It was the fake Adobe update that caused it, I believe. I am running Windows 64 bit and MSE mentions I have sirefef y and sirefef b. Like others here, I also encounter a critical error on starting windows and get a minute before it reboots.
Thanks so much for any help.
I took the liberty of assuming you might want me to download Farbar 64bit and run it from a flashdrive (from System recovery, not within Windows).
The results are below:
Scan result of Farbar Recovery Scan Tool Version: 11-07-2012
Ran by SYSTEM at 13-07-2012 07:56:17
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [102400 2010-05-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe [664600 2010-09-28] (PDF Complete Inc)
HKLM-x32\...\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe [385024 2009-04-03] (Hewlett-Packard)
HKLM-x32\...\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [x]
HKLM-x32\...\Run: [V0640Mon.exe] C:\Windows\V0640Mon.exe [28672 2009-09-22] (Creative Technology Ltd.)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\Nick\Start Menu\Programs\Startup\Mozilla Firefox.lnk
ShortcutTarget: Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Startup: C:\Users\Nick\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Nick\Start Menu\Programs\Startup\Windows Live Mail.lnk
ShortcutTarget: Windows Live Mail.lnk -> C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RapportMgmtService; "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" [976728 2012-06-08] (Trusteer Ltd.)
2 HP Health Check Service; "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe" [x]
3 hpqwmiex; "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe" [x]
========================== Drivers (Whitelisted) =============
1 RapportCerberus_34302; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus64_34302.sys [397520 2011-12-15] ()
1 RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [55096 2012-06-08] (Trusteer Ltd.)
0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [101400 2012-06-08] (Trusteer Ltd.)
1 RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [297048 2012-06-08] (Trusteer Ltd.)
3 V0640Vid; C:\Windows\System32\Drivers\V0640Vid.sys [319520 2009-12-03] (Creative Technology Ltd.)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-13 07:36 - 2012-07-13 07:36 - 00000000 ____D C:\Users\All Users\Recovery
2012-07-12 21:52 - 2012-07-12 21:52 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-12 21:52 - 2012-07-12 21:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-12 21:45 - 2012-07-12 21:45 - 12621696 ____A (Microsoft Corporation) C:\Users\Nick\Downloads\mseinstall.exe
2012-07-12 12:54 - 2012-07-12 12:54 - 00000000 ____D C:\Users\Nick\AppData\Local\{B90D9025-050E-49BE-87EE-6FF7C9542EEF}
2012-07-12 12:54 - 2012-07-12 12:54 - 00000000 ____D C:\Users\Nick\AppData\Local\{AE7D64B8-B404-40AE-AD7D-95077CDE4F52}
2012-07-12 12:10 - 2012-07-12 12:10 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-12 12:09 - 2012-07-12 22:34 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-12 12:09 - 2012-07-12 12:19 - 00002342 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-12 12:09 - 2012-07-12 12:19 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-12 12:08 - 2012-07-12 12:09 - 00000000 ____D C:\Users\Nick\AppData\Local\Google
2012-07-12 12:08 - 2012-07-12 12:09 - 00000000 ____D C:\Program Files (x86)\Google
2012-07-12 00:53 - 2012-07-12 00:53 - 00000000 ____D C:\Users\Nick\AppData\Local\{F825A961-913E-4A6E-AF6A-0EB31F7BC474}
2012-07-12 00:53 - 2012-07-12 00:53 - 00000000 ____D C:\Users\Nick\AppData\Local\{B1DB62FE-6BD6-4F00-A92F-21B7C743A24E}
2012-07-11 12:07 - 2012-07-11 12:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{D8FF24A9-58D5-4BAE-9221-35147786B936}
2012-07-11 12:07 - 2012-07-11 12:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{39F8F8FF-94AB-42E9-A350-9F26BAEE0417}
2012-07-10 23:14 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 23:11 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 23:11 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 23:11 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 23:11 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 23:11 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 23:11 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 23:11 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 23:11 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 23:11 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 23:11 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 23:11 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 23:11 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 23:11 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 23:11 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 23:11 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-10 23:11 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-10 23:11 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-10 23:11 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-10 23:11 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-10 23:11 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-10 23:11 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-10 23:11 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-10 23:11 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-10 23:11 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-10 23:11 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-10 23:11 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-10 23:11 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-10 23:11 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 22:40 - 2012-07-10 22:41 - 00000000 ____D C:\Users\Nick\AppData\Local\{584EB645-7094-4D2C-82F7-896D444407A0}
2012-07-10 22:40 - 2012-07-10 22:40 - 00000000 ____D C:\Users\Nick\AppData\Local\{8BB21673-994B-4652-9DC3-1B92DF24F620}
2012-07-10 21:49 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 21:49 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 21:49 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 21:49 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 21:49 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 21:49 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 21:49 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 21:49 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 21:49 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 21:49 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 21:49 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 21:49 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 21:49 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 21:49 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 21:49 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 21:49 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 21:49 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 21:49 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 21:49 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 10:40 - 2012-07-10 10:40 - 00000000 ____D C:\Users\Nick\AppData\Local\{C9C406DE-B88A-44EF-8105-1B71C2A5B491}
