1. Thanks so much for helping me out with this ST, much appreciated.
2. FRST log:
Scan result of Farbar Recovery Scan Tool Version: 11-05-2012
Ran by SYSTEM at 11-05-2012 13:05:42
Running from E:\
Windows Vista Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1657128 2008-11-11] (Synaptics, Inc.)
HKLM\...\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe [2041112 2008-09-26] (Dell Inc.)
HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [15871520 2009-04-28] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [82464 2009-04-28] (NVIDIA Corporation)
HKLM\...\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe [4119552 2008-12-21] (Dell Inc.)
HKLM\...\Run: [RunDLLEntry] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry [17920 2008-12-17] (Creative Technology Ltd.)
HKLM\...\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2304904 2009-01-07] (Microsoft Corporation)
HKLM\...\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray64.exe [462848 2009-03-29] (IDT, Inc.)
HKLM-x32\...\Run: [VolPanel] "C:\Program Files (x86)\Creative\SB X-Fi MB\Volume Panel\VolPanlu.exe" /r [237693 2008-12-09] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] C:\Windows\UpdReg.EXE [90112 2000-05-10] (Creative Technology Ltd.)
HKLM-x32\...\Run: [FAStartup] [x]
HKLM-x32\...\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [250192 2009-04-24] (Microsoft Corporation)
HKLM-x32\...\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.)
HKLM-x32\...\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe" [479232 2005-07-15] (Google Inc.)
HKLM-x32\...\Run: [FATrayAlert] C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe [95560 2010-04-04] (Sensible Vision )
HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-03-06] (Apple Inc.)
HKLM-x32\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4241512 2012-03-06] (AVAST Software)
HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKU\xxx\...\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme [x]
HKU\xxx\...\Run: [Facebook Update] "C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver [137536 2011-10-19] (Facebook Inc.)
HKU\xxx\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [3872080 2010-04-16] (Microsoft Corporation)
HKU\xxx\...\Winlogon: [Shell] EXPLORER.EXE
HKU\RA Media Server\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-10] (Microsoft Corporation)
HKLM-x32\...\Runonce: [AvgUninstallURL] cmd.exe /c start
http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAWgBZAEYAOAAtAEMASwA3AFEARwAtADkAVQBCAFUAUgAtADcAUwBVAEwAUwAtADQANABLAFIAMgA"&"inst=NwA3AC0ANAAxADIAOQAxADMAMgAzADgALQBYAEwAKwAxAC0AVAA1AC0ARgBQADkAMgArADYALQBOADEARgArADEALQBCAEEAUgA5AEcAKwAxAC0AVABCADkAKwAyAC0ARgBMACsAOQAtAFgATwAzADYAKwAxAC0ARgA5AE0AMQAwAEIAKwAyAC0AWABPADkAKwAxAC0ARgA5AE0AMgArADEALQBEAEQAVAArADUAMwAwADAAMAAtAEQARAA5ADAARgArADEALQBTAFQAOQAwAEYAQQBQAFAAKwAxAC0ARgA5ADAATQAxADIARABUACsAMQAtAFQAQgBOACsAMQAtAFUAOQA1ACsAMQAtAEYAVQBJACsAMgA"&"prod=90"&"ver=9.0.894 [x]
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X]
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Lsa: [Notification Packages] scecli
FAPassSync
SubSystems: [Windows] ATTENTION! ====> ZeroAccess
==================== Services (Whitelisted) ======
2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe [89600 2009-03-29] (Andrea Electronics Corporation)
2 Apache2.2; "C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe" -k runservice [15872 2007-09-21] (Apache Software Foundation)
2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [44768 2012-03-06] (AVAST Software)
2 btwdins; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [795176 2008-06-05] (Broadcom Corporation.)
2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [307200 2009-02-04] (Creative Technology Ltd)
4 dlcg_device; C:\Windows\system32\dlcgcoms.exe -service [566152 2006-12-07] ( )
4 dlcg_device; C:\Windows\SysWow64\dlcgcoms.exe -service [537480 2006-12-07] ( )
4 dsl-db; "C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe" "--defaults-file=C:\Program Files (x86)\Common Files\Dell\MySQL\my.ini" dsl-db [9560 2009-12-12] ()
4 dsl-fs-sync; "C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe" [189680 2009-04-13] (SingleClick Systems)
2 gupdate1ca2388b140f870; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [133104 2009-08-22] (Google Inc.)
3 IDriverT; "C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" [69632 2005-11-13] (Macrovision Corporation)
4 LicCtrlService; C:\Windows\runservice.exe [2560 2009-11-02] ()
3 Microsoft Office Groove Audit Service; "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe" [64856 2009-02-26] (Microsoft Corporation)
3 p2pimsvc; C:\Windows\SysWow64\p2psvc.dll [644608 2009-04-10] (Microsoft Corporation)
3 p2psvc; C:\Windows\SysWow64\p2psvc.dll [644608 2009-04-10] (Microsoft Corporation)
3 PNRPAutoReg; C:\Windows\SysWow64\p2psvc.dll [644608 2009-04-10] (Microsoft Corporation)
3 PNRPsvc; C:\Windows\SysWow64\p2psvc.dll [644608 2009-04-10] (Microsoft Corporation)
2 rpcnet; C:\Windows\SysWOW64\rpcnet.exe [58288 2012-04-12] (Absolute Software Corp.)
3 SCardSvr; C:\Windows\SysWow64\SCardSvr.dll [95232 2009-04-10] (Microsoft Corporation)
2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe [268288 2009-03-29] (IDT, Inc.)
2 Themes; C:\Windows\SysWow64\shsvcs.dll [247808 2009-07-10] (Microsoft Corporation)
2 vvdsvc; C:\Windows\SysWow64\Nagasoft\vjocx.dll [1695368 2009-09-23] (NanJing Nagasoft Co, LTD.)
2 wltrysvc; C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe [3051520 2008-12-21] (Dell Inc.)
4 hnmsvc; "c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe" [x]
========================== Drivers (Whitelisted) =============
2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [24408 2012-03-06] (AVAST Software)
2 aswMonFlt; C:\Windows\System32\Drivers\aswMonFlt.sys [69976 2012-03-06] (AVAST Software)
1 AswRdr; C:\Windows\System32\Drivers\AswRdr.sys [43864 2012-03-06] (AVAST Software)
1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [819032 2012-03-06] (AVAST Software)
1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [337240 2012-03-06] (AVAST Software)
1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [59224 2012-03-06] (AVAST Software)
3 itecir; C:\Windows\System32\Drivers\itecir.sys [67104 2010-03-08] (ITE Tech. Inc. )
3 NVENETFD; C:\Windows\System32\DRIVERS\nvmfdx64.sys [1495456 2008-10-26] (NVIDIA Corporation)
3 nvsmu; C:\Windows\System32\Drivers\nvsmu.sys [28192 2009-03-17] (NVIDIA Corporation)
0 nvstor64; C:\Windows\System32\Drivers\nvstor64.sys [170528 2009-03-17] (NVIDIA Corporation)
