RichardWittmann
Posts: 19 +0
Another Sirefef victim here. Microsoft Security Essentials is detecting the infection and causing reboots. Here are the logs.
Scan result of Farbar Recovery Scan Tool Version: 16-07-2012 02
Ran by SYSTEM at 16-07-2012 16:03:29
Running from G:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL [x]
HKLM-x32\...\Run: [CTHelper] CTHELPER.EXE [x]
HKLM-x32\...\Run: [CTxfiHlp] CTXFIHLP.EXE [x]
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 CTAUDFX.SYS; C:\Windows\System32\drivers\CTAUDFX.SYS [588824 2008-03-20] (Creative Technology Ltd)
3 CTEAPSFX; C:\Windows\System32\Drivers\CTEAPSFX.sys [187416 2008-03-20] (Creative Technology Ltd)
3 CTEAPSFX.SYS; C:\Windows\System32\drivers\CTEAPSFX.SYS [187416 2008-03-20] (Creative Technology Ltd)
3 CTEDSPFX; C:\Windows\System32\Drivers\CTEDSPFX.sys [287256 2008-03-20] (Creative Technology Ltd)
3 CTEDSPFX.SYS; C:\Windows\System32\drivers\CTEDSPFX.SYS [287256 2008-03-20] (Creative Technology Ltd)
3 CTEDSPIO; C:\Windows\System32\Drivers\CTEDSPIO.sys [158232 2008-03-20] (Creative Technology Ltd)
3 CTEDSPIO.SYS; C:\Windows\System32\drivers\CTEDSPIO.SYS [158232 2008-03-20] (Creative Technology Ltd)
3 CTEDSPSY; C:\Windows\System32\Drivers\CTEDSPSY.sys [338456 2008-03-20] (Creative Technology Ltd)
3 CTEDSPSY.SYS; C:\Windows\System32\drivers\CTEDSPSY.SYS [338456 2008-03-20] (Creative Technology Ltd)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-14 16:13 - 2012-07-14 16:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B3FD8E13131A392
2012-07-14 16:13 - 2012-07-14 16:13 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kimrhfkj.sys
2012-07-14 16:12 - 2012-07-14 16:12 - 00000328 ____A C:\Windows\PFRO.log
2012-07-14 15:58 - 2012-07-14 15:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B551C64334B04C8
2012-07-14 15:58 - 2012-07-14 15:58 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jvvgonwy.sys
2012-07-14 15:56 - 2012-07-14 15:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47E40579819528AA
2012-07-14 15:32 - 2012-07-14 15:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5AAE0E7C0FBF5B27
2012-07-14 15:30 - 2012-07-14 15:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11749DDF72D6420F
2012-07-14 15:25 - 2012-07-14 15:26 - 00000000 ____D C:\Windows\F896D02690164122B9BD957FF092FFE9.TMP
2012-07-14 15:25 - 2012-07-14 15:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.22820D943A7F6A5D
2012-07-14 15:23 - 2012-07-14 15:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E5778C433E565A5F
2012-07-14 15:22 - 2012-07-14 15:22 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Richard\Downloads\SpyHunter-Installer.exe
2012-07-14 15:05 - 2012-07-14 15:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.85E73AE77950F037
2012-07-14 14:58 - 2012-07-14 14:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1A7E32AB6A39FA0D
2012-07-14 14:55 - 2012-07-14 14:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9880049BF0430811
2012-07-14 14:53 - 2012-07-14 14:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.252EB0119A8BE747
2012-07-14 14:51 - 2012-07-14 14:51 - 00000000 ____D C:\Windows\pss
2012-07-14 14:42 - 2012-07-14 14:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5AA57FC00AE9977
2012-07-14 14:39 - 2012-07-14 14:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FDD9F75954E19C9
2012-07-14 14:36 - 2012-07-14 14:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.708F92FA94995861
2012-07-14 14:33 - 2012-07-14 14:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74908C64A0141E4A
2012-07-14 14:30 - 2012-07-14 14:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E101712428ECDC06
2012-07-14 14:27 - 2012-07-14 14:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96349CA0501F3E7D
2012-07-14 14:25 - 2012-07-14 14:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9A39899B7D73C1B1
2012-07-14 14:22 - 2012-07-14 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.540C8A113B2126AE
2012-07-14 14:19 - 2012-07-14 14:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6DBDE2810B8453F0
2012-07-14 14:16 - 2012-07-14 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B92BBBDA51C524
2012-07-14 14:14 - 2012-07-14 14:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.07CBA381906A69DD
2012-07-14 14:11 - 2012-07-14 14:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F362EC4F7D4ABD27
2012-07-14 14:08 - 2012-07-14 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.153253B202F4F076
2012-07-14 14:05 - 2012-07-14 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA6694D9EF1E2F2A
2012-07-14 14:03 - 2012-07-14 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CCE13D66FD3541F7
2012-07-14 14:00 - 2012-07-14 14:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8D06EF6B7AE09131
2012-07-14 13:57 - 2012-07-14 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.49A63A15125C03E7
2012-07-14 13:52 - 2012-07-14 13:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7616499FECD2A8
2012-07-14 13:49 - 2012-07-14 13:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D66EAD80A06FB7E4
2012-07-14 13:47 - 2012-07-14 13:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F753320516FCC8E5
2012-07-14 13:44 - 2012-07-14 13:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6A32846D07E4FE0A
2012-07-14 13:41 - 2012-07-14 13:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C1605C74937A0BB
2012-07-14 13:38 - 2012-07-14 13:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.387310E8F4988A4E
2012-07-14 13:35 - 2012-07-14 13:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFD64654D8E9176
2012-07-14 13:32 - 2012-07-14 13:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBADEFEAC1F228AA
2012-07-14 13:30 - 2012-07-14 13:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3091F89A18E75BF2
2012-07-14 13:27 - 2012-07-14 13:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C5784F866AE7948D
2012-07-14 13:24 - 2012-07-14 13:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.56CE466A322FF89D
2012-07-14 13:19 - 2012-07-14 13:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C26E25B7F5535462
2012-07-14 13:17 - 2012-07-14 13:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDEECA4D1FD33A9A
2012-07-14 13:14 - 2012-07-14 13:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7F43E41A393063D7
2012-07-14 13:12 - 2012-07-14 13:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F009999DE2CE8BEF
2012-07-14 13:09 - 2012-07-14 13:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9BE767816EE322D1
2012-07-14 13:06 - 2012-07-14 13:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E79E0203B4FBCA10
2012-07-14 13:03 - 2012-07-14 13:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.150249AEAB2C0346
2012-07-14 13:00 - 2012-07-14 13:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4571E4EEC7B7CE80
2012-07-14 12:58 - 2012-07-14 12:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.21354E187DE8D8FD
2012-07-14 12:50 - 2012-07-14 12:50 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-14 12:50 - 2012-07-14 12:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-14 12:48 - 2012-07-14 12:48 - 12621696 ____A (Microsoft Corporation) C:\Users\Richard\Downloads\mseinstall(1).exe
