exe [99328 2011-04-27] (Hewlett-Packard)
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [240112 2009-07-24] (Sonic Solutions)
HKLM-x32\...\Run: [CPMonitor] "C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe" [84464 2009-07-21] ()
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [494064 2009-06-22] ()
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Kev laptop\...\Run: [Google Update] "C:\Users\Kev laptop\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-05-17] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\EFI ES-1000.lnk
ShortcutTarget: EFI ES-1000.lnk -> C:\Program Files (x86)\Common Files\EFI\EFI ES-1000 Service\ES1000Notifier.exe (Electronics for Imaging, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Fiery Command WorkStation 5.lnk
ShortcutTarget: Fiery Command WorkStation 5.lnk -> C:\Program Files (x86)\Fiery\Applications3\Command WorkStation 5\Contents\WinOS\cws.exe (Electronics for Imaging, Inc)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Canada ULC.)
==================== Services (Whitelisted) ======
2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [457200 2009-06-02] ()
2 ASLDRService; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
2 AstroS; C:\ProgramData\HP Wi-Fi Mobile Mouse Config\AstroS.exe [172032 2010-12-01] ()
2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-15] (ASUS)
2 EFI ES1000; C:\Program Files (x86)\Common Files\EFI\EFI ES-1000 Service\ES1000Service.exe [11776 2009-10-19] (Electronics for Imaging, Inc.)
3 hasplms; C:\Windows\system32\hasplms.exe -run [4180576 2010-09-27] (SafeNet Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 ozwpansvc; C:\Program Files\Ozmo Devices\ozwpansvc.exe [77080 2011-04-29] (Ozmo Inc)
========================== Drivers (Whitelisted) =============
3 AiCharger; C:\Windows\System32\Drivers\AiCharger.sys [17152 2011-10-14] (ASUSTek Computer Inc.)
3 AiCharger; C:\Windows\SysWow64\Drivers\AiCharger.sys [17152 2011-10-14] (ASUSTek Computer Inc.)
2 aksdf; C:\Windows\System32\Drivers\aksdf.sys [75648 2010-07-27] (SafeNet Inc.)
2 aksfridge; C:\Windows\System32\Drivers\aksfridge.sys [131072 2010-09-27] (SafeNet Inc.)
2 ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS)
1 ATKWMIACPIIO; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
3 HPMoA907; C:\Windows\System32\Drivers\HPMoA907.sys [25088 2011-01-14] (TPMX Electronics Ltd.)
3 HPubA907; C:\Windows\System32\Drivers\HPubA907.sys [19456 2011-01-27] (TPMX Electronics Ltd.)
3 hswpan; C:\Windows\System32\Drivers\hswpan.sys [106880 2011-04-29] (Ozmo Inc)
3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )
3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-09 05:54 - 2012-08-09 05:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0CA5021C8A8CE5A6
2012-08-09 05:48 - 2012-08-09 05:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBD69DCCCC9A7A2C
2012-08-09 05:44 - 2012-08-09 05:44 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-09 05:44 - 2012-08-09 05:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-09 05:42 - 2012-08-09 05:42 - 12621696 ____A (Microsoft Corporation) C:\Users\Kev laptop\Downloads\mseinstall.exe
2012-08-08 09:33 - 2012-08-08 09:33 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\Enki Games
2012-08-07 16:12 - 2012-08-07 16:12 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\DominiGames
2012-08-02 06:29 - 2012-08-02 06:29 - 00000000 ____D C:\Windows\Redemption Cemetery 3- Grave Testimony CE
2012-07-31 11:45 - 2012-07-31 11:00 - 11820204 ____A C:\Users\Kev laptop\Desktop\Thunder.wav
2012-07-31 10:31 - 2012-07-31 10:31 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2012-07-28 06:14 - 2012-07-28 06:14 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\TikisLab
2012-07-25 07:41 - 2012-07-25 07:43 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\Sonic
2012-07-23 17:03 - 2012-07-23 17:03 - 00000028 ____A C:\Users\Kev laptop\Desktop\$ owed.txt
2012-07-21 17:07 - 2012-07-21 17:07 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\AlawarEntertainment
2012-07-20 08:11 - 2012-07-24 01:59 - 00000000 ____D C:\Users\Kev laptop\AppData\Local\Windows Live
2012-07-20 08:11 - 2012-07-20 08:11 - 00000000 ____D C:\Users\Kev laptop\AppData\Local\{DF025549-4D6E-4A23-BB41-3BE3DD0CFA73}
2012-07-20 08:11 - 2012-07-20 08:11 - 00000000 ____D C:\Users\Kev laptop\AppData\Local\{44848A0B-E434-45D0-AFE0-B97CC28FCECD}
2012-07-19 11:40 - 2012-07-19 11:40 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\Orneon
2012-07-17 13:52 - 2012-07-17 13:52 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\Artogon
2012-07-14 19:40 - 2012-07-14 19:40 - 00000000 ____D C:\Users\Kev laptop\AppData\Local\Daedalic Entertainment
2012-07-14 19:37 - 2012-07-22 12:51 - 00000000 ____D C:\Program Files (x86)\Lace Mamba Global Ltd
2012-07-14 19:16 - 2012-07-14 19:16 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\DAVA
2012-07-14 19:13 - 2012-07-14 19:13 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00000000 ____D C:\Program Files (x86)\OpenAL
2012-07-14 19:05 - 2012-07-14 19:05 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\SpeedyPC Software
2012-07-14 19:05 - 2012-07-14 19:05 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\DriverCure
2012-07-14 19:04 - 2012-07-14 19:10 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-07-13 19:03 - 2012-07-13 19:04 - 01434551 ____A (Farbar) C:\Users\Kev laptop\Downloads\FRST64.exe
2012-07-13 12:12 - 2012-07-13 12:12 - 00000000 ____D C:\Windows\System32\MpEngineStore
2012-07-13 10:13 - 2012-07-13 10:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.56DBC9E4D6E6459C
2012-07-13 09:41 - 2012-07-13 10:10 - 00000000 ____D C:\sh4ldr
2012-07-13 09:41 - 2012-07-13 09:41 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-07-13 09:40 - 2012-07-13 10:09 - 00000000 ____D C:\Windows\18F97AF04F884494AFE25A5702E142CC.TMP
2012-07-13 08:18 - 2012-07-13 08:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15F8F8FD5421836A
2012-07-13 08:15 - 2012-07-13 08:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.82FDE9765F3970EF