3 OA001Ufd; C:\Windows\System32\Drivers\OA001Ufd.sys [159840 2009-03-06] (Creative Technology Ltd.)
3 OA001Vid; C:\Windows\System32\Drivers\OA001Vid.sys [319840 2009-03-08] (Creative Technology Ltd.)
2 Packet; C:\Windows\System32\Drivers\Packet.sys [29184 2008-06-18] (SingleClick Systems)
2 Packet; C:\Windows\SysWow64\Drivers\Packet.sys [22016 2008-06-17] (SingleClick Systems)
3 Point64; C:\Windows\System32\DRIVERS\point64k.sys [33160 2008-12-19] (Microsoft Corporation)
3 R300; C:\Windows\System32\DRIVERS\atikmdag.sys [2488320 2006-11-01] (ATI Technologies Inc.)
1 SASDIFSV; \??\C:\Program Files (x86)\SUPERAntiSpyware\SASDIFSV.SYS [12872 2010-02-17] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 SASENUM; \??\C:\Program Files (x86)\SUPERAntiSpyware\SASENUM.SYS [12872 2010-02-17] ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS [66632 2010-02-17] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
3 SRS_SSCFilter; C:\Windows\System32\drivers\srs_sscfilter_amd64.sys [55040 2007-07-26] ()
3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x]
3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x]
3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x]
========================== NetSvcs (Whitelisted) ===========
NETSVC: atmeltpm
NETSVCx32: Themes
============ One Month Created Files and Folders ==============
2012-05-10 11:24 - 2012-05-10 11:32 - 0002502 ____A C:\Users\xxx\Desktop\avastlog2.txt
2012-05-10 11:24 - 2012-05-10 11:24 - 0000512 ____A C:\Users\xxx\Desktop\MBR.dat
2012-05-10 10:26 - 2012-05-10 11:32 - 0000914 ____A C:\Users\xxx\Desktop\ESETSCAN.txt
2012-05-09 20:25 - 2012-05-09 20:25 - 2322184 ____A (ESET) C:\Users\xxx\Downloads\esetsmartinstaller_enu.exe
2012-05-09 20:25 - 2012-05-09 20:25 - 0000000 ____D C:\Program Files (x86)\ESET
2012-05-09 20:15 - 2012-05-09 20:29 - 0002293 ____A C:\Users\xxx\My Documents\aswMBR.txt
2012-05-09 20:15 - 2012-05-09 20:29 - 0002293 ____A C:\Users\xxx\Documents\aswMBR.txt
2012-05-09 20:15 - 2012-05-09 20:15 - 0000512 ____A C:\Users\xxx\My Documents\MBR.dat
2012-05-09 20:15 - 2012-05-09 20:15 - 0000512 ____A C:\Users\xxx\Documents\MBR.dat
2012-05-09 19:24 - 2012-05-09 19:24 - 4731392 ____A (AVAST Software) C:\Users\xxx\Downloads\aswMBR.exe
2012-05-09 18:42 - 2012-05-09 18:42 - 2055783 ____A C:\Users\xxx\Downloads\tdsskiller.zip
2012-05-09 10:19 - 2012-05-09 10:19 - 0572494 ____A C:\Users\xxx\Local Settings\dd_vcredistMSI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0572494 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistMSI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0572494 ____A C:\Users\xxx\AppData\Local\dd_vcredistMSI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0012384 ____A C:\Users\xxx\Local Settings\dd_vcredistUI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0012384 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistUI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0012384 ____A C:\Users\xxx\AppData\Local\dd_vcredistUI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0001787 ____A C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2012-05-09 10:19 - 2012-05-09 10:19 - 0001787 ____A C:\Users\All Users\Desktop\avast! Free Antivirus.lnk
2012-05-09 10:19 - 2012-05-09 10:19 - 0000000 ____A C:\Windows\SysWOW64\config.nt
2012-05-09 10:19 - 2012-03-06 15:15 - 0258520 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2012-05-09 10:19 - 2012-03-06 15:04 - 0819032 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2012-05-09 10:19 - 2012-03-06 15:04 - 0337240 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2012-05-09 10:19 - 2012-03-06 15:02 - 0043864 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr.sys
2012-05-09 10:19 - 2012-03-06 15:01 - 0069976 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2012-05-09 10:19 - 2012-03-06 15:01 - 0059224 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2012-05-09 10:19 - 2012-03-06 15:01 - 0024408 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2012-05-09 10:18 - 2012-03-06 15:15 - 0201352 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
2012-05-09 10:18 - 2012-03-06 15:15 - 0041184 ____A (AVAST Software) C:\Windows\avastSS.scr
2012-05-09 10:04 - 2012-05-09 10:05 - 0618278 ____A C:\Windows\dd_vcredistMSI7D83.txt
2012-05-09 10:04 - 2012-05-09 10:05 - 0012360 ____A C:\Windows\dd_vcredistUI7D83.txt
2012-05-08 21:04 - 2012-05-08 21:05 - 0574200 ____A C:\Users\xxx\Local Settings\dd_vcredistMSI288C.txt
2012-05-08 21:04 - 2012-05-08 21:05 - 0574200 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistMSI288C.txt
2012-05-08 21:04 - 2012-05-08 21:05 - 0574200 ____A C:\Users\xxx\AppData\Local\dd_vcredistMSI288C.txt
2012-05-08 21:04 - 2012-05-08 21:05 - 0012460 ____A C:\Users\xxx\Local Settings\dd_vcredistUI288C.txt
2012-05-08 21:04 - 2012-05-08 21:05 - 0012460 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistUI288C.txt
2012-05-08 21:04 - 2012-05-08 21:05 - 0012460 ____A C:\Users\xxx\AppData\Local\dd_vcredistUI288C.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0572890 ____A C:\Users\xxx\Local Settings\dd_vcredistMSI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0572890 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistMSI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0572890 ____A C:\Users\xxx\AppData\Local\dd_vcredistMSI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0012400 ____A C:\Users\xxx\Local Settings\dd_vcredistUI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0012400 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistUI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0012400 ____A C:\Users\xxx\AppData\Local\dd_vcredistUI24F3.txt
2012-05-08 15:24 - 2012-05-09 10:18 - 0000000 ____D C:\Users\All Users\AVAST Software
2012-05-08 15:24 - 2012-05-09 10:18 - 0000000 ____D C:\Users\All Users\Application Data\AVAST Software
2012-05-08 15:24 - 2012-05-09 10:18 - 0000000 ____D C:\ProgramData\AVAST Software
2012-05-08 15:24 - 2012-05-09 10:18 - 0000000 ____D C:\Program Files\AVAST Software
2012-05-08 15:22 - 2012-05-08 15:23 - 74761776 ____A C:\Users\xxx\Downloads\avast_free_antivirus_setup.exe
2012-05-08 15:18 - 2012-05-08 15:18 - 3877872 ____A (AVG Technologies) C:\Users\xxx\Downloads\avg_free_stb_all_2012_2171_cnet.exe
2012-05-08 08:42 - 2012-05-09 19:00 - 0000342 ____A C:\Windows\Tasks\At48.job
2012-05-08 08:42 - 2012-05-09 18:00 - 0000342 ____A C:\Windows\Tasks\At47.job
2012-05-08 08:42 - 2012-05-09 17:00 - 0000342 ____A C:\Windows\Tasks\At46.job
2012-05-08 08:42 - 2012-05-09 16:00 - 0000342 ____A C:\Windows\Tasks\At45.job
2012-05-08 08:42 - 2012-05-09 15:00 - 0000342 ____A C:\Windows\Tasks\At44.job
2012-05-08 08:42 - 2012-05-09 14:00 - 0000342 ____A C:\Windows\Tasks\At43.job
2012-05-08 08:42 - 2012-05-09 13:00 - 0000342 ____A C:\Windows\Tasks\At42.job
2012-05-08 08:42 - 2012-05-09 12:00 - 0000342 ____A C:\Windows\Tasks\At41.job
2012-05-08 08:42 - 2012-05-09 11:00 - 0000342 ____A C:\Windows\Tasks\At40.job
2012-05-08 08:42 - 2012-05-09 10:00 - 0000342 ____A C:\Windows\Tasks\At39.job
2012-05-08 08:42 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At37.job
2012-05-08 08:42 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At36.job
2012-05-08 08:42 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At35.job
2012-05-08 08:42 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At34.job
2012-05-08 08:42 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At33.job
2012-05-08 08:42 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At32.job
