FRST.txt:
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 30-07-2012 20:24:04
Running from K:\
Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [EvtMgr6] D:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [x]
HKLM\...\Run: [LogiScrollApp] C:\Program Files\Logitech\FlowScroll\KhalScroll.exe [166680 2012-02-08] (Logitech, Inc.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2011-08-22] (VMware, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "D:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "D:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [x]
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe" [x]
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448 2011-11-02] (Research In Motion Limited)
HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-06-10] (Brother Industries, Ltd.)
HKU\Richard\...\Run: [uTorrent] "D:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [737656 2012-02-21] (BitTorrent, Inc.)
HKU\Richard\...\Run: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [107000 2011-11-24] (Siber Systems)
HKU\Richard\...\Run: [HFM.NET] "D:\Program Files (x86)\HFM.NET\HFM.exe" [x]
HKU\Richard\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Richard\...\Policies\system: [LogonHoursAction] 2
HKU\Richard\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
IMEO\notepad.exe: [Debugger] "C:\Program Files\Notepad2\Notepad2.exe" /z
Lsa: [Notification Packages] scecli
PGPpwflt
Startup: C:\Users\All Users\Start Menu\Programs\Startup\PGPtray.exe.lnk
ShortcutTarget: PGPtray.exe.lnk -> C:\Windows\Installer\{E5A1684E-3F13-41EA-80C7-3B91FA51AE36}\Icon6560581611.exe ()
Startup: C:\Users\Richard\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Richard\Start Menu\Programs\Startup\FAHControl.lnk
ShortcutTarget: FAHControl.lnk -> C:\Program Files (x86)\FAHClient\FAHControl.exe (No File)
==================== Services (Whitelisted) ======
2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2012-07-15] ()
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NovacomD; C:\Program Files\Palm, Inc\novacomd\amd64\novacomd.exe [71168 2011-03-15] (Palm)
2 PGP RDD Service; C:\Program Files (x86)\PGP Corporation\PGP Desktop\RDDService.exe [166520 2010-09-30] (PGP Corporation)
2 PGPserv; C:\Windows\SysWOW64\PGPserv.exe [135288 2010-09-30] (PGP Corporation)
4 RosettaStoneLtdController; "C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneLtdController.exe" [352312 2008-09-16] (Rosetta Stone Ltd.)
3 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2011-11-16] ()
4 WinVNC4; "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service [2357488 2010-12-01] (RealVNC Ltd)
2 SATARaid5 Config Service; "C:\Program Files\Silicon Image\3114-W-A64-R SATARAID5\SATARaid5ConfigService.exe" [x]
========================== Drivers (Whitelisted) =============
3 epmntdrv; \??\C:\Windows\system32\epmntdrv.sys [16776 2010-07-15] ()
3 EuGdiDrv; \??\C:\Windows\system32\EuGdiDrv.sys [9096 2010-07-15] ()
1 ISODrive; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.)
3 ivusb; C:\Windows\System32\Drivers\ivusb.sys [29720 2010-07-29] (Initio Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-15] ()
2 PGPdisk; C:\Windows\System32\Drivers\PGPdisk.sys [274552 2010-09-30] (PGP Corporation)
0 pgpfs; C:\Windows\System32\Drivers\PGPfsfd.sys [170104 2010-09-30] (PGP Corporation)
2 PGPsdkDriver; C:\Windows\System32\Drivers\PGPsdk.sys [50296 2010-09-30] (PGP Corporation)
0 PGPwded; C:\Windows\System32\Drivers\PGPwded.sys [363128 2010-09-30] (PGP Corporation)
0 Pgpwdefs; C:\Windows\System32\Drivers\Pgpwdefs.sys [14968 2010-09-30] (PGP Corporation)
0 Si3114r5; C:\Windows\System32\Drivers\Si3114r5.sys [327720 2008-04-29] (Silicon Image, Inc)
0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [22568 2008-04-29] (Silicon Image, Inc.)
0 SiRemFil; C:\Windows\System32\Drivers\SiRemFil.sys [16936 2008-04-29] (Silicon Image, Inc.)
1 sosadpdy; C:\Windows\System32\Drivers\sosadpdy.sys [50392 2012-07-28] (Microsoft Corporation)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2011-11-16] (Duplex Secure Ltd.)
1 zrdqjfer; C:\Windows\System32\Drivers\zrdqjfer.sys [50392 2012-07-28] (Microsoft Corporation)
3 ALSysIO; \??\C:\Users\Richard\AppData\Local\Temp\ALSysIO64.sys [x]
3 EMDMgmt; [x]
1 geyjgkth; \??\C:\Windows\system32\drivers\geyjgkth.sys [x]
3 RSUSBSTOR; C:\Windows\System32\Drivers\RTS5121.sys [x]
3 RTCore64; \??\D:\Program Files (x86)\MSI Afterburner\RTCore64.sys [x]
3 Rts516xIR; C:\Windows\System32\DRIVERS\Rts516xIR.sys [x]
3 USBCCID; C:\Windows\System32\DRIVERS\Rts5161ccid.sys [x]
3 VBoxNetFlt; C:\Windows\System32\DRIVERS\VBoxNetFlt.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-28 23:28 - 2012-07-28 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ACDE9A3D2C29E7DA
2012-07-28 23:28 - 2012-07-28 23:28 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tmwdvxkc.sys
2012-07-28 23:27 - 2012-07-28 23:27 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zrdqjfer.sys
2012-07-28 23:27 - 2012-07-28 23:27 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sosadpdy.sys
2012-07-28 23:26 - 2012-07-28 23:26 - 00000000 ____D C:\Windows\LastGood
2012-07-28 23:26 - 2011-09-01 22:30 - 00076056 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LEqdUsb.Sys
2012-07-28 23:24 - 2012-07-28 23:25 - 00000000 ____D C:\Users\Richard\AppData\Roaming\GetRightToGo
2012-07-28 23:24 - 2012-07-28 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6F1AE7CBA62CAC76
2012-07-28 23:20 - 2012-07-28 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1185453B8AFDDAA6
2012-07-28 23:17 - 2012-07-28 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.06031A55C35F4C8D
2012-07-28 23:14 - 2012-07-28 23:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AE23ACB6C99C92D
2012-07-28 23:10 - 2012-07-28 23:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41C24112DBFD222D
2012-07-28 23:06 - 2012-07-28 23:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66B08003D80E9238
2012-07-28 23:02 - 2012-07-28 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.12D4086389B0AFB0
2012-07-28 22:58 - 2012-07-28 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.047B8A2365EE8721
2012-07-28 22:54 - 2012-07-28 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDC6258772EC1F38
2012-07-28 22:51 - 2012-07-28 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.644D2E1B8D299F45
2012-07-28 22:48 - 2012-07-28 22:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-28 21:19 - 2012-07-28 21:19 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-27 23:33 - 2012-07-27 23:33 - 00001080 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-27 20:56 - 2011-07-25 16:44 - 00074752 ____A (Research In Motion Limited) C:\Windows\System32\Drivers\RimUsb_AMD64.sys
2012-07-22 18:20 - 2012-07-28 23:19 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-18 23:07 - 2012-07-18 23:07 - 00000632 _RASH C:\Users\Richard\ntuser.pol
2012-07-18 21:04 - 2011-11-23 08:31 - 00031744 ____A (Google Inc) C:\Windows\System32\Drivers\androidusb.sys
2012-07-18 02:00 - 2012-07-18 02:00 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2008
2012-07-18 02:00 - 2012-07-18 02:00 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2008
2012-07-17 18:15 - 2012-07-17 18:15 - 00062771 ____A C:\Windows\FontData.fdb
2012-07-17 18:14 - 2012-07-17 18:14 - 00000000 ____D C:\Users\Richard\Documents\My Palettes
2012-07-17 18:11 - 2012-07-17 18:11 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Corel
2012-07-17 18:11 - 2012-07-17 18:11 - 00000000 ____D C:\Users\All Users\Protexis
2012-07-17 18:09 - 2012-07-27 17:09 - 00000000 ____D C:\Users\Richard\Documents\Corel
2012-07-17 18:09 - 2012-07-17 18:09 - 00000000 ____D C:\Users\Richard\Documents\Visual Studio 2008
2012-07-17 18:08 - 2012-07-17 18:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0
2012-07-17 18:08 - 2012-07-17 18:08 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2012-07-17 18:07 - 2012-07-17 18:12 - 00000000 ____D C:\Users\All Users\Corel
2012-07-17 18:04 - 2012-07-17 18:04 - 00000000 ____D C:\Program Files (x86)\Corel
2012-07-16 22:40 - 2012-07-16 22:40 - 00000744 ____A C:\Users\Richard\Desktop\Core Temp.lnk
2012-07-15 19:09 - 2012-07-15 19:09 - 00001988 ____A C:\Users\UpdatusUser\Desktop\esb3.lnk
2012-07-15 19:09 - 2012-07-15 19:09 - 00001988 ____A C:\Users\Richard\Desktop\esb3.lnk
2012-07-15 19:09 - 2012-07-15 19:09 - 00000000 ____D C:\esb
2012-07-15 19:09 - 2003-01-08 01:01 - 00070656 ____A C:\Windows\SysWOW64\JReg.dll