2012-07-10 10:39 - 2012-07-10 10:40 - 00000000 ____D C:\Users\Nick\AppData\Local\{0EE56A72-64FC-41C5-94A8-9D25A7A35AD9}
2012-07-09 22:39 - 2012-07-09 22:39 - 00000000 ____D C:\Users\Nick\AppData\Local\{FB960092-32DA-462A-9C25-42AA9A962B48}
2012-07-09 22:39 - 2012-07-09 22:39 - 00000000 ____D C:\Users\Nick\AppData\Local\{C0EAF565-7EF8-4724-9403-55C85CBBC30C}
2012-07-09 10:38 - 2012-07-09 10:38 - 00000000 ____D C:\Users\Nick\AppData\Local\{1BD48371-EAC0-42CA-8F77-A7574BC3217B}
2012-07-09 10:38 - 2012-07-09 10:38 - 00000000 ____D C:\Users\Nick\AppData\Local\{00D59B2A-79BB-4627-9E4E-738BE9ED2950}
2012-07-08 22:37 - 2012-07-08 22:37 - 00000000 ____D C:\Users\Nick\AppData\Local\{6F500260-0214-47B1-BB42-DB25C52684B6}
2012-07-08 22:37 - 2012-07-08 22:37 - 00000000 ____D C:\Users\Nick\AppData\Local\{5F013C15-F2A9-4CE6-8BA7-2353FE3BA719}
2012-07-08 02:07 - 2012-07-08 02:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{D14185A6-1E41-48CE-9720-66817F2DF9D0}
2012-07-08 02:07 - 2012-07-08 02:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{AF6AE319-DF7A-4189-AACC-99AA4FD6B6C4}
2012-07-07 14:06 - 2012-07-07 14:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{8ADF0B2A-6A20-4518-B2B8-AA07525F36FE}
2012-07-07 14:06 - 2012-07-07 14:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{E6CED18A-8164-4A89-968E-46FFBEB7FAA7}
2012-07-07 01:18 - 2012-07-07 01:19 - 00000000 ____D C:\Users\Nick\AppData\Local\{FAEFD1FF-AFF0-4D34-8389-184AA3B80016}
2012-07-07 01:18 - 2012-07-07 01:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{15630BEB-AFF8-460F-A1E8-A53A4EE7F91B}
2012-07-06 13:18 - 2012-07-06 13:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{A298EB6A-B924-490B-91F4-671769F06835}
2012-07-06 13:17 - 2012-07-06 13:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{3B75D8BB-6519-4203-B245-ACC54D4F1BA8}
2012-07-05 22:24 - 2012-07-05 22:24 - 00000000 ____D C:\Users\Nick\AppData\Local\{CD9F5B98-8CBB-4682-9E03-0988B3926197}
2012-07-05 22:23 - 2012-07-05 22:24 - 00000000 ____D C:\Users\Nick\AppData\Local\{B22E9A96-A121-405F-BE9E-91E3539CB892}
2012-07-05 09:59 - 2012-07-05 09:59 - 00000000 ____D C:\Users\Nick\AppData\Local\{7E1F5C26-E9B3-41D7-A2F7-DBEF7226E6C5}
2012-07-05 09:59 - 2012-07-05 09:59 - 00000000 ____D C:\Users\Nick\AppData\Local\{535E5E57-55B8-4289-84C2-252A7B760B0E}
2012-07-04 21:59 - 2012-07-04 21:59 - 00000000 ____D C:\Users\Nick\AppData\Local\{76F34B1A-E2A7-4D45-9E50-CA639E4F4B14}
2012-07-04 21:58 - 2012-07-04 21:59 - 00000000 ____D C:\Users\Nick\AppData\Local\{BEB6DA39-9C51-44E0-947E-842D7ECF12E3}
2012-07-04 09:57 - 2012-07-04 09:57 - 00000000 ____D C:\Users\Nick\AppData\Local\{745D7808-5881-4AAA-9F2D-4BB8A489E6AD}
2012-07-04 09:56 - 2012-07-04 09:57 - 00000000 ____D C:\Users\Nick\AppData\Local\{334F9E18-4CA9-4012-804F-26388C7A83B4}
2012-07-03 21:56 - 2012-07-03 21:56 - 00000000 ____D C:\Users\Nick\AppData\Local\{C087C645-B59B-4CD7-B0DF-BC3413C66D51}
2012-07-03 21:56 - 2012-07-03 21:56 - 00000000 ____D C:\Users\Nick\AppData\Local\{0566AA2F-0D3C-4E28-A1CC-C08A979E3349}
2012-07-03 09:55 - 2012-07-03 09:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{F6C08CF6-836D-47CF-A3EE-933C3DCC8D1C}
2012-07-03 09:55 - 2012-07-03 09:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{14CAA059-26B3-4F51-A1B8-409350794CA4}
2012-07-02 21:54 - 2012-07-02 21:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{2F4AA866-2A2C-40EF-8654-3C97805D70B3}
2012-07-02 21:54 - 2012-07-02 21:54 - 00000000 ____D C:\Users\Nick\AppData\Local\{748C527C-ACBA-48BC-9214-0D68442783CC}
2012-07-02 08:10 - 2012-07-02 08:10 - 00000000 ____D C:\Users\Nick\AppData\Local\{D9B9F882-7332-4AA7-857D-EFA39B243532}
2012-07-02 08:10 - 2012-07-02 08:10 - 00000000 ____D C:\Users\Nick\AppData\Local\{08854A89-B624-4ABD-A8F6-6CAF7205EC14}
2012-07-01 16:25 - 2012-07-01 16:26 - 00000000 ____D C:\Users\Nick\AppData\Local\{89271E75-F705-487F-BC50-4B8DD82D8D28}
2012-07-01 16:25 - 2012-07-01 16:25 - 00000000 ____D C:\Users\Nick\AppData\Local\{71C4BE19-5BD5-4A35-A4DF-D024C9498D41}
2012-07-01 03:26 - 2012-07-01 03:26 - 00000000 ____D C:\Users\Nick\AppData\Local\{D317A0B0-851B-4B8F-B45E-A6502F305FBD}
2012-07-01 03:26 - 2012-07-01 03:26 - 00000000 ____D C:\Users\Nick\AppData\Local\{7EAA9403-AEA8-4E2F-91A7-EB9CE5753D98}
2012-06-30 15:25 - 2012-06-30 15:25 - 00000000 ____D C:\Users\Nick\AppData\Local\{C477856A-D10E-4231-8BE0-DDCE7C02E449}
2012-06-30 15:25 - 2012-06-30 15:25 - 00000000 ____D C:\Users\Nick\AppData\Local\{321342B1-8703-47E1-BC7D-62A66D92D8D6}
2012-06-30 03:24 - 2012-06-30 03:25 - 00000000 ____D C:\Users\Nick\AppData\Local\{A2E8B310-D43A-4152-B972-20B3F6399F76}
2012-06-30 03:24 - 2012-06-30 03:24 - 00000000 ____D C:\Users\Nick\AppData\Local\{24A36B8E-6695-4000-80C0-58EAFB9024E0}
2012-06-29 10:06 - 2012-06-29 10:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{EF10A2B5-471A-4C4C-A13E-E771935093D8}
2012-06-29 10:06 - 2012-06-29 10:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{E55C73EF-37BA-439C-8227-FCA3D7CB1324}
2012-06-28 22:06 - 2012-06-28 22:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{956D2391-025F-4357-9BD6-EFF77B7D0883}
2012-06-28 22:05 - 2012-06-28 22:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{FF78CBEA-9AF2-4975-8940-9EAC0082C534}
2012-06-28 13:13 - 2012-06-28 13:13 - 00000148 ____A C:\Users\Nick\Downloads\staffportal.html
2012-06-28 10:05 - 2012-06-28 10:05 - 00000000 ____D C:\Users\Nick\AppData\Local\{7271320B-FA68-416A-B81D-F238BCA3B90A}
2012-06-28 10:05 - 2012-06-28 10:05 - 00000000 ____D C:\Users\Nick\AppData\Local\{2535CC88-4C61-4A8E-B1B9-95807946C879}
2012-06-27 22:04 - 2012-06-27 22:04 - 00000000 ____D C:\Users\Nick\AppData\Local\{DB131843-BFFA-422C-90BC-EA83F66F3F0C}
2012-06-27 22:04 - 2012-06-27 22:04 - 00000000 ____D C:\Users\Nick\AppData\Local\{2EC23E65-3F9D-40B0-9103-E3E967929B5C}
2012-06-27 09:56 - 2012-06-27 09:56 - 00000000 ____D C:\Users\Nick\AppData\Local\{F042E3ED-C605-46FF-A458-2FFED04F7AC4}
2012-06-27 09:55 - 2012-06-27 09:56 - 00000000 ____D C:\Users\Nick\AppData\Local\{4A7339EB-ADA6-4706-8843-377D706CDC63}
2012-06-26 21:55 - 2012-06-26 21:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{C0AEF26D-9A75-4171-81D4-0C6CB8640416}
2012-06-26 21:55 - 2012-06-26 21:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{4C7D55BD-DFC4-4296-AFE3-21DF71CCF5C9}
2012-06-26 07:49 - 2012-06-26 07:49 - 00000000 ____D C:\Users\Nick\AppData\Local\{295AC423-A8C4-461F-9712-240944F579B8}
2012-06-26 07:48 - 2012-06-26 07:49 - 00000000 ____D C:\Users\Nick\AppData\Local\{49D41160-4221-4FD0-ACCF-22E90DC02046}
2012-06-25 11:16 - 2012-06-25 11:16 - 00000000 ____D C:\Users\Nick\AppData\Local\{C381A0F9-5FB8-4B91-BD42-12F4D4F7EB01}
