Scan result of Farbar Recovery Scan Tool Version: 21-06-2012 02
Ran by SYSTEM at 22-06-2012 01:27:17
Running from G:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001
========================== Registry (Whitelisted) =============
HKLM\...\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [489472 2010-09-29] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2538280 2011-07-01] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp [21705296 2010-10-25] ()
HKLM\...\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background [611896 2010-08-31] ()
HKLM\...\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden [363064 2010-07-21] (Hewlett-Packard Company)
HKLM\...\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1580368 2010-11-03] (Logitech, Inc.)
HKLM-x32\...\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [336384 2010-11-10] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [boincmgr] "C:\Program Files (x86)\BOINC\boincmgr.exe" /a /s [4543232 2010-09-23] (World Community Grid)
HKLM-x32\...\Run: [boinctray] "C:\Program Files (x86)\BOINC\boinctray.exe" [58112 2010-09-23] (Space Sciences Laboratory)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-03-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [3744552 2011-11-28] (AVAST Software)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [1987976 2012-02-28] (LogMeIn Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKLM-x32\...\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKU\
[username]\...\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk [2080 2011-04-21] ()
HKU\
[username]\...\Run: [Akamai NetSession Interface] "C:\Users\
[username]\AppData\Local\Akamai\netsession_win.exe" [4327744 2012-05-26] (Akamai Technologies, Inc)
HKU\
[username]\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1242448 2012-02-23] (Valve Corporation)
HKU\
[username]\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17148552 2012-02-29] (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 68.238.96.12
Startup: C:\Users\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)
==================== Services (Whitelisted) ======
2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2011-08-11] (SUPERAntiSpyware.com)
2 Akamai; C:\program files (x86)\common files\akamai/netsession_win_80c2ffa.dll [3417376 2012-05-29] ()
2 AMD Reservation Manager; "C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe" [194496 2010-06-17] (Advanced Micro Devices)
2 Apache2.2; "C:\xampp\apache\bin\httpd.exe" -k runservice [20549 2010-10-17] (Apache Software Foundation)
2 avast! Antivirus; "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [44768 2011-11-28] (AVAST Software)
3 Bluetooth Device Manager; "C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe" [4150864 2010-10-25] (Motorola, Inc.)
3 Bluetooth Media Service; "C:\Program Files\Motorola\Bluetooth\audiosrv.exe" [1188616 2010-07-15] (Motorola, Inc.)
2 Bluetooth OBEX Service; "C:\Program Files\Motorola\Bluetooth\obexsrv.exe" [679176 2010-07-16] (Motorola, Inc.)
2 CLKMSVC10_C6F09094; "C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe" /svc [245232 2010-10-25] (CyberLink)
2 DvmMDES; "C:\SwSetup\HPQWMM\QuickWeb\QW.SYS\config\DVMExportService.exe" [338208 2010-11-18] (DeviceVM, Inc.)
3 FLEXnet Licensing Service; "C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" [647680 2011-04-21] (Macrovision Europe Ltd.)
3 FLEXnet Licensing Service 64; "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe" [1028096 2011-04-21] (Macrovision Europe Ltd.)
2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [2343816 2012-02-28] (LogMeIn Inc.)
2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [35200 2012-03-05] (Hewlett-Packard Development Company, L.P.)
2 libusbd; C:\Windows\SysWow64\libusbd-nt.exe [18944 2005-03-09] (
http://libusb-win32.sourceforge.net)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe" [237008 2011-06-17] (McAfee, Inc.)
2 NitroDriverReadSpool2; "C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe" [216072 2012-05-16] (Nitro PDF Software)
2 nlsX86cc; C:\Windows\SysWOW64\NLSSRV32.EXE [69640 2012-05-16] (Nalpeiron Ltd.)
2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-06-01] (Symantec Corporation)
========================== Drivers (Whitelisted) =============
2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [24408 2011-11-28] (AVAST Software)
2 aswMonFlt; C:\Windows\System32\Drivers\aswMonFlt.sys [66904 2011-11-28] (AVAST Software)
1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [42328 2011-11-28] (AVAST Software)
1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [591192 2011-11-28] (AVAST Software)
1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [304472 2011-11-28] (AVAST Software)
1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [58712 2011-11-28] (AVAST Software)
3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [116752 2010-09-24] (ATI Technologies, Inc.)
3 BTMCOM; C:\Windows\System32\Drivers\BTMCOM.sys [52736 2010-06-30] (Motorola, Inc.)
3 BTMUSB; C:\Windows\System32\Drivers\BTMUSB.sys [484096 2010-10-26] (Motorola, Inc.)
3 clwvd; C:\Windows\System32\Drivers\clwvd.sys [31088 2010-09-03] (CyberLink Corporation)
1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [254528 2011-07-19] (DT Soft Ltd)
1 DVMIO; C:\Windows\System32\Drivers\DVMIO.sys [20056 2009-11-11] (DeviceVM, Inc.)
3 hamachi; C:\Windows\System32\Drivers\hamachi.sys [33856 2009-03-18] (LogMeIn, Inc.)
