Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Anybody Care to check out some logs to ease some suspicion


  • Please log in to reply

#1
Kman4488

Kman4488

    Member

  • Member
  • PipPip
  • 40 posts

I had av avast pick up on 2 files on was my old kapersky av , wich it reported was a fake. the other was a memtest file from windows SDK that said possible rootkit , i had done a system restore due to the fact everything was so slow it was nearly impossible to navigate windows . now im concerned 


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,007 posts
  • MVP

Download OTL from
http://www.geekstogo...timers-list-it/
and Save it to your desktop.
 

Download : ADWCleaner to your desktop.  Make sure you get the correct Download button.  Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @BleepingComputer

NOTE: If using Internet Explorer and you get an alert that stops the program downloading, click on the warning and allow the download to complete.

Close  all programs, pause your anti-virus and run AdwCleaner (Vista or Win 7 => right click and Run As Administrator).

scan-results.jpg

Click on Scan  and follow the prompts. Let it run unhindered. When done, click on the Clean button, and follow the prompts. Allow the system to reboot. You will then be presented with the report. Copy & Paste this report on your next reply.

The report will be saved in the C:\AdwCleaner folder.



Junkware-Removal-Tool

Please download Junkware Removal Tool to your desktop.  Make sure you get the correct Download button.  Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @Author's site

  • Pause your anti-virus.  Close all browsers.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.




Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.  
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.



Copy the text in the code box:

DRIVES
nnetsvcs
%SYSTEMDRIVE%\*.exe
%systemroot%\assembly\GAC_32\*.ini
%systemroot%\assembly\GAC_64\*.ini
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.exe
%APPDATA%\*.
/md5start
rsvpsp.dll
pnrpnsp.dll
nwprovau.dll
nlaapi.dll
napinsp.dll
mswsock.dll
winrnr.dll
wshelper.dll
services.exe
atapi.sys
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
csrss.exe
PrintIsolationHost.exe
consrv.dll
user32.dll
/md5stop
C:\Windows\assembly\tmp\U\*.* /s
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%ProgramFiles%\WINDOWS NT\*.* /s
%systemroot%\system32\drivers\*.sys /lockedfiles
CREATERESTOREPOINT

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes

Select the All option in the Extra Registry group then Run Scan.

You should get two logs.  Please copy and paste both of them.

Ron
  • 0

#3
Kman4488

Kman4488

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts

Sorry I didn't see I had a reply , im running those right now ill post the results momentarily


  • 0

#4
Kman4488

Kman4488

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts

OTL

 

OTL logfile created on: 4/14/2014 1:47:11 AM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Karl\Desktop
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
7.46 Gb Total Physical Memory | 5.78 Gb Available Physical Memory | 77.57% Memory free
9.27 Gb Paging File | 7.55 Gb Available in Paging File | 81.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 233.00 Gb Total Space | 209.14 Gb Free Space | 89.76% Space Free | Partition Type: NTFS
Drive E: | 212.07 Gb Total Space | 211.95 Gb Free Space | 99.94% Space Free | Partition Type: NTFS
 
Computer Name: COMPTONCOMPUTE | User Name: Karl | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/04/13 20:20:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Karl\Desktop\OTL.exe
PRC - [2014/03/15 03:40:21 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014/02/21 15:59:18 | 001,294,136 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
PRC - [2014/02/21 15:59:18 | 000,319,288 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/03/15 03:40:39 | 003,642,480 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/02/06 05:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/12/13 10:23:32 | 000,239,616 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2013/12/06 16:06:06 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2013/11/27 10:36:30 | 003,395,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2013/11/27 04:17:40 | 000,263,168 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2013/11/22 23:50:00 | 000,282,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2013/11/07 22:41:17 | 001,302,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:64bit: - [2013/10/30 19:29:53 | 000,348,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:64bit: - [2013/10/30 19:29:53 | 000,023,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:64bit: - [2013/10/10 17:54:28 | 000,144,152 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:64bit: - [2013/10/04 03:10:59 | 000,533,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:64bit: - [2013/09/21 00:38:15 | 000,365,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2013/09/21 00:34:45 | 001,555,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2013/08/31 05:00:10 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:64bit: - [2013/08/22 14:12:03 | 000,183,296 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2013/08/22 14:12:02 | 000,090,464 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\KeyboardFilterSvc.dll -- (MsKeyboardFilter)
SRV:64bit: - [2013/08/22 14:12:02 | 000,022,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlms\wlms.exe -- (WLMS)
SRV:64bit: - [2013/08/22 07:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2013/08/22 06:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:64bit: - [2013/08/22 06:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2013/08/22 06:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2013/08/22 06:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2013/08/22 06:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2013/08/22 05:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2013/08/22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2013/08/22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2013/08/22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2013/08/22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2013/08/22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2013/08/22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2013/08/22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:64bit: - [2013/08/22 05:04:53 | 000,716,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2013/08/22 05:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:64bit: - [2013/08/22 04:59:26 | 000,832,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2013/08/22 04:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:64bit: - [2013/08/22 04:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2013/08/22 04:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2013/08/22 04:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2013/08/22 04:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:64bit: - [2013/08/22 04:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2013/08/22 04:40:14 | 000,398,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2013/08/22 04:39:33 | 000,198,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2013/08/22 04:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2013/08/22 04:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV - [2014/03/15 03:40:31 | 000,119,408 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/02/21 15:59:18 | 000,319,288 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe -- (MbaeSvc)
SRV - [2013/08/31 04:25:30 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2013/08/22 07:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2013/08/21 22:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013/08/21 21:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/03/10 05:35:53 | 000,377,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2014/01/07 20:46:27 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2013/12/13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013/12/13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013/11/10 21:48:41 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:64bit: - [2013/11/04 03:32:06 | 000,020,280 | ---- | M] (ASUS) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AsHIDSwitch64.sys -- (HIDSwitch)
DRV:64bit: - [2013/11/01 06:39:53 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:64bit: - [2013/10/30 19:58:59 | 000,372,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2013/10/30 19:29:36 | 000,236,888 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2013/10/30 19:29:36 | 000,124,760 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:64bit: - [2013/10/30 19:28:47 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2013/10/25 20:54:32 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:64bit: - [2013/10/12 21:48:34 | 000,136,536 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2013/10/05 10:25:54 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:64bit: - [2013/09/21 07:10:51 | 000,236,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2013/09/19 23:05:02 | 000,059,648 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2.0)
DRV:64bit: - [2013/09/17 04:18:30 | 000,467,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2013/09/14 09:06:57 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2013/08/22 14:12:06 | 000,022,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\kbldfltr.sys -- (kbldfltr)
DRV:64bit: - [2013/08/22 14:12:03 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2013/08/22 14:11:51 | 000,111,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2013/08/22 14:11:51 | 000,056,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2013/08/22 14:11:51 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2013/08/22 14:11:50 | 000,220,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Vid.sys -- (Vid)
DRV:64bit: - [2013/08/22 14:11:50 | 000,129,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbusr.sys -- (vmbusr)
DRV:64bit: - [2013/08/22 14:11:50 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsp.sys -- (storvsp)
DRV:64bit: - [2013/08/22 14:11:50 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcivsp.sys -- (vpcivsp)
DRV:64bit: - [2013/08/22 08:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:64bit: - [2013/08/22 08:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2013/08/22 07:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:64bit: - [2013/08/22 07:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2013/08/22 07:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2013/08/22 07:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2013/08/22 07:43:48 | 000,146,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2013/08/22 07:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2013/08/22 07:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2013/08/22 07:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2013/08/22 07:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2013/08/22 07:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2013/08/22 07:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:64bit: - [2013/08/22 07:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:64bit: - [2013/08/22 07:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2013/08/22 07:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2013/08/22 07:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:64bit: - [2013/08/22 07:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2013/08/22 07:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2013/08/22 07:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2013/08/22 07:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2013/08/22 07:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2013/08/22 07:43:33 | 000,189,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2013/08/22 07:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2013/08/22 07:43:32 | 000,078,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2013/08/22 07:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2013/08/22 07:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013/08/22 07:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2013/08/22 07:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2013/08/22 07:41:08 | 000,054,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2013/08/22 07:39:15 | 000,924,512 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refs.sys -- (ReFS)
DRV:64bit: - [2013/08/22 07:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:64bit: - [2013/08/22 07:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:64bit: - [2013/08/22 07:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2013/08/22 06:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:64bit: - [2013/08/22 06:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2013/08/22 06:39:28 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2013/08/22 06:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2013/08/22 06:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2013/08/22 06:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2013/08/22 06:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2013/08/22 06:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013/08/22 06:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2013/08/22 06:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2013/08/22 06:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2013/08/22 06:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2013/08/22 06:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2013/08/22 06:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2013/08/22 06:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2013/08/22 06:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/08/22 06:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2013/08/22 06:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2013/08/22 06:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:64bit: - [2013/08/22 06:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:64bit: - [2013/08/22 06:36:17 | 000,124,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2013/08/22 06:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2013/08/22 06:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2013/08/22 03:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2013/08/12 18:25:46 | 000,017,624 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:64bit: - [2013/08/09 19:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:64bit: - [2013/07/30 13:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:64bit: - [2013/07/25 14:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:64bit: - [2013/06/18 09:46:17 | 000,591,360 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2013/06/18 09:45:02 | 003,680,256 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athw8x.sys -- (athr)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV - [2014/02/21 15:59:18 | 000,062,168 | ---- | M] () [Kernel | System | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys -- (ESProtectionDriver)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20131118
FF - prefs.js..extensions.enabledAddons: safepreview%40everhelper.me:1.1.2
FF - prefs.js..extensions.enabledAddons: %7Bf53ae83d-ca13-4cf8-8fd4-c58ae36051b4%7D:0.7.1
FF - prefs.js..extensions.enabledAddons: %7Bf36c6cd1-da73-491d-b290-8fc9115bfa55%7D:3.0.8
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:28.0
FF - user.js - File not found
 
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2014/04/13 19:18:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Karl\AppData\Roaming\mozilla\Extensions
[2014/04/14 00:28:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Karl\AppData\Roaming\mozilla\Firefox\Profiles\8tyseozw.default\extensions
[2014/04/13 19:40:20 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Karl\AppData\Roaming\mozilla\Firefox\Profiles\8tyseozw.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2014/04/13 19:40:21 | 000,267,869 | ---- | M] () (No name found) -- C:\Users\Karl\AppData\Roaming\mozilla\firefox\profiles\8tyseozw.default\extensions\[email protected]
[2014/04/14 00:28:14 | 000,799,362 | ---- | M] () (No name found) -- C:\Users\Karl\AppData\Roaming\mozilla\firefox\profiles\8tyseozw.default\extensions\{f36c6cd1-da73-491d-b290-8fc9115bfa55}.xpi
[2014/04/14 00:28:14 | 000,060,509 | ---- | M] () (No name found) -- C:\Users\Karl\AppData\Roaming\mozilla\firefox\profiles\8tyseozw.default\extensions\{f53ae83d-ca13-4cf8-8fd4-c58ae36051b4}.xpi
[2014/04/06 21:42:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/04/06 21:42:55 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
O1 HOSTS File: ([2014/04/14 01:17:11 | 000,000,741 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1    localhost
O4 - HKLM..\Run: [Malwarebytes Anti-Exploit] C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF72D8CA-5E90-47E6-AD10-4D9D8D0C6921}: DhcpNameServer = 192.168.1.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs:64bit: lfsvc - C:\Windows\SysNative\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
NetSvcs:64bit: MsKeyboardFilter - C:\Windows\SysNative\KeyboardFilterSvc.dll (Microsoft Corporation)
 
MsConfig:64bit - State: "services" - Reg Error: Key error.
 
SafeBootMin:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootMin:64bit: BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SafeBootMin:64bit: EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SafeBootMin:64bit: LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SafeBootMin:64bit: Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootMin:64bit: TBS - Service
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootMin:64bit: WLMS - C:\Windows\SysNative\wlms\wlms.exe (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin:64bit: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: TBS - Service
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootMin: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
SafeBootNet:64bit: !SASCORE - C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: BasicDisplay.sys - C:\Windows\SysNative\drivers\BasicDisplay.sys (Microsoft Corporation)
SafeBootNet:64bit: BasicRender.sys - C:\Windows\SysNative\drivers\BasicRender.sys (Microsoft Corporation)
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: BrokerInfrastructure - C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SafeBootNet:64bit: Browser - Service
SafeBootNet:64bit: EFS - C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: KeyIso - C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SafeBootNet:64bit: LSM - C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: mrxsmb10 - Driver
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Netlogon - C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SafeBootNet:64bit: netprofm - C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdpencdd.sys - Driver
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: SmartcardSimulator - Driver
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SafeBootNet:64bit: TBS - Service
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: VaultSvc - C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: VirtualSmartcardReader - Driver
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: Wcmsvc - C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SafeBootNet:64bit: WLMS - C:\Windows\SysNative\wlms\wlms.exe (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet:64bit: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: Browser - Service
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: mrxsmb10 - Driver
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdpencdd.sys - Driver
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: SmartcardSimulator - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TBS - Service
SafeBootNet: TDI - Driver Group
SafeBootNet: VirtualSmartcardReader - Driver
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {9DA2B80F-F89F-4A49-A5C2-511B085B9E8A} - Enhanced Storage Devices
SafeBootNet: {A0A588A4-C46F-4B37-B7EA-C82FE89870C6} - SDA Standard Compliant SD Host Controller
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
 
ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - /UserInstall
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {78E345F7-E976-3595-9C30-2458D6A8EC32} - .NET Framework
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - U
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\System32\Rundll32.exe C:\Windows\System32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} -
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EC43E638-09F0-38CC-A585-72FCCDDF035C} - .NET Framework
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
 