2012-05-08 08:42 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At31.job
2012-05-08 08:42 - 2012-05-08 09:03 - 0000342 ____A C:\Windows\Tasks\At38.job
2012-05-08 08:41 - 2012-05-09 23:00 - 0000342 ____A C:\Windows\Tasks\At28.job
2012-05-08 08:41 - 2012-05-09 22:00 - 0000342 ____A C:\Windows\Tasks\At27.job
2012-05-08 08:41 - 2012-05-09 21:00 - 0000342 ____A C:\Windows\Tasks\At26.job
2012-05-08 08:41 - 2012-05-09 20:34 - 0000342 ____A C:\Windows\Tasks\At25.job
2012-05-08 08:41 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At30.job
2012-05-08 08:41 - 2012-05-08 12:20 - 0000342 ____A C:\Windows\Tasks\At29.job
2012-05-08 08:31 - 2012-05-08 08:31 - 0000000 __ASH C:\Windows\System32\dds_trash_log.cmd
2012-05-07 08:12 - 2012-05-07 08:12 - 0000387 ____A C:\Users\xxx\Downloads\temp_file-[The.Big.Bang.Theory.S05E22.480p.HDTV.x264-mSD.mkv][vidhog].xspf
2012-05-06 18:43 - 2012-05-06 18:42 - 0000299 ____A C:\Users\xxx\Downloads\temp_file-[video.avi][sharebees].xspf
2012-05-06 18:40 - 2012-05-06 18:39 - 0000370 ____A C:\Users\xxx\Downloads\temp_file-[ice-This.Means.War.2012.DVDRip.x264-scOrp.mkv][180upload].xspf
2012-05-06 18:39 - 2012-05-06 18:39 - 0000330 ____A C:\Users\xxx\Downloads\temp_file-[This.Means.War.2012._.x264-scOrp.mkv][movreel].xspf
2012-05-06 18:38 - 2012-05-06 18:38 - 0000242 ____A C:\Users\xxx\Downloads\temp_file-[zpakn1m6wjwa][jumbofiles].xspf
2012-05-06 14:02 - 2012-05-06 14:02 - 0000241 ____A C:\Users\xxx\Downloads\temp_file-[m17fi6wibmjc][uploadorb].xspf
2012-05-04 23:04 - 2012-05-04 23:04 - 0619860 ____A C:\Windows\dd_vcredistMSI4BA5.txt
2012-05-04 23:04 - 2012-05-04 23:04 - 0013388 ____A C:\Windows\dd_vcredistUI4BA5.txt
2012-05-03 23:02 - 2012-05-03 23:02 - 0619562 ____A C:\Windows\dd_vcredistMSI7BDE.txt
2012-05-03 23:02 - 2012-05-03 23:02 - 0012420 ____A C:\Windows\dd_vcredistUI7BDE.txt
2012-05-01 16:39 - 2012-05-01 18:40 - 0000000 ____D C:\Users\xxx\Downloads\Mad.Men.S04.BDRip.XviD-REWARD
2012-05-01 16:38 - 2012-05-01 16:38 - 0012734 ____A C:\Users\xxx\Downloads\Mad_Men_Season_4_HDTV_+-Demonoid.me-+_8697461.222.torrent
2012-05-01 16:37 - 2012-05-01 16:36 - 0012934 ____A C:\Users\xxx\Downloads\Mad_Men_Season_4_Complete_BDrip_Reward-_=Demonoid.me=__8697461.222.torrent
2012-05-01 13:09 - 2012-05-01 15:36 - 0000000 ____D C:\Users\xxx\Downloads\Mad Men S03 DVDrip-Reward
2012-05-01 13:05 - 2012-05-01 13:05 - 0038622 ____A C:\Users\xxx\Downloads\Mad_Men_Season_3_Complete_DVD_Rip_-Demonoid.me-__8697461.222.torrent
2012-05-01 13:04 - 2012-05-01 13:04 - 0024070 ____A C:\Users\xxx\Downloads\-_Demonoid.me_-Mad_Men_Season_3_Complete_DVDrip_Reward_8697461.222.torrent
2012-05-01 05:03 - 2012-05-01 05:03 - 0618364 ____A C:\Windows\dd_vcredistMSI25D1.txt
2012-05-01 05:03 - 2012-05-01 05:03 - 0012372 ____A C:\Windows\dd_vcredistUI25D1.txt
2012-04-29 21:16 - 2012-04-29 21:16 - 0000353 ____A C:\Users\xxx\Downloads\temp_file-[mad.men.s02e01.dvdrip.xvid-reward.avi].xspf
2012-04-29 20:40 - 2012-04-29 20:42 - 3175832 ____A (Microsoft Corporation) C:\Users\xxx\Desktop\vcredist_x64.EXE
2012-04-29 20:16 - 2012-04-29 20:16 - 0001696 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-04-29 20:16 - 2012-04-29 20:16 - 0001696 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-04-29 20:15 - 2012-04-29 20:16 - 0000000 ____D C:\Program Files\iTunes
2012-04-29 20:15 - 2012-04-29 20:16 - 0000000 ____D C:\Program Files (x86)\iTunes
2012-04-29 20:15 - 2012-04-29 20:15 - 0000000 ____D C:\Program Files\iPod
2012-04-29 20:04 - 2012-04-29 20:05 - 76763504 ____A (Apple Inc.) C:\Users\xxx\Downloads\iTunes64Setup.exe
2012-04-29 19:48 - 2012-04-29 22:46 - 0000000 ____D C:\Users\xxx\Downloads\Mad Men - Season 2 - Complete
2012-04-29 19:45 - 2012-04-29 19:44 - 0023929 ____A C:\Users\xxx\Downloads\Mad_Men_Season_2_Complete-(Demonoid.me)_8697461.222.torrent
2012-04-28 23:03 - 2012-04-28 23:03 - 0616892 ____A C:\Windows\dd_vcredistMSI7642.txt
2012-04-28 23:03 - 2012-04-28 23:03 - 0012308 ____A C:\Windows\dd_vcredistUI7642.txt
2012-04-27 23:04 - 2012-04-27 23:04 - 0619244 ____A C:\Windows\dd_vcredistMSI2868.txt
2012-04-27 23:04 - 2012-04-27 23:04 - 0012404 ____A C:\Windows\dd_vcredistUI2868.txt
2012-04-26 23:04 - 2012-04-26 23:04 - 0618726 ____A C:\Windows\dd_vcredistMSI5A6A.txt
2012-04-26 23:04 - 2012-04-26 23:04 - 0012388 ____A C:\Windows\dd_vcredistUI5A6A.txt
2012-04-26 13:06 - 2012-04-26 13:06 - 0709009 ____A C:\Users\xxx\Downloads\photo.JPG
2012-04-26 09:31 - 2012-04-26 09:31 - 0000369 ____A C:\Users\xxx\Downloads\temp_file-[survivor.s24e11.hdtv.xvid-fqm__180upload.avi].xspf
2012-04-25 18:48 - 2012-04-25 18:48 - 0042317 ____A C:\Users\xxx\Downloads\Mad_Men_Season_2_Complete_DVD_Rip-[[Demonoid.me]]_8697461.222.torrent
2012-04-24 23:04 - 2012-04-24 23:04 - 0619238 ____A C:\Windows\dd_vcredistMSI3E43.txt
2012-04-24 23:04 - 2012-04-24 23:04 - 0012404 ____A C:\Windows\dd_vcredistUI3E43.txt
2012-04-23 23:05 - 2012-04-23 23:05 - 0616892 ____A C:\Windows\dd_vcredistMSI7109.txt
2012-04-23 23:05 - 2012-04-23 23:05 - 0012308 ____A C:\Windows\dd_vcredistUI7109.txt
2012-04-23 18:45 - 2012-04-25 15:11 - 0000000 ____D C:\Users\xxx\Downloads\Season 01
2012-04-23 18:35 - 2012-04-23 18:35 - 0041152 ____A C:\Users\xxx\Downloads\Mad_Men_Season_1_Complete_DVD_Rip-_Demonoid.me_-_8697461.222.torrent
2012-04-23 18:23 - 2012-04-23 18:23 - 0047354 ____A C:\Users\xxx\Downloads\Mad_Men_Season_1_(All_13_Episodes)-((Demonoid.me))_8697461.222.torrent
2012-04-23 18:22 - 2012-04-23 18:22 - 0012457 ____A C:\Users\xxx\Downloads\Mad_Men_Season_1_(All_13_Episodes)_O-Demonoid.me-O_8697461.222.torrent
2012-04-22 20:19 - 2012-05-04 17:19 - 8744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-04-22 19:33 - 2012-05-09 22:19 - 0000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-04-22 19:33 - 2012-05-04 17:19 - 0419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-04-22 19:33 - 2012-04-22 19:33 - 0000000 ____D C:\Windows\System32\Macromed
2012-04-22 19:32 - 2012-04-22 19:32 - 0000000 ____D C:\Windows\system64
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\Local Settings\MSoft
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\Local Settings\Application Data\MSoft
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\Local Settings\Application Data\{9D0F945C-8CEC-11E1-826D-B8AC6F996F26}
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\Local Settings\{9D0F945C-8CEC-11E1-826D-B8AC6F996F26}
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\AppData\Local\MSoft
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\AppData\Local\{9D0F945C-8CEC-11E1-826D-B8AC6F996F26}
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____A C:\Users\xxx\Application Data\domRK.txt
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____A C:\Users\xxx\AppData\Roaming\domRK.txt
2012-04-21 23:05 - 2012-04-21 23:05 - 0616892 ____A C:\Windows\dd_vcredistMSI54BE.txt
2012-04-21 23:05 - 2012-04-21 23:05 - 0012308 ____A C:\Windows\dd_vcredistUI54BE.txt
2012-04-20 23:01 - 2012-04-20 23:02 - 0617670 ____A C:\Windows\dd_vcredistMSI03EB.txt
2012-04-20 23:01 - 2012-04-20 23:02 - 0012340 ____A C:\Windows\dd_vcredistUI03EB.txt
2012-04-19 23:02 - 2012-04-19 23:02 - 0618454 ____A C:\Windows\dd_vcredistMSI3649.txt
2012-04-19 23:02 - 2012-04-19 23:02 - 0012372 ____A C:\Windows\dd_vcredistUI3649.txt
2012-04-19 20:03 - 2012-04-19 20:03 - 0000000 ____D C:\Program Files (x86)\QuickTime
2012-04-17 13:09 - 2012-05-02 07:45 - 0000000 ____D C:\Users\xxx\Valuations
2012-04-16 23:02 - 2012-04-16 23:03 - 0618846 ____A C:\Windows\dd_vcredistMSI4C0D.txt
