Hi,
I'm new to this forum and am getting the same "Critical Error" leading to restart in 1 minute issues that other people have encountered.
I have run the frst64 scan and this is the contents of FRST.txt:
Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 01
Ran by SYSTEM at 08-08-2012 10:31:43
Running from E:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [TpShocks] TpShocks.exe [x]
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2851112 2011-11-17] (Synaptics Incorporated)
HKLM\...\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [62312 2010-07-27] (Lenovo Group Limited)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-15] ()
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-11-01] (Intel(R) Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-09-27] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [112152 2010-05-03] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [AT&T Communication Manager] "C:\Program Files (x86)\AT&T\Communication Manager\ATTCM.exe" -a [33280 2008-12-01] (ATT)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor [1631808 2012-01-23] (Lenovo Group Limited)
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2012-01-18] (VMware, Inc.)
HKU\conorbev\...\Run: [NetSP - restore settings on power failure] "C:\Program Files (x86)\AT&T Global Network Client\NetSP.exe" -show [55136 2011-08-05] (AT&T)
HKU\conorbev\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1242448 2011-10-20] (Valve Corporation)
HKU\conorbev\...\Run: [Akamai NetSession Interface] "C:\Users\conorbev\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc)
HKU\conorbev\...\Run: [Google Update] "C:\Users\conorbev\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-06-15] (Google Inc.)
HKU\conorbev\...\Run: [SODCPreLoad] C:\notes\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090922-1655\preload.exe C:\notes\data\workspace\.sodc\ [40960 2011-09-03] ()
HKU\conorbev\...\Run: [DAT3F3F.tmp.exe] C:\Users\conorbev\AppData\Local\Temp\DAT3F3F.tmp.exe [50176 2012-07-31] (Mesh Computers)
HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{B6503417-F4F3-4080-A1F4-C38947AB5B95}: [NameServer]9.0.128.50,9.0.130.50
Startup: C:\Users\All Users\Start Menu\Programs\Startup\AT&T Global Network Client Monitor.lnk
ShortcutTarget: AT&T Global Network Client Monitor.lnk -> C:\Windows\Installer\{3330748F-151F-4112-A88C-04AE88EDBE34}\NetGM1_89563E53ECF44E868145468A128BDC83.exe (Flexera Software, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files (x86)\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Users\All Users\Start Menu\Programs\Startup\InfoPrint Select Notification.lnk
ShortcutTarget: InfoPrint Select Notification.lnk -> C:\Program Files\ibm\Infoprint Select\ipnotify.exe ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\conorbev\Start Menu\Programs\Startup\MagicDisc.lnk
ShortcutTarget: MagicDisc.lnk -> C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
==================== Services (Whitelisted) ======
3 ATTRcAppSvc; "C:\Program Files (x86)\AT&T\Communication Manager\RcAppSvc.exe" /n "ATTRcAppSvc" [113152 2008-11-20] (SmithMicro Inc.)
2 BTHSSecurityMgr; "C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe" [135440 2011-10-20] (Intel(R) Corporation)
3 CAATT; "C:\Program Files (x86)\AT&T\Communication Manager\ConAppsSvc.exe" /n "CAATT" [125440 2008-11-20] (SmithMicro Inc.)
3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2012-01-23] (Lenovo.)
2 IBMPMSVC; C:\Windows\System32\ibmpmsvc.exe [45928 2011-08-11] (Lenovo.)
2 IBMWAS70Service - conorbev-W510Node02; "C:\Program Files (x86)\IBM\SDP_75\runtimes\base_v7\bin\wasservice.exe" "IBMWAS70Service - conorbev-W510Node02" [81920 2011-11-18] ()
2 LENOVO.CAMMUTE; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [50536 2010-07-27] (Lenovo Group Limited)
2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [101736 2011-07-12] (Lenovo Group Limited)
2 LENOVO.TPKNRSVC; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [74088 2010-07-27] (Lenovo Group Limited)
2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited)
2 Lotus Notes Diagnostics; C:\notes\nsd.exe -svcinvoke -ini "C:\notes\notes.ini" [14999 2012-08-01] ()
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe" [237008 2011-06-17] (McAfee, Inc.)
2 Multi-user Cleanup Service; C:\notes\ntmulti.exe [58760 2009-09-29] (IBM Corp)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-11-01] ()
2 netcfgsvr; "C:\Program Files (x86)\AT&T Global Network Client\netcfgsvr.exe" [1061728 2011-08-05] (AT&T)
2 NetClientSvc; "C:\Program Files (x86)\AT&T Global Network Client\NetClientSvc.exe" [352096 2011-08-05] (AT&T)
3 NetLogSvc; C:\Program Files (x86)\AT&T Global Network Client\NetLogSvc.exe [81760 2011-08-05] (AT&T)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 Power Manager DBC Service; "C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE" [89152 2012-01-23] (Lenovo)
3 PwmEWSvc; C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [175168 2012-01-23] (Lenovo Group Limited)
2 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [28672 2011-07-25] (Lenovo Group Limited)
2 SwiCardDetectSvc; "C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe" [317296 2011-05-20] (Sierra Wireless, Inc.)
3 TPHDEXLGSVC; C:\Windows\System32\TPHDEXLG64.exe [47728 2011-03-29] (Lenovo.)
2 TPHKLOAD; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [145256 2011-07-12] (Lenovo Group Limited)
2 TPHKSVC; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [142696 2011-07-12] (Lenovo Group Limited)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2533400 2010-05-03] (Intel Corporation)
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-04-22] ()
2 WRTService; C:\Windows\wrtService.exe [122880 2008-09-18] ()
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
========================== Drivers (Whitelisted) =============
3 5U877; C:\Windows\System32\Drivers\5U877.sys [167040 2011-05-23] (Ricoh co.,Ltd.)
