Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2014 Ran by Kristen (administrator) on KBROZELL on 11-03-2014 23:09:14 Running from C:\Users\Kristen\Downloads Windows 8.1 (X64) OS Language: English(US) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (SUPERAntiSpyware.com) C:\Program Files (x86)\SUPERAntiSpyware\SASCORE.EXE (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\WINDOWS\system32\dashost.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe (SUPERAntiSpyware) C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (Nikon Corporation) C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe (Bose Corporation) C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Intel Corporation) C:\WINDOWS\system32\DptfParticipantProcessorService.exe (Intel Corporation) C:\WINDOWS\system32\DptfPolicyLpmService.exe (Intel Corporation) C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe (Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\viaaud.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (VIA Technologies, Inc.) C:\WINDOWS\system32\viakaraokesrv.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS VivoBook\ASUSWakeupService.exe (ASUSTeK Computer Inc.) C:\Program Files\ASUS\ASUS VivoBook\VivoBook.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe () C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\WINDOWS\system32\wbem\WMIADAP.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [mcui_exe] - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2011-03-09] (CyberLink) HKLM-x32\...\Run: [Nikon Message Center 2] - C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation) HKLM-x32\...\Run: [AgentMonitor] - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-19] () HKLM-x32\...\Run: [ATLauncher] - "C:\Program Files\McAfee\MSC\OOBE\ATLauncher.exe" /createshortcuts:1 HKLM-x32\...\Run: [SoundTouch Music Server] - C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch music server.exe [1315328 2013-12-09] (Bose Corporation) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-541397282-4190240310-1865117955-1001\...\Run: [Power2GoExpress] - [X] HKU\S-1-5-21-541397282-4190240310-1865117955-1001\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-541397282-4190240310-1865117955-1001\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-541397282-4190240310-1865117955-1001\...\Run: [AppleIEDAV] - C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1326408 2013-11-15] (Apple Inc.) HKU\S-1-5-21-541397282-4190240310-1865117955-1001\...\Run: [SUPERAntiSpyware] - C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe [5625624 2014-01-06] (SUPERAntiSpyware) Startup: C:\Users\Kristen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - {46197f3d-30e7-4905-a14b-02bee3aaeb58} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZR^xdm603^YY^us&ptb=C4345DCD-E9F6-402C-AE8A-3DB9C9E0B4F8&ind=2013012704&n=77fc22e0&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {46197f3d-30e7-4905-a14b-02bee3aaeb58} URL = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^ZR^xdm603^YY^us&ptb=C4345DCD-E9F6-402C-AE8A-3DB9C9E0B4F8&ind=2013012704&n=77fc22e0&psa=&st=sb&searchfor={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) ShellExecuteHooks-x32: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files (x86)\SUPERAntiSpyware\SASSEH.DLL [115440 2013-05-07] (SuperAdBlocker.com) Tcpip\Parameters: [DhcpNameServer] 192.168.227.1 Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.146\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File CHR Extension: (Google Docs) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-01-25] CHR Extension: (Google Drive) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-01-25] CHR Extension: (YouTube) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-25] CHR Extension: (Google Search) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-25] CHR Extension: (Google Wallet) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21] CHR Extension: (Gmail) - C:\Users\Kristen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-25] ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files (x86)\SUPERAntiSpyware\SASCORE.EXE [120088 2013-10-10] (SUPERAntiSpyware.com) R3 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) R3 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [30080 2012-09-30] (Intel Corporation) R3 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [37760 2012-09-30] (Intel Corporation) R3 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation) R3 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R3 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193576 2012-07-30] (Intel Corporation) R3 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R3 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-10-22] (VIA Technologies, Inc.) R3 WakeupService; C:\Program Files\ASUS\ASUS VivoBook\ASUSWakeupService.exe [42336 2012-11-16] (ASUSTek Computer Inc.) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S3 ASUSProcObsrv; C:\eSupport\eDriver\I386\AsPrOb64.sys [12416 2010-05-25] () S3 ATP; C:\Windows\System32\drivers\AsusTP.sys [62848 2012-11-20] (ASUS Corporation) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Windows (R) Win 7 DDK provider) R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [107328 2012-09-30] (Intel Corporation) R3 DptfDevFan; C:\Windows\system32\DRIVERS\DptfDevFan.sys [42816 2012-09-30] (Intel Corporation) R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [64832 2012-09-30] (Intel Corporation) R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96576 2012-09-30] (Intel Corporation) R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [229184 2012-09-30] (Intel Corporation) R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [363328 2012-09-30] (Intel Corporation) R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation) R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-09] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-10] (Microsoft Corporation) R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [43800 2012-07-30] (Intel Corporation) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-01] ( ) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106552 2013-02-19] (McAfee, Inc.) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) S1 SASDIFSV; C:\Program Files (x86)\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S1 SASKUTIL; C:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-25] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-25] (Microsoft Corporation) S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [15712 2013-02-11] () S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2013-08-22] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-11 23:09 - 2014-03-11 23:09 - 00017246 _____ () C:\Users\Kristen\Downloads\FRST.txt 2014-03-11 23:09 - 2014-03-11 23:09 - 00000000 ____D () C:\FRST 2014-03-11 23:07 - 2014-03-11 23:07 - 02157056 _____ (Farbar) C:\Users\Kristen\Downloads\FRST64.exe 2014-03-11 23:05 - 2014-03-11 23:05 - 00024375 _____ () C:\Users\Kristen\Desktop\Farbar_recovery_.htm 2014-03-11 23:03 - 2014-03-11 22:53 - 00017373 _____ () C:\Users\Kristen\Desktop\Farbar_recovery scan.htm 2014-03-10 18:30 - 2014-03-10 18:30 - 00000556 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 6da420b3-44ca-4cac-9a5d-c5787391bdf5.job 2014-03-10 18:30 - 2014-03-10 18:30 - 00000556 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 09aa1cef-9359-42d7-85d7-7ae9e89ac7e2.job 2014-03-10 18:30 - 2014-03-10 18:30 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\SUPERAntiSpyware.com 2014-03-10 18:28 - 2014-03-10 18:30 - 00000000 ____D () C:\Program Files (x86)\SUPERAntiSpyware 2014-03-10 18:28 - 2014-03-10 18:28 - 00002029 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk 2014-03-10 18:28 - 2014-03-10 18:28 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com 2014-03-09 15:10 - 2014-03-09 23:59 - 00001123 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-03-09 15:10 - 2014-03-09 23:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-09 15:10 - 2014-03-09 15:10 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Malwarebytes 2014-03-09 15:10 - 2014-03-09 15:10 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-09 15:10 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2014-03-07 06:31 - 2014-03-10 18:24 - 00000000 _____ () C:\Recovery.txt 2014-03-01 12:15 - 2014-03-01 12:15 - 00001797 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 12:15 - 2014-03-01 12:15 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 12:15 - 2014-03-01 12:15 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 12:15 - 2014-03-01 12:15 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 12:14 - 2014-03-01 12:15 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 11:55 - 2014-03-01 11:55 - 00001859 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-03-01 11:54 - 2014-03-01 11:55 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-02-18 13:53 - 2014-02-18 13:53 - 00000291 _____ () C:\Users\Kristen\Desktop\Fairbanks’ Best is top woman in Susitina 100 - Local-Community - Fairbanks Daily News-Miner.url 2014-02-17 01:37 - 2014-02-17 01:37 - 00025343 _____ () C:\Users\Kristen\Documents\su100_2014_skiers.xlsx 2014-02-16 16:41 - 2013-12-08 16:34 - 01227264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll 2014-02-16 16:41 - 2013-11-27 07:34 - 03210528 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2014-02-16 16:41 - 2013-11-27 07:27 - 00809872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2014-02-16 