2012-04-16 23:02 - 2012-04-16 23:03 - 0012388 ____A C:\Windows\dd_vcredistUI4C0D.txt
2012-04-15 23:02 - 2012-04-15 23:03 - 0618046 ____A C:\Windows\dd_vcredistMSI7DEB.txt
2012-04-15 23:02 - 2012-04-15 23:03 - 0012356 ____A C:\Windows\dd_vcredistUI7DEB.txt
2012-04-14 23:02 - 2012-04-14 23:02 - 0618046 ____A C:\Windows\dd_vcredistMSI2F43.txt
2012-04-14 23:02 - 2012-04-14 23:02 - 0012356 ____A C:\Windows\dd_vcredistUI2F43.txt
2012-04-13 23:02 - 2012-04-13 23:02 - 0618830 ____A C:\Windows\dd_vcredistMSI618A.txt
2012-04-13 23:02 - 2012-04-13 23:02 - 0012388 ____A C:\Windows\dd_vcredistUI618A.txt
2012-04-12 23:13 - 2012-04-12 23:13 - 0618240 ____A C:\Windows\dd_vcredistMSI1BC9.txt
2012-04-12 23:13 - 2012-04-12 23:13 - 0013796 ____A C:\Windows\dd_vcredistUI1BC9.txt
2012-04-12 23:06 - 2012-03-05 22:44 - 4699520 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-04-12 23:06 - 2012-02-29 07:37 - 0219136 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2012-04-12 23:06 - 2012-02-29 07:37 - 0005632 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll
2012-04-12 23:06 - 2012-02-29 07:35 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll
2012-04-12 23:06 - 2012-02-29 07:11 - 0172032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2012-04-12 23:06 - 2012-02-29 07:11 - 0005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2012-04-12 23:06 - 2012-02-29 07:09 - 0157696 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2012-04-12 23:06 - 2012-02-29 05:52 - 0016384 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys
============ 3 Months Modified Files and Folders =============
2012-05-11 13:05 - 2012-05-11 13:05 - 0000000 ____D C:\FRST
2012-05-10 15:54 - 2009-12-12 08:02 - 0000000 ____D C:\users\RA Media Server
2012-05-10 15:54 - 2006-11-02 04:33 - 84148224 ____A C:\Windows\System32\config\software_previous
2012-05-10 15:53 - 2009-09-17 15:12 - 0000000 ____D C:\Users\xxx\Application Data\stickies
2012-05-10 15:53 - 2009-09-17 15:12 - 0000000 ____D C:\Users\xxx\AppData\Roaming\stickies
2012-05-10 15:53 - 2009-09-05 08:41 - 0000000 ____D C:\Users\xxx\Application Data\vlc
2012-05-10 15:53 - 2009-09-05 08:41 - 0000000 ____D C:\Users\xxx\AppData\Roaming\vlc
2012-05-10 15:53 - 2009-08-17 17:08 - 0000000 ____D C:\users\xxx
2012-05-10 15:53 - 2009-08-05 16:33 - 0000000 ____D C:\Users\All Users\Microsoft Help
2012-05-10 15:53 - 2009-08-05 16:33 - 0000000 ____D C:\Users\All Users\Application Data\Microsoft Help
2012-05-10 15:53 - 2009-08-05 16:33 - 0000000 ____D C:\ProgramData\Microsoft Help
2012-05-10 15:53 - 2009-08-05 16:32 - 0000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-10 15:53 - 2006-11-02 07:07 - 0000000 ____D C:\Windows\ShellNew
2012-05-10 15:53 - 2006-11-02 05:34 - 0000000 ____D C:\Windows\System32\spool
2012-05-10 15:53 - 2006-11-02 05:34 - 0000000 ____D C:\Windows\System32\Msdtc
2012-05-10 15:53 - 2006-11-02 04:33 - 44040192 ____A C:\Windows\System32\config\system_previous
2012-05-10 15:52 - 2006-11-02 05:33 - 0000000 ____D C:\Windows\registration
2012-05-10 15:52 - 2006-11-02 05:33 - 0000000 ____D C:\Program Files\Common Files\Microsoft Shared
2012-05-10 15:38 - 2006-11-02 04:33 - 49283072 ____A C:\Windows\System32\config\components_previous
2012-05-10 15:38 - 2006-11-02 04:33 - 0262144 ____A C:\Windows\System32\config\sam_previous
2012-05-10 12:20 - 2009-08-18 17:06 - 0000000 ____D C:\Program Files (x86)\mIRC
2012-05-10 12:06 - 2012-01-24 09:46 - 4024811520 __ASH C:\hiberfil.sys
2012-05-10 11:55 - 2006-11-02 05:33 - 0000000 ____D C:\Windows\System32\config\TxR
2012-05-10 11:37 - 2006-11-02 04:33 - 0524288 ____A C:\Windows\System32\config\default_previous
2012-05-10 11:37 - 2006-11-02 04:33 - 0262144 ____A C:\Windows\System32\config\security_previous
2012-05-10 11:35 - 2008-01-20 19:26 - 0561880 ____A C:\Windows\PFRO.log
2012-05-10 11:34 - 2009-08-05 10:41 - 1984299 ____A C:\Windows\WindowsUpdate.log
2012-05-10 11:32 - 2012-05-10 11:24 - 0002502 ____A C:\Users\xxx\Desktop\avastlog2.txt
2012-05-10 11:32 - 2012-05-10 10:26 - 0000914 ____A C:\Users\xxx\Desktop\ESETSCAN.txt
2012-05-10 11:24 - 2012-05-10 11:24 - 0000512 ____A C:\Users\xxx\Desktop\MBR.dat
2012-05-10 09:08 - 2009-08-05 15:52 - 0426573 ____A C:\Users\All Users\nvModes.001
2012-05-10 09:08 - 2009-08-05 15:52 - 0426573 ____A C:\Users\All Users\Application Data\nvModes.001
2012-05-10 09:08 - 2009-08-05 15:52 - 0426573 ____A C:\ProgramData\nvModes.001
2012-05-10 08:24 - 2009-08-18 17:00 - 0000000 ____D C:\Users\xxx\Tracing
2012-05-10 08:24 - 2009-08-05 15:50 - 0426573 ____A C:\Users\All Users\nvModes.dat
2012-05-10 08:24 - 2009-08-05 15:50 - 0426573 ____A C:\Users\All Users\Application Data\nvModes.dat
2012-05-10 08:24 - 2009-08-05 15:50 - 0426573 ____A C:\ProgramData\nvModes.dat
2012-05-09 23:02 - 2011-03-07 08:04 - 0000434 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{B1603A9F-20A2-41A9-B92B-78D8EF1E028F}.job
2012-05-09 23:00 - 2012-05-08 08:41 - 0000342 ____A C:\Windows\Tasks\At28.job
2012-05-09 22:30 - 2009-08-22 16:51 - 0000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-05-09 22:19 - 2012-04-22 19:33 - 0000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-05-09 22:12 - 2011-10-19 19:07 - 0000928 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1400044214-2866311749-911984212-1000UA.job
2012-05-09 22:00 - 2012-05-08 08:41 - 0000342 ____A C:\Windows\Tasks\At27.job
2012-05-09 21:55 - 2006-11-02 07:22 - 0003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-05-09 21:55 - 2006-11-02 07:22 - 0003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-05-09 21:34 - 2010-08-28 15:08 - 0000000 ____D C:\Users\xxx\Local Settings\Windows Server
2012-05-09 21:34 - 2010-08-28 15:08 - 0000000 ____D C:\Users\xxx\Local Settings\Application Data\Windows Server
2012-05-09 21:34 - 2010-08-28 15:08 - 0000000 ____D C:\Users\xxx\AppData\Local\Windows Server
2012-05-09 21:00 - 2012-05-08 08:41 - 0000342 ____A C:\Windows\Tasks\At26.job
2012-05-09 20:34 - 2012-05-08 08:41 - 0000342 ____A C:\Windows\Tasks\At25.job
2012-05-09 20:29 - 2012-05-09 20:15 - 0002293 ____A C:\Users\xxx\My Documents\aswMBR.txt
2012-05-09 20:29 - 2012-05-09 20:15 - 0002293 ____A C:\Users\xxx\Documents\aswMBR.txt
2012-05-09 20:25 - 2012-05-09 20:25 - 2322184 ____A (ESET) C:\Users\xxx\Downloads\esetsmartinstaller_enu.exe
2012-05-09 20:25 - 2012-05-09 20:25 - 0000000 ____D C:\Program Files (x86)\ESET
2012-05-09 20:15 - 2012-05-09 20:15 - 0000512 ____A C:\Users\xxx\My Documents\MBR.dat
2012-05-09 20:15 - 2012-05-09 20:15 - 0000512 ____A C:\Users\xxx\Documents\MBR.dat
2012-05-09 19:24 - 2012-05-09 19:24 - 4731392 ____A (AVAST Software) C:\Users\xxx\Downloads\aswMBR.exe
2012-05-09 19:12 - 2011-10-19 19:07 - 0000906 ____A C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1400044214-2866311749-911984212-1000Core.job
2012-05-09 19:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At48.job
2012-05-09 18:42 - 2012-05-09 18:42 - 2055783 ____A C:\Users\xxx\Downloads\tdsskiller.zip
2012-05-09 18:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At47.job
2012-05-09 17:30 - 2009-08-22 16:51 - 0000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-05-09 17:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At46.job
2012-05-09 16:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At45.job
2012-05-09 15:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At44.job
2012-05-09 14:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At43.job
