A little embarrassed to admit this got me last night. I was browsing Amazon when it caught me. Not sure how, and realised as soon as I installed the adobe update I had been duped, but anyway, I would appreciate some help getting rid of it
Microsoft Security Essentials disabled itself, Windows Update stopped working, I couldnt launch task manager etc etc.
My laptop keeps displaying a pop-up telling me that the laptop will restart after one minute.I cannot perform any sort of scan since the laptop keeps restarting. Safe mode works fine though
I have pasted the logs I think you will need?
frst.txt:
Scan result of Farbar Recovery Scan Tool Version: 09-08-2012
Ran by SYSTEM at 13-08-2012 20:02:20
Running from G:\
Windows 7 Enterprise (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [picon] "C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" -startup [358936 2009-07-15] (Intel Corporation)
HKLM\...\Run: [SoundMAX] C:\Program Files (x86)\Analog Devices\SoundMAX\soundmax.exe /tray [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-03] (Synaptics Incorporated)
HKLM\...\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe" [196648 2009-06-03] (ActivIdentity)
HKLM\...\Run: [] [x]
HKLM\...\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe" [483880 2009-06-03] (ActivIdentity)
HKLM\...\Run: [VX6000] C:\Windows\vVX6000.exe [764784 2010-05-20] (Microsoft Corporation
)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162584 2011-06-21] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386840 2011-06-21] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417560 2011-06-21] (Intel Corporation)
HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1580368 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM-x32\...\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [287800 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11227136 2009-07-06] (Hewlett-Packard)
HKLM-x32\...\Run: [IFXSPMGT] "C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon [1107232 2009-07-19] (Infineon Technologies AG)
HKLM-x32\...\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2009-04-27] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2009-04-27] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [75048 2009-05-07] (cyberlink)
HKLM-x32\...\Run: [PTHOSTTR] C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start [358456 2010-04-13] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [CognizanceTS] rundll32.exe C:\PROGRA~2\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule [24832 2010-01-17] (Bioscrypt Inc.)
HKLM-x32\...\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103576 2012-06-08] (VMware, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\administrator\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\administrator\...\Run: [kdx] C:\Program Files (x86)\Kontiki\KHost.exe -all [x]
HKU\tony\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-12-20] (Google Inc.)
HKU\tony\...\Run: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe [5860984 2012-02-20] (SlySoft, Inc.)
HKU\tony\...\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [718720 2011-07-21] (Microsoft Corporation)
HKU\tony\...\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2012-02-23] (Apple Inc.)
HKU\tony\...\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe [59240 2012-02-23] (Apple Inc.)
HKU\tony\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\tony\...\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59240 2012-02-23] (Apple Inc.)
HKU\tony\...\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" [668944 2012-04-10] (SANDBOXIE L.T.D)
HKU\tony\...\Run: [atdpn] rundll32.exe "C:\Users\tony\AppData\Roaming\atdpn.dll",GotoPosition [162304 2012-08-12] (Crytek)
HKU\tony\...\Run: [dmplmg] "C:\Windows\System32\rundll32.exe" "C:\Users\tony\AppData\Roaming\dmplmg.dll",ThreadsInitialized [474624 2012-08-12] (BitTorrent, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
AppInit_DLLs: C:\PROGRA~2\HEWLET~1\IAM\bin\APSHOO~1.DLL
Tcpip\..\Interfaces\{4C43C4B9-7D8E-4350-B5A2-C86EDB711BB5}: [NameServer]192.168.0.1,192.168.0.2
Lsa: [Notification Packages] scecli
ASCredProv64
Startup: C:\Users\administrator\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\tony\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 ac.sharedstore; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [277032 2009-06-03] (ActivIdentity)
2 AEADIFilters; C:\Windows\System32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation)
2 ASBroker; C:\Program Files (x86)\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll [192768 2010-01-17] (Bioscrypt Inc.)
2 ASChannel; C:\Program Files (x86)\Hewlett-Packard\IAM\bin\AsChnl.dll [150272 2010-01-17] (Bioscrypt Inc.)
3 DMService; C:\Windows\DOWNLO~1\DMService.exe [487824 2012-06-20] (Microsoft Corporation)
3 FLCDLOCK; C:\Windows\SysWOW64\flcdlock.exe [362040 2009-10-05] (Hewlett-Packard Ltd)
2 HpFkCryptService; "C:\Program Files (x86)\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe" [256616 2010-03-05] (McAfee, Inc.)
2 IFXSpMgtSrv; C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [1107232 2009-07-19] (Infineon Technologies AG)
2 IFXTCS; C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [984352 2009-07-19] (Infineon Technologies AG)
2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [174616 2009-07-15] (Intel Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PersonalSecureDriveService; "C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe" [214304 2009-07-19] (Infineon Technologies AG)
2 RapportMgmtService; "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" [976728 2012-07-29] (Trusteer Ltd.)
2 SbieSvc; "C:\Program Files\Sandboxie\SbieSvc.exe" [97552 2012-04-10] (SANDBOXIE L.T.D)
2 uagqecsvc; C:\Program Files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe [150928 2010-12-19] (Microsoft Corporation)
2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2058776 2009-07-15] (Intel Corporation)
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-05-19] ()
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
========================== Drivers (Whitelisted) =============
3 ADIHdAudAddService; C:\Windows\System32\drivers\ADIHdAud.sys [497152 2009-05-18] (Analog Devices, Inc.)
3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [138360 2012-01-29] (SlySoft, Inc.)
3 AnyDVD; C:\Windows\SysWow64\Drivers\AnyDVD.sys [138360 2012-01-29] (SlySoft, Inc.)
3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2009-09-08] (Hewlett-Packard Development Company L.P.)
3 HBtnKey; C:\Windows\System32\DRIVERS\cpqbttn.sys [19000 2010-02-24] (Hewlett-Packard Company)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2010-06-25] (CACE Technologies, Inc.)
3 PAC7302; C:\Windows\System32\Drivers\PAC7302.sys [527872 2007-11-08] (PixArt Imaging Inc.)
3 PAC7302; C:\Windows\SysWow64\Drivers\PAC7302.sys [454656 2007-11-08] (PixArt Imaging Inc.)
1 PersonalSecureDrive; C:\Windows\System32\drivers\psd.sys [44576 2009-07-19] (Infineon Technologies AG)
1 RapportCerberus_42020; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_42020.sys [397720 2012-08-08] ()
1 RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [55096 2012-07-29] (Trusteer Ltd.)
0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [101688 2012-07-29] (Trusteer Ltd.)
1 RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [297240 2012-07-29] (Trusteer Ltd.)
3 RICOH SmartCard Reader; C:\Windows\System32\DRIVERS\rismcx64.sys [59008 2009-07-20] (RICOH Company, Ltd.)
3 rismcx64; C:\Windows\System32\Drivers\rismcx64.sys [59008 2009-07-20] (RICOH Company, Ltd.)
1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [14952 2010-03-05] (SafeBoot International)
0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [55912 2010-03-05] (SafeBoot International)
0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2007-07-16] (SafeBoot N.V.)
0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15464 2010-03-05] (SafeBoot International)
3 SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [164528 2012-04-10] (SANDBOXIE L.T.D)
3 Ser2pl; C:\Windows\System32\DRIVERS\ser2pl64.sys [89600 2007-02-12] (Prolific Technology Inc.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-05-27] (Duplex Secure Ltd.)