2012-06-25 11:15 - 2012-06-25 11:16 - 00000000 ____D C:\Users\Nick\AppData\Local\{145D473A-77F3-4302-8516-9E47E08F1D3E}
2012-06-24 23:15 - 2012-06-24 23:15 - 00000000 ____D C:\Users\Nick\AppData\Local\{838B1AA6-0D86-4889-9666-97669650B1CF}
2012-06-24 23:15 - 2012-06-24 23:15 - 00000000 ____D C:\Users\Nick\AppData\Local\{27748708-4F7A-4F8E-9620-10B797AE769F}
2012-06-24 11:14 - 2012-06-24 11:14 - 00000000 ____D C:\Users\Nick\AppData\Local\{3356CA5A-4B68-463D-BB24-44A656692D7C}
2012-06-24 11:14 - 2012-06-24 11:14 - 00000000 ____D C:\Users\Nick\AppData\Local\{2D90F4FC-DBFF-473C-91C1-2A416742601A}
2012-06-23 23:15 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-23 23:15 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-23 23:15 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-23 23:15 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-23 23:14 - 2012-06-23 23:14 - 00000000 ____D C:\Users\Nick\AppData\Local\{258DFD1E-3EB3-4EA8-BF10-6FC8E2C62AAA}
2012-06-23 23:14 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-23 23:14 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-23 23:14 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-23 23:14 - 2012-06-02 06:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-23 23:14 - 2012-06-02 06:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-23 23:13 - 2012-06-23 23:14 - 00000000 ____D C:\Users\Nick\AppData\Local\{1C6380F5-1559-4724-A538-BACFC129ED94}
2012-06-23 01:20 - 2012-06-23 01:20 - 00000000 ____D C:\Users\Nick\AppData\Local\{C8669A9D-BFFB-4B75-B1BB-28E3E8CBB9DD}
2012-06-23 01:20 - 2012-06-23 01:20 - 00000000 ____D C:\Users\Nick\AppData\Local\{B483488A-604E-4DD2-B698-38B4EE63DB07}
2012-06-22 13:19 - 2012-06-22 13:19 - 00000000 ____D C:\Users\Nick\AppData\Local\Macromedia
2012-06-22 13:19 - 2012-06-22 13:19 - 00000000 ____D C:\Users\Nick\AppData\Local\{A3F8F356-DDCB-4BF7-91D0-5BDD459488B1}
2012-06-22 13:19 - 2012-06-22 13:19 - 00000000 ____D C:\Users\Nick\AppData\Local\{6C9F7628-7458-4682-B89A-2C937A1847C7}
2012-06-21 21:39 - 2012-06-21 21:39 - 00000000 ____D C:\Users\Nick\AppData\Local\{B0CD499F-A032-480B-AF80-C1805B8C2D1D}
2012-06-21 21:39 - 2012-06-21 21:39 - 00000000 ____D C:\Users\Nick\AppData\Local\{5E8F5A10-A119-49EA-8650-E7A4D553711C}
2012-06-21 07:50 - 2012-06-21 07:50 - 00000000 ____D C:\Users\Nick\AppData\Local\{E53BC128-1E34-40FC-A19A-04EBBFDE2D26}
2012-06-21 07:50 - 2012-06-21 07:50 - 00000000 ____D C:\Users\Nick\AppData\Local\{8850ED6A-A5BE-492D-94C9-2AF64AAE6B96}
2012-06-20 12:09 - 2012-06-20 12:09 - 00000000 ____D C:\Users\Nick\AppData\Local\{B321C1A6-DABB-45E6-9B8E-7A780D8B8FF6}
2012-06-20 12:09 - 2012-06-20 12:09 - 00000000 ____D C:\Users\Nick\AppData\Local\{527B8C23-C80D-4609-818C-83EBF824794A}
2012-06-20 00:08 - 2012-06-20 00:08 - 00000000 ____D C:\Users\Nick\AppData\Local\{74F3A7A4-C642-4736-A763-A0710C9FB5CC}
2012-06-20 00:08 - 2012-06-20 00:08 - 00000000 ____D C:\Users\Nick\AppData\Local\{3721E10D-60BA-4940-9F43-B266505EFBAF}
2012-06-19 12:08 - 2012-06-19 12:08 - 00000000 ____D C:\Users\Nick\AppData\Local\{322DE805-F2E8-4D46-B278-8ADF23F3F0DA}
2012-06-19 12:07 - 2012-06-19 12:08 - 00000000 ____D C:\Users\Nick\AppData\Local\{C7B22371-46B1-4510-B29E-F71447F9E3A6}
2012-06-19 00:07 - 2012-06-19 00:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{F3DD5FEA-6CAE-4DDA-8F00-9AE42A503A95}
2012-06-19 00:07 - 2012-06-19 00:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{487779A3-73DA-46DD-B373-5F3F83C86833}
2012-06-18 12:06 - 2012-06-18 12:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{523FD651-E2F8-4263-A676-C841B7B43CE9}
2012-06-18 00:06 - 2012-06-18 00:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{F387DA99-1669-4430-A094-857BC51E2C36}
2012-06-17 12:05 - 2012-06-17 12:05 - 00000000 ____D C:\Users\Nick\AppData\Local\{0D23086E-2C3A-41F1-BEE5-903C749A93E0}
2012-06-17 00:05 - 2012-06-17 00:05 - 00000000 ____D C:\Users\Nick\AppData\Local\{B0ADB908-D9C1-4C7B-929E-C1707C23947D}
2012-06-16 09:46 - 2012-06-16 09:46 - 00000000 ____D C:\Users\Nick\AppData\Local\{FBC7EFDE-46CE-4D8A-BF7A-B508B3D0713A}
2012-06-15 21:46 - 2012-06-15 21:46 - 00000000 ____D C:\Users\Nick\AppData\Local\{690B3562-C6C2-4E21-A4F7-4F3B00A44A1D}
2012-06-15 09:45 - 2012-06-15 09:46 - 00000000 ____D C:\Users\Nick\AppData\Local\{0D7C3205-EEFA-4A4C-8F47-6D606DA9FFD2}
2012-06-14 21:45 - 2012-06-14 21:45 - 00000000 ____D C:\Users\Nick\AppData\Local\{A16466C6-81C1-4DCB-8E1E-CFAF341BD17B}
2012-06-14 09:45 - 2012-06-14 09:45 - 00000000 ____D C:\Users\Nick\AppData\Local\{74398816-F0A6-4ED3-8F4F-0A62B5AA9D1E}
2012-06-14 09:44 - 2012-06-14 09:45 - 00000000 ____D C:\Users\Nick\AppData\Local\{394FA640-90DA-45AE-95C6-D7BD8EF933AF}
2012-06-13 21:44 - 2012-06-13 21:44 - 00000000 ____D C:\Users\Nick\AppData\Local\{72C1B89C-3CC7-43C6-894C-B99B711DDAA3}
2012-06-13 21:44 - 2012-06-13 21:44 - 00000000 ____D C:\Users\Nick\AppData\Local\{03F838B3-4D7A-4EB3-A8D5-B01DC51811F3}
2012-06-13 09:18 - 2012-06-13 09:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{AA54C897-1C94-4765-8082-6B462A541E00}
2012-06-13 09:17 - 2012-06-13 09:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{FC4E9955-4E6A-4028-84D1-785D65CF773F}
============ 3 Months Modified Files ========================
2012-07-12 22:34 - 2012-07-12 12:09 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-12 22:34 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-12 22:34 - 2009-07-13 20:51 - 00084774 ____A C:\Windows\setupact.log
2012-07-12 22:32 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-12 22:23 - 2009-07-13 21:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-12 22:15 - 2012-04-26 23:24 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-12 21:55 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-12 21:55 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-12 21:53 - 2011-06-11 06:44 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-12 21:53 - 2011-05-16 06:56 - 01410291 ____A C:\Windows\WindowsUpdate.log
2012-07-12 21:52 - 2011-06-11 06:44 - 00787498 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-12 21:45 - 2012-07-12 21:45 - 12621696 ____A (Microsoft Corporation) C:\Users\Nick\Downloads\mseinstall.exe
2012-07-12 13:08 - 2011-05-16 09:19 - 00254290 ____A C:\Windows\PFRO.log
2012-07-12 12:19 - 2012-07-12 12:09 - 00002342 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-12 12:19 - 2012-07-12 12:09 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-12 12:08 - 2012-04-26 23:24 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-12 12:08 - 2011-06-11 07:34 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-11 05:04 - 2009-07-13 20:45 - 00302824 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 23:12 - 2011-06-14 10:00 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 12:31 - 2011-08-05 00:48 - 00000420 ____A C:\Users\Nick\Desktop\Films to watch.txt
2012-06-28 13:13 - 2012-06-28 13:13 - 00000148 ____A C:\Users\Nick\Downloads\staffportal.html
