Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-05-2015 Ran by john (administrator) on JOHN-PC on 12-05-2015 20:05:01 Running from C:\Users\john\Desktop Loaded Profiles: john (Available profiles: john) Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: English (United States) Internet Explorer Version 9 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (globalUpdate) C:\Program Files\globalUpdate\Update\GoogleUpdate.exe () C:\ProgramData\airtel\OnlineUpdate\ouc.exe (Avid Technology, Inc.) C:\Program Files\Digidesign\Drivers\MMERefresh.exe () C:\ProgramData\DataCardService\HWDeviceService.exe (MyWebSearch.com) C:\Program Files\MyWebSearch\bar\7.bin\MWSSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DataCardService\DCSHelper.exe (ShopperPro) C:\Program Files\Common Files\ShopperPro\spbiu.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Zbshareware Lab) C:\Program Files\USB Disk Security\USBGuard.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe () C:\Program Files\ShopperPro\JSDriver\1.42.0.1791\jsdrv.exe (Google Inc.) C:\Users\john\AppData\Local\Google\Update\GoogleUpdate.exe (Speedbit Ltd.) C:\Program Files\DAP\DAP.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Users\john\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe (Nero AG) C:\Program Files\Nero\Update\NASvc.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [TkBellExe] => C:\Program Files\Common Files\Real\Update_OB\realsched.exe [185896 2010-10-03] (RealNetworks, Inc.) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation) HKLM\...\Run: [MyWebSearch Email Plugin] => C:\PROGRA~1\MYWEBS~1\bar\7.bin\mwsoemon.exe HKLM\...\Run: [RemoteControl10] => C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.) HKLM\...\Run: [DigidesignMMERefresh] => C:\Program Files\Digidesign\Drivers\MMERefresh.exe [77824 2010-05-04] (Avid Technology, Inc.) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [Nvtmru] => C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [ISUSScheduler] => C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [69632 2004-04-13] (InstallShield Software Corporation) HKLM\...\Run: [USB Security] => C:\Program Files\USB Disk Security\USBGuard.exe [687336 2014-05-23] (Zbshareware Lab) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation) HKLM\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.42.0.1791\jsdrv.exe [3224576 2015-04-23] () HKLM\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-lsf?lic=OUxTRlJFRS1WUFVaNy1HMkNNWC1SWFBXQS1QM05aSC05RDIwQy0zN1RT"&"inst=NzctNTA0MTQzMjE0LVFJWDErNC1YMjAxMCsyLUxJQysyLVNQMSsxLVNVU (the data entry has 65 more characters). HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\Run: [ISUSPM Startup] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [196608 2004-04-17] (InstallShield Software Corporation) HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\Run: [Google Update] => C:\Users\john\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-12-13] (Google Inc.) HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\Run: [DownloadAccelerator] => C:\Program Files\DAP\DAP.EXE [3865232 2014-03-31] (Speedbit Ltd.) HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\Run: [SPDriver] => C:\Program Files\ShopperPro\JSDriver\1.42.0.1791\jsdrv.exe [3224576 2015-04-23] () HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: M - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: N - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {085c031c-0062-11e4-a464-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {0f04ab53-ee13-11e3-ab57-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {101c6e8d-c972-11e3-bae0-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {101c6e9a-c972-11e3-bae0-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {101c6eb3-c972-11e3-bae0-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {143b79cc-73ed-11e0-9bcb-4487fcab4607} - M:\Autorun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {217ab7a2-0127-11e4-b444-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {217ab7c9-0127-11e4-b444-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {2c431d26-965c-11e3-bc38-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {33f9fd63-01ca-11e4-8f2d-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {35c73c50-fc71-11e3-a116-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {35c73c62-fc71-11e3-a116-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {47f4969e-f117-11e3-b731-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {55654451-fb4d-11e3-ae2a-4487fcab4607} - G:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {55654467-fb4d-11e3-ae2a-4487fcab4607} - G:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {60a6e115-963c-11e3-9191-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {60a6e15a-963c-11e3-9191-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {60a6e16b-963c-11e3-9191-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {60a6e182-963c-11e3-9191-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {640d55cc-746c-11e0-9144-4487fcab4607} - M:\jpn-ts.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {6cea7044-d544-11df-9764-4487fcab4607} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {6cea704b-d544-11df-9764-4487fcab4607} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {6d58ac29-1df4-11e3-a480-4487fcab4607} - G:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {6d58ac33-1df4-11e3-a480-4487fcab4607} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {6d58ac48-1df4-11e3-a480-001e101f859f} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {6d8b3b58-f7bc-11e3-b317-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {71d69763-05b7-11e4-b284-4487fcab4607} - I:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {77091d29-fc6c-11e3-9d6a-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {77091d34-fc6c-11e3-9d6a-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {84a7a981-68bb-11e3-ae86-4487fcab4607} - N:\Setup.exe /Auto HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {8bc246a0-ccf7-11e3-8147-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {a0f92105-d273-11e3-bfa5-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {a2834c79-75f7-11e0-9a55-4487fcab4607} - M:\Autorun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {a42cf3a3-0773-11e4-9b81-4487fcab4607} - I:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {aca8c064-8228-11e4-99e2-4487fcab4607} - H:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {b1df923d-fddf-11e3-9a86-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {b63fee2e-cd4f-11e3-a695-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {b63fee39-cd4f-11e3-a695-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {bdc0b513-015b-11e1-b775-4487fcab4607} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {bdc0b519-015b-11e1-b775-4487fcab4607} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {cd22b11d-fd8f-11e3-81f9-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {d5ef6026-e29b-11e4-851d-4487fcab4607} - H:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {d5ef6043-e29b-11e4-851d-4487fcab4607} - H:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {d5ef6055-e29b-11e4-851d-4487fcab4607} - H:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {df614009-2945-11e1-afeb-4487fcab4607} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {df84c4a6-486a-11e3-ad09-4487fcab4607} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {ea7d0ca3-046c-11e4-bfe8-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {ea7d0cc9-046c-11e4-bfe8-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {eea14c94-d100-11e3-a250-4487fcab4607} - O:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {eea14ca0-d100-11e3-a250-4487fcab4607} - N:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {f52afa20-515d-11e4-9969-4487fcab4607} - H:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {f6c1bd8d-09b1-11e3-83a7-4487fcab4607} - M:\AutoRun.exe HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\MountPoints2: {fc3528a8-e410-11df-9e32-4487fcab4607} - M:\AutoRun.