3 libusb0; C:\Windows\SysWow64\Drivers\libusb0.sys [33792 2005-03-09] ()
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
2 MySQL; "C:\Program Files (x86)\MySQL\MySQL Server 5.5\bin\mysqld" --defaults-file="C:\Program Files (x86)\MySQL\MySQL Server 5.5\my.ini" MySQL [8924 2011-05-24] ()
3 RSUSBSTOR; C:\Windows\System32\Drivers\RtsUStor.sys [247400 2010-07-20] (Realtek Semiconductor Corp.)
1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
========================== NetSvcs (Whitelisted) ===========
============ One Month Created Files and Folders ==============
2012-06-21 11:22 - 2012-06-21 11:22 - 00262144 ____A C:\Windows\Minidump\062112-44226-01.dmp
2012-06-21 10:09 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 10:09 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 10:09 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 10:09 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 10:08 - 2012-06-02 12:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 10:08 - 2012-06-02 12:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-21 10:03 - 2012-06-21 10:03 - 04731392 ____A (AVAST Software) C:\Users\
[username]\Downloads\aswMBR.exe
2012-06-17 15:36 - 2012-06-17 17:36 - 00014689 ____A C:\Users\
[username]\Documents\Joseph Tares.WoD
2012-06-17 03:07 - 2012-06-17 03:07 - 00001417 ____A C:\Users\
[username]\Documents\fountain.txt
2012-06-16 20:38 - 2012-06-16 20:38 - 00028532 ____A C:\Users\
[username]\Documents\DDS (again).txt
2012-06-16 20:37 - 2012-06-16 20:37 - 00013879 ____A C:\Users\
[username]\Documents\Attach (again).txt
2012-06-13 09:14 - 2012-05-17 18:47 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-13 09:14 - 2012-05-17 18:16 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-13 09:14 - 2012-05-17 18:06 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-13 09:14 - 2012-05-17 17:59 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-13 09:14 - 2012-05-17 17:59 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-13 09:14 - 2012-05-17 17:58 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-13 09:14 - 2012-05-17 17:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-13 09:14 - 2012-05-17 17:56 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-13 09:14 - 2012-05-17 17:55 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-13 09:14 - 2012-05-17 17:55 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-13 09:14 - 2012-05-17 17:54 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-13 09:14 - 2012-05-17 17:51 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-13 09:14 - 2012-05-17 17:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-13 09:14 - 2012-05-17 17:47 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-13 09:14 - 2012-05-17 15:11 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-13 09:14 - 2012-05-17 14:48 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-13 09:14 - 2012-05-17 14:45 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-13 09:14 - 2012-05-17 14:36 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-13 09:14 - 2012-05-17 14:35 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-13 09:14 - 2012-05-17 14:35 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-13 09:14 - 2012-05-17 14:33 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-13 09:14 - 2012-05-17 14:31 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-13 09:14 - 2012-05-17 14:29 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-13 09:14 - 2012-05-17 14:29 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-13 09:14 - 2012-05-17 14:27 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-13 09:14 - 2012-05-17 14:25 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-13 09:14 - 2012-05-17 14:24 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-13 09:14 - 2012-05-17 14:20 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-12 13:45 - 2012-05-14 17:32 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-12 13:45 - 2012-05-04 03:06 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-06-12 13:45 - 2012-05-04 02:03 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-06-12 13:45 - 2012-04-30 21:40 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-06-12 13:45 - 2012-04-25 21:41 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-06-12 13:45 - 2012-04-25 21:41 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-06-12 13:45 - 2012-04-25 21:34 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-06-12 13:44 - 2012-05-04 02:03 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-06-12 13:44 - 2012-04-27 19:55 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-06-12 13:44 - 2012-04-23 21:37 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-06-12 13:44 - 2012-04-23 21:37 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-06-12 13:44 - 2012-04-23 21:37 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-06-12 13:44 - 2012-04-23 20:36 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-06-12 13:44 - 2012-04-23 20:36 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-06-12 13:44 - 2012-04-23 20:36 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-06-12 13:44 - 2012-04-07 04:31 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-06-12 13:44 - 2012-04-07 03:26 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-06-11 19:32 - 2012-06-11 19:32 - 00004316 ____A C:\Users\