2012-07-12 15:56 - 2012-07-12 15:56 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-10 16:03 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 16:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 16:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 16:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 16:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 16:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 16:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 16:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 16:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 16:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 16:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 16:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 16:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 16:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 16:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 16:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-10 16:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-10 16:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-10 16:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-10 16:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-10 16:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-10 16:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-10 16:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-10 16:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-10 16:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-10 16:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-10 16:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-10 16:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-10 16:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 11:47 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 11:47 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 11:47 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 11:47 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 11:47 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 11:47 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 11:47 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 11:47 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 11:47 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 11:47 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 11:47 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 11:47 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 11:47 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 11:47 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 11:47 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 11:47 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 11:47 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 11:47 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 11:47 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-01 16:35 - 2012-07-14 12:45 - 00000000 ____D C:\Users\Richard\Desktop\Mazy And The Mob Studio
============ 3 Months Modified Files ========================
2012-07-14 16:13 - 2012-07-14 16:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B3FD8E13131A392
2012-07-14 16:13 - 2012-07-14 16:13 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kimrhfkj.sys
2012-07-14 16:12 - 2012-07-14 16:12 - 00000328 ____A C:\Windows\PFRO.log
2012-07-14 15:58 - 2012-07-14 15:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B551C64334B04C8
2012-07-14 15:58 - 2012-07-14 15:58 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jvvgonwy.sys
2012-07-14 15:56 - 2012-07-14 15:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47E40579819528AA
2012-07-14 15:32 - 2012-07-14 15:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5AAE0E7C0FBF5B27
2012-07-14 15:30 - 2012-07-14 15:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11749DDF72D6420F
2012-07-14 15:28 - 2009-07-13 20:45 - 00016848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-14 15:28 - 2009-07-13 20:45 - 00016848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-14 15:27 - 2012-06-11 17:26 - 00004957 ____A C:\Windows\setupact.log
2012-07-14 15:27 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-14 15:25 - 2012-07-14 15:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.22820D943A7F6A5D
2012-07-14 15:23 - 2012-07-14 15:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E5778C433E565A5F
2012-07-14 15:22 - 2012-07-14 15:22 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Richard\Downloads\SpyHunter-Installer.exe
2012-07-14 15:09 - 2012-05-28 13:52 - 01365762 ____A C:\Windows\WindowsUpdate.log
2012-07-14 15:05 - 2012-07-14 15:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.85E73AE77950F037
2012-07-14 14:58 - 2012-07-14 14:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1A7E32AB6A39FA0D
2012-07-14 14:55 - 2012-07-14 14:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9880049BF0430811
2012-07-14 14:53 - 2012-07-14 14:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.252EB0119A8BE747
2012-07-14 14:47 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-14 14:42 - 2012-07-14 14:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5AA57FC00AE9977
2012-07-14 14:39 - 2012-07-14 14:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FDD9F75954E19C9
2012-07-14 14:36 - 2012-07-14 14:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.708F92FA94995861
2012-07-14 14:33 - 2012-07-14 14:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74908C64A0141E4A
2012-07-14 14:30 - 2012-07-14 14:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E101712428ECDC06
2012-07-14 14:27 - 2012-07-14 14:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96349CA0501F3E7D
2012-07-14 14:25 - 2012-07-14 14:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9A39899B7D73C1B1
2012-07-14 14:22 - 2012-07-14 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.540C8A113B2126AE
2012-07-14 14:19 - 2012-07-14 14:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6DBDE2810B8453F0
2012-07-14 14:16 - 2012-07-14 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B92BBBDA51C524
2012-07-14 14:14 - 2012-07-14 14:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.07CBA381906A69DD
2012-07-14 14:11 - 2012-07-14 14:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F362EC4F7D4ABD27
2012-07-14 14:08 - 2012-07-14 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.153253B202F4F076
2012-07-14 14:05 - 2012-07-14 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA6694D9EF1E2F2A
2012-07-14 14:03 - 2012-07-14 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CCE13D66FD3541F7
2012-07-14 14:00 - 2012-07-14 14:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8D06EF6B7AE09131
2012-07-14 13:57 - 2012-07-14 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.49A63A15125C03E7
2012-07-14 13:52 - 2012-07-14 13:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7616499FECD2A8
2012-07-14 13:49 - 2012-07-14 13:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D66EAD80A06FB7E4