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkID=226786&Mkt=en-US&Src=MSE&Tid=80033373&OHP=http%3A%2F%2Fhome.speedbit.com%2F%3Faff%3D115&OSP= SearchScopes: HKLM -> DefaultScope {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = http://home.speedbit.com/search.aspx?site=shdefault&pid=%s&aid=%s&shr=%d&q={searchTerms} SearchScopes: HKLM -> {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {96bd48dd-741b-41ae-ac4a-aff96ba00f7e} URL = http://home.myplaycity.com/results.php?category=web&s={searchTerms} SearchScopes: HKLM -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2476351 SearchScopes: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = http://home.speedbit.com/search.aspx?site=shdefault&pid=%s&aid=%s&shr=%d&q={searchTerms} SearchScopes: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL = http://home.speedbit.com/search.aspx?aff=115&q={searchTerms} BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11] (Adobe Systems Incorporated) BHO: SaveSense -> {2e32cfe5-df92-4ae5-b0be-609ed0df74a6} -> C:\Program Files\SaveSense\SaveSenseIE.dll [2013-12-06] (SaveSense) BHO: Conduit Engine -> {30F9B915-B755-4826-820B-08FBA6BD249D} -> C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17] (Conduit Ltd.) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation) BHO: Shopper Pro -> {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} -> C:\ProgramData\ShopperPro\ShopperPro.dll [2015-04-23] (Goobzo Ltd.) BHO: QUICKfind BHO Object -> {C08DF07A-3E49-4E25-9AB0-D3882835F153} -> C:\Program Files\TEXTware\QUICKfind\PlugIns\IEHelp.dll [2001-08-10] () BHO: SpeedBit Link Verification Helper -> {D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} -> C:\Program Files\DAP\LinkVerifier.dll [2014-03-31] (Speedbit Ltd.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-06-30] (Sun Microsystems, Inc.) Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17] (Conduit Ltd.) Toolbar: HKLM - My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No File Toolbar: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File Toolbar: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> No Name - {51A86BB3-6602-4C85-92A5-130EE4864F13} - No File Toolbar: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll [2011-01-17] (Conduit Ltd.) Toolbar: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> No Name - {414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - No File Toolbar: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Toolbar: HKU\S-1-5-21-2280821914-3189600555-3011743376-1000 -> My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-12] (Microsoft Corporation) Handler: textwareilluminatorbase - {CE5CD329-1650-414A-8DB0-4CBF72FAED87} - C:\Windows\system32\textwareilluminatorbaseProtocol.dll [2002-09-27] () FireFox: ======== FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-01-07] (Google, Inc.) FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-05-04] (Sun Microsystems, Inc.) FF Plugin: @mcafee.com/SAFFPlugin -> C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll No File FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-11-11] (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-11-11] (NVIDIA Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [2011-04-13] (Pando Networks) FF Plugin: @real.com/nppl3260;version=6.0.12.46 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2010-10-03] (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=1.0.3.46 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll [2010-10-03] (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.46 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll [2010-10-03] (RealNetworks, Inc.) FF Plugin: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2014-07-03] (globalUpdate) FF Plugin: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2014-07-03] (globalUpdate) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-15] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-15] (Google Inc.) FF Plugin HKU\S-1-5-21-2280821914-3189600555-3011743376-1000: @tools.google.com/Google Update;version=3 -> C:\Users\john\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-15] (Google Inc.) FF Plugin HKU\S-1-5-21-2280821914-3189600555-3011743376-1000: @tools.google.com/Google Update;version=9 -> C:\Users\john\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-15] (Google Inc.) FF Plugin HKU\S-1-5-21-2280821914-3189600555-3011743376-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [2011-04-13] (Pando Networks) FF HKLM\...\Firefox\Extensions: [searchpredict@speedbit.com] - FF HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\Firefox\Extensions: [{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}] - C:\Program Files\DAP\DAPFireFox FF Extension: Download Accelerator Plus (DAP) extension - C:\Program Files\DAP\DAPFireFox [2014-03-31] FF HKU\S-1-5-21-2280821914-3189600555-3011743376-1000\...\Firefox\Extensions: [wcapturex@deskperience.com] - C:\Program Files\TheSage\extensions\firefox FF Extension: TheSage one-click lookup - C:\Program Files\TheSage\extensions\firefox [2015-05-10] Chrome: ======= CHR HomePage: Default -> hxxp://start.mysearchdial.com/?f=1&a=adk_14_18&cd=2XzuyEtN2Y1L1QzuyEyEzzyB0F0C0A0ByEyCtDyByDzy0E0AtN0D0Tzu0SzytCtBtN1L2XzutBtFtBtCtFtCtCtFtDtN1L1Czu1T1Q1J1VtCyE1VtCzztN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyB0B0D0AtG0F0FtCyBtGtCyD0ByBtG0CzzyB0BtGyC0Azz0DzyyE0B0FyB0E0FyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtDzzyD0C0C0FtG0DyBtDtDtG0CzzyCyDtGtD0E0AtCtGyEtBzytD0D0A0EyEtDtC0B0D2Q&cr=206597108&ir= CHR StartupUrls: Default -> "hxxp://start.mysearchdial.com/?f=7&a=adk_14_18&cd=2XzuyEtN2Y1L1QzuyEyEzzyB0F0C0A0ByEyCtDyByDzy0E0AtN0D0Tzu0SzytCtBtN1L2XzutBtFtBtCtFtCtCtFtDtN1L1Czu1T1Q1J1VtCyE1VtCzztN1L1G1B1V1N2Y1L1Qzu2StAtC0CyDyB0B0D0AtG0F0FtCyBtGtCyD0ByBtG0CzzyB0BtGyC0Azz0DzyyE0B0FyB0E0FyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StByDtDzzyD0C0C0FtG0DyBtDtDtG0CzzyCyDtGtD0E0AtCtGyEtBzytD0D0A0EyEtDtC0B0D2Q&cr=206597108&ir=", "https://www.google.co.in/" CHR DefaultSearchKeyword: Default -> speedbit.com CHR DefaultSearchURL: Default -> http://home.speedbit.com/search.aspx?aff=115&q={searchTerms} CHR DefaultSuggestURL: Default -> http://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms} CHR Profile: C:\Users\john\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Download Accelerator Plus (DAP)) - C:\Users\john\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb [2014-03-31] CHR Extension: (Bookmark Manager) - C:\Users\john\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-26] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\john\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-26] CHR Extension: (AT_WesCravenV2) - C:\Users\john\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahooofggegjbnodalhoibemeabkapop [2011-05-30] CHR Extension: (Google Wallet) - C:\Users\john\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-12] CHR Extension: (APK Downloader) - C:\Users\john\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhlfmheblhjhkmacldlhdnbgbaiigba [2014-07-10] CHR HKLM\...