16:41 - 2013-11-27 06:00 - 00663680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2014-02-16 16:41 - 2013-11-27 05:47 - 02804528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2014-02-16 16:41 - 2013-11-27 04:02 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ipnat.sys 2014-02-16 16:41 - 2013-11-27 02:54 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll 2014-02-16 16:41 - 2013-11-27 02:24 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\msieftp.dll 2014-02-16 16:41 - 2013-11-27 01:41 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll 2014-02-16 16:41 - 2013-11-27 01:17 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2014-02-16 16:41 - 2013-11-27 01:10 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll 2014-02-16 16:41 - 2013-11-27 00:58 - 01503232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2014-02-16 16:41 - 2013-11-27 00:56 - 00218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll 2014-02-16 16:41 - 2013-11-26 05:22 - 01928144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2014-02-16 16:41 - 2013-11-26 05:20 - 02131120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2014-02-16 16:41 - 2013-11-26 05:20 - 01399176 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2014-02-16 16:41 - 2013-11-26 05:20 - 01374384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2014-02-16 16:41 - 2013-11-26 03:50 - 01371312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2014-02-16 16:41 - 2013-11-26 03:44 - 02142936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2014-02-16 16:41 - 2013-11-26 03:44 - 01204968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2014-02-16 16:41 - 2013-11-26 02:13 - 04191232 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-02-16 16:41 - 2013-11-26 01:21 - 18577920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2014-02-16 16:41 - 2013-11-26 00:28 - 13925888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2014-02-16 16:41 - 2013-11-24 17:45 - 00142680 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS 2014-02-16 16:41 - 2013-11-24 17:32 - 01119064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys 2014-02-16 16:41 - 2013-11-24 15:28 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll 2014-02-16 16:41 - 2013-11-23 04:47 - 00032088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ploptin.dll 2014-02-16 16:41 - 2013-11-23 03:49 - 21196664 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2014-02-16 16:41 - 2013-11-23 00:19 - 18642504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2014-02-16 16:41 - 2013-11-22 23:08 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2014-02-16 16:41 - 2013-11-22 20:50 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2014-02-16 16:41 - 2013-11-22 19:57 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2014-02-16 16:41 - 2013-11-22 19:48 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2014-02-16 16:41 - 2013-11-22 19:25 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2014-02-16 16:41 - 2013-11-22 19:25 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2014-02-16 16:41 - 2013-11-22 19:19 - 02617344 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2014-02-16 16:41 - 2013-11-22 19:15 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2014-02-16 16:41 - 2013-11-20 22:26 - 01415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-02-16 16:41 - 2013-11-15 21:11 - 00764856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2014-02-16 16:41 - 2013-11-15 10:19 - 00669344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2014-02-16 16:41 - 2013-11-15 06:59 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll 2014-02-16 16:41 - 2013-11-15 06:25 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll 2014-02-16 16:41 - 2013-11-15 06:08 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2014-02-16 16:41 - 2013-11-15 05:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2014-02-16 16:41 - 2013-11-05 12:12 - 02551128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2014-02-16 16:41 - 2013-10-30 16:29 - 00745336 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2014-02-16 16:41 - 2013-10-30 15:41 - 00552624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2014-02-16 16:40 - 2013-12-08 16:04 - 00980480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll 2014-02-16 16:40 - 2013-11-27 02:08 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll 2014-02-16 16:40 - 2013-11-27 01:46 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msieftp.dll 2014-02-16 16:40 - 2013-11-26 20:01 - 00385614 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2014-02-16 16:40 - 2013-11-24 15:30 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll 2014-02-16 16:40 - 2013-11-22 23:13 