PART 2:
========== Files/Folders - Created Within 30 Days ==========
[2012/12/16 12:11:19 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{101127C6-F807-49C4-B4A0-A46CB144F8FD}
[2012/12/15 22:20:51 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{34D4C856-C0E4-47A9-A2E4-82CC1435F3ED}
[2012/12/15 10:20:26 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{4FB8CD1E-9B6B-43E3-8F7D-7C7F73ED60E1}
[2012/12/14 22:20:14 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{230EE0CE-CF30-4C05-8F42-97EF574830E2}
[2012/12/13 21:00:16 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{C23E470B-D917-4E82-847C-1A6305F21050}
[2012/12/13 09:00:04 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{0F6DA327-67C7-4BDC-B167-255A23A39F75}
[2012/12/12 17:33:17 | 000,000,000 | ---D | C] -- C:\Users\Kathi\Documents\MysteryAgency
[2012/12/12 16:56:52 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{C3036A2B-1AE2-4960-9181-A0580CB0B1CC}
[2012/12/12 03:02:39 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/12/12 03:02:39 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/12/12 03:02:38 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/12/12 03:02:38 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/12/12 03:02:38 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/12/12 03:02:38 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/12/12 03:02:38 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/12/12 03:02:38 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/12/12 03:02:36 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/12/12 03:02:36 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/12/12 03:02:36 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/12/12 03:02:36 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/12/12 03:02:34 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/12/12 03:02:33 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/12/12 03:02:33 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2012/12/12 02:56:15 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2012/12/12 02:56:15 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2012/12/12 02:56:15 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2012/12/12 02:56:15 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2012/12/12 02:56:00 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2012/12/12 02:56:00 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2012/12/12 02:56:00 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2012/12/12 02:56:00 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2012/12/12 02:55:58 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2012/12/12 02:55:57 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2012/12/12 02:55:57 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2012/12/12 02:55:57 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2012/12/12 02:55:57 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2012/12/12 02:55:57 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2012/12/12 02:55:57 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2012/12/12 02:55:56 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2012/12/12 02:55:56 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/12 02:55:55 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/12/12 02:55:54 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/12/12 02:55:54 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/12/12 02:55:54 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/12/12 02:55:54 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/12 02:55:54 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/12 02:55:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/12 02:55:54 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/12/12 02:55:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/12 02:55:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/12 02:55:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/12/12 02:55:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/12/12 02:55:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/12/12 02:55:54 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/12 02:55:53 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/12 02:55:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/12/12 02:55:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/12 02:55:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/12 02:55:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/12 02:55:52 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/12/12 02:55:52 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/12 02:55:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/12/12 02:55:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/12/12 02:55:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/12/12 02:55:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/12/12 02:55:50 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2012/12/12 02:55:35 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpnet.dll
[2012/12/12 02:55:35 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpnet.dll
[2012/12/11 20:56:55 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{07DA5331-7C91-4EF8-8E30-B2038862347A}
[2012/12/10 17:21:54 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{5C48830D-5769-45DB-A00D-16847BE68C08}
[2012/12/09 16:35:38 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{8292795E-7025-4FD4-9BA5-95A8D282A127}
[2012/12/08 21:09:15 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{23DF0909-A38F-4D77-9599-597CF11C44DF}