[username]\Desktop\Attach.zip
2012-06-11 19:31 - 2012-06-11 19:31 - 00012257 ____A C:\Users\
[username]\Desktop\Attach - original.txt
2012-06-11 19:03 - 2012-06-11 19:32 - 00012108 ____A C:\Users\
[username]\Desktop\Attach.txt
2012-06-11 19:03 - 2012-06-11 19:03 - 00027377 ____A C:\Users\
[username]\Desktop\DDS.txt
2012-06-11 18:52 - 2012-06-11 18:52 - 00607260 ____R (Swearware) C:\Users\
[username]\Desktop\dds.scr
2012-06-11 18:51 - 2012-06-11 18:51 - 00000558 ____A C:\Users\
[username]\Desktop\defogger_disable.log
2012-06-11 18:51 - 2012-06-11 18:51 - 00000168 ____A C:\Users\
[username]\defogger_reenable
2012-06-11 18:49 - 2012-06-11 18:49 - 00050477 ____A C:\Users\
[username]\Desktop\Defogger.exe
2012-06-09 23:00 - 2012-06-09 23:00 - 00000402 ____A C:\Users\
[username]\Documents\randomyszzg.txt
2012-06-09 08:36 - 2012-06-09 08:36 - 00000411 ____A C:\Users\
[username]\Documents\gmer.log
2012-06-09 04:05 - 2012-06-09 04:05 - 00302592 ____A C:\Users\
[username]\Downloads\wf53e7c4.exe
2012-06-09 03:44 - 2012-06-09 03:44 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-09 03:44 - 2012-04-04 12:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-09 03:42 - 2012-06-09 03:42 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\
[username]\Downloads\yabbadabado.exe
2012-06-08 23:35 - 2012-06-08 23:35 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\SUPERAntiSpyware.com
2012-06-08 23:33 - 2012-06-08 23:35 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-06-08 23:33 - 2012-06-08 23:33 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-06-08 23:33 - 2012-06-08 23:33 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-06-08 23:19 - 2012-06-08 23:19 - 00000992 ____A C:\Users\
[username]\Documents\checkup.txt
2012-06-08 23:18 - 2012-06-08 23:18 - 17578952 ____A (SUPERAntiSpyware.com) C:\Users\
[username]\Downloads\SUPERAntiSpyware.exe
2012-06-08 22:55 - 2012-06-08 22:56 - 00853862 ____A C:\Users\
[username]\Desktop\SecurityCheck.exe
2012-06-08 15:41 - 2012-06-08 15:41 - 00024923 ____A C:\Users\
[username]\Documents\rep.png
2012-06-05 13:02 - 2012-06-05 13:02 - 02153416 ____A C:\Users\
[username]\Documents\sidesmoines.png
2012-06-04 23:58 - 2012-06-04 23:58 - 00003369 ____A C:\Users\
[username]\.recently-used.xbel
2012-06-04 15:33 - 2012-06-04 15:33 - 00000220 ____A C:\Users\
[username]\Desktop\Garry's Mod.url
2012-06-04 14:05 - 2012-06-04 14:05 - 00750827 ____A C:\Users\
[username]\Downloads\1521.png
2012-06-03 17:09 - 2012-06-03 17:10 - 00480088 ____A C:\Users\
[username]\Downloads\4ch5.png
2012-06-03 10:45 - 2012-06-03 10:45 - 00035637 ____A C:\Users\
[username]\Documents\Suzu - Act 2.7 - Fill Your Eyes.txt
2012-06-03 10:44 - 2012-06-03 10:44 - 00044436 ____A C:\Users\
[username]\Documents\Suzu - Act 2.6 - Look Both Ways - Gold Coast Hustle.txt
2012-06-03 10:43 - 2012-06-03 10:43 - 00029284 ____A C:\Users\
[username]\Documents\Suzu - Act 2.4 - I Can See It In Your Face.txt
2012-06-03 10:43 - 2012-06-03 10:43 - 00022367 ____A C:\Users\
[username]\Documents\Suzu - Act 2.5 - Dark As The Sky.txt
2012-06-03 10:42 - 2012-06-03 10:42 - 00017525 ____A C:\Users\
[username]\Documents\Suzu - Act 2.3 - Someday Is Everyday.txt
2012-06-03 10:42 - 2012-06-03 10:42 - 00011390 ____A C:\Users\
[username]\Documents\Suzu - Act 2.2 - Maybe Tomorrow.txt
2012-06-03 10:40 - 2012-06-03 10:40 - 00016445 ____A C:\Users\
[username]\Documents\Suzu - Act 2.1 - Pop Quiz - Gazing At The Glare.txt
2012-06-03 10:39 - 2012-06-03 10:39 - 00022897 ____A C:\Users\
[username]\Documents\Suzu - Act 1.1 - Who Loves Me.txt
2012-06-03 10:38 - 2012-06-03 10:49 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Nitro PDF
2012-06-03 10:38 - 2012-06-03 10:38 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\FileOpen
2012-06-03 10:38 - 2012-06-03 10:38 - 00000000 ____D C:\Users\All Users\FileOpen
2012-06-03 10:37 - 2012-06-03 10:37 - 00002019 ____A C:\Users\Public\Desktop\Nitro Pro 7.lnk
2012-06-03 10:37 - 2012-05-16 12:32 - 00029704 ____A (Nitro PDF Software) C:\Windows\System32\nitrolocalmon2.dll
2012-06-03 10:37 - 2012-05-16 12:32 - 00017928 ____A (Nitro PDF Software) C:\Windows\System32\nitrolocalui2.dll
2012-06-03 10:36 - 2012-06-03 10:36 - 00000000 ____D C:\Users\All Users\Nitro PDF
2012-06-03 10:36 - 2012-06-03 10:36 - 00000000 ____D C:\Program Files\Common Files\Nitro PDF
2012-06-03 10:36 - 2012-06-03 10:36 - 00000000 ____D C:\Program Files (x86)\Nitro PDF
2012-06-03 10:34 - 2012-06-03 10:34 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Downloaded Installations
2012-06-03 10:32 - 2012-06-03 10:32 - 58803048 ____A (Nitro PDF Software) C:\Users\
[username]\Downloads\nitro_pdf_professional7_x64.exe
2012-06-01 23:13 - 2012-06-01 23:13 - 00001859 ____A C:\Users\
[username]\Downloads\rin test.png
2012-06-01 23:02 - 2012-06-01 23:02 - 00000000 ____D C:\Users\
[username]\Documents\rinbin
2012-05-31 22:58 - 2012-05-31 22:58 - 00000000 ____D C:\Users\
