Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014 Ran by Hubert (administrator) on ASUS-PC on 20-07-2014 20:39:54 Running from C:\Users\Hubert.ASUS-PC\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Adobe Systems Incorporated) C:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\bin\VersionCueCS2.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft) C:\Program Files (x86)\Spotflux\services\SpotfluxUpdateService.exe (ClientConnect Ltd.) C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe () C:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (mech) C:\Program Files (x86)\Eyes Relax\EyesRelax.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\EaseUS Partition Master 9.2.2\bin\EpmNews.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (Adobe Sytems Incorporated) C:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe () C:\Program Files (x86)\Garena Plus\ggdllhost.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\osk.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [617120 2011-03-14] (Atheros Commnucations) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379552 2011-03-14] (Atheros Commnucations) HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-02] (Logitech Inc.) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [ShadowPlay] => C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation) HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [204048 2011-08-03] (Trend Micro Inc.) HKLM\...\Run: [Trend Micro Titanium] => C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe [1300672 2011-08-03] (Trend Micro Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-18] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-08] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-20] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2099200 2014-04-13] (Dominik Reichl) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [EaseUS EPM tray] => C:\Program Files (x86)\EaseUS\EaseUS Partition Master 9.2.2\bin\EpmNews.exe [2081792 2013-03-29] (CHENGDU YIWO Tech Development Co., Ltd) HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [Adobe Version Cue CS2] => c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe [856064 2005-04-04] (Adobe Sytems Incorporated) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.143.296\AsusWSPanel.exe [740736 2012-08-03] (ASUS Cloud Corporation) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation) HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-228239459-1228040494-1754010821-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3595608 2014-06-26] (Electronic Arts) HKU\S-1-5-21-228239459-1228040494-1754010821-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1754816 2014-05-30] (Valve Corporation) HKU\S-1-5-21-228239459-1228040494-1754010821-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-228239459-1228040494-1754010821-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [9936176 2014-04-29] () HKU\S-1-5-21-228239459-1228040494-1754010821-1001\...\Run: [BackgroundContainerV2] => "C:\windows\SysWOW64\Rundll32.exe" "C:\Users\Hubert.ASUS-PC\AppData\Local\Tbccint\BackgroundContaine (the data entry has 34 more characters). HKU\S-1-5-21-228239459-1228040494-1754010821-1001\...\MountPoints2: {de3fa041-4100-11e3-b192-806e6f6e6963} - E:\Autorun.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Eyes Relax.lnk ShortcutTarget: Eyes Relax.lnk -> C:\Windows\Installer\{9C890D28-9671-4DC2-B017-D5327B9062C8}\EyeIcon.ico () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe () ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.143.296\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.143.296\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.143.296\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: FunOverlay -> {A5662DF9-0C2E-4A56-9FE1-BACFF6966D88} => C:\Users\Public\Fundata\FunSeed64V019.dll (Funshion) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ncr URLSearchHook: HKLM-x32 - RuneScape Toolbar - {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Users\Hubert.ASUS-PC\AppData\LocalLow\RuneScape\prxtbRun0.dll (ClientConnect Ltd.) SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {23784F92-94AE-4757-BE78-381361A7DF86} URL = http://trovi.