[2012/12/08 16:18:19 | 000,000,000 | ---D | C] -- C:\Users\Kathi\Desktop\Alexis Music
[2012/12/08 09:09:03 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{F2D3781D-EB9B-40E3-A4A8-4E71AF75C4BA}
[2012/12/07 21:08:37 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{D532FEFA-41A8-4F65-BCDE-7F2E98426B1A}
[2012/12/06 21:09:00 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{F06706D2-6961-4278-95FB-CD9741C3731D}
[2012/12/06 09:08:34 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{4B2CE0AD-ECC4-41D6-8E2A-DE0ED913DCC7}
[2012/12/05 17:16:51 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{8CB98B19-057D-4B4E-A2B8-78105B9EF410}
[2012/12/05 05:16:40 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{05E9E7E9-8698-4847-8C3C-A3DEA214F888}
[2012/12/05 02:32:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/12/04 17:16:28 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{F32A04B1-CED7-4C9A-9110-88A299271614}
[2012/12/03 21:46:06 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{7EDE21F6-4DA8-4439-A5C9-66AA788C005D}
[2012/12/03 15:10:21 | 000,000,000 | ---D | C] -- C:\Users\Kathi\Desktop\PNA
[2012/12/03 08:25:51 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{FCD356BC-10A8-4E72-BE15-096DB2D11D19}
[2012/12/02 12:08:23 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{B681B04F-8F72-4E67-86A2-4F8D97D143EE}
[2012/12/02 12:07:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trustwave
[2012/12/02 12:00:28 | 000,000,000 | ---D | C] -- C:\Users\Kathi\Desktop\Contractor Stuff
[2012/12/02 00:07:56 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{15F4C8B7-047F-4CC7-B9DD-19C43E557320}
[2012/12/01 14:33:10 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/12/01 12:07:26 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{61F9D008-5B6C-42B6-91B9-0D910B040E50}
[2012/11/30 14:32:57 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{4608C5FA-37EF-4EE0-94CE-1F9378567A3D}
[2012/11/29 15:11:34 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/11/29 15:10:30 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{C9D3E595-166B-4108-8FBB-E38912055C17}
[2012/11/29 00:39:55 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/11/28 20:13:47 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{E8E58D15-3237-4464-8EF2-372578F51F11}
[2012/11/28 08:13:34 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{AB4B3DAA-4657-457A-915B-EF2D01D484EF}
[2012/11/28 00:24:33 | 000,000,000 | ---D | C] -- C:\Users\Kathi\Desktop\Virus removal
[2012/11/28 00:05:18 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Roaming\Malwarebytes
[2012/11/28 00:05:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/28 00:05:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/11/28 00:05:12 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/11/28 00:05:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/11/27 23:19:15 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/11/27 23:19:15 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/11/27 23:19:15 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/11/27 23:18:45 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/11/27 23:18:14 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/11/27 22:28:13 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012/11/27 18:37:28 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{57E04207-89F6-446D-8DCB-B86398E7A2CA}
[2012/11/27 03:28:51 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{8293A4E9-4F86-458A-9056-38D94E7A1B2D}
[2012/11/26 15:28:25 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{F9A09894-87D9-4E4A-8A26-76C7F64C4A0A}
[2012/11/25 13:11:14 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{FE403889-A439-46EF-8F08-68DF75D25B1D}
[2012/11/25 01:10:50 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{A8A9512F-FF18-4BBC-A7AA-7B206248EFE4}
[2012/11/24 13:10:37 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{0EE3B6A2-DA5B-4E17-B2E4-2BD6A8A48774}
[2012/11/23 11:46:27 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{269F6611-3BD7-4DEB-93EC-AB388F35B96E}
[2012/11/22 23:46:01 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{CD6029AC-1401-46E8-8619-25569DF6764A}
[2012/11/20 13:14:29 | 000,000,000 | ---D | C] -- C:\LGMobileUpgrade
[2012/11/20 13:13:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LG Electronics
[2012/11/20 11:35:09 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{7FA3AFF0-1ED7-4C62-93F5-35427272AF4C}
[2012/11/19 23:34:58 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{58BA76CF-231E-4630-8C02-C9B31FF1370C}
[2012/11/19 17:34:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
[2012/11/19 17:32:55 | 000,000,000 | ---D | C] -- C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}
[2012/11/19 11:34:46 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{2E351E04-2111-4EF3-86CD-CBEE0261BAEE}
[2012/11/18 23:34:34 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{D5AD68FF-7C77-4356-AF80-3F7D56E66B3D}
[2012/11/18 11:34:21 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{58A551D9-F5D8-4FE3-8261-D691F564D20E}
[2012/11/17 15:16:26 | 000,000,000 | ---D | C] -- C:\Users\Kathi\AppData\Local\{0C525CDA-33F9-42CE-871D-5609DD015E6D}
[2011/02/25 18:07:35 | 021,882,800 | ---- | C] (Trion Worlds, Inc.) -- C:\Users\Kathi\Rift_LIVE_Patcher_setup.exe
========== Files - Modified Within 30 Days ==========
[2012/12/16 23:40:00 | 000,000,338 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/12/16 23:35:02 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/16 23:32:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/16 21:28:30 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/16 21:28:30 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/16 19:05:01 | 000,000,266 | ---- | M] () -- C:\Windows\tasks\RMSchedule.job