2012-07-13 08:12 - 2012-07-13 08:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.48BB8C9BAE64471C
2012-07-13 07:29 - 2012-07-13 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.465517795C13C4D3
2012-07-13 07:25 - 2012-07-13 07:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC8E4713E37C6DA5
2012-07-13 07:22 - 2012-07-13 07:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.682091D64104891E
2012-07-13 07:18 - 2012-07-13 07:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.01896B6780916145
2012-07-13 07:14 - 2012-07-13 07:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.517708032818F452
2012-07-13 07:08 - 2012-07-13 07:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.16C41E14DFFA663C
2012-07-13 07:02 - 2012-07-13 07:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.86C6ED9507E8338D
2012-07-12 10:30 - 2012-07-12 10:30 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-11 07:43 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 07:38 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 07:38 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 07:38 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 07:38 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 07:38 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 07:38 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 07:38 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 07:38 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 07:38 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 07:38 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 07:38 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 07:38 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 07:38 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 07:38 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 07:38 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 07:38 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 07:38 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 07:38 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 07:38 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 07:38 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 07:38 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 07:38 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 07:38 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 07:38 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 07:38 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 07:38 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 07:38 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 07:38 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 06:08 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 06:08 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 06:08 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 06:08 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 06:08 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 06:08 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 06:08 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 06:08 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 06:08 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 06:08 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 06:08 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 06:08 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 06:08 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 06:08 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 06:08 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 06:08 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 06:08 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 06:08 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 06:08 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
============ 3 Months Modified Files ========================
2012-08-10 00:15 - 2009-07-13 21:13 - 00801564 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-10 00:10 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-10 00:10 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-10 00:02 - 2012-01-26 12:58 - 00045056 ____A C:\Windows\SysWOW64\acovcnt.exe
2012-08-10 00:02 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-10 00:02 - 2009-07-13 20:51 - 00068612 ____A C:\Windows\setupact.log
2012-08-09 05:58 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-09 05:54 - 2012-08-09 05:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0CA5021C8A8CE5A6
2012-08-09 05:48 - 2012-08-09 05:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBD69DCCCC9A7A2C
2012-08-09 05:45 - 2012-01-26 12:42 - 01444814 ____A C:\Windows\WindowsUpdate.log
2012-08-09 05:44 - 2012-05-17 19:20 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2649880500-3787995184-3447727740-1001UA.job
2012-08-09 05:44 - 2012-05-17 15:37 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 05:44 - 2011-10-17 20:17 - 00807410 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-09 05:42 - 2012-08-09 05:42 - 12621696 ____A (Microsoft Corporation) C:\Users\Kev laptop\Downloads\mseinstall.exe
2012-08-09 05:31 - 2012-05-17 15:33 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-08 20:44 - 2012-05-17 19:20 - 00000876 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2649880500-3787995184-3447727740-1001Core.job
2012-08-08 11:45 - 2012-05-19 18:27 - 00001232 ____A C:\Users\Kev laptop\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-08-08 11:45 - 2012-05-19 18:27 - 00001232 ____A C:\Users\Kev laptop\AppData\Roaming\Rim.Desktop.Exception.log
2012-08-03 07:31 - 2012-05-17 15:33 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 07:31 - 2012-05-17 15:33 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-31 11:00 - 2012-07-31 11:45 - 11820204 ____A C:\Users\Kev laptop\Desktop\Thunder.wav
2012-07-31 10:36 - 2012-05-18 01:07 - 00153256 ____A C:\Users\Kev laptop\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-31 10:36 - 2009-07-13 20:45 - 03784384 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-31 10:35 - 2011-10-17 19:58 - 00341372 ____A C:\Windows\PFRO.log