1 agnfilt; C:\Windows\System32\Drivers\agnfilt.sys [200192 2011-08-05] (AT&T)
3 avpnnic; C:\Windows\System32\Drivers\avpnnic.sys [14848 2011-08-05] (AT&T)
3 e1kexpress; C:\Windows\System32\DRIVERS\e1k62x64.sys [295600 2010-07-22] (Intel Corporation)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2010-06-25] (CACE Technologies, Inc.)
3 PCTINDIS5X64; \??\C:\Windows\system32\PCTINDIS5X64.SYS [43032 2008-11-20] (Smith Micro Inc.)
0 Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [139888 2011-03-29] (Lenovo.)
3 swmsflt; C:\Windows\System32\Drivers\swmsflt.sys [30088 2008-08-22] ()
1 tcpipBM; C:\Windows\SysWow64\Drivers\tcpipBM.sys [18816 2008-11-20] (Bytemobile, Inc.)
0 TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [23664 2011-03-29] (Lenovo.)
3 NETw5s64; C:\Windows\System32\DRIVERS\NETw5s64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-08 10:31 - 2012-08-08 10:31 - 00000000 ____D C:\FRST
2012-08-08 07:59 - 2012-08-08 08:00 - 00019518 ____A C:\Users\conorbev\Desktop\temp.html
2012-08-08 07:59 - 2012-08-08 08:00 - 00001638 ____A C:\Users\conorbev\Desktop\temp.org
2012-08-02 11:48 - 2012-08-02 11:48 - 00000000 ____D C:\Users\conorbev\AppData\Roaming\smkits
2012-07-31 11:30 - 2012-07-31 11:30 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-27 10:49 - 2012-07-31 16:20 - 00000000 ____D C:\Users\conorbev\Desktop\JayData
2012-07-24 11:06 - 2012-07-24 11:10 - 00000000 ____D C:\Users\conorbev\Desktop\Matt
2012-07-19 19:36 - 2012-07-19 19:36 - 00011961 ____A C:\Users\conorbev\Desktop\temp.txt
2012-07-19 14:12 - 2012-07-19 14:12 - 01711616 ____A C:\Users\conorbev\Desktop\ApplicationToolkit.ppt
2012-07-12 09:00 - 2012-07-12 09:20 - 02429952 ____A C:\Users\conorbev\Desktop\RDM Gartner Presentation (Jul 12 2012)_with Notes IBM version.ppt
2012-07-12 02:11 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-12 02:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-12 02:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-12 02:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-12 02:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-12 02:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-12 02:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-12 02:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-12 02:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-12 02:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-12 02:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-12 02:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-12 02:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-12 02:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-12 02:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 02:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-12 02:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-12 02:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-12 02:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-12 02:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-12 02:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-12 02:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-12 02:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-12 02:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-12 02:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-12 02:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-12 02:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-12 02:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-12 02:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 07:59 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 07:59 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 07:59 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 07:59 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 07:59 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 07:59 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 07:59 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 07:59 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 07:59 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 07:59 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 07:59 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 07:59 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 07:59 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 07:59 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 07:59 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 07:59 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 07:59 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 07:59 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 07:59 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 19:38 - 2011-11-10 19:00 - 00127440 ____A C:\Users\conorbev\Desktop\DWLCommonServicesEJB.jar
2012-07-10 15:02 - 2012-07-10 20:11 - 00000000 ____D C:\Users\conorbev\Desktop\MDM-EAR
2012-07-10 11:50 - 2012-07-10 12:01 - 122317968 ____A (SmartBear Software) C:\Users\conorbev\Downloads\soapUI-x32-4.5.1.exe
2012-07-09 19:18 - 2012-07-09 19:18 - 29585408 ____A C:\Users\conorbev\Desktop\IM and NTZ 07 09 2012.xls
2012-07-09 18:55 - 2012-07-09 18:55 - 72246061 ____A C:\Users\conorbev\Desktop\MDM-App.ear
2012-07-09 07:04 - 2012-07-09 07:04 - 03506288 ____A C:\Users\conorbev\Desktop\IM and NTZ 07 09 2012.zip
============ 3 Months Modified Files ========================
2012-08-08 08:00 - 2012-08-08 07:59 - 00019518 ____A C:\Users\conorbev\Desktop\temp.html
2012-08-08 08:00 - 2012-08-08 07:59 - 00001638 ____A C:\Users\conorbev\Desktop\temp.org
2012-08-03 08:21 - 2012-03-30 07:42 - 00002881 ____A C:\Users\conorbev\soapui-settings.xml
2012-08-03 08:21 - 2012-03-30 07:23 - 00000675 ____A C:\Users\conorbev\default-soapui-workspace.xml
2012-08-01 16:55 - 2012-03-30 15:34 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-01 16:52 - 2012-06-15 16:20 - 00000920 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1618418893-165983485-2789643751-1000UA.job
