Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-09-2012
Ran by SYSTEM at 23-09-2012 17:43:58
Running from I:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [] [x]
HKLM\...\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2595792 2008-04-09] (Acronis)
HKLM\...\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [642856 2008-12-12] (Cisco Systems, Inc.)
HKLM\...\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [1778064 2010-07-21] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [HP KEYBOARDg] "C:\Program Files\Hewlett-Packard\HP Wireless Elite Desktop\HPKEYBOARDg.EXE" [701592 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.)
HKLM\...\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [1884160 2007-03-20] (Adobe Systems Incorporated)
HKLM\...\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [909208 2008-04-09] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [136472 2008-04-09] (Acronis)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-09-09] (Apple Inc.)
HKU\HP_Owner\...\Run: [AdobeBridge] [x]
HKU\HP_Owner\...\Run: [TrayStatus] "C:\Program Files\TrayStatus\TrayStatus.exe" [283032 2011-05-18] (Binary Fortress Software)
HKU\HP_Owner\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet [6591800 2012-02-22] (Yahoo! Inc.)
HKU\HP_Owner\...\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2736128 2011-06-20] (Hewlett-Packard Company)
HKU\HP_Owner\...\Run: [DriverFinder] C:\Program Files\DriverFinder\DriverFinder.exe [7811592 2009-12-16] ()
HKU\HP_Owner\...\Run: [Desktop Software] "C:\Program Files\Common Files\SupportSoft\bin\bcont.exe" /ini "C:\Program Files\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden [1025320 2009-04-24] (SupportSoft, Inc.)
HKU\HP_Owner\...\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" [545552 2012-08-25] (SANDBOXIE L.T.D)
Winlogon\Notify\PFW:
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 75.75.75.75 75.75.76.76
Lsa: [Authentication Packages] msv1_0 relog_ap
==================== Services (Whitelisted) ===================
2 AcrSch2Svc; "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" [431384 2008-04-09] (Acronis)
2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
2 Autodesk Content Service; "C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe" [18656 2011-02-02] ()
2 BotkindSyncService; C:\Program Files\Allway Sync\Bin\SyncService.exe service [182784 2012-05-14] ()
3 FLEXnet Licensing Service; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [1044816 2012-03-31] (Flexera Software, Inc.)
2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [399432 2012-09-07] (Malwarebytes Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [676936 2012-09-07] (Malwarebytes Corporation)
2 MotoHelper; C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe [214896 2011-12-06] ()
3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [114144 2012-09-05] (Mozilla Foundation)
2 nmservice; "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" [642856 2008-12-12] (Cisco Systems, Inc.)
2 SbieSvc; "C:\Program Files\Sandboxie\SbieSvc.exe" [85776 2012-08-25] (SANDBOXIE L.T.D)
3 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 TryAndDecideService; "C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [492896 2008-04-09] ()
2 LinksysUpdater; "C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe" -s "C:\Program Files\Linksys\Linksys Updater\conf\wrapper.conf" [x]
3 WPFFontCache_v0400; C:\Windows\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe [x]
==================== Drivers (Whitelisted) ====================
3 catchme; \??\C:\Users\HP_Owner\AppData\Local\Temp\catchme.sys [31744 2012-09-23] ()
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22856 2012-09-07] (Malwarebytes Corporation)
3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [21520 2010-07-21] (Microsoft Corporation)
3 P1130VID; C:\Windows\System32\DRIVERS\P1130Vid.sys [90229 2004-05-04] (Creative Technology Ltd.)
2 PEVSystemStart; "C:\A_Wisdom_Fix5437A\pev.3XE" EXEC /I "C:\A_Wisdom_Fix5437A\HIDEC.3XE" "C:\A_Wisdom_Fix5437A\SWREG.3XE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q [518144 2000-08-30] (SteelWerX)
2 pnarp; C:\Windows\System32\DRIVERS\pnarp.sys [24880 2008-12-12] (Cisco Systems, Inc.)
2 purendis; C:\Windows\System32\DRIVERS\purendis.sys [26416 2008-12-12] (Cisco Systems, Inc.)
3 SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [157776 2012-08-25] (SANDBOXIE L.T.D)
0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [368480 2010-01-23] (Acronis)
2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2010-01-23] (Acronis)
3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22792 2009-09-11] (Logitech Inc.)
3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [35592 2009-09-11] (Logitech Inc.)
3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [14984 2009-09-11] (Logitech Inc.)
3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66056 2009-09-11] (Logitech Inc.)
3 cpuz132; \??\C:\Users\HP_Owner\AppData\Local\Temp\cpuz132\cpuz132_x32.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2012-09-23 12:46 - 2012-09-23 12:46 - 00000000 ___SD C:\A_Wisdom_Fix5437A
2012-09-23 10:56 - 2012-09-23 10:58 - 00000000 ___SD C:\A_Wisdom_Fix
2012-09-23 10:47 - 2012-09-23 10:47 - 01678240 ____A (Bleeping Computer, LLC) C:\Users\HP_Owner\Desktop\iExplore.exe
2012-09-23 10:46 - 2012-09-23 10:46 - 04755721 ____R (Swearware) C:\Users\HP_Owner\Desktop\A_Wisdom_Fix.exe
2012-09-22 23:23 - 2012-09-23 12:45 - 00006972 ____A C:\Users\HP_Owner\Desktop\Rkill.txt
2012-09-22 20:46 - 2012-09-22 20:46 - 00000000 ____D C:\Qoobox
2012-09-22 20:46 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-09-22 20:46 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-09-22 20:46 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-09-22 20:45 - 2012-09-22 20:45 - 00000000 ____D C:\Windows\erdnt
2012-09-22 20:35 - 2012-09-22 20:35 - 01678240 ____A (Bleeping Computer, LLC) C:\Users\HP_Owner\Desktop\rkill.exe
2012-09-22 16:36 - 2012-09-22 16:47 - 00000000 ____D C:\Users\HP_Owner\Desktop\RK_Quarantine