2012-07-15 11:49 - 2012-07-15 11:49 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2012-07-15 11:48 - 2012-07-15 11:48 - 00000000 ____D C:\Windows\PCHEALTH
2012-07-15 11:48 - 2012-07-15 11:48 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2012-07-15 11:48 - 2012-07-15 11:48 - 00000000 ____D C:\Program Files\Microsoft Sync Framework
2012-07-15 11:48 - 2012-07-15 11:48 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2012-07-15 11:46 - 2012-07-15 11:46 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2012-07-15 11:46 - 2012-07-15 11:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2012-07-15 11:46 - 2012-07-15 11:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2012-07-15 11:45 - 2012-07-15 11:48 - 00000000 ____D C:\Program Files\Microsoft Office
2012-07-15 11:45 - 2012-07-15 11:45 - 00000000 __RHD C:\MSOCache
2012-07-15 11:10 - 2012-07-15 11:53 - 00151552 ____A C:\Windows\KMService.exe
2012-07-15 11:10 - 2012-07-15 11:53 - 00008192 ____A C:\Windows\SysWOW64\srvany.exe
2012-07-14 20:38 - 2012-07-14 20:38 - 00000010 ____A C:\ScrubRetValFile.txt
2012-07-14 15:01 - 2012-07-14 15:01 - 00000000 ___RD C:\Users\Richard\AppData\Roaming\Brother
2012-07-14 14:58 - 2012-07-14 14:58 - 00002174 ____A C:\Users\Public\Desktop\Brother Creative Center.lnk
2012-07-14 14:57 - 2012-07-14 14:57 - 00000000 ____D C:\Program Files (x86)\Browny02
2012-07-14 14:57 - 2012-07-14 14:57 - 00000000 ____D C:\Program Files (x86)\Brother
2012-07-14 14:57 - 2012-07-14 14:57 - 00000000 ____D C:\Brother
2012-07-14 14:57 - 2010-03-30 16:57 - 00217088 ____N (brother) C:\Windows\SysWOW64\NSSearch.dll
2012-07-14 14:57 - 2010-03-15 18:56 - 00002560 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2S.dll
2012-07-14 14:57 - 2010-03-15 18:45 - 00073728 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2.dll
2012-07-14 14:57 - 2010-02-05 10:42 - 00180224 ____N (Brother Industries, Ltd.) C:\Windows\SysWOW64\BroSNMP.dll
2012-07-14 14:57 - 2007-12-13 21:16 - 00005120 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2L.dll
2012-07-14 14:56 - 2012-07-14 14:58 - 00000000 ____D C:\Users\All Users\Brother
2012-07-14 02:04 - 2012-07-14 02:04 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2012-07-14 02:04 - 2012-07-14 02:04 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2012-07-13 19:55 - 2012-07-13 19:55 - 00000000 RASHD C:\Windows\kmsem
2012-07-12 02:04 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-12 02:00 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-12 02:00 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-12 02:00 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-12 02:00 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-12 02:00 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-12 02:00 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-12 02:00 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-12 02:00 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-12 02:00 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-12 02:00 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-12 02:00 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-12 02:00 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-12 02:00 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-12 02:00 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 02:00 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-12 02:00 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-12 02:00 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-12 02:00 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-12 02:00 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-12 02:00 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-12 02:00 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-12 02:00 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-12 02:00 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-12 02:00 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-12 02:00 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-12 02:00 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-12 02:00 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-12 02:00 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 20:26 - 2012-07-11 20:26 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2012-07-11 20:22 - 2012-07-11 20:22 - 00000000 ____D C:\Program Files\SAMSUNG
2012-07-11 20:20 - 2012-07-11 20:20 - 00000000 ____D C:\Users\All Users\Samsung
2012-07-11 19:41 - 2012-07-11 19:41 - 00038410 ____A C:\Users\Richard\AppData\Roaming\Comma Separated Values (Windows).ADR
2012-07-11 19:18 - 2012-07-27 20:57 - 00000308 ____A C:\Users\Richard\AppData\Roaming\Rim.Transcoder.Exception.log
2012-07-11 19:18 - 2012-07-11 20:21 - 00024261 ____A C:\ads_err.adt
2012-07-11 19:18 - 2012-07-11 19:19 - 00004559 ____A C:\ads_err.adm
2012-07-11 19:18 - 2012-07-11 19:19 - 00003072 ____A C:\ads_err.adi
2012-07-11 19:18 - 2012-07-11 19:18 - 00006499 ____A C:\ads_err.dbf
2012-07-11 19:18 - 2012-07-11 19:18 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-07-11 19:18 - 2012-07-11 19:18 - 00000000 ____D C:\Users\Richard\Documents\BlackBerry
2012-07-11 19:17 - 2012-07-27 20:57 - 00000308 ____A C:\Users\Richard\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-07-11 19:17 - 2012-07-15 14:05 - 00000231 ____A C:\Users\Richard\AppData\Roaming\Rim.Desktop.Exception.log
2012-07-11 19:17 - 2012-07-11 19:29 - 00000000 ____D C:\Users\Richard\AppData\Local\Research In Motion
2012-07-11 19:17 - 2012-07-11 19:18 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Research In Motion
2012-07-11 19:17 - 2012-07-11 19:17 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-07-11 19:17 - 2011-07-20 13:58 - 00044032 ____A (Research in Motion Ltd) C:\Windows\System32\Drivers\RimSerial_AMD64.sys
2012-07-11 19:16 - 2012-07-11 19:16 - 00002263 ____A C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2012-07-11 19:16 - 2012-07-11 19:16 - 00001153 ____A C:\Users\Richard\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-07-11 19:16 - 2012-07-11 19:16 - 00000000 ____D C:\Users\All Users\Research In Motion
2012-07-11 19:16 - 2012-07-11 19:16 - 00000000 ____D C:\Program Files (x86)\Research In Motion
2012-07-11 02:42 - 2012-06-08 21:23 - 14175232 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 02:42 - 2012-06-08 20:24 - 12874752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 02:42 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 02:42 - 2012-06-05 21:24 - 01879552 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 02:42 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 02:42 - 2012-06-05 20:25 - 01236480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 02:42 - 2012-06-03 23:55 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 02:42 - 2012-06-03 23:55 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 02:42 - 2012-06-03 23:54 - 01446400 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00029184 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll
2012-07-11 02:42 - 2012-06-03 23:53 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 02:42 - 2012-06-03 23:51 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe
2012-07-11 02:42 - 2012-06-01 20:55 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 02:42 - 2012-06-01 20:55 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 02:42 - 2012-06-01 20:54 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 02:42 - 2012-06-01 20:50 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 02:42 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-07-11 02:42 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-07-11 02:42 - 2012-04-23 21:22 - 01463296 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-07-11 02:42 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-07-11 02:42 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-07-11 02:42 - 2012-04-23 20:28 - 01159168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-07-11 02:41 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 02:41 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-08 10:36 - 2012-07-08 10:36 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-08 10:35 - 2012-07-08 10:36 - 00000000 ____D C:\Program Files\iTunes
2012-07-08 10:35 - 2012-07-08 10:35 - 00000000 ____D C:\Program Files\iPod