[2012/12/16 18:35:03 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/16 15:44:19 | 000,001,916 | ---- | M] () -- C:\Users\Kathi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6700.lnk
[2012/12/16 15:42:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/12/16 15:42:05 | 4025,966,592 | -HS- | M] () -- C:\hiberfil.sys
[2012/12/12 03:26:38 | 000,382,112 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/11 18:32:32 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/12/11 18:32:32 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/12/10 20:57:23 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForKathi.job
[2012/12/09 17:16:05 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_lgvzandnetadb_01005.Wdf
[2012/12/03 15:08:13 | 001,540,212 | ---- | M] () -- C:\Users\Kathi\Documents\Scan0145.pdf
[2012/12/02 12:07:13 | 000,001,958 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TrustKeeper Agent Status.lnk
[2012/11/29 22:13:08 | 002,213,678 | ---- | M] () -- C:\Users\Kathi\Documents\Scan0144.pdf
[2012/11/29 20:59:10 | 003,800,587 | ---- | M] () -- C:\Users\Kathi\Documents\Scan0143.pdf
[2012/11/29 20:55:38 | 004,816,175 | ---- | M] () -- C:\Users\Kathi\Documents\Scan0142.pdf
[2012/11/28 00:05:14 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/27 23:45:09 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/11/27 22:28:48 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2012/11/27 22:26:13 | 000,000,034 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxoverride.ini
[2012/11/26 17:18:07 | 000,226,083 | ---- | M] () -- C:\Users\Kathi\Desktop\Auto Insurance.pdf
[2012/11/23 13:16:24 | 000,251,271 | ---- | M] () -- C:\Users\Kathi\Desktop\Matthew Xmas.pdf
[2012/11/23 13:15:59 | 000,246,731 | ---- | M] () -- C:\Users\Kathi\Documents\Scan0141.pdf
[2012/11/23 13:14:04 | 000,458,368 | ---- | M] () -- C:\Users\Kathi\Desktop\Alexis Xmas List.pdf
[2012/11/23 13:12:48 | 000,453,825 | ---- | M] () -- C:\Users\Kathi\Documents\Scan0140.pdf
[2012/11/23 13:11:07 | 000,726,444 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/23 13:11:07 | 000,624,162 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/11/23 13:11:07 | 000,106,538 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/11/19 17:34:57 | 000,002,147 | ---- | M] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
========== Files Created - No Company Name ==========
[2012/12/09 17:16:05 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_lgvzandnetadb_01005.Wdf
[2012/12/03 15:08:12 | 001,540,212 | ---- | C] () -- C:\Users\Kathi\Documents\Scan0145.pdf
[2012/12/02 12:07:13 | 000,001,958 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TrustKeeper Agent Status.lnk
[2012/11/29 22:13:01 | 002,213,678 | ---- | C] () -- C:\Users\Kathi\Documents\Scan0144.pdf
[2012/11/29 20:59:08 | 003,800,587 | ---- | C] () -- C:\Users\Kathi\Documents\Scan0143.pdf
[2012/11/29 20:55:35 | 004,816,175 | ---- | C] () -- C:\Users\Kathi\Documents\Scan0142.pdf
[2012/11/28 00:05:14 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/27 23:19:15 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/11/27 23:19:15 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/11/27 23:19:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/11/27 23:19:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/11/27 23:19:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/11/27 22:28:48 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2012/11/26 21:01:18 | 000,000,034 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxoverride.ini
[2012/11/26 17:18:05 | 000,226,083 | ---- | C] () -- C:\Users\Kathi\Desktop\Auto Insurance.pdf
[2012/11/23 13:16:24 | 000,251,271 | ---- | C] () -- C:\Users\Kathi\Desktop\Matthew Xmas.pdf
[2012/11/23 13:15:59 | 000,246,731 | ---- | C] () -- C:\Users\Kathi\Documents\Scan0141.pdf
[2012/11/23 13:14:04 | 000,458,368 | ---- | C] () -- C:\Users\Kathi\Desktop\Alexis Xmas List.pdf
[2012/11/23 13:12:48 | 000,453,825 | ---- | C] () -- C:\Users\Kathi\Documents\Scan0140.pdf
[2012/11/19 17:34:57 | 000,002,147 | ---- | C] () -- C:\Users\Public\Desktop\HP Support Assistant.lnk
[2012/08/11 10:15:38 | 006,885,376 | ---- | C] () -- C:\Users\Kathi\s-1-5-21-2635634824-2115636220-2321885851-1000.rrr
[2012/07/04 21:55:42 | 000,870,128 | ---- | C] () -- C:\Users\Kathi\AppData\Roaming\mcs.rma
[2012/06/15 21:25:50 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2011/10/05 17:16:07 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2011/05/22 19:27:27 | 000,001,854 | ---- | C] () -- C:\Users\Kathi\AppData\Roaming\GhostObjGAFix.xml
[2011/03/21 18:56:22 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/01/12 19:03:18 | 000,003,155 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/12/28 16:35:54 | 000,000,114 | ---- | C] () -- C:\Users\Kathi\AppData\Roaming\sview.ini
[2010/12/28 16:35:51 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\srfvdo.dat
[2010/11/24 20:51:43 | 000,009,216 | ---- | C] () -- C:\Users\Kathi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 21:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 20:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 17:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 04:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 17:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Alternate Data Streams ==========
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp

1B5B4F1
< End of report >