2012-09-22 16:24 - 2011-01-01 00:14 - 00002254 ___RA C:\Users\HP_Owner\Desktop\eula.txt
2012-09-22 13:03 - 2012-09-23 12:38 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-22 11:15 - 2012-09-22 11:16 - 00001533 ____A C:\Windows\pcsetup.log
2012-09-22 11:14 - 2012-09-22 11:14 - 00002498 ____A C:\Windows\System32\FDInstall.log
2012-09-22 08:29 - 2012-09-22 08:29 - 00000000 ____A C:\Users\HP_Owner\Desktop\New Text Document.txt
2012-09-21 13:25 - 2012-09-21 13:25 - 00000870 ____A C:\Users\All Users\ltgubaa.tmp
2012-09-21 13:25 - 2012-09-21 13:25 - 00000869 ____A C:\Users\All Users\ktgubaa.tmp
2012-09-21 13:18 - 2012-09-21 13:18 - 00000873 ____A C:\Users\All Users\bcfrhaa.tmp
2012-09-21 13:11 - 2012-08-23 23:27 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-09-21 13:11 - 2012-08-23 23:03 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-09-21 13:11 - 2012-08-23 22:59 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-09-21 13:11 - 2012-08-23 22:51 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-09-21 13:11 - 2012-08-23 22:51 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-09-21 13:11 - 2012-08-23 22:51 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-09-21 13:11 - 2012-08-23 22:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-09-21 13:11 - 2012-08-23 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-09-21 13:11 - 2012-08-23 22:47 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-09-21 13:11 - 2012-08-23 22:47 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-09-21 13:11 - 2012-08-23 22:47 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-09-21 13:11 - 2012-08-23 22:45 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-09-21 13:11 - 2012-08-23 22:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-09-21 13:11 - 2012-08-23 22:44 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-09-21 13:11 - 2012-08-23 22:43 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-09-21 13:11 - 2012-08-23 22:40 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-09-21 12:15 - 2012-09-21 12:15 - 00607260 ____A (Swearware) C:\Users\HP_Owner\Downloads\dds.scr
2012-09-20 13:47 - 2012-09-20 13:47 - 00000040 ____A C:\Users\HP_Owner\AppData\Roaming\mbam.context.scan
2012-09-19 17:44 - 2012-09-19 17:44 - 00000872 ____A C:\Users\All Users\gpxbbaa.tmp
2012-09-19 17:44 - 2012-09-19 17:44 - 00000862 ____A C:\Users\All Users\hpxbbaa.tmp
2012-09-19 16:44 - 2012-09-19 16:44 - 223850095 ____A C:\Windows\MEMORY.DMP
2012-09-19 16:44 - 2012-09-19 16:44 - 00146088 ____A C:\Windows\Minidump\091912-16738-01.dmp
2012-09-19 15:07 - 2012-09-19 15:07 - 00000000 ____D C:\Program Files\ESET
2012-09-19 14:36 - 2012-09-19 14:36 - 00000000 ____D C:\Users\HP_Owner\AppData\Local\Macromedia
2012-09-19 12:52 - 2012-09-19 12:52 - 00000000 ____D C:\Program Files\Common Files\Java
2012-09-19 12:51 - 2012-09-19 12:50 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-09-19 12:40 - 2012-09-19 17:41 - 00000000 ____D C:\Program Files\PC Cleanup Utility
2012-09-19 12:40 - 2012-09-19 12:40 - 00000000 ____D C:\Users\HP_Owner\AppData\Local\PC Cleanup Utility Inc
2012-09-19 12:40 - 2012-09-19 12:40 - 00000000 ____D C:\Users\All Users\PC Cleanup Utility Inc
2012-09-19 12:40 - 2012-09-19 12:40 - 00000000 ____D C:\Users\All Users\Browser Manager
2012-09-19 09:27 - 2012-09-19 09:27 - 00000005 ____A C:\0.bak
2012-09-18 16:17 - 2012-09-18 16:17 - 00001184 ____A C:\Windows\IE9_main.log
2012-09-17 05:52 - 2012-09-23 16:33 - 00001960 ____A C:\Windows\setupact.log
2012-09-17 05:52 - 2012-09-23 15:53 - 00084848 ____A C:\Windows\PFRO.log
2012-09-17 05:52 - 2012-09-17 05:52 - 00000000 ____A C:\Windows\setuperr.log
2012-09-16 16:42 - 2012-09-16 16:42 - 00000000 ____D C:\sh4ldr
2012-09-16 16:42 - 2012-09-16 16:42 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-09-16 13:07 - 2012-09-23 16:33 - 00000498 ____A C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job
2012-09-16 11:50 - 2012-08-22 09:16 - 01292144 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-09-16 11:50 - 2012-08-22 09:16 - 00712048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2012-09-16 11:50 - 2012-08-22 09:16 - 00240496 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-09-16 11:50 - 2012-08-22 09:16 - 00187760 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-09-16 11:50 - 2012-08-02 08:57 - 00490496 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-09-16 11:50 - 2012-07-04 11:45 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2012-09-15 19:33 - 2012-09-15 19:33 - 00000000 ____D C:\Motorola
2012-09-15 19:06 - 2012-09-22 12:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-09-15 19:06 - 2012-09-16 19:37 - 00000000 ____D C:\Users\HP_Owner\AppData\Roaming\Malwarebytes
2012-09-15 19:06 - 2012-09-15 19:06 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-09-15 19:06 - 2012-09-07 16:04 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-09-15 18:58 - 2012-09-22 13:04 - 00002224 ____A C:\Windows\Sandboxie.ini
2012-09-15 18:49 - 2012-09-15 18:49 - 00001760 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-09-15 18:49 - 2012-08-21 12:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-09-15 18:48 - 2012-09-15 18:49 - 00000000 ____D C:\Users\All Users\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-09-15 18:48 - 2012-09-15 18:49 - 00000000 ____D C:\Program Files\iTunes
2012-09-15 18:48 - 2012-09-15 18:48 - 00000000 ____D C:\Program Files\iPod
2012-09-15 15:04 - 2012-09-15 15:04 - 00000000 ____D C:\Users\HP_Owner\AppData\Roaming\SUPERAntiSpyware.com
2012-09-15 15:04 - 2012-09-15 15:04 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-09-02 13:00 - 2012-09-15 17:19 - 00000000 ____D C:\Users\HP_Owner\AppData\Roaming\xsecva
2012-09-02 12:58 - 2012-09-15 17:19 - 00000000 ____D C:\Users\HP_Owner\AppData\Local\{E30CF1F5-F540-11E1-8270-B8AC6F996F26}
2012-09-02 12:58 - 2012-09-15 16:43 - 00000000 ____A C:\Users\HP_Owner\AppData\Local\¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖרÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
2012-09-01 12:30 - 2012-09-03 18:16 - 00000000 ____D C:\Users\HP_Owner\AppData\Local\Xobni