2012-06-12 13:09 - 2009-07-13 21:13 - 00787892 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-11 19:08 - 2012-07-10 23:14 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 11:33 - 2012-06-09 11:33 - 01203408 ____A C:\Users\Nick\Downloads\Promo 25 Fiesta Patria Gaucha 2011 - 20seg.avi
2012-06-09 11:29 - 2012-06-09 11:29 - 01928149 ____A C:\Users\Nick\Downloads\Promo 25 Fiesta Patria Gaucha 2011 - 20seg.mp4
2012-06-08 21:43 - 2012-07-10 21:49 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 21:49 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 12:42 - 2011-08-29 10:50 - 00101400 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKE64.sys
2012-06-05 22:06 - 2012-07-10 21:49 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 21:49 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 21:49 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 21:49 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 21:49 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 21:49 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 07:36 - 2012-06-01 11:22 - 00063488 __ASH C:\Users\Nick\Desktop\Thumbs.db
2012-06-02 14:19 - 2012-06-23 23:15 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-23 23:15 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-23 23:15 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-23 23:14 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-23 23:14 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-23 23:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-23 23:14 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-23 23:14 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:15 - 2012-06-23 23:14 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 23:11 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 23:11 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 23:11 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 23:11 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 23:11 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 23:11 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 23:11 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 23:11 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 23:11 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 23:11 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 23:11 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 23:11 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 23:11 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 23:11 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 23:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 23:11 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 23:11 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 23:11 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 23:11 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 23:11 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 23:11 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 23:11 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 23:11 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 23:11 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 23:11 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 23:11 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 23:11 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 23:11 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 21:49 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 21:49 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 21:49 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 21:49 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 21:49 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 21:49 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 21:49 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 21:49 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 21:49 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-06-01 11:22 - 2012-06-01 11:22 - 00001241 ____A C:\Users\Nick\Desktop\SEASON 5 - Shortcut.lnk
2012-05-04 03:06 - 2012-06-12 11:07 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 11:07 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 11:07 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 12:12 - 2012-05-03 12:12 - 01639789 ____A C:\Users\Nick\Downloads\winrar-x64-411.exe
2012-04-30 21:40 - 2012-06-12 11:07 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-12 11:07 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 11:07 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 11:07 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 11:07 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 11:06 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 11:06 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 11:06 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 11:06 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 11:06 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 11:06 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\@
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\L
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\n
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\U
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\U\00000001.@
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\U\80000000.@
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\U\800000cb.@
ZeroAccess:
C:\Users\Nick\AppData\Local\{f26f19f5-8055-2193-e125-44b55f27d338}
C:\Users\Nick\AppData\Local\{f26f19f5-8055-2193-e125-44b55f27d338}\@
C:\Users\Nick\AppData\Local\{f26f19f5-8055-2193-e125-44b55f27d338}\L
C:\Users\Nick\AppData\Local\{f26f19f5-8055-2193-e125-44b55f27d338}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 5887.29 MB
Available physical RAM: 4983.95 MB
Total Pagefile: 5885.43 MB
Available Pagefile: 4964.1 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:918.65 GB) (Free:710.68 GB) NTFS
2 Drive e: (HP_RECOVERY) (Fixed) (Total:12.76 GB) (Free:1.57 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
5 Drive h: () (Removable) (Total:7.47 GB) (Free:5.11 GB) FAT32
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
11 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 7657 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 918 GB 101 MB
Partition 3 Primary 12 GB 918 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 918 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E HP_RECOVERY NTFS Partition 12 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7655 MB 22 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT32 Removable 7655 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-08 00:22
======================= End Of Log ==========================
Thanks so much for any help.
I took the liberty of assuming you might want me to download Farbar 64bit and run it from a flashdrive (from System recovery, not within Windows).