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\bi.dll 2014-02-16 16:40 - 2013-11-22 23:13 - 00019456 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys 2014-02-16 16:40 - 2013-11-20 22:58 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceregistration.dll 2014-02-12 21:38 - 2014-02-06 04:16 - 23170048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-02-12 21:38 - 2014-02-06 03:30 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2014-02-12 21:38 - 2014-02-06 03:30 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll 2014-02-12 21:38 - 2014-02-06 03:12 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-02-12 21:38 - 2014-02-06 03:07 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 2014-02-12 21:38 - 2014-02-06 03:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll 2014-02-12 21:38 - 2014-02-06 02:57 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2014-02-12 21:38 - 2014-02-06 02:56 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 2014-02-12 21:38 - 2014-02-06 02:49 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe 2014-02-12 21:38 - 2014-02-06 02:48 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2014-02-12 21:38 - 2014-02-06 02:48 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe 2014-02-12 21:38 - 2014-02-06 02:38 - 17103872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-02-12 21:38 - 2014-02-06 02:32 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-02-12 21:38 - 2014-02-06 02:20 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-02-12 21:38 - 2014-02-06 02:17 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll 2014-02-12 21:38 - 2014-02-06 02:11 - 05768704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-02-12 21:38 - 2014-02-06 02:01 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll 2014-02-12 21:38 - 2014-02-06 02:00 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll 2014-02-12 21:38 - 2014-02-06 01:57 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-02-12 21:38 - 2014-02-06 01:57 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-02-12 21:38 - 2014-02-06 01:52 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2014-02-12 21:38 - 2014-02-06 01:52 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll 2014-02-12 21:38 - 2014-02-06 01:50 - 02041856 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-02-12 21:38 - 2014-02-06 01:47 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe 2014-02-12 21:38 - 2014-02-06 01:46 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2014-02-12 21:38 - 2014-02-06 01:25 - 04244480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-02-12 21:38 - 2014-02-06 01:25 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll 2014-02-12 21:38 - 2014-02-06 01:24 - 02334208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-02-12 21:38 - 2014-02-06 01:22 - 13051392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-02-12 21:38 - 2014-02-06 01:13 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-02-12 21:38 - 2014-02-06 01:09 - 01964032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-02-12 21:38 - 2014-02-06 01:03 - 11266048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-02-12 21:38 - 2014-02-06 00:55 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-02-12 21:38 - 2014-02-06 00:41 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-02-12 21:38 - 2014-02-06 00:40 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-02-12 21:38 - 2014-02-06 00:36 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-02-12 21:38 - 2014-02-06 00:34 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-02-12 21:31 - 2013-12-08 16:19 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdrm.dll 2014-02-12 21:31 - 2013-12-08 15:55 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdrm.dll 2014-02-12 21:30 - 2014-01-06 21:00 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2014-02-12 21:30 - 2014-01-06 20:30 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2014-02-12 21:30 - 2013-12-08 16:27 - 02152448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll 2014-02-12 21:30 - 2013-12-08 15:54 - 01317376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll 2014-02-12 21:30 - 2013-11-20 22:42 - 04604416 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2014-02-12 21:30 - 2013-11-20 21:44 - 03936256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2014-02-12 21:24 - 2014-01-04 12:50 - 01462216 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 2014-02-12 21:24 - 2014-01-04 11:22 - 01202888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll 2014-02-12 21:24 - 2014-01-04 06:30 - 13209088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-02-12 21:24 - 2014-01-04 06:23 - 11702272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-02-12 