2012-09-01 12:29 - 2012-09-15 17:19 - 00000000 ____D C:\Program Files\Xobni
2012-08-31 10:17 - 2012-08-31 10:17 - 00000380 ____A C:\edu.bmp
2012-08-29 16:13 - 2012-09-21 17:31 - 00000000 ____D C:\Users\HP_Owner\Desktop\2012-08-29 AW_Card
2012-08-29 13:07 - 2012-08-29 13:07 - 00000304 ____A C:\dir.bmp
2012-08-28 23:36 - 2012-08-28 23:37 - 17789456 ____A (Mozilla) C:\Users\HP_Owner\Downloads\Firefox Setup 15.0.exe
2012-08-28 20:11 - 2012-08-29 22:54 - 00000000 ____D C:\Users\HP_Owner\Desktop\Galeries
2012-08-25 21:34 - 2012-08-25 21:34 - 00000000 ____D C:\Users\HP_Owner\AppData\Roaming\Nero
2012-08-25 21:01 - 2012-09-15 17:19 - 00000000 ____D C:\Sandbox
2012-08-25 20:58 - 2012-09-15 18:57 - 00000000 ____D C:\Program Files\Sandboxie
2012-08-25 20:45 - 2012-08-25 20:45 - 16476616 ____A (Microsoft Corporation) C:\Users\HP_Owner\Downloads\Windows-KB890830-V4.11 (1).exe
2012-08-25 20:31 - 2012-09-15 19:03 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2012-08-25 20:31 - 2012-08-25 20:31 - 00000000 ____D C:\Users\All Users\Mozilla
2012-08-25 12:38 - 2012-09-15 17:19 - 00000000 ____D C:\Users\All Users\036DFF8502FA96D5026EDA02F875F020
2012-08-24 11:10 - 2012-08-24 14:45 - 00000000 ____D C:\fcbce6b505fad7c66dd8138645
==================== 3 Months Modified Files ==================
2012-09-23 16:33 - 2012-09-17 05:52 - 00001960 ____A C:\Windows\setupact.log
2012-09-23 16:33 - 2012-09-16 13:07 - 00000498 ____A C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job
2012-09-23 16:33 - 2012-08-13 06:05 - 00000384 ____A C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2012-09-23 16:33 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-23 16:25 - 2010-01-23 14:18 - 00823948 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-23 16:21 - 2010-01-23 13:48 - 01741533 ____A C:\Windows\WindowsUpdate.log
2012-09-23 16:13 - 2009-07-13 20:34 - 00013760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-23 16:13 - 2009-07-13 20:34 - 00013760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-23 15:53 - 2012-09-17 05:52 - 00084848 ____A C:\Windows\PFRO.log
2012-09-23 12:45 - 2012-09-22 23:23 - 00006972 ____A C:\Users\HP_Owner\Desktop\Rkill.txt
2012-09-23 12:38 - 2012-09-22 13:03 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-23 11:41 - 2012-04-15 23:31 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-09-23 10:47 - 2012-09-23 10:47 - 01678240 ____A (Bleeping Computer, LLC) C:\Users\HP_Owner\Desktop\iExplore.exe
2012-09-23 10:46 - 2012-09-23 10:46 - 04755721 ____R (Swearware) C:\Users\HP_Owner\Desktop\A_Wisdom_Fix.exe
2012-09-22 20:35 - 2012-09-22 20:35 - 01678240 ____A (Bleeping Computer, LLC) C:\Users\HP_Owner\Desktop\rkill.exe
2012-09-22 17:00 - 2012-03-31 16:56 - 00000474 ____A C:\Windows\Tasks\SpeedyPC Registration3.job
2012-09-22 13:04 - 2012-09-15 18:58 - 00002224 ____A C:\Windows\Sandboxie.ini
2012-09-22 11:17 - 2011-09-03 02:02 - 00229228 ____A C:\Windows\System32\Drivers\KmxAgent.asc
2012-09-22 11:16 - 2012-09-22 11:15 - 00001533 ____A C:\Windows\pcsetup.log
2012-09-22 11:14 - 2012-09-22 11:14 - 00002498 ____A C:\Windows\System32\FDInstall.log
2012-09-22 08:29 - 2012-09-22 08:29 - 00000000 ____A C:\Users\HP_Owner\Desktop\New Text Document.txt
2012-09-21 13:25 - 2012-09-21 13:25 - 00000870 ____A C:\Users\All Users\ltgubaa.tmp
2012-09-21 13:25 - 2012-09-21 13:25 - 00000869 ____A C:\Users\All Users\ktgubaa.tmp
2012-09-21 13:18 - 2012-09-21 13:18 - 00000873 ____A C:\Users\All Users\bcfrhaa.tmp
2012-09-21 12:15 - 2012-09-21 12:15 - 00607260 ____A (Swearware) C:\Users\HP_Owner\Downloads\dds.scr
2012-09-20 18:41 - 2012-04-15 23:31 - 00696240 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-09-20 18:41 - 2011-05-15 13:03 - 00073136 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-09-20 13:47 - 2012-09-20 13:47 - 00000040 ____A C:\Users\HP_Owner\AppData\Roaming\mbam.context.scan
2012-09-20 07:35 - 2012-03-31 16:56 - 00000446 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job
2012-09-20 02:00 - 2012-03-31 21:12 - 00000388 ____A C:\Windows\Tasks\ErrorEND.job
2012-09-19 17:44 - 2012-09-19 17:44 - 00000872 ____A C:\Users\All Users\gpxbbaa.tmp
2012-09-19 17:44 - 2012-09-19 17:44 - 00000862 ____A C:\Users\All Users\hpxbbaa.tmp
2012-09-19 16:44 - 2012-09-19 16:44 - 223850095 ____A C:\Windows\MEMORY.DMP
2012-09-19 16:44 - 2012-09-19 16:44 - 00146088 ____A C:\Windows\Minidump\091912-16738-01.dmp
2012-09-19 12:50 - 2012-09-19 12:51 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-09-19 09:27 - 2012-09-19 09:27 - 00000005 ____A C:\0.bak
2012-09-18 16:17 - 2012-09-18 16:17 - 00001184 ____A C:\Windows\IE9_main.log
2012-09-18 16:06 - 2012-04-01 18:13 - 00013338 ____A C:\0
2012-09-17 17:53 - 2009-07-13 20:53 - 00032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-09-17 05:52 - 2012-09-17 05:52 - 00000000 ____A C:\Windows\setuperr.log
2012-09-16 19:12 - 2010-01-23 14:44 - 62164608 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-09-16 08:03 - 2012-03-31 16:56 - 00000402 ____A C:\Windows\Tasks\SpeedyPC Pro.job
2012-09-15 18:49 - 2012-09-15 18:49 - 00001760 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-09-15 16:43 - 2012-09-02 12:58 - 00000000 ____A C:\Users\HP_Owner\AppData\Local\¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖרÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
2012-09-07 16:04 - 2012-09-15 19:06 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-31 10:17 - 2012-08-31 10:17 - 00000380 ____A C:\edu.bmp
2012-08-29 13:07 - 2012-08-29 13:07 - 00000304 ____A C:\dir.bmp
2012-08-28 23:37 - 2012-08-28 23:36 - 17789456 ____A (Mozilla) C:\Users\HP_Owner\Downloads\Firefox Setup 15.0.exe
2012-08-25 20:45 - 2012-08-25 20:45 - 16476616 ____A (Microsoft Corporation) C:\Users\HP_Owner\Downloads\Windows-KB890830-V4.11 (1).exe