2012-07-08 10:31 - 2012-07-08 10:31 - 00001861 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-08 10:30 - 2012-07-08 10:31 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-07-05 22:45 - 2012-07-05 22:45 - 00000243 ____A C:\Users\Richard\AppData\Roaming\GPU Meter_Settings.ini
2012-07-05 22:43 - 2012-07-05 22:43 - 00000000 ____D C:\Users\All Users\Mozilla
2012-07-05 22:43 - 2012-07-05 22:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-07-03 20:15 - 2012-07-03 20:15 - 00000000 ____D C:\Users\Richard\AppData\Roaming\ArcSoft
2012-07-03 20:14 - 2012-07-03 20:14 - 00000945 ____A C:\Users\Public\Desktop\Panorama Maker 4 Pro.lnk
============ 3 Months Modified Files ========================
2012-07-28 23:28 - 2012-07-28 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ACDE9A3D2C29E7DA
2012-07-28 23:28 - 2012-07-28 23:28 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tmwdvxkc.sys
2012-07-28 23:27 - 2012-07-28 23:27 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zrdqjfer.sys
2012-07-28 23:27 - 2012-07-28 23:27 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sosadpdy.sys
2012-07-28 23:27 - 2012-06-03 09:27 - 00000266 ____A C:\Windows\Tasks\AutoKMS.job
2012-07-28 23:26 - 2011-11-16 19:57 - 00087444 ____A C:\Windows\setupact.log
2012-07-28 23:26 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-28 23:24 - 2012-07-28 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6F1AE7CBA62CAC76
2012-07-28 23:20 - 2012-07-28 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1185453B8AFDDAA6
2012-07-28 23:19 - 2012-07-22 18:20 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-28 23:17 - 2012-07-28 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.06031A55C35F4C8D
2012-07-28 23:16 - 2011-11-16 19:39 - 01750207 ____A C:\Windows\WindowsUpdate.log
2012-07-28 23:14 - 2012-07-28 23:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AE23ACB6C99C92D
2012-07-28 23:10 - 2012-07-28 23:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41C24112DBFD222D
2012-07-28 23:06 - 2012-07-28 23:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66B08003D80E9238
2012-07-28 23:02 - 2012-07-28 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.12D4086389B0AFB0
2012-07-28 22:58 - 2012-07-28 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.047B8A2365EE8721
2012-07-28 22:54 - 2012-07-28 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDC6258772EC1F38
2012-07-28 22:51 - 2012-07-28 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.644D2E1B8D299F45
2012-07-28 22:48 - 2011-11-24 19:39 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-28 22:48 - 2011-11-16 16:38 - 00812370 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-28 22:43 - 2009-07-13 20:45 - 00026576 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-28 22:43 - 2009-07-13 20:45 - 00026576 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-28 22:41 - 2009-07-13 21:13 - 00798712 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-28 22:37 - 2011-11-16 20:41 - 00504462 ____A C:\Windows\PFRO.log
2012-07-27 23:33 - 2012-07-27 23:33 - 00001080 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-27 20:57 - 2012-07-11 19:18 - 00000308 ____A C:\Users\Richard\AppData\Roaming\Rim.Transcoder.Exception.log
2012-07-27 20:57 - 2012-07-11 19:17 - 00000308 ____A C:\Users\Richard\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-07-27 01:18 - 2012-04-09 14:26 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-27 01:18 - 2011-11-25 17:20 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-22 18:20 - 2009-07-13 20:45 - 00436528 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 23:07 - 2012-07-18 23:07 - 00000632 _RASH C:\Users\Richard\ntuser.pol
2012-07-17 18:15 - 2012-07-17 18:15 - 00062771 ____A C:\Windows\FontData.fdb
2012-07-17 18:11 - 2011-11-16 16:46 - 00117968 ____A C:\Users\Richard\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-16 22:40 - 2012-07-16 22:40 - 00000744 ____A C:\Users\Richard\Desktop\Core Temp.lnk
2012-07-16 22:39 - 2011-12-09 22:35 - 00000412 ____A C:\Users\Richard\AppData\Roaming\All CPU Meter_Settings.ini
2012-07-16 22:39 - 2011-11-16 16:53 - 00007604 ____A C:\Users\Richard\AppData\Local\Resmon.ResmonCfg
2012-07-16 02:11 - 2009-07-13 18:34 - 00000487 ____A C:\Windows\win.ini
2012-07-15 19:09 - 2012-07-15 19:09 - 00001988 ____A C:\Users\UpdatusUser\Desktop\esb3.lnk
2012-07-15 19:09 - 2012-07-15 19:09 - 00001988 ____A C:\Users\Richard\Desktop\esb3.lnk
2012-07-15 14:05 - 2012-07-11 19:17 - 00000231 ____A C:\Users\Richard\AppData\Roaming\Rim.Desktop.Exception.log
2012-07-15 11:53 - 2012-07-15 11:10 - 00151552 ____A C:\Windows\KMService.exe
2012-07-15 11:53 - 2012-07-15 11:10 - 00008192 ____A C:\Windows\SysWOW64\srvany.exe
2012-07-14 20:38 - 2012-07-14 20:38 - 00000010 ____A C:\ScrubRetValFile.txt
2012-07-14 14:58 - 2012-07-14 14:58 - 00002174 ____A C:\Users\Public\Desktop\Brother Creative Center.lnk
2012-07-12 02:01 - 2011-11-16 16:42 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 20:26 - 2012-07-11 20:26 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2012-07-11 20:21 - 2012-07-11 19:18 - 00024261 ____A C:\ads_err.adt
2012-07-11 19:41 - 2012-07-11 19:41 - 00038410 ____A C:\Users\Richard\AppData\Roaming\Comma Separated Values (Windows).ADR
2012-07-11 19:19 - 2012-07-11 19:18 - 00004559 ____A C:\ads_err.adm
2012-07-11 19:19 - 2012-07-11 19:18 - 00003072 ____A C:\ads_err.adi
2012-07-11 19:18 - 2012-07-11 19:18 - 00006499 ____A C:\ads_err.dbf
2012-07-11 19:18 - 2012-07-11 19:18 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-07-11 19:17 - 2012-07-11 19:17 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-07-11 19:16 - 2012-07-11 19:16 - 00002263 ____A C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2012-07-11 19:16 - 2012-07-11 19:16 - 00001153 ____A C:\Users\Richard\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-07-08 10:36 - 2012-07-08 10:36 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-08 10:31 - 2012-07-08 10:31 - 00001861 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-08 10:29 - 2012-03-23 18:31 - 00002521 ____A C:\Users\Public\Desktop\Safari.lnk
2012-07-05 22:45 - 2012-07-05 22:45 - 00000243 ____A C:\Users\Richard\AppData\Roaming\GPU Meter_Settings.ini
2012-07-03 20:14 - 2012-07-03 20:14 - 00000945 ____A C:\Users\Public\Desktop\Panorama Maker 4 Pro.lnk
2012-06-16 12:16 - 2012-06-16 12:16 - 00000816 ____A C:\Users\Public\Desktop\On Target.lnk
2012-06-15 14:29 - 2012-06-15 14:29 - 00004608 ____A C:\Users\Richard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-13 19:41 - 2012-06-13 19:41 - 00000865 ____A C:\Users\Richard\Desktop\IrfanView Thumbnails.lnk
2012-06-13 19:41 - 2012-06-13 19:41 - 00000761 ____A C:\Users\Richard\Desktop\IrfanView.lnk
2012-06-11 19:08 - 2012-07-12 02:04 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:23 - 2012-07-11 02:42 - 14175232 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:24 - 2012-07-11 02:42 - 12874752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 23:15 - 2012-06-05 23:15 - 00000468 ____A C:\Users\Richard\Desktop\AcerIDs.txt
2012-06-05 22:06 - 2012-07-11 02:42 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:02 - 2012-07-11 02:41 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:24 - 2012-07-11 02:42 - 01879552 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:05 - 2012-07-11 02:42 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:03 - 2012-07-11 02:41 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 20:25 - 2012-07-11 02:42 - 01236480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 16:30 - 2012-05-15 15:52 - 00000043 ____A C:\Users\Richard\.lastsbk
2012-06-05 15:20 - 2012-06-05 15:20 - 00001427 ____A C:\Users\Public\Desktop\Applian FLV and Media Player.lnk
2012-06-05 15:19 - 2012-06-05 15:19 - 00031470 ____A C:\Users\Richard\AppData\Local\funmoods.crx
2012-06-03 23:55 - 2012-07-11 02:42 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-03 23:55 - 2012-07-11 02:42 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-03 23:54 - 2012-07-11 02:42 - 01446400 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00029184 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll
2012-06-03 23:53 - 2012-07-11 02:42 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-03 23:51 - 2012-07-11 02:42 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe
2012-06-03 09:23 - 2012-01-30 18:28 - 00001025 ____A C:\Users\Richard\Desktop\Dropbox.lnk