2012-08-01 16:52 - 2011-09-08 08:28 - 00000902 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-01 12:03 - 2012-06-15 16:20 - 00000868 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1618418893-165983485-2789643751-1000Core.job
2012-08-01 12:01 - 2011-09-08 08:28 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-01 06:43 - 2009-07-13 21:13 - 00734066 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-31 22:24 - 2009-07-13 20:45 - 00021904 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-31 22:24 - 2009-07-13 20:45 - 00021904 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-31 22:16 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-31 22:16 - 2009-07-13 20:51 - 00048967 ____A C:\Windows\setupact.log
2012-07-31 22:02 - 2011-09-06 19:49 - 00155787 ____A C:\Users\conorbev\.ido.last
2012-07-31 22:02 - 2011-09-03 11:12 - 00001640 ____A C:\Users\conorbev\.recentf
2012-07-31 11:26 - 2011-09-03 01:41 - 02017739 ____A C:\Windows\WindowsUpdate.log
2012-07-27 08:24 - 2011-09-27 21:29 - 00020669 ____A C:\Users\conorbev\.newsrc.eld
2012-07-27 08:24 - 2011-09-27 21:29 - 00012343 ____A C:\Users\conorbev\.newsrc
2012-07-26 17:55 - 2012-03-30 15:34 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-26 17:55 - 2011-09-08 08:14 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-19 19:36 - 2012-07-19 19:36 - 00011961 ____A C:\Users\conorbev\Desktop\temp.txt
2012-07-19 14:12 - 2012-07-19 14:12 - 01711616 ____A C:\Users\conorbev\Desktop\ApplicationToolkit.ppt
2012-07-12 09:24 - 2011-09-30 09:02 - 00003888 ____A C:\cpsweb.log
2012-07-12 09:20 - 2012-07-12 09:00 - 02429952 ____A C:\Users\conorbev\Desktop\RDM Gartner Presentation (Jul 12 2012)_with Notes IBM version.ppt
2012-07-12 02:31 - 2009-07-13 20:45 - 00418640 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 02:30 - 2010-11-20 19:47 - 00021758 ____A C:\Windows\PFRO.log
2012-07-12 02:04 - 2011-09-02 19:04 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-12 02:03 - 2012-06-15 16:21 - 00002374 ____A C:\Users\conorbev\Desktop\Google Chrome.lnk
2012-07-10 22:10 - 2011-10-20 18:02 - 00000600 ____A C:\Users\conorbev\AppData\Local\PUTTY.RND
2012-07-10 13:39 - 2011-09-27 21:04 - 00001870 ____A C:\Users\conorbev\.gnus.el
2012-07-10 12:01 - 2012-07-10 11:50 - 122317968 ____A (SmartBear Software) C:\Users\conorbev\Downloads\soapUI-x32-4.5.1.exe
2012-07-09 19:18 - 2012-07-09 19:18 - 29585408 ____A C:\Users\conorbev\Desktop\IM and NTZ 07 09 2012.xls
2012-07-09 18:55 - 2012-07-09 18:55 - 72246061 ____A C:\Users\conorbev\Desktop\MDM-App.ear
2012-07-09 07:04 - 2012-07-09 07:04 - 03506288 ____A C:\Users\conorbev\Desktop\IM and NTZ 07 09 2012.zip
2012-07-06 18:42 - 2012-07-06 18:42 - 00583502 ____A C:\Users\conorbev\Desktop\Composite.zip
2012-07-06 18:30 - 2012-07-06 18:30 - 00001485 ____N C:\Users\conorbev\Desktop\module.mdmxmi
2012-07-06 15:20 - 2012-07-06 15:20 - 00011723 ____A C:\Users\conorbev\Desktop\#StoreEmailForPolicyNamedInsuredCompositeTxnBP.java#
2012-07-05 16:50 - 2012-07-05 16:50 - 00305152 ____A C:\Users\conorbev\Desktop\Global IBMer Initiation Form for Hyung Gook (Howard) Yoo 373472.xls
2012-07-05 16:49 - 2012-06-22 04:30 - 00274944 ____A C:\Users\conorbev\Desktop\Global_IBMer_Initiation_Form-1.1.xls
2012-06-28 16:43 - 2012-06-28 16:43 - 00011065 ____A C:\Users\conorbev\Desktop\Q2-2012-PSP.xlsx
2012-06-27 16:19 - 2012-06-08 17:00 - 00001049 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-06-27 09:26 - 2012-06-27 09:19 - 16577248 ____A (Mozilla) C:\Users\conorbev\Downloads\Firefox Setup 13.0.1.exe
2012-06-26 14:10 - 2012-06-26 14:09 - 00298024 ____A C:\Windows\Minidump\062612-25100-01.dmp
2012-06-26 14:09 - 2012-06-26 14:09 - 1305433259 ____A C:\Windows\MEMORY.DMP
2012-06-26 10:41 - 2012-04-22 15:27 - 01522386 ____A C:\Users\conorbev\Desktop\DataStewardship_debug.log
2012-06-22 14:21 - 2012-06-21 15:14 - 14010425 ____A C:\Users\conorbev\Desktop\RDM_test.swf
2012-06-21 17:30 - 2012-06-21 17:30 - 02188288 ____A C:\Users\conorbev\Desktop\RDM SWAT Enablement_Draft_vFinal.ppt
2012-06-19 10:19 - 2012-06-19 10:19 - 00228550 ____A C:\Users\conorbev\Desktop\Introduction to the demo flow v3.pptx
2012-06-18 11:16 - 2012-06-18 11:16 - 03230208 ____A C:\Users\conorbev\Desktop\Understanding INFA Integration for MDM.ppt
2012-06-16 22:25 - 2012-06-10 03:53 - 01401856 ____A C:\Users\conorbev\Desktop\MDM v10 Integration.ppt
2012-06-15 16:20 - 2012-06-15 16:20 - 00739808 ____A (Google Inc.) C:\Users\conorbev\Downloads\ChromeSetup.exe
2012-06-15 13:51 - 2012-06-15 13:51 - 01984476 ____A C:\Users\conorbev\Desktop\Clinical Hub Overview.pptx
2012-06-14 12:34 - 2012-06-14 12:34 - 00001066 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-06-14 12:31 - 2012-06-14 12:23 - 22259528 ____A C:\Users\conorbev\Desktop\vlc-2.0.1-win32.exe
2012-06-11 19:08 - 2012-07-12 02:11 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 17:21 - 2012-06-11 17:21 - 00000889 ____A C:\Users\conorbev\Desktop\StoreEmailForPolicyNamedInsuredRequest.txt
2012-06-11 17:17 - 2012-06-11 17:17 - 00002974 ____A C:\Users\conorbev\Desktop\AddContract2.txt
2012-06-11 17:15 - 2012-06-11 17:15 - 00002974 ____A C:\Users\conorbev\Desktop\AddContract1.txt
2012-06-11 17:06 - 2012-06-11 17:06 - 00011961 ____A C:\Users\conorbev\Desktop\StoreEmailForPolicyNamedInsuredCompositeTxnBP.java
2012-06-08 21:43 - 2012-07-11 07:59 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 07:59 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 16:10 - 2011-09-20 09:20 - 00043629 ____A C:\Users\conorbev\Desktop\RDMVideoDataLoads.zip
2012-06-07 10:03 - 2012-06-07 09:49 - 82735493 ____A C:\Users\conorbev\Desktop\RDM_V1.1.1-04-24-2012.zip
2012-06-07 08:36 - 2012-06-07 04:58 - 05538816 ____A C:\Users\conorbev\Desktop\IBM MDM for CricKet 6.7.12_PS.ppt
2012-06-05 22:06 - 2012-07-11 07:59 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 07:59 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 07:59 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 07:59 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 07:59 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 07:59 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 08:23 - 2012-06-05 08:23 - 14343213 ____A C:\Users\conorbev\Desktop\IBM Response to Belk Inc. EAS RFP Final 022211.zip