2012-08-23 23:27 - 2012-09-21 13:11 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-23 23:03 - 2012-09-21 13:11 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-23 22:59 - 2012-09-21 13:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-23 22:51 - 2012-09-21 13:11 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-23 22:51 - 2012-09-21 13:11 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-23 22:51 - 2012-09-21 13:11 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-23 22:49 - 2012-09-21 13:11 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-23 22:48 - 2012-09-21 13:11 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-23 22:47 - 2012-09-21 13:11 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-23 22:47 - 2012-09-21 13:11 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-23 22:47 - 2012-09-21 13:11 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-23 22:45 - 2012-09-21 13:11 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-23 22:44 - 2012-09-21 13:11 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-23 22:44 - 2012-09-21 13:11 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-23 22:43 - 2012-09-21 13:11 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-23 22:40 - 2012-09-21 13:11 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-22 09:16 - 2012-09-16 11:50 - 01292144 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-08-22 09:16 - 2012-09-16 11:50 - 00712048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2012-08-22 09:16 - 2012-09-16 11:50 - 00240496 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-08-22 09:16 - 2012-09-16 11:50 - 00187760 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-08-21 12:01 - 2012-09-15 18:49 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-08-21 12:01 - 2011-11-03 23:22 - 00106928 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi.dll
2012-08-15 20:43 - 2012-08-15 20:43 - 01688511 ____A C:\Users\HP_Owner\Desktop\Horvitz Elevs.dwg
2012-08-15 20:43 - 2012-08-15 20:43 - 01328113 ____A C:\Users\HP_Owner\Desktop\Horvitz - Details.dwg
2012-08-15 20:22 - 2009-07-13 20:33 - 04112744 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-13 06:25 - 2012-07-30 21:11 - 04503728 ___AT C:\Users\All Users\ras_0oed.pad
2012-08-09 11:27 - 2012-08-09 11:27 - 00001562 ____A C:\Users\HP_Owner\Desktop\Network Drives.lnk
2012-08-09 10:29 - 2012-08-08 13:57 - 19581440 ____A (Netgear Inc.) C:\Users\HP_Owner\Documents\RAIDar_Win.exe
2012-08-02 08:57 - 2012-09-16 11:50 - 00490496 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-07-26 14:05 - 2012-07-26 14:05 - 01290089 ____A C:\Users\HP_Owner\Desktop\SITEPLAN.DWG
2012-07-18 09:47 - 2012-08-15 06:37 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 12:30 - 2009-07-13 18:04 - 00000499 ____A C:\Windows\win.ini
2012-07-04 13:16 - 2012-08-15 06:37 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 13:14 - 2012-08-15 06:37 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 13:14 - 2012-08-15 06:37 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 11:45 - 2012-09-16 11:50 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2011-04-27 09:37] - [2010-11-20 04:21] - 2640896 ____A (Microsoft Corporation) C2D18B7A36CF417AD78A5CE153636D60
C:\Windows\System32\winlogon.exe
[2011-07-09 07:56] - [2010-11-20 04:21] - 0311296 ____A (Microsoft Corporation) 187867056AE4C401DE297E6A2BD4FABE
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe
[2009-07-13 15:19] - [2010-11-20 04:21] - 0045568 ____A (Microsoft Corporation) 32CF5E31B02C0709D92C0B95948D2B22
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-09-16 14:05:25
Restore point made on: 2012-09-16 14:24:07
Restore point made on: 2012-09-16 14:41:48
Restore point made on: 2012-09-16 19:12:19
Restore point made on: 2012-09-16 21:39:21
Restore point made on: 2012-09-17 05:49:05
Restore point made on: 2012-09-17 22:56:47
Restore point made on: 2012-09-17 23:03:40
Restore point made on: 2012-09-18 17:07:13
Restore point made on: 2012-09-19 09:27:12
Restore point made on: 2012-09-19 10:38:43
Restore point made on: 2012-09-19 12:50:19
Restore point made on: 2012-09-19 14:37:43
Restore point made on: 2012-09-21 13:11:26
Restore point made on: 2012-09-22 11:16:00
Restore point made on: 2012-09-22 20:42:06
Restore point made on: 2012-09-23 12:24:46
==================== Memory info ===========================
Percentage of memory in use: 23%
Total physical RAM: 2009.55 MB
Available physical RAM: 1541.77 MB
Total Pagefile: 2009.55 MB
Available Pagefile: 1553.25 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.3 MB
==================== Partitions =============================
1 Drive c: (Desktop) (Fixed) (Total:232.89 GB) (Free:145.59 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (GRMCHPFRER_EN_DVD) (CDROM) (Total:2.33 GB) (Free:0 GB) UDF
7 Drive I: (UDISK) (Removable) (Total:7.63 GB) (Free:0.74 GB) FAT32
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 Online 7830 MB 0 B
Disk 6 No Media 0 B 0 B
Disk 7 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 232 GB 31 KB
=========================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Desktop NTFS Partition 232 GB Healthy
=========================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7827 MB 2784 KB
=========================================================
Disk: 5
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 I UDISK FAT32 Removable 7827 MB Healthy
=========================================================
Last Boot: 2012-09-16 01:08
==================== End Of Log ============================
Ran by SYSTEM at 23-09-2012 17:43:58
Running from I:\
Windows 7 Home Premium (X86) OS Language: English(US)
The current controlset is ControlSet001
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [] [x]
HKLM\...\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2595792 2008-04-09] (Acronis)
HKLM\...\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [642856 2008-12-12] (Cisco Systems, Inc.)
HKLM\...\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [1778064 2010-07-21] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1821576 2011-08-01] (Microsoft Corporation)
HKLM\...\Run: [HP KEYBOARDg] "C:\Program Files\Hewlett-Packard\HP Wireless Elite Desktop\HPKEYBOARDg.EXE" [701592 2009-07-23] (Hewlett-Packard)
HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.)