2012-07-31 10:26 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-07-23 18:42 - 2012-05-19 18:29 - 00005120 ____A C:\Users\Kev laptop\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-23 17:03 - 2012-07-23 17:03 - 00000028 ____A C:\Users\Kev laptop\Desktop\$ owed.txt
2012-07-14 19:13 - 2012-07-14 19:13 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-07-13 19:04 - 2012-07-13 19:03 - 01434551 ____A (Farbar) C:\Users\Kev laptop\Downloads\FRST64.exe
2012-07-13 10:13 - 2012-07-13 10:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.56DBC9E4D6E6459C
2012-07-13 08:18 - 2012-07-13 08:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15F8F8FD5421836A
2012-07-13 08:15 - 2012-07-13 08:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.82FDE9765F3970EF
2012-07-13 08:12 - 2012-07-13 08:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.48BB8C9BAE64471C
2012-07-13 07:29 - 2012-07-13 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.465517795C13C4D3
2012-07-13 07:25 - 2012-07-13 07:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC8E4713E37C6DA5
2012-07-13 07:22 - 2012-07-13 07:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.682091D64104891E
2012-07-13 07:18 - 2012-07-13 07:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.01896B6780916145
2012-07-13 07:14 - 2012-07-13 07:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.517708032818F452
2012-07-13 07:08 - 2012-07-13 07:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.16C41E14DFFA663C
2012-07-13 07:02 - 2012-07-13 07:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.86C6ED9507E8338D
2012-07-11 07:39 - 2012-05-18 08:11 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-07 16:08 - 2012-07-07 16:08 - 00004096 ____A C:\Windows\d3dx.dat
2012-07-07 06:54 - 2012-06-17 15:33 - 00001189 ____A C:\Users\Kev laptop\AppData\Roaming\vso_ts_preview.xml
2012-06-29 10:02 - 2012-01-26 12:56 - 00002396 ____A C:\Windows\System32\AutoRunFilter.ini
2012-06-29 10:02 - 2012-01-26 12:56 - 00001389 ____A C:\Windows\System32\ServiceFilter.ini
2012-06-28 14:25 - 2012-06-28 14:25 - 00000648 ____A C:\Users\Kev laptop\AppData\Local\rx_image32.Cache
2012-06-28 14:25 - 2012-06-28 14:24 - 00018972 ____A C:\Users\Kev laptop\AppData\Local\rx_audio.Cache
2012-06-28 14:15 - 2012-06-28 14:15 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-06-27 16:50 - 2012-06-27 16:50 - 00000380 ____A C:\Windows\xpsp1hfm.log
2012-06-27 16:43 - 2011-10-17 20:19 - 00196320 ____A C:\Windows\DirectX.log
2012-06-20 19:02 - 2012-06-20 19:02 - 00004357 ____A C:\Windows\SysWOW64\jupdate-1.6.0_33-b03.log
2012-06-11 19:08 - 2012-07-11 07:43 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-11 06:08 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 06:08 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-11 06:08 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 06:08 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 06:08 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 06:08 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 06:08 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 06:08 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-26 01:04 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-26 01:04 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-26 01:04 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-26 01:04 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-26 01:04 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-26 01:04 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-26 01:04 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-26 01:04 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-26 01:04 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 07:38 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 07:38 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 07:38 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 07:38 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 07:38 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 07:38 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 07:38 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 07:38 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 07:38 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 07:38 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 07:38 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 07:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 07:38 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 07:38 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 07:38 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 07:38 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 07:38 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 07:38 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 07:38 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 07:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 07:38 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 07:38 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 07:38 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 07:38 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 07:38 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 07:38 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 07:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 07:38 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 06:08 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 06:08 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 06:08 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 06:08 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 06:08 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 06:08 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 06:08 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 06:08 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 06:08 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-30 10:27 - 2012-05-30 10:27 - 00001995 ____A C:\Users\Public\Desktop\MyPhotoCreations.lnk
2012-05-30 10:24 - 2012-05-30 10:16 - 67075816 ____A (Digilabs) C:\Users\Kev laptop\Downloads\MyPhotoCreationLInstaller.exe