The results are below:
Scan result of Farbar Recovery Scan Tool Version: 11-07-2012
Ran by SYSTEM at 13-07-2012 07:56:17
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [102400 2010-05-11] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe [664600 2010-09-28] (PDF Complete Inc)
HKLM-x32\...\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe [385024 2009-04-03] (Hewlett-Packard)
HKLM-x32\...\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [x]
HKLM-x32\...\Run: [V0640Mon.exe] C:\Windows\V0640Mon.exe [28672 2009-09-22] (Creative Technology Ltd.)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Startup: C:\Users\Nick\Start Menu\Programs\Startup\Mozilla Firefox.lnk
ShortcutTarget: Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Startup: C:\Users\Nick\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Nick\Start Menu\Programs\Startup\Windows Live Mail.lnk
ShortcutTarget: Windows Live Mail.lnk -> C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation)
==================== Services (Whitelisted) ======
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 RapportMgmtService; "C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe" [976728 2012-06-08] (Trusteer Ltd.)
2 HP Health Check Service; "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe" [x]
3 hpqwmiex; "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe" [x]
========================== Drivers (Whitelisted) =============
1 RapportCerberus_34302; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\34302\RapportCerberus64_34302.sys [397520 2011-12-15] ()
1 RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [55096 2012-06-08] (Trusteer Ltd.)
0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [101400 2012-06-08] (Trusteer Ltd.)
1 RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [297048 2012-06-08] (Trusteer Ltd.)
3 V0640Vid; C:\Windows\System32\Drivers\V0640Vid.sys [319520 2009-12-03] (Creative Technology Ltd.)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-13 07:36 - 2012-07-13 07:36 - 00000000 ____D C:\Users\All Users\Recovery
2012-07-12 21:52 - 2012-07-12 21:52 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-07-12 21:52 - 2012-07-12 21:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-12 21:45 - 2012-07-12 21:45 - 12621696 ____A (Microsoft Corporation) C:\Users\Nick\Downloads\mseinstall.exe
2012-07-12 12:54 - 2012-07-12 12:54 - 00000000 ____D C:\Users\Nick\AppData\Local\{B90D9025-050E-49BE-87EE-6FF7C9542EEF}
2012-07-12 12:54 - 2012-07-12 12:54 - 00000000 ____D C:\Users\Nick\AppData\Local\{AE7D64B8-B404-40AE-AD7D-95077CDE4F52}
2012-07-12 12:10 - 2012-07-12 12:10 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-12 12:09 - 2012-07-12 22:34 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-12 12:09 - 2012-07-12 12:19 - 00002342 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-12 12:09 - 2012-07-12 12:19 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-12 12:08 - 2012-07-12 12:09 - 00000000 ____D C:\Users\Nick\AppData\Local\Google
2012-07-12 12:08 - 2012-07-12 12:09 - 00000000 ____D C:\Program Files (x86)\Google
2012-07-12 00:53 - 2012-07-12 00:53 - 00000000 ____D C:\Users\Nick\AppData\Local\{F825A961-913E-4A6E-AF6A-0EB31F7BC474}
2012-07-12 00:53 - 2012-07-12 00:53 - 00000000 ____D C:\Users\Nick\AppData\Local\{B1DB62FE-6BD6-4F00-A92F-21B7C743A24E}
2012-07-11 12:07 - 2012-07-11 12:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{D8FF24A9-58D5-4BAE-9221-35147786B936}
2012-07-11 12:07 - 2012-07-11 12:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{39F8F8FF-94AB-42E9-A350-9F26BAEE0417}
2012-07-10 23:14 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-10 23:11 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-10 23:11 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-10 23:11 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-10 23:11 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-10 23:11 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-10 23:11 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-10 23:11 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-10 23:11 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-10 23:11 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-10 23:11 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-10 23:11 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-10 23:11 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-10 23:11 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-10 23:11 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-10 23:11 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-10 23:11 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-10 23:11 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-10 23:11 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-10 23:11 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-10 23:11 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-10 23:11 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-10 23:11 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-10 23:11 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-10 23:11 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-10 23:11 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-10 23:11 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-10 23:11 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-10 23:11 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-10 22:40 - 2012-07-10 22:41 - 00000000 ____D C:\Users\Nick\AppData\Local\{584EB645-7094-4D2C-82F7-896D444407A0}
2012-07-10 22:40 - 2012-07-10 22:40 - 00000000 ____D C:\Users\Nick\AppData\Local\{8BB21673-994B-4652-9DC3-1B92DF24F620}
2012-07-10 21:49 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-10 21:49 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-10 21:49 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-10 21:49 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-10 21:49 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-10 21:49 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-10 21:49 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-10 21:49 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-10 21:49 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-10 21:49 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-10 21:49 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-10 21:49 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-10 21:49 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-10 21:49 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-10 21:49 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-10 21:49 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-10 21:49 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-10 21:49 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-10 21:49 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 10:40 - 2012-07-10 10:40 - 00000000 ____D C:\Users\Nick\AppData\Local\{C9C406DE-B88A-44EF-8105-1B71C2A5B491}