2012-07-14 13:47 - 2012-07-14 13:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F753320516FCC8E5
2012-07-14 13:44 - 2012-07-14 13:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6A32846D07E4FE0A
2012-07-14 13:41 - 2012-07-14 13:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C1605C74937A0BB
2012-07-14 13:38 - 2012-07-14 13:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.387310E8F4988A4E
2012-07-14 13:35 - 2012-07-14 13:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFD64654D8E9176
2012-07-14 13:32 - 2012-07-14 13:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBADEFEAC1F228AA
2012-07-14 13:30 - 2012-07-14 13:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3091F89A18E75BF2
2012-07-14 13:27 - 2012-07-14 13:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C5784F866AE7948D
2012-07-14 13:24 - 2012-07-14 13:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.56CE466A322FF89D
2012-07-14 13:19 - 2012-07-14 13:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C26E25B7F5535462
2012-07-14 13:17 - 2012-07-14 13:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDEECA4D1FD33A9A
2012-07-14 13:14 - 2012-07-14 13:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7F43E41A393063D7
2012-07-14 13:12 - 2012-07-14 13:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F009999DE2CE8BEF
2012-07-14 13:09 - 2012-07-14 13:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9BE767816EE322D1
2012-07-14 13:06 - 2012-07-14 13:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E79E0203B4FBCA10
2012-07-14 13:03 - 2012-07-14 13:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.150249AEAB2C0346
2012-07-14 13:00 - 2012-07-14 13:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4571E4EEC7B7CE80
2012-07-14 12:58 - 2012-07-14 12:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.21354E187DE8D8FD
2012-07-14 12:50 - 2012-05-28 15:12 - 00742892 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-14 12:50 - 2012-05-28 15:03 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-14 12:48 - 2012-07-14 12:48 - 12621696 ____A (Microsoft Corporation) C:\Users\Richard\Downloads\mseinstall(1).exe
2012-07-12 15:48 - 2012-05-29 11:07 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-12 15:48 - 2012-05-29 11:07 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-10 16:14 - 2009-07-13 21:13 - 00729688 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-10 16:10 - 2009-07-13 20:45 - 00275792 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 16:02 - 2012-06-02 17:08 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-13 15:12 - 2012-06-03 10:54 - 00003584 ____A C:\Users\Richard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-11 19:08 - 2012-07-10 16:03 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 17:40 - 2012-06-11 17:40 - 04958588 ____A C:\Windows\{00000003-00000000-00000007-00001102-00000004-40011102}.CDF
2012-06-11 17:39 - 2012-05-28 15:29 - 00431104 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-06-11 17:39 - 2012-05-28 15:29 - 00409600 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-06-11 17:39 - 2012-05-28 15:29 - 00136192 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-06-11 17:39 - 2012-05-28 15:29 - 00114688 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-06-11 17:37 - 2012-06-11 17:30 - 00000008 _RASH C:\Users\All Users\ntuser.pol
2012-06-11 17:26 - 2012-06-11 17:26 - 00000000 ____A C:\Windows\setuperr.log
2012-06-11 17:26 - 2012-06-11 17:25 - 35030595 ____A (Creative Technology Ltd) C:\Users\Richard\Downloads\EmuPMX_PCDrv_L6_2_10_00.exe
2012-06-11 17:26 - 2012-06-11 17:25 - 30704975 ____A (Creative Technology Ltd) C:\Users\Richard\Downloads\EmuPMX_PCApp_L6_2_10_00.exe
2012-06-10 10:34 - 2012-06-10 10:34 - 00000017 ____A C:\Users\Richard\AppData\Local\resmon.resmoncfg
2012-06-08 21:43 - 2012-07-10 11:47 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 11:47 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 11:47 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 11:47 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 11:47 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 11:47 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 11:47 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 11:47 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-03 16:17 - 2012-06-03 16:13 - 00000412 ____A C:\Users\Richard\AppData\Roaming\All CPU Meter_Settings.ini
2012-06-03 12:07 - 2012-06-03 12:07 - 00301688 ____A (Thesycon GmbH) C:\Users\Richard\Downloads\dpclat.exe
2012-06-02 17:04 - 2009-07-13 18:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2012-06-02 17:04 - 2009-07-13 18:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2012-06-02 14:19 - 2012-06-08 16:45 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-08 16:45 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-08 16:45 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-08 16:45 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-08 16:45 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-08 16:45 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-08 16:45 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-08 16:45 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-08 16:45 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 16:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 16:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 16:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 16:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 16:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 16:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 16:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 16:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 16:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 16:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 16:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 16:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 16:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 16:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 16:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 16:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 16:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 16:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 16:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 16:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 16:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 16:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 16:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 16:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 16:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 16:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 11:47 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 11:47 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 11:47 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 11:47 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 11:47 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 11:47 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 11:47 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 11:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 11:47 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-30 15:42 - 2012-05-30 15:42 - 12621696 ____A (Microsoft Corporation) C:\Users\Richard\Downloads\mseinstall.exe