2012-05-25 09:02 - 2012-01-26 12:53 - 00029664 ____A C:\Windows\DPINST.LOG
2012-05-23 05:54 - 2012-05-23 05:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_HPubA907_01009.Wdf
2012-05-19 18:26 - 2012-05-19 18:26 - 00001153 ____A C:\Users\Kev laptop\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-05-19 18:26 - 2012-05-19 18:26 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-05-19 18:26 - 2012-05-19 18:26 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-05-19 18:25 - 2012-05-19 18:25 - 00002233 ____A C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2012-05-19 06:54 - 2012-05-19 06:54 - 00284190 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-05-19 06:54 - 2012-05-19 06:53 - 00290156 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-05-18 21:14 - 2012-05-23 06:17 - 00017408 __ASH C:\Users\Kev laptop\Documents\Thumbs.db
2012-05-18 20:36 - 2012-05-18 20:37 - 00086584 ____A (Adobe Systems, Inc.) C:\Windows\SysWOW64\Drivers\adfs.sys
2012-05-18 20:36 - 2008-06-27 03:51 - 00086584 ____A (Adobe Systems, Inc.) C:\Windows\System32\Drivers\adfs.sys
2012-05-18 12:44 - 2012-05-18 11:10 - 00000090 ____A C:\Windows\QBChanUtil_Trigger.ini
2012-05-18 11:17 - 2012-05-18 11:17 - 00002113 ____A C:\Users\Public\Desktop\QuickBooks Pro 2010.lnk
2012-05-18 08:19 - 2012-05-18 08:19 - 00003742 ____A C:\Windows\efi_test.log
2012-05-18 08:06 - 2012-05-18 07:02 - 00002204 ____A C:\Windows\efimi.log
2012-05-18 07:20 - 2012-05-18 07:20 - 00000062 ____A C:\Windows\efifsw.log
2012-05-18 07:20 - 2012-05-18 07:09 - 00004992 ____A C:\Windows\efiinst.log
2012-05-18 07:18 - 2012-05-18 07:18 - 00002546 ____A C:\Users\Public\Desktop\Fiery Command WorkStation 5.lnk
2012-05-18 07:18 - 2012-05-18 07:18 - 00000000 ____A C:\Windows\cws_install.done
2012-05-18 07:14 - 2012-05-18 07:14 - 00274432 ____A (IBPhoenix Inc.) C:\Windows\SysWOW64\IscDbc.dll
2012-05-18 07:14 - 2012-05-18 07:14 - 00262144 ____A (IBPhoenix Inc) C:\Windows\SysWOW64\OdbcJdbcMT.dll
2012-05-18 07:14 - 2012-05-18 07:14 - 00253952 ____A (IBPhoenix Inc) C:\Windows\SysWOW64\OdbcJdbc.dll
2012-05-18 07:14 - 2012-05-18 07:14 - 00155648 ____A (IBPhoenix Inc.) C:\Windows\SysWOW64\OdbcJdbcSetup.dll
2012-05-18 07:14 - 2012-05-18 07:14 - 00000401 ____A C:\Windows\ODBCINST.INI
2012-05-18 07:09 - 2012-05-18 07:06 - 00015542 ____A C:\Windows\aksdrvsetup.log
2012-05-18 04:04 - 2012-01-26 12:56 - 00000080 ____A C:\Windows\System32\Defrag.ini
2012-05-18 04:04 - 2009-07-13 21:01 - 00108227 ____A C:\Windows\SysWOW64\license.rtf
2012-05-18 04:04 - 2009-07-13 21:01 - 00108227 ____A C:\Windows\System32\license.rtf
2012-05-18 02:51 - 2012-05-18 02:27 - 00002872 ____A C:\Windows\System32\TmInstall.log
2012-05-18 02:27 - 2012-05-18 02:27 - 00004280 ____A C:\Windows\SysWOW64\TmInstall.log
2012-05-18 01:07 - 2012-05-18 01:07 - 00000186 ____A C:\Windows\FixPatch.log
2012-05-18 01:07 - 2012-05-18 01:07 - 00000020 ___SH C:\Users\Kev laptop\ntuser.ini
2012-05-18 01:07 - 2011-10-17 20:18 - 02714728 ____A C:\Windows\AsDebug.log
2012-05-18 01:07 - 2011-10-17 20:10 - 00002858 ____A C:\Windows\PQArecord.log
2012-05-18 01:07 - 2011-02-18 12:12 - 00261288 ____A C:\Windows\AsCDProc.log
2012-05-17 21:01 - 2012-05-17 21:01 - 00000178 ____A C:\Windows\Tasks\AutoKMSCustom.job
ZeroAccess:
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\L
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\L\00000004.@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\L\1afb2d56
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\L\201d3dde
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U\00000004.@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U\00000008.@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U\000000cb.@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U\80000000.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 7656.9 MB
Available physical RAM: 6907.06 MB
Total Pagefile: 7655.05 MB
Available Pagefile: 6901.36 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:300.41 GB) (Free:233.78 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (DATA) (Fixed) (Total:373.22 GB) (Free:364.03 GB) NTFS
4 Drive f: (Lexar) (Removable) (Total:3.73 GB) (Free:1.67 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 3824 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 25 GB 1024 KB
Partition 2 Primary 300 GB 25 GB
Partition 3 Primary 373 GB 325 GB
==================================================================================
Disk: 0
Partition 1
Type : 1C
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C OS NTFS Partition 300 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D DATA NTFS Partition 373 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3823 MB 4096 B
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Lexar FAT32 Removable 3823 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-08 22:19
======================= End Of Log ==========================
I've read through the forums and have already run the Farbar Recovery Scan Tool. Here's the log file...
Scan result of Farbar Recovery Scan Tool Version: 11-07-2012
Ran by SYSTEM at 10-08-2012 04:23:01
Running from F:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3 [2278504 2011-10-13] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-01-21] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE" [3331312 2011-10-17] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-21] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS)
HKLM-x32\...\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [180224 2009-03-15] (PowerISO Computing, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [623880 2008-11-18] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin [611712 2012-05-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [40376 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640440 2012-03-26] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448 2011-09-01] (Research In Motion Limited)
HKLM-x32\...\Run: [PelAstro] C:\ProgramData\HP Wi-Fi Mobile Mouse Config\PelAstro.exe [65536 2011-01-14] (Primax Electronics Ltd.)