\Chrome\Extension: [ffdcfjdljhbehggjdkdioajnknjcpbjb] - C:\Program Files\DAP\DAPChrome\DAPChrome6.crx [2014-03-31] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - No Path Or update_url value CHR HKLM\...\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files\TheSage\TheSage\extensions\chrome\ [Not Found] CHR HKLM\...\Chrome\Extension: [ojhagnahfpegocdhlopgljpaafeogmcc] - No Path Or update_url value StartMenuInternet: Google Chrome - C:\Users\john\AppData\Local\Google\Chrome\Application\chrome.exe ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 airtel. RunOuc; C:\Program Files\airtel\UpdateDog\ouc.exe [650096 2013-12-09] () [File not signed] R2 DigiRefresh; C:\Program Files\Digidesign\Drivers\MMERefresh.exe [77824 2010-05-04] (Avid Technology, Inc.) [File not signed] S2 globalUpdate; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-03] (globalUpdate) [File not signed] <==== ATTENTION S3 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe [68608 2014-07-03] (globalUpdate) [File not signed] <==== ATTENTION R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [276048 2013-10-28] () R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation) R2 MyWebSearchService; C:\Program Files\MyWebSearch\bar\7.bin\MWSSVC.EXE [28762 2011-03-20] (MyWebSearch.com) [File not signed] R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [490280 2010-03-25] (Nero AG) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14658848 2013-12-10] (NVIDIA Corporation) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] R2 SPBIUpd; C:\Program Files\Common Files\ShopperPro\spbiu.exe [1813504 2015-04-23] (ShopperPro) [File not signed] S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X] S3 SuperProServer; spnsrvnt.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 athsgt; C:\Windows\System32\DRIVERS\athsgt.sys [164992 2013-03-29] () [File not signed] S3 BTCAMDRV; C:\Windows\System32\DRIVERS\BTCamDrv.sys [219136 2006-01-11] (Windows (R) 2000 DDK provider) [File not signed] S3 hid7906; C:\Windows\System32\drivers\hid7906.sys [53793 2006-06-28] (Compuware Corporation) [File not signed] S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [101248 2013-03-04] (Huawei Technologies Co., Ltd.) S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27776 2013-03-04] (Huawei Technologies Co., Ltd.) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [208384 2013-06-29] (Huawei Technologies Co., Ltd.) S3 hwusb_cdcacm; C:\Windows\System32\DRIVERS\ew_cdcacm.sys [108032 2013-10-23] (Huawei Technologies Co., Ltd.) S3 hwusb_wwanecm; C:\Windows\System32\DRIVERS\ew_wwanecm.sys [316544 2013-11-01] (Huawei Technologies Co., Ltd.) R2 limsgt; C:\Windows\System32\DRIVERS\limsgt.sys [12544 2013-03-29] () [File not signed] R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation) R1 MpKsl4d0d9b04; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{93A6CF27-DCC8-41DD-A855-20E67C8A27D2}\MpKsl4d0d9b04.sys [39464 2015-05-12] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-05] (NVIDIA Corporation) R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [36624 2006-11-02] (Sonic Solutions) [File not signed] S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2012-07-31] (Screaming Bee LLC) S0 sfdrv01; C:\Windows\System32\drivers\sfdrv01.sys [50688 2005-08-10] (Protection Technology) [File not signed] R0 sfhlp02; C:\Windows\System32\drivers\sfhlp02.sys [6656 2005-05-16] (Protection Technology) [File not signed] S0 sfsync02; C:\Windows\System32\drivers\sfsync02.sys [19968 2005-08-10] (Protection Technology) [File not signed] S0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [66048 2005-09-29] (Protection Technology) [File not signed] R3 SPBIUpdd; C:\Program Files\Common Files\ShopperPro\spbiw.sys [26112 2015-04-23] () [File not signed] R2 SPDRIVER_1.42.0.1791; C:\Program Files\ShopperPro\JSDriver\1.42.0.1791\jsdrv.sys [41112 2015-04-23] () R0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2011-03-25] () [File not signed] R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-06-28] (CyberLink Corp.) U3 a1benesc; C:\Windows\system32\Drivers\a1benesc.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero size file/folder) S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X] S3 tsusbhub; system32\drivers\tsusbhub.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] S3 ztemtusbser; system32\DRIVERS\CT_ZTEMT_U_USBSER.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-12 20:05 - 2015-05-12 20:05 - 00029416 _____ () C:\Users\john\Desktop\FRST.txt 2015-05-12 20:04 - 2015-05-12 20:05 - 00000000 ____D () C:\FRST 2015-05-12 20:03 - 2015-05-12 19:52 - 01141248 _____ (Farbar) C:\Users\john\Desktop\FRST.exe 2015-05-12 16:39 - 2015-05-12 16:39 - 00029692 _____ () C:\Users\john\Desktop\Result.txt 2015-05-12 16:30 - 2015-05-12 16:23 - 00403456 _____ (Farbar) C:\Users\john\Desktop\MiniToolBox.exe 2015-05-12 15:49 - 2004-12-10 09:06 - 00327680 _____ (On2.com Inc.) C:\Windows\system32\vp6dec.ax 2015-05-10 15:04 - 2015-05-10 15:05 - 00000000 ____D () C:\Users\john\AppData\Roaming\TheSage 2015-05-10 15:04 - 2015-05-10 15:04 - 00000000 ____D () C:\Users\john\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheSage 2015-05-10 15:03 - 2015-05-10 15:04 - 00000000 ____D () C:\Program Files\TheSage 2015-05-03 11:53 - 2015-05-03 11:53 - 00001102 _____ () C:\Users\Public\Desktop\Cambridge Advanced Learner's Dictionary.lnk 2015-05-03 11:53 - 2015-05-03 11:53 - 00000000 ____D () C:\Users\john\AppData\Roaming\Cambridge 2015-05-03 11:53 - 2015-05-03 11:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TEXTware 2015-05-03 11:53 - 2015-05-03 11:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cambridge 2015-05-03 11:53 - 2003-02-18 16:01 - 00047104 _____ () C:\Windows\system32\PolyHot.ILX 2015-05-03 11:53 - 2003-01-27 15:26 - 00142848 _____ (TEXTware A/S) C:\Windows\system32\Textv.ILX 2015-05-03 11:53 - 2002-11-15 15:24 - 00059392 _____ () C:\Windows\system32\Bass.ILX 2015-05-03 11:53 - 2002-11-14 15:16 - 00091648 _____ () C:\Windows\system32\IEBrowser.ILX 2015-05-03 11:53 - 2002-11-13 17:18 - 00202752 _____ (TEXTware A/S) C:\Windows\system32\Illprs.dll 2015-05-03 11:53 - 2002-11-11 10:01 - 00059904 _____ (TEXTware A/S) C:\Windows\system32\ListBox.ILX 2015-05-03 11:53 - 2002-11-01 13:15 - 00147456 _____ () C:\Windows\system32\Twavbx32.dll 2015-05-03 11:53 - 2002-10-15 14:15 - 00075264 _____ (TEXTware A/S) C:\Windows\system32\TreeView.ILX 2015-05-03 11:53 - 2002-09-27 15:57 - 00321024 _____ () C:\Windows\system32\textwareilluminatorbaseProtocol.dll 2015-05-03 11:53 - 2002-08-01 15:44 - 00160768 _____ (TEXTware A/S) C:\Windows\system32\ILLKRN.DLL 2015-05-03 11:53 - 2002-06-28 12:03 - 00113288 _____ () C:\Windows\system32\bass.dll 2015-05-03 11:53 - 2002-05-23 16:10 - 00360500 _____ () C:\Windows\system32\TWATBS32.VBX 2015-05-03 11:53 - 2002-01-25 10:29 - 00258048 _____ () C:\Windows\system32\TWABTE32.TBM 2015-05-03 11:53 - 2002-01-21 12:20 - 00048128 _____ () C:\Windows\system32\QFClient.ILX 2015-05-03 11:53 - 2002-01-07 10:19 - 00069632 _____ (TEXTware A/S) C:\Windows\system32\TwaBcu01.dll 