2 VMparport; C:\Windows\System32\Drivers\VMparport.sys [31384 2012-06-08] (VMware, Inc.)
3 VX6000; C:\Windows\System32\DRIVERS\VX6000Xp.sys [2143600 2010-05-20] (Microsoft Corporation
)
2 {B154377D-700F-42cc-9474-23858FBDF4BD}; \??\C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [146928 2009-05-07] (CyberLink Corp.)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-13 10:52 - 2012-08-13 10:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8EC5BB89CC96809F
2012-08-13 10:49 - 2012-08-13 10:49 - 00000070 ____A C:\Users\tony\Desktop\sirefef.txt
2012-08-13 10:18 - 2012-08-13 10:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89DF1D46DC7FF6F5
2012-08-13 09:53 - 2012-08-13 09:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87DC529FB367025F
2012-08-13 09:49 - 2012-08-13 09:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CADB10F71D3C7DFE
2012-08-13 09:47 - 2012-08-13 09:47 - 00277368 ____A C:\Windows\Minidump\081312-22604-01.dmp
2012-08-13 09:44 - 2012-08-13 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96769962702029E5
2012-08-13 09:41 - 2012-08-13 09:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD0CF8451C7E2577
2012-08-13 09:38 - 2012-08-13 09:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B7C243ACFBCA2AB0
2012-08-13 09:34 - 2012-08-13 09:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1B0782A6B18A8870
2012-08-13 09:31 - 2012-08-13 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.281279862548F519
2012-08-13 09:27 - 2012-08-13 09:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.58D35FBBE24D16F5
2012-08-13 09:24 - 2012-08-13 09:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8DCA81C2B58CB7B9
2012-08-13 09:22 - 2012-08-13 09:22 - 00277368 ____A C:\Windows\Minidump\081312-22557-02.dmp
2012-08-13 09:20 - 2012-08-13 09:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AC86DE813D3524E
2012-08-13 09:16 - 2012-08-13 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D598EDF38F8FBE98
2012-08-13 09:13 - 2012-08-13 09:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1558BA4065F5D8B9
2012-08-13 09:10 - 2012-08-13 09:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2DCC255C0DAD37CE
2012-08-13 09:06 - 2012-08-13 09:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.139CEDADEDE5F004
2012-08-13 09:03 - 2012-08-13 09:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.316AD5A7234A9231
2012-08-13 09:00 - 2012-08-13 09:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BA6007BD3303683A
2012-08-13 08:58 - 2012-08-13 08:58 - 00277368 ____A C:\Windows\Minidump\081312-22573-01.dmp
2012-08-13 08:55 - 2012-08-13 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.83569D544CBAD205
2012-08-13 08:52 - 2012-08-13 08:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3058733D6FDE5976
2012-08-13 08:49 - 2012-08-13 08:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4732BDA16FECB3B0
2012-08-13 08:45 - 2012-08-13 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E7291831023B54A
2012-08-13 08:42 - 2012-08-13 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.061F4EBB4442F69E
2012-08-13 08:40 - 2012-08-13 08:40 - 00277368 ____A C:\Windows\Minidump\081312-22682-01.dmp
2012-08-13 08:38 - 2012-08-13 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11147D22D6F6116B
2012-08-13 08:36 - 2012-08-13 08:36 - 00277368 ____A C:\Windows\Minidump\081312-22479-01.dmp
2012-08-13 08:33 - 2012-08-13 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E367C6DAE0A7E22
2012-08-13 08:30 - 2012-08-13 08:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33A70F179AC6721B
2012-08-13 08:27 - 2012-08-13 08:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.20C0F6BAC81441A5
2012-08-13 08:25 - 2012-08-13 08:25 - 00277368 ____A C:\Windows\Minidump\081312-22557-01.dmp
2012-08-13 08:22 - 2012-08-13 08:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF85E7574E8270E
2012-08-13 08:19 - 2012-08-13 08:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5EA9A1972E3E12E
2012-08-13 08:17 - 2012-08-13 08:17 - 00277368 ____A C:\Windows\Minidump\081312-22651-01.dmp
2012-08-13 08:15 - 2012-08-13 08:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DB852EB137BE97DE
2012-08-12 14:45 - 2012-08-12 14:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4FD52826D4F3B679
2012-08-12 14:25 - 2012-08-12 14:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAC12AA6A025A9E6
2012-08-12 14:22 - 2012-08-12 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AE77015A856B18B
2012-08-12 14:18 - 2012-08-12 14:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.146F804316016965
2012-08-12 14:13 - 2012-08-12 14:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63C3662FCF329286
2012-08-12 14:07 - 2012-08-12 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D286AE7979B6DAE
2012-08-12 14:03 - 2012-08-12 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DF44002BF3E67B
2012-08-12 13:57 - 2012-08-12 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3778643EBAEFF046
2012-08-12 13:52 - 2012-08-12 13:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD1BFB014FA86050
2012-08-12 13:46 - 2012-08-12 13:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1DCF8D5D972341BE
2012-08-12 13:28 - 2012-08-12 13:28 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-12 13:28 - 2012-08-12 13:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-12 12:59 - 2012-08-12 12:59 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-08-12 12:58 - 2012-08-12 13:04 - 00000000 ____D C:\Windows\F896D02690164122B9BD957FF092FFE9.TMP
2012-08-12 12:53 - 2012-08-12 12:53 - 01144963 ____A C:\Users\tony\Desktop\ProcessExplorer.zip
2012-08-12 12:39 - 2012-08-12 12:39 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-12 12:36 - 2012-08-12 12:37 - 00000000 ____D C:\Users\All Users\0C1CFB13000D001A3518CADFF875EF60
2012-08-12 12:36 - 2012-08-12 12:36 - 00474624 ____A (BitTorrent, Inc.) C:\Users\tony\AppData\Roaming\dmplmg.dll
2012-08-12 12:36 - 2012-08-12 12:36 - 00000000 ____D C:\Users\tony\AppData\Local\{7324E2D1-E4BD-11E1-8270-B8AC6F996F26}
2012-08-12 12:35 - 2012-08-12 12:35 - 00162304 __ASH (Crytek) C:\Users\tony\AppData\Roaming\atdpn.dll
2012-08-12 12:35 - 2012-08-12 12:35 - 00000000 ____D C:\Users\tony\AppData\Roaming\Zufe
2012-08-11 22:54 - 2012-08-11 22:54 - 00277392 ____A C:\Windows\Minidump\081212-23072-01.dmp
2012-07-23 12:27 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-23 12:24 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-23 12:24 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-23 12:24 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-23 12:24 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-23 12:24 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-23 12:24 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-23 12:24 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-23 12:24 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-23 12:24 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-23 12:24 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-23 12:24 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-23 12:24 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-23 12:24 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-23 12:24 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-23 12:24 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-23 12:24 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-23 12:24 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-23 12:24 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-23 12:24 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-23 12:24 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-23 12:24 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-23 12:24 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-23 12:24 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-23 12:24 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-23 12:24 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-23 12:24 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-23 12:23 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-23 12:23 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-23 12:13 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-23 12:13 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-23 12:13 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-23 12:13 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-23 12:13 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-23 12:13 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-23 12:13 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-23 12:13 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-23 12:13 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-23 12:13 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-23 12:13 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-23 12:13 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-23 12:13 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-23 12:12 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-23 12:12 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-23 12:12 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-23 12:12 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-23 12:12 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-23 12:12 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