HKLM\...\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE [1884160 2007-03-20] (Adobe Systems Incorporated)
HKLM\...\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [909208 2008-04-09] (Acronis)
HKLM\...\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [136472 2008-04-09] (Acronis)
HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-09-09] (Apple Inc.)
HKU\HP_Owner\...\Run: [AdobeBridge] [x]
HKU\HP_Owner\...\Run: [TrayStatus] "C:\Program Files\TrayStatus\TrayStatus.exe" [283032 2011-05-18] (Binary Fortress Software)
HKU\HP_Owner\...\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet [6591800 2012-02-22] (Yahoo! Inc.)
HKU\HP_Owner\...\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [2736128 2011-06-20] (Hewlett-Packard Company)
HKU\HP_Owner\...\Run: [DriverFinder] C:\Program Files\DriverFinder\DriverFinder.exe [7811592 2009-12-16] ()
HKU\HP_Owner\...\Run: [Desktop Software] "C:\Program Files\Common Files\SupportSoft\bin\bcont.exe" /ini "C:\Program Files\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden [1025320 2009-04-24] (SupportSoft, Inc.)
HKU\HP_Owner\...\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" [545552 2012-08-25] (SANDBOXIE L.T.D)
Winlogon\Notify\PFW:
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 75.75.75.75 75.75.76.76
Lsa: [Authentication Packages] msv1_0 relog_ap
==================== Services (Whitelisted) ===================
2 AcrSch2Svc; "C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe" [431384 2008-04-09] (Acronis)
2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-03-27] (LSI Corporation)
2 Autodesk Content Service; "C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe" [18656 2011-02-02] ()
2 BotkindSyncService; C:\Program Files\Allway Sync\Bin\SyncService.exe service [182784 2012-05-14] ()
3 FLEXnet Licensing Service; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [1044816 2012-03-31] (Flexera Software, Inc.)
2 MBAMScheduler; "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe" [399432 2012-09-07] (Malwarebytes Corporation)
2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [676936 2012-09-07] (Malwarebytes Corporation)
2 MotoHelper; C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe [214896 2011-12-06] ()
3 MozillaMaintenance; "C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe" [114144 2012-09-05] (Mozilla Foundation)
2 nmservice; "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" [642856 2008-12-12] (Cisco Systems, Inc.)
2 SbieSvc; "C:\Program Files\Sandboxie\SbieSvc.exe" [85776 2012-08-25] (SANDBOXIE L.T.D)
3 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
2 TryAndDecideService; "C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [492896 2008-04-09] ()
2 LinksysUpdater; "C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe" -s "C:\Program Files\Linksys\Linksys Updater\conf\wrapper.conf" [x]
3 WPFFontCache_v0400; C:\Windows\Microsoft.NET\Framework\v4.0.21006\WPF\WPFFontCache_v0400.exe [x]
==================== Drivers (Whitelisted) ====================
3 catchme; \??\C:\Users\HP_Owner\AppData\Local\Temp\catchme.sys [31744 2012-09-23] ()
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22856 2012-09-07] (Malwarebytes Corporation)
3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [21520 2010-07-21] (Microsoft Corporation)
3 P1130VID; C:\Windows\System32\DRIVERS\P1130Vid.sys [90229 2004-05-04] (Creative Technology Ltd.)
2 PEVSystemStart; "C:\A_Wisdom_Fix5437A\pev.3XE" EXEC /I "C:\A_Wisdom_Fix5437A\HIDEC.3XE" "C:\A_Wisdom_Fix5437A\SWREG.3XE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q [518144 2000-08-30] (SteelWerX)
2 pnarp; C:\Windows\System32\DRIVERS\pnarp.sys [24880 2008-12-12] (Cisco Systems, Inc.)
2 purendis; C:\Windows\System32\DRIVERS\purendis.sys [26416 2008-12-12] (Cisco Systems, Inc.)
3 SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [157776 2012-08-25] (SANDBOXIE L.T.D)
0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [368480 2010-01-23] (Acronis)
2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2010-01-23] (Acronis)
3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [22792 2009-09-11] (Logitech Inc.)
3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [35592 2009-09-11] (Logitech Inc.)
3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [14984 2009-09-11] (Logitech Inc.)
3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [66056 2009-09-11] (Logitech Inc.)
3 cpuz132; \??\C:\Users\HP_Owner\AppData\Local\Temp\cpuz132\cpuz132_x32.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2012-09-23 12:46 - 2012-09-23 12:46 - 00000000 ___SD C:\A_Wisdom_Fix5437A
2012-09-23 10:56 - 2012-09-23 10:58 - 00000000 ___SD C:\A_Wisdom_Fix
2012-09-23 10:47 - 2012-09-23 10:47 - 01678240 ____A (Bleeping Computer, LLC) C:\Users\HP_Owner\Desktop\iExplore.exe
2012-09-23 10:46 - 2012-09-23 10:46 - 04755721 ____R (Swearware) C:\Users\HP_Owner\Desktop\A_Wisdom_Fix.exe
2012-09-22 23:23 - 2012-09-23 12:45 - 00006972 ____A C:\Users\HP_Owner\Desktop\Rkill.txt
2012-09-22 20:46 - 2012-09-22 20:46 - 00000000 ____D C:\Qoobox
2012-09-22 20:46 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-09-22 20:46 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-09-22 20:46 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-09-22 20:46 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-09-22 20:45 - 2012-09-22 20:45 - 00000000 ____D C:\Windows\erdnt
2012-09-22 20:35 - 2012-09-22 20:35 - 01678240 ____A (Bleeping Computer, LLC) C:\Users\HP_Owner\Desktop\rkill.exe
2012-09-22 16:36 - 2012-09-22 16:47 - 00000000 ____D C:\Users\HP_Owner\Desktop\RK_Quarantine
2012-09-22 16:24 - 2011-01-01 00:14 - 00002254 ___RA C:\Users\HP_Owner\Desktop\eula.txt
2012-09-22 13:03 - 2012-09-23 12:38 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-22 11:15 - 2012-09-22 11:16 - 00001533 ____A C:\Windows\pcsetup.log