21:24 - 2014-01-04 05:42 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll 2014-02-12 21:24 - 2014-01-04 05:40 - 07416832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2014-02-12 21:24 - 2014-01-04 05:36 - 00830976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll 2014-02-12 21:24 - 2014-01-04 05:28 - 04961792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2014-02-12 21:24 - 2013-12-20 18:10 - 00009701 _____ () C:\WINDOWS\SysWOW64\connectedsearch-results.searchconnector-ms 2014-02-12 21:24 - 2013-12-20 18:10 - 00009701 _____ () C:\WINDOWS\system32\connectedsearch-results.searchconnector-ms 2014-02-12 21:24 - 2013-12-08 18:57 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2014-02-12 21:24 - 2013-12-08 17:51 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2014-02-12 21:23 - 2014-01-06 23:03 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe 2014-02-12 21:23 - 2014-01-06 21:59 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe 2014-02-12 21:23 - 2013-12-20 02:10 - 01113040 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2014-02-12 21:23 - 2013-12-19 22:13 - 00835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2014-02-12 21:21 - 2014-01-09 00:25 - 02804224 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2014-02-12 21:21 - 2014-01-08 23:59 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2014-02-12 21:21 - 2014-01-08 23:59 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll 2014-02-12 21:21 - 2014-01-08 23:49 - 00919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2014-02-12 21:21 - 2014-01-08 23:44 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll 2014-02-12 21:21 - 2014-01-08 23:43 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll 2014-02-12 21:21 - 2014-01-08 23:29 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll 2014-02-12 21:21 - 2014-01-08 23:28 - 04217344 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll 2014-02-12 21:21 - 2014-01-08 23:28 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2014-02-12 21:21 - 2014-01-08 23:18 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe ==================== One Month Modified Files and Folders ======= 2014-03-11 23:09 - 2014-03-11 23:09 - 00017246 _____ () C:\Users\Kristen\Downloads\FRST.txt 2014-03-11 23:09 - 2014-03-11 23:09 - 00000000 ____D () C:\FRST 2014-03-11 23:09 - 2013-09-29 20:04 - 00863592 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-03-11 23:07 - 2014-03-11 23:07 - 02157056 _____ (Farbar) C:\Users\Kristen\Downloads\FRST64.exe 2014-03-11 23:07 - 2013-01-25 19:42 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-541397282-4190240310-1865117955-1001 2014-03-11 23:05 - 2014-03-11 23:05 - 00024375 _____ () C:\Users\Kristen\Desktop\Farbar_recovery_.htm 2014-03-11 23:05 - 2013-11-25 22:22 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{F70B3536-3675-46E8-BD5D-B146E5615C82} 2014-03-11 23:04 - 2014-01-06 14:26 - 00003474 _____ () C:\WINDOWS\System32\Tasks\ASUS Live Update1 2014-03-11 23:04 - 2014-01-06 14:26 - 00003464 _____ () C:\WINDOWS\System32\Tasks\ASUS Live Update2 2014-03-11 23:04 - 2013-11-25 21:01 - 01624204 _____ () C:\WINDOWS\WindowsUpdate.log 2014-03-11 23:04 - 2013-01-25 19:39 - 00000500 _____ () C:\Users\Kristen\AppData\Roaming\sp_data.sys 2014-03-11 23:04 - 2012-12-15 11:23 - 00003048 _____ () C:\WINDOWS\System32\Tasks\ASUS Splendid ACMON 2014-03-11 23:04 - 2012-12-15 11:20 - 00003028 _____ () C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus 2014-03-11 23:04 - 2012-12-15 11:14 - 00003222 _____ () C:\WINDOWS\System32\Tasks\ASUS Patch for VIA Audio 2014-03-11 23:03 - 2014-01-06 14:26 - 00003114 _____ () C:\WINDOWS\System32\Tasks\ASUS Live Update 2014-03-11 23:03 - 2013-08-22 06:46 - 00300048 _____ () C:\WINDOWS\setupact.log 2014-03-11 23:03 - 2013-01-25 22:46 - 00002205 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-03-11 23:03 - 2012-12-15 11:43 - 00003262 _____ () C:\WINDOWS\System32\Tasks\ASUS Patch for Touch Panel 2014-03-11 23:03 - 2012-12-15 11:23 - 00003056 _____ () C:\WINDOWS\System32\Tasks\ASUS P4G 2014-03-11 23:02 - 2013-01-25 22:41 - 00000914 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-11 23:01 - 2013-08-22 06:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-03-11 22:53 - 2014-03-11 23:03 - 00017373 _____ () C:\Users\Kristen\Desktop\Farbar_recovery scan.htm 2014-03-10 21:29 - 2013-11-25 20:48 - 00000000 ____D () C:\Users\Kristen 2014-03-10 18:30 - 2014-03-10 18:30 - 00000556 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 6da420b3-44ca-4cac-9a5d-c5787391bdf5.job 2014-03-10 18:30 - 2014-03-10 18:30 - 00000556 _____ () C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 09aa1cef-9359-42d7-85d7-7ae9e89ac7e2.job 2014-03-10 