[username]\AppData\Local\2DBoy
2012-05-31 22:58 - 2012-05-31 22:58 - 00000000 ____D C:\Users\All Users\2DBoy
2012-05-31 22:55 - 2012-05-31 22:55 - 00000221 ____A C:\Users\
[username]\Desktop\World of Goo.url
2012-05-30 14:44 - 2012-05-30 15:15 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Golly
2012-05-30 14:43 - 2012-05-30 14:43 - 00000000 ____D C:\Users\
[username]\Documents\Golly
2012-05-29 08:25 - 2012-05-29 08:25 - 00000000 ____D C:\Users\
[username]\AppData\Local\{9A5D93C7-192A-4434-8EE6-65F9E23673EF}
2012-05-27 20:36 - 2012-05-27 20:36 - 00012027 ____A C:\Users\
[username]\Documents\Asher.WoD
2012-05-25 03:44 - 2012-05-25 03:46 - 00000000 ____D C:\Program Files (x86)\Katawa Shoujo
2012-05-25 03:39 - 2012-05-25 03:43 - 441375029 ____A C:\Users\
[username]\[4ls]_katawa_shoujo_[windows][C3798628].exe
============ 3 Months Modified Files and Folders =============
2012-06-22 01:27 - 2012-06-22 01:27 - 00000000 ____D C:\FRST
2012-06-21 22:20 - 2009-07-13 20:51 - 00054388 ____A C:\Windows\setupact.log
2012-06-21 22:15 - 2011-05-12 23:39 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\ZumoDrive
2012-06-21 22:15 - 2011-04-20 23:58 - 01747345 ____A C:\Windows\WindowsUpdate.log
2012-06-21 22:11 - 2009-07-13 21:13 - 00791694 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-21 21:33 - 2012-05-11 14:01 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-06-21 21:19 - 2012-03-06 21:07 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-06-21 19:19 - 2012-03-06 21:07 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-06-21 18:01 - 2012-02-23 19:17 - 00000000 ____D C:\Program Files (x86)\Steam
2012-06-21 17:55 - 2011-11-09 18:12 - 00000000 ____D C:\Users\
[username]\AppData\Local\Akamai
2012-06-21 14:22 - 2011-09-24 18:17 - 00000000 ____D C:\Users\All Users\BOINC
2012-06-21 12:56 - 2011-05-23 15:37 - 00000000 ____D C:\Users\
[username]\AppData\Local\CrashDumps
2012-06-21 12:37 - 2012-03-11 12:38 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Skype
2012-06-21 11:34 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-21 11:34 - 2009-07-13 20:45 - 00023248 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-21 11:31 - 2011-09-24 17:48 - 00000364 ____A C:\Windows\Tasks\HPCeeScheduleFor
[username].job
2012-06-21 11:31 - 2011-05-04 15:15 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-06-21 11:25 - 2012-01-07 12:47 - 00000000 ____D C:\Users\
[username]\AppData\Local\LogMeIn Hamachi
2012-06-21 11:23 - 2011-05-02 18:36 - 00000314 ____A C:\Users\
[username]\AppData\Local\mv_Photo.xml
2012-06-21 11:23 - 2011-05-02 18:36 - 00000155 ____A C:\Users\
[username]\AppData\Local\mv_music.xml
2012-06-21 11:23 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-21 11:22 - 2012-06-21 11:22 - 00262144 ____A C:\Windows\Minidump\062112-44226-01.dmp
2012-06-21 11:22 - 2012-05-07 18:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2012-06-21 11:22 - 2011-08-09 13:56 - 831496460 ____A C:\Windows\MEMORY.DMP
2012-06-21 11:22 - 2011-08-09 13:56 - 00000000 ____D C:\Windows\Minidump
2012-06-21 10:03 - 2012-06-21 10:03 - 04731392 ____A (AVAST Software) C:\Users\
[username]\Downloads\aswMBR.exe
2012-06-20 14:45 - 2011-05-02 18:23 - 00000000 ____D C:\users\
[username]2012-06-20 14:45 - 2010-12-13 16:21 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2012-06-20 14:42 - 2009-09-06 16:40 - 00000000 ____D C:\SwSetup
2012-06-19 06:42 - 2011-05-16 18:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2012-06-17 17:36 - 2012-06-17 15:36 - 00014689 ____A C:\Users\
[username]\Documents\Joseph Tares.WoD
2012-06-17 03:07 - 2012-06-17 03:07 - 00001417 ____A C:\Users\
[username]\Documents\fountain.txt
2012-06-16 20:38 - 2012-06-16 20:38 - 00028532 ____A C:\Users\
[username]\Documents\DDS (again).txt
2012-06-16 20:37 - 2012-06-16 20:37 - 00013879 ____A C:\Users\
[username]\Documents\Attach (again).txt
2012-06-13 12:11 - 2009-07-13 20:45 - 00528896 ____A C:\Windows\System32\FNTCACHE.DAT
2012-06-13 09:52 - 2011-05-09 15:27 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-06-13 09:33 - 2012-02-04 10:56 - 58957832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-06-11 19:32 - 2012-06-11 19:32 - 00004316 ____A C:\Users\
[username]\Desktop\Attach.zip
2012-06-11 19:32 - 2012-06-11 19:03 - 00012108 ____A C:\Users\
[username]\Desktop\Attach.txt
2012-06-11 19:31 - 2012-06-11 19:31 - 00012257 ____A C:\Users\
[username]\Desktop\Attach - original.txt
2012-06-11 19:03 - 2012-06-11 19:03 - 00027377 ____A C:\Users\
[username]\Desktop\DDS.txt
2012-06-11 18:52 - 2012-06-11 18:52 - 00607260 ____R (Swearware) C:\Users\
[username]\Desktop\dds.scr
2012-06-11 18:51 - 2012-06-11 18:51 - 00000558 ____A C:\Users\
[username]\Desktop\defogger_disable.log
2012-06-11 18:51 - 2012-06-11 18:51 - 00000168 ____A C:\Users\
[username]\defogger_reenable
2012-06-11 18:49 - 2012-06-11 18:49 - 00050477 ____A C:\Users\
[username]\Desktop\Defogger.exe
2012-06-09 23:00 - 2012-06-09 23:00 - 00000402 ____A C:\Users\
[username]\Documents\randomyszzg.txt
2012-06-09 08:36 - 2012-06-09 08:36 - 00000411 ____A C:\Users\
[username]\Documents\gmer.log