============ 3 Months Modified Files ========================
2012-08-13 10:54 - 2010-05-26 10:09 - 00000144 ____A C:\Windows\System32\config\netlogon.ftl
2012-08-13 10:52 - 2012-08-13 10:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8EC5BB89CC96809F
2012-08-13 10:51 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-13 10:51 - 2009-07-13 20:51 - 00099713 ____A C:\Windows\setupact.log
2012-08-13 10:49 - 2012-08-13 10:49 - 00000070 ____A C:\Users\tony\Desktop\sirefef.txt
2012-08-13 10:18 - 2012-08-13 10:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89DF1D46DC7FF6F5
2012-08-13 09:53 - 2012-08-13 09:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87DC529FB367025F
2012-08-13 09:49 - 2012-08-13 09:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CADB10F71D3C7DFE
2012-08-13 09:47 - 2012-08-13 09:47 - 00277368 ____A C:\Windows\Minidump\081312-22604-01.dmp
2012-08-13 09:47 - 2010-08-31 10:02 - 310577905 ____A C:\Windows\MEMORY.DMP
2012-08-13 09:47 - 2010-05-28 10:11 - 00044618 ____A C:\Windows\PFRO.log
2012-08-13 09:44 - 2012-08-13 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96769962702029E5
2012-08-13 09:41 - 2012-08-13 09:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD0CF8451C7E2577
2012-08-13 09:41 - 2010-08-29 01:29 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-13 09:38 - 2012-08-13 09:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B7C243ACFBCA2AB0
2012-08-13 09:34 - 2012-08-13 09:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1B0782A6B18A8870
2012-08-13 09:31 - 2012-08-13 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.281279862548F519
2012-08-13 09:27 - 2012-08-13 09:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.58D35FBBE24D16F5
2012-08-13 09:24 - 2012-08-13 09:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8DCA81C2B58CB7B9
2012-08-13 09:22 - 2012-08-13 09:22 - 00277368 ____A C:\Windows\Minidump\081312-22557-02.dmp
2012-08-13 09:20 - 2012-08-13 09:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AC86DE813D3524E
2012-08-13 09:16 - 2012-08-13 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D598EDF38F8FBE98
2012-08-13 09:13 - 2012-08-13 09:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1558BA4065F5D8B9
2012-08-13 09:10 - 2012-08-13 09:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2DCC255C0DAD37CE
2012-08-13 09:06 - 2012-08-13 09:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.139CEDADEDE5F004
2012-08-13 09:03 - 2012-08-13 09:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.316AD5A7234A9231
2012-08-13 09:00 - 2012-08-13 09:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BA6007BD3303683A
2012-08-13 08:58 - 2012-08-13 08:58 - 00277368 ____A C:\Windows\Minidump\081312-22573-01.dmp
2012-08-13 08:55 - 2012-08-13 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.83569D544CBAD205
2012-08-13 08:52 - 2012-08-13 08:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3058733D6FDE5976
2012-08-13 08:49 - 2012-08-13 08:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4732BDA16FECB3B0
2012-08-13 08:45 - 2012-08-13 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E7291831023B54A
2012-08-13 08:42 - 2012-08-13 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.061F4EBB4442F69E
2012-08-13 08:40 - 2012-08-13 08:40 - 00277368 ____A C:\Windows\Minidump\081312-22682-01.dmp
2012-08-13 08:38 - 2012-08-13 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11147D22D6F6116B
2012-08-13 08:36 - 2012-08-13 08:36 - 00277368 ____A C:\Windows\Minidump\081312-22479-01.dmp
2012-08-13 08:33 - 2012-08-13 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E367C6DAE0A7E22
2012-08-13 08:30 - 2012-08-13 08:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33A70F179AC6721B
2012-08-13 08:27 - 2012-08-13 08:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.20C0F6BAC81441A5
2012-08-13 08:25 - 2012-08-13 08:25 - 00277368 ____A C:\Windows\Minidump\081312-22557-01.dmp
2012-08-13 08:22 - 2012-08-13 08:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF85E7574E8270E
2012-08-13 08:19 - 2012-08-13 08:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5EA9A1972E3E12E
2012-08-13 08:17 - 2012-08-13 08:17 - 00277368 ____A C:\Windows\Minidump\081312-22651-01.dmp
2012-08-13 08:15 - 2012-08-13 08:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DB852EB137BE97DE
2012-08-12 14:45 - 2012-08-12 14:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4FD52826D4F3B679
2012-08-12 14:42 - 2010-08-29 01:29 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-12 14:25 - 2012-08-12 14:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAC12AA6A025A9E6
2012-08-12 14:22 - 2012-08-12 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AE77015A856B18B
2012-08-12 14:18 - 2012-08-12 14:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.146F804316016965
2012-08-12 14:13 - 2012-08-12 14:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63C3662FCF329286
2012-08-12 14:08 - 2012-04-02 10:06 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-12 14:07 - 2012-08-12 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D286AE7979B6DAE
2012-08-12 14:03 - 2012-08-12 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DF44002BF3E67B
2012-08-12 13:57 - 2012-08-12 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3778643EBAEFF046
2012-08-12 13:52 - 2012-08-12 13:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD1BFB014FA86050
2012-08-12 13:46 - 2012-08-12 13:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1DCF8D5D972341BE
2012-08-12 13:29 - 2011-01-26 14:46 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-12 13:29 - 2010-05-26 09:39 - 01267499 ____A C:\Windows\WindowsUpdate.log
2012-08-12 13:28 - 2010-07-31 15:53 - 00796738 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-12 13:24 - 2009-07-13 20:45 - 00017312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-12 13:24 - 2009-07-13 20:45 - 00017312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-12 12:53 - 2012-08-12 12:53 - 01144963 ____A C:\Users\tony\Desktop\ProcessExplorer.zip
2012-08-12 12:36 - 2012-08-12 12:36 - 00474624 ____A (BitTorrent, Inc.) C:\Users\tony\AppData\Roaming\dmplmg.dll
2012-08-12 12:35 - 2012-08-12 12:35 - 00162304 __ASH (Crytek) C:\Users\tony\AppData\Roaming\atdpn.dll
2012-08-12 12:09 - 2010-05-26 13:24 - 00001940 ____A C:\Windows\Sandboxie.ini
2012-08-12 02:17 - 2010-12-20 10:40 - 00002000 ____A C:\Users\tony\Documents\Default.rdp
2012-08-11 22:54 - 2012-08-11 22:54 - 00277392 ____A C:\Windows\Minidump\081212-23072-01.dmp
2012-08-08 13:42 - 2012-02-03 15:59 - 00002340 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-08-03 09:08 - 2012-04-02 10:06 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 09:08 - 2011-05-17 13:08 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-01 10:42 - 2009-07-13 21:08 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-29 11:52 - 2012-04-15 01:51 - 00101688 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKE64.sys
2012-07-23 12:33 - 2009-07-13 20:45 - 00416720 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-23 12:24 - 2010-05-27 11:05 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-20 10:47 - 2012-06-17 04:41 - 00002021 ____A C:\Users\tony\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-07-01 11:14 - 2012-07-01 11:14 - 00866923 ____A C:\Users\tony\Downloads\MPCleaner.mpe1
2012-06-27 22:03 - 2012-06-27 22:03 - 00277448 ____A C:\Windows\Minidump\062812-22682-01.dmp
2012-06-23 22:03 - 2012-06-23 22:03 - 00277464 ____A C:\Windows\Minidump\062412-22978-01.dmp
2012-06-23 10:58 - 2010-07-16 09:58 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-06-22 08:06 - 2012-06-09 01:07 - 00001192 ____A C:\Users\Public\Desktop\My LastPass Vault.lnk
2012-06-21 09:33 - 2012-06-21 09:33 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-21 09:24 - 2012-06-21 09:24 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-06-20 08:58 - 2012-06-20 08:58 - 00277448 ____A C:\Windows\Minidump\062012-22666-01.dmp
2012-06-17 05:21 - 2012-06-17 04:42 - 00000154 ____A C:\Users\tony\AppData\Roaming\Rim.Transcoder.Exception.log