2012-05-09 13:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At42.job
2012-05-09 12:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At41.job
2012-05-09 11:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At40.job
2012-05-09 10:19 - 2012-05-09 10:19 - 0572494 ____A C:\Users\xxx\Local Settings\dd_vcredistMSI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0572494 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistMSI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0572494 ____A C:\Users\xxx\AppData\Local\dd_vcredistMSI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0012384 ____A C:\Users\xxx\Local Settings\dd_vcredistUI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0012384 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistUI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0012384 ____A C:\Users\xxx\AppData\Local\dd_vcredistUI08CA.txt
2012-05-09 10:19 - 2012-05-09 10:19 - 0001787 ____A C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2012-05-09 10:19 - 2012-05-09 10:19 - 0001787 ____A C:\Users\All Users\Desktop\avast! Free Antivirus.lnk
2012-05-09 10:19 - 2012-05-09 10:19 - 0000000 ____A C:\Windows\SysWOW64\config.nt
2012-05-09 10:18 - 2012-05-08 15:24 - 0000000 ____D C:\Users\All Users\AVAST Software
2012-05-09 10:18 - 2012-05-08 15:24 - 0000000 ____D C:\Users\All Users\Application Data\AVAST Software
2012-05-09 10:18 - 2012-05-08 15:24 - 0000000 ____D C:\ProgramData\AVAST Software
2012-05-09 10:18 - 2012-05-08 15:24 - 0000000 ____D C:\Program Files\AVAST Software
2012-05-09 10:05 - 2012-05-09 10:04 - 0618278 ____A C:\Windows\dd_vcredistMSI7D83.txt
2012-05-09 10:05 - 2012-05-09 10:04 - 0012360 ____A C:\Windows\dd_vcredistUI7D83.txt
2012-05-09 10:01 - 2006-11-02 04:46 - 0707520 ____A C:\Windows\System32\PerfStringBackup.INI
2012-05-09 10:00 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At39.job
2012-05-09 09:55 - 2009-09-01 17:06 - 0058288 ____A (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.dll
2012-05-09 09:55 - 2009-09-01 08:03 - 0017408 ____A C:\Windows\System32\rpcnetp.exe
2012-05-09 09:54 - 2006-11-02 07:42 - 0000006 ___AH C:\Windows\Tasks\SA.DAT
2012-05-08 21:05 - 2012-05-08 21:04 - 0574200 ____A C:\Users\xxx\Local Settings\dd_vcredistMSI288C.txt
2012-05-08 21:05 - 2012-05-08 21:04 - 0574200 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistMSI288C.txt
2012-05-08 21:05 - 2012-05-08 21:04 - 0574200 ____A C:\Users\xxx\AppData\Local\dd_vcredistMSI288C.txt
2012-05-08 21:05 - 2012-05-08 21:04 - 0012460 ____A C:\Users\xxx\Local Settings\dd_vcredistUI288C.txt
2012-05-08 21:05 - 2012-05-08 21:04 - 0012460 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistUI288C.txt
2012-05-08 21:05 - 2012-05-08 21:04 - 0012460 ____A C:\Users\xxx\AppData\Local\dd_vcredistUI288C.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0572890 ____A C:\Users\xxx\Local Settings\dd_vcredistMSI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0572890 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistMSI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0572890 ____A C:\Users\xxx\AppData\Local\dd_vcredistMSI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0012400 ____A C:\Users\xxx\Local Settings\dd_vcredistUI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0012400 ____A C:\Users\xxx\Local Settings\Application Data\dd_vcredistUI24F3.txt
2012-05-08 15:25 - 2012-05-08 15:25 - 0012400 ____A C:\Users\xxx\AppData\Local\dd_vcredistUI24F3.txt
2012-05-08 15:23 - 2012-05-08 15:22 - 74761776 ____A C:\Users\xxx\Downloads\avast_free_antivirus_setup.exe
2012-05-08 15:18 - 2012-05-08 15:18 - 3877872 ____A (AVG Technologies) C:\Users\xxx\Downloads\avg_free_stb_all_2012_2171_cnet.exe
2012-05-08 15:12 - 2009-08-05 16:09 - 0000012 ____A C:\Windows\bthservsdp.dat
2012-05-08 15:12 - 2006-11-02 07:42 - 0032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-08 12:20 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At37.job
2012-05-08 12:20 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At36.job
2012-05-08 12:20 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At35.job
2012-05-08 12:20 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At34.job
2012-05-08 12:20 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At33.job
2012-05-08 12:20 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At32.job
2012-05-08 12:20 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At31.job
2012-05-08 12:20 - 2012-05-08 08:41 - 0000342 ____A C:\Windows\Tasks\At30.job
2012-05-08 12:20 - 2012-05-08 08:41 - 0000342 ____A C:\Windows\Tasks\At29.job
2012-05-08 09:03 - 2012-05-08 08:42 - 0000342 ____A C:\Windows\Tasks\At38.job
2012-05-08 09:01 - 2010-10-27 05:49 - 0000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-05-08 08:49 - 2012-03-31 13:11 - 0000771 ____A C:\Users\xxx\Desktop\Valuation Targets.txt
2012-05-08 08:31 - 2012-05-08 08:31 - 0000000 __ASH C:\Windows\System32\dds_trash_log.cmd
2012-05-07 08:12 - 2012-05-07 08:12 - 0000387 ____A C:\Users\xxx\Downloads\temp_file-[The.Big.Bang.Theory.S05E22.480p.HDTV.x264-mSD.mkv][vidhog].xspf
2012-05-06 18:42 - 2012-05-06 18:43 - 0000299 ____A C:\Users\xxx\Downloads\temp_file-[video.avi][sharebees].xspf
2012-05-06 18:39 - 2012-05-06 18:40 - 0000370 ____A C:\Users\xxx\Downloads\temp_file-[ice-This.Means.War.2012.DVDRip.x264-scOrp.mkv][180upload].xspf
2012-05-06 18:39 - 2012-05-06 18:39 - 0000330 ____A C:\Users\xxx\Downloads\temp_file-[This.Means.War.2012._.x264-scOrp.mkv][movreel].xspf
2012-05-06 18:38 - 2012-05-06 18:38 - 0000242 ____A C:\Users\xxx\Downloads\temp_file-[zpakn1m6wjwa][jumbofiles].xspf
2012-05-06 14:02 - 2012-05-06 14:02 - 0000241 ____A C:\Users\xxx\Downloads\temp_file-[m17fi6wibmjc][uploadorb].xspf
2012-05-04 23:04 - 2012-05-04 23:04 - 0619860 ____A C:\Windows\dd_vcredistMSI4BA5.txt
2012-05-04 23:04 - 2012-05-04 23:04 - 0013388 ____A C:\Windows\dd_vcredistUI4BA5.txt
2012-05-04 17:19 - 2012-04-22 20:19 - 8744608 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-04 17:19 - 2012-04-22 19:33 - 0419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-04 17:19 - 2011-07-04 09:18 - 0070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-03 23:02 - 2012-05-03 23:02 - 0619562 ____A C:\Windows\dd_vcredistMSI7BDE.txt
2012-05-03 23:02 - 2012-05-03 23:02 - 0012420 ____A C:\Windows\dd_vcredistUI7BDE.txt
2012-05-02 17:37 - 2009-08-18 17:06 - 0000000 ____D C:\Users\xxx\Application Data\mIRC
2012-05-02 17:37 - 2009-08-18 17:06 - 0000000 ____D C:\Users\xxx\AppData\Roaming\mIRC
2012-05-02 16:38 - 2009-09-01 20:39 - 0000623 ____A C:\Users\xxx\untitled.txt
2012-05-02 07:45 - 2012-04-17 13:09 - 0000000 ____D C:\Users\xxx\Valuations
2012-05-01 19:01 - 2009-09-19 12:05 - 0000000 ____D C:\Users\xxx\Application Data\uTorrent
2012-05-01 19:01 - 2009-09-19 12:05 - 0000000 ____D C:\Users\xxx\AppData\Roaming\uTorrent
2012-05-01 18:58 - 2009-08-17 18:33 - 0064512 ____A C:\Users\xxx\Local Settings\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-01 18:58 - 2009-08-17 18:33 - 0064512 ____A C:\Users\xxx\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-01 18:58 - 2009-08-17 18:33 - 0064512 ____A C:\Users\xxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-01 18:40 - 2012-05-01 16:39 - 0000000 ____D C:\Users\xxx\Downloads\Mad.Men.S04.BDRip.XviD-REWARD
2012-05-01 16:38 - 2012-05-01 16:38 - 0012734 ____A C:\Users\xxx\Downloads\Mad_Men_Season_4_HDTV_+-Demonoid.me-+_8697461.222.torrent
2012-05-01 16:36 - 2012-05-01 16:37 - 0012934 ____A C:\Users\xxx\Downloads\Mad_Men_Season_4_Complete_BDrip_Reward-_=Demonoid.me=__8697461.222.torrent