2012-06-09 04:05 - 2012-06-09 04:05 - 00302592 ____A C:\Users\
[username]\Downloads\wf53e7c4.exe
2012-06-09 03:45 - 2011-05-23 16:53 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-09 03:44 - 2012-06-09 03:44 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-09 03:42 - 2012-06-09 03:42 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\
[username]\Downloads\yabbadabado.exe
2012-06-09 03:33 - 2011-04-21 00:13 - 00334588 ____A C:\Windows\PFRO.log
2012-06-09 03:31 - 2011-05-05 14:32 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\BitTorrent
2012-06-08 23:35 - 2012-06-08 23:35 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\SUPERAntiSpyware.com
2012-06-08 23:35 - 2012-06-08 23:33 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2012-06-08 23:33 - 2012-06-08 23:33 - 00001808 ____A C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2012-06-08 23:33 - 2012-06-08 23:33 - 00000000 ____D C:\Users\All Users\SUPERAntiSpyware.com
2012-06-08 23:19 - 2012-06-08 23:19 - 00000992 ____A C:\Users\
[username]\Documents\checkup.txt
2012-06-08 23:18 - 2012-06-08 23:18 - 17578952 ____A (SUPERAntiSpyware.com) C:\Users\
[username]\Downloads\SUPERAntiSpyware.exe
2012-06-08 22:56 - 2012-06-08 22:55 - 00853862 ____A C:\Users\
[username]\Desktop\SecurityCheck.exe
2012-06-08 15:41 - 2012-06-08 15:41 - 00024923 ____A C:\Users\
[username]\Documents\rep.png
2012-06-05 13:02 - 2012-06-05 13:02 - 02153416 ____A C:\Users\
[username]\Documents\sidesmoines.png
2012-06-04 23:58 - 2012-06-04 23:58 - 00003369 ____A C:\Users\
[username]\.recently-used.xbel
2012-06-04 23:58 - 2011-05-25 19:07 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\gtk-2.0
2012-06-04 23:58 - 2011-05-25 18:58 - 00000000 ____D C:\Users\
[username]\.gimp-2.6
2012-06-04 15:33 - 2012-06-04 15:33 - 00000220 ____A C:\Users\
[username]\Desktop\Garry's Mod.url
2012-06-04 14:05 - 2012-06-04 14:05 - 00750827 ____A C:\Users\
[username]\Downloads\1521.png
2012-06-03 21:03 - 2011-05-23 17:05 - 00000348 ____A C:\Windows\Tasks\HPCeeScheduleFor
[name]_LAPTOP$.job
2012-06-03 17:10 - 2012-06-03 17:09 - 00480088 ____A C:\Users\
[username]\Downloads\4ch5.png
2012-06-03 10:49 - 2012-06-03 10:38 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Nitro PDF
2012-06-03 10:45 - 2012-06-03 10:45 - 00035637 ____A C:\Users\
[username]\Documents\Suzu - Act 2.7 - Fill Your Eyes.txt
2012-06-03 10:44 - 2012-06-03 10:44 - 00044436 ____A C:\Users\
[username]\Documents\Suzu - Act 2.6 - Look Both Ways - Gold Coast Hustle.txt
2012-06-03 10:43 - 2012-06-03 10:43 - 00029284 ____A C:\Users\
[username]\Documents\Suzu - Act 2.4 - I Can See It In Your Face.txt
2012-06-03 10:43 - 2012-06-03 10:43 - 00022367 ____A C:\Users\
[username]\Documents\Suzu - Act 2.5 - Dark As The Sky.txt
2012-06-03 10:42 - 2012-06-03 10:42 - 00017525 ____A C:\Users\
[username]\Documents\Suzu - Act 2.3 - Someday Is Everyday.txt
2012-06-03 10:42 - 2012-06-03 10:42 - 00011390 ____A C:\Users\
[username]\Documents\Suzu - Act 2.2 - Maybe Tomorrow.txt
2012-06-03 10:40 - 2012-06-03 10:40 - 00016445 ____A C:\Users\
[username]\Documents\Suzu - Act 2.1 - Pop Quiz - Gazing At The Glare.txt
2012-06-03 10:39 - 2012-06-03 10:39 - 00022897 ____A C:\Users\
[username]\Documents\Suzu - Act 1.1 - Who Loves Me.txt
2012-06-03 10:38 - 2012-06-03 10:38 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\FileOpen
2012-06-03 10:38 - 2012-06-03 10:38 - 00000000 ____D C:\Users\All Users\FileOpen
2012-06-03 10:37 - 2012-06-03 10:37 - 00002019 ____A C:\Users\Public\Desktop\Nitro Pro 7.lnk
2012-06-03 10:36 - 2012-06-03 10:36 - 00000000 ____D C:\Users\All Users\Nitro PDF
2012-06-03 10:36 - 2012-06-03 10:36 - 00000000 ____D C:\Program Files\Common Files\Nitro PDF
2012-06-03 10:36 - 2012-06-03 10:36 - 00000000 ____D C:\Program Files (x86)\Nitro PDF
2012-06-03 10:34 - 2012-06-03 10:34 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Downloaded Installations
2012-06-03 10:32 - 2012-06-03 10:32 - 58803048 ____A (Nitro PDF Software) C:\Users\
[username]\Downloads\nitro_pdf_professional7_x64.exe
2012-06-02 14:19 - 2012-06-21 10:09 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 10:09 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 10:09 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:15 - 2012-06-21 10:09 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 12:19 - 2012-06-21 10:08 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 12:15 - 2012-06-21 10:08 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 23:13 - 2012-06-01 23:13 - 00001859 ____A C:\Users\
[username]\Downloads\rin test.png
2012-06-01 23:02 - 2012-06-01 23:02 - 00000000 ____D C:\Users\
[username]\Documents\rinbin
2012-05-31 22:58 - 2012-05-31 22:58 - 00000000 ____D C:\Users\
[username]\AppData\Local\2DBoy
2012-05-31 22:58 - 2012-05-31 22:58 - 00000000 ____D C:\Users\All Users\2DBoy
2012-05-31 22:55 - 2012-05-31 22:55 - 00000221 ____A C:\Users\
[username]\Desktop\World of Goo.url
2012-05-31 11:45 - 2011-12-23 22:32 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\fotw
2012-05-30 15:15 - 2012-05-30 14:44 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Golly
2012-05-30 14:43 - 2012-05-30 14:43 - 00000000 ____D C:\Users\