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2680363&CUI=UN25738629912625371&UM=1 SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = BHO: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> C:\Program Files\Trend Micro\AMSP\Module\20004\2.0.1313\6.8.1066\TmIEPlg.dll (Trend Micro Inc.) BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) BHO: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1081\7.0.1081\TmBpIe64.dll (Trend Micro Inc.) BHO-x32: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> C:\Program Files\Trend Micro\AMSP\Module\20004\2.0.1313\6.8.1066\TmIEPlg32.dll (Trend Micro Inc.) BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) BHO-x32: AdventureQuest Worlds Toolbar BHO -> {745A6D3B-4DB0-4246-B596-9189787D4ED5} -> C:\Program Files (x86)\AdventureQuest Worlds Toolbar\Toolbar.dll () BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll (Perfect World Entertainment Inc) BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: RuneScape Toolbar -> {a8864317-e18b-4292-99d9-e6e65ab905d3} -> C:\Users\Hubert.ASUS-PC\AppData\LocalLow\RuneScape\prxtbRun0.dll (ClientConnect Ltd.) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) BHO-x32: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1081\7.0.1081\TmBpIe32.dll (Trend Micro Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - AdventureQuest Worlds Toolbar - {3385E2D6-567B-4FC6-8F0F-D7A8C6E6118C} - C:\Program Files (x86)\AdventureQuest Worlds Toolbar\Toolbar.dll () Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - RuneScape Toolbar - {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Users\Hubert.ASUS-PC\AppData\LocalLow\RuneScape\prxtbRun0.dll (ClientConnect Ltd.) Toolbar: HKCU - No Name - {3385E2D6-567B-4FC6-8F0F-D7A8C6E6118C} - No File Toolbar: HKCU - No Name - {A8864317-E18B-4292-99D9-E6E65AB905D3} - No File DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: HKLM-x32 {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield.play4free.com/static/updater/BP4FUpdater_1.0.96.0.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1081\7.0.1081\TmBpIe64.dll (Trend Micro Inc.) Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\2.0.1313\6.8.1066\TmIEPlg.dll (Trend Micro Inc.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1081\7.0.1081\TmBpIe32.dll (Trend Micro Inc.) Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\2.0.1313\6.8.1066\TmIEPlg32.dll (Trend Micro Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{EDB76F38-6FE5-4F2D-8878-E44E6B39E60F}: [NameServer]192.168.1.254 FireFox: ======== FF ProfilePath: C:\Users\Hubert.ASUS-PC\AppData\Roaming\Mozilla\Firefox\Profiles\s5ztywky.default FF DefaultSearchEngine: dosearches FF NetworkProxy: "type", 0 FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1212152.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @funshion.com/npFunshion - C:\Users\Hubert.ASUS-PC\funshion\funshiontools\npFunshion.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin - C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc) FF Plugin-x32: @t.garena.com/garenatalk - C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Hubert.ASUS-PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF user.js: detected! => C:\Users\Hubert.ASUS-PC\AppData\Roaming\Mozilla\Firefox\Profiles\s5ztywky.default\user.js FF Extension: Media Hint - C:\Users\Hubert.ASUS-PC\AppData\Roaming\Mozilla\Firefox\Profiles\s5ztywky.default\Extensions\mediahint@jetpack.xpi [2014-05-19] FF Extension: AdventureQuest Worlds Toolbar - C:\Users\Hubert.ASUS-PC\AppData\Roaming\Mozilla\Firefox\Profiles\s5ztywky.default\Extensions\{88c4479d-3515-4ca3-a805-27b920c3bf6d}.xpi [2013-10-31] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11] FF HKLM-x32\...\Firefox\Extensions: [{38783831-6098-4faa-A9C9-1EE1E343F4D2}] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1081\7.0.1081\firefoxextension FF Extension: Trend Micro BEP Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20002\7.0.1081\7.0.1081\firefoxextension [2014-07-20] FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension [2014-07-20] Chrome: ======= CHR HomePage: hxxp://www.google.com/ncr CHR StartupUrls: "hxxp://www.google.com/ncr" CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Hubert.ASUS-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-10] CHR Extension: (Skype Click to Call) - C:\Users\Hubert.ASUS-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-01-03] CHR Extension: (Google Wallet) - C:\Users\Hubert.ASUS-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-01] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11] ==================== Services (Whitelisted) ================= S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-02-01] (Adobe Systems) [File not signed] R2 Adobe Version Cue CS2; c:\Creative Suite CS2\Adobe Creative Suite 2.0\Adobe Version Cue CS2\bin\VersionCueCS2.exe [163840 2005-04-04] (Adobe Systems Incorporated) [File not signed] S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2014-06-12] (Perfect World Entertainment Inc) R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-03-14] (Atheros) [File not signed] R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-14] (Atheros Commnucations) [File not signed] R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation) S3 DAUpdaterSvc; C:\Program