2012-05-30 14:02 - 2012-05-30 14:02 - 00159144 ____A (Microsoft Corporation) C:\Users\Richard\Downloads\WindowsActivationUpdate.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2012-05-29 17:58 - 2012-05-29 17:58 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-05-29 17:58 - 2012-05-29 17:58 - 00697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-29 17:58 - 2012-05-29 17:58 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-05-29 17:58 - 2012-05-29 17:58 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-05-29 17:58 - 2012-05-29 17:58 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2012-05-29 17:58 - 2012-05-29 17:58 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-05-29 17:06 - 2012-05-29 17:04 - 00001852 ____A C:\Users\Public\Desktop\Vuze.lnk
2012-05-29 15:18 - 2012-05-29 15:18 - 00001066 ____A C:\Users\Public\Desktop\Dimension Pro x64.lnk
2012-05-29 12:38 - 2012-05-29 12:38 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2012-05-28 17:17 - 2012-05-28 17:13 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-05-28 17:17 - 2012-05-28 17:13 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-05-28 17:15 - 2012-05-28 17:15 - 00892360 ____A (Oracle Corporation) C:\Users\Richard\Downloads\jxpiinstall.exe
2012-05-28 16:53 - 2012-05-28 14:28 - 00058344 ____A C:\Users\Richard\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-28 16:45 - 2009-07-13 21:38 - 00025600 __ASH C:\Windows\System32\config\BCD-Template.LOG
2012-05-28 16:45 - 2009-07-13 21:32 - 00028672 ____A C:\Windows\System32\config\BCD-Template
2012-05-28 16:26 - 2012-05-28 16:26 - 00722680 ____A C:\Program Files (x86)\unins000.exe
2012-05-28 16:26 - 2012-05-28 16:26 - 00300827 ____A C:\Program Files (x86)\unins000.dat
2012-05-28 16:15 - 2012-05-28 16:15 - 00001044 ____A C:\Users\Public\Desktop\Guitar Rig 4.lnk
2012-05-28 16:14 - 2012-05-28 16:14 - 00001094 ____A C:\Users\Public\Desktop\Controller Editor.lnk
2012-05-28 16:07 - 2012-05-28 16:07 - 00001908 ____A C:\Users\Public\Desktop\SONAR X1 Producer (x64).lnk
2012-05-28 15:35 - 2012-05-28 15:35 - 00001134 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-28 15:33 - 2012-05-28 15:33 - 00000994 ____A C:\Users\Public\Desktop\PS3 Media Server.lnk
2012-05-28 15:26 - 2012-05-28 15:26 - 00002276 ____A C:\Users\Public\Desktop\PatchMix DSP Application.lnk
2012-05-28 15:25 - 2012-05-28 15:25 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-05-28 14:26 - 2012-05-28 14:25 - 33240976 ____A C:\Users\Richard\Downloads\winzip16-64.exe
2012-05-28 13:52 - 2012-05-28 13:52 - 00000020 ___SH C:\Users\Richard\ntuser.ini
2012-05-04 03:06 - 2012-06-13 13:35 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 13:35 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 13:35 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-13 13:35 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 21:32 - 2012-06-13 13:35 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-04-27 19:55 - 2012-06-13 13:35 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 13:35 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 13:35 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 13:35 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 13:35 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 13:35 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 13:35 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 13:35 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 13:35 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 13:35 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\@
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\L
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\n
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\U
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\U\00000001.@
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\U\80000000.@
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\U\800000cb.@
ZeroAccess:
C:\Users\Richard\AppData\Local\{d702e329-5765-0b03-ad00-c9e8be327dee}
C:\Users\Richard\AppData\Local\{d702e329-5765-0b03-ad00-c9e8be327dee}\@
C:\Users\Richard\AppData\Local\{d702e329-5765-0b03-ad00-c9e8be327dee}\L
C:\Users\Richard\AppData\Local\{d702e329-5765-0b03-ad00-c9e8be327dee}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 8190.55 MB
Available physical RAM: 7415.82 MB
Total Pagefile: 8188.7 MB
Available Pagefile: 7404.81 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:931.41 GB) (Free:699.82 GB) NTFS
3 Drive d: () (Fixed) (Total:186.31 GB) (Free:177.49 GB) NTFS
5 Drive g: (PAULS) (Removable) (Total:15.01 GB) (Free:0.03 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 186 GB 1024 KB
Disk 2 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 931 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 931 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 186 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D NTFS Partition 186 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G PAULS FAT32 Removable 15 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 22:03
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool Version: 16-07-2012 02
Ran by SYSTEM at 16-07-2012 16:03:29
Running from G:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL [x]
HKLM-x32\...\Run: [CTHelper] CTHELPER.EXE [x]
HKLM-x32\...\Run: [CTxfiHlp] CTXFIHLP.EXE [x]
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
========================== Drivers (Whitelisted) =============
3 CTAUDFX.SYS; C:\Windows\System32\drivers\CTAUDFX.SYS [588824 2008-03-20] (Creative Technology Ltd)
3 CTEAPSFX; C:\Windows\System32\Drivers\CTEAPSFX.sys [187416 2008-03-20] (Creative Technology Ltd)
3 CTEAPSFX.SYS; C:\Windows\System32\drivers\CTEAPSFX.SYS [187416 2008-03-20] (Creative Technology Ltd)
3 CTEDSPFX; C:\Windows\System32\Drivers\CTEDSPFX.sys [287256 2008-03-20] (Creative Technology Ltd)
3 CTEDSPFX.SYS; C:\Windows\System32\drivers\CTEDSPFX.SYS [287256 2008-03-20] (Creative Technology Ltd)
3 CTEDSPIO; C:\Windows\System32\Drivers\CTEDSPIO.sys [158232 2008-03-20] (Creative Technology Ltd)
3 CTEDSPIO.SYS; C:\Windows\System32\drivers\CTEDSPIO.SYS [158232 2008-03-20] (Creative Technology Ltd)
3 CTEDSPSY; C:\Windows\System32\Drivers\CTEDSPSY.sys [338456 2008-03-20] (Creative Technology Ltd)
3 CTEDSPSY.SYS; C:\Windows\System32\drivers\CTEDSPSY.SYS [338456 2008-03-20] (Creative Technology Ltd)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-28] ()
3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x]
3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-14 16:13 - 2012-07-14 16:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B3FD8E13131A392
2012-07-14 16:13 - 2012-07-14 16:13 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kimrhfkj.sys