2012-05-01 15:36 - 2012-05-01 13:09 - 0000000 ____D C:\Users\xxx\Downloads\Mad Men S03 DVDrip-Reward
2012-05-01 13:05 - 2012-05-01 13:05 - 0038622 ____A C:\Users\xxx\Downloads\Mad_Men_Season_3_Complete_DVD_Rip_-Demonoid.me-__8697461.222.torrent
2012-05-01 13:04 - 2012-05-01 13:04 - 0024070 ____A C:\Users\xxx\Downloads\-_Demonoid.me_-Mad_Men_Season_3_Complete_DVDrip_Reward_8697461.222.torrent
2012-05-01 05:03 - 2012-05-01 05:03 - 0618364 ____A C:\Windows\dd_vcredistMSI25D1.txt
2012-05-01 05:03 - 2012-05-01 05:03 - 0012372 ____A C:\Windows\dd_vcredistUI25D1.txt
2012-04-29 22:46 - 2012-04-29 19:48 - 0000000 ____D C:\Users\xxx\Downloads\Mad Men - Season 2 - Complete
2012-04-29 21:16 - 2012-04-29 21:16 - 0000353 ____A C:\Users\xxx\Downloads\temp_file-[mad.men.s02e01.dvdrip.xvid-reward.avi].xspf
2012-04-29 20:42 - 2012-04-29 20:40 - 3175832 ____A (Microsoft Corporation) C:\Users\xxx\Desktop\vcredist_x64.EXE
2012-04-29 20:16 - 2012-04-29 20:16 - 0001696 ____A C:\Users\Public\Desktop\iTunes.lnk
2012-04-29 20:16 - 2012-04-29 20:16 - 0001696 ____A C:\Users\All Users\Desktop\iTunes.lnk
2012-04-29 20:16 - 2012-04-29 20:15 - 0000000 ____D C:\Program Files\iTunes
2012-04-29 20:16 - 2012-04-29 20:15 - 0000000 ____D C:\Program Files (x86)\iTunes
2012-04-29 20:15 - 2012-04-29 20:15 - 0000000 ____D C:\Program Files\iPod
2012-04-29 20:05 - 2012-04-29 20:04 - 76763504 ____A (Apple Inc.) C:\Users\xxx\Downloads\iTunes64Setup.exe
2012-04-29 19:44 - 2012-04-29 19:45 - 0023929 ____A C:\Users\xxx\Downloads\Mad_Men_Season_2_Complete-(Demonoid.me)_8697461.222.torrent
2012-04-28 23:03 - 2012-04-28 23:03 - 0616892 ____A C:\Windows\dd_vcredistMSI7642.txt
2012-04-28 23:03 - 2012-04-28 23:03 - 0012308 ____A C:\Windows\dd_vcredistUI7642.txt
2012-04-27 23:04 - 2012-04-27 23:04 - 0619244 ____A C:\Windows\dd_vcredistMSI2868.txt
2012-04-27 23:04 - 2012-04-27 23:04 - 0012404 ____A C:\Windows\dd_vcredistUI2868.txt
2012-04-26 23:04 - 2012-04-26 23:04 - 0618726 ____A C:\Windows\dd_vcredistMSI5A6A.txt
2012-04-26 23:04 - 2012-04-26 23:04 - 0012388 ____A C:\Windows\dd_vcredistUI5A6A.txt
2012-04-26 13:06 - 2012-04-26 13:06 - 0709009 ____A C:\Users\xxx\Downloads\photo.JPG
2012-04-26 09:31 - 2012-04-26 09:31 - 0000369 ____A C:\Users\xxx\Downloads\temp_file-[survivor.s24e11.hdtv.xvid-fqm__180upload.avi].xspf
2012-04-25 18:48 - 2012-04-25 18:48 - 0042317 ____A C:\Users\xxx\Downloads\Mad_Men_Season_2_Complete_DVD_Rip-[[Demonoid.me]]_8697461.222.torrent
2012-04-25 15:11 - 2012-04-23 18:45 - 0000000 ____D C:\Users\xxx\Downloads\Season 01
2012-04-25 07:13 - 2010-08-17 19:26 - 0000000 ____D C:\Users\xxx\Application Data\Dropbox
2012-04-25 07:13 - 2010-08-17 19:26 - 0000000 ____D C:\Users\xxx\AppData\Roaming\Dropbox
2012-04-24 23:04 - 2012-04-24 23:04 - 0619238 ____A C:\Windows\dd_vcredistMSI3E43.txt
2012-04-24 23:04 - 2012-04-24 23:04 - 0012404 ____A C:\Windows\dd_vcredistUI3E43.txt
2012-04-24 20:04 - 2009-10-01 20:53 - 0000000 ____D C:\Users\xxx\Application Data\Skype
2012-04-24 20:04 - 2009-10-01 20:53 - 0000000 ____D C:\Users\xxx\AppData\Roaming\Skype
2012-04-23 23:05 - 2012-04-23 23:05 - 0616892 ____A C:\Windows\dd_vcredistMSI7109.txt
2012-04-23 23:05 - 2012-04-23 23:05 - 0012308 ____A C:\Windows\dd_vcredistUI7109.txt
2012-04-23 23:00 - 2009-08-17 18:12 - 0007592 ____A C:\Users\xxx\Local Settings\d3d9caps.dat
2012-04-23 23:00 - 2009-08-17 18:12 - 0007592 ____A C:\Users\xxx\Local Settings\Application Data\d3d9caps.dat
2012-04-23 23:00 - 2009-08-17 18:12 - 0007592 ____A C:\Users\xxx\AppData\Local\d3d9caps.dat
2012-04-23 18:35 - 2012-04-23 18:35 - 0041152 ____A C:\Users\xxx\Downloads\Mad_Men_Season_1_Complete_DVD_Rip-_Demonoid.me_-_8697461.222.torrent
2012-04-23 18:23 - 2012-04-23 18:23 - 0047354 ____A C:\Users\xxx\Downloads\Mad_Men_Season_1_(All_13_Episodes)-((Demonoid.me))_8697461.222.torrent
2012-04-23 18:22 - 2012-04-23 18:22 - 0012457 ____A C:\Users\xxx\Downloads\Mad_Men_Season_1_(All_13_Episodes)_O-Demonoid.me-O_8697461.222.torrent
2012-04-23 12:09 - 2010-08-17 19:28 - 0000000 ___RD C:\Users\xxx\My Documents\My Dropbox
2012-04-23 12:09 - 2010-08-17 19:28 - 0000000 ___RD C:\Users\xxx\Documents\My Dropbox
2012-04-22 19:33 - 2012-04-22 19:33 - 0000000 ____D C:\Windows\System32\Macromed
2012-04-22 19:32 - 2012-04-22 19:32 - 0000000 ____D C:\Windows\system64
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\Local Settings\MSoft
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\Local Settings\Application Data\MSoft
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\Local Settings\Application Data\{9D0F945C-8CEC-11E1-826D-B8AC6F996F26}
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\Local Settings\{9D0F945C-8CEC-11E1-826D-B8AC6F996F26}
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\AppData\Local\MSoft
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____D C:\Users\xxx\AppData\Local\{9D0F945C-8CEC-11E1-826D-B8AC6F996F26}
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____A C:\Users\xxx\Application Data\domRK.txt
2012-04-22 18:32 - 2012-04-22 18:32 - 0000000 ____A C:\Users\xxx\AppData\Roaming\domRK.txt
2012-04-21 23:05 - 2012-04-21 23:05 - 0616892 ____A C:\Windows\dd_vcredistMSI54BE.txt
2012-04-21 23:05 - 2012-04-21 23:05 - 0012308 ____A C:\Windows\dd_vcredistUI54BE.txt
2012-04-21 19:15 - 2009-09-10 15:17 - 0000000 ____D C:\Users\xxx\My Courses
2012-04-20 23:02 - 2012-04-20 23:01 - 0617670 ____A C:\Windows\dd_vcredistMSI03EB.txt
2012-04-20 23:02 - 2012-04-20 23:01 - 0012340 ____A C:\Windows\dd_vcredistUI03EB.txt
2012-04-19 23:02 - 2012-04-19 23:02 - 0618454 ____A C:\Windows\dd_vcredistMSI3649.txt
2012-04-19 23:02 - 2012-04-19 23:02 - 0012372 ____A C:\Windows\dd_vcredistUI3649.txt
2012-04-19 20:03 - 2012-04-19 20:03 - 0000000 ____D C:\Program Files (x86)\QuickTime
2012-04-16 23:03 - 2012-04-16 23:02 - 0618846 ____A C:\Windows\dd_vcredistMSI4C0D.txt
2012-04-16 23:03 - 2012-04-16 23:02 - 0012388 ____A C:\Windows\dd_vcredistUI4C0D.txt
2012-04-15 23:03 - 2012-04-15 23:02 - 0618046 ____A C:\Windows\dd_vcredistMSI7DEB.txt
2012-04-15 23:03 - 2012-04-15 23:02 - 0012356 ____A C:\Windows\dd_vcredistUI7DEB.txt
2012-04-14 23:02 - 2012-04-14 23:02 - 0618046 ____A C:\Windows\dd_vcredistMSI2F43.txt
2012-04-14 23:02 - 2012-04-14 23:02 - 0012356 ____A C:\Windows\dd_vcredistUI2F43.txt
2012-04-13 23:02 - 2012-04-13 23:02 - 0618830 ____A C:\Windows\dd_vcredistMSI618A.txt
2012-04-13 23:02 - 2012-04-13 23:02 - 0012388 ____A C:\Windows\dd_vcredistUI618A.txt
2012-04-12 23:41 - 2009-09-01 17:06 - 0058288 ____N (Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe
2012-04-12 23:38 - 2009-09-01 08:03 - 0017408 ____A C:\Windows\SysWOW64\rpcnetp.dll
2012-04-12 23:37 - 2009-09-01 08:03 - 0017408 ____A C:\Windows\SysWOW64\rpcnetp.exe
2012-04-12 23:13 - 2012-04-12 23:13 - 0618240 ____A C:\Windows\dd_vcredistMSI1BC9.txt
2012-04-12 23:13 - 2012-04-12 23:13 - 0013796 ____A C:\Windows\dd_vcredistUI1BC9.txt
2012-04-12 23:03 - 2006-11-02 04:35 - 57249312 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-04-10 23:02 - 2012-04-10 23:02 - 0619150 ____A C:\Windows\dd_vcredistMSI771A.txt
2012-04-10 23:02 - 2012-04-10 23:02 - 0013828 ____A C:\Windows\dd_vcredistUI771A.txt
2012-04-10 05:05 - 2012-04-10 05:05 - 0619934 ____A C:\Windows\dd_vcredistMSI3E67.txt
2012-04-10 05:05 - 2012-04-10 05:05 - 0013860 ____A C:\Windows\dd_vcredistUI3E67.txt
2012-04-07 23:02 - 2012-04-07 23:02 - 0617190 ____A C:\Windows\dd_vcredistMSI0C51.txt