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/04/14 01:40:18 | 000,000,000 | ---D | C] -- C:\FRST
[2014/04/14 00:15:50 | 107,394,336 | ---- | C] (Oracle Corporation) -- C:\Users\Karl\Desktop\VirtualBox-4.3.10-93012-Win.exe
[2014/04/14 00:12:38 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\Diagnostics
[2014/04/14 00:01:58 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\AMD
[2014/04/14 00:01:45 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\ATI
[2014/04/14 00:01:45 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\ATI
[2014/04/14 00:01:45 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2014/04/13 23:17:06 | 000,000,000 | ---D | C] -- C:\Program Files\Reason
[2014/04/13 23:17:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\herdProtect
[2014/04/13 23:04:47 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Karl\Desktop\MBR.com.exe
[2014/04/13 23:00:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sophos
[2014/04/13 23:00:11 | 000,000,000 | ---D | C] -- C:\Users\Karl\Pavark
[2014/04/13 22:51:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Sophos
[2014/04/13 22:44:40 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sophos
[2014/04/13 22:44:38 | 000,000,000 | ---D | C] -- C:\Sophos
[2014/04/13 22:44:30 | 000,000,000 | ---D | C] -- C:\scss_10
[2014/04/13 22:13:25 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2014/04/13 21:51:04 | 018,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Xaml.dll
[2014/04/13 21:51:01 | 013,949,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2014/04/13 21:50:57 | 002,143,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmcore.dll
[2014/04/13 21:50:57 | 002,140,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2014/04/13 21:50:57 | 001,765,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dwmcore.dll
[2014/04/13 21:50:56 | 001,765,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2014/04/13 21:50:56 | 001,720,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2014/04/13 21:50:56 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncHost.exe
[2014/04/13 21:50:56 | 000,516,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2014/04/13 21:50:56 | 000,481,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfsvr.dll
[2014/04/13 21:50:56 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSyncHost.exe
[2014/04/13 21:50:55 | 000,960,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MFMediaEngine.dll
[2014/04/13 21:50:55 | 000,914,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ReAgent.dll
[2014/04/13 21:50:55 | 000,842,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.dll
[2014/04/13 21:50:55 | 000,802,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MFMediaEngine.dll
[2014/04/13 21:50:55 | 000,770,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ReAgent.dll
[2014/04/13 21:50:55 | 000,749,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSyncCore.dll
[2014/04/13 21:50:55 | 000,588,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSyncCore.dll
[2014/04/13 21:50:55 | 000,461,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2014/04/13 21:50:55 | 000,419,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\hal.dll
[2014/04/13 21:50:55 | 000,382,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2014/04/13 21:50:55 | 000,381,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfsvr.dll
[2014/04/13 21:50:55 | 000,336,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2014/04/13 21:50:55 | 000,206,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSClient.dll
[2014/04/13 21:50:55 | 000,174,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSClient.dll
[2014/04/13 21:50:54 | 000,947,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\reseteng.dll
[2014/04/13 21:50:54 | 000,630,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsSpellCheckingFacility.dll
[2014/04/13 21:50:54 | 000,325,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBXHCI.SYS
[2014/04/13 21:50:54 | 000,303,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sti.dll
[2014/04/13 21:50:54 | 000,178,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\easwrt.dll
[2014/04/13 21:50:54 | 000,140,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\easwrt.dll
[2014/04/13 21:50:54 | 000,131,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\easinvoker.exe
[2014/04/13 21:50:50 | 000,688,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MrmIndexer.dll
[2014/04/13 21:50:49 | 000,515,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MrmIndexer.dll
[2014/04/13 21:50:21 | 002,328,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2014/04/13 21:50:20 | 002,065,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\explorer.exe
[2014/04/13 21:50:20 | 001,067,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfasfsrcsnk.dll
[2014/04/13 21:50:19 | 000,883,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfasfsrcsnk.dll
[2014/04/13 21:50:18 | 002,134,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d9.dll
[2014/04/13 21:50:18 | 001,160,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Web.Http.dll
[2014/04/13 21:50:18 | 000,708,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iuilp.dll
[2014/04/13 21:50:17 | 001,231,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.dll
[2014/04/13 21:50:17 | 001,147,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAutomationCore.dll
[2014/04/13 21:50:17 | 001,011,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll
[2014/04/13 21:50:17 | 000,920,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
[2014/04/13 21:50:17 | 000,699,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2014/04/13 21:50:17 | 000,656,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dnsapi.dll
[2014/04/13 21:50:17 | 000,533,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppReadiness.dll
[2014/04/13 21:50:16 | 000,888,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.dll
[2014/04/13 21:50:16 | 000,631,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WWAHost.exe
[2014/04/13 21:50:16 | 000,578,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.BackgroundTransfer.dll
[2014/04/13 21:50:16 | 000,518,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WWAHost.exe
[2014/04/13 21:50:16 | 000,411,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Networking.BackgroundTransfer.dll
[2014/04/13 21:50:16 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapphost.dll
[2014/04/13 21:50:16 | 000,171,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kd_02_8086.dll
[2014/04/13 21:50:15 | 000,795,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll
[2014/04/13 21:50:15 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\comdlg32.dll
[2014/04/13 21:50:15 | 000,558,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apphelp.dll
[2014/04/13 21:50:15 | 000,465,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AudioSes.dll
[2014/04/13 21:50:15 | 000,391,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsmf.dll
[2014/04/13 21:50:15 | 000,325,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eapp3hst.dll
[2014/04/13 21:50:15 | 000,317,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2014/04/13 21:50:14 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll
[2014/04/13 21:50:14 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Web.Http.dll
[2014/04/13 21:50:14 | 000,345,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsmf.dll
[2014/04/13 21:50:14 | 000,286,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcsvDevice.dll
[2014/04/13 21:50:14 | 000,262,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapphost.dll
[2014/04/13 21:50:14 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\miutils.dll
[2014/04/13 21:50:14 | 000,132,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msched.dll
[2014/04/13 21:50:14 | 000,104,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncryptsslp.dll
[2014/04/13 21:50:14 | 000,096,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\embeddedapplauncher.exe
[2014/04/13 21:50:14 | 000,088,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncryptsslp.dll
[2014/04/13 21:50:14 | 000,044,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wldp.dll
[2014/04/13 21:50:13 | 000,381,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUSettingsProvider.dll
[2014/04/13 21:50:13 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eappcfg.dll
[2014/04/13 21:50:13 | 000,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eapp3hst.dll
[2014/04/13 21:50:13 | 000,184,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dafWfdProvider.dll
[2014/04/13 21:50:13 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shsetup.dll
[2014/04/13 21:50:13 | 000,103,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WiFiDisplay.dll
[2014/04/13 21:50:13 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\shsetup.dll
[2014/04/13 21:50:13 | 000,092,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dafBth.dll
[2014/04/13 21:50:13 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2014/04/13 21:50:13 | 000,057,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\stornvme.sys
[2014/04/13 21:50:13 | 000,054,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2014/04/13 21:50:12 | 001,704,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2014/04/13 21:50:12 | 000,338,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpclip.exe
[2014/04/13 21:50:12 | 000,272,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eappcfg.dll
[2014/04/13 21:50:12 | 000,180,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\miutils.dll
[2014/04/13 21:50:12 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\eappgnui.dll
[2014/04/13 21:50:12 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\eappgnui.dll
[2014/04/13 21:50:12 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ftp.exe
[2014/04/13 21:50:12 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ftp.exe
[2014/04/13 21:49:54 | 003,210,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msmpeg2vdec.dll
[2014/04/13 21:49:53 | 002,804,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msmpeg2vdec.dll
[2014/04/13 21:49:50 | 001,415,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2014/04/13 21:49:50 | 001,399,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winmde.dll
[2014/04/13 21:49:49 | 002,617,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2014/04/13 21:49:49 | 002,295,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2014/04/13 21:49:49 | 001,374,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpmde.dll
[2014/04/13 21:49:49 | 001,204,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winmde.dll
[2014/04/13 21:49:49 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SystemEventsBrokerServer.dll
[2014/04/13 21:49:49 | 000,263,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bisrv.dll
[2014/04/13 21:49:49 | 000,202,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ubpm.dll
[2014/04/13 21:49:48 | 000,809,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfmp4srcsnk.dll
[2014/04/13 21:49:48 | 000,745,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2014/04/13 21:49:48 | 000,663,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfmp4srcsnk.dll
[2014/04/13 21:49:48 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfds.dll
[2014/04/13 21:49:48 | 000,273,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Graphics.dll
[2014/04/13 21:49:48 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psmsrv.dll
[2014/04/13 21:49:48 | 000,032,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ploptin.dll
[2014/04/13 21:49:47 | 001,227,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mispace.dll
[2014/04/13 21:49:47 | 000,980,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mispace.dll
[2014/04/13 21:49:47 | 000,589,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rastls.dll
[2014/04/13 21:49:47 | 000,433,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfds.dll
[2014/04/13 21:49:47 | 000,306,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msieftp.dll
[2014/04/13 21:49:47 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Graphics.dll
[2014/04/13 21:49:47 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\bi.dll
[2014/04/13 21:49:47 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\BtaMPM.sys
[2014/04/13 21:49:46 | 000,513,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rastls.dll
[2014/04/13 21:49:46 | 000,273,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msieftp.dll
[2014/04/13 21:49:46 | 000,207,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\deviceregistration.dll
[2014/04/13 21:49:36 | 001,085,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.appcore.dll
[2014/04/13 21:49:36 | 000,869,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.appcore.dll
[2014/04/13 21:49:17 | 007,399,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014/04/13 21:49:17 | 001,302,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentServer.dll
[2014/04/13 21:49:15 | 002,570,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingsHandlers.dll
[2014/04/13 21:49:15 | 000,358,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dcomp.dll
[2014/04/13 21:49:14 | 002,896,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msftedit.dll
[2014/04/13 21:49:14 | 001,756,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPDMC.exe
[2014/04/13 21:49:14 | 001,476,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2014/04/13 21:49:14 | 001,345,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.exe
[2014/04/13 21:49:14 | 000,747,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlidcli.dll
[2014/04/13 21:49:14 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dcomp.dll
[2014/04/13 21:49:14 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AppxAllUserStore.dll
[2014/04/13 21:49:13 | 002,266,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msftedit.dll
[2014/04/13 21:49:13 | 001,843,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Display.dll
[2014/04/13 21:49:13 | 001,816,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Display.dll
[2014/04/13 21:49:13 | 001,391,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPDMC.exe
[2014/04/13 21:49:13 | 000,922,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2014/04/13 21:49:13 | 000,566,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpncore.dll
[2014/04/13 21:49:13 | 000,449,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appmgr.dll
[2014/04/13 21:49:13 | 000,372,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\spaceport.sys
[2014/04/13 21:49:13 | 000,254,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppXDeploymentClient.dll
[2014/04/13 21:49:13 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\AppXDeploymentClient.dll
[2014/04/13 21:49:13 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\AppxAllUserStore.dll
[2014/04/13 21:49:13 | 000,146,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\SerCx2.sys
[2014/04/13 21:49:13 | 000,086,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\pdc.sys
[2014/04/13 21:49:13 | 000,039,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\intelpep.sys
[2014/04/13 21:49:13 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CredentialMigrationHandler.dll
[2014/04/13 21:49:13 | 000,027,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CredentialMigrationHandler.dll
[2014/04/13 21:49:12 | 000,544,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlidcli.dll
[2014/04/13 21:49:12 | 000,366,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appmgr.dll
[2014/04/13 21:48:28 | 011,366,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\glcndFilter.dll
[2014/04/13 21:48:27 | 012,028,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Data.Pdf.dll
[2014/04/13 21:48:24 | 001,555,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlidsvc.dll
[2014/04/13 21:48:24 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WorkFoldersRes.dll
[2014/04/13 21:48:24 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WorkFoldersRes.dll
[2014/04/13 21:48:21 | 001,662,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Immersive.dll
[2014/04/13 21:48:21 | 000,796,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfsrcsnk.dll
[2014/04/13 21:48:21 | 000,783,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfnetcore.dll
[2014/04/13 21:48:20 | 008,712,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\glcndFilter.dll
[2014/04/13 21:48:19 | 008,875,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Data.Pdf.dll
[2014/04/13 21:48:19 | 001,455,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Immersive.dll
[2014/04/13 21:48:18 | 000,648,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfnetcore.dll
[2014/04/13 21:48:17 | 002,050,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SRH.dll
[2014/04/13 21:48:17 | 001,534,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll
[2014/04/13 21:48:17 | 001,150,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Globalization.dll
[2014/04/13 21:48:17 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Security.Authentication.OnlineId.dll
[2014/04/13 21:48:17 | 000,504,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.BackgroundTransfer.ContentPrefetchTask.dll
[2014/04/13 21:48:17 | 000,401,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlidprov.dll
[2014/04/13 21:48:16 | 001,730,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dui70.dll
[2014/04/13 21:48:16 | 000,996,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinTypes.dll
[2014/04/13 21:48:16 | 000,405,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vpnike.dll
[2014/04/13 21:48:16 | 000,314,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlidprov.dll
[2014/04/13 21:48:15 | 000,534,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wer.dll
[2014/04/13 21:48:15 | 000,524,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Security.Authentication.OnlineId.dll
[2014/04/13 21:48:14 | 000,934,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfsrcsnk.dll
[2014/04/13 21:48:13 | 000,802,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Globalization.dll
[2014/04/13 21:48:13 | 000,726,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinapi.dll
[2014/04/13 21:48:13 | 000,427,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll
[2014/04/13 21:48:12 | 001,344,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dui70.dll
[2014/04/13 21:48:12 | 000,570,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SettingSync.dll
[2014/04/13 21:48:12 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tpmvsc.dll
[2014/04/13 21:48:12 | 000,365,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wcmsvc.dll
[2014/04/13 21:48:12 | 000,171,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2014/04/13 21:48:11 | 001,741,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SRH.dll
[2014/04/13 21:48:11 | 000,552,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinapi.dll
[2014/04/13 21:48:11 | 000,366,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvproc.dll
[2014/04/13 21:48:11 | 000,240,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSCard.dll
[2014/04/13 21:48:10 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BulkOperationHost.exe
[2014/04/13 21:48:09 | 001,185,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printui.dll
[2014/04/13 21:48:09 | 000,528,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ci.dll
[2014/04/13 21:48:09 | 000,467,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\USBHUB3.SYS
[2014/04/13 21:48:09 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SettingSync.dll
[2014/04/13 21:48:09 | 000,312,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvproc.dll
[2014/04/13 21:48:09 | 000,273,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TetheringMgr.dll
[2014/04/13 21:48:09 | 000,236,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdbus.sys
[2014/04/13 21:48:09 | 000,205,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mftranscode.dll
[2014/04/13 21:48:09 | 000,194,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpapisrv.dll
[2014/04/13 21:48:09 | 000,180,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mftranscode.dll
[2014/04/13 21:48:09 | 000,123,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dwmapi.dll
[2014/04/13 21:48:08 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msra.exe
[2014/04/13 21:48:08 | 000,456,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sysmon.ocx
[2014/04/13 21:48:08 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DscCore.dll
[2014/04/13 21:48:08 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DscCoreConfProv.dll
[2014/04/13 21:48:07 | 000,358,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vmrdvcore.dll
[2014/04/13 21:48:07 | 000,290,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fdprint.dll
[2014/04/13 21:48:07 | 000,151,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dumpsd.sys
[2014/04/13 21:48:04 | 000,638,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\riched20.dll
[2014/04/13 21:48:04 | 000,426,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Devices.Usb.dll