2012-09-22 11:14 - 2012-09-22 11:14 - 00002498 ____A C:\Windows\System32\FDInstall.log
2012-09-22 08:29 - 2012-09-22 08:29 - 00000000 ____A C:\Users\HP_Owner\Desktop\New Text Document.txt
2012-09-21 13:25 - 2012-09-21 13:25 - 00000870 ____A C:\Users\All Users\ltgubaa.tmp
2012-09-21 13:25 - 2012-09-21 13:25 - 00000869 ____A C:\Users\All Users\ktgubaa.tmp
2012-09-21 13:18 - 2012-09-21 13:18 - 00000873 ____A C:\Users\All Users\bcfrhaa.tmp
2012-09-21 13:11 - 2012-08-23 23:27 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-09-21 13:11 - 2012-08-23 23:03 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-09-21 13:11 - 2012-08-23 22:59 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-09-21 13:11 - 2012-08-23 22:51 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-09-21 13:11 - 2012-08-23 22:51 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-09-21 13:11 - 2012-08-23 22:51 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-09-21 13:11 - 2012-08-23 22:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-09-21 13:11 - 2012-08-23 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-09-21 13:11 - 2012-08-23 22:47 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-09-21 13:11 - 2012-08-23 22:47 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-09-21 13:11 - 2012-08-23 22:47 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-09-21 13:11 - 2012-08-23 22:45 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-09-21 13:11 - 2012-08-23 22:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-09-21 13:11 - 2012-08-23 22:44 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-09-21 13:11 - 2012-08-23 22:43 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-09-21 13:11 - 2012-08-23 22:40 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-09-21 12:15 - 2012-09-21 12:15 - 00607260 ____A (Swearware) C:\Users\HP_Owner\Downloads\dds.scr
2012-09-20 13:47 - 2012-09-20 13:47 - 00000040 ____A C:\Users\HP_Owner\AppData\Roaming\mbam.context.scan
2012-09-19 17:44 - 2012-09-19 17:44 - 00000872 ____A C:\Users\All Users\gpxbbaa.tmp
2012-09-19 17:44 - 2012-09-19 17:44 - 00000862 ____A C:\Users\All Users\hpxbbaa.tmp
2012-09-19 16:44 - 2012-09-19 16:44 - 223850095 ____A C:\Windows\MEMORY.DMP
2012-09-19 16:44 - 2012-09-19 16:44 - 00146088 ____A C:\Windows\Minidump\091912-16738-01.dmp
2012-09-19 15:07 - 2012-09-19 15:07 - 00000000 ____D C:\Program Files\ESET
2012-09-19 14:36 - 2012-09-19 14:36 - 00000000 ____D C:\Users\HP_Owner\AppData\Local\Macromedia
2012-09-19 12:52 - 2012-09-19 12:52 - 00000000 ____D C:\Program Files\Common Files\Java
2012-09-19 12:51 - 2012-09-19 12:50 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-09-19 12:40 - 2012-09-19 17:41 - 00000000 ____D C:\Program Files\PC Cleanup Utility
2012-09-19 12:40 - 2012-09-19 12:40 - 00000000 ____D C:\Users\HP_Owner\AppData\Local\PC Cleanup Utility Inc
2012-09-19 12:40 - 2012-09-19 12:40 - 00000000 ____D C:\Users\All Users\PC Cleanup Utility Inc
2012-09-19 12:40 - 2012-09-19 12:40 - 00000000 ____D C:\Users\All Users\Browser Manager
2012-09-19 09:27 - 2012-09-19 09:27 - 00000005 ____A C:\0.bak
2012-09-18 16:17 - 2012-09-18 16:17 - 00001184 ____A C:\Windows\IE9_main.log
2012-09-17 05:52 - 2012-09-23 16:33 - 00001960 ____A C:\Windows\setupact.log
2012-09-17 05:52 - 2012-09-23 15:53 - 00084848 ____A C:\Windows\PFRO.log
2012-09-17 05:52 - 2012-09-17 05:52 - 00000000 ____A C:\Windows\setuperr.log
2012-09-16 16:42 - 2012-09-16 16:42 - 00000000 ____D C:\sh4ldr
2012-09-16 16:42 - 2012-09-16 16:42 - 00000000 ____D C:\Program Files\Enigma Software Group
2012-09-16 13:07 - 2012-09-23 16:33 - 00000498 ____A C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job
2012-09-16 11:50 - 2012-08-22 09:16 - 01292144 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-09-16 11:50 - 2012-08-22 09:16 - 00712048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2012-09-16 11:50 - 2012-08-22 09:16 - 00240496 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-09-16 11:50 - 2012-08-22 09:16 - 00187760 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-09-16 11:50 - 2012-08-02 08:57 - 00490496 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-09-16 11:50 - 2012-07-04 11:45 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
2012-09-15 19:33 - 2012-09-15 19:33 - 00000000 ____D C:\Motorola
2012-09-15 19:06 - 2012-09-22 12:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2012-09-15 19:06 - 2012-09-16 19:37 - 00000000 ____D C:\Users\HP_Owner\AppData\Roaming\Malwarebytes
2012-09-15 19:06 - 2012-09-15 19:06 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-09-15 19:06 - 2012-09-07 16:04 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-09-15 18:58 - 2012-09-22 13:04 - 00002224 ____A C:\Windows\Sandboxie.ini
2012-09-15 18:49 - 2012-09-15 18:49 - 00001760 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-09-15 18:49 - 2012-08-21 12:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-09-15 18:48 - 2012-09-15 18:49 - 00000000 ____D C:\Users\All Users\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-09-15 18:48 - 2012-09-15 18:49 - 00000000 ____D C:\Program Files\iTunes
2012-09-15 18:48 - 2012-09-15 18:48 - 00000000 ____D C:\Program Files\iPod
2012-09-15 15:04 - 2012-09-15 15:04 - 00000000 ____D C:\Users\HP_Owner\AppData\Roaming\SUPERAntiSpyware.com
2012-09-15 15:04 - 2012-09-15 15:04 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-09-02 13:00 - 2012-09-15 17:19 - 00000000 ____D C:\Users\HP_Owner\AppData\Roaming\xsecva
2012-09-02 12:58 - 2012-09-15 17:19 - 00000000 ____D C:\Users\HP_Owner\AppData\Local\{E30CF1F5-F540-11E1-8270-B8AC6F996F26}
2012-09-02 12:58 - 2012-09-15 16:43 - 00000000 ____A C:\Users\HP_Owner\AppData\Local\¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖרÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