2012-06-05 08:23 - 2012-06-05 08:23 - 00000022 ____A C:\Users\conorbev\Desktop\IBM Response to Belk Inc. EAS RFP Final 022211.doc.zip
2012-06-02 14:19 - 2012-06-21 07:51 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 07:51 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 07:51 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 07:51 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 07:51 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 07:51 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 07:51 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 07:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 07:51 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-12 02:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-12 02:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-12 02:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-12 02:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-12 02:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-12 02:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-12 02:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-12 02:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-12 02:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-12 02:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-12 02:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-12 02:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-12 02:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-12 02:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-12 02:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-12 02:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-12 02:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-12 02:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-12 02:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 02:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-12 02:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-12 02:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 02:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 02:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-12 02:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-12 02:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 02:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 02:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 07:59 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 07:59 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 07:59 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 07:59 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 07:59 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 07:59 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 07:59 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 07:59 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 07:59 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 08:04 - 2012-05-31 08:04 - 04195630 ____A C:\Users\conorbev\Downloads\MDM Proposal Template.zip
2012-05-29 22:07 - 2012-05-29 21:29 - 05345280 ____A C:\Users\conorbev\Desktop\IBM MDM for CricKet 5.30.12.ppt
2012-05-29 17:50 - 2011-10-18 11:57 - 00002034 ___AH C:\Users\conorbev\Documents\Default.rdp
2012-05-25 09:55 - 2012-05-25 09:53 - 32247698 ____A C:\Users\conorbev\Desktop\II-i2 Insurance Claim Fraun Link Analysis Demo - V2.mp4
2012-05-23 17:45 - 2012-02-01 17:21 - 00118286 ____A C:\Users\conorbev\Desktop\MDMServerCustomerMaintanance.jar
2012-05-22 23:10 - 2012-05-22 23:08 - 03738624 ____A C:\Users\conorbev\Desktop\IBM MDM for Union Bank 5.24.12 CW.ppt
2012-05-21 13:33 - 2012-05-20 10:27 - 34902016 ____A C:\Users\conorbev\Downloads\InfoSphere_MDM_Server_v10_Technical_Deep_Dive-2012-Apr-10.ppt
2012-05-18 11:05 - 2012-05-18 11:01 - 00111104 ____A C:\Users\conorbev\Desktop\FE RFP Questions.xls
2012-05-18 10:34 - 2012-05-18 10:34 - 00007605 ____A C:\Users\conorbev\AppData\Local\Resmon.ResmonCfg
2012-05-17 08:09 - 2012-05-17 08:09 - 00379182 ____A C:\Users\conorbev\Desktop\Cricket CDL_FromTomD05172012.pptx
2012-05-15 14:05 - 2012-05-15 13:58 - 56154688 ____A C:\Users\conorbev\Downloads\MDMServerDemo.mp4
2012-05-15 09:25 - 2012-05-15 09:25 - 01534464 ____A C:\Users\conorbev\Desktop\IBM MDM Functional Overview Deck _for Mark.ppt
ZeroAccess:
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\@
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\L
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\n
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U\00000001.@
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U\80000000.@
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U\800000cb.@
ZeroAccess:
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\@
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\L
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\n
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 16315.52 MB
Available physical RAM: 15134.02 MB
Total Pagefile: 16313.71 MB
Available Pagefile: 15125.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:465.76 GB) (Free:26.99 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive e: () (Removable) (Total:15.11 GB) (Free:13.71 GB) NTFS
3 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
4 Drive y: (SSD) (Fixed) (Total:119.24 GB) (Free:11.47 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 119 GB 0 B
Disk 1 Online 465 GB 0 B
Disk 2 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 119 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SSD NTFS Partition 119 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 6024 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E NTFS Removable 15 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 10:41
======================= End Of Log ==========================
I'm new to this forum and am getting the same "Critical Error" leading to restart in 1 minute issues that other people have encountered.