2012-06-17 05:21 - 2012-06-17 04:42 - 00000154 ____A C:\Users\tony\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-06-17 05:21 - 2012-06-17 04:42 - 00000154 ____A C:\Users\tony\AppData\Roaming\Rim.Desktop.Exception.log
2012-06-17 05:16 - 2012-06-17 04:42 - 00009216 ____A C:\Users\tony\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-17 04:47 - 2009-07-13 21:13 - 00791130 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-17 04:45 - 2012-06-17 04:45 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-06-17 04:36 - 2012-06-17 04:36 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-06-14 23:09 - 2012-06-14 23:09 - 00002135 ____A C:\Users\Public\Desktop\VMware Workstation.lnk
2012-06-12 22:50 - 2012-06-12 22:50 - 00277392 ____A C:\Windows\Minidump\061312-22807-01.dmp
2012-06-12 11:56 - 2012-06-12 11:56 - 00277392 ____A C:\Windows\Minidump\061212-23415-01.dmp
2012-06-11 19:08 - 2012-07-23 12:27 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 12:06 - 2012-06-11 12:06 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2012-06-11 11:43 - 2012-06-11 11:43 - 00277392 ____A C:\Windows\Minidump\061112-22386-01.dmp
2012-06-10 13:30 - 2011-11-16 13:31 - 00001017 ____A C:\Users\tony\Desktop\Dropbox.lnk
2012-06-08 21:43 - 2012-07-23 12:13 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-23 12:13 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 17:29 - 2012-06-14 23:09 - 00942744 ____A (VMware, Inc.) C:\Windows\System32\vnetlib64.dll
2012-06-08 17:29 - 2012-06-14 23:09 - 00063128 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmx86.sys
2012-06-08 17:29 - 2012-06-14 23:09 - 00031384 ____A (VMware, Inc.) C:\Windows\System32\Drivers\VMparport.sys
2012-06-08 17:28 - 2012-06-14 23:09 - 00433816 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2012-06-08 17:28 - 2012-06-14 23:09 - 00354456 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
2012-06-08 17:27 - 2012-06-14 23:09 - 00030360 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnetuserif.sys
2012-06-08 15:29 - 2012-06-08 15:29 - 00252056 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnc.dll
2012-06-08 14:52 - 2012-06-08 14:52 - 00062064 ____A (VMware, Inc.) C:\Windows\System32\vmnetbridge.dll
2012-06-08 14:52 - 2012-06-08 14:52 - 00048752 ____A (VMware, Inc.) C:\Windows\System32\vnetinst.dll
2012-06-08 14:52 - 2012-06-08 14:52 - 00045680 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnetbridge.sys
2012-06-08 14:52 - 2012-06-08 14:52 - 00024176 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnet.sys
2012-06-08 14:52 - 2012-06-08 14:52 - 00020080 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnetadapter.sys
2012-06-07 09:37 - 2012-06-07 09:37 - 00277392 ____A C:\Windows\Minidump\060712-23088-01.dmp
2012-06-05 22:06 - 2012-07-23 12:13 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-23 12:13 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-23 12:13 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-23 12:13 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-23 12:13 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-23 12:13 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-09 20:29 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-09 20:29 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-09 20:29 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-09 20:29 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-09 20:29 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-09 20:29 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-09 20:29 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-09 20:29 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:15 - 2012-06-09 20:29 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-23 12:24 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-23 12:23 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-23 12:24 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-23 12:24 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-23 12:24 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-23 12:24 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-23 12:24 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-23 12:24 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-23 12:24 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-23 12:24 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-23 12:24 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-23 12:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-23 12:24 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-23 12:24 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-23 12:24 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-23 12:23 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-23 12:24 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-23 12:24 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-23 12:24 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-23 12:24 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-23 12:24 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-23 12:24 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-23 12:24 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-23 12:24 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-23 12:24 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-23 12:24 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-23 12:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-23 12:24 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-23 12:13 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-23 12:12 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-23 12:12 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-23 12:13 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-23 12:13 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-23 12:12 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-23 12:12 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-23 12:12 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-23 12:12 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-06-01 14:05 - 2012-06-01 14:00 - 4239261696 ____A C:\iobw.tst
2012-06-01 14:05 - 2012-06-01 14:00 - 00000186 ____A C:\Users\tony\Documents\results.csv
2012-06-01 13:43 - 2012-06-01 13:31 - 491232944 ____A (VMware, Inc.) C:\Users\tony\Downloads\VMware-workstation-full-8.0.3-703057.exe
2012-06-01 10:40 - 2012-06-01 10:40 - 00000857 ____A C:\Users\tony\Desktop\putty.exe - Shortcut.lnk
2012-05-31 09:56 - 2012-05-31 09:56 - 00277408 ____A C:\Windows\Minidump\053112-22838-01.dmp
2012-05-28 09:45 - 2012-05-28 09:45 - 00277392 ____A C:\Windows\Minidump\052812-23025-01.dmp
2012-05-25 09:38 - 2012-05-25 09:38 - 00277392 ____A C:\Windows\Minidump\052512-22854-01.dmp
2012-05-19 23:45 - 2010-11-21 07:01 - 00001024 ____A C:\.rnd
2012-05-19 11:30 - 2011-03-05 07:36 - 00007615 ____A C:\Users\tony\AppData\Local\Resmon.ResmonCfg
ZeroAccess:
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\@
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\L
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\n
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\U
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\U\00000001.@
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\U\80000000.@
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\U\800000cb.@
ZeroAccess:
C:\Users\tony\AppData\Local\{592c8187-54b0-9145-c804-6140afd6967a}
C:\Users\tony\AppData\Local\{592c8187-54b0-9145-c804-6140afd6967a}\@
C:\Users\tony\AppData\Local\{592c8187-54b0-9145-c804-6140afd6967a}\L
C:\Users\tony\AppData\Local\{592c8187-54b0-9145-c804-6140afd6967a}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 31%
Total physical RAM: 1910.27 MB
Available physical RAM: 1303.97 MB
Total Pagefile: 1910.27 MB
Available Pagefile: 1301.66 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:221.97 GB) (Free:12.21 GB) NTFS
2 Drive e: (HP_TOOLS) (Fixed) (Total:1.5 GB) (Free:1.5 GB) FAT32
4 Drive g: (CORSAIR) (Removable) (Total:29.85 GB) (Free:29.66 GB) NTFS
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 223 GB 0 B
Disk 1 Online 29 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 221 GB 101 MB
Partition 3 Primary 1540 MB 222 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 221 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E HP_TOOLS FAT32 Partition 1540 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 29 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G CORSAIR NTFS Removable 29 GB Healthy
==================================================================================
Last Boot: 2012-08-06 22:10
======================= End Of Log ==========================
Microsoft Security Essentials disabled itself, Windows Update stopped working, I couldnt launch task manager etc etc.