2012-09-01 12:30 - 2012-09-03 18:16 - 00000000 ____D C:\Users\HP_Owner\AppData\Local\Xobni
2012-09-01 12:29 - 2012-09-15 17:19 - 00000000 ____D C:\Program Files\Xobni
2012-08-31 10:17 - 2012-08-31 10:17 - 00000380 ____A C:\edu.bmp
2012-08-29 16:13 - 2012-09-21 17:31 - 00000000 ____D C:\Users\HP_Owner\Desktop\2012-08-29 AW_Card
2012-08-29 13:07 - 2012-08-29 13:07 - 00000304 ____A C:\dir.bmp
2012-08-28 23:36 - 2012-08-28 23:37 - 17789456 ____A (Mozilla) C:\Users\HP_Owner\Downloads\Firefox Setup 15.0.exe
2012-08-28 20:11 - 2012-08-29 22:54 - 00000000 ____D C:\Users\HP_Owner\Desktop\Galeries
2012-08-25 21:34 - 2012-08-25 21:34 - 00000000 ____D C:\Users\HP_Owner\AppData\Roaming\Nero
2012-08-25 21:01 - 2012-09-15 17:19 - 00000000 ____D C:\Sandbox
2012-08-25 20:58 - 2012-09-15 18:57 - 00000000 ____D C:\Program Files\Sandboxie
2012-08-25 20:45 - 2012-08-25 20:45 - 16476616 ____A (Microsoft Corporation) C:\Users\HP_Owner\Downloads\Windows-KB890830-V4.11 (1).exe
2012-08-25 20:31 - 2012-09-15 19:03 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2012-08-25 20:31 - 2012-08-25 20:31 - 00000000 ____D C:\Users\All Users\Mozilla
2012-08-25 12:38 - 2012-09-15 17:19 - 00000000 ____D C:\Users\All Users\036DFF8502FA96D5026EDA02F875F020
2012-08-24 11:10 - 2012-08-24 14:45 - 00000000 ____D C:\fcbce6b505fad7c66dd8138645
==================== 3 Months Modified Files ==================
2012-09-23 16:33 - 2012-09-17 05:52 - 00001960 ____A C:\Windows\setupact.log
2012-09-23 16:33 - 2012-09-16 13:07 - 00000498 ____A C:\Windows\Tasks\SpeedyPC Update Version3 Startup Task.job
2012-09-23 16:33 - 2012-08-13 06:05 - 00000384 ____A C:\Windows\Tasks\FreeFileViewerUpdateChecker.job
2012-09-23 16:33 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-23 16:25 - 2010-01-23 14:18 - 00823948 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-23 16:21 - 2010-01-23 13:48 - 01741533 ____A C:\Windows\WindowsUpdate.log
2012-09-23 16:13 - 2009-07-13 20:34 - 00013760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-23 16:13 - 2009-07-13 20:34 - 00013760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-23 15:53 - 2012-09-17 05:52 - 00084848 ____A C:\Windows\PFRO.log
2012-09-23 12:45 - 2012-09-22 23:23 - 00006972 ____A C:\Users\HP_Owner\Desktop\Rkill.txt
2012-09-23 12:38 - 2012-09-22 13:03 - 00001945 ____A C:\Windows\epplauncher.mif
2012-09-23 11:41 - 2012-04-15 23:31 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-09-23 10:47 - 2012-09-23 10:47 - 01678240 ____A (Bleeping Computer, LLC) C:\Users\HP_Owner\Desktop\iExplore.exe
2012-09-23 10:46 - 2012-09-23 10:46 - 04755721 ____R (Swearware) C:\Users\HP_Owner\Desktop\A_Wisdom_Fix.exe
2012-09-22 20:35 - 2012-09-22 20:35 - 01678240 ____A (Bleeping Computer, LLC) C:\Users\HP_Owner\Desktop\rkill.exe
2012-09-22 17:00 - 2012-03-31 16:56 - 00000474 ____A C:\Windows\Tasks\SpeedyPC Registration3.job
2012-09-22 13:04 - 2012-09-15 18:58 - 00002224 ____A C:\Windows\Sandboxie.ini
2012-09-22 11:17 - 2011-09-03 02:02 - 00229228 ____A C:\Windows\System32\Drivers\KmxAgent.asc
2012-09-22 11:16 - 2012-09-22 11:15 - 00001533 ____A C:\Windows\pcsetup.log
2012-09-22 11:14 - 2012-09-22 11:14 - 00002498 ____A C:\Windows\System32\FDInstall.log
2012-09-22 08:29 - 2012-09-22 08:29 - 00000000 ____A C:\Users\HP_Owner\Desktop\New Text Document.txt
2012-09-21 13:25 - 2012-09-21 13:25 - 00000870 ____A C:\Users\All Users\ltgubaa.tmp
2012-09-21 13:25 - 2012-09-21 13:25 - 00000869 ____A C:\Users\All Users\ktgubaa.tmp
2012-09-21 13:18 - 2012-09-21 13:18 - 00000873 ____A C:\Users\All Users\bcfrhaa.tmp
2012-09-21 12:15 - 2012-09-21 12:15 - 00607260 ____A (Swearware) C:\Users\HP_Owner\Downloads\dds.scr
2012-09-20 18:41 - 2012-04-15 23:31 - 00696240 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2012-09-20 18:41 - 2011-05-15 13:03 - 00073136 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2012-09-20 13:47 - 2012-09-20 13:47 - 00000040 ____A C:\Users\HP_Owner\AppData\Roaming\mbam.context.scan
2012-09-20 07:35 - 2012-03-31 16:56 - 00000446 ____A C:\Windows\Tasks\SpeedyPC Update Version3.job
2012-09-20 02:00 - 2012-03-31 21:12 - 00000388 ____A C:\Windows\Tasks\ErrorEND.job
2012-09-19 17:44 - 2012-09-19 17:44 - 00000872 ____A C:\Users\All Users\gpxbbaa.tmp
2012-09-19 17:44 - 2012-09-19 17:44 - 00000862 ____A C:\Users\All Users\hpxbbaa.tmp
2012-09-19 16:44 - 2012-09-19 16:44 - 223850095 ____A C:\Windows\MEMORY.DMP
2012-09-19 16:44 - 2012-09-19 16:44 - 00146088 ____A C:\Windows\Minidump\091912-16738-01.dmp
2012-09-19 12:50 - 2012-09-19 12:51 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-09-19 09:27 - 2012-09-19 09:27 - 00000005 ____A C:\0.bak
2012-09-18 16:17 - 2012-09-18 16:17 - 00001184 ____A C:\Windows\IE9_main.log
2012-09-18 16:06 - 2012-04-01 18:13 - 00013338 ____A C:\0
2012-09-17 17:53 - 2009-07-13 20:53 - 00032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-09-17 05:52 - 2012-09-17 05:52 - 00000000 ____A C:\Windows\setuperr.log
2012-09-16 19:12 - 2010-01-23 14:44 - 62164608 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-09-16 08:03 - 2012-03-31 16:56 - 00000402 ____A C:\Windows\Tasks\SpeedyPC Pro.job
2012-09-15 18:49 - 2012-09-15 18:49 - 00001760 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-09-15 16:43 - 2012-09-02 12:58 - 00000000 ____A C:\Users\HP_Owner\AppData\Local\¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖרÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
2012-09-07 16:04 - 2012-09-15 19:06 - 00022856 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-31 10:17 - 2012-08-31 10:17 - 00000380 ____A C:\edu.bmp
2012-08-29 13:07 - 2012-08-29 13:07 - 00000304 ____A C:\dir.bmp
2012-08-28 23:37 - 2012-08-28 23:36 - 17789456 ____A (Mozilla) C:\Users\HP_Owner\Downloads\Firefox Setup 15.0.exe
2012-08-25 20:45 - 2012-08-25 20:45 - 16476616 ____A (Microsoft Corporation) C:\Users\HP_Owner\Downloads\Windows-KB890830-V4.11 (1).exe