2015-05-03 11:53 - 2001-12-21 13:18 - 00028672 _____ () C:\Windows\system32\TwaBcu.ILX 2015-05-03 11:53 - 2001-09-10 16:52 - 00434688 _____ (TEXTware A/S) C:\Windows\system32\HTML.ILX 2015-05-03 11:53 - 2001-08-24 13:14 - 00018432 _____ () C:\Windows\system32\TWAIED02.DLL 2015-05-03 11:53 - 2001-01-19 13:55 - 00056320 _____ (TEXTware A/S) C:\Windows\system32\AlphaPic.ILX 2015-05-03 11:53 - 2000-09-11 16:00 - 00305152 _____ () C:\Windows\system32\ASpell.ILX 2015-05-03 11:53 - 2000-06-15 14:49 - 00030720 _____ () C:\Windows\system32\BroadCast.ILX 2015-05-03 11:53 - 2000-05-22 17:17 - 00162304 _____ (TEXTware A/S) C:\Windows\system32\MPegPlay.ILX 2015-05-03 11:53 - 2000-04-25 18:11 - 00017408 _____ () C:\Windows\system32\WavRecpk4.bpl 2015-05-03 11:53 - 1999-11-10 11:04 - 00062464 _____ (TEXTware A/S) C:\Windows\system32\TWATBS.ILX 2015-05-03 11:53 - 1999-07-13 13:26 - 00070656 _____ (Polar) C:\Windows\system32\polspell.dll 2015-05-03 11:53 - 1999-07-01 15:29 - 00036352 _____ (TEXTware A/S) C:\Windows\system32\Whelp.ILX 2015-05-03 11:53 - 1998-12-03 12:07 - 00103424 _____ (LEAD Technologies, Inc.) C:\Windows\system32\ltfil10N.DLL 2015-05-03 11:53 - 1998-12-01 14:00 - 00266752 _____ (LEAD Technologies, Inc.) C:\Windows\system32\LFCMP10N.DLL 2015-05-03 11:53 - 1998-12-01 14:00 - 00134144 _____ (LEAD Technologies, Inc.) C:\Windows\system32\lfpng10N.dll 2015-05-03 11:53 - 1998-12-01 13:59 - 00034304 _____ (LEAD Technologies, Inc.) C:\Windows\system32\lfbmp10N.dll 2015-05-03 11:53 - 1998-12-01 13:58 - 00297472 _____ (LEAD Technologies, Inc.) C:\Windows\system32\ltkrn10N.dll 2015-05-03 11:53 - 1998-12-01 13:58 - 00231424 _____ (LEAD Technologies, Inc.) C:\Windows\system32\LTDIS10N.dll 2015-05-03 11:53 - 1998-11-30 13:09 - 00114176 _____ (LEAD Technologies, Inc.) C:\Windows\system32\ltimg10N.dll 2015-05-03 11:53 - 1998-10-22 04:01 - 01888744 _____ (Inprise Corporation) C:\Windows\system32\VCL40.BPL 2015-05-03 11:53 - 1998-10-21 12:46 - 00143360 _____ () C:\Windows\system32\ILXTBS.DLL 2015-05-03 11:52 - 2003-01-23 19:41 - 00066614 _____ () C:\Windows\system\TWADIB04.BMP 2015-04-26 07:17 - 2015-04-26 07:17 - 00000000 ____D () C:\Users\john\AppData\Roaming\KSafe 2015-04-26 07:17 - 2015-04-26 07:17 - 00000000 ____D () C:\ProgramData\KSafe 2015-04-26 07:16 - 2015-04-26 07:16 - 00001003 _____ () C:\Users\john\Desktop\DllTool.lnk 2015-04-26 07:16 - 2015-04-26 07:16 - 00000000 ____D () C:\Users\john\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DllTool 2015-04-26 07:16 - 2015-04-26 07:16 - 00000000 ____D () C:\Program Files\DllTool 2015-04-25 20:01 - 2015-04-25 20:01 - 00000867 _____ () C:\Users\Public\Desktop\Just Cause 2.lnk 2015-04-25 20:01 - 2015-04-25 20:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX - Eidos Interactive 2015-04-24 10:03 - 2015-04-24 10:03 - 00001759 _____ () C:\Users\Public\Desktop\Recuva.lnk 2015-04-22 12:25 - 2015-04-22 12:25 - 00001088 _____ () C:\Users\john\Desktop\Left 4 Dead By blaze69.lnk 2015-04-21 14:43 - 2015-04-21 14:43 - 00000841 _____ () C:\Users\Public\Desktop\Contract JACK Singleplayer Demo.lnk 2015-04-21 14:42 - 2015-04-21 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra 2015-04-16 17:48 - 2015-04-16 17:48 - 00000000 ____D () C:\Users\john\AppData\Roaming\GRETECH 2015-04-15 07:11 - 2014-10-18 07:03 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-04-15 07:11 - 2014-07-07 07:10 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-04-15 07:11 - 2014-07-07 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2015-04-15 07:11 - 2014-07-07 07:09 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2015-04-15 07:11 - 2014-07-07 07:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2015-04-15 06:57 - 2012-07-26 08:51 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2015-04-15 06:57 - 2012-07-26 08:50 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2015-04-15 06:57 - 2012-07-26 08:50 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2015-04-15 06:57 - 2012-07-26 08:50 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2015-04-15 06:57 - 2012-07-26 08:50 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2015-04-15 06:57 - 2012-07-26 08:03 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2015-04-15 06:57 - 2012-07-26 08:02 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2015-04-15 06:57 - 2012-06-02 20:27 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2015-04-15 05:27 - 2015-04-15 05:27 - 00033535 _____ () C:\Users\john\Downloads\ATH - Enter The Matrix - Full PC Game.torrent 2015-04-15 03:28 - 2014-07-01 03:44 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2015-04-15 03:28 - 2014-06-06 11:46 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2015-04-15 03:28 - 2014-03-10 03:17 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2015-04-15 03:28 - 2014-03-10 03:17 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2015-04-15 03:27 - 2012-03-01 11:16 - 00019824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys 2015-04-15 03:27 - 2012-03-01 10:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll 2015-04-15 03:16 - 2013-05-10 10:26 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-04-15 03:16 - 2013-05-10 10:26 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-04-15 02:27 - 2015-04-15 02:27 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d076f59cac145b.job 2015-04-15 02:27 - 2015-04-15 02:27 - 00000852 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2280821914-3189600555-3011743376-1000Core1d076f59f224db5.job 2015-04-15 02:26 - 2014-10-03 07:15 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2015-04-15 02:26 - 2014-10-03 07:15 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2015-04-15 02:26 - 2014-10-03 07:15 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2015-04-15 02:26 - 2014-10-03 07:15 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2015-04-15 02:26 - 2014-10-03 07:14 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2015-04-15 02:26 - 2013-02-27 10:19 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll 2015-04-15 02:24 - 2013-12-04 07:33 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2015-04-15 02:24 - 2013-12-04 07:33 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2015-04-15 02:24 - 2013-12-04 07:33 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2015-04-15 02:24 - 2013-12-04 07:33 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2015-04-15 02:24 - 2013-12-04 07:32 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2015-04-15 02:24 - 2013-12-04 07:24 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2015-04-15 02:24 - 2013-12-04 07:24 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2015-04-15 02:24 - 2013-12-04 07:24 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2015-04-15 02:24 - 2013-12-04 07:24 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2015-04-15 02:23 - 2014-10-18 07:03 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-04-15 02:23 - 2013-10-04 07:28 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2015-04-15 02:23 - 2013-10-04 07:26 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2015-04-15 02:23 - 2013-09-08 07:33 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2015-04-15 02:23 - 2013-07-09 10:22 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2015-04-15 02:23 - 2013-07-04 17:20 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2015-04-15 02:23 - 