My laptop keeps displaying a pop-up telling me that the laptop will restart after one minute.I cannot perform any sort of scan since the laptop keeps restarting. Safe mode works fine though
I have pasted the logs I think you will need?
frst.txt:
Scan result of Farbar Recovery Scan Tool Version: 09-08-2012
Ran by SYSTEM at 13-08-2012 20:02:20
Running from G:\
Windows 7 Enterprise (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [picon] "C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" -startup [358936 2009-07-15] (Intel Corporation)
HKLM\...\Run: [SoundMAX] C:\Program Files (x86)\Analog Devices\SoundMAX\soundmax.exe /tray [3866624 2009-05-18] (Analog Devices, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-03] (Synaptics Incorporated)
HKLM\...\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM\...\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe" [196648 2009-06-03] (ActivIdentity)
HKLM\...\Run: [] [x]
HKLM\...\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe" [483880 2009-06-03] (ActivIdentity)
HKLM\...\Run: [VX6000] C:\Windows\vVX6000.exe [764784 2010-05-20] (Microsoft Corporation
)
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [162584 2011-06-21] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [386840 2011-06-21] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417560 2011-06-21] (Intel Corporation)
HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1580368 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
HKLM-x32\...\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start [287800 2010-02-25] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [11227136 2009-07-06] (Hewlett-Packard)
HKLM-x32\...\Run: [IFXSPMGT] "C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon [1107232 2009-07-19] (Infineon Technologies AG)
HKLM-x32\...\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM-x32\...\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2009-04-27] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2009-04-27] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe [75048 2009-05-07] (cyberlink)
HKLM-x32\...\Run: [PTHOSTTR] C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start [358456 2010-04-13] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [CognizanceTS] rundll32.exe C:\PROGRA~2\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule [24832 2010-01-17] (Bioscrypt Inc.)
HKLM-x32\...\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe" [119152 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103576 2012-06-08] (VMware, Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421776 2012-06-07] (Apple Inc.)
HKU\administrator\...\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2363392 2009-06-17] (Hewlett-Packard Company)
HKU\administrator\...\Run: [kdx] C:\Program Files (x86)\Kontiki\KHost.exe -all [x]
HKU\tony\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-12-20] (Google Inc.)
HKU\tony\...\Run: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe [5860984 2012-02-20] (SlySoft, Inc.)
HKU\tony\...\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE" [718720 2011-07-21] (Microsoft Corporation)
HKU\tony\...\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59240 2012-02-23] (Apple Inc.)
HKU\tony\...\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe [59240 2012-02-23] (Apple Inc.)
HKU\tony\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\tony\...\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59240 2012-02-23] (Apple Inc.)
HKU\tony\...\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" [668944 2012-04-10] (SANDBOXIE L.T.D)
HKU\tony\...\Run: [atdpn] rundll32.exe "C:\Users\tony\AppData\Roaming\atdpn.dll",GotoPosition [162304 2012-08-12] (Crytek)
HKU\tony\...\Run: [dmplmg] "C:\Windows\System32\rundll32.exe" "C:\Users\tony\AppData\Roaming\dmplmg.dll",ThreadsInitialized [474624 2012-08-12] (BitTorrent, Inc.)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
AppInit_DLLs: C:\PROGRA~2\HEWLET~1\IAM\bin\APSHOO~1.DLL
Tcpip\..\Interfaces\{4C43C4B9-7D8E-4350-B5A2-C86EDB711BB5}: [NameServer]192.168.0.1,192.168.0.2
Lsa: [Notification Packages] scecli
ASCredProv64
Startup: C:\Users\administrator\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\tony\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
==================== Services (Whitelisted) ======
2 ac.sharedstore; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [277032 2009-06-03] (ActivIdentity)
2 AEADIFilters; C:\Windows\System32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation)
2 ASBroker; C:\Program Files (x86)\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll [192768 2010-01-17] (Bioscrypt Inc.)
2 ASChannel; C:\Program Files (x86)\Hewlett-Packard\IAM\bin\AsChnl.dll [150272 2010-01-17] (Bioscrypt Inc.)
3 DMService; C:\Windows\DOWNLO~1\DMService.exe [487824 2012-06-20] (Microsoft Corporation)
3 FLCDLOCK; C:\Windows\SysWOW64\flcdlock.exe [362040 2009-10-05] (Hewlett-Packard Ltd)
2 HpFkCryptService; "C:\Program Files (x86)\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe" [256616 2010-03-05] (McAfee, Inc.)
2 IFXSpMgtSrv; C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [1107232 2009-07-19] (Infineon Technologies AG)
2 IFXTCS; C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [984352 2009-07-19] (Infineon Technologies AG)
2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [174616 2009-07-15] (Intel Corporation)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 PersonalSecureDriveService; "C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe" [214304 2009-07-19] (Infineon Technologies AG)
2 RapportMgmtService; "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" [976728 2012-07-29] (Trusteer Ltd.)
2 SbieSvc; "C:\Program Files\Sandboxie\SbieSvc.exe" [97552 2012-04-10] (SANDBOXIE L.T.D)
2 uagqecsvc; C:\Program Files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe [150928 2010-12-19] (Microsoft Corporation)
2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2058776 2009-07-15] (Intel Corporation)
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-05-19] ()
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
========================== Drivers (Whitelisted) =============
3 ADIHdAudAddService; C:\Windows\System32\drivers\ADIHdAud.sys [497152 2009-05-18] (Analog Devices, Inc.)
3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [138360 2012-01-29] (SlySoft, Inc.)
3 AnyDVD; C:\Windows\SysWow64\Drivers\AnyDVD.sys [138360 2012-01-29] (SlySoft, Inc.)
3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [40760 2009-09-08] (Hewlett-Packard Development Company L.P.)
3 HBtnKey; C:\Windows\System32\DRIVERS\cpqbttn.sys [19000 2010-02-24] (Hewlett-Packard Company)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2010-06-25] (CACE Technologies, Inc.)
3 PAC7302; C:\Windows\System32\Drivers\PAC7302.sys [527872 2007-11-08] (PixArt Imaging Inc.)
3 PAC7302; C:\Windows\SysWow64\Drivers\PAC7302.sys [454656 2007-11-08] (PixArt Imaging Inc.)
1 PersonalSecureDrive; C:\Windows\System32\drivers\psd.sys [44576 2009-07-19] (Infineon Technologies AG)
1 RapportCerberus_42020; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_42020.sys [397720 2012-08-08] ()
1 RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [55096 2012-07-29] (Trusteer Ltd.)
0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [101688 2012-07-29] (Trusteer Ltd.)
1 RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [297240 2012-07-29] (Trusteer Ltd.)
3 RICOH SmartCard Reader; C:\Windows\System32\DRIVERS\rismcx64.sys [59008 2009-07-20] (RICOH Company, Ltd.)
3 rismcx64; C:\Windows\System32\Drivers\rismcx64.sys [59008 2009-07-20] (RICOH Company, Ltd.)
1 RsvLock; C:\Windows\System32\Drivers\RsvLock.sys [14952 2010-03-05] (SafeBoot International)
0 SafeBoot; C:\Windows\System32\Drivers\SafeBoot.sys [55912 2010-03-05] (SafeBoot International)
0 SbAlg; C:\Windows\System32\Drivers\SbAlg.sys [60160 2007-07-16] (SafeBoot N.V.)
0 SbFsLock; C:\Windows\System32\Drivers\SbFsLock.sys [15464 2010-03-05] (SafeBoot International)
3 SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [164528 2012-04-10] (SANDBOXIE L.T.D)
3 Ser2pl; C:\Windows\System32\DRIVERS\ser2pl64.sys [89600 2007-02-12] (Prolific Technology Inc.)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-05-27] (Duplex Secure Ltd.)