[2014/04/13 21:48:04 | 000,233,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Devices.HumanInterfaceDevice.dll
[2014/04/13 21:48:03 | 000,970,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WebcamUi.dll
[2014/04/13 21:48:02 | 000,738,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctfuimanager.dll
[2014/04/13 21:48:02 | 000,393,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sysmon.ocx
[2014/04/13 21:48:02 | 000,334,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MDEServer.exe
[2014/04/13 21:48:02 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CryptoWinRT.dll
[2014/04/13 21:48:02 | 000,158,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\thumbcache.dll
[2014/04/13 21:48:01 | 001,225,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usercpl.dll
[2014/04/13 21:48:01 | 001,057,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\printui.dll
[2014/04/13 21:48:01 | 000,329,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpshell.exe
[2014/04/13 21:48:01 | 000,175,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\VerifierExt.sys
[2014/04/13 21:48:01 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SensorsClassExtension.dll
[2014/04/13 21:48:01 | 000,155,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Devices.HumanInterfaceDevice.dll
[2014/04/13 21:48:01 | 000,098,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\windows.immersiveshell.serviceprovider.dll
[2014/04/13 21:48:01 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Utilman.exe
[2014/04/13 21:48:01 | 000,066,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PSHED.DLL
[2014/04/13 21:48:00 | 000,813,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WebcamUi.dll
[2014/04/13 21:48:00 | 000,695,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msctfuimanager.dll
[2014/04/13 21:48:00 | 000,638,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wimgapi.dll
[2014/04/13 21:48:00 | 000,556,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\recimg.exe
[2014/04/13 21:48:00 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DeviceCenter.dll
[2014/04/13 21:48:00 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Devices.Usb.dll
[2014/04/13 21:48:00 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rascustom.dll
[2014/04/13 21:48:00 | 000,244,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Networking.Vpn.dll
[2014/04/13 21:48:00 | 000,153,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CryptoWinRT.dll
[2014/04/13 21:48:00 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\efswrt.dll
[2014/04/13 21:48:00 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BthRadioMedia.dll
[2014/04/13 21:48:00 | 000,054,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcaui.dll
[2014/04/13 21:48:00 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdsdwmdr.dll
[2014/04/13 21:47:59 | 001,160,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\usercpl.dll
[2014/04/13 21:47:59 | 000,528,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wimgapi.dll
[2014/04/13 21:47:59 | 000,482,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DeviceCenter.dll
[2014/04/13 21:47:59 | 000,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wlanmsm.dll
[2014/04/13 21:47:59 | 000,300,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wlanmsm.dll
[2014/04/13 21:47:59 | 000,256,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fdprint.dll
[2014/04/13 21:47:59 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2014/04/13 21:47:59 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pcaui.dll
[2014/04/13 21:47:58 | 000,253,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mcbuilder.exe
[2014/04/13 21:47:58 | 000,102,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\efswrt.dll
[2014/04/13 21:47:57 | 000,491,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\GeofenceMonitorService.dll
[2014/04/13 21:47:57 | 000,284,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mcbuilder.exe
[2014/04/13 21:47:57 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Utilman.exe
[2014/04/13 21:47:56 | 000,357,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\GeofenceMonitorService.dll
[2014/04/13 21:47:56 | 000,200,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ReInfo.dll
[2014/04/13 21:47:56 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2014/04/13 21:47:15 | 001,286,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msctf.dll
[2014/04/13 21:47:14 | 001,217,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Media.Streaming.dll
[2014/04/13 21:47:13 | 000,977,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Media.Streaming.dll
[2014/04/13 21:47:13 | 000,294,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.Devices.Sensors.dll
[2014/04/13 21:47:13 | 000,225,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.Devices.Sensors.dll
[2014/04/13 21:47:02 | 000,000,000 | ---D | C] -- C:\SUPERDelete
[2014/04/13 21:46:57 | 001,643,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2014/04/13 21:46:56 | 001,507,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.exe
[2014/04/13 21:46:56 | 000,075,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imagehlp.dll
[2014/04/13 21:46:55 | 000,570,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2014/04/13 21:46:40 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\poqexec.exe
[2014/04/13 21:46:40 | 000,124,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\poqexec.exe
[2014/04/13 21:46:38 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/04/13 21:46:38 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/04/13 21:46:37 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/04/13 21:46:37 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/04/13 21:46:35 | 001,964,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/04/13 21:46:35 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/04/13 21:46:35 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/04/13 21:46:35 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/04/13 21:46:35 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/04/13 21:46:34 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/04/13 21:46:33 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/04/13 21:46:33 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/04/13 21:46:32 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/04/13 21:46:32 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/04/13 21:46:32 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/04/13 21:46:32 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/04/13 21:46:30 | 005,768,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/04/13 21:46:30 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/04/13 21:46:30 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/04/13 21:46:29 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/04/13 21:46:29 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/04/13 21:46:20 | 004,604,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2014/04/13 21:46:19 | 002,397,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2014/04/13 21:46:18 | 002,133,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfcore.dll
[2014/04/13 21:46:18 | 001,928,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\combase.dll
[2014/04/13 21:46:17 | 006,640,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2014/04/13 21:46:17 | 002,143,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfcore.dll
[2014/04/13 21:46:17 | 001,371,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\combase.dll
[2014/04/13 21:46:17 | 000,764,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfmpeg2srcsnk.dll
[2014/04/13 21:46:16 | 005,770,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2014/04/13 21:46:16 | 004,175,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dbgeng.dll
[2014/04/13 21:46:16 | 001,486,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dbghelp.dll
[2014/04/13 21:46:16 | 000,669,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfmpeg2srcsnk.dll
[2014/04/13 21:46:15 | 002,873,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbgeng.dll
[2014/04/13 21:46:15 | 001,238,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dbghelp.dll
[2014/04/13 21:46:15 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdvidcrl.dll
[2014/04/13 21:46:15 | 000,458,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WerFault.exe
[2014/04/13 21:46:15 | 000,408,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WerFault.exe
[2014/04/13 21:46:15 | 000,407,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Faultrep.dll
[2014/04/13 21:46:15 | 000,369,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Faultrep.dll
[2014/04/13 21:46:15 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpencom.dll
[2014/04/13 21:46:15 | 000,233,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2014/04/13 21:46:14 | 000,447,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sppcomapi.dll
[2014/04/13 21:46:14 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpencom.dll
[2014/04/13 21:46:14 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWWIN.EXE
[2014/04/13 21:46:14 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DWWIN.EXE
[2014/04/13 21:46:14 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2014/04/13 21:46:14 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2014/04/13 21:46:13 | 000,872,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfplat.dll
[2014/04/13 21:46:13 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdvidcrl.dll
[2014/04/13 21:46:13 | 000,698,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfplat.dll
[2014/04/13 21:46:13 | 000,136,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwfs.sys
[2014/04/13 21:46:12 | 001,341,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2014/04/13 21:46:12 | 001,287,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2014/04/13 21:46:12 | 001,109,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2014/04/13 21:46:12 | 000,393,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2014/04/13 21:46:12 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2014/04/13 21:46:07 | 003,395,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSService.dll
[2014/04/13 21:46:06 | 000,848,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSShared.dll
[2014/04/13 21:46:06 | 000,695,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSShared.dll
[2014/04/13 21:46:06 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2014/04/13 21:46:06 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2014/04/13 21:46:06 | 000,084,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSCollect.exe
[2014/04/13 21:46:03 | 000,236,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdFilter.sys
[2014/04/13 21:46:02 | 000,124,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdNisDrv.sys
[2014/04/13 21:46:02 | 000,035,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdBoot.sys
[2014/04/13 21:45:50 | 001,943,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2014/04/13 21:45:49 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pcaui.exe
[2014/04/13 21:45:48 | 000,586,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll
[2014/04/13 21:45:48 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/04/13 21:45:48 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll
[2014/04/13 21:45:48 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scrrun.dll
[2014/04/13 21:45:48 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scrrun.dll
[2014/04/13 21:45:48 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pcaui.exe
[2014/04/13 21:45:47 | 000,377,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\clfs.sys
[2014/04/13 21:45:45 | 000,787,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\uDWM.dll
[2014/04/13 21:45:45 | 000,287,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mdmregistration.dll
[2014/04/13 21:45:44 | 013,209,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\twinui.dll
[2014/04/13 21:45:44 | 007,416,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Windows.UI.Search.dll
[2014/04/13 21:45:44 | 000,615,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MDMAgent.exe
[2014/04/13 21:45:44 | 000,240,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mdmregistration.dll
[2014/04/13 21:45:43 | 011,702,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\twinui.dll
[2014/04/13 21:45:42 | 004,961,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Windows.UI.Search.dll
[2014/04/13 21:45:41 | 001,462,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\propsys.dll
[2014/04/13 21:45:41 | 001,105,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SearchFolder.dll
[2014/04/13 21:40:02 | 000,000,000 | ---D | C] -- C:\Users\Karl\Desktop\RemovalTool
[2014/04/13 21:36:51 | 004,217,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SyncEngine.dll
[2014/04/13 21:36:51 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SkyDrive.exe
[2014/04/13 21:36:50 | 002,804,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\actxprxy.dll
[2014/04/13 21:36:50 | 000,919,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MrmCoreR.dll
[2014/04/13 21:36:50 | 000,720,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SkyDriveTelemetry.dll
[2014/04/13 21:36:50 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MrmCoreR.dll
[2014/04/13 21:36:49 | 000,121,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SkyDriveShell.dll
[2014/04/13 21:36:49 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winbici.dll
[2014/04/13 21:36:49 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SkyDriveShell.dll
[2014/04/13 21:34:12 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/04/13 20:48:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
[2014/04/13 20:48:01 | 000,829,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcr100.dll
[2014/04/13 20:48:01 | 000,773,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr100.dll
[2014/04/13 20:48:01 | 000,608,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msvcp100.dll
[2014/04/13 20:48:01 | 000,421,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcp100.dll
[2014/04/13 20:48:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Exploit
[2014/04/13 20:43:50 | 000,119,512 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/04/13 20:26:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
[2014/04/13 20:26:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
[2014/04/13 20:25:51 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2014/04/13 20:25:51 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2014/04/13 20:25:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/04/13 20:24:57 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\Programs
[2014/04/13 20:24:25 | 000,778,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationNative_v0300.dll
[2014/04/13 20:24:25 | 000,102,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2014/04/13 20:24:25 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TsWpfWrp.exe
[2014/04/13 20:24:24 | 001,166,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationNative_v0300.dll
[2014/04/13 20:24:24 | 000,124,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2014/04/13 20:24:24 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsWpfWrp.exe
[2014/04/13 20:20:24 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Karl\Desktop\OTL.exe
[2014/04/13 20:20:01 | 002,157,568 | ---- | C] (Farbar) -- C:\Users\Karl\Desktop\FRST64.exe
[2014/04/13 19:26:49 | 000,000,000 | R--D | C] -- C:\Users\Karl\Desktop\SkyDrive
[2014/04/06 21:43:19 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\Mozilla
[2014/04/06 21:43:19 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\Mozilla
[2014/04/06 21:43:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2014/04/06 21:43:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2014/04/06 21:42:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014/04/06 20:23:50 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\SUPERAntiSpyware.com
[2014/04/06 20:23:28 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2014/04/06 20:23:25 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2014/04/06 20:23:25 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2014/04/06 18:53:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group
[2014/04/06 18:53:56 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2014/04/06 18:49:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2014/04/06 18:49:17 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014/04/06 18:48:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
[2014/04/06 18:48:34 | 000,000,000 | ---D | C] -- C:\Program Files\Speccy
[2014/04/06 18:46:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
[2014/04/06 18:46:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Advanced Micro Devices, Inc
[2014/04/06 18:46:13 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2014/04/06 18:46:12 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2014/04/06 18:45:49 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2014/04/06 18:45:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2014/04/06 18:45:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014/04/06 18:45:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2014/04/06 18:45:16 | 000,000,000 | ---D | C] -- C:\AMD
[2014/04/06 18:45:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2014/04/06 18:45:02 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2014/04/06 17:57:29 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\Macromedia
[2014/04/06 17:24:13 | 000,000,000 | R--D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014/04/06 17:24:13 | 000,000,000 | R--D | C] -- C:\Users\Karl\Searches
[2014/04/06 17:24:13 | 000,000,000 | R--D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014/04/06 17:24:12 | 002,407,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PrintConfig.dll
[2014/04/06 17:24:12 | 000,000,000 | R--D | C] -- C:\Users\Karl\Contacts
[2014/04/06 17:24:12 | 000,000,000 | -H-D | C] -- C:\Users\Karl\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2014/04/06 17:24:03 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\Adobe
[2014/04/06 17:24:00 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\VirtualStore
[2014/04/06 17:23:57 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\Packages
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\AppData\Local\Temporary Internet Files
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Templates
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Start Menu
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\SendTo
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Recent
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\PrintHood
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\NetHood
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Local Settings
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\AppData\Local\History
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Cookies
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Application Data
[2014/04/06 17:23:42 | 000,000,000 | -HSD | C] -- C:\Users\Karl\AppData\Local\Application Data
[2014/04/06 17:23:41 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Documents\My Videos
[2014/04/06 17:23:41 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Documents\My Pictures
[2014/04/06 17:23:41 | 000,000,000 | -HSD | C] -- C:\Users\Karl\Documents\My Music
[2014/04/06 17:23:41 | 000,000,000 | -HSD | C] -- C:\Users\Karl\My Documents
[2014/04/06 17:23:41 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\Temp
[2014/04/06 17:23:41 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Local\Microsoft
[2014/04/06 17:23:40 | 000,000,000 | --SD | C] -- C:\Users\Karl\AppData\Roaming\Microsoft
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Videos
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Saved Games
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Pictures
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Music
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Links
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Favorites
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Downloads
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Documents
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\Desktop
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014/04/06 17:23:40 | 000,000,000 | R--D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2014/04/06 17:23:40 | 000,000,000 | -H-D | C] -- C:\Users\Karl\AppData
[2014/04/06 17:23:40 | 000,000,000 | ---D | C] -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014/04/06 17:23:40 | 000,000,000 | ---D | C] -- C:\Windows\CSC
[2014/04/06 17:23:31 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2014/04/06 16:10:10 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2014/04/06 16:09:24 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2014/04/03 23:17:34 | 000,000,000 | --SD | C] -- C:\Recovery
[2014/04/03 22:18:12 | 000,000,000 | --SD | C] -- C:\System Volume Information
 