I have run the frst64 scan and this is the contents of FRST.txt:
Scan result of Farbar Recovery Scan Tool Version: 08-08-2012 01
Ran by SYSTEM at 08-08-2012 10:31:43
Running from E:\
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [TpShocks] TpShocks.exe [x]
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2851112 2011-11-17] (Synaptics Incorporated)
HKLM\...\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [62312 2010-07-27] (Lenovo Group Limited)
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-15] ()
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2417032 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-11-01] (Intel(R) Corporation)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-09-27] (Intel Corporation)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [112152 2010-05-03] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [AT&T Communication Manager] "C:\Program Files (x86)\AT&T\Communication Manager\ATTCM.exe" -a [33280 2008-12-01] (ATT)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor [1631808 2012-01-23] (Lenovo Group Limited)
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2012-01-18] (VMware, Inc.)
HKU\conorbev\...\Run: [NetSP - restore settings on power failure] "C:\Program Files (x86)\AT&T Global Network Client\NetSP.exe" -show [55136 2011-08-05] (AT&T)
HKU\conorbev\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1242448 2011-10-20] (Valve Corporation)
HKU\conorbev\...\Run: [Akamai NetSession Interface] "C:\Users\conorbev\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc)
HKU\conorbev\...\Run: [Google Update] "C:\Users\conorbev\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-06-15] (Google Inc.)
HKU\conorbev\...\Run: [SODCPreLoad] C:\notes\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090922-1655\preload.exe C:\notes\data\workspace\.sodc\ [40960 2011-09-03] ()
HKU\conorbev\...\Run: [DAT3F3F.tmp.exe] C:\Users\conorbev\AppData\Local\Temp\DAT3F3F.tmp.exe [50176 2012-07-31] (Mesh Computers)
HKLM\...\RunOnce: [*Restore] C:\Windows\system32\rstrui.exe /RUNONCE [296960 2010-11-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{B6503417-F4F3-4080-A1F4-C38947AB5B95}: [NameServer]9.0.128.50,9.0.130.50
Startup: C:\Users\All Users\Start Menu\Programs\Startup\AT&T Global Network Client Monitor.lnk
ShortcutTarget: AT&T Global Network Client Monitor.lnk -> C:\Windows\Installer\{3330748F-151F-4112-A88C-04AE88EDBE34}\NetGM1_89563E53ECF44E868145468A128BDC83.exe (Flexera Software, Inc.)
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files (x86)\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\Users\All Users\Start Menu\Programs\Startup\InfoPrint Select Notification.lnk
ShortcutTarget: InfoPrint Select Notification.lnk -> C:\Program Files\ibm\Infoprint Select\ipnotify.exe ()
Startup: C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\conorbev\Start Menu\Programs\Startup\MagicDisc.lnk
ShortcutTarget: MagicDisc.lnk -> C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
==================== Services (Whitelisted) ======
3 ATTRcAppSvc; "C:\Program Files (x86)\AT&T\Communication Manager\RcAppSvc.exe" /n "ATTRcAppSvc" [113152 2008-11-20] (SmithMicro Inc.)
2 BTHSSecurityMgr; "C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe" [135440 2011-10-20] (Intel(R) Corporation)
3 CAATT; "C:\Program Files (x86)\AT&T\Communication Manager\ConAppsSvc.exe" /n "CAATT" [125440 2008-11-20] (SmithMicro Inc.)
3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [478056 2012-01-23] (Lenovo.)
2 IBMPMSVC; C:\Windows\System32\ibmpmsvc.exe [45928 2011-08-11] (Lenovo.)
2 IBMWAS70Service - conorbev-W510Node02; "C:\Program Files (x86)\IBM\SDP_75\runtimes\base_v7\bin\wasservice.exe" "IBMWAS70Service - conorbev-W510Node02" [81920 2011-11-18] ()
2 LENOVO.CAMMUTE; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [50536 2010-07-27] (Lenovo Group Limited)
2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [101736 2011-07-12] (Lenovo Group Limited)
2 LENOVO.TPKNRSVC; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [74088 2010-07-27] (Lenovo Group Limited)
2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [133992 2011-07-12] (Lenovo Group Limited)
2 Lotus Notes Diagnostics; C:\notes\nsd.exe -svcinvoke -ini "C:\notes\notes.ini" [14999 2012-08-01] ()
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe" [237008 2011-06-17] (McAfee, Inc.)
2 Multi-user Cleanup Service; C:\notes\ntmulti.exe [58760 2009-09-29] (IBM Corp)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-11-01] ()
2 netcfgsvr; "C:\Program Files (x86)\AT&T Global Network Client\netcfgsvr.exe" [1061728 2011-08-05] (AT&T)
2 NetClientSvc; "C:\Program Files (x86)\AT&T Global Network Client\NetClientSvc.exe" [352096 2011-08-05] (AT&T)
3 NetLogSvc; C:\Program Files (x86)\AT&T Global Network Client\NetLogSvc.exe [81760 2011-08-05] (AT&T)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
3 Power Manager DBC Service; "C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE" [89152 2012-01-23] (Lenovo)
3 PwmEWSvc; C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [175168 2012-01-23] (Lenovo Group Limited)
2 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [28672 2011-07-25] (Lenovo Group Limited)
2 SwiCardDetectSvc; "C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe" [317296 2011-05-20] (Sierra Wireless, Inc.)
3 TPHDEXLGSVC; C:\Windows\System32\TPHDEXLG64.exe [47728 2011-03-29] (Lenovo.)
2 TPHKLOAD; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [145256 2011-07-12] (Lenovo Group Limited)
2 TPHKSVC; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [142696 2011-07-12] (Lenovo Group Limited)
2 UNS; "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe" [2533400 2010-05-03] (Intel Corporation)
2 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2012-04-22] ()
2 WRTService; C:\Windows\wrtService.exe [122880 2008-09-18] ()
3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini" [x]
========================== Drivers (Whitelisted) =============
3 5U877; C:\Windows\System32\Drivers\5U877.sys [167040 2011-05-23] (Ricoh co.,Ltd.)