2 VMparport; C:\Windows\System32\Drivers\VMparport.sys [31384 2012-06-08] (VMware, Inc.)
3 VX6000; C:\Windows\System32\DRIVERS\VX6000Xp.sys [2143600 2010-05-20] (Microsoft Corporation
)
2 {B154377D-700F-42cc-9474-23858FBDF4BD}; \??\C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [146928 2009-05-07] (CyberLink Corp.)
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-13 10:52 - 2012-08-13 10:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8EC5BB89CC96809F
2012-08-13 10:49 - 2012-08-13 10:49 - 00000070 ____A C:\Users\tony\Desktop\sirefef.txt
2012-08-13 10:18 - 2012-08-13 10:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89DF1D46DC7FF6F5
2012-08-13 09:53 - 2012-08-13 09:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87DC529FB367025F
2012-08-13 09:49 - 2012-08-13 09:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CADB10F71D3C7DFE
2012-08-13 09:47 - 2012-08-13 09:47 - 00277368 ____A C:\Windows\Minidump\081312-22604-01.dmp
2012-08-13 09:44 - 2012-08-13 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96769962702029E5
2012-08-13 09:41 - 2012-08-13 09:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD0CF8451C7E2577
2012-08-13 09:38 - 2012-08-13 09:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B7C243ACFBCA2AB0
2012-08-13 09:34 - 2012-08-13 09:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1B0782A6B18A8870
2012-08-13 09:31 - 2012-08-13 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.281279862548F519
2012-08-13 09:27 - 2012-08-13 09:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.58D35FBBE24D16F5
2012-08-13 09:24 - 2012-08-13 09:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8DCA81C2B58CB7B9
2012-08-13 09:22 - 2012-08-13 09:22 - 00277368 ____A C:\Windows\Minidump\081312-22557-02.dmp
2012-08-13 09:20 - 2012-08-13 09:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AC86DE813D3524E
2012-08-13 09:16 - 2012-08-13 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D598EDF38F8FBE98
2012-08-13 09:13 - 2012-08-13 09:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1558BA4065F5D8B9
2012-08-13 09:10 - 2012-08-13 09:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2DCC255C0DAD37CE
2012-08-13 09:06 - 2012-08-13 09:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.139CEDADEDE5F004
2012-08-13 09:03 - 2012-08-13 09:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.316AD5A7234A9231
2012-08-13 09:00 - 2012-08-13 09:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BA6007BD3303683A
2012-08-13 08:58 - 2012-08-13 08:58 - 00277368 ____A C:\Windows\Minidump\081312-22573-01.dmp
2012-08-13 08:55 - 2012-08-13 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.83569D544CBAD205
2012-08-13 08:52 - 2012-08-13 08:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3058733D6FDE5976
2012-08-13 08:49 - 2012-08-13 08:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4732BDA16FECB3B0
2012-08-13 08:45 - 2012-08-13 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E7291831023B54A
2012-08-13 08:42 - 2012-08-13 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.061F4EBB4442F69E
2012-08-13 08:40 - 2012-08-13 08:40 - 00277368 ____A C:\Windows\Minidump\081312-22682-01.dmp
2012-08-13 08:38 - 2012-08-13 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11147D22D6F6116B
2012-08-13 08:36 - 2012-08-13 08:36 - 00277368 ____A C:\Windows\Minidump\081312-22479-01.dmp
2012-08-13 08:33 - 2012-08-13 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E367C6DAE0A7E22
2012-08-13 08:30 - 2012-08-13 08:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33A70F179AC6721B
2012-08-13 08:27 - 2012-08-13 08:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.20C0F6BAC81441A5
2012-08-13 08:25 - 2012-08-13 08:25 - 00277368 ____A C:\Windows\Minidump\081312-22557-01.dmp
2012-08-13 08:22 - 2012-08-13 08:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF85E7574E8270E
2012-08-13 08:19 - 2012-08-13 08:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5EA9A1972E3E12E
2012-08-13 08:17 - 2012-08-13 08:17 - 00277368 ____A C:\Windows\Minidump\081312-22651-01.dmp
2012-08-13 08:15 - 2012-08-13 08:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DB852EB137BE97DE
2012-08-12 14:45 - 2012-08-12 14:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4FD52826D4F3B679
2012-08-12 14:25 - 2012-08-12 14:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAC12AA6A025A9E6
2012-08-12 14:22 - 2012-08-12 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AE77015A856B18B
2012-08-12 14:18 - 2012-08-12 14:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.146F804316016965
2012-08-12 14:13 - 2012-08-12 14:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63C3662FCF329286
2012-08-12 14:07 - 2012-08-12 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D286AE7979B6DAE
2012-08-12 14:03 - 2012-08-12 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DF44002BF3E67B
2012-08-12 13:57 - 2012-08-12 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3778643EBAEFF046
2012-08-12 13:52 - 2012-08-12 13:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD1BFB014FA86050
2012-08-12 13:46 - 2012-08-12 13:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1DCF8D5D972341BE
2012-08-12 13:28 - 2012-08-12 13:28 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-12 13:28 - 2012-08-12 13:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-12 12:59 - 2012-08-12 12:59 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-08-12 12:58 - 2012-08-12 13:04 - 00000000 ____D C:\Windows\F896D02690164122B9BD957FF092FFE9.TMP
2012-08-12 12:53 - 2012-08-12 12:53 - 01144963 ____A C:\Users\tony\Desktop\ProcessExplorer.zip
2012-08-12 12:39 - 2012-08-12 12:39 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-08-12 12:36 - 2012-08-12 12:37 - 00000000 ____D C:\Users\All Users\0C1CFB13000D001A3518CADFF875EF60
2012-08-12 12:36 - 2012-08-12 12:36 - 00474624 ____A (BitTorrent, Inc.) C:\Users\tony\AppData\Roaming\dmplmg.dll
2012-08-12 12:36 - 2012-08-12 12:36 - 00000000 ____D C:\Users\tony\AppData\Local\{7324E2D1-E4BD-11E1-8270-B8AC6F996F26}
2012-08-12 12:35 - 2012-08-12 12:35 - 00162304 __ASH (Crytek) C:\Users\tony\AppData\Roaming\atdpn.dll
2012-08-12 12:35 - 2012-08-12 12:35 - 00000000 ____D C:\Users\tony\AppData\Roaming\Zufe
2012-08-11 22:54 - 2012-08-11 22:54 - 00277392 ____A C:\Windows\Minidump\081212-23072-01.dmp
2012-07-23 12:27 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-23 12:24 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-23 12:24 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-23 12:24 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-23 12:24 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-23 12:24 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-23 12:24 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-23 12:24 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-23 12:24 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-23 12:24 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-23 12:24 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-23 12:24 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-23 12:24 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-23 12:24 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-23 12:24 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-23 12:24 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-23 12:24 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-23 12:24 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-23 12:24 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-23 12:24 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-23 12:24 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-23 12:24 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-23 12:24 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-23 12:24 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-23 12:24 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-23 12:24 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-23 12:24 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-23 12:23 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-23 12:23 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-23 12:13 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-23 12:13 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-23 12:13 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-23 12:13 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-23 12:13 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-23 12:13 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-23 12:13 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-23 12:13 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-23 12:13 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-23 12:13 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-23 12:13 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-23 12:13 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-23 12:13 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-23 12:12 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-23 12:12 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-23 12:12 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-23 12:12 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-23 12:12 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-23 12:12 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