2012-07-14 16:12 - 2012-07-14 16:12 - 00000328 ____A C:\Windows\PFRO.log
2012-07-14 15:58 - 2012-07-14 15:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B551C64334B04C8
2012-07-14 15:58 - 2012-07-14 15:58 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jvvgonwy.sys
2012-07-14 15:56 - 2012-07-14 15:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47E40579819528AA
2012-07-14 15:32 - 2012-07-14 15:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5AAE0E7C0FBF5B27
2012-07-14 15:30 - 2012-07-14 15:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11749DDF72D6420F
2012-07-14 15:25 - 2012-07-14 15:26 - 00000000 ____D C:\Windows\F896D02690164122B9BD957FF092FFE9.TMP
2012-07-14 15:25 - 2012-07-14 15:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.22820D943A7F6A5D
2012-07-14 15:23 - 2012-07-14 15:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E5778C433E565A5F
2012-07-14 15:22 - 2012-07-14 15:22 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Richard\Downloads\SpyHunter-Installer.exe
2012-07-14 15:05 - 2012-07-14 15:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.85E73AE77950F037
2012-07-14 14:58 - 2012-07-14 14:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1A7E32AB6A39FA0D
2012-07-14 14:55 - 2012-07-14 14:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9880049BF0430811
2012-07-14 14:53 - 2012-07-14 14:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.252EB0119A8BE747
2012-07-14 14:51 - 2012-07-14 14:51 - 00000000 ____D C:\Windows\pss
2012-07-14 14:42 - 2012-07-14 14:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5AA57FC00AE9977
2012-07-14 14:39 - 2012-07-14 14:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FDD9F75954E19C9
2012-07-14 14:36 - 2012-07-14 14:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.708F92FA94995861
2012-07-14 14:33 - 2012-07-14 14:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74908C64A0141E4A
2012-07-14 14:30 - 2012-07-14 14:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E101712428ECDC06
2012-07-14 14:27 - 2012-07-14 14:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96349CA0501F3E7D
2012-07-14 14:25 - 2012-07-14 14:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9A39899B7D73C1B1
2012-07-14 14:22 - 2012-07-14 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.540C8A113B2126AE
2012-07-14 14:19 - 2012-07-14 14:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6DBDE2810B8453F0
2012-07-14 14:16 - 2012-07-14 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B92BBBDA51C524
2012-07-14 14:14 - 2012-07-14 14:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.07CBA381906A69DD
2012-07-14 14:11 - 2012-07-14 14:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F362EC4F7D4ABD27
2012-07-14 14:08 - 2012-07-14 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.153253B202F4F076
2012-07-14 14:05 - 2012-07-14 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA6694D9EF1E2F2A
2012-07-14 14:03 - 2012-07-14 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CCE13D66FD3541F7
2012-07-14 14:00 - 2012-07-14 14:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8D06EF6B7AE09131
2012-07-14 13:57 - 2012-07-14 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.49A63A15125C03E7
2012-07-14 13:52 - 2012-07-14 13:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7616499FECD2A8
2012-07-14 13:49 - 2012-07-14 13:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D66EAD80A06FB7E4
2012-07-14 13:47 - 2012-07-14 13:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F753320516FCC8E5
2012-07-14 13:44 - 2012-07-14 13:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6A32846D07E4FE0A
2012-07-14 13:41 - 2012-07-14 13:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C1605C74937A0BB
2012-07-14 13:38 - 2012-07-14 13:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.387310E8F4988A4E
2012-07-14 13:35 - 2012-07-14 13:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFD64654D8E9176
2012-07-14 13:32 - 2012-07-14 13:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBADEFEAC1F228AA
2012-07-14 13:30 - 2012-07-14 13:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3091F89A18E75BF2
2012-07-14 13:27 - 2012-07-14 13:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C5784F866AE7948D
2012-07-14 13:24 - 2012-07-14 13:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.56CE466A322FF89D
2012-07-14 13:19 - 2012-07-14 13:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C26E25B7F5535462
2012-07-14 13:17 - 2012-07-14 13:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDEECA4D1FD33A9A
2012-07-14 13:14 - 2012-07-14 13:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7F43E41A393063D7
2012-07-14 13:12 - 2012-07-14 13:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F009999DE2CE8BEF
2012-07-14 13:09 - 2012-07-14 13:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9BE767816EE322D1
2012-07-14 13:06 - 2012-07-14 13:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E79E0203B4FBCA10
2012-07-14 13:03 - 2012-07-14 13:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.150249AEAB2C0346
2012-07-14 13:00 - 2012-07-14 13:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4571E4EEC7B7CE80
2012-07-14 12:58 - 2012-07-14 12:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.21354E187DE8D8FD
2012-07-14 12:50 - 2012-07-14 12:50 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-14 12:50 - 2012-07-14 12:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-14 12:48 - 2012-07-14 12:48 - 12621696 ____A (Microsoft Corporation) C:\Users\Richard\Downloads\mseinstall(1).exe
2012-07-12 15:56 - 2012-07-12 15:56 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-10 16:03 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 16:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 16:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 16:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 16:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 16:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 16:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 16:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 16:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 16:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 16:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 16:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 16:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 16:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 16:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 16:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-10 16:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-10 16:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-10 16:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-10 16:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-10 16:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-10 16:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-10 16:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-10 16:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-10 16:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-10 16:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-10 16:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-10 16:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-10 16:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 11:47 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 11:47 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 11:47 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 11:47 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 11:47 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 11:47 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 11:47 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 11:47 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 11:47 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 11:47 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 11:47 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 11:47 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 11:47 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 11:47 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 11:47 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 11:47 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 11:47 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 11:47 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 11:47 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-01 16:35 - 2012-07-14 12:45 - 00000000 ____D C:\Users\Richard\Desktop\Mazy And The Mob Studio
============ 3 Months Modified Files ========================
2012-07-14 16:13 - 2012-07-14 16:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3B3FD8E13131A392
2012-07-14 16:13 - 2012-07-14 16:13 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\kimrhfkj.sys
2012-07-14 16:12 - 2012-07-14 16:12 - 00000328 ____A C:\Windows\PFRO.log
2012-07-14 15:58 - 2012-07-14 15:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5B551C64334B04C8
2012-07-14 15:58 - 2012-07-14 15:58 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\jvvgonwy.sys
2012-07-14 15:56 - 2012-07-14 15:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.47E40579819528AA
2012-07-14 15:32 - 2012-07-14 15:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5AAE0E7C0FBF5B27
2012-07-14 15:30 - 2012-07-14 15:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.11749DDF72D6420F
2012-07-14 15:28 - 2009-07-13 20:45 - 00016848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-14 15:28 - 2009-07-13 20:45 - 00016848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-14 15:27 - 2012-06-11 17:26 - 00004957 ____A C:\Windows\setupact.log
2012-07-14 15:27 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-14 15:25 - 2012-07-14 15:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.22820D943A7F6A5D
2012-07-14 15:23 - 2012-07-14 15:23 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E5778C433E565A5F
2012-07-14 15:22 - 2012-07-14 15:22 - 00725440 ____A (Enigma Software Group USA, LLC.) C:\Users\Richard\Downloads\SpyHunter-Installer.exe
2012-07-14 15:09 - 2012-05-28 13:52 - 01365762 ____A C:\Windows\WindowsUpdate.log
2012-07-14 15:05 - 2012-07-14 15:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.85E73AE77950F037
2012-07-14 14:58 - 2012-07-14 14:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1A7E32AB6A39FA0D
2012-07-14 14:55 - 2012-07-14 14:55 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9880049BF0430811
2012-07-14 14:53 - 2012-07-14 14:53 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.252EB0119A8BE747
2012-07-14 14:47 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-14 14:42 - 2012-07-14 14:42 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A5AA57FC00AE9977
2012-07-14 14:39 - 2012-07-14 14:39 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1FDD9F75954E19C9
2012-07-14 14:36 - 2012-07-14 14:36 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.708F92FA94995861
2012-07-14 14:33 - 2012-07-14 14:33 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.74908C64A0141E4A
2012-07-14 14:30 - 2012-07-14 14:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E101712428ECDC06
2012-07-14 14:27 - 2012-07-14 14:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.96349CA0501F3E7D
2012-07-14 14:25 - 2012-07-14 14:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9A39899B7D73C1B1
2012-07-14 14:22 - 2012-07-14 14:22 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.540C8A113B2126AE
2012-07-14 14:19 - 2012-07-14 14:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6DBDE2810B8453F0
2012-07-14 14:16 - 2012-07-14 14:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.62B92BBBDA51C524
2012-07-14 14:14 - 2012-07-14 14:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.07CBA381906A69DD
2012-07-14 14:11 - 2012-07-14 14:11 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F362EC4F7D4ABD27
2012-07-14 14:08 - 2012-07-14 14:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.153253B202F4F076
2012-07-14 14:05 - 2012-07-14 14:05 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FA6694D9EF1E2F2A
2012-07-14 14:03 - 2012-07-14 14:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CCE13D66FD3541F7
2012-07-14 14:00 - 2012-07-14 14:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8D06EF6B7AE09131
2012-07-14 13:57 - 2012-07-14 13:57 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.49A63A15125C03E7
2012-07-14 13:52 - 2012-07-14 13:52 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.0D7616499FECD2A8
2012-07-14 13:49 - 2012-07-14 13:49 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D66EAD80A06FB7E4
2012-07-14 13:47 - 2012-07-14 13:47 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F753320516FCC8E5
2012-07-14 13:44 - 2012-07-14 13:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6A32846D07E4FE0A
2012-07-14 13:41 - 2012-07-14 13:41 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5C1605C74937A0BB
2012-07-14 13:38 - 2012-07-14 13:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.387310E8F4988A4E
2012-07-14 13:35 - 2012-07-14 13:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1BFD64654D8E9176
2012-07-14 13:32 - 2012-07-14 13:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FBADEFEAC1F228AA
2012-07-14 13:30 - 2012-07-14 13:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.3091F89A18E75BF2
2012-07-14 13:27 - 2012-07-14 13:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C5784F866AE7948D
2012-07-14 13:24 - 2012-07-14 13:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.56CE466A322FF89D
2012-07-14 13:19 - 2012-07-14 13:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.C26E25B7F5535462
2012-07-14 13:17 - 2012-07-14 13:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDEECA4D1FD33A9A
2012-07-14 13:14 - 2012-07-14 13:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7F43E41A393063D7
2012-07-14 13:12 - 2012-07-14 13:12 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F009999DE2CE8BEF
2012-07-14 13:09 - 2012-07-14 13:09 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.9BE767816EE322D1
2012-07-14 13:06 - 2012-07-14 13:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E79E0203B4FBCA10