[username]\Documents\Golly
2012-05-30 13:26 - 2011-10-26 15:20 - 00000000 ____A C:\Windows\System32\HP_ActiveX_Patch_NOT_DETECTED.txt
2012-05-29 18:50 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
2012-05-29 08:25 - 2012-05-29 08:25 - 00000000 ____D C:\Users\
[username]\AppData\Local\{9A5D93C7-192A-4434-8EE6-65F9E23673EF}
2012-05-27 21:01 - 2009-07-13 19:20 - 00000000 __RHD C:\Users\Public\Libraries
2012-05-27 20:36 - 2012-05-27 20:36 - 00012027 ____A C:\Users\
[username]\Documents\Asher.WoD
2012-05-25 12:17 - 2011-07-28 15:25 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\RenPy
2012-05-25 03:46 - 2012-05-25 03:44 - 00000000 ____D C:\Program Files (x86)\Katawa Shoujo
2012-05-25 03:43 - 2012-05-25 03:39 - 441375029 ____A C:\Users\
[username]\[4ls]_katawa_shoujo_[windows][C3798628].exe
2012-05-22 23:04 - 2012-05-22 23:02 - 00000000 ____D C:\Users\
[username]\The Salvation War Armageddon & Pantheocide
2012-05-20 15:00 - 2012-05-20 15:00 - 00000000 ____D C:\Users\
[username]\AppData\Local\{ED4BBF7B-2A4C-49E5-9F85-4F0B4C531867}
2012-05-18 00:22 - 2012-03-04 12:55 - 00000000 ____D C:\Users\
[username]\Documents\DriveThruRPG
2012-05-17 18:47 - 2012-06-13 09:14 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-05-17 18:16 - 2012-06-13 09:14 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-05-17 18:06 - 2012-06-13 09:14 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-05-17 17:59 - 2012-06-13 09:14 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-17 17:59 - 2012-06-13 09:14 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-05-17 17:58 - 2012-06-13 09:14 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-05-17 17:58 - 2012-06-13 09:14 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-05-17 17:56 - 2012-06-13 09:14 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-17 17:55 - 2012-06-13 09:14 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-05-17 17:55 - 2012-06-13 09:14 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-05-17 17:54 - 2012-06-13 09:14 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-05-17 17:51 - 2012-06-13 09:14 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-05-17 17:51 - 2012-06-13 09:14 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-05-17 17:47 - 2012-06-13 09:14 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-05-17 17:34 - 2012-05-17 16:28 - 02066077 ____A C:\Users\
[username]\Documents\Untitled.png
2012-05-17 15:11 - 2012-06-13 09:14 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-05-17 14:48 - 2012-06-13 09:14 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-05-17 14:45 - 2012-06-13 09:14 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-05-17 14:36 - 2012-06-13 09:14 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-05-17 14:35 - 2012-06-13 09:14 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-05-17 14:35 - 2012-06-13 09:14 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-17 14:33 - 2012-06-13 09:14 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-05-17 14:31 - 2012-06-13 09:14 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-17 14:29 - 2012-06-13 09:14 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-05-17 14:29 - 2012-06-13 09:14 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-05-17 14:27 - 2012-06-13 09:14 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-05-17 14:25 - 2012-06-13 09:14 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-05-17 14:24 - 2012-06-13 09:14 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-05-17 14:20 - 2012-06-13 09:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-05-16 12:33 - 2012-05-16 12:33 - 00069640 ____A (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
2012-05-16 12:32 - 2012-06-03 10:37 - 00029704 ____A (Nitro PDF Software) C:\Windows\System32\nitrolocalmon2.dll
2012-05-16 12:32 - 2012-06-03 10:37 - 00017928 ____A (Nitro PDF Software) C:\Windows\System32\nitrolocalui2.dll
2012-05-15 14:01 - 2012-05-11 14:01 - 00002054 ____A C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2012-05-15 14:01 - 2012-05-11 14:01 - 00000000 ____D C:\Program Files (x86)\McAfee Security Scan
2012-05-14 17:32 - 2012-06-12 13:45 - 03146752 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-11 18:15 - 2012-05-11 18:15 - 08769696 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2012-05-11 18:15 - 2012-05-11 14:01 - 00419488 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-05-11 18:15 - 2011-05-12 22:33 - 00070304 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-05-11 14:01 - 2012-05-11 14:01 - 00000000 ____D C:\Windows\System32\Macromed
2012-05-11 14:01 - 2012-05-11 14:01 - 00000000 ____D C:\Users\All Users\McAfee Security Scan
2012-05-11 14:01 - 2012-05-11 14:01 - 00000000 ____D C:\Users\All Users\McAfee
2012-05-10 12:54 - 2010-12-13 16:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-08 19:05 - 2012-05-08 19:05 - 00000000 ____D C:\Users\
[username]\AppData\Local\{532D9B8B-1BD0-47C6-83BB-36721FCD265D}
2012-05-07 19:10 - 2011-06-11 20:51 - 00000000 ____D C:\Users\
[username]\.cream