2012-06-02 14:19 - 2012-06-21 01:28 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 01:28 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 01:28 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 01:28 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 01:28 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 01:28 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 01:28 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 01:28 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 01:28 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-12 02:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-12 02:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-12 02:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-12 02:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-12 02:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-12 02:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-12 02:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-12 02:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-12 02:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-12 02:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-12 02:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-12 02:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-12 02:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-12 02:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-12 02:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-12 02:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-12 02:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-12 02:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-12 02:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 02:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-12 02:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-12 02:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 02:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 02:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-12 02:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-12 02:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 02:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 02:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 20:55 - 2012-07-11 02:42 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:55 - 2012-07-11 02:42 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:54 - 2012-07-11 02:42 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:50 - 2012-07-11 02:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 20:57 - 2012-01-23 21:00 - 00000708 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-05-26 08:11 - 2012-05-26 08:11 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2012-05-22 23:07 - 2012-05-22 23:07 - 00000899 ____A C:\Users\Richard\Desktop\FAHControl.lnk
2012-05-22 21:59 - 2009-07-13 21:08 - 00032628 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-14 16:41 - 2012-05-14 16:41 - 00035502 ____A C:\Users\Richard\Desktop\dmesg.txt
2012-05-11 06:34 - 2012-05-11 06:34 - 00203320 ____A (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudmdm.sys
2012-05-11 06:34 - 2012-05-11 06:34 - 00099384 ____A (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys
2012-05-04 03:06 - 2012-06-12 18:42 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 18:42 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 18:42 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
ZeroAccess:
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\@
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\L
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\n
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\U
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\L\00000004.@
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\L\201d3dde
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\U\00000008.@
ZeroAccess:
C:\Users\Richard\AppData\Local\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}
C:\Users\Richard\AppData\Local\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\@
C:\Users\Richard\AppData\Local\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\L
C:\Users\Richard\AppData\Local\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe
[2011-05-07 11:49] - [2011-05-07 11:49] - 0390656 ____A (Microsoft Corporation) BAEDB39886EB4BD51990EE2B7893E806
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 8190.15 MB
Available physical RAM: 7371.01 MB
Total Pagefile: 8188.35 MB
Available Pagefile: 7371.33 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:119.24 GB) (Free:83.86 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive e: (U2 Bootlegs Lossless 698GB) (Fixed) (Total:698.64 GB) (Free:138.12 GB) NTFS
3 Drive f: (WD 1500) (Fixed) (Total:1397.26 GB) (Free:1395.5 GB) NTFS
4 Drive g: (WD 1500 - Apps-Music-Pictures) (Fixed) (Total:1397.26 GB) (Free:716.57 GB) NTFS
5 Drive h: (Torrent 698GB) (Fixed) (Total:698.63 GB) (Free:25.02 GB) NTFS
6 Drive I: () (Fixed) (Total:465.76 GB) (Free:303.36 GB) NTFS
8 Drive k: (SANDISK 4GB) (Removable) (Total:3.83 GB) (Free:3.78 GB) NTFS
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
11 Drive y: (Install) (Fixed) (Total:465.75 GB) (Free:449.36 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 119 GB 0 B
Disk 2 Online 1397 GB 1024 KB
Disk 3 Online 1397 GB 1024 KB
Disk 4 Online 1397 GB 0 B
Disk 5 Online 3919 MB 0 B
Disk 6 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 31 KB
Partition 2 Primary 465 GB 465 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y Install NTFS Partition 465 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 I NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 119 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NTFS Partition 119 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 698 GB 31 KB
Partition 0 Extended 698 GB 698 GB
Partition 2 Logical 698 GB 698 GB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E U2 Bootlegs NTFS Partition 698 GB Healthy
==================================================================================
Disk: 2
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H Torrent 698 NTFS Partition 698 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1397 GB 31 KB
==================================================================================
Disk: 3
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 F WD 1500 NTFS Partition 1397 GB Healthy
==================================================================================
Partitions of Disk 4:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1397 GB 1024 KB
==================================================================================
Disk: 4
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 G WD 1500 - A NTFS Partition 1397 GB Healthy
==================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3919 MB 31 KB
==================================================================================
Disk: 5
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 K SANDISK 4GB NTFS Removable 3919 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 00:23
======================= End Of Log ==========================
Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01
Ran by SYSTEM at 30-07-2012 20:24:04
Running from K:\
Windows 7 Ultimate Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [EvtMgr6] D:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming [x]
HKLM\...\Run: [LogiScrollApp] C:\Program Files\Logitech\FlowScroll\KhalScroll.exe [166680 2012-02-08] (Logitech, Inc.)
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM-x32\...\Run: [vmware-tray] "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" [103536 2011-08-22] (VMware, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-05-30] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "D:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "D:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [x]
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe" [x]
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [90448 2011-11-02] (Research In Motion Limited)
HKLM-x32\...\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN [2621440 2010-06-10] (Brother Industries, Ltd.)
HKU\Richard\...\Run: [uTorrent] "D:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [737656 2012-02-21] (BitTorrent, Inc.)
HKU\Richard\...\Run: [RoboForm] "C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [107000 2011-11-24] (Siber Systems)
HKU\Richard\...\Run: [HFM.NET] "D:\Program Files (x86)\HFM.NET\HFM.exe" [x]
HKU\Richard\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.)