2012-08-23 23:27 - 2012-09-21 13:11 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-23 23:03 - 2012-09-21 13:11 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-23 22:59 - 2012-09-21 13:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-23 22:51 - 2012-09-21 13:11 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-23 22:51 - 2012-09-21 13:11 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-23 22:51 - 2012-09-21 13:11 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-23 22:49 - 2012-09-21 13:11 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-23 22:48 - 2012-09-21 13:11 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-23 22:47 - 2012-09-21 13:11 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-23 22:47 - 2012-09-21 13:11 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-08-23 22:47 - 2012-09-21 13:11 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-23 22:45 - 2012-09-21 13:11 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-08-23 22:44 - 2012-09-21 13:11 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-23 22:44 - 2012-09-21 13:11 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-23 22:43 - 2012-09-21 13:11 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-23 22:40 - 2012-09-21 13:11 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-22 09:16 - 2012-09-16 11:50 - 01292144 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-08-22 09:16 - 2012-09-16 11:50 - 00712048 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndis.sys
2012-08-22 09:16 - 2012-09-16 11:50 - 00240496 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\netio.sys
2012-08-22 09:16 - 2012-09-16 11:50 - 00187760 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS
2012-08-21 12:01 - 2012-09-15 18:49 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys
2012-08-21 12:01 - 2011-11-03 23:22 - 00106928 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi.dll
2012-08-15 20:43 - 2012-08-15 20:43 - 01688511 ____A C:\Users\HP_Owner\Desktop\Horvitz Elevs.dwg
2012-08-15 20:43 - 2012-08-15 20:43 - 01328113 ____A C:\Users\HP_Owner\Desktop\Horvitz - Details.dwg
2012-08-15 20:22 - 2009-07-13 20:33 - 04112744 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-13 06:25 - 2012-07-30 21:11 - 04503728 ___AT C:\Users\All Users\ras_0oed.pad
2012-08-09 11:27 - 2012-08-09 11:27 - 00001562 ____A C:\Users\HP_Owner\Desktop\Network Drives.lnk
2012-08-09 10:29 - 2012-08-08 13:57 - 19581440 ____A (Netgear Inc.) C:\Users\HP_Owner\Documents\RAIDar_Win.exe
2012-08-02 08:57 - 2012-09-16 11:50 - 00490496 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll
2012-07-26 14:05 - 2012-07-26 14:05 - 01290089 ____A C:\Users\HP_Owner\Desktop\SITEPLAN.DWG
2012-07-18 09:47 - 2012-08-15 06:37 - 02345984 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 12:30 - 2009-07-13 18:04 - 00000499 ____A C:\Windows\win.ini
2012-07-04 13:16 - 2012-08-15 06:37 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 13:14 - 2012-08-15 06:37 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 13:14 - 2012-08-15 06:37 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 11:45 - 2012-09-16 11:50 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\RNDISMP.sys
==================== Known DLLs (Whitelisted) =================
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2011-04-27 09:37] - [2010-11-20 04:21] - 2640896 ____A (Microsoft Corporation) C2D18B7A36CF417AD78A5CE153636D60
C:\Windows\System32\winlogon.exe
[2011-07-09 07:56] - [2010-11-20 04:21] - 0311296 ____A (Microsoft Corporation) 187867056AE4C401DE297E6A2BD4FABE
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe
[2009-07-13 15:19] - [2010-11-20 04:21] - 0045568 ____A (Microsoft Corporation) 32CF5E31B02C0709D92C0B95948D2B22
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-09-16 14:05:25
Restore point made on: 2012-09-16 14:24:07
Restore point made on: 2012-09-16 14:41:48
Restore point made on: 2012-09-16 19:12:19
Restore point made on: 2012-09-16 21:39:21
Restore point made on: 2012-09-17 05:49:05
Restore point made on: 2012-09-17 22:56:47
Restore point made on: 2012-09-17 23:03:40
Restore point made on: 2012-09-18 17:07:13
Restore point made on: 2012-09-19 09:27:12
Restore point made on: 2012-09-19 10:38:43
Restore point made on: 2012-09-19 12:50:19
Restore point made on: 2012-09-19 14:37:43
Restore point made on: 2012-09-21 13:11:26
Restore point made on: 2012-09-22 11:16:00
Restore point made on: 2012-09-22 20:42:06
Restore point made on: 2012-09-23 12:24:46
==================== Memory info ===========================
Percentage of memory in use: 23%
Total physical RAM: 2009.55 MB
Available physical RAM: 1541.77 MB
Total Pagefile: 2009.55 MB
Available Pagefile: 1553.25 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.3 MB
==================== Partitions =============================
1 Drive c: (Desktop) (Fixed) (Total:232.89 GB) (Free:145.59 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (GRMCHPFRER_EN_DVD) (CDROM) (Total:2.33 GB) (Free:0 GB) UDF
7 Drive I: (UDISK) (Removable) (Total:7.63 GB) (Free:0.74 GB) FAT32
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 232 GB 0 B
Disk 1 No Media 0 B 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 Online 7830 MB 0 B
Disk 6 No Media 0 B 0 B
Disk 7 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 232 GB 31 KB
=========================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C Desktop NTFS Partition 232 GB Healthy
=========================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7827 MB 2784 KB
=========================================================
Disk: 5
Partition 1
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 I UDISK FAT32 Removable 7827 MB Healthy
=========================================================
Last Boot: 2012-09-16 01:08
==================== End Of Log ============================