2012-05-07 18:18 - 2012-05-07 18:18 - 00000000 ____D C:\Users\All Users\Mozilla
2012-05-07 18:16 - 2012-05-07 18:16 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Apple Computer
2012-05-05 12:25 - 2012-05-05 12:23 - 169487783 ____A (Acresso Software Inc.) C:\Users\
[username]\Downloads\worldtool.exe
2012-05-04 03:06 - 2012-06-12 13:45 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 13:45 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-12 13:44 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-02 22:19 - 2012-05-02 22:13 - 00000132 ____A C:\Users\
[username]\Documents\ifglitchthenremove.txt
2012-04-30 21:40 - 2012-06-12 13:45 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-27 19:55 - 2012-06-12 13:44 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-27 13:33 - 2012-04-27 13:33 - 02238732 ____A C:\Users\
[username]\Downloads\nWoD Framework - Jamz.cmpgn
2012-04-27 13:29 - 2012-04-27 13:29 - 03636877 ____A C:\Users\
[username]\Downloads\nWoD Framework 0_4_1(1).cmpgn
2012-04-27 13:17 - 2012-01-05 23:02 - 00000000 ____D C:\Users\
[username]\AppData\Local\Deployment
2012-04-27 13:15 - 2011-07-29 12:25 - 00000000 ____D C:\Users\
[username]\Desktop\New Folder
2012-04-26 19:02 - 2012-04-26 18:41 - 03643742 ____A C:\Users\
[username]\Downloads\nWoD Framework 0_4_1.cmpgn
2012-04-26 18:42 - 2012-04-26 18:22 - 00000000 ____D C:\Users\
[username]\.maptool
2012-04-26 18:22 - 2012-04-26 18:22 - 00002037 ____A C:\Users\
[username]\Desktop\RPTools MapTool.lnk
2012-04-26 18:21 - 2012-04-26 18:21 - 00003365 ____A C:\Users\
[username]\Downloads\MapTool-13b84-512m-2m(1).jnlp
2012-04-26 18:19 - 2012-04-26 18:19 - 00157472 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe
2012-04-26 18:19 - 2012-04-26 18:19 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe
2012-04-26 18:19 - 2012-04-26 18:19 - 00149280 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe
2012-04-26 18:19 - 2010-12-13 17:01 - 00472808 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll
2012-04-26 18:15 - 2012-04-26 18:15 - 00908576 ____A (Sun Microsystems, Inc.) C:\Users\
[username]\Downloads\jxpiinstall.exe
2012-04-26 18:12 - 2012-04-26 18:12 - 00003365 ____A C:\Users\
[username]\Downloads\MapTool-13b84-512m-2m.jnlp
2012-04-26 15:49 - 2012-04-20 23:35 - 00000000 ____D C:\Python26
2012-04-26 15:43 - 2012-04-26 15:43 - 03649536 ____A C:\Users\
[username]\Downloads\osu-gt-2.0-RC9.msi
2012-04-25 21:41 - 2012-06-12 13:45 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-12 13:45 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-12 13:45 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-12 13:44 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-12 13:44 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-12 13:44 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-12 13:44 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-12 13:44 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-12 13:44 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-23 16:46 - 2012-04-23 16:46 - 00001805 ____A C:\Users\Public\Desktop\QuickTime Player.lnk
2012-04-23 16:46 - 2012-04-23 16:45 - 00000000 ____D C:\Program Files (x86)\QuickTime
2012-04-23 16:45 - 2012-04-23 16:45 - 00000000 ____D C:\Users\All Users\Apple Computer
2012-04-23 16:42 - 2012-04-23 16:42 - 00000000 ____D C:\Users\
[username]\AppData\Local\Apple
2012-04-23 16:42 - 2012-04-23 16:42 - 00000000 ____D C:\Users\All Users\Apple
2012-04-23 16:42 - 2012-04-23 16:42 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2012-04-23 16:40 - 2012-04-23 16:33 - 39401336 ____A (Apple Inc.) C:\Users\
[username]\Downloads\QuickTimeInstaller.exe
2012-04-21 12:19 - 2012-04-20 23:41 - 00000000 ____D C:\Users\Public\OpenRPG
2012-04-21 11:04 - 2012-04-21 11:04 - 00002142 ____A C:\Users\Public\Desktop\Adobe Digital Editions.lnk
2012-04-21 11:04 - 2012-04-21 11:04 - 00000000 ____D C:\Users\
[username]\Documents\My Digital Editions
2012-04-21 11:04 - 2010-12-13 16:40 - 00000000 ____D C:\Program Files (x86)\Adobe
2012-04-20 23:41 - 2012-04-20 23:41 - 00001091 ____A C:\Users\
[username]\Desktop\OpenRPG.lnk
2012-04-20 23:06 - 2011-12-03 14:27 - 00000000 ____D C:\Program Files (x86)\FlexHEX
2012-04-20 22:57 - 2012-04-20 22:57 - 01531697 ____A C:\Users\
[username]\Downloads\OpenRPG1.8.0Vista.exe
2012-04-20 22:54 - 2012-01-06 01:17 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Notepad++
2012-04-20 22:54 - 2012-01-06 01:17 - 00000000 ____D C:\Program Files (x86)\Notepad++
2012-04-20 22:52 - 2011-08-22 13:25 - 00000000 ____D C:\Program Files (x86)\DNA2.0
2012-04-20 21:38 - 2011-06-18 16:16 - 00000000 ____D C:\AeriaGames
2012-04-20 21:30 - 2011-05-19 14:31 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Blender Foundation
2012-04-20 21:30 - 2011-05-19 14:31 - 00000000 ____D C:\Program Files (x86)\Blender Foundation
2012-04-20 21:28 - 2012-03-08 20:24 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Google
2012-04-20 21:27 - 2012-03-08 20:06 - 00000000 ____D C:\Program Files (x86)\Pidgin
2012-04-20 19:21 - 2012-04-13 15:03 - 00000000 ____D C:\Users\
[username]\Documents\Scores
2012-04-15 16:11 - 2011-05-02 18:32 - 00121552 ____A C:\Users\