========== Files - Modified Within 30 Days ==========
 
[2014/04/14 01:12:10 | 000,863,592 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/04/14 01:12:10 | 000,731,650 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/04/14 01:12:10 | 000,135,726 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/04/14 00:48:18 | 000,000,000 | ---- | M] () -- C:\Users\Karl\defogger_reenable
[2014/04/14 00:17:47 | 107,394,336 | ---- | M] (Oracle Corporation) -- C:\Users\Karl\Desktop\VirtualBox-4.3.10-93012-Win.exe
[2014/04/13 23:57:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/04/13 23:56:05 | 000,000,538 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 06cff99d-0889-4a8d-9d21-3d247d7b3846.job
[2014/04/13 23:55:45 | 000,335,784 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/04/13 23:55:33 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014/04/13 23:55:29 | 2110,795,775 | -HS- | M] () -- C:\hiberfil.sys
[2014/04/13 23:41:55 | 000,119,512 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/04/13 23:17:07 | 000,001,133 | ---- | M] () -- C:\Users\Public\Desktop\herdProtect.lnk
[2014/04/13 20:23:00 | 000,000,538 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 97428f67-5333-4e96-b808-7f8e18cde318.job
[2014/04/13 20:20:24 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Karl\Desktop\OTL.exe
[2014/04/13 20:20:01 | 002,157,568 | ---- | M] (Farbar) -- C:\Users\Karl\Desktop\FRST64.exe
[2014/04/06 20:21:41 | 000,005,054 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2014/04/06 18:45:14 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
[2014/04/06 18:40:56 | 000,001,440 | ---- | M] () -- C:\Users\Karl\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/04/06 16:10:19 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2014/03/31 16:23:52 | 000,693,240 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/03/31 16:23:52 | 000,105,464 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
 
========== Files Created - No Company Name ==========
 
[2014/04/14 00:48:18 | 000,000,000 | ---- | C] () -- C:\Users\Karl\defogger_reenable
[2014/04/13 23:17:07 | 000,001,133 | ---- | C] () -- C:\Users\Public\Desktop\herdProtect.lnk
[2014/04/13 23:01:06 | 000,003,233 | ---- | C] () -- C:\Users\Karl\Desktop\Sophos Virus Removal Tool.lnk
[2014/04/13 21:50:54 | 000,138,240 | ---- | C] () -- C:\Windows\SysNative\OEMLicense.dll
[2014/04/13 21:50:54 | 000,103,936 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2014/04/13 21:46:15 | 000,386,722 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
[2014/04/13 21:45:41 | 000,009,701 | ---- | C] () -- C:\Windows\SysWow64\connectedsearch-results.searchconnector-ms
[2014/04/13 21:45:40 | 000,009,701 | ---- | C] () -- C:\Windows\SysNative\connectedsearch-results.searchconnector-ms
[2014/04/06 21:43:13 | 000,001,175 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2014/04/06 20:23:55 | 000,000,538 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 97428f67-5333-4e96-b808-7f8e18cde318.job
[2014/04/06 20:23:54 | 000,000,538 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 06cff99d-0889-4a8d-9d21-3d247d7b3846.job
[2014/04/06 18:59:34 | 000,005,054 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014/04/06 18:45:14 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014/04/06 18:40:56 | 000,001,440 | ---- | C] () -- C:\Users\Karl\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/04/06 17:27:23 | 000,863,592 | ---- | C] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/04/06 17:24:02 | 000,001,446 | ---- | C] () -- C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014/04/06 17:23:41 | 000,000,352 | ---- | C] () -- C:\Users\Karl\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2014/04/06 17:23:41 | 000,000,334 | ---- | C] () -- C:\Users\Karl\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2014/04/06 17:20:11 | 2110,795,775 | -HS- | C] () -- C:\hiberfil.sys
[2014/04/06 16:10:19 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2014/04/06 16:09:22 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys
[2013/12/13 10:23:56 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013/12/13 10:23:54 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013/12/13 10:23:46 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2013/12/13 10:23:24 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013/12/13 10:23:24 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013/12/13 10:23:14 | 000,123,392 | ---- | C] () -- C:\Windows\SysWow64\amdhdl32.dll
[2013/08/22 10:36:43 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2013/08/22 10:36:42 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2013/08/22 09:46:23 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2013/08/22 02:01:23 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2013/08/21 22:32:36 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2013/08/21 18:55:20 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2013/08/21 18:52:39 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
 
========== ZeroAccess Check ==========
 
[2014/04/13 23:23:57 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/12/09 03:05:24 | 021,199,256 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/12/08 23:51:04 | 018,643,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 04:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 21:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 04:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== Custom Scans ==========
 
<  >
 
========== Drive Information ==========
 
Physical Drives
---------------
 
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HTS545050A7E380
Partitions: 3
Status: OK
Status Info: 0
 
Partitions
---------------
 
DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 350.00MB
Starting Offset: 1048576
Hidden sectors: 0
 
 
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 233.00GB
Starting Offset: 368050176
Hidden sectors: 0
 
 
DeviceID: Disk #0, Partition #2
PartitionType: Extended w/Extended Int 13
Bootable: False
BootPartition: False
PrimaryPartition: False
Size: 212.00GB
Starting Offset: 250545700864
Hidden sectors: 0
 
 
< %SYSTEMDRIVE%\*.exe >
 
< %systemroot%\assembly\GAC_32\*.ini >
 
< %systemroot%\assembly\GAC_64\*.ini >
 
< %SYSTEMDRIVE%\*.exe >
 
< %ALLUSERSPROFILE%\Application Data\*.exe >
 
< %APPDATA%\*. >
[2014/04/06 17:24:03 | 000,000,000 | ---D | M] -- C:\Users\Karl\AppData\Roaming\Adobe
[2014/04/14 00:01:45 | 000,000,000 | ---D | M] -- C:\Users\Karl\AppData\Roaming\ATI
[2014/04/06 17:57:29 | 000,000,000 | ---D | M] -- C:\Users\Karl\AppData\Roaming\Macromedia
[2014/04/13 22:44:40 | 000,000,000 | --SD | M] -- C:\Users\Karl\AppData\Roaming\Microsoft
[2014/04/13 19:18:05 | 000,000,000 | ---D | M] -- C:\Users\Karl\AppData\Roaming\Mozilla
[2014/04/06 20:23:50 | 000,000,000 | ---D | M] -- C:\Users\Karl\AppData\Roaming\SUPERAntiSpyware.com
 
< MD5 for: ATAPI.SYS  >
[2013/08/22 07:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\SysNative\drivers\atapi.sys
[2013/08/22 07:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_64aa4354da84c2df\atapi.sys
[2013/08/22 07:43:41 | 000,026,464 | ---- | M] (Microsoft Corporation) MD5=74B14192CF79A72F7536B27CB8814FBD -- C:\Windows\WinSxS\amd64_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_cdf68824f580d510\atapi.sys
 
< MD5 for: CSRSS.EXE  >
[2013/08/22 08:25:40 | 000,017,120 | ---- | M] (Microsoft Corporation) MD5=B2D3F07F5E8A13AF988A8B3C0A800880 -- C:\Windows\SysNative\csrss.exe
[2013/08/22 08:25:40 | 000,017,120 | ---- | M] (Microsoft Corporation) MD5=B2D3F07F5E8A13AF988A8B3C0A800880 -- C:\Windows\WinSxS\amd64_microsoft-windows-csrss_31bf3856ad364e35_6.3.9600.16384_none_49a243e2b80cb4c0\csrss.exe
 
< MD5 for: EXPLORER.EXE  >
[2013/10/22 01:03:47 | 002,065,448 | ---- | M] (Microsoft Corporation) MD5=1A0BC9598E4A58FC84570FFF5A108E58 -- C:\Windows\SysWOW64\explorer.exe
[2013/10/22 01:03:47 | 002,065,448 | ---- | M] (Microsoft Corporation) MD5=1A0BC9598E4A58FC84570FFF5A108E58 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_4ceff22781f6788c\explorer.exe
[2013/08/22 00:25:34 | 002,063,408 | ---- | M] (Microsoft Corporation) MD5=2CA8E3C9335C3C8BAEB335345E48364D -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16384_none_4cc7b16f8214372e\explorer.exe
[2013/10/22 02:55:27 | 002,328,872 | ---- | M] (Microsoft Corporation) MD5=63DC38C3E4564B2405D562855643ABA2 -- C:\Windows\explorer.exe
[2013/10/22 02:55:27 | 002,328,872 | ---- | M] (Microsoft Corporation) MD5=63DC38C3E4564B2405D562855643ABA2 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16441_none_429b47d54d95b691\explorer.exe
[2013/09/21 04:37:39 | 002,065,960 | ---- | M] (Microsoft Corporation) MD5=712B0D2ADE5297563168C997DDC2DD13 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16408_none_4d2233dd81cfba29\explorer.exe
[2013/08/22 07:39:51 | 002,328,880 | ---- | M] (Microsoft Corporation) MD5=8479DC46E9A09015C0777A16BC22A15D -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16384_none_4273071d4db37533\explorer.exe
[2013/09/21 05:54:20 | 002,328,328 | ---- | M] (Microsoft Corporation) MD5=C1400519D76A364E974E47BBA62B95B0 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16408_none_42cd898b4d6ef82e\explorer.exe
 
< MD5 for: MSWSOCK.DLL  >
[2013/08/21 21:55:25 | 000,270,848 | ---- | M] (Microsoft Corporation) MD5=5B4FF009D24F73F6FC6EB4870A789843 -- C:\Windows\SysWOW64\mswsock.dll
[2013/08/21 21:55:25 | 000,270,848 | ---- | M] (Microsoft Corporation) MD5=5B4FF009D24F73F6FC6EB4870A789843 -- C:\Windows\WinSxS\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.16384_none_4cf31b8d48e553cc\mswsock.dll
[2013/08/22 05:05:19 | 000,338,432 | ---- | M] (Microsoft Corporation) MD5=896B307E803430F67EC772807F9CC023 -- C:\Windows\SysNative\mswsock.dll
[2013/08/22 05:05:19 | 000,338,432 | ---- | M] (Microsoft Corporation) MD5=896B307E803430F67EC772807F9CC023 -- C:\Windows\WinSxS\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.3.9600.16384_none_a911b7110142c502\mswsock.dll
 
< MD5 for: NAPINSP.DLL  >
[2013/08/22 06:32:16 | 000,067,584 | ---- | M] (Microsoft Corporation) MD5=4CD5B246B2DB81DC403B7C9041456B0E -- C:\Windows\SysNative\NapiNSP.dll
[2013/08/22 06:32:16 | 000,067,584 | ---- | M] (Microsoft Corporation) MD5=4CD5B246B2DB81DC403B7C9041456B0E -- C:\Windows\WinSxS\amd64_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.3.9600.16384_none_9cdba0d36327ed34\NapiNSP.dll
[2013/08/21 23:03:46 | 000,053,760 | ---- | M] (Microsoft Corporation) MD5=8DB30DA1FA8620A5C4AF53DEB85194D8 -- C:\Windows\SysWOW64\NapiNSP.dll
[2013/08/21 23:03:46 | 000,053,760 | ---- | M] (Microsoft Corporation) MD5=8DB30DA1FA8620A5C4AF53DEB85194D8 -- C:\Windows\WinSxS\wow64_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.3.9600.16384_none_a7304b259788af2f\NapiNSP.dll
 
< MD5 for: NLAAPI.DLL  >
[2013/08/22 04:56:10 | 000,084,480 | ---- | M] (Microsoft Corporation) MD5=E5DFD54D2DAA70738F581D1AC74C09CD -- C:\Windows\SysNative\nlaapi.dll
[2013/08/22 04:56:10 | 000,084,480 | ---- | M] (Microsoft Corporation) MD5=E5DFD54D2DAA70738F581D1AC74C09CD -- C:\Windows\WinSxS\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.3.9600.16384_none_584455d1dee14bd9\nlaapi.dll
[2013/08/21 21:48:53 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=F604350906CE4E3F67D81384566DE3E4 -- C:\Windows\SysWOW64\nlaapi.dll
[2013/08/21 21:48:53 | 000,064,000 | ---- | M] (Microsoft Corporation) MD5=F604350906CE4E3F67D81384566DE3E4 -- C:\Windows\WinSxS\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.3.9600.16384_none_6299002413420dd4\nlaapi.dll
 