HKLM-x32\...\Run: [HPMonitor] C:\Program Files (x86)\Hewlett-Packard\HP Wi-Fi Mobile Mouse\hpMonitor23.exe [99328 2011-04-27] (Hewlett-Packard)
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [240112 2009-07-24] (Sonic Solutions)
HKLM-x32\...\Run: [CPMonitor] "C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe" [84464 2009-07-21] ()
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [494064 2009-06-22] ()
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\Kev laptop\...\Run: [Google Update] "C:\Users\Kev laptop\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-05-17] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Startup: C:\Users\All Users\Start Menu\Programs\Startup\EFI ES-1000.lnk
ShortcutTarget: EFI ES-1000.lnk -> C:\Program Files (x86)\Common Files\EFI\EFI ES-1000 Service\ES1000Notifier.exe (Electronics for Imaging, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Fiery Command WorkStation 5.lnk
ShortcutTarget: Fiery Command WorkStation 5.lnk -> C:\Program Files (x86)\Fiery\Applications3\Command WorkStation 5\Contents\WinOS\cws.exe (Electronics for Imaging, Inc)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Canada ULC.)
==================== Services (Whitelisted) ======
2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [457200 2009-06-02] ()
2 ASLDRService; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
2 AstroS; C:\ProgramData\HP Wi-Fi Mobile Mouse Config\AstroS.exe [172032 2010-12-01] ()
2 ATKGFNEXSrv; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896 2009-12-15] (ASUS)
2 EFI ES1000; C:\Program Files (x86)\Common Files\EFI\EFI ES-1000 Service\ES1000Service.exe [11776 2009-10-19] (Electronics for Imaging, Inc.)
3 hasplms; C:\Windows\system32\hasplms.exe -run [4180576 2010-09-27] (SafeNet Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 ozwpansvc; C:\Program Files\Ozmo Devices\ozwpansvc.exe [77080 2011-04-29] (Ozmo Inc)
========================== Drivers (Whitelisted) =============
3 AiCharger; C:\Windows\System32\Drivers\AiCharger.sys [17152 2011-10-14] (ASUSTek Computer Inc.)
3 AiCharger; C:\Windows\SysWow64\Drivers\AiCharger.sys [17152 2011-10-14] (ASUSTek Computer Inc.)
2 aksdf; C:\Windows\System32\Drivers\aksdf.sys [75648 2010-07-27] (SafeNet Inc.)
2 aksfridge; C:\Windows\System32\Drivers\aksfridge.sys [131072 2010-09-27] (SafeNet Inc.)
2 ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [15416 2009-07-02] (ASUS)
1 ATKWMIACPIIO; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [17536 2011-09-07] (ASUS)
3 HPMoA907; C:\Windows\System32\Drivers\HPMoA907.sys [25088 2011-01-14] (TPMX Electronics Ltd.)
3 HPubA907; C:\Windows\System32\Drivers\HPubA907.sys [19456 2011-01-27] (TPMX Electronics Ltd.)
3 hswpan; C:\Windows\System32\Drivers\hswpan.sys [106880 2011-04-29] (Ozmo Inc)
3 kbfiltr; C:\Windows\System32\Drivers\kbfiltr.sys [15416 2009-07-20] ( )
3 atillk64; \??\C:\Program Files (x86)\AMD\System Monitor\atillk64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-09 05:54 - 2012-08-09 05:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0CA5021C8A8CE5A6
2012-08-09 05:48 - 2012-08-09 05:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBD69DCCCC9A7A2C
2012-08-09 05:44 - 2012-08-09 05:44 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-09 05:44 - 2012-08-09 05:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-09 05:42 - 2012-08-09 05:42 - 12621696 ____A (Microsoft Corporation) C:\Users\Kev laptop\Downloads\mseinstall.exe
2012-08-08 09:33 - 2012-08-08 09:33 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\Enki Games
2012-08-07 16:12 - 2012-08-07 16:12 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\DominiGames
2012-08-02 06:29 - 2012-08-02 06:29 - 00000000 ____D C:\Windows\Redemption Cemetery 3- Grave Testimony CE
2012-07-31 11:45 - 2012-07-31 11:00 - 11820204 ____A C:\Users\Kev laptop\Desktop\Thunder.wav
2012-07-31 10:31 - 2012-07-31 10:31 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2012-07-28 06:14 - 2012-07-28 06:14 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\TikisLab
2012-07-25 07:41 - 2012-07-25 07:43 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\Sonic
2012-07-23 17:03 - 2012-07-23 17:03 - 00000028 ____A C:\Users\Kev laptop\Desktop\$ owed.txt
2012-07-21 17:07 - 2012-07-21 17:07 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\AlawarEntertainment
2012-07-20 08:11 - 2012-07-24 01:59 - 00000000 ____D C:\Users\Kev laptop\AppData\Local\Windows Live
2012-07-20 08:11 - 2012-07-20 08:11 - 00000000 ____D C:\Users\Kev laptop\AppData\Local\{DF025549-4D6E-4A23-BB41-3BE3DD0CFA73}
2012-07-20 08:11 - 2012-07-20 08:11 - 00000000 ____D C:\Users\Kev laptop\AppData\Local\{44848A0B-E434-45D0-AFE0-B97CC28FCECD}
2012-07-19 11:40 - 2012-07-19 11:40 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\Orneon
2012-07-17 13:52 - 2012-07-17 13:52 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\Artogon
2012-07-14 19:40 - 2012-07-14 19:40 - 00000000 ____D C:\Users\Kev laptop\AppData\Local\Daedalic Entertainment
2012-07-14 19:37 - 2012-07-22 12:51 - 00000000 ____D C:\Program Files (x86)\Lace Mamba Global Ltd
2012-07-14 19:16 - 2012-07-14 19:16 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\DAVA
2012-07-14 19:13 - 2012-07-14 19:13 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00000000 ____D C:\Program Files (x86)\OpenAL
2012-07-14 19:05 - 2012-07-14 19:05 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\SpeedyPC Software
2012-07-14 19:05 - 2012-07-14 19:05 - 00000000 ____D C:\Users\Kev laptop\AppData\Roaming\DriverCure
2012-07-14 19:04 - 2012-07-14 19:10 - 00000000 ____D C:\Users\All Users\SpeedyPC Software
2012-07-13 19:03 - 2012-07-13 19:04 - 01434551 ____A (Farbar) C:\Users\Kev laptop\Downloads\FRST64.exe
2012-07-13 12:12 - 2012-07-13 12:12 - 00000000 ____D C:\Windows\System32\MpEngineStore
2012-07-13 10:13 - 2012-07-13 10:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.56DBC9E4D6E6459C
2012-07-13 09:41 - 2012-07-13 10:10 - 00000000 ____D C:\sh4ldr