Files (x86)\Origin Games\Dragon Age Origins Ultimate Edition\bin_ship\daupdatersvc.service.exe [25832 2011-05-17] (BioWare) R2 EpsonScanSvc; C:\windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation) R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76152 2014-06-28] () R2 SpotfluxUpdateService; C:\Program Files (x86)\Spotflux\services\SpotfluxUpdateService.exe [28160 2013-12-03] (Microsoft) [File not signed] R2 TBSrv; C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe [350528 2014-04-01] (ClientConnect Ltd.) R2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad [X] ==================== Drivers (Whitelisted) ==================== S3 epmntdrv; C:\windows\system32\epmntdrv.sys [17480 2013-03-07] () S3 epmntdrv; C:\windows\SysWOW64\epmntdrv.sys [13896 2013-03-07] () S3 EuGdiDrv; C:\windows\system32\EuGdiDrv.sys [9800 2013-03-07] () S3 EuGdiDrv; C:\windows\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-20] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-04-01] (NVIDIA Corporation) R3 tapSF0901; C:\Windows\System32\DRIVERS\tapSF0901.sys [39104 2013-12-03] (Spotflux, Inc.) R1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [91920 2011-07-12] (Trend Micro Inc.) R1 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [167696 2011-07-12] (Trend Micro Inc.) R1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [70928 2011-07-12] (Trend Micro Inc.) R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105744 2011-08-03] (Trend Micro Inc.) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-20 20:39 - 2014-07-20 20:40 - 00029245 _____ () C:\Users\Hubert.ASUS-PC\Downloads\FRST.txt 2014-07-20 20:39 - 2014-07-20 20:40 - 00000000 ____D () C:\FRST 2014-07-20 20:37 - 2014-07-20 20:38 - 02089984 _____ (Farbar) C:\Users\Hubert.ASUS-PC\Downloads\FRST64.exe 2014-07-20 19:41 - 2014-07-20 19:41 - 00000046 _____ () C:\Users\Hubert.ASUS-PC\FunShion.ini 2014-07-20 18:59 - 2014-07-20 18:59 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-07-20 18:59 - 2014-07-20 18:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-07-20 18:59 - 2014-07-20 18:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-07-20 18:59 - 2014-07-20 18:59 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-07-20 18:59 - 2014-07-20 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-20 18:39 - 2014-07-20 18:39 - 00000000 ____D () C:\temp 2014-07-20 18:25 - 2014-07-20 18:25 - 00001443 _____ () C:\Users\Hubert.ASUS-PC\Desktop\Trend Micro Titanium Internet Security 2012.lnk 2014-07-20 18:25 - 2014-07-20 18:25 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium Internet Security 2012 2014-07-20 18:25 - 2014-07-20 18:25 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Trend Micro 2014-07-20 18:25 - 2011-08-03 04:45 - 00105744 _____ (Trend Micro Inc.) C:\windows\system32\Drivers\tmtdi.sys 2014-07-20 18:25 - 2011-07-12 19:13 - 00167696 _____ (Trend Micro Inc.) C:\windows\system32\Drivers\tmcomm.sys 2014-07-20 18:25 - 2011-07-12 19:13 - 00091920 _____ (Trend Micro Inc.) C:\windows\system32\Drivers\tmactmon.sys 2014-07-20 18:25 - 2011-07-12 19:13 - 00070928 _____ (Trend Micro Inc.) C:\windows\system32\Drivers\tmevtmgr.sys 2014-07-20 18:21 - 2014-07-20 18:21 - 00000056 _____ () C:\windows\system32\SupportTool.exe.bat 2014-07-20 18:20 - 2014-07-20 18:20 - 00000258 __RSH () C:\ProgramData\ntuser.pol 2014-07-20 18:19 - 2014-07-20 18:20 - 00000000 ____D () C:\Program Files\Trend Micro 2014-07-20 18:18 - 2014-07-20 18:25 - 00000000 ____D () C:\ProgramData\Trend Micro 2014-07-20 11:30 - 2014-07-20 19:07 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-20 11:30 - 2014-07-20 11:30 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-07-20 11:30 - 2014-07-20 11:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-07-20 11:30 - 2014-07-20 11:30 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-20 11:30 - 2014-07-20 11:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-07-20 11:30 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-07-20 11:30 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-07-20 11:30 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-07-20 02:41 - 2014-07-20 02:41 - 00004489 _____ () C:\windows\SysWOW64\jupdate-1.7.0_65-b20.log 2014-07-19 00:30 - 2014-07-19 00:30 - 00000355 _____ () C:\Users\Hubert.ASUS-PC\Downloads\following.html 2014-07-19 00:29 - 2014-07-19 00:29 - 00001524 _____ () C:\Users\Hubert.ASUS-PC\Downloads\views.py 2014-07-19 00:29 - 2014-07-19 00:29 - 00000352 _____ () C:\Users\Hubert.ASUS-PC\Downloads\urls.py 2014-07-19 00:29 - 2014-07-19 00:29 - 00000318 _____ () C:\Users\Hubert.ASUS-PC\Downloads\followers.html 2014-07-19 00:29 - 2014-07-19 00:29 - 00000288 _____ () C:\Users\Hubert.ASUS-PC\Downloads\allusers.html 2014-07-18 21:18 - 2014-07-18 