HKU\Richard\...\Policies\system: [LogonHoursAction] 2
HKU\Richard\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
IMEO\notepad.exe: [Debugger] "C:\Program Files\Notepad2\Notepad2.exe" /z
Lsa: [Notification Packages] scecli
PGPpwflt
Startup: C:\Users\All Users\Start Menu\Programs\Startup\PGPtray.exe.lnk
ShortcutTarget: PGPtray.exe.lnk -> C:\Windows\Installer\{E5A1684E-3F13-41EA-80C7-3B91FA51AE36}\Icon6560581611.exe ()
Startup: C:\Users\Richard\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> (No File)
Startup: C:\Users\Richard\Start Menu\Programs\Startup\FAHControl.lnk
ShortcutTarget: FAHControl.lnk -> C:\Program Files (x86)\FAHClient\FAHControl.exe (No File)
==================== Services (Whitelisted) ======
2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2012-07-15] ()
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NovacomD; C:\Program Files\Palm, Inc\novacomd\amd64\novacomd.exe [71168 2011-03-15] (Palm)
2 PGP RDD Service; C:\Program Files (x86)\PGP Corporation\PGP Desktop\RDDService.exe [166520 2010-09-30] (PGP Corporation)
2 PGPserv; C:\Windows\SysWOW64\PGPserv.exe [135288 2010-09-30] (PGP Corporation)
4 RosettaStoneLtdController; "C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneLtdController.exe" [352312 2008-09-16] (Rosetta Stone Ltd.)
3 VMwareHostd; "C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe" -u "C:\ProgramData\VMware\hostd\config.xml" [31995 2011-11-16] ()
4 WinVNC4; "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service [2357488 2010-12-01] (RealVNC Ltd)
2 SATARaid5 Config Service; "C:\Program Files\Silicon Image\3114-W-A64-R SATARAID5\SATARaid5ConfigService.exe" [x]
========================== Drivers (Whitelisted) =============
3 epmntdrv; \??\C:\Windows\system32\epmntdrv.sys [16776 2010-07-15] ()
3 EuGdiDrv; \??\C:\Windows\system32\EuGdiDrv.sys [9096 2010-07-15] ()
1 ISODrive; \??\C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.)
3 ivusb; C:\Windows\System32\Drivers\ivusb.sys [29720 2010-07-29] (Initio Corporation)
3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-15] ()
2 PGPdisk; C:\Windows\System32\Drivers\PGPdisk.sys [274552 2010-09-30] (PGP Corporation)
0 pgpfs; C:\Windows\System32\Drivers\PGPfsfd.sys [170104 2010-09-30] (PGP Corporation)
2 PGPsdkDriver; C:\Windows\System32\Drivers\PGPsdk.sys [50296 2010-09-30] (PGP Corporation)
0 PGPwded; C:\Windows\System32\Drivers\PGPwded.sys [363128 2010-09-30] (PGP Corporation)
0 Pgpwdefs; C:\Windows\System32\Drivers\Pgpwdefs.sys [14968 2010-09-30] (PGP Corporation)
0 Si3114r5; C:\Windows\System32\Drivers\Si3114r5.sys [327720 2008-04-29] (Silicon Image, Inc)
0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [22568 2008-04-29] (Silicon Image, Inc.)
0 SiRemFil; C:\Windows\System32\Drivers\SiRemFil.sys [16936 2008-04-29] (Silicon Image, Inc.)
1 sosadpdy; C:\Windows\System32\Drivers\sosadpdy.sys [50392 2012-07-28] (Microsoft Corporation)
0 sptd; C:\Windows\System32\Drivers\sptd.sys [526392 2011-11-16] (Duplex Secure Ltd.)
1 zrdqjfer; C:\Windows\System32\Drivers\zrdqjfer.sys [50392 2012-07-28] (Microsoft Corporation)
3 ALSysIO; \??\C:\Users\Richard\AppData\Local\Temp\ALSysIO64.sys [x]
3 EMDMgmt; [x]
1 geyjgkth; \??\C:\Windows\system32\drivers\geyjgkth.sys [x]
3 RSUSBSTOR; C:\Windows\System32\Drivers\RTS5121.sys [x]
3 RTCore64; \??\D:\Program Files (x86)\MSI Afterburner\RTCore64.sys [x]
3 Rts516xIR; C:\Windows\System32\DRIVERS\Rts516xIR.sys [x]
3 USBCCID; C:\Windows\System32\DRIVERS\Rts5161ccid.sys [x]
3 VBoxNetFlt; C:\Windows\System32\DRIVERS\VBoxNetFlt.sys [x]
3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x]
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-07-28 23:28 - 2012-07-28 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ACDE9A3D2C29E7DA
2012-07-28 23:28 - 2012-07-28 23:28 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tmwdvxkc.sys
2012-07-28 23:27 - 2012-07-28 23:27 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zrdqjfer.sys
2012-07-28 23:27 - 2012-07-28 23:27 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sosadpdy.sys
2012-07-28 23:26 - 2012-07-28 23:26 - 00000000 ____D C:\Windows\LastGood
2012-07-28 23:26 - 2011-09-01 22:30 - 00076056 ____A (Logitech, Inc.) C:\Windows\System32\Drivers\LEqdUsb.Sys
2012-07-28 23:24 - 2012-07-28 23:25 - 00000000 ____D C:\Users\Richard\AppData\Roaming\GetRightToGo
2012-07-28 23:24 - 2012-07-28 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6F1AE7CBA62CAC76
2012-07-28 23:20 - 2012-07-28 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1185453B8AFDDAA6
2012-07-28 23:17 - 2012-07-28 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.06031A55C35F4C8D
2012-07-28 23:14 - 2012-07-28 23:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AE23ACB6C99C92D
2012-07-28 23:10 - 2012-07-28 23:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41C24112DBFD222D
2012-07-28 23:06 - 2012-07-28 23:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66B08003D80E9238
2012-07-28 23:02 - 2012-07-28 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.12D4086389B0AFB0
2012-07-28 22:58 - 2012-07-28 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.047B8A2365EE8721
2012-07-28 22:54 - 2012-07-28 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDC6258772EC1F38
2012-07-28 22:51 - 2012-07-28 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.644D2E1B8D299F45
2012-07-28 22:48 - 2012-07-28 22:48 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-07-28 21:19 - 2012-07-28 21:19 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-07-27 23:33 - 2012-07-27 23:33 - 00001080 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-27 20:56 - 2011-07-25 16:44 - 00074752 ____A (Research In Motion Limited) C:\Windows\System32\Drivers\RimUsb_AMD64.sys
2012-07-22 18:20 - 2012-07-28 23:19 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-18 23:07 - 2012-07-18 23:07 - 00000632 _RASH C:\Users\Richard\ntuser.pol
2012-07-18 21:04 - 2011-11-23 08:31 - 00031744 ____A (Google Inc) C:\Windows\System32\Drivers\androidusb.sys
2012-07-18 02:00 - 2012-07-18 02:00 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2008
2012-07-18 02:00 - 2012-07-18 02:00 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2008
2012-07-17 18:15 - 2012-07-17 18:15 - 00062771 ____A C:\Windows\FontData.fdb
2012-07-17 18:14 - 2012-07-17 18:14 - 00000000 ____D C:\Users\Richard\Documents\My Palettes
2012-07-17 18:11 - 2012-07-17 18:11 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Corel
2012-07-17 18:11 - 2012-07-17 18:11 - 00000000 ____D C:\Users\All Users\Protexis
2012-07-17 18:09 - 2012-07-27 17:09 - 00000000 ____D C:\Users\Richard\Documents\Corel
2012-07-17 18:09 - 2012-07-17 18:09 - 00000000 ____D C:\Users\Richard\Documents\Visual Studio 2008
2012-07-17 18:08 - 2012-07-17 18:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 9.0
2012-07-17 18:08 - 2012-07-17 18:08 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2012-07-17 18:07 - 2012-07-17 18:12 - 00000000 ____D C:\Users\All Users\Corel
2012-07-17 18:04 - 2012-07-17 18:04 - 00000000 ____D C:\Program Files (x86)\Corel
2012-07-16 22:40 - 2012-07-16 22:40 - 00000744 ____A C:\Users\Richard\Desktop\Core Temp.lnk
2012-07-15 19:09 - 2012-07-15 19:09 - 00001988 ____A C:\Users\UpdatusUser\Desktop\esb3.lnk
2012-07-15 19:09 - 2012-07-15 19:09 - 00001988 ____A C:\Users\Richard\Desktop\esb3.lnk
2012-07-15 19:09 - 2012-07-15 19:09 - 00000000 ____D C:\esb
2012-07-15 19:09 - 2003-01-08 01:01 - 00070656 ____A C:\Windows\SysWOW64\JReg.dll
2012-07-15 11:49 - 2012-07-15 11:49 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2012-07-15 11:48 - 2012-07-15 11:48 - 00000000 ____D C:\Windows\PCHEALTH
2012-07-15 11:48 - 2012-07-15 11:48 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2012-07-15 11:48 - 2012-07-15 11:48 - 00000000 ____D C:\Program Files\Microsoft Sync Framework
2012-07-15 11:48 - 2012-07-15 11:48 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2012-07-15 11:46 - 2012-07-15 11:46 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2012-07-15 11:46 - 2012-07-15 11:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2012-07-15 11:46 - 2012-07-15 11:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2012-07-15 11:45 - 2012-07-15 11:48 - 00000000 ____D C:\Program Files\Microsoft Office
2012-07-15 11:45 - 2012-07-15 11:45 - 00000000 __RHD C:\MSOCache