2013-07-03 09:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2015-04-15 02:23 - 2013-07-03 09:06 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2015-04-15 02:23 - 2012-08-22 22:46 - 00712048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-04-15 02:23 - 2012-07-05 01:15 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2015-04-15 02:22 - 2014-11-11 07:02 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-04-15 02:22 - 2013-10-30 07:49 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2015-04-15 02:22 - 2013-02-12 09:02 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2015-04-15 02:22 - 2012-11-02 10:41 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll 2015-04-15 02:21 - 2014-11-11 08:14 - 01011200 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-04-15 02:21 - 2014-07-14 07:12 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2015-04-15 02:20 - 2014-11-11 08:14 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-15 02:20 - 2014-11-11 08:14 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2015-04-15 02:20 - 2014-10-14 07:20 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-04-15 02:20 - 2014-08-12 07:06 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2015-04-15 02:20 - 2014-06-16 07:14 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2015-04-15 02:20 - 2014-06-16 07:14 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2015-04-15 02:20 - 2014-06-16 07:10 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2015-04-15 02:20 - 2014-03-26 19:57 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2015-04-15 02:20 - 2014-03-26 19:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2015-04-15 02:20 - 2014-03-04 14:50 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-04-15 02:20 - 2014-03-04 14:50 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-15 02:20 - 2014-03-04 14:47 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2015-04-15 02:20 - 2014-03-04 14:47 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-04-15 02:20 - 2014-03-04 14:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2015-04-15 02:20 - 2014-03-04 14:47 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2015-04-15 02:20 - 2014-03-04 14:47 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2015-04-15 02:20 - 2014-03-04 14:47 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2015-04-15 02:20 - 2014-03-04 14:47 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2015-04-15 02:20 - 2014-03-04 14:47 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2015-04-15 02:20 - 2014-01-01 04:35 - 00420008 _____ () C:\Windows\system32\locale.nls 2015-04-15 02:20 - 2013-10-19 07:06 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2015-04-15 02:20 - 2013-10-12 07:34 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2015-04-15 02:20 - 2013-10-12 07:33 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2015-04-15 02:20 - 2013-10-12 06:45 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2015-04-15 02:20 - 2013-10-12 06:45 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2015-04-15 02:20 - 2013-08-29 06:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys 2015-04-15 02:20 - 2013-08-27 13:51 - 01077760 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-04-15 02:20 - 2013-08-27 13:51 - 00808448 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-04-15 02:20 - 2013-01-24 10:17 - 00196328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2015-04-15 02:19 - 2014-09-04 10:34 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2015-04-15 02:19 - 2014-08-23 07:16 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-15 02:19 - 2014-08-21 11:56 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-04-15 02:19 - 2014-08-21 11:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-04-15 02:19 - 2013-05-10 08:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2015-04-15 02:19 - 2012-08-22 01:42 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2015-04-15 02:19 - 2011-12-30 10:57 - 00478720 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl 2015-04-15 02:19 - 2011-08-27 09:56 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll 2015-04-15 02:19 - 2011-08-17 09:54 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll 2015-04-15 02:19 - 2011-08-17 09:49 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax 2015-04-15 02:18 - 2014-10-10 06:15 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-04-15 02:18 - 2014-10-03 07:14 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-04-15 02:18 - 2014-10-03 07:14 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2015-04-15 02:18 - 2014-10-03 07:14 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2015-04-15 02:18 - 2014-10-03 07:14 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2015-04-15 02:18 - 2014-10-03 07:14 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-04-15 02:18 - 2014-01-28 07:37 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2015-04-15 02:18 - 2013-08-29 07:20 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-15 02:18 - 2013-08-29 07:20 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2015-04-15 02:18 - 2013-08-29 07:18 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2015-04-15 02:18 - 2013-08-28 06:27 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2015-04-15 02:18 - 2013-07-20 16:03 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-04-15 02:18 - 2013-06-06 10:22 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-04-15 02:18 - 2013-06-06 10:21 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-04-15 02:18 - 2013-06-06 10:20 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-04-15 02:18 - 2013-06-06 08:31 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-04-15 02:18 - 2013-06-06 08:31 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-04-15 02:18 - 2013-05-13 08:38 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2015-04-15 02:18 - 2013-05-13 08:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2015-04-15 02:18 - 2013-04-26 10:25 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2015-04-15 02:18 - 2013-03-19 10:18 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-15 02:18 - 2013-03-19 09:03 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2015-04-15 02:18 - 2013-03-19 08:19 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-15 02:17 - 2014-09-19 14:53 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-15 02:17 - 2014-09-19 14:53 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-15 02:17 - 2014-09-19 14:53 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-15 02:17 - 2014-09-19 14:53 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-15 02:17 - 2014-09-19 14:53 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-15 02:17 - 2014-09-19 14:53 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-15 02:17 - 2014-02-04 07:37 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2015-04-15 02:17 - 2014-02-04 07:37 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2015-04-15 02:17 - 2014-02-04 07:37 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2015-04-15 02:17 - 2014-02-04 07:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2015-04-15 02:17 - 2012-10-03 22:12 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-04-15 02:17 - 2012-10-03 22:12 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2015-04-15 02:17 - 2012-10-03 22:12 