1 agnfilt; C:\Windows\System32\Drivers\agnfilt.sys [200192 2011-08-05] (AT&T)
3 avpnnic; C:\Windows\System32\Drivers\avpnnic.sys [14848 2011-08-05] (AT&T)
3 e1kexpress; C:\Windows\System32\DRIVERS\e1k62x64.sys [295600 2010-07-22] (Intel Corporation)
2 NPF; C:\Windows\System32\Drivers\NPF.sys [35344 2010-06-25] (CACE Technologies, Inc.)
3 PCTINDIS5X64; \??\C:\Windows\system32\PCTINDIS5X64.SYS [43032 2008-11-20] (Smith Micro Inc.)
0 Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [139888 2011-03-29] (Lenovo.)
3 swmsflt; C:\Windows\System32\Drivers\swmsflt.sys [30088 2008-08-22] ()
1 tcpipBM; C:\Windows\SysWow64\Drivers\tcpipBM.sys [18816 2008-11-20] (Bytemobile, Inc.)
0 TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [23664 2011-03-29] (Lenovo.)
3 NETw5s64; C:\Windows\System32\DRIVERS\NETw5s64.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-08-08 10:31 - 2012-08-08 10:31 - 00000000 ____D C:\FRST
2012-08-08 07:59 - 2012-08-08 08:00 - 00019518 ____A C:\Users\conorbev\Desktop\temp.html
2012-08-08 07:59 - 2012-08-08 08:00 - 00001638 ____A C:\Users\conorbev\Desktop\temp.org
2012-08-02 11:48 - 2012-08-02 11:48 - 00000000 ____D C:\Users\conorbev\AppData\Roaming\smkits
2012-07-31 11:30 - 2012-07-31 11:30 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-27 10:49 - 2012-07-31 16:20 - 00000000 ____D C:\Users\conorbev\Desktop\JayData
2012-07-24 11:06 - 2012-07-24 11:10 - 00000000 ____D C:\Users\conorbev\Desktop\Matt
2012-07-19 19:36 - 2012-07-19 19:36 - 00011961 ____A C:\Users\conorbev\Desktop\temp.txt
2012-07-19 14:12 - 2012-07-19 14:12 - 01711616 ____A C:\Users\conorbev\Desktop\ApplicationToolkit.ppt
2012-07-12 09:00 - 2012-07-12 09:20 - 02429952 ____A C:\Users\conorbev\Desktop\RDM Gartner Presentation (Jul 12 2012)_with Notes IBM version.ppt
2012-07-12 02:11 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-12 02:01 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-12 02:01 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-12 02:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-12 02:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-12 02:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-12 02:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-12 02:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-12 02:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-12 02:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-12 02:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-12 02:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-12 02:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-12 02:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-12 02:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 02:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-12 02:01 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-12 02:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-12 02:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-12 02:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-12 02:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-12 02:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-12 02:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-12 02:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-12 02:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-12 02:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-12 02:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-12 02:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-12 02:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 07:59 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 07:59 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 07:59 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 07:59 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 07:59 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 07:59 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 07:59 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 07:59 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 07:59 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 07:59 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 07:59 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 07:59 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 07:59 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 07:59 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 07:59 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 07:59 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 07:59 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 07:59 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 07:59 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 19:38 - 2011-11-10 19:00 - 00127440 ____A C:\Users\conorbev\Desktop\DWLCommonServicesEJB.jar
2012-07-10 15:02 - 2012-07-10 20:11 - 00000000 ____D C:\Users\conorbev\Desktop\MDM-EAR
2012-07-10 11:50 - 2012-07-10 12:01 - 122317968 ____A (SmartBear Software) C:\Users\conorbev\Downloads\soapUI-x32-4.5.1.exe
2012-07-09 19:18 - 2012-07-09 19:18 - 29585408 ____A C:\Users\conorbev\Desktop\IM and NTZ 07 09 2012.xls
2012-07-09 18:55 - 2012-07-09 18:55 - 72246061 ____A C:\Users\conorbev\Desktop\MDM-App.ear
2012-07-09 07:04 - 2012-07-09 07:04 - 03506288 ____A C:\Users\conorbev\Desktop\IM and NTZ 07 09 2012.zip
============ 3 Months Modified Files ========================
2012-08-08 08:00 - 2012-08-08 07:59 - 00019518 ____A C:\Users\conorbev\Desktop\temp.html
2012-08-08 08:00 - 2012-08-08 07:59 - 00001638 ____A C:\Users\conorbev\Desktop\temp.org
2012-08-03 08:21 - 2012-03-30 07:42 - 00002881 ____A C:\Users\conorbev\soapui-settings.xml
2012-08-03 08:21 - 2012-03-30 07:23 - 00000675 ____A C:\Users\conorbev\default-soapui-workspace.xml
2012-08-01 16:55 - 2012-03-30 15:34 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-08-01 16:52 - 2012-06-15 16:20 - 00000920 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1618418893-165983485-2789643751-1000UA.job