21:18 - 00621085 _____ () C:\Users\Hubert.ASUS-PC\Downloads\views_and_templates2.pptx 2014-07-18 21:18 - 2014-07-18 21:18 - 00095933 _____ () C:\Users\Hubert.ASUS-PC\Downloads\regex.pptx 2014-07-13 18:18 - 2014-07-13 18:18 - 00002656 _____ () C:\Users\Hubert.ASUS-PC\AppData\Local\recently-used.xbel 2014-07-09 18:34 - 2014-06-21 04:14 - 00266424 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-07-09 18:34 - 2014-06-21 03:39 - 00240824 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-07-09 18:34 - 2014-06-19 09:39 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-07-09 18:34 - 2014-06-19 09:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-07-09 18:34 - 2014-06-19 09:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-07-09 18:34 - 2014-06-19 08:48 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-07-09 18:34 - 2014-06-19 08:42 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2014-07-09 18:34 - 2014-06-19 08:42 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-07-09 18:34 - 2014-06-19 08:41 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2014-07-09 18:34 - 2014-06-19 08:41 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-07-09 18:34 - 2014-06-19 08:32 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-07-09 18:34 - 2014-06-19 08:31 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-07-09 18:34 - 2014-06-19 08:26 - 00598016 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-07-09 18:34 - 2014-06-19 08:24 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-07-09 18:34 - 2014-06-19 08:24 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-07-09 18:34 - 2014-06-19 08:23 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-07-09 18:34 - 2014-06-19 08:16 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-07-09 18:34 - 2014-06-19 08:14 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-07-09 18:34 - 2014-06-19 08:09 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-07-09 18:34 - 2014-06-19 07:59 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2014-07-09 18:34 - 2014-06-19 07:56 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-07-09 18:34 - 2014-06-19 07:53 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-07-09 18:34 - 2014-06-19 07:51 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-07-09 18:34 - 2014-06-19 07:50 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-07-09 18:34 - 2014-06-19 07:48 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-07-09 18:34 - 2014-06-19 07:39 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-07-09 18:34 - 2014-06-19 07:38 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2014-07-09 18:34 - 2014-06-19 07:37 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-07-09 18:34 - 2014-06-19 07:36 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-07-09 18:34 - 2014-06-19 07:35 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2014-07-09 18:34 - 2014-06-19 07:33 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-07-09 18:34 - 2014-06-19 07:32 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-07-09 18:34 - 2014-06-19 07:28 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-07-09 18:34 - 2014-06-19 07:28 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-07-09 18:34 - 2014-06-19 07:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-07-09 18:34 - 2014-06-19 07:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2014-07-09 18:34 - 2014-06-19 07:25 - 00442368 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2014-07-09 18:34 - 2014-06-19 07:23 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-07-09 18:34 - 2014-06-19 07:22 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-07-09 18:34 - 2014-06-19 07:12 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-07-09 18:34 - 2014-06-19 07:06 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-09 18:34 - 2014-06-19 07:01 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-07-09 18:34 - 2014-06-19 06:59 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-07-09 18:34 - 2014-06-19 06:58 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-07-09 18:34 - 2014-06-19 06:58 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-07-09 18:34 - 2014-06-19 06:52 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-07-09 18:34 - 2014-06-19 06:51 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-07-09 18:34 - 2014-06-19 06:49 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-07-09 18:34 - 2014-06-19 06:46 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2014-07-09 18:34 - 2014-06-19 06:45 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-07-09 18:34 - 2014-06-19 06:35 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-07-09 18:34 - 2014-06-19 06:34 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-07-09 