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2015-04-15 02:17 - 2012-10-03 22:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2015-04-15 02:17 - 2012-10-03 22:12 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2015-04-15 02:17 - 2012-10-03 22:10 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2015-04-15 02:17 - 2012-10-03 20:51 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2015-04-15 02:17 - 2012-06-06 10:33 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll 2015-04-15 02:16 - 2014-11-08 08:15 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2015-04-15 02:16 - 2014-09-25 07:10 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-04-15 02:16 - 2014-08-01 17:05 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2015-04-15 02:16 - 2014-06-18 07:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2015-04-15 02:16 - 2014-06-06 15:14 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2015-04-15 02:16 - 2014-06-03 15:00 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2015-04-15 02:16 - 2014-06-03 14:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-04-15 02:16 - 2014-06-03 14:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2015-04-15 02:16 - 2014-05-30 12:06 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2015-04-15 02:16 - 2014-04-05 07:55 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2015-04-15 02:16 - 2014-04-05 07:54 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2015-04-15 02:16 - 2014-01-24 07:48 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2015-04-15 02:16 - 2013-11-26 16:41 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2015-04-15 02:16 - 2013-10-04 07:19 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2015-04-15 02:16 - 2013-10-04 06:47 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2015-04-15 02:16 - 2013-07-25 14:27 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2015-04-15 02:16 - 2012-07-05 02:46 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll 2015-04-15 02:16 - 2012-07-05 02:44 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll 2015-04-15 02:16 - 2012-07-05 02:44 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll 2015-04-15 02:16 - 2012-05-05 13:16 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-15 02:16 - 2011-10-26 10:02 - 01328128 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2015-04-15 02:16 - 2011-10-15 11:08 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2015-04-15 02:15 - 2014-11-25 02:14 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-04-15 02:15 - 2014-11-25 02:11 - 12369920 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-04-15 02:15 - 2014-11-25 02:10 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-04-15 02:15 - 2014-11-25 02:07 - 09740800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-04-15 02:15 - 2014-11-25 02:05 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-04-15 02:15 - 2014-11-25 02:05 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-04-15 02:15 - 2014-11-25 02:04 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-04-15 02:15 - 2014-11-25 02:04 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2015-04-15 02:15 - 2014-11-25 02:03 - 01802752 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-04-15 02:15 - 2014-11-25 02:03 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-04-15 02:15 - 2014-11-25 02:03 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-04-15 02:15 - 2014-11-25 02:03 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-04-15 02:15 - 2014-11-25 02:03 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-04-15 02:15 - 2014-11-25 02:03 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-04-15 02:15 - 2014-11-25 02:03 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2015-04-15 02:15 - 2014-11-25 02:02 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-04-15 02:15 - 2014-11-25 02:02 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-04-15 02:15 - 2014-11-25 02:02 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-04-15 02:15 - 2014-11-25 02:02 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-04-15 02:15 - 2014-11-25 02:02 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-04-15 02:15 - 2014-11-25 02:02 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2015-04-15 02:15 - 2014-11-25 02:02 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2015-04-15 02:15 - 2014-06-19 03:53 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2015-04-15 02:15 - 2014-06-19 03:53 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2015-04-15 02:15 - 2014-06-19 03:53 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2015-04-15 02:15 - 2012-12-07 17:56 - 00308736 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2015-04-15 02:15 - 2012-12-07 17:50 - 02576384 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2015-04-15 02:15 - 2012-12-07 16:16 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2015-04-15 02:15 - 2012-12-07 16:16 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2015-04-15 02:12 - 2014-10-30 07:15 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2015-04-15 02:12 - 2014-10-25 07:02 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2015-04-15 02:12 - 2013-10-12 07:31 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2015-04-15 02:12 - 2013-10-12 07:31 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2015-04-15 02:12 - 2013-08-05 07:26 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2015-04-15 02:12 - 2013-07-26 07:25 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2015-04-15 02:12 - 2013-07-04 17:27 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2015-04-15 02:12 - 2013-07-04 17:21 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2015-04-15 02:12 - 2013-07-04 15:18 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-04-15 02:12 - 2012-09-26 04:17 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll 2015-04-15 02:12 - 2012-05-01 10:14 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-04-15 02:12 - 2012-03-17 12:57 - 00056176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2015-04-15 02:12 - 2011-12-16 13:22 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll 2015-04-15 02:12 - 2011-11-17 11:05 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2015-04-15 02:11 - 2014-10-14 07:26 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-15 02:11 - 2014-10-14 07:20 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-15 02:11 - 2014-10-14 07:20 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2015-04-15 02:11 - 2014-10-14 07:17 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-15 02:11 - 2014-10-14 07:16 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-15 02:11 - 2014-07-17 07:10 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2015-04-15 02:11 - 2014-07-17 07:09 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-04-15 02:11 - 2014-07-17 07:09 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2015-04-15 02:11 - 2014-07-17 07:09 - 00919552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-04-15 02:11 - 2014-07-17 07:09 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2015-04-15 02:11 - 2014-07-17 07:09 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll 2015-04-15 02:11 - 2014-07-17 07:09 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2015-04-15 02:11 - 2014-07-17 06:33 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2015-04-15 02:11 - 2014-07-17 