2012-08-01 16:52 - 2011-09-08 08:28 - 00000902 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-08-01 12:03 - 2012-06-15 16:20 - 00000868 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1618418893-165983485-2789643751-1000Core.job
2012-08-01 12:01 - 2011-09-08 08:28 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-08-01 06:43 - 2009-07-13 21:13 - 00734066 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-31 22:24 - 2009-07-13 20:45 - 00021904 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-31 22:24 - 2009-07-13 20:45 - 00021904 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-31 22:16 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-31 22:16 - 2009-07-13 20:51 - 00048967 ____A C:\Windows\setupact.log
2012-07-31 22:02 - 2011-09-06 19:49 - 00155787 ____A C:\Users\conorbev\.ido.last
2012-07-31 22:02 - 2011-09-03 11:12 - 00001640 ____A C:\Users\conorbev\.recentf
2012-07-31 11:26 - 2011-09-03 01:41 - 02017739 ____A C:\Windows\WindowsUpdate.log
2012-07-27 08:24 - 2011-09-27 21:29 - 00020669 ____A C:\Users\conorbev\.newsrc.eld
2012-07-27 08:24 - 2011-09-27 21:29 - 00012343 ____A C:\Users\conorbev\.newsrc
2012-07-26 17:55 - 2012-03-30 15:34 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-26 17:55 - 2011-09-08 08:14 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-19 19:36 - 2012-07-19 19:36 - 00011961 ____A C:\Users\conorbev\Desktop\temp.txt
2012-07-19 14:12 - 2012-07-19 14:12 - 01711616 ____A C:\Users\conorbev\Desktop\ApplicationToolkit.ppt
2012-07-12 09:24 - 2011-09-30 09:02 - 00003888 ____A C:\cpsweb.log
2012-07-12 09:20 - 2012-07-12 09:00 - 02429952 ____A C:\Users\conorbev\Desktop\RDM Gartner Presentation (Jul 12 2012)_with Notes IBM version.ppt
2012-07-12 02:31 - 2009-07-13 20:45 - 00418640 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-12 02:30 - 2010-11-20 19:47 - 00021758 ____A C:\Windows\PFRO.log
2012-07-12 02:04 - 2011-09-02 19:04 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-12 02:03 - 2012-06-15 16:21 - 00002374 ____A C:\Users\conorbev\Desktop\Google Chrome.lnk
2012-07-10 22:10 - 2011-10-20 18:02 - 00000600 ____A C:\Users\conorbev\AppData\Local\PUTTY.RND
2012-07-10 13:39 - 2011-09-27 21:04 - 00001870 ____A C:\Users\conorbev\.gnus.el
2012-07-10 12:01 - 2012-07-10 11:50 - 122317968 ____A (SmartBear Software) C:\Users\conorbev\Downloads\soapUI-x32-4.5.1.exe
2012-07-09 19:18 - 2012-07-09 19:18 - 29585408 ____A C:\Users\conorbev\Desktop\IM and NTZ 07 09 2012.xls
2012-07-09 18:55 - 2012-07-09 18:55 - 72246061 ____A C:\Users\conorbev\Desktop\MDM-App.ear
2012-07-09 07:04 - 2012-07-09 07:04 - 03506288 ____A C:\Users\conorbev\Desktop\IM and NTZ 07 09 2012.zip
2012-07-06 18:42 - 2012-07-06 18:42 - 00583502 ____A C:\Users\conorbev\Desktop\Composite.zip
2012-07-06 18:30 - 2012-07-06 18:30 - 00001485 ____N C:\Users\conorbev\Desktop\module.mdmxmi
2012-07-06 15:20 - 2012-07-06 15:20 - 00011723 ____A C:\Users\conorbev\Desktop\#StoreEmailForPolicyNamedInsuredCompositeTxnBP.java#
2012-07-05 16:50 - 2012-07-05 16:50 - 00305152 ____A C:\Users\conorbev\Desktop\Global IBMer Initiation Form for Hyung Gook (Howard) Yoo 373472.xls
2012-07-05 16:49 - 2012-06-22 04:30 - 00274944 ____A C:\Users\conorbev\Desktop\Global_IBMer_Initiation_Form-1.1.xls
2012-06-28 16:43 - 2012-06-28 16:43 - 00011065 ____A C:\Users\conorbev\Desktop\Q2-2012-PSP.xlsx
2012-06-27 16:19 - 2012-06-08 17:00 - 00001049 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-06-27 09:26 - 2012-06-27 09:19 - 16577248 ____A (Mozilla) C:\Users\conorbev\Downloads\Firefox Setup 13.0.1.exe
2012-06-26 14:10 - 2012-06-26 14:09 - 00298024 ____A C:\Windows\Minidump\062612-25100-01.dmp
2012-06-26 14:09 - 2012-06-26 14:09 - 1305433259 ____A C:\Windows\MEMORY.DMP
2012-06-26 10:41 - 2012-04-22 15:27 - 01522386 ____A C:\Users\conorbev\Desktop\DataStewardship_debug.log
2012-06-22 14:21 - 2012-06-21 15:14 - 14010425 ____A C:\Users\conorbev\Desktop\RDM_test.swf
2012-06-21 17:30 - 2012-06-21 17:30 - 02188288 ____A C:\Users\conorbev\Desktop\RDM SWAT Enablement_Draft_vFinal.ppt
2012-06-19 10:19 - 2012-06-19 10:19 - 00228550 ____A C:\Users\conorbev\Desktop\Introduction to the demo flow v3.pptx
2012-06-18 11:16 - 2012-06-18 11:16 - 03230208 ____A C:\Users\conorbev\Desktop\Understanding INFA Integration for MDM.ppt
2012-06-16 22:25 - 2012-06-10 03:53 - 01401856 ____A C:\Users\conorbev\Desktop\MDM v10 Integration.ppt
2012-06-15 16:20 - 2012-06-15 16:20 - 00739808 ____A (Google Inc.) C:\Users\conorbev\Downloads\ChromeSetup.exe
2012-06-15 13:51 - 2012-06-15 13:51 - 01984476 ____A C:\Users\conorbev\Desktop\Clinical Hub Overview.pptx
2012-06-14 12:34 - 2012-06-14 12:34 - 00001066 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-06-14 12:31 - 2012-06-14 12:23 - 22259528 ____A C:\Users\conorbev\Desktop\vlc-2.0.1-win32.exe
2012-06-11 19:08 - 2012-07-12 02:11 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-11 17:21 - 2012-06-11 17:21 - 00000889 ____A C:\Users\conorbev\Desktop\StoreEmailForPolicyNamedInsuredRequest.txt
2012-06-11 17:17 - 2012-06-11 17:17 - 00002974 ____A C:\Users\conorbev\Desktop\AddContract2.txt
2012-06-11 17:15 - 2012-06-11 17:15 - 00002974 ____A C:\Users\conorbev\Desktop\AddContract1.txt
2012-06-11 17:06 - 2012-06-11 17:06 - 00011961 ____A C:\Users\conorbev\Desktop\StoreEmailForPolicyNamedInsuredCompositeTxnBP.java
2012-06-08 21:43 - 2012-07-11 07:59 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 07:59 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 16:10 - 2011-09-20 09:20 - 00043629 ____A C:\Users\conorbev\Desktop\RDMVideoDataLoads.zip
2012-06-07 10:03 - 2012-06-07 09:49 - 82735493 ____A C:\Users\conorbev\Desktop\RDM_V1.1.1-04-24-2012.zip
2012-06-07 08:36 - 2012-06-07 04:58 - 05538816 ____A C:\Users\conorbev\Desktop\IBM MDM for CricKet 6.7.12_PS.ppt
2012-06-05 22:06 - 2012-07-11 07:59 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 07:59 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 07:59 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 07:59 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 07:59 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 07:59 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 08:23 - 2012-06-05 08:23 - 14343213 ____A C:\Users\conorbev\Desktop\IBM Response to Belk Inc. EAS RFP Final 022211.zip