18:34 - 2014-06-19 06:15 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-07-09 18:34 - 2014-06-19 06:13 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-07-09 18:34 - 2014-06-19 06:09 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-07-09 18:34 - 2014-06-19 06:07 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-07-09 18:34 - 2014-06-18 10:18 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\osk.exe 2014-07-09 18:34 - 2014-06-18 09:51 - 00646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe 2014-07-09 18:34 - 2014-06-18 09:10 - 03157504 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-07-09 18:34 - 2014-06-06 18:10 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-07-09 18:34 - 2014-06-06 17:44 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll 2014-07-09 18:34 - 2014-06-05 22:45 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2014-07-09 18:34 - 2014-06-05 22:26 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll 2014-07-09 18:34 - 2014-06-05 22:25 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll 2014-07-09 18:34 - 2014-05-30 16:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2014-07-09 18:34 - 2014-05-30 16:08 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2014-07-09 18:34 - 2014-05-30 16:08 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2014-07-09 18:34 - 2014-05-30 16:08 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2014-07-09 18:34 - 2014-05-30 16:08 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2014-07-09 18:34 - 2014-05-30 16:08 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2014-07-09 18:34 - 2014-05-30 16:08 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2014-07-09 18:34 - 2014-05-30 15:52 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll 2014-07-09 18:34 - 2014-05-30 15:52 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll 2014-07-09 18:34 - 2014-05-30 15:52 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll 2014-07-09 18:34 - 2014-05-30 15:52 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll 2014-07-09 18:34 - 2014-05-30 15:52 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll 2014-07-09 18:34 - 2014-05-30 15:52 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll 2014-07-09 18:34 - 2014-05-30 15:52 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll 2014-07-09 18:34 - 2014-05-30 14:45 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys 2014-07-07 12:11 - 2014-07-07 12:11 - 00003266 _____ () C:\windows\System32\Tasks\AsusVibeSchedule 2014-07-06 11:08 - 2014-07-06 11:08 - 00002294 _____ () C:\Users\Hubert.ASUS-PC\Desktop\Transformers Universe.lnk 2014-07-06 11:08 - 2014-07-06 11:08 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Transformers Universe 2014-07-06 11:08 - 2014-07-06 11:08 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Jagex Ltd 2014-06-30 17:38 - 2014-06-30 17:38 - 00000000 ____D () C:\ProgramData\PopCap Games 2014-06-29 19:45 - 2014-06-29 19:45 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Blizzard 2014-06-29 18:48 - 2014-07-01 20:26 - 00000000 ____D () C:\Program Files (x86)\Hearthstone 2014-06-29 18:48 - 2014-06-29 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2014-06-29 18:40 - 2014-07-20 11:42 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Battle.net 2014-06-29 18:40 - 2014-07-10 16:38 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-06-29 18:40 - 2014-06-29 18:48 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\Battle.net 2014-06-29 18:40 - 2014-06-29 18:40 - 00001148 _____ () C:\Users\Public\Desktop\Battle.net.lnk 2014-06-29 18:40 - 2014-06-29 18:40 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Blizzard Entertainment 2014-06-29 18:40 - 2014-06-29 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2014-06-29 18:40 - 2014-06-29 18:40 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-06-29 18:39 - 2014-06-29 18:39 - 00000000 ____D () C:\ProgramData\Battle.net 2014-06-27 14:55 - 2014-06-27 14:55 - 00001406 _____ () C:\Users\Hubert.ASUS-PC\Downloads\WarningSlip_Reference_14004895.htm 2014-06-23 00:06 - 2014-06-23 00:06 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\Documents\Respawn 2014-06-22 00:57 - 2014-06-22 01:01 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\Documents\BFH.Beta ==================== One Month Modified Files and Folders ======= 2014-07-20 20:40 - 2014-07-20 20:39 - 00029245 _____ () C:\Users\Hubert.ASUS-PC\Downloads\FRST.txt 2014-07-20 20:40 - 2014-07-20 20:39 - 00000000 ____D () C:\FRST 2014-07-20 20:38 - 2014-07-20 20:37 - 02089984 _____ (Farbar) C:\Users\Hubert.ASUS-PC\Downloads\FRST64.exe 2014-07-20 20:22 - 2013-10-30 23:27 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\KeePass 2014-07-20 20:05 - 