2012-07-13 09:41 - 2012-07-13 09:41 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-07-13 09:40 - 2012-07-13 10:09 - 00000000 ____D C:\Windows\18F97AF04F884494AFE25A5702E142CC.TMP
2012-07-13 08:18 - 2012-07-13 08:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15F8F8FD5421836A
2012-07-13 08:15 - 2012-07-13 08:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.82FDE9765F3970EF
2012-07-13 08:12 - 2012-07-13 08:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.48BB8C9BAE64471C
2012-07-13 07:29 - 2012-07-13 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.465517795C13C4D3
2012-07-13 07:25 - 2012-07-13 07:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC8E4713E37C6DA5
2012-07-13 07:22 - 2012-07-13 07:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.682091D64104891E
2012-07-13 07:18 - 2012-07-13 07:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.01896B6780916145
2012-07-13 07:14 - 2012-07-13 07:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.517708032818F452
2012-07-13 07:08 - 2012-07-13 07:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.16C41E14DFFA663C
2012-07-13 07:02 - 2012-07-13 07:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.86C6ED9507E8338D
2012-07-12 10:30 - 2012-07-12 10:30 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-11 07:43 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 07:38 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-11 07:38 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-11 07:38 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-11 07:38 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-11 07:38 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-11 07:38 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-11 07:38 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-11 07:38 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-11 07:38 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-11 07:38 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-11 07:38 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-11 07:38 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-11 07:38 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-11 07:38 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-11 07:38 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-11 07:38 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-11 07:38 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-11 07:38 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-11 07:38 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-11 07:38 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-11 07:38 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-11 07:38 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-11 07:38 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-11 07:38 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-11 07:38 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-11 07:38 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-11 07:38 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-11 07:38 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 06:08 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 06:08 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 06:08 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 06:08 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 06:08 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 06:08 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 06:08 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 06:08 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 06:08 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 06:08 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 06:08 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 06:08 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 06:08 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 06:08 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 06:08 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 06:08 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 06:08 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 06:08 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 06:08 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
============ 3 Months Modified Files ========================
2012-08-10 00:15 - 2009-07-13 21:13 - 00801564 ____A C:\Windows\System32\PerfStringBackup.INI
2012-08-10 00:10 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-10 00:10 - 2009-07-13 20:45 - 00009920 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-10 00:02 - 2012-01-26 12:58 - 00045056 ____A C:\Windows\SysWOW64\acovcnt.exe
2012-08-10 00:02 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-10 00:02 - 2009-07-13 20:51 - 00068612 ____A C:\Windows\setupact.log
2012-08-09 05:58 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-08-09 05:54 - 2012-08-09 05:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0CA5021C8A8CE5A6
2012-08-09 05:48 - 2012-08-09 05:48 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBD69DCCCC9A7A2C
2012-08-09 05:45 - 2012-01-26 12:42 - 01444814 ____A C:\Windows\WindowsUpdate.log
2012-08-09 05:44 - 2012-05-17 19:20 - 00000928 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2649880500-3787995184-3447727740-1001UA.job
2012-08-09 05:44 - 2012-05-17 15:37 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-09 05:44 - 2011-10-17 20:17 - 00807410 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-09 05:42 - 2012-08-09 05:42 - 12621696 ____A (Microsoft Corporation) C:\Users\Kev laptop\Downloads\mseinstall.exe
2012-08-09 05:31 - 2012-05-17 15:33 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-08 20:44 - 2012-05-17 19:20 - 00000876 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2649880500-3787995184-3447727740-1001Core.job
2012-08-08 11:45 - 2012-05-19 18:27 - 00001232 ____A C:\Users\Kev laptop\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-08-08 11:45 - 2012-05-19 18:27 - 00001232 ____A C:\Users\Kev laptop\AppData\Roaming\Rim.Desktop.Exception.log