2012-06-05 08:23 - 2012-06-05 08:23 - 00000022 ____A C:\Users\conorbev\Desktop\IBM Response to Belk Inc. EAS RFP Final 022211.doc.zip
2012-06-02 14:19 - 2012-06-21 07:51 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 07:51 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 07:51 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 07:51 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 07:51 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 07:51 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 07:51 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 07:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 07:51 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-12 02:01 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-12 02:01 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-12 02:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-12 02:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-12 02:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-12 02:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-12 02:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-12 02:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-12 02:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-12 02:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-12 02:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-12 02:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-12 02:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-12 02:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-12 02:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-12 02:01 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-12 02:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-12 02:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-12 02:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 02:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-12 02:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-12 02:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 02:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 02:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-12 02:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-12 02:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 02:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 02:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-11 07:59 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 07:59 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 07:59 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 07:59 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 07:59 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 07:59 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 07:59 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 07:59 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 07:59 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 08:04 - 2012-05-31 08:04 - 04195630 ____A C:\Users\conorbev\Downloads\MDM Proposal Template.zip
2012-05-29 22:07 - 2012-05-29 21:29 - 05345280 ____A C:\Users\conorbev\Desktop\IBM MDM for CricKet 5.30.12.ppt
2012-05-29 17:50 - 2011-10-18 11:57 - 00002034 ___AH C:\Users\conorbev\Documents\Default.rdp
2012-05-25 09:55 - 2012-05-25 09:53 - 32247698 ____A C:\Users\conorbev\Desktop\II-i2 Insurance Claim Fraun Link Analysis Demo - V2.mp4
2012-05-23 17:45 - 2012-02-01 17:21 - 00118286 ____A C:\Users\conorbev\Desktop\MDMServerCustomerMaintanance.jar
2012-05-22 23:10 - 2012-05-22 23:08 - 03738624 ____A C:\Users\conorbev\Desktop\IBM MDM for Union Bank 5.24.12 CW.ppt
2012-05-21 13:33 - 2012-05-20 10:27 - 34902016 ____A C:\Users\conorbev\Downloads\InfoSphere_MDM_Server_v10_Technical_Deep_Dive-2012-Apr-10.ppt
2012-05-18 11:05 - 2012-05-18 11:01 - 00111104 ____A C:\Users\conorbev\Desktop\FE RFP Questions.xls
2012-05-18 10:34 - 2012-05-18 10:34 - 00007605 ____A C:\Users\conorbev\AppData\Local\Resmon.ResmonCfg
2012-05-17 08:09 - 2012-05-17 08:09 - 00379182 ____A C:\Users\conorbev\Desktop\Cricket CDL_FromTomD05172012.pptx
2012-05-15 14:05 - 2012-05-15 13:58 - 56154688 ____A C:\Users\conorbev\Downloads\MDMServerDemo.mp4
2012-05-15 09:25 - 2012-05-15 09:25 - 01534464 ____A C:\Users\conorbev\Desktop\IBM MDM Functional Overview Deck _for Mark.ppt
ZeroAccess:
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\@
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\L
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\n
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U\00000001.@
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U\80000000.@
C:\Windows\Installer\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U\800000cb.@
ZeroAccess:
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\@
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\L
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\n
C:\Users\conorbev\AppData\Local\{6dd08b73-2e11-ef59-276b-cc5ba85f43ed}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 7%
Total physical RAM: 16315.52 MB
Available physical RAM: 15134.02 MB
Total Pagefile: 16313.71 MB
Available Pagefile: 15125.3 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:465.76 GB) (Free:26.99 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive e: () (Removable) (Total:15.11 GB) (Free:13.71 GB) NTFS
3 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
4 Drive y: (SSD) (Fixed) (Total:119.24 GB) (Free:11.47 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 119 GB 0 B
Disk 1 Online 465 GB 0 B
Disk 2 Online 15 GB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 119 GB 1024 KB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SSD NTFS Partition 119 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 15 GB 6024 KB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E NTFS Removable 15 GB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 10:41
======================= End Of Log ==========================