06:32 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2015-04-15 02:11 - 2014-04-12 07:45 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-15 02:11 - 2014-04-12 07:42 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-15 02:11 - 2014-04-12 07:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-15 02:11 - 2014-04-12 07:42 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-15 02:11 - 2014-04-12 07:41 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-15 02:11 - 2013-10-12 07:33 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2015-04-15 02:11 - 2013-07-04 17:46 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-04-15 02:11 - 2013-02-15 08:55 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2015-04-15 02:11 - 2012-11-23 08:18 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe 2015-04-15 02:11 - 2012-05-14 10:03 - 00769024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2015-04-15 02:11 - 2012-04-26 10:15 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll 2015-04-15 02:11 - 2012-04-26 10:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe 2015-04-15 02:11 - 2012-01-04 14:28 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2015-04-15 02:10 - 2014-03-04 14:47 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-04-15 02:10 - 2014-01-29 07:36 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2015-04-15 02:10 - 2013-10-06 01:27 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-04-15 02:10 - 2013-08-02 07:20 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 07:18 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 06:22 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-04-15 02:10 - 2013-08-02 06:13 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 06:13 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 06:13 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-04-15 02:10 - 2013-08-02 06:13 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-04-15 02:10 - 2013-07-12 15:38 - 00146816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2015-04-15 02:10 - 2013-07-12 15:37 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2015-04-15 02:10 - 2013-07-09 10:16 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-04-15 02:10 - 2013-07-09 10:16 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2015-04-15 02:10 - 2012-10-09 23:10 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2015-04-15 02:10 - 2012-10-09 23:10 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2015-04-15 02:01 - 2014-06-25 07:11 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-04-15 02:01 - 2014-04-25 07:36 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2015-04-15 02:01 - 2013-11-27 06:44 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2015-04-15 02:01 - 2013-11-27 06:43 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2015-04-15 02:01 - 2013-11-27 06:43 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2015-04-15 02:01 - 2013-11-27 06:43 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2015-04-15 02:01 - 2013-11-27 06:43 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2015-04-15 02:01 - 2013-11-27 06:43 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2015-04-15 02:01 - 2013-11-27 06:43 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2015-04-15 02:01 - 2013-06-26 04:26 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2015-04-15 02:01 - 2012-11-29 04:27 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys 2015-04-15 02:01 - 2012-11-29 04:27 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll 2015-04-15 02:01 - 2012-11-29 04:27 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2015-04-15 00:16 - 2012-02-17 11:04 - 00826880 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2015-04-15 00:16 - 2012-02-17 09:43 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-05-12 20:06 - 2014-07-03 17:06 - 00001694 _____ () C:\Windows\Tasks\6e6cd208-0efe-4538-accb-e2ac55bf206c-7.job 2015-05-12 20:06 - 2014-07-02 18:06 - 00001718 _____ () C:\Windows\Tasks\7c50704a-df5b-4d48-82d1-351213e1cf36-7.job 2015-05-12 20:06 - 2013-06-03 16:39 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-05-12 20:03 - 2014-03-31 21:58 - 00000000 ____D () C:\Users\john\AppData\Roaming\EQATEC Analytics 2015-05-12 20:03 - 2011-03-07 20:03 - 00000000 ____D () C:\ProgramData\TEMP 2015-05-12 20:03 - 2010-10-04 05:59 - 01635615 _____ () C:\Windows\WindowsUpdate.log 2015-05-12 20:02 - 2014-07-03 17:08 - 00002082 _____ () C:\Windows\Tasks\a8ae6161-0f96-46cd-b86f-580f1aa2fa9f-5_user.job 2015-05-12 20:02 - 2014-07-03 17:08 - 00002082 _____ () C:\Windows\Tasks\a8ae6161-0f96-46cd-b86f-580f1aa2fa9f-5.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00003792 _____ () C:\Windows\Tasks\a8ae6161-0f96-46cd-b86f-580f1aa2fa9f-11.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00002402 _____ () C:\Windows\Tasks\6e6cd208-0efe-4538-accb-e2ac55bf206c-5_user.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00002402 _____ () C:\Windows\Tasks\6e6cd208-0efe-4538-accb-e2ac55bf206c-5.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00002152 _____ () C:\Windows\Tasks\a8ae6161-0f96-46cd-b86f-580f1aa2fa9f-4.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00001762 _____ () C:\Windows\Tasks\6e6cd208-0efe-4538-accb-e2ac55bf206c-1.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00001560 _____ () C:\Windows\Tasks\6e6cd208-0efe-4538-accb-e2ac55bf206c-2.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00001526 _____ () C:\Windows\Tasks\a8ae6161-0f96-46cd-b86f-580f1aa2fa9f-6.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00001524 _____ () C:\Windows\Tasks\a8ae6161-0f96-46cd-b86f-580f1aa2fa9f-1.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00001456 _____ () C:\Windows\Tasks\a8ae6161-0f96-46cd-b86f-580f1aa2fa9f-7.job 2015-05-12 20:02 - 2014-07-03 17:07 - 00001290 _____ () C:\Windows\Tasks\a8ae6161-0f96-46cd-b86f-580f1aa2fa9f-2.job 2015-05-12 20:02 - 2014-07-03 17:06 - 00004120 _____ () C:\Windows\Tasks\6e6cd208-0efe-4538-accb-e2ac55bf206c-11.job 2015-05-12 20:02 - 2014-07-03 17:06 - 00002354 _____ () C:\Windows\Tasks\6e6cd208-0efe-4538-accb-e2ac55bf206c-4.job 2015-05-12 20:02 - 2014-07-03 17:06 - 00001764 _____ () C:\Windows\Tasks\6e6cd208-0efe-4538-accb-e2ac55bf206c-6.job 2015-05-12 20:02 - 2014-07-02 18:07 - 00002400 _____ () C:\Windows\Tasks\7c50704a-df5b-4d48-82d1-351213e1cf36-5_user.job 2015-05-12 20:02 - 2014-07-02 18:07 - 00002400 _____ () C:\Windows\Tasks\7c50704a-df5b-4d48-82d1-351213e1cf36-5.job 2015-05-12 20:02 - 2014-07-02 18:07 - 00002366 _____ () C:\Windows\Tasks\7c50704a-df5b-4d48-82d1-351213e1cf36-4.job 2015-05-12 20:02 - 2014-07-02 18:07 - 00001772 _____ () C:\Windows\Tasks\7c50704a-df5b-4d48-82d1-351213e1cf36-1.job 2015-05-12 20:02 - 2014-07-02 18:06 - 00004112 _____ () C:\Windows\Tasks\7c50704a-df5b-4d48-82d1-351213e1cf36-11.job 2015-05-12 20:02 - 2014-07-02 18:06 - 00001780 _____ () C:\Windows\Tasks\7c50704a-df5b-4d48-82d1-351213e1cf36-6.job 2015-05-12 20:02 - 2014-07-02 18:06 - 00000938 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job 2015-05-12 20:02 - 2012-07-08 19:59 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-05-12 20:02 - 2011-07-15 17:45 - 00000302 ___SH () C:\Windows\Tasks\khdshrsrf.job 2015-05-12 20:02 - 2011-05-08 07:12 - 00511038 _____ () C:\Windows\setupact.log 2015-05-12 20:02 - 2011-01-30 14:36 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-05-12 