2012-07-15 11:10 - 2012-07-15 11:53 - 00151552 ____A C:\Windows\KMService.exe
2012-07-15 11:10 - 2012-07-15 11:53 - 00008192 ____A C:\Windows\SysWOW64\srvany.exe
2012-07-14 20:38 - 2012-07-14 20:38 - 00000010 ____A C:\ScrubRetValFile.txt
2012-07-14 15:01 - 2012-07-14 15:01 - 00000000 ___RD C:\Users\Richard\AppData\Roaming\Brother
2012-07-14 14:58 - 2012-07-14 14:58 - 00002174 ____A C:\Users\Public\Desktop\Brother Creative Center.lnk
2012-07-14 14:57 - 2012-07-14 14:57 - 00000000 ____D C:\Program Files (x86)\Browny02
2012-07-14 14:57 - 2012-07-14 14:57 - 00000000 ____D C:\Program Files (x86)\Brother
2012-07-14 14:57 - 2012-07-14 14:57 - 00000000 ____D C:\Brother
2012-07-14 14:57 - 2010-03-30 16:57 - 00217088 ____N (brother) C:\Windows\SysWOW64\NSSearch.dll
2012-07-14 14:57 - 2010-03-15 18:56 - 00002560 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2S.dll
2012-07-14 14:57 - 2010-03-15 18:45 - 00073728 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2.dll
2012-07-14 14:57 - 2010-02-05 10:42 - 00180224 ____N (Brother Industries, Ltd.) C:\Windows\SysWOW64\BroSNMP.dll
2012-07-14 14:57 - 2007-12-13 21:16 - 00005120 ____N (Brother Industries Ltd.) C:\Windows\SysWOW64\BrDctF2L.dll
2012-07-14 14:56 - 2012-07-14 14:58 - 00000000 ____D C:\Users\All Users\Brother
2012-07-14 02:04 - 2012-07-14 02:04 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2012-07-14 02:04 - 2012-07-14 02:04 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2012-07-13 19:55 - 2012-07-13 19:55 - 00000000 RASHD C:\Windows\kmsem
2012-07-12 02:04 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-12 02:00 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-07-12 02:00 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-07-12 02:00 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-07-12 02:00 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-07-12 02:00 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-07-12 02:00 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-07-12 02:00 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-07-12 02:00 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-07-12 02:00 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-07-12 02:00 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-07-12 02:00 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-07-12 02:00 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-07-12 02:00 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-07-12 02:00 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-07-12 02:00 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-07-12 02:00 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-07-12 02:00 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-07-12 02:00 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-07-12 02:00 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-07-12 02:00 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-07-12 02:00 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-07-12 02:00 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-07-12 02:00 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-07-12 02:00 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-07-12 02:00 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-07-12 02:00 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-07-12 02:00 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-07-12 02:00 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-07-11 20:26 - 2012-07-11 20:26 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2012-07-11 20:22 - 2012-07-11 20:22 - 00000000 ____D C:\Program Files\SAMSUNG
2012-07-11 20:20 - 2012-07-11 20:20 - 00000000 ____D C:\Users\All Users\Samsung
2012-07-11 19:41 - 2012-07-11 19:41 - 00038410 ____A C:\Users\Richard\AppData\Roaming\Comma Separated Values (Windows).ADR
2012-07-11 19:18 - 2012-07-27 20:57 - 00000308 ____A C:\Users\Richard\AppData\Roaming\Rim.Transcoder.Exception.log
2012-07-11 19:18 - 2012-07-11 20:21 - 00024261 ____A C:\ads_err.adt
2012-07-11 19:18 - 2012-07-11 19:19 - 00004559 ____A C:\ads_err.adm
2012-07-11 19:18 - 2012-07-11 19:19 - 00003072 ____A C:\ads_err.adi
2012-07-11 19:18 - 2012-07-11 19:18 - 00006499 ____A C:\ads_err.dbf
2012-07-11 19:18 - 2012-07-11 19:18 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-07-11 19:18 - 2012-07-11 19:18 - 00000000 ____D C:\Users\Richard\Documents\BlackBerry
2012-07-11 19:17 - 2012-07-27 20:57 - 00000308 ____A C:\Users\Richard\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-07-11 19:17 - 2012-07-15 14:05 - 00000231 ____A C:\Users\Richard\AppData\Roaming\Rim.Desktop.Exception.log
2012-07-11 19:17 - 2012-07-11 19:29 - 00000000 ____D C:\Users\Richard\AppData\Local\Research In Motion
2012-07-11 19:17 - 2012-07-11 19:18 - 00000000 ____D C:\Users\Richard\AppData\Roaming\Research In Motion
2012-07-11 19:17 - 2012-07-11 19:17 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-07-11 19:17 - 2011-07-20 13:58 - 00044032 ____A (Research in Motion Ltd) C:\Windows\System32\Drivers\RimSerial_AMD64.sys
2012-07-11 19:16 - 2012-07-11 19:16 - 00002263 ____A C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2012-07-11 19:16 - 2012-07-11 19:16 - 00001153 ____A C:\Users\Richard\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-07-11 19:16 - 2012-07-11 19:16 - 00000000 ____D C:\Users\All Users\Research In Motion
2012-07-11 19:16 - 2012-07-11 19:16 - 00000000 ____D C:\Program Files (x86)\Research In Motion
2012-07-11 02:42 - 2012-06-08 21:23 - 14175232 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 02:42 - 2012-06-08 20:24 - 12874752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 02:42 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 02:42 - 2012-06-05 21:24 - 01879552 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 02:42 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 02:42 - 2012-06-05 20:25 - 01236480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 02:42 - 2012-06-03 23:55 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 02:42 - 2012-06-03 23:55 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 02:42 - 2012-06-03 23:54 - 01446400 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00029184 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2012-07-11 02:42 - 2012-06-03 23:54 - 00028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll
2012-07-11 02:42 - 2012-06-03 23:53 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 02:42 - 2012-06-03 23:51 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe
2012-07-11 02:42 - 2012-06-01 20:55 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 02:42 - 2012-06-01 20:55 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 02:42 - 2012-06-01 20:54 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 02:42 - 2012-06-01 20:50 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 02:42 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-07-11 02:42 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-07-11 02:42 - 2012-04-23 21:22 - 01463296 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-07-11 02:42 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-07-11 02:42 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-07-11 02:42 - 2012-04-23 20:28 - 01159168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-07-11 02:41 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 02:41 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-08 10:36 - 2012-07-08 10:36 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-08 10:35 - 2012-07-08 10:36 - 00000000 ____D C:\Program Files\iTunes
2012-07-08 10:35 - 2012-07-08 10:35 - 00000000 ____D C:\Program Files\iPod
2012-07-08 10:31 - 2012-07-08 10:31 - 00001861 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-08 10:30 - 2012-07-08 10:31 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-07-05 22:45 - 2012-07-05 22:45 - 00000243 ____A C:\Users\Richard\AppData\Roaming\GPU Meter_Settings.ini
2012-07-05 22:43 - 2012-07-05 22:43 - 00000000 ____D C:\Users\All Users\Mozilla
2012-07-05 22:43 - 2012-07-05 22:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-07-03 20:15 - 2012-07-03 20:15 - 00000000 ____D C:\Users\Richard\AppData\Roaming\ArcSoft
2012-07-03 20:14 - 2012-07-03 20:14 - 00000945 ____A C:\Users\Public\Desktop\Panorama Maker 4 Pro.lnk
============ 3 Months Modified Files ========================