2012-07-10 10:39 - 2012-07-10 10:40 - 00000000 ____D C:\Users\Nick\AppData\Local\{0EE56A72-64FC-41C5-94A8-9D25A7A35AD9}
2012-07-09 22:39 - 2012-07-09 22:39 - 00000000 ____D C:\Users\Nick\AppData\Local\{FB960092-32DA-462A-9C25-42AA9A962B48}
2012-07-09 22:39 - 2012-07-09 22:39 - 00000000 ____D C:\Users\Nick\AppData\Local\{C0EAF565-7EF8-4724-9403-55C85CBBC30C}
2012-07-09 10:38 - 2012-07-09 10:38 - 00000000 ____D C:\Users\Nick\AppData\Local\{1BD48371-EAC0-42CA-8F77-A7574BC3217B}
2012-07-09 10:38 - 2012-07-09 10:38 - 00000000 ____D C:\Users\Nick\AppData\Local\{00D59B2A-79BB-4627-9E4E-738BE9ED2950}
2012-07-08 22:37 - 2012-07-08 22:37 - 00000000 ____D C:\Users\Nick\AppData\Local\{6F500260-0214-47B1-BB42-DB25C52684B6}
2012-07-08 22:37 - 2012-07-08 22:37 - 00000000 ____D C:\Users\Nick\AppData\Local\{5F013C15-F2A9-4CE6-8BA7-2353FE3BA719}
2012-07-08 02:07 - 2012-07-08 02:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{D14185A6-1E41-48CE-9720-66817F2DF9D0}
2012-07-08 02:07 - 2012-07-08 02:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{AF6AE319-DF7A-4189-AACC-99AA4FD6B6C4}
2012-07-07 14:06 - 2012-07-07 14:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{8ADF0B2A-6A20-4518-B2B8-AA07525F36FE}
2012-07-07 14:06 - 2012-07-07 14:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{E6CED18A-8164-4A89-968E-46FFBEB7FAA7}
2012-07-07 01:18 - 2012-07-07 01:19 - 00000000 ____D C:\Users\Nick\AppData\Local\{FAEFD1FF-AFF0-4D34-8389-184AA3B80016}
2012-07-07 01:18 - 2012-07-07 01:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{15630BEB-AFF8-460F-A1E8-A53A4EE7F91B}
2012-07-06 13:18 - 2012-07-06 13:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{A298EB6A-B924-490B-91F4-671769F06835}
2012-07-06 13:17 - 2012-07-06 13:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{3B75D8BB-6519-4203-B245-ACC54D4F1BA8}
2012-07-05 22:24 - 2012-07-05 22:24 - 00000000 ____D C:\Users\Nick\AppData\Local\{CD9F5B98-8CBB-4682-9E03-0988B3926197}
2012-07-05 22:23 - 2012-07-05 22:24 - 00000000 ____D C:\Users\Nick\AppData\Local\{B22E9A96-A121-405F-BE9E-91E3539CB892}
2012-07-05 09:59 - 2012-07-05 09:59 - 00000000 ____D C:\Users\Nick\AppData\Local\{7E1F5C26-E9B3-41D7-A2F7-DBEF7226E6C5}
2012-07-05 09:59 - 2012-07-05 09:59 - 00000000 ____D C:\Users\Nick\AppData\Local\{535E5E57-55B8-4289-84C2-252A7B760B0E}
2012-07-04 21:59 - 2012-07-04 21:59 - 00000000 ____D C:\Users\Nick\AppData\Local\{76F34B1A-E2A7-4D45-9E50-CA639E4F4B14}
2012-07-04 21:58 - 2012-07-04 21:59 - 00000000 ____D C:\Users\Nick\AppData\Local\{BEB6DA39-9C51-44E0-947E-842D7ECF12E3}
2012-07-04 09:57 - 2012-07-04 09:57 - 00000000 ____D C:\Users\Nick\AppData\Local\{745D7808-5881-4AAA-9F2D-4BB8A489E6AD}
2012-07-04 09:56 - 2012-07-04 09:57 - 00000000 ____D C:\Users\Nick\AppData\Local\{334F9E18-4CA9-4012-804F-26388C7A83B4}
2012-07-03 21:56 - 2012-07-03 21:56 - 00000000 ____D C:\Users\Nick\AppData\Local\{C087C645-B59B-4CD7-B0DF-BC3413C66D51}
2012-07-03 21:56 - 2012-07-03 21:56 - 00000000 ____D C:\Users\Nick\AppData\Local\{0566AA2F-0D3C-4E28-A1CC-C08A979E3349}
2012-07-03 09:55 - 2012-07-03 09:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{F6C08CF6-836D-47CF-A3EE-933C3DCC8D1C}
2012-07-03 09:55 - 2012-07-03 09:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{14CAA059-26B3-4F51-A1B8-409350794CA4}
2012-07-02 21:54 - 2012-07-02 21:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{2F4AA866-2A2C-40EF-8654-3C97805D70B3}
2012-07-02 21:54 - 2012-07-02 21:54 - 00000000 ____D C:\Users\Nick\AppData\Local\{748C527C-ACBA-48BC-9214-0D68442783CC}
2012-07-02 08:10 - 2012-07-02 08:10 - 00000000 ____D C:\Users\Nick\AppData\Local\{D9B9F882-7332-4AA7-857D-EFA39B243532}
2012-07-02 08:10 - 2012-07-02 08:10 - 00000000 ____D C:\Users\Nick\AppData\Local\{08854A89-B624-4ABD-A8F6-6CAF7205EC14}
2012-07-01 16:25 - 2012-07-01 16:26 - 00000000 ____D C:\Users\Nick\AppData\Local\{89271E75-F705-487F-BC50-4B8DD82D8D28}
2012-07-01 16:25 - 2012-07-01 16:25 - 00000000 ____D C:\Users\Nick\AppData\Local\{71C4BE19-5BD5-4A35-A4DF-D024C9498D41}
2012-07-01 03:26 - 2012-07-01 03:26 - 00000000 ____D C:\Users\Nick\AppData\Local\{D317A0B0-851B-4B8F-B45E-A6502F305FBD}
2012-07-01 03:26 - 2012-07-01 03:26 - 00000000 ____D C:\Users\Nick\AppData\Local\{7EAA9403-AEA8-4E2F-91A7-EB9CE5753D98}
2012-06-30 15:25 - 2012-06-30 15:25 - 00000000 ____D C:\Users\Nick\AppData\Local\{C477856A-D10E-4231-8BE0-DDCE7C02E449}
2012-06-30 15:25 - 2012-06-30 15:25 - 00000000 ____D C:\Users\Nick\AppData\Local\{321342B1-8703-47E1-BC7D-62A66D92D8D6}
2012-06-30 03:24 - 2012-06-30 03:25 - 00000000 ____D C:\Users\Nick\AppData\Local\{A2E8B310-D43A-4152-B972-20B3F6399F76}
2012-06-30 03:24 - 2012-06-30 03:24 - 00000000 ____D C:\Users\Nick\AppData\Local\{24A36B8E-6695-4000-80C0-58EAFB9024E0}
2012-06-29 10:06 - 2012-06-29 10:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{EF10A2B5-471A-4C4C-A13E-E771935093D8}
2012-06-29 10:06 - 2012-06-29 10:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{E55C73EF-37BA-439C-8227-FCA3D7CB1324}
2012-06-28 22:06 - 2012-06-28 22:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{956D2391-025F-4357-9BD6-EFF77B7D0883}
2012-06-28 22:05 - 2012-06-28 22:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{FF78CBEA-9AF2-4975-8940-9EAC0082C534}
2012-06-28 13:13 - 2012-06-28 13:13 - 00000148 ____A C:\Users\Nick\Downloads\staffportal.html
2012-06-28 10:05 - 2012-06-28 10:05 - 00000000 ____D C:\Users\Nick\AppData\Local\{7271320B-FA68-416A-B81D-F238BCA3B90A}
2012-06-28 10:05 - 2012-06-28 10:05 - 00000000 ____D C:\Users\Nick\AppData\Local\{2535CC88-4C61-4A8E-B1B9-95807946C879}
2012-06-27 22:04 - 2012-06-27 22:04 - 00000000 ____D C:\Users\Nick\AppData\Local\{DB131843-BFFA-422C-90BC-EA83F66F3F0C}
2012-06-27 22:04 - 2012-06-27 22:04 - 00000000 ____D C:\Users\Nick\AppData\Local\{2EC23E65-3F9D-40B0-9103-E3E967929B5C}
2012-06-27 09:56 - 2012-06-27 09:56 - 00000000 ____D C:\Users\Nick\AppData\Local\{F042E3ED-C605-46FF-A458-2FFED04F7AC4}
2012-06-27 09:55 - 2012-06-27 09:56 - 00000000 ____D C:\Users\Nick\AppData\Local\{4A7339EB-ADA6-4706-8843-377D706CDC63}
2012-06-26 21:55 - 2012-06-26 21:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{C0AEF26D-9A75-4171-81D4-0C6CB8640416}
2012-06-26 21:55 - 2012-06-26 21:55 - 00000000 ____D C:\Users\Nick\AppData\Local\{4C7D55BD-DFC4-4296-AFE3-21DF71CCF5C9}
2012-06-26 07:49 - 2012-06-26 07:49 - 00000000 ____D C:\Users\Nick\AppData\Local\{295AC423-A8C4-461F-9712-240944F579B8}
2012-06-26 07:48 - 2012-06-26 07:49 - 00000000 ____D C:\Users\Nick\AppData\Local\{49D41160-4221-4FD0-ACCF-22E90DC02046}
2012-06-25 11:16 - 2012-06-25 11:16 - 00000000 ____D C:\Users\Nick\AppData\Local\{C381A0F9-5FB8-4B91-BD42-12F4D4F7EB01}
2012-06-25 11:15 - 2012-06-25 11:16 - 00000000 ____D C:\Users\Nick\AppData\Local\{145D473A-77F3-4302-8516-9E47E08F1D3E}
2012-06-24 23:15 - 2012-06-24 23:15 - 00000000 ____D C:\Users\Nick\AppData\Local\{838B1AA6-0D86-4889-9666-97669650B1CF}