============ 3 Months Modified Files ========================
2012-08-13 10:54 - 2010-05-26 10:09 - 00000144 ____A C:\Windows\System32\config\netlogon.ftl
2012-08-13 10:52 - 2012-08-13 10:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8EC5BB89CC96809F
2012-08-13 10:51 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-08-13 10:51 - 2009-07-13 20:51 - 00099713 ____A C:\Windows\setupact.log
2012-08-13 10:49 - 2012-08-13 10:49 - 00000070 ____A C:\Users\tony\Desktop\sirefef.txt
2012-08-13 10:18 - 2012-08-13 10:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.89DF1D46DC7FF6F5
2012-08-13 09:53 - 2012-08-13 09:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.87DC529FB367025F
2012-08-13 09:49 - 2012-08-13 09:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CADB10F71D3C7DFE
2012-08-13 09:47 - 2012-08-13 09:47 - 00277368 ____A C:\Windows\Minidump\081312-22604-01.dmp
2012-08-13 09:47 - 2010-08-31 10:02 - 310577905 ____A C:\Windows\MEMORY.DMP
2012-08-13 09:47 - 2010-05-28 10:11 - 00044618 ____A C:\Windows\PFRO.log
2012-08-13 09:44 - 2012-08-13 09:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96769962702029E5
2012-08-13 09:41 - 2012-08-13 09:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DD0CF8451C7E2577
2012-08-13 09:41 - 2010-08-29 01:29 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-13 09:38 - 2012-08-13 09:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.B7C243ACFBCA2AB0
2012-08-13 09:34 - 2012-08-13 09:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1B0782A6B18A8870
2012-08-13 09:31 - 2012-08-13 09:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.281279862548F519
2012-08-13 09:27 - 2012-08-13 09:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.58D35FBBE24D16F5
2012-08-13 09:24 - 2012-08-13 09:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8DCA81C2B58CB7B9
2012-08-13 09:22 - 2012-08-13 09:22 - 00277368 ____A C:\Windows\Minidump\081312-22557-02.dmp
2012-08-13 09:20 - 2012-08-13 09:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AC86DE813D3524E
2012-08-13 09:16 - 2012-08-13 09:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D598EDF38F8FBE98
2012-08-13 09:13 - 2012-08-13 09:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1558BA4065F5D8B9
2012-08-13 09:10 - 2012-08-13 09:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2DCC255C0DAD37CE
2012-08-13 09:06 - 2012-08-13 09:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.139CEDADEDE5F004
2012-08-13 09:03 - 2012-08-13 09:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.316AD5A7234A9231
2012-08-13 09:00 - 2012-08-13 09:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.BA6007BD3303683A
2012-08-13 08:58 - 2012-08-13 08:58 - 00277368 ____A C:\Windows\Minidump\081312-22573-01.dmp
2012-08-13 08:55 - 2012-08-13 08:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.83569D544CBAD205
2012-08-13 08:52 - 2012-08-13 08:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3058733D6FDE5976
2012-08-13 08:49 - 2012-08-13 08:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4732BDA16FECB3B0
2012-08-13 08:45 - 2012-08-13 08:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6E7291831023B54A
2012-08-13 08:42 - 2012-08-13 08:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.061F4EBB4442F69E
2012-08-13 08:40 - 2012-08-13 08:40 - 00277368 ____A C:\Windows\Minidump\081312-22682-01.dmp
2012-08-13 08:38 - 2012-08-13 08:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11147D22D6F6116B
2012-08-13 08:36 - 2012-08-13 08:36 - 00277368 ____A C:\Windows\Minidump\081312-22479-01.dmp
2012-08-13 08:33 - 2012-08-13 08:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3E367C6DAE0A7E22
2012-08-13 08:30 - 2012-08-13 08:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.33A70F179AC6721B
2012-08-13 08:27 - 2012-08-13 08:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.20C0F6BAC81441A5
2012-08-13 08:25 - 2012-08-13 08:25 - 00277368 ____A C:\Windows\Minidump\081312-22557-01.dmp
2012-08-13 08:22 - 2012-08-13 08:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF85E7574E8270E
2012-08-13 08:19 - 2012-08-13 08:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F5EA9A1972E3E12E
2012-08-13 08:17 - 2012-08-13 08:17 - 00277368 ____A C:\Windows\Minidump\081312-22651-01.dmp
2012-08-13 08:15 - 2012-08-13 08:15 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DB852EB137BE97DE
2012-08-12 14:45 - 2012-08-12 14:45 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4FD52826D4F3B679
2012-08-12 14:42 - 2010-08-29 01:29 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-12 14:25 - 2012-08-12 14:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AAC12AA6A025A9E6
2012-08-12 14:22 - 2012-08-12 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2AE77015A856B18B
2012-08-12 14:18 - 2012-08-12 14:18 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.146F804316016965
2012-08-12 14:13 - 2012-08-12 14:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.63C3662FCF329286
2012-08-12 14:08 - 2012-04-02 10:06 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-12 14:07 - 2012-08-12 14:07 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D286AE7979B6DAE
2012-08-12 14:03 - 2012-08-12 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C9DF44002BF3E67B
2012-08-12 13:57 - 2012-08-12 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3778643EBAEFF046
2012-08-12 13:52 - 2012-08-12 13:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CD1BFB014FA86050
2012-08-12 13:46 - 2012-08-12 13:46 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1DCF8D5D972341BE
2012-08-12 13:29 - 2011-01-26 14:46 - 00001945 ____A C:\Windows\epplauncher.mif
2012-08-12 13:29 - 2010-05-26 09:39 - 01267499 ____A C:\Windows\WindowsUpdate.log
2012-08-12 13:28 - 2010-07-31 15:53 - 00796738 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-12 13:24 - 2009-07-13 20:45 - 00017312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-08-12 13:24 - 2009-07-13 20:45 - 00017312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-08-12 12:53 - 2012-08-12 12:53 - 01144963 ____A C:\Users\tony\Desktop\ProcessExplorer.zip
2012-08-12 12:36 - 2012-08-12 12:36 - 00474624 ____A (BitTorrent, Inc.) C:\Users\tony\AppData\Roaming\dmplmg.dll
2012-08-12 12:35 - 2012-08-12 12:35 - 00162304 __ASH (Crytek) C:\Users\tony\AppData\Roaming\atdpn.dll
2012-08-12 12:09 - 2010-05-26 13:24 - 00001940 ____A C:\Windows\Sandboxie.ini
2012-08-12 02:17 - 2010-12-20 10:40 - 00002000 ____A C:\Users\tony\Documents\Default.rdp
2012-08-11 22:54 - 2012-08-11 22:54 - 00277392 ____A C:\Windows\Minidump\081212-23072-01.dmp
2012-08-08 13:42 - 2012-02-03 15:59 - 00002340 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-08-03 09:08 - 2012-04-02 10:06 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-03 09:08 - 2011-05-17 13:08 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-01 10:42 - 2009-07-13 21:08 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-29 11:52 - 2012-04-15 01:51 - 00101688 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKE64.sys
2012-07-23 12:33 - 2009-07-13 20:45 - 00416720 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-23 12:24 - 2010-05-27 11:05 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-20 10:47 - 2012-06-17 04:41 - 00002021 ____A C:\Users\tony\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-07-01 11:14 - 2012-07-01 11:14 - 00866923 ____A C:\Users\tony\Downloads\MPCleaner.mpe1
2012-06-27 22:03 - 2012-06-27 22:03 - 00277448 ____A C:\Windows\Minidump\062812-22682-01.dmp
2012-06-23 22:03 - 2012-06-23 22:03 - 00277464 ____A C:\Windows\Minidump\062412-22978-01.dmp
2012-06-23 10:58 - 2010-07-16 09:58 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
2012-06-22 08:06 - 2012-06-09 01:07 - 00001192 ____A C:\Users\Public\Desktop\My LastPass Vault.lnk
2012-06-21 09:33 - 2012-06-21 09:33 - 00001783 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-06-21 09:24 - 2012-06-21 09:24 - 00001845 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-06-20 08:58 - 2012-06-20 08:58 - 00277448 ____A C:\Windows\Minidump\062012-22666-01.dmp