< MD5 for: PNRPNSP.DLL  >
[2013/08/21 21:52:11 | 000,068,096 | ---- | M] (Microsoft Corporation) MD5=4947B4C100BE88C83F027D1C8DBC4B84 -- C:\Windows\SysWOW64\pnrpnsp.dll
[2013/08/21 21:52:11 | 000,068,096 | ---- | M] (Microsoft Corporation) MD5=4947B4C100BE88C83F027D1C8DBC4B84 -- C:\Windows\WinSxS\wow64_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.3.9600.16384_none_6c9220102acc5d78\pnrpnsp.dll
[2013/08/22 05:01:06 | 000,087,040 | ---- | M] (Microsoft Corporation) MD5=F916298AF3C6AC9887427E545C7E3A69 -- C:\Windows\SysNative\pnrpnsp.dll
[2013/08/22 05:01:06 | 000,087,040 | ---- | M] (Microsoft Corporation) MD5=F916298AF3C6AC9887427E545C7E3A69 -- C:\Windows\WinSxS\amd64_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.3.9600.16384_none_623d75bdf66b9b7d\pnrpnsp.dll
 
< MD5 for: PRINTISOLATIONHOST.EXE  >
[2013/08/22 06:04:29 | 000,075,776 | ---- | M] (Microsoft Corporation) MD5=02C856EDABE82111BF4F8D93795197E3 -- C:\Windows\SysNative\PrintIsolationHost.exe
[2013/08/22 06:04:29 | 000,075,776 | ---- | M] (Microsoft Corporation) MD5=02C856EDABE82111BF4F8D93795197E3 -- C:\Windows\WinSxS\amd64_microsoft-windows-p..ng-server-isolation_31bf3856ad364e35_6.3.9600.16384_none_8d6d72f932993476\PrintIsolationHost.exe
 
< MD5 for: SERVICES.EXE  >
[2013/08/22 08:25:40 | 000,405,488 | ---- | M] (Microsoft Corporation) MD5=B4B610BBCB002EC478C6FD80CF915697 -- C:\Windows\SysNative\services.exe
[2013/08/22 08:25:40 | 000,405,488 | ---- | M] (Microsoft Corporation) MD5=B4B610BBCB002EC478C6FD80CF915697 -- C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.3.9600.16384_none_2fd72579d09a45e9\services.exe
 
< MD5 for: SVCHOST.EXE  >
[2013/08/22 00:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) MD5=425E22D9F5C01616AFC92987791B19E9 -- C:\Windows\SysWOW64\svchost.exe
[2013/08/22 00:30:58 | 000,031,552 | ---- | M] (Microsoft Corporation) MD5=425E22D9F5C01616AFC92987791B19E9 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2013/08/22 07:45:17 | 000,037,768 | ---- | M] (Microsoft Corporation) MD5=E4CA434F251681590D0538BC21C32D2F -- C:\Windows\SysNative\svchost.exe
[2013/08/22 07:45:17 | 000,037,768 | ---- | M] (Microsoft Corporation) MD5=E4CA434F251681590D0538BC21C32D2F -- C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_a679b9abd944c459\svchost.exe
 
< MD5 for: USER32.DLL  >
[2013/08/21 21:51:20 | 001,363,456 | ---- | M] (Microsoft Corporation) MD5=170A3370144196F72A04038B652732EF -- C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_6.3.9600.16384_none_c84b769e75b447a1\user32.dll
[2013/08/22 07:39:12 | 001,517,984 | ---- | M] (Microsoft Corporation) MD5=1A811BAFA2114C2FC878507F9F86566C -- C:\Windows\SysNative\user32.dll
[2013/08/22 07:39:12 | 001,517,984 | ---- | M] (Microsoft Corporation) MD5=1A811BAFA2114C2FC878507F9F86566C -- C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_6.3.9600.16384_none_bdf6cc4c415385a6\user32.dll
[2013/08/22 07:39:12 | 001,517,984 | ---- | M] (Microsoft Corporation) MD5=1A811BAFA2114C2FC878507F9F86566C -- C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_6.3.9600.16441_none_be1f0d044135c704\user32.dll
[2013/10/21 21:38:12 | 001,362,944 | ---- | M] (Microsoft Corporation) MD5=C72456BFFE941714CF05B0AA0BEE5B45 -- C:\Windows\SysWOW64\user32.dll
[2013/10/21 21:38:12 | 001,362,944 | ---- | M] (Microsoft Corporation) MD5=C72456BFFE941714CF05B0AA0BEE5B45 -- C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_6.3.9600.16441_none_c873b756759688ff\user32.dll
 
< MD5 for: USERINIT.EXE  >
[2013/08/22 05:03:12 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=08C191B2917862BE90C33E31CB6B6D79 -- C:\Windows\SysNative\userinit.exe
[2013/08/22 05:03:12 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=08C191B2917862BE90C33E31CB6B6D79 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_cce71a20a5a6fe7f\userinit.exe
[2013/08/21 21:54:12 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=41636F77AD6D9A396EA34E4786B96F2B -- C:\Windows\SysWOW64\userinit.exe
[2013/08/21 21:54:12 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=41636F77AD6D9A396EA34E4786B96F2B -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
 
< MD5 for: WINLOGON.EXE  >
[2013/08/22 04:55:08 | 000,564,736 | ---- | M] (Microsoft Corporation) MD5=7C94FDA3809015B8F2208D2E1C221F17 -- C:\Windows\SysNative\winlogon.exe
[2013/08/22 04:55:08 | 000,564,736 | ---- | M] (Microsoft Corporation) MD5=7C94FDA3809015B8F2208D2E1C221F17 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_60816121a8e88269\winlogon.exe
 
< MD5 for: WINRNR.DLL  >
[2013/08/22 06:34:20 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=218F874A78CB670172280A39A58B8F8A -- C:\Windows\SysNative\winrnr.dll
[2013/08/22 06:34:20 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=218F874A78CB670172280A39A58B8F8A -- C:\Windows\WinSxS\amd64_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.3.9600.16384_none_4a0cb2fa240d3dde\winrnr.dll
[2013/08/21 23:05:53 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=8700883867FBD565BF6C2DAE8B2D7810 -- C:\Windows\SysWOW64\winrnr.dll
[2013/08/21 23:05:53 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=8700883867FBD565BF6C2DAE8B2D7810 -- C:\Windows\WinSxS\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.3.9600.16384_none_edee17766bafcca8\winrnr.dll
 
< MD5 for: WSHELPER.DLL  >
[2013/08/22 06:17:56 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=A977FE7DAC2FEB57BD64D32DFFAF5C4E -- C:\Windows\SysNative\wshelper.dll
[2013/08/22 06:17:56 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=A977FE7DAC2FEB57BD64D32DFFAF5C4E -- C:\Windows\WinSxS\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.3.9600.16384_none_f5436278cb5201dd\wshelper.dll
[2013/08/21 22:51:16 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=E08FC17019F66263C081D17A00589AE5 -- C:\Windows\SysWOW64\wshelper.dll
[2013/08/21 22:51:16 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=E08FC17019F66263C081D17A00589AE5 -- C:\Windows\WinSxS\wow64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.3.9600.16384_none_ff980ccaffb2c3d8\wshelper.dll
 
< C:\Windows\assembly\tmp\U\*.* /s >
 
< %systemroot%\*. /mp /s >
 
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2014/03/15 03:41:20 | 000,878,024 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2014/03/15 03:41:20 | 000,878,024 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2014/03/15 03:41:20 | 000,878,024 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [2014/03/15 03:40:21 | 000,275,568 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2014/03/15 03:40:21 | 000,275,568 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2014/03/15 03:40:21 | 000,275,568 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2014/02/06 08:08:02 | 000,806,064 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2014/02/06 08:08:02 | 000,806,064 | ---- | M] (Microsoft Corporation)
 
< hklm\software\clients\startmenuinternet|command /64 /rs >
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2014/03/15 03:41:20 | 000,878,024 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2014/03/15 03:41:20 | 000,878,024 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2014/03/15 03:41:20 | 000,878,024 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" [2014/03/15 03:40:21 | 000,275,568 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -PREFERENCES [2014/03/15 03:40:21 | 000,275,568 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -SAFE-MODE [2014/03/15 03:40:21 | 000,275,568 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2014/02/28 23:17:43 | 000,218,624 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2014/02/28 23:17:43 | 000,218,624 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2014/02/28 23:17:43 | 000,218,624 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2014/02/06 08:08:02 | 000,806,064 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE" [2014/02/06 08:08:02 | 000,806,064 | ---- | M] (Microsoft Corporation)
 
< %systemroot%\system32\*.dll /lockedfiles >
 
< %systemroot%\Tasks\*.job /lockedfiles >
 
< %ProgramFiles%\WINDOWS NT\*.* /s >
[2013/08/21 22:07:14 | 004,277,760 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\Accessories\wordpad.exe
[2013/08/21 22:33:16 | 000,143,872 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\Accessories\WordpadFilter.dll
[2013/08/22 14:08:23 | 000,050,176 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\Accessories\en-US\wordpad.exe.mui
[2013/08/21 22:39:01 | 000,599,040 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextService.dll
[2013/06/18 07:50:03 | 000,013,862 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceAmharic.txt
[2013/06/18 07:50:03 | 001,272,944 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceArray.txt
[2013/06/18 07:50:03 | 000,980,224 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceDaYi.txt
[2013/06/18 07:50:03 | 000,013,874 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceTigrinya.txt
[2013/06/18 07:50:03 | 000,045,170 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceYi.txt
[2013/08/22 14:08:25 | 000,008,192 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\en-US\TableTextService.dll.mui
 
< %systemroot%\system32\drivers\*.sys /lockedfiles >
 
< CREATERESTOREPOIN >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 199 bytes -> C:\Users\Karl\Desktop\SkyDrive:ms-properties

< End of report >
 

 

 

 

OTL Extras logfile created on: 4/14/2014 1:47:11 AM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Karl\Desktop
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
7.46 Gb Total Physical Memory | 5.78 Gb Available Physical Memory | 77.57% Memory free
9.27 Gb Paging File | 7.55 Gb Available in Paging File | 81.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 233.00 Gb Total Space | 209.14 Gb Free Space | 89.76% Space Free | Partition Type: NTFS
Drive E: | 212.07 Gb Total Space | 211.95 Gb Free Space | 99.94% Space Free | Partition Type: NTFS
 
Computer Name: COMPTONCOMPUTE | User Name: Karl | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (All) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}%U{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" =  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\RemoteAdminSettings]
"Enabled" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\RemoteDesktop]
"Enabled" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\RemoteAdminSettings]
"Enabled" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\Services\RemoteDesktop]
"Enabled" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{15084F92-8AD2-4C82-9D91-1F45A0734DF7}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{21C37950-D33B-487C-A971-5D9FF50FBE7A}" = rport=138 | protocol=17 | dir=out | app=system |
"{34204BFE-5D1E-408D-8D74-CDF2D55FDB7A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4048D64C-18A2-4CC6-BC97-44134BD3030D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5B319879-05DF-45F5-A56A-217ADB2E4EA4}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{7DDE86D7-CCA1-4E64-94A6-404191F1DE9A}" = rport=139 | protocol=6 | dir=out | app=system |
"{84596BDC-C780-4734-91E6-09096DCD4EF3}" = lport=139 | protocol=6 | dir=in | app=system |
"{9BD8AFE0-7D23-418B-8969-066A3AD148E4}" = lport=137 | protocol=17 | dir=in | app=system |
"{BD572574-B61E-4ED9-97CD-453B7BEA9230}" = lport=445 | protocol=6 | dir=in | app=system |
"{F45F27F6-ADE6-4F83-948F-D17301DBC271}" = rport=137 | protocol=17 | dir=out | app=system |
"{FF422830-3203-452E-A84D-3DCF4E18B68F}" = lport=138 | protocol=17 | dir=in | app=system |
"{FF52ECC6-5618-4E31-970A-F953ECA6CA44}" = rport=445 | protocol=6 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08B38EF6-A679-4572-B5B9-19D184E57BAB}" = dir=out | [email protected]{microsoft.bingnews_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} |
"{0BC91719-A37F-424B-8733-BF59F65F271F}" = dir=out | [email protected]{microsoft.zunemusic_2.2.800.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{1AF5BB8F-A47E-4E19-9A39-900730EAFD23}" = dir=out | [email protected]{microsoft.bingtravel_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} |
"{27B347AF-BB40-4C2C-BED7-A9AF783F45B5}" = dir=out | [email protected]{microsoft.bingweather_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{30788421-9364-45A2-A8AA-4A555C1402D7}" = dir=out | [email protected]{microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{3983D407-C619-49B0-BC0D-51EA6BBD23B9}" = dir=out | [email protected]{microsoft.bingfinance_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} |
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn |
"{43C84917-7A9F-4A5B-AEF0-EFCB518FD2A7}" = dir=out | [email protected]{microsoft.zunevideo_2.2.802.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{509C306F-9E96-4BEC-931C-F0CD74D64D22}" = protocol=58 | dir=in | [email protected],-28545 |
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | [email protected]{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect |
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect |
"{870038E0-EBFB-422A-B8C2-0B61FE4987AE}" = protocol=1 | dir=in | [email protected]allapi.dll,-28543 |
"{96E8CE58-8CEE-46B2-9318-5D43192C7568}" = protocol=58 | dir=out | [email protected],-28546 |
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | [email protected]{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{CD325257-0751-4E76-B1EE-45848A95AD2F}" = dir=in | [email protected]{microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn |
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn |
"{DCC52271-1A12-476F-8222-73EE3221DE5B}" = dir=out | [email protected]{microsoft.bingsports_3.0.2.243_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} |
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn |
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client |
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client |
"{FD8B34C6-342F-4A1A-98D6-7F28B5548E7E}" = protocol=1 | dir=out | [email protected],-28544 |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{345841F8-F9F9-9910-134E-49162B7FDDAD}" = ccc-utility64
"{7EB99D77-F222-B208-C0AE-1E5D4E887532}" = AMD Fuel
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"CCleaner" = CCleaner
"Malwarebytes Anti-Exploit_is1" = Malwarebytes Anti-Exploit version 0.10.0.1000
"Speccy" = Speccy
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
"{1812E293-E2D1-3072-0ED4-C15163533D7E}" = CCC Help Swedish
"{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
"{25087F13-EBE7-C817-CA31-08C196F73B23}" = CCC Help Hungarian
"{29043AAA-3A1A-D36B-C1CB-E201FA72C16A}" = CCC Help Dutch
"{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
"{3C7F465C-765F-A038-60BE-03B7301B0161}" = CCC Help Norwegian
"{42321261-5D40-644C-1235-927141D4FA20}" = CCC Help Portuguese
"{446CF7B3-EE4D-1C10-E2B7-87C1C8517FE8}" = CCC Help Korean
"{450BED09-F405-87EE-CD52-5055B1EF8F72}" = CCC Help Chinese Standard
"{4D628C2E-D9F7-2D3A-E610-00F4D52F219F}" = CCC Help Polish
"{553B5DE6-496A-4328-DE0B-D1C83F7FE4D8}" = CCC Help Turkish
"{5EA2099A-0249-1D98-5387-0BEF207D72AA}" = AMD Catalyst Control Center
"{632396AA-8A78-A9A4-0945-7E24DF3F5B6C}" = CCC Help French
"{64592305-22DF-6756-FD51-1B7234D4C6AB}" = CCC Help Russian
"{6DC13EFF-D4FF-65B6-7538-8B3E6075853F}" = Catalyst Control Center InstallProxy
"{7BC48761-EE54-AA23-5607-0D11B7550CFB}" = CCC Help Italian
"{7C58E0C8-89FB-7E36-158C-5DC0B57027D9}" = CCC Help Czech
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87270A4A-EDE9-BFDF-AE0C-0FBDEEA5D4BD}" = CCC Help Thai
"{8B1A559A-FB9D-42F5-A8A7-2F132CF28414}" = Catalyst Control Center
"{8F1ABC89-3D34-1D8B-DF69-EC9198604283}" = CCC Help Spanish
"{96DAF3C6-C2D4-5804-E219-86C034A02355}" = CCC Help Japanese
"{9BB69BDB-FE40-24D2-3822-828FB6DF6DE2}" = CCC Help German
"{A71019D0-8C9D-DB8D-2801-CBFC736FF307}" = CCC Help Danish
"{B829E117-D072-41EA-9606-9826A38D34C1}" = Sophos Virus Removal Tool
"{B99E1A30-E349-FA3B-80F7-FB55EBC40996}" = CCC Help Chinese Traditional
"{C28E9DF6-C68D-18DF-076C-7E92B9F30A96}" = CCC Help English
"{C68D4599-2D2A-2060-39D0-0B3DEA861657}" = Catalyst Control Center Localization All
"{CB79256B-C0E0-40C6-8EB7-BDD796203581}" = Catalyst Control Center - Branding
"{EDE875B0-6566-4E93-B955-C63AE5F4737C}" = Sophos Computer Security Scan
"{F940E929-2FFF-1F4E-7ECB-DE1B0377D627}" = CCC Help Finnish
"{FB8AF07B-42FB-4746-058A-B6A063472452}" = CCC Help Greek
"{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
"herdProtectScan" = herdProtect Anti-Malware Scanner
"Mozilla Firefox 28.0 (x86 en-US)" = Mozilla Firefox 28.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Revo Uninstaller" = Revo Uninstaller 1.85
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 4/13/2014 11:47:33 PM | Computer Name = ComptonCompute | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 11.0.9600.16384,
 time stamp: 0x5215d145  Faulting module name: unknown, version: 0.0.0.0, time stamp:
 0x00000000  Exception code: 0xc0000005  Fault offset: 0x00007ffaa6d20000  Faulting process
 id: 0x1374  Faulting application start time: 0x01cf579442f05128  Faulting application
 path: C:\Program Files\Internet Explorer\iexplore.exe  Faulting module path: unknown
Report
 Id: 82290fcc-c387-11e3-824e-60a44c03c621  Faulting package full name:   Faulting package-relative
 application ID:
 