2012-04-07 23:02 - 2012-04-07 23:02 - 0013748 ____A C:\Windows\dd_vcredistUI0C51.txt
2012-04-06 23:03 - 2012-04-06 23:03 - 0618366 ____A C:\Windows\dd_vcredistMSI3F48.txt
2012-04-06 23:03 - 2012-04-06 23:03 - 0013796 ____A C:\Windows\dd_vcredistUI3F48.txt
2012-04-05 23:03 - 2012-04-05 23:03 - 0619150 ____A C:\Windows\dd_vcredistMSI70FC.txt
2012-04-05 23:03 - 2012-04-05 23:03 - 0013828 ____A C:\Windows\dd_vcredistUI70FC.txt
2012-04-05 12:40 - 2012-04-05 11:16 - 0000000 ____D C:\Users\xxx\Downloads\Friends.with.Kids.2012.DVDSCR.XviD-MC8
2012-04-05 11:42 - 2010-07-31 07:09 - 0000000 ____D C:\Users\xxx\Application Data\PrimoPDF
2012-04-05 11:42 - 2010-07-31 07:09 - 0000000 ____D C:\Users\xxx\AppData\Roaming\PrimoPDF
2012-04-05 11:13 - 2012-04-05 11:14 - 0014633 ____A C:\Users\xxx\Downloads\++Demonoid.me++-Friends_with_Kids_2012_DVDSCR_XviD_MC8_8697461.222.torrent
2012-04-05 09:55 - 2012-04-05 09:55 - 0000162 ___AH C:\Users\xxx\Desktop\~$icing and Promotion Analyst.doc
2012-04-05 09:54 - 2012-04-05 09:55 - 0196608 ____A C:\Users\xxx\Desktop\Pricing and Promotion Analyst.doc
2012-04-04 23:03 - 2012-04-04 23:03 - 0619934 ____A C:\Windows\dd_vcredistMSI22D3.txt
2012-04-04 23:03 - 2012-04-04 23:03 - 0013860 ____A C:\Windows\dd_vcredistUI22D3.txt
2012-04-04 11:56 - 2010-10-27 05:49 - 0024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-04 07:28 - 2009-08-18 17:52 - 0000000 ____D C:\Users\xxx\Work Tings
2012-04-03 23:04 - 2012-04-03 23:04 - 0619542 ____A C:\Windows\dd_vcredistMSI558F.txt
2012-04-03 23:04 - 2012-04-03 23:04 - 0013844 ____A C:\Windows\dd_vcredistUI558F.txt
2012-04-03 21:53 - 2012-04-03 19:37 - 0012501 ____A C:\Users\xxx\Q.xlsx
2012-04-03 20:55 - 2012-04-03 20:49 - 0000000 ____D C:\Users\xxx\Downloads\21.Jump.Street.2012.TS.XViD.AC3-26K
2012-04-03 20:44 - 2012-04-03 20:44 - 0127258 ____A C:\Users\xxx\Downloads\+-Demonoid.me-+_The_Sitter_2011_720p_BRRip_x264_vice_8697461.222.torrent
2012-04-03 20:44 - 2012-04-03 20:44 - 0008049 ____A C:\Users\xxx\Downloads\21_Jump_Street_2012_TS_XViD_AC3_26K-(Demonoid.me)_8697461.222.torrent
2012-04-02 23:03 - 2012-04-02 23:03 - 0618758 ____A C:\Windows\dd_vcredistMSI0699.txt
2012-04-02 23:03 - 2012-04-02 23:03 - 0013812 ____A C:\Windows\dd_vcredistUI0699.txt
2012-04-02 20:42 - 2012-04-02 20:06 - 0000000 ____D C:\Users\xxx\Downloads\The.Vow.2012.R5.LiNE.XViD.AC3-26K
2012-04-02 20:02 - 2012-04-02 20:02 - 0009883 ____A C:\Users\xxx\Downloads\(Demonoid.me)-The_Vow_2012_R5_LiNE_XViD_AC3_26K_8697461.222.torrent
2012-04-02 19:59 - 2012-04-02 19:59 - 0009883 ____A C:\Users\xxx\Downloads\x-Demonoid.me-x_The_Vow_2012_R5_LiNE_XViD_AC3_26K_8697461.222.torrent
2012-04-02 19:58 - 2012-04-02 19:58 - 0015359 ____A C:\Users\xxx\Downloads\The_Vow_(2012)_R5_NL_subs_DutchReleaseTeam_O-Demonoid.me-O_8697461.222.torrent
2012-04-01 23:03 - 2012-04-01 23:02 - 0618366 ____A C:\Windows\dd_vcredistMSI3815.txt
2012-04-01 23:03 - 2012-04-01 23:02 - 0013796 ____A C:\Windows\dd_vcredistUI3815.txt
2012-03-31 23:03 - 2012-03-31 23:03 - 0619934 ____A C:\Windows\dd_vcredistMSI6A24.txt
2012-03-31 23:03 - 2012-03-31 23:03 - 0013860 ____A C:\Windows\dd_vcredistUI6A24.txt
2012-03-30 23:04 - 2012-03-30 23:04 - 0617974 ____A C:\Windows\dd_vcredistMSI1CD0.txt
2012-03-30 23:04 - 2012-03-30 23:04 - 0013780 ____A C:\Windows\dd_vcredistUI1CD0.txt
2012-03-29 23:03 - 2012-03-29 23:03 - 0619150 ____A C:\Windows\dd_vcredistMSI4E14.txt
2012-03-29 23:03 - 2012-03-29 23:03 - 0013828 ____A C:\Windows\dd_vcredistUI4E14.txt
2012-03-29 09:36 - 2012-03-29 09:35 - 0619482 ____A C:\Windows\dd_vcredistMSI6401.txt
2012-03-29 09:36 - 2012-03-29 09:35 - 0013832 ____A C:\Windows\dd_vcredistUI6401.txt
2012-03-28 21:14 - 2012-03-28 21:15 - 0046957 ____A C:\Users\xxx\Desktop\420356_187834977988245_149842465120830_275515_831104253_n.jpg
2012-03-27 23:04 - 2012-03-27 23:04 - 0617582 ____A C:\Windows\dd_vcredistMSI3242.txt
2012-03-27 23:04 - 2012-03-27 23:03 - 0013764 ____A C:\Windows\dd_vcredistUI3242.txt
2012-03-26 23:03 - 2012-03-26 23:03 - 0619934 ____A C:\Windows\dd_vcredistMSI63C5.txt
2012-03-26 23:03 - 2012-03-26 23:03 - 0013860 ____A C:\Windows\dd_vcredistUI63C5.txt
2012-03-26 22:27 - 2012-03-26 22:27 - 0000026 ____A C:\Users\xxx\Desktop\c.txt
2012-03-25 21:54 - 2012-03-25 21:55 - 0436810 ____A C:\Users\xxx\Desktop\205-of-237.jpg
2012-03-25 07:55 - 2012-03-25 07:55 - 0617908 ____A C:\Windows\dd_vcredistMSI5EDC.txt
2012-03-25 07:55 - 2012-03-25 07:55 - 0013768 ____A C:\Windows\dd_vcredistUI5EDC.txt
2012-03-22 11:44 - 2012-03-22 11:44 - 0857041 ____A C:\Users\xxx\Desktop\template MAX .xlsx
2012-03-21 23:02 - 2012-03-21 23:02 - 0617952 ____A C:\Windows\dd_vcredistMSI5C77.txt
2012-03-21 23:02 - 2012-03-21 23:02 - 0013780 ____A C:\Windows\dd_vcredistUI5C77.txt
2012-03-21 09:44 - 2006-11-02 07:27 - 0187606 ____A C:\Windows\setupact.log
2012-03-20 15:41 - 2006-11-02 07:21 - 0391776 ____A C:\Windows\System32\FNTCACHE.DAT
2012-03-19 23:27 - 2012-03-19 23:27 - 0617848 ____A C:\Windows\dd_vcredistMSI5363.txt
2012-03-19 23:27 - 2012-03-19 23:27 - 0027824 ____A C:\Windows\dd_vcredistUI5363.txt
2012-03-19 23:14 - 2006-11-02 04:34 - 0000219 ____A C:\Windows\win.ini
2012-03-19 21:19 - 2012-03-19 21:19 - 0337007 ____A C:\Users\xxx\Desktop\RentReceipts.jpg
2012-03-18 15:43 - 2012-03-18 15:43 - 0240624 ____A C:\Users\xxx\Desktop\KPMG T4.pdf
2012-03-14 17:43 - 2012-03-14 17:43 - 2417515 ____A C:\Users\xxx\Desktop\Tuition.pdf
2012-03-11 22:07 - 2010-05-19 06:48 - 0001460 ____A C:\Users\xxx\Local Settings\d3d9caps64.dat
2012-03-11 22:07 - 2010-05-19 06:48 - 0001460 ____A C:\Users\xxx\Local Settings\Application Data\d3d9caps64.dat
2012-03-11 22:07 - 2010-05-19 06:48 - 0001460 ____A C:\Users\xxx\AppData\Local\d3d9caps64.dat
2012-03-11 18:58 - 2012-02-28 20:35 - 0025440 ____A C:\Users\xxx\Desktop\Weekend Plan.docx
2012-03-11 00:03 - 2012-03-11 00:02 - 0617582 ____A C:\Windows\dd_vcredistMSI2F1B.txt
2012-03-11 00:03 - 2012-03-11 00:02 - 0017440 ____A C:\Windows\dd_vcredistUI2F1B.txt
2012-03-10 00:02 - 2012-03-10 00:02 - 0617190 ____A C:\Windows\dd_vcredistMSI60DE.txt
2012-03-10 00:02 - 2012-03-10 00:02 - 0017424 ____A C:\Windows\dd_vcredistUI60DE.txt
2012-03-09 00:02 - 2012-03-09 00:02 - 0617456 ____A C:\Windows\dd_vcredistMSI129F.txt
2012-03-09 00:02 - 2012-03-09 00:02 - 0017440 ____A C:\Windows\dd_vcredistUI129F.txt
2012-03-08 00:03 - 2012-03-08 00:03 - 0617580 ____A C:\Windows\dd_vcredistMSI4513.txt
2012-03-08 00:03 - 2012-03-08 00:03 - 0017440 ____A C:\Windows\dd_vcredistUI4513.txt
2012-03-07 20:52 - 2012-03-07 20:52 - 0003961 ____A C:\Users\xxx\Downloads\+-Demonoid.me-+_Survivor_S24E04_Bum_Puzzled_HDTV_XviD_FQM_8697461.222.torrent
2012-03-07 20:49 - 2012-03-07 20:49 - 0014442 ____A C:\Users\xxx\Downloads\Survivor.S24E04.Bum-Puzzled.HDTV.XviD-FQM.[eztv].torrent
2012-03-06 15:15 - 2012-05-09 10:19 - 0258520 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2012-03-06 15:15 - 2012-05-09 10:18 - 0201352 ____A (AVAST Software) C:\Windows\SysWOW64\aswBoot.exe
2012-03-06 15:15 - 2012-05-09 10:18 - 0041184 ____A (AVAST Software) C:\Windows\avastSS.scr
2012-03-06 15:04 - 2012-05-09 10:19 - 0819032 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2012-03-06 15:04 - 2012-05-09 10:19 - 0337240 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2012-03-06 15:02 - 2012-05-09 10:19 - 0043864 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr.sys
2012-03-06 15:01 - 2012-05-09 10:19 - 0069976 ____A (AVAST Software) C:\Windows\System32\Drivers\aswMonFlt.sys