2012-06-17 05:21 - 2012-06-17 04:42 - 00000154 ____A C:\Users\tony\AppData\Roaming\Rim.Transcoder.Exception.log
2012-06-17 05:21 - 2012-06-17 04:42 - 00000154 ____A C:\Users\tony\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-06-17 05:21 - 2012-06-17 04:42 - 00000154 ____A C:\Users\tony\AppData\Roaming\Rim.Desktop.Exception.log
2012-06-17 05:16 - 2012-06-17 04:42 - 00009216 ____A C:\Users\tony\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-17 04:47 - 2009-07-13 21:13 - 00791130 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-17 04:45 - 2012-06-17 04:45 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-06-17 04:36 - 2012-06-17 04:36 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-06-14 23:09 - 2012-06-14 23:09 - 00002135 ____A C:\Users\Public\Desktop\VMware Workstation.lnk
2012-06-12 22:50 - 2012-06-12 22:50 - 00277392 ____A C:\Windows\Minidump\061312-22807-01.dmp
2012-06-12 11:56 - 2012-06-12 11:56 - 00277392 ____A C:\Windows\Minidump\061212-23415-01.dmp
2012-06-11 19:08 - 2012-07-23 12:27 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 12:06 - 2012-06-11 12:06 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_SynTP_01009.Wdf
2012-06-11 11:43 - 2012-06-11 11:43 - 00277392 ____A C:\Windows\Minidump\061112-22386-01.dmp
2012-06-10 13:30 - 2011-11-16 13:31 - 00001017 ____A C:\Users\tony\Desktop\Dropbox.lnk
2012-06-08 21:43 - 2012-07-23 12:13 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-23 12:13 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 17:29 - 2012-06-14 23:09 - 00942744 ____A (VMware, Inc.) C:\Windows\System32\vnetlib64.dll
2012-06-08 17:29 - 2012-06-14 23:09 - 00063128 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmx86.sys
2012-06-08 17:29 - 2012-06-14 23:09 - 00031384 ____A (VMware, Inc.) C:\Windows\System32\Drivers\VMparport.sys
2012-06-08 17:28 - 2012-06-14 23:09 - 00433816 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
2012-06-08 17:28 - 2012-06-14 23:09 - 00354456 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
2012-06-08 17:27 - 2012-06-14 23:09 - 00030360 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnetuserif.sys
2012-06-08 15:29 - 2012-06-08 15:29 - 00252056 ____A (VMware, Inc.) C:\Windows\SysWOW64\vmnc.dll
2012-06-08 14:52 - 2012-06-08 14:52 - 00062064 ____A (VMware, Inc.) C:\Windows\System32\vmnetbridge.dll
2012-06-08 14:52 - 2012-06-08 14:52 - 00048752 ____A (VMware, Inc.) C:\Windows\System32\vnetinst.dll
2012-06-08 14:52 - 2012-06-08 14:52 - 00045680 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnetbridge.sys
2012-06-08 14:52 - 2012-06-08 14:52 - 00024176 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnet.sys
2012-06-08 14:52 - 2012-06-08 14:52 - 00020080 ____A (VMware, Inc.) C:\Windows\System32\Drivers\vmnetadapter.sys
2012-06-07 09:37 - 2012-06-07 09:37 - 00277392 ____A C:\Windows\Minidump\060712-23088-01.dmp
2012-06-05 22:06 - 2012-07-23 12:13 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-23 12:13 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-23 12:13 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-23 12:13 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-23 12:13 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-23 12:13 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-09 20:29 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-09 20:29 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-09 20:29 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-09 20:29 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-09 20:29 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-09 20:29 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-09 20:29 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-09 20:29 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:15 - 2012-06-09 20:29 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-23 12:24 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-23 12:23 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-23 12:24 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-23 12:24 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-23 12:24 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-23 12:24 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-23 12:24 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-23 12:24 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-23 12:24 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-23 12:24 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-23 12:24 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-23 12:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-23 12:24 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-23 12:24 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-23 12:24 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-23 12:23 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-23 12:24 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-23 12:24 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-23 12:24 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-23 12:24 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-23 12:24 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-23 12:24 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-23 12:24 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-23 12:24 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-23 12:24 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-23 12:24 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-23 12:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-23 12:24 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-23 12:13 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-23 12:12 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-23 12:12 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-23 12:13 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-23 12:13 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-23 12:12 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-23 12:12 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-23 12:12 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-23 12:12 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-06-01 14:05 - 2012-06-01 14:00 - 4239261696 ____A C:\iobw.tst
2012-06-01 14:05 - 2012-06-01 14:00 - 00000186 ____A C:\Users\tony\Documents\results.csv
2012-06-01 13:43 - 2012-06-01 13:31 - 491232944 ____A (VMware, Inc.) C:\Users\tony\Downloads\VMware-workstation-full-8.0.3-703057.exe
2012-06-01 10:40 - 2012-06-01 10:40 - 00000857 ____A C:\Users\tony\Desktop\putty.exe - Shortcut.lnk
2012-05-31 09:56 - 2012-05-31 09:56 - 00277408 ____A C:\Windows\Minidump\053112-22838-01.dmp
2012-05-28 09:45 - 2012-05-28 09:45 - 00277392 ____A C:\Windows\Minidump\052812-23025-01.dmp
2012-05-25 09:38 - 2012-05-25 09:38 - 00277392 ____A C:\Windows\Minidump\052512-22854-01.dmp
2012-05-19 23:45 - 2010-11-21 07:01 - 00001024 ____A C:\.rnd
2012-05-19 11:30 - 2011-03-05 07:36 - 00007615 ____A C:\Users\tony\AppData\Local\Resmon.ResmonCfg
ZeroAccess:
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\@
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\L
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\n
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\U
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\U\00000001.@
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\U\80000000.@
C:\Windows\Installer\{592c8187-54b0-9145-c804-6140afd6967a}\U\800000cb.@
ZeroAccess:
C:\Users\tony\AppData\Local\{592c8187-54b0-9145-c804-6140afd6967a}
C:\Users\tony\AppData\Local\{592c8187-54b0-9145-c804-6140afd6967a}\@
C:\Users\tony\AppData\Local\{592c8187-54b0-9145-c804-6140afd6967a}\L
C:\Users\tony\AppData\Local\{592c8187-54b0-9145-c804-6140afd6967a}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 31%
Total physical RAM: 1910.27 MB
Available physical RAM: 1303.97 MB
Total Pagefile: 1910.27 MB
Available Pagefile: 1301.66 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:221.97 GB) (Free:12.21 GB) NTFS
2 Drive e: (HP_TOOLS) (Fixed) (Total:1.5 GB) (Free:1.5 GB) FAT32
4 Drive g: (CORSAIR) (Removable) (Total:29.85 GB) (Free:29.66 GB) NTFS
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 223 GB 0 B
Disk 1 Online 29 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 221 GB 101 MB
Partition 3 Primary 1540 MB 222 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 221 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E HP_TOOLS FAT32 Partition 1540 MB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 29 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G CORSAIR NTFS Removable 29 GB Healthy
==================================================================================
Last Boot: 2012-08-06 22:10
======================= End Of Log ==========================