18:30 - 2014-03-10 18:30 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\SUPERAntiSpyware.com 2014-03-10 18:30 - 2014-03-10 18:28 - 00000000 ____D () C:\Program Files (x86)\SUPERAntiSpyware 2014-03-10 18:28 - 2014-03-10 18:28 - 00002029 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk 2014-03-10 18:28 - 2014-03-10 18:28 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com 2014-03-10 18:24 - 2014-03-07 06:31 - 00000000 _____ () C:\Recovery.txt 2014-03-09 23:59 - 2014-03-09 15:10 - 00001123 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-03-09 23:59 - 2014-03-09 15:10 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-09 23:02 - 2013-08-22 07:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-03-09 16:35 - 2013-09-29 19:55 - 00012218 _____ () C:\WINDOWS\PFRO.log 2014-03-09 15:10 - 2014-03-09 15:10 - 00000000 ____D () C:\Users\Kristen\AppData\Roaming\Malwarebytes 2014-03-09 15:10 - 2014-03-09 15:10 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-09 15:01 - 2013-08-22 05:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-03-09 14:45 - 2013-01-25 22:41 - 00000918 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-09 14:30 - 2013-07-12 07:36 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-03-06 18:41 - 2013-08-22 07:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-03-05 12:41 - 2013-12-12 23:51 - 00088064 ___SH () C:\Users\Kristen\Downloads\Thumbs.db 2014-03-04 20:51 - 2013-08-22 05:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-03-01 12:15 - 2014-03-01 12:15 - 00001797 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-03-01 12:15 - 2014-03-01 12:15 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-03-01 12:15 - 2014-03-01 12:15 - 00000000 ____D () C:\Program Files\iPod 2014-03-01 12:15 - 2014-03-01 12:15 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-03-01 12:15 - 2014-03-01 12:14 - 00000000 ____D () C:\Program Files\iTunes 2014-03-01 12:11 - 2013-01-26 12:33 - 00000000 ____D () C:\ProgramData\Apple 2014-03-01 11:55 - 2014-03-01 11:55 - 00001859 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk 2014-03-01 11:55 - 2014-03-01 11:54 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-02-25 18:17 - 2013-02-25 23:58 - 00057750 _____ () C:\Users\Kristen\Desktop\Sonot training_2013.xlsm 2014-02-20 12:32 - 2013-07-12 07:36 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2014-02-18 17:23 - 2013-08-14 18:26 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-02-18 17:22 - 2013-01-26 12:17 - 88567024 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-02-18 15:21 - 2014-01-20 22:32 - 00048822 _____ () C:\Users\Kristen\Desktop\Sonot training_2014.xlsm 2014-02-18 13:53 - 2014-02-18 13:53 - 00000291 _____ () C:\Users\Kristen\Desktop\Fairbanks’ Best is top woman in Susitina 100 - Local-Community - Fairbanks Daily News-Miner.url 2014-02-18 01:17 - 2013-08-22 07:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2014-02-17 13:00 - 2013-08-22 07:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-02-17 13:00 - 2013-08-22 07:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-17 12:58 - 2013-08-22 07:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-02-17 10:43 - 2013-01-25 19:36 - 00000000 ___RD () C:\Users\Kristen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-17 10:43 - 2013-01-25 19:36 - 00000000 ___RD () C:\Users\Kristen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-02-17 10:42 - 2013-08-22 06:44 - 00474080 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-02-17 01:37 - 2014-02-17 01:37 - 00025343 _____ () C:\Users\Kristen\Documents\su100_2014_skiers.xlsx 2014-02-17 01:37 - 2013-08-22 07:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-02-17 01:37 - 2013-08-22 07:36 - 00000000 ____D () C:\WINDOWS\MediaViewer 2014-02-17 01:37 - 2013-08-22 07:36 - 00000000 ____D () C:\WINDOWS\FileManager 2014-02-17 01:37 - 2013-08-22 07:36 - 00000000 ____D () C:\WINDOWS\Camera 2014-02-17 01:37 - 2013-08-22 05:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\Dism 2014-02-17 01:37 - 2013-08-22 05:36 - 00000000 ____D () C:\WINDOWS\system32\Dism 2014-02-13 00:06 - 2013-01-28 21:04 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-02-12 21:40 - 2013-01-25 22:41 - 00003890 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-12 21:40 - 2013-01-25 22:41 - 00003654 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-12 21:18 - 2012-07-25 21:26 - 00000199 _____ () C:\WINDOWS\win.ini Files to move or delete: ==================== C:\ProgramData\PKP_DLeo.DAT C:\ProgramData\PKP_DLes.DAT C:\ProgramData\PKP_DLet.DAT C:\ProgramData\PKP_DLev.DAT C:\ProgramData\SetStretch.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-08 05:30 ==================== End Of Log ============================