2013-10-30 09:10 - 01390932 _____ () C:\windows\WindowsUpdate.log 2014-07-20 20:05 - 2012-02-18 15:37 - 00000912 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-20 19:41 - 2014-07-20 19:41 - 00000046 _____ () C:\Users\Hubert.ASUS-PC\FunShion.ini 2014-07-20 19:41 - 2014-01-07 18:13 - 00000000 ____D () C:\Users\Public\Fundata 2014-07-20 19:41 - 2013-10-30 22:07 - 00000000 ____D () C:\Users\Hubert.ASUS-PC 2014-07-20 19:07 - 2014-07-20 11:30 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-20 18:59 - 2014-07-20 18:59 - 00272808 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe 2014-07-20 18:59 - 2014-07-20 18:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe 2014-07-20 18:59 - 2014-07-20 18:59 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe 2014-07-20 18:59 - 2014-07-20 18:59 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll 2014-07-20 18:59 - 2014-07-20 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-07-20 18:59 - 2014-03-19 22:47 - 00000000 ____D () C:\Program Files (x86)\Java 2014-07-20 18:59 - 2013-10-30 22:21 - 00000000 ____D () C:\ProgramData\Oracle 2014-07-20 18:40 - 2013-11-15 15:49 - 00088577 _____ () C:\windows\setupact.log 2014-07-20 18:39 - 2014-07-20 18:39 - 00000000 ____D () C:\temp 2014-07-20 18:25 - 2014-07-20 18:25 - 00001443 _____ () C:\Users\Hubert.ASUS-PC\Desktop\Trend Micro Titanium Internet Security 2012.lnk 2014-07-20 18:25 - 2014-07-20 18:25 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium Internet Security 2012 2014-07-20 18:25 - 2014-07-20 18:25 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Trend Micro 2014-07-20 18:25 - 2014-07-20 18:18 - 00000000 ____D () C:\ProgramData\Trend Micro 2014-07-20 18:25 - 2009-07-14 13:13 - 00817386 _____ () C:\windows\system32\PerfStringBackup.INI 2014-07-20 18:21 - 2014-07-20 18:21 - 00000056 _____ () C:\windows\system32\SupportTool.exe.bat 2014-07-20 18:20 - 2014-07-20 18:20 - 00000258 __RSH () C:\ProgramData\ntuser.pol 2014-07-20 18:20 - 2014-07-20 18:19 - 00000000 ____D () C:\Program Files\Trend Micro 2014-07-20 18:20 - 2009-07-14 11:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy 2014-07-20 16:40 - 2009-07-14 12:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-20 16:40 - 2009-07-14 12:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-20 16:37 - 2013-11-04 01:32 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-07-20 16:36 - 2014-04-21 06:24 - 00003496 _____ () C:\windows\System32\Tasks\gg_uac_daemon_Hubert 2014-07-20 16:36 - 2012-02-18 15:37 - 00000908 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-20 16:35 - 2013-10-30 23:15 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-07-20 16:35 - 2013-10-29 20:07 - 00000000 ___HD () C:\ASUS.DAT 2014-07-20 16:33 - 2013-10-30 09:19 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-20 16:33 - 2009-07-14 13:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-07-20 16:32 - 2013-11-23 15:00 - 00673490 _____ () C:\windows\PFRO.log 2014-07-20 11:51 - 2013-10-30 09:30 - 00001872 _____ () C:\windows\system32\ServiceFilter.ini 2014-07-20 11:46 - 2012-02-18 15:45 - 00000000 ____D () C:\windows\en 2014-07-20 11:42 - 2014-06-29 18:40 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Battle.net 2014-07-20 11:30 - 2014-07-20 11:30 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-07-20 11:30 - 2014-07-20 11:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-07-20 11:30 - 2014-07-20 11:30 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-20 11:30 - 2014-07-20 11:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-07-20 11:17 - 2013-10-30 22:11 - 00000024 _____ () C:\Users\Hubert.ASUS-PC\random.dat 2014-07-20 11:17 - 2013-10-30 22:11 - 00000024 _____ () C:\Users\Hubert.ASUS-PC\jagexappletviewer.preferences 2014-07-20 11:11 - 2013-10-30 22:12 - 00011790 _____ () C:\Users\Hubert.ASUS-PC\Documents\Account database.kdbx 2014-07-20 11:01 - 2013-10-30 23:15 - 00000000 ____D () C:\ProgramData\Origin 2014-07-20 11:01 - 2013-10-30 22:11 - 00000053 _____ () C:\Users\Hubert.ASUS-PC\jagex_cl_runescape_LIVE.dat 2014-07-20 10:59 - 2013-10-30 22:10 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\Documents\Bluetooth Folder 2014-07-20 10:58 - 2013-10-30 10:48 - 00045056 _____ () C:\windows\SysWOW64\acovcnt.exe 2014-07-20 02:44 - 2013-11-02 01:34 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\CrashDumps 2014-07-20 02:41 - 2014-07-20 02:41 - 00004489 _____ () C:\windows\SysWOW64\jupdate-1.7.0_65-b20.log 2014-07-19 02:20 - 2013-11-01 14:54 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\SoftGrid Client 2014-07-19 00:30 - 2014-07-19 00:30 - 00000355 _____ () C:\Users\Hubert.ASUS-PC\Downloads\following.html 2014-07-19 00:29 - 2014-07-19 00:29 - 00001524 _____ () C:\Users\Hubert.ASUS-PC\Downloads\views.py 