2012-07-28 23:28 - 2012-07-28 23:28 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.ACDE9A3D2C29E7DA
2012-07-28 23:28 - 2012-07-28 23:28 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tmwdvxkc.sys
2012-07-28 23:27 - 2012-07-28 23:27 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\zrdqjfer.sys
2012-07-28 23:27 - 2012-07-28 23:27 - 00050392 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\sosadpdy.sys
2012-07-28 23:27 - 2012-06-03 09:27 - 00000266 ____A C:\Windows\Tasks\AutoKMS.job
2012-07-28 23:26 - 2011-11-16 19:57 - 00087444 ____A C:\Windows\setupact.log
2012-07-28 23:26 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-28 23:24 - 2012-07-28 23:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6F1AE7CBA62CAC76
2012-07-28 23:20 - 2012-07-28 23:20 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1185453B8AFDDAA6
2012-07-28 23:19 - 2012-07-22 18:20 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-07-28 23:17 - 2012-07-28 23:17 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.06031A55C35F4C8D
2012-07-28 23:16 - 2011-11-16 19:39 - 01750207 ____A C:\Windows\WindowsUpdate.log
2012-07-28 23:14 - 2012-07-28 23:14 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6AE23ACB6C99C92D
2012-07-28 23:10 - 2012-07-28 23:10 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.41C24112DBFD222D
2012-07-28 23:06 - 2012-07-28 23:06 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.66B08003D80E9238
2012-07-28 23:02 - 2012-07-28 23:02 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.12D4086389B0AFB0
2012-07-28 22:58 - 2012-07-28 22:58 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.047B8A2365EE8721
2012-07-28 22:54 - 2012-07-28 22:54 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CDC6258772EC1F38
2012-07-28 22:51 - 2012-07-28 22:51 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.644D2E1B8D299F45
2012-07-28 22:48 - 2011-11-24 19:39 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-28 22:48 - 2011-11-16 16:38 - 00812370 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-28 22:43 - 2009-07-13 20:45 - 00026576 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-28 22:43 - 2009-07-13 20:45 - 00026576 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-28 22:41 - 2009-07-13 21:13 - 00798712 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-28 22:37 - 2011-11-16 20:41 - 00504462 ____A C:\Windows\PFRO.log
2012-07-27 23:33 - 2012-07-27 23:33 - 00001080 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-07-27 20:57 - 2012-07-11 19:18 - 00000308 ____A C:\Users\Richard\AppData\Roaming\Rim.Transcoder.Exception.log
2012-07-27 20:57 - 2012-07-11 19:17 - 00000308 ____A C:\Users\Richard\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-07-27 01:18 - 2012-04-09 14:26 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-27 01:18 - 2011-11-25 17:20 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-22 18:20 - 2009-07-13 20:45 - 00436528 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-18 23:07 - 2012-07-18 23:07 - 00000632 _RASH C:\Users\Richard\ntuser.pol
2012-07-17 18:15 - 2012-07-17 18:15 - 00062771 ____A C:\Windows\FontData.fdb
2012-07-17 18:11 - 2011-11-16 16:46 - 00117968 ____A C:\Users\Richard\AppData\Local\GDIPFONTCACHEV1.DAT
2012-07-16 22:40 - 2012-07-16 22:40 - 00000744 ____A C:\Users\Richard\Desktop\Core Temp.lnk
2012-07-16 22:39 - 2011-12-09 22:35 - 00000412 ____A C:\Users\Richard\AppData\Roaming\All CPU Meter_Settings.ini
2012-07-16 22:39 - 2011-11-16 16:53 - 00007604 ____A C:\Users\Richard\AppData\Local\Resmon.ResmonCfg
2012-07-16 02:11 - 2009-07-13 18:34 - 00000487 ____A C:\Windows\win.ini
2012-07-15 19:09 - 2012-07-15 19:09 - 00001988 ____A C:\Users\UpdatusUser\Desktop\esb3.lnk
2012-07-15 19:09 - 2012-07-15 19:09 - 00001988 ____A C:\Users\Richard\Desktop\esb3.lnk
2012-07-15 14:05 - 2012-07-11 19:17 - 00000231 ____A C:\Users\Richard\AppData\Roaming\Rim.Desktop.Exception.log
2012-07-15 11:53 - 2012-07-15 11:10 - 00151552 ____A C:\Windows\KMService.exe
2012-07-15 11:53 - 2012-07-15 11:10 - 00008192 ____A C:\Windows\SysWOW64\srvany.exe
2012-07-14 20:38 - 2012-07-14 20:38 - 00000010 ____A C:\ScrubRetValFile.txt
2012-07-14 14:58 - 2012-07-14 14:58 - 00002174 ____A C:\Users\Public\Desktop\Brother Creative Center.lnk
2012-07-12 02:01 - 2011-11-16 16:42 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-07-11 20:26 - 2012-07-11 20:26 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_WinUsb_01007.Wdf
2012-07-11 20:21 - 2012-07-11 19:18 - 00024261 ____A C:\ads_err.adt
2012-07-11 19:41 - 2012-07-11 19:41 - 00038410 ____A C:\Users\Richard\AppData\Roaming\Comma Separated Values (Windows).ADR
2012-07-11 19:19 - 2012-07-11 19:18 - 00004559 ____A C:\ads_err.adm
2012-07-11 19:19 - 2012-07-11 19:18 - 00003072 ____A C:\ads_err.adi
2012-07-11 19:18 - 2012-07-11 19:18 - 00006499 ____A C:\ads_err.dbf
2012-07-11 19:18 - 2012-07-11 19:18 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2012-07-11 19:17 - 2012-07-11 19:17 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2012-07-11 19:16 - 2012-07-11 19:16 - 00002263 ____A C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2012-07-11 19:16 - 2012-07-11 19:16 - 00001153 ____A C:\Users\Richard\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-07-08 10:36 - 2012-07-08 10:36 - 00001628 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-07-08 10:31 - 2012-07-08 10:31 - 00001861 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-07-08 10:29 - 2012-03-23 18:31 - 00002521 ____A C:\Users\Public\Desktop\Safari.lnk
2012-07-05 22:45 - 2012-07-05 22:45 - 00000243 ____A C:\Users\Richard\AppData\Roaming\GPU Meter_Settings.ini
2012-07-03 20:14 - 2012-07-03 20:14 - 00000945 ____A C:\Users\Public\Desktop\Panorama Maker 4 Pro.lnk
2012-06-16 12:16 - 2012-06-16 12:16 - 00000816 ____A C:\Users\Public\Desktop\On Target.lnk
2012-06-15 14:29 - 2012-06-15 14:29 - 00004608 ____A C:\Users\Richard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-13 19:41 - 2012-06-13 19:41 - 00000865 ____A C:\Users\Richard\Desktop\IrfanView Thumbnails.lnk
2012-06-13 19:41 - 2012-06-13 19:41 - 00000761 ____A C:\Users\Richard\Desktop\IrfanView.lnk
2012-06-11 19:08 - 2012-07-12 02:04 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:23 - 2012-07-11 02:42 - 14175232 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:24 - 2012-07-11 02:42 - 12874752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 23:15 - 2012-06-05 23:15 - 00000468 ____A C:\Users\Richard\Desktop\AcerIDs.txt
2012-06-05 22:06 - 2012-07-11 02:42 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:02 - 2012-07-11 02:41 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:24 - 2012-07-11 02:42 - 01879552 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 21:05 - 2012-07-11 02:42 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:03 - 2012-07-11 02:41 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-05 20:25 - 2012-07-11 02:42 - 01236480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 16:30 - 2012-05-15 15:52 - 00000043 ____A C:\Users\Richard\.lastsbk
2012-06-05 15:20 - 2012-06-05 15:20 - 00001427 ____A C:\Users\Public\Desktop\Applian FLV and Media Player.lnk
2012-06-05 15:19 - 2012-06-05 15:19 - 00031470 ____A C:\Users\Richard\AppData\Local\funmoods.crx
2012-06-03 23:55 - 2012-07-11 02:42 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-03 23:55 - 2012-07-11 02:42 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-03 23:54 - 2012-07-11 02:42 - 01446400 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00029184 ____A (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2012-06-03 23:54 - 2012-07-11 02:42 - 00028160 ____A (Microsoft Corporation) C:\Windows\System32\secur32.dll
2012-06-03 23:53 - 2012-07-11 02:42 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-03 23:51 - 2012-07-11 02:42 - 00031232 ____A (Microsoft Corporation) C:\Windows\System32\lsass.exe
2012-06-03 09:23 - 2012-01-30 18:28 - 00001025 ____A C:\Users\Richard\Desktop\Dropbox.lnk