20:02 - 2009-07-14 10:23 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-05-12 17:27 - 2014-02-16 20:26 - 00000288 _____ () C:\Windows\Tasks\Digital Sites.job 2015-05-12 17:27 - 2009-07-14 10:04 - 00017360 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-12 17:27 - 2009-07-14 10:04 - 00017360 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-12 17:22 - 2011-01-30 14:36 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-05-12 16:43 - 2010-10-03 17:36 - 00006648 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-05-12 15:57 - 2014-07-01 14:57 - 00000288 _____ () C:\Windows\Tasks\MySearchDial.job 2015-05-12 15:49 - 2010-10-03 17:43 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2015-05-12 15:19 - 2010-11-05 09:46 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2280821914-3189600555-3011743376-1000UA.job 2015-05-12 11:23 - 2014-12-04 12:32 - 00000000 ____D () C:\Users\john\AppData\Local\CrashDumps 2015-05-12 11:12 - 2014-07-02 18:06 - 00000942 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job 2015-05-03 18:04 - 2010-10-03 17:57 - 00224072 _____ () C:\Users\john\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-03 18:04 - 2009-07-14 10:03 - 01957160 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-05-03 11:53 - 2013-12-10 21:48 - 00000045 _____ () C:\Windows\TEXTware.ini 2015-05-03 11:52 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system 2015-04-29 15:44 - 2011-07-06 16:48 - 00000348 _____ () C:\Windows\Tasks\At1.job 2015-04-28 09:30 - 2014-01-24 15:24 - 00000000 ____D () C:\Program Files\Recuva 2015-04-28 09:17 - 2013-03-16 12:16 - 00000000 ____D () C:\ProgramData\Beroowse22suavee 2015-04-26 07:15 - 2011-03-28 21:22 - 00000000 ____D () C:\Users\john\Documents\WORD 2015-04-26 06:31 - 2014-07-01 14:59 - 00000000 ____D () C:\Program Files\Common Files\ShopperPro 2015-04-26 05:51 - 2014-07-02 18:06 - 00000000 ____D () C:\Program Files\Sense 2015-04-26 04:41 - 2013-08-21 20:26 - 00000178 _____ () C:\Users\john\AppData\Roaming\WB.CFG 2015-04-26 03:32 - 2014-12-25 13:25 - 00000000 ____D () C:\ProgramData\ShopperPro 2015-04-26 03:32 - 2014-07-01 14:59 - 00000000 ____D () C:\Program Files\ShopperPro 2015-04-22 19:26 - 2009-07-14 10:22 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-04-19 19:03 - 2011-11-09 14:15 - 00000000 ____D () C:\Program Files\UBISOFT 2015-04-19 18:39 - 2013-06-30 19:54 - 00000000 _____ () C:\adorage-protocol.txt 2015-04-19 18:24 - 2011-05-28 11:51 - 00474326 _____ () C:\Windows\PFRO.log 2015-04-19 18:21 - 2013-06-06 10:22 - 00000000 ____D () C:\Users\john\AppData\Roaming\Opera 2015-04-19 18:21 - 2013-06-06 10:22 - 00000000 ____D () C:\Users\john\AppData\Local\Opera 2015-04-19 18:21 - 2013-06-06 10:22 - 00000000 ____D () C:\Program Files\Opera 2015-04-19 18:21 - 2011-02-02 16:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo! 2015-04-19 18:21 - 2011-02-02 16:31 - 00000000 ____D () C:\Program Files\Photo! 2015-04-19 18:19 - 2011-07-01 16:39 - 00000000 ____D () C:\Users\john\AppData\Local\Unity 2015-04-16 17:56 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\Microsoft.NET 2015-04-15 07:21 - 2011-05-04 08:31 - 00000000 ____D () C:\Windows\system32\Drivers\ar-SA 2015-04-15 07:21 - 2009-07-14 13:20 - 00000000 ____D () C:\Program Files\Windows Journal 2015-04-15 07:21 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\fr-FR 2015-04-15 07:21 - 2009-07-14 08:07 - 00000000 ____D () C:\Windows\system32\ar-SA 2015-04-15 07:21 - 2009-07-14 08:07 - 00000000 ____D () C:\Program Files\Common Files\System 2015-04-15 07:15 - 2010-10-03 17:38 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-04-15 06:50 - 2009-07-14 10:22 - 00000000 ____D () C:\Program Files\Windows Defender 2015-04-15 06:48 - 2011-05-04 08:33 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2015-04-15 03:20 - 2011-05-04 08:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-04-15 03:06 - 2011-09-10 12:37 - 00000452 _____ () C:\Windows\win.ini 2015-04-15 02:27 - 2014-12-13 02:42 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d016506776cf4c.job 2015-04-15 02:27 - 2014-12-13 01:35 - 00000852 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2280821914-3189600555-3011743376-1000Core1d01646fee86a63.job 2015-04-12 14:37 - 2011-05-10 13:49 - 00465496 _____ () C:\Windows\DirectX.log ==================== Files in the root of some directories ======= 2012-06-27 21:24 - 2012-06-27 21:24 - 0000288 _____ () C:\Users\john\AppData\Roaming\.backup.dm 2011-12-27 20:15 - 2014-02-05 18:22 - 0000132 _____ () C:\Users\john\AppData\Roaming\Adobe BMP Format CS5 Prefs 2011-06-26 18:38 - 2012-02-11 08:59 - 0000132 _____ () C:\Users\john\AppData\Roaming\Adobe GIF Format CS5 Prefs 2011-12-27 20:16 - 2015-03-05 15:34 - 0000132 _____ () C:\Users\john\AppData\Roaming\Adobe PNG Format CS5 Prefs 2015-03-03 21:15 - 2015-03-03 21:17 - 0000132 _____ () C:\Users\john\AppData\Roaming\Adobe Targa Format CS5 Prefs 2013-09-28 17:40 - 2013-09-28 17:40 - 0022328 _____ () C:\Users\john\AppData\Roaming\PnkBstrK.sys 2011-05-12 18:05 - 2011-05-12 18:05 - 0000057 _____ () C:\Users\john\AppData\Roaming\temp.bat 2010-10-03 18:07 - 2011-02-25 19:32 - 5046202 _____ () C:\Users\john\AppData\Roaming\UserTile.png 2013-08-21 20:26 - 2015-04-26 04:41 - 0000178 _____ () C:\Users\john\AppData\Roaming\WB.CFG 2013-08-21 20:26 - 2014-01-16 14:09 - 0000005 _____ () C:\Users\john\AppData\Roaming\WBPU-TTL.DAT 2013-06-02 13:07 - 2013-06-02 13:07 - 0000037 ___SH () C:\Users\john\AppData\Local\20986331705021ca58edc424.96250074 2010-10-08 18:36 - 2013-07-07 18:55 - 0069120 _____ () C:\Users\john\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-05-09 20:50 - 2012-05-09 20:50 - 0000092 _____ () C:\Users\john\AppData\Local\fusioncache.dat 2014-01-13 18:44 - 2014-01-13 18:45 - 0007599 _____ () C:\Users\john\AppData\Local\resmon.resmoncfg 2013-08-02 16:49 - 2013-08-17 12:03 - 0000080 _____ () C:\Users\john\AppData\Local\X-Plane Installer.prf 2011-05-05 21:11 - 2011-05-06 08:38 - 0000000 _____ () C:\ProgramData\CLDShowX.ini 2010-10-03 17:50 - 2013-06-01 10:14 - 0015008 _____ () C:\ProgramData\hpzinstall.log ZeroAccess: C:\Users\john\AppData\Local\NFS Underground 2 C:\Users\john\AppData\Local\NFS Underground 2\Simon Magazine 5\Simon Magazine 5 C:\Users\john\AppData\Local\NFS Underground 2\Simon Magazine 4\Simon Magazine 4 C:\Users\john\AppData\Local\NFS Underground 2\Simon Magazine 3\Simon Magazine 3 C:\Users\john\AppData\Local\NFS Underground 2\Simon Magazine 2\Simon Magazine 2 C:\Users\john\AppData\Local\NFS Underground 2\Simon Magazine 1\Simon Magazine 1 C:\Users\john\AppData\Local\NFS Underground 2\Simon DVD 3\Simon DVD 3 C:\Users\john\AppData\Local\NFS Underground 2\Simon DVD 2\Simon DVD 2 C:\Users\john\AppData\Local\NFS Underground 2\Simon DVD 1\Simon DVD 1 C:\Users\john\AppData\Local\NFS Underground 2\Simon\Simon C:\Users\john\AppData\Local\NFS Underground 2\N\N Files to move or delete: ==================== C:\Windows\Tasks\At1.job C:\Windows\Tasks\At2.job Some content of TEMP: ==================== C:\Users\john\AppData\Local\Temp\AskPIP_FF_.exe C:\Users\john\AppData\Local\Temp\AutoRun.exe C:\Users\john\AppData\Local\Temp\AutoRunGUI.dll C:\Users\john\AppData\Local\Temp\drm_dyndata_7380012.dll C:\Users\john\AppData\Local\Temp\ShopperProJSINJFull.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-14 13:55 ==================== End Of Log ============================