2014-07-19 00:29 - 2014-07-19 00:29 - 00000352 _____ () C:\Users\Hubert.ASUS-PC\Downloads\urls.py 2014-07-19 00:29 - 2014-07-19 00:29 - 00000318 _____ () C:\Users\Hubert.ASUS-PC\Downloads\followers.html 2014-07-19 00:29 - 2014-07-19 00:29 - 00000288 _____ () C:\Users\Hubert.ASUS-PC\Downloads\allusers.html 2014-07-18 21:18 - 2014-07-18 21:18 - 00621085 _____ () C:\Users\Hubert.ASUS-PC\Downloads\views_and_templates2.pptx 2014-07-18 21:18 - 2014-07-18 21:18 - 00095933 _____ () C:\Users\Hubert.ASUS-PC\Downloads\regex.pptx 2014-07-16 06:35 - 2013-11-07 22:41 - 00699056 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-07-16 06:35 - 2013-11-07 22:41 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-07-13 18:24 - 2014-06-18 19:12 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Adobe 2014-07-13 18:19 - 2014-05-26 19:37 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\.gimp-2.8 2014-07-13 18:18 - 2014-07-13 18:18 - 00002656 _____ () C:\Users\Hubert.ASUS-PC\AppData\Local\recently-used.xbel 2014-07-13 18:18 - 2014-01-23 20:36 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\gtk-2.0 2014-07-13 00:35 - 2009-07-14 11:20 - 00000000 ____D () C:\windows\system32\NDF 2014-07-11 14:29 - 2009-07-14 11:20 - 00000000 ____D () C:\windows\rescache 2014-07-10 16:38 - 2014-06-29 18:40 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-07-10 06:18 - 2009-07-14 12:45 - 00279672 _____ () C:\windows\system32\FNTCACHE.DAT 2014-07-10 06:17 - 2009-07-14 15:45 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 06:17 - 2009-07-14 11:20 - 00000000 ____D () C:\windows\SysWOW64\Dism 2014-07-10 06:17 - 2009-07-14 11:20 - 00000000 ____D () C:\windows\system32\Dism 2014-07-10 00:21 - 2013-11-04 12:02 - 00000000 ____D () C:\windows\system32\MRT 2014-07-10 00:20 - 2013-11-04 12:02 - 96441528 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-07-09 00:09 - 2013-11-29 02:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-07 12:11 - 2014-07-07 12:11 - 00003266 _____ () C:\windows\System32\Tasks\AsusVibeSchedule 2014-07-07 12:11 - 2012-02-18 15:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2014-07-07 12:11 - 2012-02-18 15:46 - 00000000 ____D () C:\AsusVibeData 2014-07-07 12:10 - 2013-10-30 23:04 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-07-07 12:10 - 2013-10-30 23:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-07-07 12:10 - 2013-10-30 23:04 - 00000000 ____D () C:\Program Files\CCleaner 2014-07-07 12:04 - 2013-10-29 20:07 - 00000000 __RSD () C:\Users\Public\Desktop\ASUS 2014-07-06 11:36 - 2013-10-30 23:14 - 00001119 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk 2014-07-06 11:36 - 2013-10-30 23:14 - 00001107 _____ () C:\Users\Hubert.ASUS-PC\Desktop\KeePass 2.lnk 2014-07-06 11:36 - 2013-10-30 23:14 - 00000000 ____D () C:\Program Files (x86)\KeePass Password Safe 2 2014-07-06 11:08 - 2014-07-06 11:08 - 00002294 _____ () C:\Users\Hubert.ASUS-PC\Desktop\Transformers Universe.lnk 2014-07-06 11:08 - 2014-07-06 11:08 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Transformers Universe 2014-07-06 11:08 - 2014-07-06 11:08 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Jagex Ltd 2014-07-02 01:01 - 2013-10-30 22:11 - 00000054 _____ () C:\Users\Hubert.ASUS-PC\jagex_cl_runescape_LIVE1.dat 2014-07-01 20:26 - 2014-06-29 18:48 - 00000000 ____D () C:\Program Files (x86)\Hearthstone 2014-07-01 20:20 - 2014-04-05 17:13 - 00214392 _____ () C:\windows\SysWOW64\PnkBstrB.exe 2014-06-30 20:06 - 2013-11-22 16:08 - 00297088 _____ () C:\windows\SysWOW64\PnkBstrB.xtr 2014-06-30 20:06 - 2013-11-01 09:52 - 00297088 _____ () C:\windows\SysWOW64\PnkBstrB.ex0 2014-06-30 17:38 - 2014-06-30 17:38 - 00000000 ____D () C:\ProgramData\PopCap Games 2014-06-29 19:45 - 2014-06-29 19:45 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Blizzard 2014-06-29 18:48 - 2014-06-29 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone 2014-06-29 18:48 - 2014-06-29 18:40 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\Battle.net 2014-06-29 18:40 - 2014-06-29 18:40 - 00001148 _____ () C:\Users\Public\Desktop\Battle.net.lnk 2014-06-29 18:40 - 2014-06-29 18:40 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Local\Blizzard Entertainment 2014-06-29 18:40 - 2014-06-29 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2014-06-29 18:40 - 2014-06-29 18:40 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment 2014-06-29 18:39 - 2014-06-29 18:39 - 00000000 ____D () C:\ProgramData\Battle.net 2014-06-28 14:36 - 2013-11-01 09:52 - 00076152 _____ () C:\windows\SysWOW64\PnkBstrA.exe 2014-06-28 14:23 - 2013-10-30 23:17 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2014-06-28 14:23 - 2009-07-14 13:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-06-27 14:55 - 2014-06-27 14:55 - 00001406 _____ () C:\Users\Hubert.ASUS-PC\Downloads\WarningSlip_Reference_14004895.htm 2014-06-27 01:07 - 2014-01-31 12:14 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\AppData\Roaming\.spotflux 2014-06-26 00:51 - 2013-10-30 22:19 - 00062056 _____ () C:\Users\Hubert.ASUS-PC\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-23 00:06 - 2014-06-23 00:06 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\Documents\Respawn 2014-06-22 01:01 - 2014-06-22 00:57 - 00000000 ____D () C:\Users\Hubert.ASUS-PC\Documents\BFH.Beta 2014-06-21 18:34 - 2013-11-29 12:43 - 00071158 _____ () C:\windows\DirectX.log 2014-06-21 04:14 - 2014-07-09 18:34 - 00266424 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-06-21 03:39 - 2014-07-09 18:34 - 00240824 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll Files to move or delete: ==================== C:\ProgramData\hash.dat C:\Users\Hubert\jagex_cl_loginapplet_LIVE.dat C:\Users\Hubert\jagex_cl_runescape_LIVE.dat C:\Users\Hubert\jagex_cl_runescape_LIVE1.dat C:\Users\Hubert\jagex_cl_runescape_LIVE_BETA.dat C:\Users\Hubert\jagex_cl_speccollect_LIVE.dat C:\Users\Hubert\random.dat C:\Users\Hubert.ASUS-PC\jagex_cl_loginapplet_LIVE.dat C:\Users\Hubert.ASUS-PC\jagex_cl_runescape_LIVE.dat C:\Users\Hubert.ASUS-PC\jagex_cl_runescape_LIVE1.dat C:\Users\Hubert.ASUS-PC\jagex_cl_runescape_LIVE_BETA.dat C:\Users\Hubert.ASUS-PC\jagex_cl_speccollect_LIVE.dat C:\Users\Hubert.ASUS-PC\random.dat Some content of TEMP: ==================== C:\Users\Hubert\AppData\Local\Temp\JavaIC.dll C:\Users\Hubert\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Hubert\AppData\Local\Temp\lol_patch_130620to130716.exe C:\Users\Hubert\AppData\Local\Temp\lol_patch_130716to130717v2.exe C:\Users\Hubert\AppData\Local\Temp\lol_patch_130717to130801.exe C:\Users\Hubert\AppData\Local\Temp\lol_patch_130801to130827.exe C:\Users\Hubert\AppData\Local\Temp\lol_patch_130827to130911.exe C:\Users\Hubert\AppData\Local\Temp\lol_patch_130911to130913.exe C:\Users\Hubert\AppData\Local\Temp\msscct32.dll C:\Users\Hubert\AppData\Local\Temp\npp.6.5.Installer.exe C:\Users\Hubert\AppData\Local\Temp\SkypeSetup.exe C:\Users\Hubert\AppData\Local\Temp\update_2_183.exe C:\Users\Hubert\AppData\Local\Temp\update_2_184.exe C:\Users\Hubert\AppData\Local\Temp\update_2_185.exe C:\Users\Hubert\AppData\Local\Temp\update_2_186.exe C:\Users\Hubert\AppData\Local\Temp\update_2_187.exe C:\Users\Hubert\AppData\Local\Temp\xmlUpdater.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\Crysis_Patch_1_2_launcher.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\jna3050455838131992151.dll C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\jna3245616368550308288.dll C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\jna4017214495932985763.dll C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\jna5542672012273498115.dll C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_131016to131104v2.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_131104to131114.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_131114to131127v3.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_131127to131217v2.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_131217to140110.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140110to140121v2.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140121to140212v2.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140212to140214.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140214to140220.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140220to140306.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140306to140307.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140307to140325.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140325to140401v2.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140401to140409.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140409to140410.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140410to140429.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140429to140430.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140430to140513.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140513to140529.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\lol_patch_140529to140610v2.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\npp.6.5.5.Installer.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\npp.6.6.3.Installer.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\nvStInst.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\sonarinst.exe C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\SRLDetectionLibrary5072208304759568307.dll C:\Users\Hubert.ASUS-PC\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-18 22:25 ==================== End Of Log ============================