Error - 4/14/2014 12:17:38 AM | Computer Name = ComptonCompute | Source = Application Error | ID = 1000
Description = Faulting application name: herdProtectScan.exe, version: 1.0.3.1,
time stamp: 0x534837fd  Faulting module name: LSASRV.dll, version: 6.3.9600.16384,
 time stamp: 0x5215e180  Exception code: 0xc0000005  Fault offset: 0x0000000000058162
Faulting
 process id: 0x6d0  Faulting application start time: 0x01cf579867483886  Faulting application
 path: C:\Program Files\Reason\herdProtect\Scanner\herdProtectScan.exe  Faulting module
 path: C:\Windows\SYSTEM32\LSASRV.dll  Report Id: b62dfb21-c38b-11e3-824e-60a44c03c621
Faulting
 package full name:   Faulting package-relative application ID:
 
Error - 4/14/2014 12:23:41 AM | Computer Name = ComptonCompute | Source = Application Error | ID = 1000
Description = Faulting application name: herdProtectScan.exe, version: 1.0.3.1,
time stamp: 0x534837fd  Faulting module name: LSASRV.dll, version: 6.3.9600.16384,
 time stamp: 0x5215e180  Exception code: 0xc0000005  Fault offset: 0x0000000000058162
Faulting
 process id: 0x6d0  Faulting application start time: 0x01cf579867483886  Faulting application
 path: C:\Program Files\Reason\herdProtect\Scanner\herdProtectScan.exe  Faulting module
 path: C:\Windows\SYSTEM32\LSASRV.dll  Report Id: 8e7d28c8-c38c-11e3-824e-60a44c03c621
Faulting
 package full name:   Faulting package-relative application ID:
 
Error - 4/14/2014 12:44:52 AM | Computer Name = ComptonCompute | Source = Application Error | ID = 1000
Description = Faulting application name: explorer.exe, version: 6.3.9600.16384,
time stamp: 0x5215d379  Faulting module name: ntdll.dll, version: 6.3.9600.16384,
time stamp: 0x5215f938  Exception code: 0xc0000005  Fault offset: 0x0000000000032739
Faulting
 process id: 0xc30  Faulting application start time: 0x01cf578a96129140  Faulting application
 path: C:\Windows\explorer.exe  Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
 Id: 844315eb-c38f-11e3-824e-60a44c03c621  Faulting package full name:   Faulting package-relative
 application ID:
 
Error - 4/14/2014 1:48:59 AM | Computer Name = ComptonCompute | Source = Application Error | ID = 1000
Description = Faulting application name: socool.com, version: 1.71.0.0, time stamp:
 0x44e255aa  Faulting module name: socool.com, version: 1.71.0.0, time stamp: 0x44e255aa
Exception
 code: 0xc0000005  Fault offset: 0x000040cd  Faulting process id: 0x8e8  Faulting application
 start time: 0x01cf57a537b37559  Faulting application path: C:\Users\Karl\Desktop\socool.com
Faulting
 module path: C:\Users\Karl\Desktop\socool.com  Report Id: 78cd634f-c398-11e3-824f-60a44c03c621
Faulting
 package full name:   Faulting package-relative application ID:
 
[ System Events ]
Error - 4/14/2014 1:43:11 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:16 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:16 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:16 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:16 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:16 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:16 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:16 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:16 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
Error - 4/14/2014 1:43:26 AM | Computer Name = ComptonCompute | Source = Service Control Manager | ID = 7000
Description = The Diagnostic Service Host service failed to start due to the following
 error:   %%1297
 
 
< End of report >
 


  • 0

#5
Kman4488

Kman4488

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2014 01
Ran by Karl (administrator) on COMPTONCOMPUTE on 14-04-2014 01:40:45
Running from C:\Users\Karl\Desktop
Windows 8.1 Enterprise Evaluation (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Microsoft Corporation) C:\Windows\system32\wlms\wlms.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\LiveComm.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\system32\wwahost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [1294136 2014-02-21] (Malwarebytes Corporation)
HKU\S-1-5-21-2552152212-2573470380-3959478730-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-06] (SUPERAntiSpyware)

==================== Internet (Whitelisted) ====================

Hosts: 127.0.0.1    localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Karl\AppData\Roaming\Mozilla\Firefox\Profiles\8tyseozw.default
FF Extension: WOT - C:\Users\Karl\AppData\Roaming\Mozilla\Firefox\Profiles\8tyseozw.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-04-13]
FF Extension: Safe Preview - C:\Users\Karl\AppData\Roaming\Mozilla\Firefox\Profiles\8tyseozw.default\Extensions\[email protected] [2014-04-13]
FF Extension: WorldIP - C:\Users\Karl\AppData\Roaming\Mozilla\Firefox\Profiles\8tyseozw.default\Extensions\{f36c6cd1-da73-491d-b290-8fc9115bfa55}.xpi [2014-04-14]
FF Extension: Fireclam - C:\Users\Karl\AppData\Roaming\Mozilla\Firefox\Profiles\8tyseozw.default\Extensions\{f53ae83d-ca13-4cf8-8fd4-c58ae36051b4}.xpi [2014-04-14]

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-12-06] (Advanced Micro Devices, Inc.)
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [319288 2014-02-21] (Malwarebytes Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-30] (Microsoft Corporation)
R2 WLMS; C:\Windows\system32\wlms\wlms.exe [22016 2013-08-22] (Microsoft Corporation)
S2 MBAMScheduler; "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe" [X]
S2 MBAMService; "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe" [X]

==================== Drivers (Whitelisted) ====================

S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Windows ® Win 7 DDK provider)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [62168 2014-02-21] ()
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-09] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-10] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-08-22] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-25] (Microsoft Corporation)
R0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-30] (Microsoft Corporation)
S3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [X]