2012-08-03 07:31 - 2012-05-17 15:33 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 07:31 - 2012-05-17 15:33 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-31 11:00 - 2012-07-31 11:45 - 11820204 ____A C:\Users\Kev laptop\Desktop\Thunder.wav
2012-07-31 10:36 - 2012-05-18 01:07 - 00153256 ____A C:\Users\Kev laptop\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-31 10:36 - 2009-07-13 20:45 - 03784384 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-31 10:35 - 2011-10-17 19:58 - 00341372 ____A C:\Windows\PFRO.log
2012-07-31 10:26 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-07-23 18:42 - 2012-05-19 18:29 - 00005120 ____A C:\Users\Kev laptop\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-07-23 17:03 - 2012-07-23 17:03 - 00000028 ____A C:\Users\Kev laptop\Desktop\$ owed.txt
2012-07-14 19:13 - 2012-07-14 19:13 - 00466456 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00444952 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00122904 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-07-14 19:13 - 2012-07-14 19:13 - 00109080 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-07-13 19:04 - 2012-07-13 19:03 - 01434551 ____A (Farbar) C:\Users\Kev laptop\Downloads\FRST64.exe
2012-07-13 10:13 - 2012-07-13 10:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.56DBC9E4D6E6459C
2012-07-13 08:18 - 2012-07-13 08:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15F8F8FD5421836A
2012-07-13 08:15 - 2012-07-13 08:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.82FDE9765F3970EF
2012-07-13 08:12 - 2012-07-13 08:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.48BB8C9BAE64471C
2012-07-13 07:29 - 2012-07-13 07:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.465517795C13C4D3
2012-07-13 07:25 - 2012-07-13 07:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BC8E4713E37C6DA5
2012-07-13 07:22 - 2012-07-13 07:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.682091D64104891E
2012-07-13 07:18 - 2012-07-13 07:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.01896B6780916145
2012-07-13 07:14 - 2012-07-13 07:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.517708032818F452
2012-07-13 07:08 - 2012-07-13 07:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.16C41E14DFFA663C
2012-07-13 07:02 - 2012-07-13 07:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.86C6ED9507E8338D
2012-07-11 07:39 - 2012-05-18 08:11 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-07 16:08 - 2012-07-07 16:08 - 00004096 ____A C:\Windows\d3dx.dat
2012-07-07 06:54 - 2012-06-17 15:33 - 00001189 ____A C:\Users\Kev laptop\AppData\Roaming\vso_ts_preview.xml
2012-06-29 10:02 - 2012-01-26 12:56 - 00002396 ____A C:\Windows\System32\AutoRunFilter.ini
2012-06-29 10:02 - 2012-01-26 12:56 - 00001389 ____A C:\Windows\System32\ServiceFilter.ini
2012-06-28 14:25 - 2012-06-28 14:25 - 00000648 ____A C:\Users\Kev laptop\AppData\Local\rx_image32.Cache
2012-06-28 14:25 - 2012-06-28 14:24 - 00018972 ____A C:\Users\Kev laptop\AppData\Local\rx_audio.Cache
2012-06-28 14:15 - 2012-06-28 14:15 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-06-27 16:50 - 2012-06-27 16:50 - 00000380 ____A C:\Windows\xpsp1hfm.log
2012-06-27 16:43 - 2011-10-17 20:19 - 00196320 ____A C:\Windows\DirectX.log
2012-06-20 19:02 - 2012-06-20 19:02 - 00004357 ____A C:\Windows\SysWOW64\jupdate-1.6.0_33-b03.log
2012-06-11 19:08 - 2012-07-11 07:43 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-11 06:08 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 06:08 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-11 06:08 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 06:08 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 06:08 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 06:08 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 06:08 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 06:08 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-26 01:04 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-26 01:04 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-26 01:04 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-26 01:04 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-26 01:04 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-26 01:04 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-26 01:04 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 11:19 - 2012-06-26 01:04 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 11:15 - 2012-06-26 01:04 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-11 07:38 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-11 07:38 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-11 07:38 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-11 07:38 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-11 07:38 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-11 07:38 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-11 07:38 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-11 07:38 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-11 07:38 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-11 07:38 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-11 07:38 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-11 07:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-11 07:38 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-11 07:38 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-11 07:38 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-11 07:38 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-11 07:38 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-11 07:38 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-11 07:38 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-11 07:38 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-11 07:38 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-11 07:38 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-11 07:38 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-11 07:38 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-11 07:38 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-11 07:38 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-11 07:38 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-11 07:38 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 06:08 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 06:08 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 06:08 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 06:08 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 06:08 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 06:08 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 06:08 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 06:08 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 06:08 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-30 10:27 - 2012-05-30 10:27 - 00001995 ____A C:\Users\Public\Desktop\MyPhotoCreations.lnk