2012-06-24 23:15 - 2012-06-24 23:15 - 00000000 ____D C:\Users\Nick\AppData\Local\{27748708-4F7A-4F8E-9620-10B797AE769F}
2012-06-24 11:14 - 2012-06-24 11:14 - 00000000 ____D C:\Users\Nick\AppData\Local\{3356CA5A-4B68-463D-BB24-44A656692D7C}
2012-06-24 11:14 - 2012-06-24 11:14 - 00000000 ____D C:\Users\Nick\AppData\Local\{2D90F4FC-DBFF-473C-91C1-2A416742601A}
2012-06-23 23:15 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-23 23:15 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-23 23:15 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-23 23:15 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-23 23:14 - 2012-06-23 23:14 - 00000000 ____D C:\Users\Nick\AppData\Local\{258DFD1E-3EB3-4EA8-BF10-6FC8E2C62AAA}
2012-06-23 23:14 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-23 23:14 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-23 23:14 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-23 23:14 - 2012-06-02 06:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-23 23:14 - 2012-06-02 06:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-23 23:13 - 2012-06-23 23:14 - 00000000 ____D C:\Users\Nick\AppData\Local\{1C6380F5-1559-4724-A538-BACFC129ED94}
2012-06-23 01:20 - 2012-06-23 01:20 - 00000000 ____D C:\Users\Nick\AppData\Local\{C8669A9D-BFFB-4B75-B1BB-28E3E8CBB9DD}
2012-06-23 01:20 - 2012-06-23 01:20 - 00000000 ____D C:\Users\Nick\AppData\Local\{B483488A-604E-4DD2-B698-38B4EE63DB07}
2012-06-22 13:19 - 2012-06-22 13:19 - 00000000 ____D C:\Users\Nick\AppData\Local\Macromedia
2012-06-22 13:19 - 2012-06-22 13:19 - 00000000 ____D C:\Users\Nick\AppData\Local\{A3F8F356-DDCB-4BF7-91D0-5BDD459488B1}
2012-06-22 13:19 - 2012-06-22 13:19 - 00000000 ____D C:\Users\Nick\AppData\Local\{6C9F7628-7458-4682-B89A-2C937A1847C7}
2012-06-21 21:39 - 2012-06-21 21:39 - 00000000 ____D C:\Users\Nick\AppData\Local\{B0CD499F-A032-480B-AF80-C1805B8C2D1D}
2012-06-21 21:39 - 2012-06-21 21:39 - 00000000 ____D C:\Users\Nick\AppData\Local\{5E8F5A10-A119-49EA-8650-E7A4D553711C}
2012-06-21 07:50 - 2012-06-21 07:50 - 00000000 ____D C:\Users\Nick\AppData\Local\{E53BC128-1E34-40FC-A19A-04EBBFDE2D26}
2012-06-21 07:50 - 2012-06-21 07:50 - 00000000 ____D C:\Users\Nick\AppData\Local\{8850ED6A-A5BE-492D-94C9-2AF64AAE6B96}
2012-06-20 12:09 - 2012-06-20 12:09 - 00000000 ____D C:\Users\Nick\AppData\Local\{B321C1A6-DABB-45E6-9B8E-7A780D8B8FF6}
2012-06-20 12:09 - 2012-06-20 12:09 - 00000000 ____D C:\Users\Nick\AppData\Local\{527B8C23-C80D-4609-818C-83EBF824794A}
2012-06-20 00:08 - 2012-06-20 00:08 - 00000000 ____D C:\Users\Nick\AppData\Local\{74F3A7A4-C642-4736-A763-A0710C9FB5CC}
2012-06-20 00:08 - 2012-06-20 00:08 - 00000000 ____D C:\Users\Nick\AppData\Local\{3721E10D-60BA-4940-9F43-B266505EFBAF}
2012-06-19 12:08 - 2012-06-19 12:08 - 00000000 ____D C:\Users\Nick\AppData\Local\{322DE805-F2E8-4D46-B278-8ADF23F3F0DA}
2012-06-19 12:07 - 2012-06-19 12:08 - 00000000 ____D C:\Users\Nick\AppData\Local\{C7B22371-46B1-4510-B29E-F71447F9E3A6}
2012-06-19 00:07 - 2012-06-19 00:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{F3DD5FEA-6CAE-4DDA-8F00-9AE42A503A95}
2012-06-19 00:07 - 2012-06-19 00:07 - 00000000 ____D C:\Users\Nick\AppData\Local\{487779A3-73DA-46DD-B373-5F3F83C86833}
2012-06-18 12:06 - 2012-06-18 12:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{523FD651-E2F8-4263-A676-C841B7B43CE9}
2012-06-18 00:06 - 2012-06-18 00:06 - 00000000 ____D C:\Users\Nick\AppData\Local\{F387DA99-1669-4430-A094-857BC51E2C36}
2012-06-17 12:05 - 2012-06-17 12:05 - 00000000 ____D C:\Users\Nick\AppData\Local\{0D23086E-2C3A-41F1-BEE5-903C749A93E0}
2012-06-17 00:05 - 2012-06-17 00:05 - 00000000 ____D C:\Users\Nick\AppData\Local\{B0ADB908-D9C1-4C7B-929E-C1707C23947D}
2012-06-16 09:46 - 2012-06-16 09:46 - 00000000 ____D C:\Users\Nick\AppData\Local\{FBC7EFDE-46CE-4D8A-BF7A-B508B3D0713A}
2012-06-15 21:46 - 2012-06-15 21:46 - 00000000 ____D C:\Users\Nick\AppData\Local\{690B3562-C6C2-4E21-A4F7-4F3B00A44A1D}
2012-06-15 09:45 - 2012-06-15 09:46 - 00000000 ____D C:\Users\Nick\AppData\Local\{0D7C3205-EEFA-4A4C-8F47-6D606DA9FFD2}
2012-06-14 21:45 - 2012-06-14 21:45 - 00000000 ____D C:\Users\Nick\AppData\Local\{A16466C6-81C1-4DCB-8E1E-CFAF341BD17B}
2012-06-14 09:45 - 2012-06-14 09:45 - 00000000 ____D C:\Users\Nick\AppData\Local\{74398816-F0A6-4ED3-8F4F-0A62B5AA9D1E}
2012-06-14 09:44 - 2012-06-14 09:45 - 00000000 ____D C:\Users\Nick\AppData\Local\{394FA640-90DA-45AE-95C6-D7BD8EF933AF}
2012-06-13 21:44 - 2012-06-13 21:44 - 00000000 ____D C:\Users\Nick\AppData\Local\{72C1B89C-3CC7-43C6-894C-B99B711DDAA3}
2012-06-13 21:44 - 2012-06-13 21:44 - 00000000 ____D C:\Users\Nick\AppData\Local\{03F838B3-4D7A-4EB3-A8D5-B01DC51811F3}
2012-06-13 09:18 - 2012-06-13 09:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{AA54C897-1C94-4765-8082-6B462A541E00}
2012-06-13 09:17 - 2012-06-13 09:18 - 00000000 ____D C:\Users\Nick\AppData\Local\{FC4E9955-4E6A-4028-84D1-785D65CF773F}
============ 3 Months Modified Files ========================
2012-07-12 22:34 - 2012-07-12 12:09 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-07-12 22:34 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-12 22:34 - 2009-07-13 20:51 - 00084774 ____A C:\Windows\setupact.log
2012-07-12 22:32 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-12 22:23 - 2009-07-13 21:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-12 22:15 - 2012-04-26 23:24 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-12 21:55 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-12 21:55 - 2009-07-13 20:45 - 00015792 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-12 21:53 - 2011-06-11 06:44 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-12 21:53 - 2011-05-16 06:56 - 01410291 ____A C:\Windows\WindowsUpdate.log
2012-07-12 21:52 - 2011-06-11 06:44 - 00787498 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-12 21:45 - 2012-07-12 21:45 - 12621696 ____A (Microsoft Corporation) C:\Users\Nick\Downloads\mseinstall.exe
2012-07-12 13:08 - 2011-05-16 09:19 - 00254290 ____A C:\Windows\PFRO.log
2012-07-12 12:19 - 2012-07-12 12:09 - 00002342 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2012-07-12 12:19 - 2012-07-12 12:09 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-07-12 12:08 - 2012-04-26 23:24 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-12 12:08 - 2011-06-11 07:34 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-11 05:04 - 2009-07-13 20:45 - 00302824 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-10 23:12 - 2011-06-14 10:00 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-03 12:31 - 2011-08-05 00:48 - 00000420 ____A C:\Users\Nick\Desktop\Films to watch.txt
2012-06-28 13:13 - 2012-06-28 13:13 - 00000148 ____A C:\Users\Nick\Downloads\staffportal.html
2012-06-12 13:09 - 2009-07-13 21:13 - 00787892 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-11 19:08 - 2012-07-10 23:14 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-09 11:33 - 2012-06-09 11:33 - 01203408 ____A C:\Users\Nick\Downloads\Promo 25 Fiesta Patria Gaucha 2011 - 20seg.avi