2012-03-06 15:01 - 2012-05-09 10:19 - 0059224 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2012-03-06 15:01 - 2012-05-09 10:19 - 0024408 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2012-03-06 00:52 - 2012-02-19 22:55 - 0000607 ____A C:\Users\xxx\Desktop\00.txt
2012-03-06 00:02 - 2012-03-06 00:02 - 0618758 ____A C:\Windows\dd_vcredistMSI27EE.txt
2012-03-06 00:02 - 2012-03-06 00:02 - 0017488 ____A C:\Windows\dd_vcredistUI27EE.txt
2012-03-05 22:44 - 2012-04-12 23:06 - 4699520 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-03-05 07:10 - 2012-03-05 07:08 - 29167441 ____A C:\Users\xxx\Desktop\IveyPrintersInstallerXPV7.exe
2012-03-05 05:29 - 2012-03-05 05:29 - 7520077 ____A C:\Users\xxx\Desktop\mercedes.zip
2012-03-05 00:03 - 2012-03-05 00:03 - 0616892 ____A C:\Windows\dd_vcredistMSI5A96.txt
2012-03-05 00:03 - 2012-03-05 00:03 - 0012308 ____A C:\Windows\dd_vcredistUI5A96.txt
2012-03-04 00:05 - 2012-03-04 00:04 - 0619636 ____A C:\Windows\dd_vcredistMSI0DB4.txt
2012-03-04 00:05 - 2012-03-04 00:04 - 0012420 ____A C:\Windows\dd_vcredistUI0DB4.txt
2012-03-03 00:04 - 2012-03-03 00:04 - 0618852 ____A C:\Windows\dd_vcredistMSI3F2D.txt
2012-03-03 00:04 - 2012-03-03 00:04 - 0012388 ____A C:\Windows\dd_vcredistUI3F2D.txt
2012-03-02 00:02 - 2012-03-02 00:02 - 0618068 ____A C:\Windows\dd_vcredistMSI6FC1.txt
2012-03-02 00:02 - 2012-03-02 00:02 - 0012356 ____A C:\Windows\dd_vcredistUI6FC1.txt
2012-02-29 07:37 - 2012-04-12 23:06 - 0219136 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll
2012-02-29 07:37 - 2012-04-12 23:06 - 0005632 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll
2012-02-29 07:35 - 2012-04-12 23:06 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll
2012-02-29 07:11 - 2012-04-12 23:06 - 0172032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2012-02-29 07:11 - 2012-04-12 23:06 - 0005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2012-02-29 07:09 - 2012-04-12 23:06 - 0157696 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2012-02-29 05:52 - 2012-04-12 23:06 - 0016384 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys
2012-02-27 05:04 - 2012-02-27 05:04 - 0619244 ____A C:\Windows\dd_vcredistMSI1E29.txt
2012-02-27 05:04 - 2012-02-27 05:04 - 0012404 ____A C:\Windows\dd_vcredistUI1E29.txt
2012-02-26 00:02 - 2012-02-26 00:02 - 0619636 ____A C:\Windows\dd_vcredistMSI692B.txt
2012-02-26 00:02 - 2012-02-26 00:02 - 0012420 ____A C:\Windows\dd_vcredistUI692B.txt
2012-02-23 06:18 - 2009-10-21 11:09 - 0279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2012-02-19 20:28 - 2012-02-19 20:29 - 0072968 ____A C:\Users\xxx\Desktop\pic1.jpg
2012-02-19 00:03 - 2012-02-19 00:03 - 0618046 ____A C:\Windows\dd_vcredistMSI4670.txt
2012-02-19 00:03 - 2012-02-19 00:03 - 0012356 ____A C:\Windows\dd_vcredistUI4670.txt
2012-02-18 00:02 - 2012-02-18 00:02 - 0619222 ____A C:\Windows\dd_vcredistMSI77E2.txt
2012-02-18 00:02 - 2012-02-18 00:02 - 0012404 ____A C:\Windows\dd_vcredistUI77E2.txt
2012-02-17 11:18 - 2012-02-17 11:18 - 0042678 ____A C:\Users\xxx\Desktop\Surgeon Form.pdf
2012-02-16 00:15 - 2012-02-16 00:15 - 0618632 ____A C:\Windows\dd_vcredistMSI65D6.txt
2012-02-16 00:15 - 2012-02-16 00:15 - 0226276 ____A C:\Windows\dd_vcredistUI65D6.txt
2012-02-14 08:49 - 2012-03-13 13:25 - 0327680 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll
2012-02-14 08:49 - 2012-03-13 13:25 - 0196096 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll
2012-02-14 07:45 - 2012-03-13 13:25 - 0219648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2012-02-14 07:45 - 2012-03-13 13:25 - 0160768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2012-02-13 06:38 - 2012-03-13 13:25 - 2002944 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2012-02-13 06:12 - 2012-03-13 13:25 - 1172480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2012-02-13 06:06 - 2012-03-13 13:25 - 0834048 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll
2012-02-13 06:03 - 2012-03-13 13:25 - 1555968 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2012-02-13 05:47 - 2012-03-13 13:25 - 0683008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2012-02-13 05:44 - 2012-03-13 13:25 - 1068544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2012-02-12 19:10 - 2012-02-12 19:10 - 0000000 ____D C:\Users\xxx\Application Data\webex
2012-02-12 19:10 - 2012-02-12 19:10 - 0000000 ____D C:\Users\xxx\AppData\Roaming\webex
2012-02-12 18:59 - 2012-02-12 18:59 - 0000000 ____D C:\Users\All Users\WebEx
2012-02-12 18:59 - 2012-02-12 18:59 - 0000000 ____D C:\Users\All Users\Application Data\WebEx
2012-02-12 18:59 - 2012-02-12 18:59 - 0000000 ____D C:\ProgramData\WebEx
2012-02-12 18:59 - 2009-08-18 16:24 - 0000000 ____D C:\Users\xxx\Application Data\Mozilla
2012-02-12 18:59 - 2009-08-18 16:24 - 0000000 ____D C:\Users\xxx\AppData\Roaming\Mozilla
2012-02-12 18:59 - 2009-08-17 17:08 - 0000000 ____D C:\Users\xxx\AppData\LocalLow
2012-02-12 12:09 - 2012-02-12 12:09 - 1085509 ____A C:\Users\xxx\Desktop\V23 - xxx edits v2.docx
2012-02-12 11:50 - 2012-02-12 11:42 - 1085391 ____A C:\Users\xxx\Desktop\V23 - xxx edits.docx
2012-02-12 11:20 - 2012-02-12 11:40 - 1138734 ____A C:\Users\xxx\Desktop\V23.docx
2012-02-12 09:13 - 2012-02-12 09:19 - 1021952 ____A C:\Users\xxx\Desktop\Draft V20 (xxx ccc's conflicted copy 2012-02-12).doc
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe
[2008-01-20 18:49] - [2008-01-20 18:49] - 0028160 ____A (Microsoft Corporation) A0AB2BB9A92293D9CE66E252719AB5FE
C:\Windows\SysWOW64\userinit.exe
[2008-01-20 18:50] - [2008-01-20 18:50] - 0025088 ____A (Microsoft Corporation) 0E135526E9785D085BCD9AEDE6FBCBF9
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 3837.43 MB
Available physical RAM: 3386.62 MB
Total Pagefile: 3717.32 MB
Available Pagefile: 3365.52 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB
======================= Partitions =========================
1 Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:17.34 GB) NTFS ==>[Drive with boot components (obtanied from BCD)]
3 Drive e: () (Removable) (Total:0.24 GB) (Free:0.22 GB) FAT
4 Drive x: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:5.33 GB) NTFS
Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 244 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 32 KB
Partition 2 Primary 15 GB 39 MB
Partition 3 Primary 283 GB 15 GB
======================================================================================================
Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 FAT Partition 39 MB Healthy Hidden
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 X RECOVERY NTFS Partition 15 GB Healthy Boot
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 283 GB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
* Partition 1 Primary 244 MB 0 B
======================================================================================================
Disk: 1
There is no partition selected.
There is no partition selected.
Please select a partition and try again.
======================================================================================================
==========================================================
Last Boot: 2012-05-10 10:20
======================= End Of Log ==========================
3. Status of the infected PC is still the same, haven't been able to boot it up or restore windows after the last set of removal scans that were done a few days ago. There was a button "fix" on the FRST tool that was there after I did the scan however I didn't click it as it wasn't under the instructions you specified.
Thanks again.