2012-05-30 10:24 - 2012-05-30 10:16 - 67075816 ____A (Digilabs) C:\Users\Kev laptop\Downloads\MyPhotoCreationLInstaller.exe
2012-05-25 09:02 - 2012-01-26 12:53 - 00029664 ____A C:\Windows\DPINST.LOG
2012-05-23 05:54 - 2012-05-23 05:54 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_HPubA907_01009.Wdf
2012-05-19 18:26 - 2012-05-19 18:26 - 00001153 ____A C:\Users\Kev laptop\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-05-19 18:26 - 2012-05-19 18:26 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-05-19 18:26 - 2012-05-19 18:26 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-05-19 18:25 - 2012-05-19 18:25 - 00002233 ____A C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2012-05-19 06:54 - 2012-05-19 06:54 - 00284190 ____A C:\Windows\msxml4-KB973688-enu.LOG
2012-05-19 06:54 - 2012-05-19 06:53 - 00290156 ____A C:\Windows\msxml4-KB954430-enu.LOG
2012-05-18 21:14 - 2012-05-23 06:17 - 00017408 __ASH C:\Users\Kev laptop\Documents\Thumbs.db
2012-05-18 20:36 - 2012-05-18 20:37 - 00086584 ____A (Adobe Systems, Inc.) C:\Windows\SysWOW64\Drivers\adfs.sys
2012-05-18 20:36 - 2008-06-27 03:51 - 00086584 ____A (Adobe Systems, Inc.) C:\Windows\System32\Drivers\adfs.sys
2012-05-18 12:44 - 2012-05-18 11:10 - 00000090 ____A C:\Windows\QBChanUtil_Trigger.ini
2012-05-18 11:17 - 2012-05-18 11:17 - 00002113 ____A C:\Users\Public\Desktop\QuickBooks Pro 2010.lnk
2012-05-18 08:19 - 2012-05-18 08:19 - 00003742 ____A C:\Windows\efi_test.log
2012-05-18 08:06 - 2012-05-18 07:02 - 00002204 ____A C:\Windows\efimi.log
2012-05-18 07:20 - 2012-05-18 07:20 - 00000062 ____A C:\Windows\efifsw.log
2012-05-18 07:20 - 2012-05-18 07:09 - 00004992 ____A C:\Windows\efiinst.log
2012-05-18 07:18 - 2012-05-18 07:18 - 00002546 ____A C:\Users\Public\Desktop\Fiery Command WorkStation 5.lnk
2012-05-18 07:18 - 2012-05-18 07:18 - 00000000 ____A C:\Windows\cws_install.done
2012-05-18 07:14 - 2012-05-18 07:14 - 00274432 ____A (IBPhoenix Inc.) C:\Windows\SysWOW64\IscDbc.dll
2012-05-18 07:14 - 2012-05-18 07:14 - 00262144 ____A (IBPhoenix Inc) C:\Windows\SysWOW64\OdbcJdbcMT.dll
2012-05-18 07:14 - 2012-05-18 07:14 - 00253952 ____A (IBPhoenix Inc) C:\Windows\SysWOW64\OdbcJdbc.dll
2012-05-18 07:14 - 2012-05-18 07:14 - 00155648 ____A (IBPhoenix Inc.) C:\Windows\SysWOW64\OdbcJdbcSetup.dll
2012-05-18 07:14 - 2012-05-18 07:14 - 00000401 ____A C:\Windows\ODBCINST.INI
2012-05-18 07:09 - 2012-05-18 07:06 - 00015542 ____A C:\Windows\aksdrvsetup.log
2012-05-18 04:04 - 2012-01-26 12:56 - 00000080 ____A C:\Windows\System32\Defrag.ini
2012-05-18 04:04 - 2009-07-13 21:01 - 00108227 ____A C:\Windows\SysWOW64\license.rtf
2012-05-18 04:04 - 2009-07-13 21:01 - 00108227 ____A C:\Windows\System32\license.rtf
2012-05-18 02:51 - 2012-05-18 02:27 - 00002872 ____A C:\Windows\System32\TmInstall.log
2012-05-18 02:27 - 2012-05-18 02:27 - 00004280 ____A C:\Windows\SysWOW64\TmInstall.log
2012-05-18 01:07 - 2012-05-18 01:07 - 00000186 ____A C:\Windows\FixPatch.log
2012-05-18 01:07 - 2012-05-18 01:07 - 00000020 ___SH C:\Users\Kev laptop\ntuser.ini
2012-05-18 01:07 - 2011-10-17 20:18 - 02714728 ____A C:\Windows\AsDebug.log
2012-05-18 01:07 - 2011-10-17 20:10 - 00002858 ____A C:\Windows\PQArecord.log
2012-05-18 01:07 - 2011-02-18 12:12 - 00261288 ____A C:\Windows\AsCDProc.log
2012-05-17 21:01 - 2012-05-17 21:01 - 00000178 ____A C:\Windows\Tasks\AutoKMSCustom.job
ZeroAccess:
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\L
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\L\00000004.@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\L\1afb2d56
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\L\201d3dde
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U\00000004.@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U\00000008.@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U\000000cb.@
C:\Windows\Installer\{1be64ec9-fa84-4c81-8fc8-831216fb33ae}\U\80000000.@
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 7656.9 MB
Available physical RAM: 6907.06 MB
Total Pagefile: 7655.05 MB
Available Pagefile: 6901.36 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:300.41 GB) (Free:233.78 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (DATA) (Fixed) (Total:373.22 GB) (Free:364.03 GB) NTFS
4 Drive f: (Lexar) (Removable) (Total:3.73 GB) (Free:1.67 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 0 B
Disk 1 Online 3824 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 25 GB 1024 KB
Partition 2 Primary 300 GB 25 GB
Partition 3 Primary 373 GB 325 GB
==================================================================================
Disk: 0
Partition 1
Type : 1C
Hidden: Yes
Active: No
There is no volume associated with this partition.
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C OS NTFS Partition 300 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D DATA NTFS Partition 373 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3823 MB 4096 B
==================================================================================
Disk: 1
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F Lexar FAT32 Removable 3823 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-08-08 22:19
======================= End Of Log ==========================