[username]\AppData\Local\GDIPFONTCACHEV1.DAT
2012-04-15 16:09 - 2012-04-15 16:09 - 00262144 ____A C:\Windows\Minidump\041512-48141-01.dmp
2012-04-13 15:27 - 2012-04-13 15:27 - 00000604 ___AH C:\Program Files (x86)\_Z2
2012-04-13 15:27 - 2012-04-13 14:59 - 00000000 ____D C:\Users\
[username]\AppData\Roaming\Avid
2012-04-13 15:25 - 2012-04-13 14:59 - 00000000 ____D C:\Users\All Users\Avid
2012-04-13 15:04 - 2012-04-13 14:59 - 00000000 ____D C:\Program Files (x86)\Avid
2012-04-13 15:03 - 2012-04-13 15:03 - 00000925 ____A C:\Users\Public\Desktop\Sibelius 7.lnk
2012-04-13 15:03 - 2012-04-13 15:03 - 00000000 ____D C:\Program Files\Common Files\Propellerhead Software
2012-04-13 15:00 - 2012-04-13 14:59 - 00000000 ____D C:\Users\Public\Documents\Sibelius Example Scores
2012-04-13 14:59 - 2012-04-13 14:59 - 00000000 ____D C:\Program Files\Avid
2012-04-13 14:55 - 2012-04-13 14:41 - 545700520 ____A (Avid ) C:\Users\
[username]\Downloads\Sibelius712b46.exe
2012-04-11 14:48 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-04-07 04:31 - 2012-06-12 13:44 - 03216384 ____A (Microsoft Corporation) C:\Windows\System32\msi.dll
2012-04-07 03:26 - 2012-06-12 13:44 - 02342400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2012-04-06 18:57 - 2012-04-06 18:57 - 00705038 ____A C:\Users\
[username]\Downloads\background.xcf
2012-04-06 18:01 - 2012-04-06 18:01 - 00000000 ____D C:\Program Files (x86)\MediaFire
2012-04-06 18:01 - 2012-04-06 18:00 - 04353512 ____A C:\Users\
[username]\Downloads\MediaFireToolbar-1.0.2.3-setup.exe
2012-04-04 12:56 - 2012-06-09 03:44 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-04-01 15:51 - 2012-04-01 12:12 - 00000000 ____D C:\Program Files (x86)\The Elder Scrolls V Skyrim
2012-04-01 15:20 - 2012-04-01 15:20 - 06709514 ____A C:\Users\
[username]\The.Elder.Scrolls.V.Skyrim-Razor1911-[BTARENA.org]-CrackOnly.rar
2012-04-01 13:13 - 2012-04-01 13:13 - 00002058 ____A C:\Users\Public\Desktop\FXAA Tool.lnk
2012-04-01 13:12 - 2012-04-01 13:11 - 00295316 ____A () C:\Users\
[username]\Downloads\Post_Process_Injector_2_1_Installer-131-2-1.exe
2012-04-01 12:58 - 2012-04-01 12:58 - 00000000 ____D C:\Users\
[username]\AppData\Local\Skyrim
2012-04-01 12:58 - 2011-07-30 09:21 - 00000000 ____D C:\Users\
[username]\Documents\My Games
2012-04-01 12:23 - 2010-12-13 16:38 - 00198102 ____A C:\Windows\DirectX.log
2012-04-01 12:05 - 2012-04-01 10:18 - 00000000 ____D C:\Users\
[username]\The_Elder_Scrolls_V_Skyrim-Razor1911
2012-03-31 19:01 - 2011-08-13 19:47 - 00000000 ____D C:\Program Files\Construct 2
2012-03-31 18:59 - 2012-03-06 21:06 - 00000000 ____D C:\Program Files (x86)\Google
2012-03-31 18:55 - 2010-12-13 17:01 - 00000000 ____D C:\Program Files (x86)\Java
2012-03-30 03:35 - 2012-05-08 12:21 - 01918320 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-29 12:24 - 2011-10-12 15:59 - 00785910 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
========================= Known DLLs (Whitelisted) ============
========================= Bamital & volsnap Check ============
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
========================= Memory info ======================
Percentage of memory in use: 11%
Total physical RAM: 7785.9 MB
Available physical RAM: 6893.55 MB
Total Pagefile: 7784.05 MB
Available Pagefile: 6887.82 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
======================= Partitions =========================
1 Drive c: () (Fixed) (Total:446.3 GB) (Free:227.85 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (RECOVERY) (Fixed) (Total:19.16 GB) (Free:2.42 GB) NTFS
3 Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
4 Drive g: () (Removable) (Total:3.74 GB) (Free:3.18 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 465 GB 0 B
Disk 1 Online 3827 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 199 MB 1024 KB
Partition 2 Primary 446 GB 200 MB
Partition 3 Primary 19 GB 446 GB
Partition 4 Primary 103 MB 465 GB
======================================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 0 Y SYSTEM NTFS Partition 199 MB Healthy
======================================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 446 GB Healthy
======================================================================================================
Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 E RECOVERY NTFS Partition 19 GB Healthy
======================================================================================================
Disk: 0
Partition 4
Type : 0C
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F HP_TOOLS FAT32 Partition 103 MB Healthy
======================================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3826 MB 16 KB
======================================================================================================
Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT32 Removable 3826 MB Healthy
======================================================================================================
==========================================================
Last Boot: 2012-04-20 11:50
======================= End Of Log ==========================