2012-07-14 13:03 - 2012-07-14 13:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.150249AEAB2C0346
2012-07-14 13:00 - 2012-07-14 13:00 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.4571E4EEC7B7CE80
2012-07-14 12:58 - 2012-07-14 12:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.21354E187DE8D8FD
2012-07-14 12:50 - 2012-05-28 15:12 - 00742892 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-14 12:50 - 2012-05-28 15:03 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-14 12:48 - 2012-07-14 12:48 - 12621696 ____A (Microsoft Corporation) C:\Users\Richard\Downloads\mseinstall(1).exe
2012-07-12 15:48 - 2012-05-29 11:07 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-12 15:48 - 2012-05-29 11:07 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-10 16:14 - 2009-07-13 21:13 - 00729688 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-10 16:10 - 2009-07-13 20:45 - 00275792 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 16:02 - 2012-06-02 17:08 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-13 15:12 - 2012-06-03 10:54 - 00003584 ____A C:\Users\Richard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-11 19:08 - 2012-07-10 16:03 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 17:40 - 2012-06-11 17:40 - 04958588 ____A C:\Windows\{00000003-00000000-00000007-00001102-00000004-40011102}.CDF
2012-06-11 17:39 - 2012-05-28 15:29 - 00431104 ____A (Creative Labs) C:\Windows\System32\wrap_oal.dll
2012-06-11 17:39 - 2012-05-28 15:29 - 00409600 ____A (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2012-06-11 17:39 - 2012-05-28 15:29 - 00136192 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
2012-06-11 17:39 - 2012-05-28 15:29 - 00114688 ____A (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2012-06-11 17:37 - 2012-06-11 17:30 - 00000008 _RASH C:\Users\All Users\ntuser.pol
2012-06-11 17:26 - 2012-06-11 17:26 - 00000000 ____A C:\Windows\setuperr.log
2012-06-11 17:26 - 2012-06-11 17:25 - 35030595 ____A (Creative Technology Ltd) C:\Users\Richard\Downloads\EmuPMX_PCDrv_L6_2_10_00.exe
2012-06-11 17:26 - 2012-06-11 17:25 - 30704975 ____A (Creative Technology Ltd) C:\Users\Richard\Downloads\EmuPMX_PCApp_L6_2_10_00.exe
2012-06-10 10:34 - 2012-06-10 10:34 - 00000017 ____A C:\Users\Richard\AppData\Local\resmon.resmoncfg
2012-06-08 21:43 - 2012-07-10 11:47 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 11:47 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-10 11:47 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 11:47 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 11:47 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 11:47 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 11:47 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 11:47 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-03 16:17 - 2012-06-03 16:13 - 00000412 ____A C:\Users\Richard\AppData\Roaming\All CPU Meter_Settings.ini
2012-06-03 12:07 - 2012-06-03 12:07 - 00301688 ____A (Thesycon GmbH) C:\Users\Richard\Downloads\dpclat.exe
2012-06-02 17:04 - 2009-07-13 18:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll
2012-06-02 17:04 - 2009-07-13 18:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll
2012-06-02 14:19 - 2012-06-08 16:45 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-08 16:45 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-08 16:45 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-08 16:45 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-08 16:45 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-08 16:45 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-08 16:45 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 12:19 - 2012-06-08 16:45 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-08 16:45 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 16:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 16:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 16:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 16:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 16:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 16:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 16:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 16:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 16:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 16:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 16:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 16:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 16:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 16:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 16:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 16:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 16:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 16:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 16:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 16:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 16:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 16:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 16:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 16:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 16:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 16:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 11:47 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 11:47 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 11:47 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 11:47 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 11:47 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 11:47 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 11:47 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 11:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 11:47 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-30 15:42 - 2012-05-30 15:42 - 12621696 ____A (Microsoft Corporation) C:\Users\Richard\Downloads\mseinstall.exe
2012-05-30 14:02 - 2012-05-30 14:02 - 00159144 ____A (Microsoft Corporation) C:\Users\Richard\Downloads\WindowsActivationUpdate.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 03695416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2012-05-29 17:58 - 2012-05-29 17:58 - 03695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2012-05-29 17:58 - 2012-05-29 17:58 - 00697344 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00603648 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00580608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00534528 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00452608 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00448512 ____A (Microsoft Corporation) C:\Windows\System32\html.iec