========================== Drivers MD5 =======================

C:\Windows\System32\drivers\1394ohci.sys E1832BD9FD7E0FC2DC9FA5935DE3E8C1
C:\Windows\System32\drivers\3ware.sys AD508A1A46EC21B740AB31C28EFDFDB1
C:\Windows\System32\drivers\ACPI.sys 3D30878A269D934100FA5F972E53AF39
C:\Windows\System32\Drivers\acpiex.sys AC8279D229398BCF05C3154ADCA86813
C:\Windows\System32\drivers\acpipagr.sys A8970D9BF23CD309E0403978A1B58F3F
C:\Windows\System32\drivers\acpipmi.sys 111A89C99C5B4F1A7BCE5F643DD86F65
C:\Windows\System32\drivers\acpitime.sys 5758387D68A20AE7D3245011B07E36E7
C:\Windows\System32\drivers\ADP80XX.SYS 7C1FDF1B48298CBA7CE4BDD4978951AD
C:\Windows\system32\drivers\afd.sys 239268BAB58EAE9A3FF4E08334C00451
C:\Windows\System32\drivers\agp440.sys 7DFAEBA9AD62D20102B576D5CAC45EC8
C:\Windows\System32\DRIVERS\ahcache.sys 8E8E34B7BA059050EED827410D0697A2
C:\Windows\System32\drivers\amdk8.sys 7589DE749DB6F71A68489DCE04158729
C:\Windows\system32\DRIVERS\atikmdag.sys FBB35875FEFE53D4280259842069ED72
C:\Windows\system32\DRIVERS\atikmpag.sys A32BCAD9377E3B75D034CAFBA463A0AE
C:\Windows\System32\drivers\amdppm.sys B46D2D89AFF8A9490FA8C98C7A5616E3
C:\Windows\System32\drivers\amdsata.sys D2BF2F94A47D332814910FD47C6BBCD2
C:\Windows\System32\drivers\amdsbs.sys A8E04943C7BBA7219AA50400272C3C6E
C:\Windows\System32\drivers\amdxata.sys CEA5F4F27CFC08E3A44D576811B35F50
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys E8CCB797DAF80779C768BD3A9FC8FCAF
C:\Windows\system32\drivers\appid.sys 04951A9A937CBE28A2D3FEEA360B6D1F
C:\Windows\System32\drivers\arcsas.sys 65045784366F7EC5FB4E71BCF923187B
C:\Windows\System32\drivers\atapi.sys 74B14192CF79A72F7536B27CB8814FBD
C:\Windows\system32\DRIVERS\athw8x.sys 2C7676F892E88FD190F08D98048C7C6C
C:\Windows\System32\drivers\bxvbda.sys A4A73F631FE2AA2826FBE4A399B04DEF
C:\Windows\System32\drivers\BasicDisplay.sys 8CC7F7E4AFCBA605921B137ED7992C68
C:\Windows\System32\drivers\BasicRender.sys 2748E116F8621A4DB0D39FCDD7318C01
C:\Windows\System32\drivers\bcmfn2.sys C1ABB0F7E3BEA48A0417BDF6FF14AB21
C:\Windows\System32\Drivers\Beep.sys EC19013E4CF87609534165DF897274D6
C:\Windows\System32\DRIVERS\bowser.sys 6B4FFFDDC618FCF64473CAA86E305697
C:\Windows\System32\drivers\BthAvrcpTg.sys A8F23D453A424FF4DE04989C4727ECC7
C:\Windows\System32\drivers\bthhfenum.sys 746B9F94214915AECDE4B7FEA5FF9664
C:\Windows\System32\drivers\BthHFHid.sys 71FE2A48E4C93DDB9798C024880B6C07
C:\Windows\System32\drivers\bthmodem.sys 07E33226AD218A2A162662A05CAFB52F
C:\Windows\System32\DRIVERS\cdfs.sys 2FA6510E33F7DEFEC03658B74101A9B9
C:\Windows\System32\drivers\cdrom.sys C6796EA22B513E3457514D92DCDB1A3D
C:\Windows\System32\drivers\circlass.sys BE9936EDD3267FAAFF94A7835867F00B
C:\Windows\System32\drivers\CLFS.sys B8B663BE41827211737F627473D6D192
C:\Windows\System32\drivers\CmBatt.sys EF6EF85DADC3184A10D8F2F7159973CB
C:\Windows\System32\Drivers\cng.sys 825BE21E6395E00698D8A23955A87972
C:\Windows\System32\drivers\CompositeBus.sys 03AAED827C36F35D70900558B8274905
C:\Windows\System32\drivers\condrv.sys A1FF7DFBFBE164CF92603C651D304DD2
C:\Windows\System32\drivers\csc.sys EE2F3C0D6ADBC975D6B621EC15ACF4E2
C:\Windows\System32\drivers\dam.sys 315BA4BC19316D72B2E037534E048B93
C:\Windows\System32\Drivers\dfsc.sys 5DB26D7E0216D0BF364A81D3829AD7B9
C:\Windows\System32\drivers\disk.sys 4D40C9B33F738797CF50E77CB7C53E85
C:\Windows\System32\drivers\dmvsc.sys EB70A894708D1BC176AFD690FF06085F
C:\Windows\system32\drivers\drmkaud.sys DDC11A202207C0400CBE07315B8FDE5E
C:\Windows\System32\drivers\dxgkrnl.sys 13B160C1913F012BD1615EB1398D3779
C:\Windows\System32\drivers\evbda.sys 114BCFDF367FF37C3F1B0A96AF542E4D
C:\Windows\System32\drivers\EhStorClass.sys 43531A5993380CC5113242C29D265FD9
C:\Windows\System32\drivers\EhStorTcgDrv.sys 6F8E738A9505A388B1157FDDE7B3101B
C:\Windows\System32\drivers\errdev.sys DFFFAE1442BA4076E18EED5E406FA0D3
C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys A0DD2BA297229D13FAEEDE08998694D6
C:\Windows\System32\Drivers\exfat.sys 7729D294A555C7AEB281ED8E4D0E01E4
C:\Windows\System32\Drivers\fastfat.sys 7C4E0D5900B2A1D11EDD626D6DDB937B
C:\Windows\System32\drivers\fdc.sys 5D8402613E778B3BD45E687A8372710B
C:\Windows\System32\drivers\fileinfo.sys 957A7A8F5ACCAF23DD9DFF6DAA393CE5
C:\Windows\System32\drivers\filetrace.sys A1A66C4FDAFD6B0289523232AFB7D8AF
C:\Windows\System32\drivers\flpydisk.sys BE743083CF7063C486A4398E3AEFE59A
C:\Windows\System32\drivers\fltmgr.sys 60D5067FCE6D9433D35E04C01D8538B3
C:\Windows\System32\drivers\FsDepends.sys 35005534E600E993A90B036E4E599F2B
C:\Windows\System32\Drivers\Fs_Rec.sys 09F460AFEDCA03F3BF6E07D1CCC9AC42
C:\Windows\System32\DRIVERS\fvevol.sys 83E1F0983B02A6F8EC764D18E24ECF10
C:\Windows\System32\drivers\fxppm.sys 9591D0B9351ED489EAFD9D1CE52A8015
C:\Windows\System32\drivers\gagp30kx.sys FC3EF65EE20D39F8749C2218DBA681CA
C:\Windows\System32\drivers\vmgencounter.sys 0BF5CAD281E25F1418E5B8875DC5ADD1
C:\Windows\System32\Drivers\msgpioclx.sys FDA72810CA2F8409D9B31E833C448E34
C:\Windows\system32\drivers\HdAudio.sys 56F69F7C25FB67C970997D7066DBC593
C:\Windows\System32\drivers\HDAudBus.sys 03909BDBFF0DCACCABF2B2D4ADEE44DC
C:\Windows\System32\drivers\HidBatt.sys 10A70BC1871CD955D85CD88372724906
C:\Windows\System32\drivers\hidbth.sys 1EA1B4FABB8CC348E73CA90DBA22E104
C:\Windows\System32\drivers\hidi2c.sys C241A8BAFBBFC90176EA0F5240EACC17
C:\Windows\System32\drivers\hidir.sys 9BDDEE26255421017E161CCB9D5EDA95
C:\Windows\System32\drivers\AsHIDSwitch64.sys 894D982CEAB8CD45A56AE2C9988E86C0
C:\Windows\System32\drivers\hidusb.sys F31397220D9687E11EB448649AA6E038
C:\Windows\System32\drivers\HpSAMD.sys A6AACEA4C785789BDA5912AD1FEDA80D
C:\Windows\System32\drivers\HTTP.sys 3502776E366C913D49C0DA928AE3E6CB
C:\Windows\System32\drivers\hwpolicy.sys 90656C0B3864804B090434EFC582404F
C:\Windows\System32\drivers\hyperkbd.sys 6D6F9E3BF0484967E52F7E846BFF1CA1
C:\Windows\system32\DRIVERS\HyperVideo.sys 907C870F8C31F8DDD6F090857B46AB25
C:\Windows\System32\drivers\i8042prt.sys 84CFC5EFA97D0C965EDE1D56F116A541
C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 5D90E32E36CE5D4C535D17CE08AEAF05
C:\Windows\System32\drivers\iaLPSSi_I2C.sys DD05E7E80F52ADE9AEB292819920F32C
C:\Windows\System32\drivers\iaStorAV.sys 08BFE413B0B4AA8DFA4B5684CE06D3DC
C:\Windows\System32\drivers\iaStorV.sys A2200C3033FA4EF249FC096A7A7D02A2
C:\Windows\System32\drivers\intelide.sys 4E448FCFFD00E8D657CD9E48D3E47157
C:\Windows\System32\drivers\intelpep.sys 139CFCDCD36B1B1782FD8C0014AC9B0E
C:\Windows\System32\drivers\intelppm.sys 47E74A8E53C7C24DCE38311E1451C1D9
C:\Windows\System32\DRIVERS\ipfltdrv.sys 9DB76D7F9E4E53EFE5DD8C53DE837514
C:\Windows\System32\drivers\IPMIDrv.sys 9949A3C7590B8C536C05312205079A82
C:\Windows\System32\drivers\ipnat.sys B7342B3C58E91107F6E946A93D9D4EFD
C:\Windows\System32\drivers\irenum.sys AE44C526AB5F8A487D941CEB57B10C97
C:\Windows\System32\drivers\isapnp.sys 8AFEEA3955AA43616A60F133B1D25F21
C:\Windows\System32\drivers\msiscsi.sys 034D4BD9DC67C64F3A4C8A049B5173BF
C:\Windows\System32\drivers\kbdclass.sys 8BE92376799B6B44D543E8D07CDCF885
C:\Windows\System32\drivers\kbdhid.sys FB6E47E569D4872ABEB506BE03A45FBA
C:\Windows\System32\drivers\kbldfltr.sys DB7A09BC90DF20F44F16F8B0F9ED3491
C:\Windows\system32\DRIVERS\kdnic.sys 813871C7D402A05F2E3A7075F9584A05
C:\Windows\System32\Drivers\ksecdd.sys ADDECBCC777665BD113BED437E602AB0
C:\Windows\System32\Drivers\ksecpkg.sys 7296EA420134EAC390798B3232D066A4
C:\Windows\system32\drivers\ksthunk.sys 11AFB527AA370B1DAFD5C36F35F6D45F
C:\Windows\system32\DRIVERS\lltdio.sys C09010B3680860131631F53E8FE7BAD8
C:\Windows\System32\drivers\lsi_sas.sys C755AE4635457AA2A11F79C0DF857ABC
C:\Windows\System32\drivers\lsi_sas2.sys ADAC09CBE7A2040B7F68B5E5C9A75141
C:\Windows\System32\drivers\lsi_sas3.sys 04D1274BB9BBCCF12BD12374002AA191
C:\Windows\System32\drivers\lsi_sss.sys 327469EEF3833D0C584B7E88A76AEC0C
C:\Windows\system32\drivers\luafv.sys 5EF604B0698F4FA962778285E8C5F1F2
C:\Windows\System32\drivers\megasas.sys EB5C03A070F30D64A6DF80E53B22F53F
C:\Windows\System32\drivers\megasr.sys F6F13533196DE7A582D422B0241E4363
C:\Windows\System32\drivers\modem.sys 8B38C44F69259987C95135C9627E2378
C:\Windows\System32\drivers\monitor.sys 601589000CC90F0DF8DA2CC254A3CCC9
C:\Windows\System32\drivers\mouclass.sys CEAC6D40FE887CE8406C2393CF97DE06
C:\Windows\System32\drivers\mouhid.sys 02D98BF804084E9A0D69D1C69B02CCA9
C:\Windows\System32\drivers\mountmgr.sys 515549560D481138E6E21AF7C6998E56
C:\Windows\System32\drivers\mpsdrv.sys F170510BE94CF45E3C6274578F6204B2
C:\Windows\system32\drivers\mrxdav.sys 59DCEC7499095DE5AED741358037AE2D
C:\Windows\System32\DRIVERS\mrxsmb.sys 79B6F3DF7CDFD12159871FF71464F0CE
C:\Windows\System32\DRIVERS\mrxsmb20.sys AAF56E4E84D35411B4E446C445732DFE
C:\Windows\system32\DRIVERS\bridge.sys 4E888019078AC363076A5433E89AA4F8
C:\Windows\System32\Drivers\Msfs.sys D13329FBF8345B28AB30F44CC247DC08
C:\Windows\System32\drivers\msgpiowin32.sys C6B474E46F9E543B875981ED3FFE6ADD
C:\Windows\System32\drivers\mshidkmdf.sys 65C92EB9D08DB5C69F28C7FFD4E84E31
C:\Windows\System32\drivers\mshidumdf.sys 52299F086AC2DAFD100DD5DC4A8614BA
C:\Windows\System32\drivers\msisadrv.sys 36D92AF3343C3A3E57FEF11C449AEA4C
C:\Windows\system32\drivers\MSKSSRV.sys A9BBBD2BAE6142253B9195E949AC2E8D
C:\Windows\system32\DRIVERS\mslldp.sys 375E44168F2DFB91A68B8A3F619C5A7C
C:\Windows\system32\drivers\MSPCLOCK.sys 7B2128EB875DCBC006E6A913211006D6
C:\Windows\system32\drivers\MSPQM.sys 1E88171579B218115C7A772F8DE04BD8
C:\Windows\System32\Drivers\MsRPC.sys BBE2A455053E63BECBF42C2F9B21FAE0
C:\Windows\System32\drivers\mssmbios.sys 8D6B7D515C5CBCDB75B928A0B73C3C5E
C:\Windows\system32\drivers\MSTEE.sys 115019AE01E0EB9C048530D2928AB4A2
C:\Windows\System32\drivers\MTConfig.sys 96D604A35070360F0DD4A7A8AF410B5E
C:\Windows\System32\Drivers\mup.sys 619CA29326B82372621DB2C0964D8365
C:\Windows\System32\drivers\mvumis.sys B8C35C94DCB2DFEAF03BB42131F2F77F
C:\Windows\system32\DRIVERS\nwifi.sys CF8B989D89D6807B887690F2CF24EFD9
C:\Windows\System32\drivers\ndis.sys ED39D676080A1AEA755F1DEC1A8DF1A4
C:\Windows\system32\DRIVERS\ndiscap.sys C6BB12BC35D1637CA17AE16D3A4725EB
C:\Windows\system32\DRIVERS\NdisImPlatform.sys 9F1DA20E943BE7AA4ED5F3E1EBA78B37
C:\Windows\system32\DRIVERS\ndistapi.sys 9423421E735BD5394351E0C47C76BB92
C:\Windows\system32\DRIVERS\ndisuio.sys B832B35055BA2B7B4181861FF94D8E59
C:\Windows\System32\drivers\NdisVirtualBus.sys 1F58E48EF75F34C35D8E93A0DC535CFE
C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
C:\Windows\System32\Drivers\NDProxy.sys A5BD69A8812FA79D1A487691DD3FB244
C:\Windows\System32\drivers\Ndu.sys 5A072F0B90C29C5233D78BE33EF5ED78
C:\Windows\System32\DRIVERS\netbios.sys A83D67D347A684F10B7D3019C8A6380C
C:\Windows\System32\DRIVERS\netbt.sys 0217532E19A748F0E5D569307363D5FD
C:\Windows\system32\DRIVERS\netvsc63.sys 70414DB660BFBB7BD58FCE8EA4364E1B
C:\Windows\System32\Drivers\Npfs.sys 8F44A2F57C9F1A19AC9C6288C10FB351
C:\Windows\System32\drivers\npsvctrig.sys CBDB4F0871C88DF930FC0E8588CA67FC
C:\Windows\System32\drivers\nsiproxy.sys E490B459978CB87779E84C761D22B827
C:\Windows\System32\Drivers\Ntfs.sys 725EF69B2DBEB7B33280019A556201BC
C:\Windows\System32\Drivers\Null.sys EF1B290FC9F0E47CC0B537292BEE5904
C:\Windows\System32\drivers\nvraid.sys BC6B5942AFF25EBAF62DE43C3807EDF8
C:\Windows\System32\drivers\nvstor.sys 1F43ABFFAC3D6CA356851D517392966E
C:\Windows\System32\drivers\nv_agp.sys 6934A936A7369DFE37B7DBA93F5E5E49
C:\Windows\System32\drivers\parport.sys 764B1121867B2D9B31C491668AC72B2B
C:\Windows\System32\drivers\partmgr.sys EF0C1749C9A8CEE9A457473D433CC00F
C:\Windows\System32\drivers\pci.sys C0D3F3BC1C84B4BA746D9847314C1164
C:\Windows\System32\drivers\pciide.sys 346E38FCC6859A727DD28AFAD1F0AFF4
C:\Windows\System32\drivers\pcmcia.sys 4D3BDCC1C7B40C9D7B6AD990E6DEC397
C:\Windows\System32\drivers\pcw.sys BF28771D1436C88BE1D297D3098B0F7D
C:\Windows\System32\drivers\pdc.sys B9D968D8E2B0F9C6301CEB39CFC9B9E4
C:\Windows\System32\drivers\peauth.sys BA50CC0BD19004AAB88BE37338B6FA0D
C:\Windows\System32\drivers\processr.sys ECD373F9571C745894367CC2635EA44F
C:\Windows\system32\DRIVERS\pacer.sys 8528BB05E4D4E25945F78B00B2555FB7
C:\Windows\system32\drivers\qwavedrv.sys 3FB466684609A4329858CF2EBD62E0FD
C:\Windows\System32\DRIVERS\rasacd.sys 2C56F0EE27E4EF70CA4B4983D3638905
C:\Windows\system32\DRIVERS\raspppoe.sys 5247F308C4103CDC4FE12AE1D235800A
C:\Windows\System32\DRIVERS\rdbss.sys A1A5E79C0D1352AFDC08328A623DA051
C:\Windows\System32\drivers\rdpbus.sys 6B21EBF892CD8CACB71669B35AB5DE32
C:\Windows\System32\drivers\rdpdr.sys 680C1DAE268B6FB67FA21B389A8B79EF
C:\Windows\System32\drivers\rdpvideominiport.sys 858776908AF838E3790F3261B799CDA6
C:\Windows\System32\drivers\rdyboost.sys 847C6A08912C3515807049C93E526D65
C:\Windows\System32\Drivers\ReFS.sys 036746D54347FD2D0385668E2A4064E4
C:\Windows\system32\DRIVERS\rspndr.sys 2D05A5508F4685412F2B89E8C2189ABC
C:\Windows\system32\DRIVERS\Rt630x64.sys 19764658C1468C2C0CEF133D28414A6B
C:\Windows\System32\drivers\vms3cap.sys 1A063730F221B2746FF00457AE17E4F0
C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS 3289766038DB2CB14D07DC84392138D5
C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS 58A38E75F3316A83C23DF6173D41F2B5
C:\Windows\System32\drivers\sbp2port.sys C624A1B32211C3166EDB3F4AB02A30B7
C:\Windows\System32\DRIVERS\scfilter.sys ABD0237B15DBD2B4695F4B7D734A58F7
C:\Windows\System32\drivers\sdbus.sys 2F9A3380B8C0380E5608E29C7AA66899
C:\Windows\System32\drivers\sdstor.sys 4EAF4DCF9DBD9A56952A58F56D61C005
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\SerCx.sys DB2FF24CE0BDD15FE75870AFE312BA89
C:\Windows\System32\drivers\SerCx2.sys 0044B31F93946D5D41982314381FE431
C:\Windows\System32\drivers\serenum.sys 3CD600C089C1251BEEB4CD4CD5164F9E
C:\Windows\System32\drivers\serial.sys D864381BC9C725FAB01D94C060660166
C:\Windows\System32\drivers\sermouse.sys 0BD2B65DCE756FDE95A2E5CCCBF7705D
C:\Windows\System32\drivers\sfloppy.sys 472B7A5AC181C050888DB454663DD764
C:\Windows\System32\drivers\SiSRaid2.sys 2F518D13DD6F3053837FE606F1A2EA1F
C:\Windows\System32\drivers\sisraid4.sys 1AC9A200A9C49C4508F04AAFFCA34A3F
C:\Windows\System32\drivers\spaceport.sys F6EBE514D13ECE7EDC23440039CDF9AB
C:\Windows\System32\drivers\SpbCx.sys F337BE11071818FC3F5DC2940B6BDE34
C:\Windows\System32\DRIVERS\srv2.sys C1AE59C0B0817236EC083A91C396005A
C:\Windows\System32\DRIVERS\srvnet.sys 77195C32175FC63D6054EBA5A066D727
C:\Windows\System32\drivers\stexstor.sys 366DEA74BBA65B362BCCFC6FC2ADFD8B
C:\Windows\System32\drivers\storahci.sys 0ED2E318ABB68C1A35A8B8038BDB4C90
C:\Windows\System32\DRIVERS\vmstorfl.sys 7A08CEE1535F5A448215634C5EA74E50
C:\Windows\System32\drivers\stornvme.sys 6B06E2D11E604BE2B1A406C4CB3B90DE
C:\Windows\System32\drivers\storvsc.sys 548759755BC73DAD663250239D7E0B9F
C:\Windows\System32\drivers\storvsp.sys 03618F935379614837F915D04C45FC0E
C:\Windows\System32\drivers\swenum.sys 84E0F5D41C138C5CC975137A2A98F6D3
C:\Windows\System32\drivers\Synth3dVsc.sys 25F0DA8E7F26416FDB5D77592B5C1A8B
C:\Windows\System32\drivers\tcpip.sys ECC68BD5347BDE9631EE68274858A41F
C:\Windows\system32\DRIVERS\tcpip.sys ECC68BD5347BDE9631EE68274858A41F
C:\Windows\System32\drivers\tcpipreg.sys 33A7D83EEB15431773A6E186CFAABA21
C:\Windows\system32\DRIVERS\tdx.sys FFF28F9F6823EB1756C60F1649560BBF
C:\Windows\System32\drivers\terminpt.sys 232D185D2337F141311D0CF1983E1431
C:\Windows\system32\drivers\tpm.sys 82F909359600D3603FE852DB7F135626
C:\Windows\System32\drivers\tsusbflt.sys BF8F54CA37E9C9D6582C31C5761F8C93
C:\Windows\System32\drivers\TsUsbGD.sys E0088068DCE2EE82897027DDB8E05254
C:\Windows\System32\drivers\tsusbhub.sys 4A445D5E44CD996D18E128EF321D54B2
C:\Windows\system32\DRIVERS\tunnel.sys C8E0E78B5D284C2FF59BDFFDAF997242
C:\Windows\System32\drivers\uagp35.sys F6EEAD052943B5A3104C1405BB856C54
C:\Windows\System32\drivers\uaspstor.sys FE6067B1FD4E63650C667B33D080565B
C:\Windows\System32\drivers\ucx01000.sys 5D1B430EA11064C56E7C8F84B90DEB6A
C:\Windows\System32\DRIVERS\udfs.sys 1EC649F112896FAE33250F0B97AC5D0B
C:\Windows\System32\drivers\UEFI.sys 9578691F297E1B1F519970FE6D47CB21
C:\Windows\System32\drivers\uliagpkx.sys 5EAB5117DDB24FC4D39E6FFFCF1837B9
C:\Windows\System32\drivers\umbus.sys DA34C39A18E60E7C3FA0630566408034
C:\Windows\System32\drivers\umpass.sys AE8294875E5446E359B1E8035D40C05E
C:\Windows\System32\drivers\usbccgp.sys 433ECDE01A52691FA7ACA51C10C09B70
C:\Windows\System32\drivers\usbcir.sys B3D6457D841A0CAEF4C52D88621715F2
C:\Windows\System32\drivers\usbehci.sys 5477D6E27C7D266EF8C152B9A25ADE5E
C:\Windows\System32\drivers\usbhub.sys DF56C2C04EFA328D7A66B69007130266
C:\Windows\System32\drivers\UsbHub3.sys C0E33820326199CE3CFD3B9F27F81D99
C:\Windows\System32\drivers\usbohci.sys 3019097FB6C985EF24C058090FF3BDBD
C:\Windows\System32\drivers\usbprint.sys 4D655E3B684BE9B0F7FFD8A2935C348C
C:\Windows\System32\drivers\USBSTOR.SYS 4628B415A84EA9D4D396A56F1D0CB6C6
C:\Windows\System32\drivers\usbuhci.sys BA4FA655E0FC577DB7436FC963932CE4
C:\Windows\System32\Drivers\usbvideo.sys 18F744E8CCEB2670040EBAF7AD77B8C6
C:\Windows\System32\drivers\USBXHCI.SYS D22EB844EB57D016CC34178AC86456DF
C:\Windows\System32\drivers\vdrvroot.sys FEB26E3B8345A7E8D62F945C4AE86562
C:\Windows\System32\drivers\VerifierExt.sys A026EDEAA5EECAE0B08E2748B616D4BD
C:\Windows\System32\drivers\vhdmp.sys 041D3EF364E624DBB2703A64A5AADF89
C:\Windows\System32\drivers\viaide.sys 06D38968028E9AB19DE9B618C7B6D199
C:\Windows\System32\drivers\Vid.sys 3CE922E34DB12D9F3C0EA856BC09687C
C:\Windows\System32\drivers\vmbus.sys C6305BDFC4F7CE51F72BB072C03D4ACE
C:\Windows\System32\drivers\VMBusHID.sys DA40BEA0A863CE768C940CA9723BF81F
C:\Windows\System32\drivers\vmbusr.sys 68F8C26DEA2D42E8DEC0778943433C80
C:\Windows\System32\drivers\volmgr.sys 55D7D963DE85162F1C49721E502F9744
C:\Windows\System32\drivers\volmgrx.sys CCB9E901F7254BF96D28EB1B0E5329B7
C:\Windows\System32\drivers\volsnap.sys C85C075DE5B6D0FE116043054DE8EE02
C:\Windows\System32\drivers\vpci.sys 01355C98B5C3ED1EC446743CDA848FCE
C:\Windows\System32\drivers\vpcivsp.sys ADBE96C33D1A5BB1BBAF90B4BC84F523
C:\Windows\System32\drivers\vsmraid.sys 4539F45F9F4C9757A86A56C949421E07
C:\Windows\System32\drivers\vstxraid.sys 0849B7260F26FE05EA56DED0672E2F4B
C:\Windows\System32\drivers\vwifibus.sys BE970C369E43B509C1EDA2B8FA7CECB0
C:\Windows\system32\DRIVERS\vwififlt.sys 6B26AD573CCDD5209DF4397438B76354
C:\Windows\system32\DRIVERS\vwifimp.sys 0B48E0DFB44EE475F4FD8A8EE599AF30
C:\Windows\System32\drivers\wacompen.sys 0910AB9ED404C1434E2D0376C2AD5D8B
C:\Windows\System32\drivers\WdBoot.sys 241895E8A9C158DF86E12FDD21033A32
C:\Windows\System32\drivers\Wdf01000.sys CB6C63FF8342B467E2EF76E98D5B934D
C:\Windows\System32\drivers\WdFilter.sys C52148456E0F6EAD9E903020A79207FC
C:\Windows\System32\Drivers\WdNisDrv.sys 57F22324FAAF92ADF957B281E88F1743
C:\Windows\System32\DRIVERS\wfplwfs.sys 2E3E82D7B1076B90F4E228A8EF17B261
C:\Windows\System32\drivers\wimmount.sys 867BCC69ED9C31C501465EB0E8BA9DFA
C:\Windows\System32\drivers\wmiacpi.sys 2834D9D3B4F554A39C72F00EA3F0E128
C:\Windows\System32\DRIVERS\wpcfltr.sys E746BCDBA2E02CF6B8D6B26FB167FBE0
C:\Windows\System32\drivers\WpdUpFltr.sys 9F2904B55F6CECCD1A8D986B5CE2609A
C:\Windows\system32\drivers\ws2ifsl.sys AE072B0339D0A18E455DC21666CAD572
C:\Windows\System32\drivers\WudfPf.sys 2FEAE33E9B2B56104596E1BA444405A9
C:\Windows\System32\drivers\WUDFRd.sys 19240C13F526125554B5370566F21A0A
C:\Windows\system32\DRIVERS\WUDFRd.sys 19240C13F526125554B5370566F21A0A