2012-06-09 11:29 - 2012-06-09 11:29 - 01928149 ____A C:\Users\Nick\Downloads\Promo 25 Fiesta Patria Gaucha 2011 - 20seg.mp4
2012-06-08 21:43 - 2012-07-10 21:49 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-10 21:49 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-08 12:42 - 2011-08-29 10:50 - 00101400 ____A (Trusteer Ltd.) C:\Windows\System32\Drivers\RapportKE64.sys
2012-06-05 22:06 - 2012-07-10 21:49 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-10 21:49 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-10 21:49 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-10 21:49 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-10 21:49 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-10 21:49 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 07:36 - 2012-06-01 11:22 - 00063488 __ASH C:\Users\Nick\Desktop\Thumbs.db
2012-06-02 14:19 - 2012-06-23 23:15 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-23 23:15 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-23 23:15 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-23 23:14 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-23 23:14 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-23 23:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-23 23:14 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-23 23:14 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:15 - 2012-06-23 23:14 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-10 23:11 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-10 23:11 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-10 23:11 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-10 23:11 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-10 23:11 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-10 23:11 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-10 23:11 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-10 23:11 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-10 23:11 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-10 23:11 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-10 23:11 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-10 23:11 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-10 23:11 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-10 23:11 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-10 23:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-10 23:11 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-10 23:11 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-10 23:11 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-10 23:11 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-10 23:11 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-10 23:11 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-10 23:11 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-10 23:11 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-10 23:11 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-10 23:11 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-10 23:11 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-10 23:11 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-10 23:11 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 21:50 - 2012-07-10 21:49 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-10 21:49 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-10 21:49 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-10 21:49 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-10 21:49 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-10 21:49 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-10 21:49 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-10 21:49 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-10 21:49 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-06-01 11:22 - 2012-06-01 11:22 - 00001241 ____A C:\Users\Nick\Desktop\SEASON 5 - Shortcut.lnk
2012-05-04 03:06 - 2012-06-12 11:07 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 11:07 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 11:07 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-03 12:12 - 2012-05-03 12:12 - 01639789 ____A C:\Users\Nick\Downloads\winrar-x64-411.exe
2012-04-30 21:40 - 2012-06-12 11:07 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-12 11:07 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-12 11:07 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 11:07 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 11:07 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 11:06 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 11:06 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 11:06 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 11:06 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 11:06 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 11:06 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
ZeroAccess:
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\@
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\L
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\n
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\U
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\U\00000001.@
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\U\80000000.@
C:\Windows\Installer\{f26f19f5-8055-2193-e125-44b55f27d338}\U\800000cb.@
ZeroAccess:
C:\Users\Nick\AppData\Local\{f26f19f5-8055-2193-e125-44b55f27d338}
C:\Users\Nick\AppData\Local\{f26f19f5-8055-2193-e125-44b55f27d338}\@
C:\Users\Nick\AppData\Local\{f26f19f5-8055-2193-e125-44b55f27d338}\L
C:\Users\Nick\AppData\Local\{f26f19f5-8055-2193-e125-44b55f27d338}\U
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 15%
Total physical RAM: 5887.29 MB
Available physical RAM: 4983.95 MB
Total Pagefile: 5885.43 MB
Available Pagefile: 4964.1 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:918.65 GB) (Free:710.68 GB) NTFS
2 Drive e: (HP_RECOVERY) (Fixed) (Total:12.76 GB) (Free:1.57 GB) NTFS ==>[System with boot components (obtained from reading drive)]
4 Drive g: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS
5 Drive h: () (Removable) (Total:7.47 GB) (Free:5.11 GB) FAT32
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
11 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 7657 MB 0 B
Disk 2 No Media 0 B 0 B
Disk 3 No Media 0 B 0 B
Disk 4 No Media 0 B 0 B
Disk 5 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 918 GB 101 MB
Partition 3 Primary 12 GB 918 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C OS NTFS Partition 918 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E HP_RECOVERY NTFS Partition 12 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 7655 MB 22 KB
==================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT32 Removable 7655 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-08 00:22
======================= End Of Log ==========================