2012-05-29 17:58 - 2012-05-29 17:58 - 00434176 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00403248 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00367104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2012-05-29 17:58 - 2012-05-29 17:58 - 00353792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00353584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00282112 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00267776 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00249344 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00227840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00223232 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00203776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00165888 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00162304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00160256 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00152064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00145920 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00135168 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00130560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00123392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00118784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00114176 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00111616 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00103936 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00101888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00091648 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00089088 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00086528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00078848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00076800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00076800 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2012-05-29 17:58 - 2012-05-29 17:58 - 00074752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00074240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00066048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00063488 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2012-05-29 17:58 - 2012-05-29 17:58 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00054272 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00049664 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00041472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00031744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00023552 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2012-05-29 17:58 - 2012-05-29 17:58 - 00012288 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2012-05-29 17:58 - 2012-05-29 17:58 - 00010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2012-05-29 17:06 - 2012-05-29 17:04 - 00001852 ____A C:\Users\Public\Desktop\Vuze.lnk
2012-05-29 15:18 - 2012-05-29 15:18 - 00001066 ____A C:\Users\Public\Desktop\Dimension Pro x64.lnk
2012-05-29 12:38 - 2012-05-29 12:38 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2012-05-28 17:17 - 2012-05-28 17:13 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-05-28 17:17 - 2012-05-28 17:13 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-05-28 17:15 - 2012-05-28 17:15 - 00892360 ____A (Oracle Corporation) C:\Users\Richard\Downloads\jxpiinstall.exe
2012-05-28 16:53 - 2012-05-28 14:28 - 00058344 ____A C:\Users\Richard\AppData\Local\GDIPFONTCACHEV1.DAT
2012-05-28 16:45 - 2009-07-13 21:38 - 00025600 __ASH C:\Windows\System32\config\BCD-Template.LOG
2012-05-28 16:45 - 2009-07-13 21:32 - 00028672 ____A C:\Windows\System32\config\BCD-Template
2012-05-28 16:26 - 2012-05-28 16:26 - 00722680 ____A C:\Program Files (x86)\unins000.exe
2012-05-28 16:26 - 2012-05-28 16:26 - 00300827 ____A C:\Program Files (x86)\unins000.dat
2012-05-28 16:15 - 2012-05-28 16:15 - 00001044 ____A C:\Users\Public\Desktop\Guitar Rig 4.lnk
2012-05-28 16:14 - 2012-05-28 16:14 - 00001094 ____A C:\Users\Public\Desktop\Controller Editor.lnk
2012-05-28 16:07 - 2012-05-28 16:07 - 00001908 ____A C:\Users\Public\Desktop\SONAR X1 Producer (x64).lnk
2012-05-28 15:35 - 2012-05-28 15:35 - 00001134 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-28 15:33 - 2012-05-28 15:33 - 00000994 ____A C:\Users\Public\Desktop\PS3 Media Server.lnk
2012-05-28 15:26 - 2012-05-28 15:26 - 00002276 ____A C:\Users\Public\Desktop\PatchMix DSP Application.lnk
2012-05-28 15:25 - 2012-05-28 15:25 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2012-05-28 14:26 - 2012-05-28 14:25 - 33240976 ____A C:\Users\Richard\Downloads\winzip16-64.exe
2012-05-28 13:52 - 2012-05-28 13:52 - 00000020 ___SH C:\Users\Richard\ntuser.ini
2012-05-04 03:06 - 2012-06-13 13:35 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 13:35 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 13:35 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-13 13:35 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 21:32 - 2012-06-13 13:35 - 01112064 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2012-04-27 19:55 - 2012-06-13 13:35 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 13:35 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 13:35 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 13:35 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 13:35 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 13:35 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 13:35 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 13:35 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 13:35 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 13:35 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\@
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\L
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\n
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\U
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\U\00000001.@
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\U\80000000.@
C:\Windows\Installer\{d702e329-5765-0b03-ad00-c9e8be327dee}\U\800000cb.@
ZeroAccess:
C:\Users\Richard\AppData\Local\{d702e329-5765-0b03-ad00-c9e8be327dee}
C:\Users\Richard\AppData\Local\{d702e329-5765-0b03-ad00-c9e8be327dee}\@
C:\Users\Richard\AppData\Local\{d702e329-5765-0b03-ad00-c9e8be327dee}\L
C:\Users\Richard\AppData\Local\{d702e329-5765-0b03-ad00-c9e8be327dee}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 9%
Total physical RAM: 8190.55 MB
Available physical RAM: 7415.82 MB
Total Pagefile: 8188.7 MB
Available Pagefile: 7404.81 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
2 Drive c: () (Fixed) (Total:931.41 GB) (Free:699.82 GB) NTFS
3 Drive d: () (Fixed) (Total:186.31 GB) (Free:177.49 GB) NTFS
5 Drive g: (PAULS) (Removable) (Total:15.01 GB) (Free:0.03 GB) FAT32
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 186 GB 1024 KB
Disk 2 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 931 GB 101 MB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 931 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 186 GB 31 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D NTFS Partition 186 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 31 KB
==================================================================================
Disk: 2
Partition 1
Type : 0C
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G PAULS FAT32 Removable 15 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-07 22:03
======================= End Of Log ==========================