2012-06-02 14:19 - 2012-06-21 01:28 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 01:28 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 01:28 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 01:28 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 01:28 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 01:28 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 01:28 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 01:28 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 01:28 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-02 04:49 - 2012-07-12 02:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-02 04:17 - 2012-07-12 02:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-02 04:12 - 2012-07-12 02:00 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-02 04:05 - 2012-07-12 02:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-02 04:05 - 2012-07-12 02:00 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-02 04:04 - 2012-07-12 02:00 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-02 04:04 - 2012-07-12 02:00 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-02 04:03 - 2012-07-12 02:00 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-02 04:01 - 2012-07-12 02:00 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-02 04:00 - 2012-07-12 02:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-02 03:59 - 2012-07-12 02:00 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-02 03:57 - 2012-07-12 02:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-02 03:57 - 2012-07-12 02:00 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-02 03:54 - 2012-07-12 02:00 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-02 01:07 - 2012-07-12 02:00 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-02 00:43 - 2012-07-12 02:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-02 00:33 - 2012-07-12 02:00 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-02 00:26 - 2012-07-12 02:00 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-02 00:25 - 2012-07-12 02:00 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-02 00:25 - 2012-07-12 02:00 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-02 00:23 - 2012-07-12 02:00 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-02 00:21 - 2012-07-12 02:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-02 00:20 - 2012-07-12 02:00 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-02 00:19 - 2012-07-12 02:00 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-02 00:19 - 2012-07-12 02:00 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-02 00:17 - 2012-07-12 02:00 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-02 00:16 - 2012-07-12 02:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-02 00:14 - 2012-07-12 02:00 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-01 20:55 - 2012-07-11 02:42 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:55 - 2012-07-11 02:42 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:54 - 2012-07-11 02:42 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:50 - 2012-07-11 02:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-31 20:57 - 2012-01-23 21:00 - 00000708 ____A C:\Users\Public\Desktop\µTorrent.lnk
2012-05-26 08:11 - 2012-05-26 08:11 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2012-05-22 23:07 - 2012-05-22 23:07 - 00000899 ____A C:\Users\Richard\Desktop\FAHControl.lnk
2012-05-22 21:59 - 2009-07-13 21:08 - 00032628 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-14 16:41 - 2012-05-14 16:41 - 00035502 ____A C:\Users\Richard\Desktop\dmesg.txt
2012-05-11 06:34 - 2012-05-11 06:34 - 00203320 ____A (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudmdm.sys
2012-05-11 06:34 - 2012-05-11 06:34 - 00099384 ____A (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\System32\Drivers\ssudbus.sys
2012-05-04 03:06 - 2012-06-12 18:42 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 18:42 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-12 18:42 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
ZeroAccess:
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\@
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\L
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\n
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\U
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\L\00000004.@
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\L\201d3dde
C:\Windows\Installer\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\U\00000008.@
ZeroAccess:
C:\Users\Richard\AppData\Local\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}
C:\Users\Richard\AppData\Local\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\@
C:\Users\Richard\AppData\Local\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\L
C:\Users\Richard\AppData\Local\{1883cae5-8220-c03c-00e3-c0024c7fb4b4}\U
ZeroAccess:
C:\Windows\assembly\GAC_32\Desktop.ini
ZeroAccess:
C:\Windows\assembly\GAC_64\Desktop.ini
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe
[2011-05-07 11:49] - [2011-05-07 11:49] - 0390656 ____A (Microsoft Corporation) BAEDB39886EB4BD51990EE2B7893E806
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 10%
Total physical RAM: 8190.15 MB
Available physical RAM: 7371.01 MB
Total Pagefile: 8188.35 MB
Available Pagefile: 7371.33 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:119.24 GB) (Free:83.86 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive e: (U2 Bootlegs Lossless 698GB) (Fixed) (Total:698.64 GB) (Free:138.12 GB) NTFS
3 Drive f: (WD 1500) (Fixed) (Total:1397.26 GB) (Free:1395.5 GB) NTFS
4 Drive g: (WD 1500 - Apps-Music-Pictures) (Fixed) (Total:1397.26 GB) (Free:716.57 GB) NTFS
5 Drive h: (Torrent 698GB) (Fixed) (Total:698.63 GB) (Free:25.02 GB) NTFS
6 Drive I: () (Fixed) (Total:465.76 GB) (Free:303.36 GB) NTFS
8 Drive k: (SANDISK 4GB) (Removable) (Total:3.83 GB) (Free:3.78 GB) NTFS
10 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
11 Drive y: (Install) (Fixed) (Total:465.75 GB) (Free:449.36 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 119 GB 0 B
Disk 2 Online 1397 GB 1024 KB
Disk 3 Online 1397 GB 1024 KB
Disk 4 Online 1397 GB 0 B
Disk 5 Online 3919 MB 0 B
Disk 6 No Media 0 B 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 465 GB 31 KB
Partition 2 Primary 465 GB 465 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y Install NTFS Partition 465 GB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 I NTFS Partition 465 GB Healthy
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 119 GB 1024 KB
==================================================================================
Disk: 1
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 C NTFS Partition 119 GB Healthy
==================================================================================
Partitions of Disk 2:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 698 GB 31 KB
Partition 0 Extended 698 GB 698 GB
Partition 2 Logical 698 GB 698 GB
==================================================================================
Disk: 2
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 E U2 Bootlegs NTFS Partition 698 GB Healthy
==================================================================================
Disk: 2
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H Torrent 698 NTFS Partition 698 GB Healthy
==================================================================================
Partitions of Disk 3:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1397 GB 31 KB
==================================================================================
Disk: 3
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 6 F WD 1500 NTFS Partition 1397 GB Healthy
==================================================================================
Partitions of Disk 4:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1397 GB 1024 KB
==================================================================================
Disk: 4
Partition 1
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 7 G WD 1500 - A NTFS Partition 1397 GB Healthy
==================================================================================
Partitions of Disk 5:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3919 MB 31 KB
==================================================================================
Disk: 5
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 8 K SANDISK 4GB NTFS Removable 3919 MB Healthy
==================================================================================
==========================================================
Last Boot: 2012-07-28 00:23
======================= End Of Log ==========================