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-14 01:40 - 2014-04-14 01:40 - 00026040 _____ () C:\Users\Karl\Desktop\FRST.txt
2014-04-14 01:40 - 2014-04-14 01:40 - 00000000 ____D () C:\FRST
2014-04-14 01:17 - 2014-04-14 01:17 - 00000978 _____ () C:\Users\Karl\Desktop\RKreport[0]_H_04142014_011711.txt
2014-04-14 00:48 - 2014-04-14 00:48 - 00000000 _____ () C:\Users\Karl\defogger_reenable
2014-04-14 00:15 - 2014-04-14 00:17 - 107394336 _____ (Oracle Corporation) C:\Users\Karl\Desktop\VirtualBox-4.3.10-93012-Win.exe
2014-04-14 00:01 - 2014-04-14 00:01 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\ATI
2014-04-14 00:01 - 2014-04-14 00:01 - 00000000 ____D () C:\Users\Karl\AppData\Local\ATI
2014-04-14 00:01 - 2014-04-14 00:01 - 00000000 ____D () C:\Users\Karl\AppData\Local\AMD
2014-04-14 00:01 - 2014-04-14 00:01 - 00000000 ____D () C:\ProgramData\ATI
2014-04-13 23:17 - 2014-04-13 23:17 - 00001133 _____ () C:\Users\Public\Desktop\herdProtect.lnk
2014-04-13 23:17 - 2014-04-13 23:17 - 00000000 ____D () C:\Program Files\Reason
2014-04-13 23:04 - 2014-04-13 23:05 - 04745728 _____ (AVAST Software) C:\Users\Karl\Desktop\MBR.com.exe
2014-04-13 23:01 - 2014-04-13 23:01 - 00003233 _____ () C:\Users\Karl\Desktop\Sophos Virus Removal Tool.lnk
2014-04-13 23:00 - 2014-04-13 23:00 - 00000000 ____D () C:\Users\Karl\Pavark
2014-04-13 23:00 - 2014-04-13 23:00 - 00000000 ____D () C:\Program Files (x86)\Sophos
2014-04-13 22:51 - 2014-04-13 23:01 - 00000000 ____D () C:\ProgramData\Sophos
2014-04-13 22:44 - 2014-04-13 23:01 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sophos
2014-04-13 22:44 - 2014-04-13 22:44 - 00000052 _____ () C:\Windows\SysWOW64\Console.log
2014-04-13 22:44 - 2014-04-13 22:44 - 00000000 ____D () C:\Sophos
2014-04-13 22:44 - 2014-04-13 22:44 - 00000000 ____D () C:\scss_10
2014-04-13 22:13 - 2014-04-13 22:13 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-13 22:13 - 2014-03-31 03:51 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-13 22:00 - 2014-04-13 22:00 - 01189560 _____ (AMD Inc.) C:\Users\Karl\Downloads\catalyst_mobility_64-bit_util.exe
2014-04-13 21:58 - 2014-04-13 21:58 - 02067320 _____ (AMD) C:\Users\Karl\Downloads\amdcompatibilitychecker.exe
2014-04-13 21:51 - 2013-12-14 01:31 - 13949440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2014-04-13 21:51 - 2013-12-14 01:19 - 18576384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2014-04-13 21:51 - 2013-12-09 03:05 - 21199256 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-04-13 21:50 - 2014-01-07 20:46 - 00325464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2014-04-13 21:50 - 2014-01-07 20:41 - 01530712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-04-13 21:50 - 2014-01-07 20:41 - 00382808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-04-13 21:50 - 2014-01-04 10:54 - 00138240 _____ () C:\Windows\system32\OEMLicense.dll
2014-04-13 21:50 - 2014-01-04 10:08 - 00103936 _____ () C:\Windows\SysWOW64\OEMLicense.dll
2014-04-13 21:50 - 2014-01-04 09:08 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2014-04-13 21:50 - 2014-01-04 08:53 - 00174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2014-04-13 21:50 - 2014-01-02 18:54 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-04-13 21:50 - 2014-01-02 18:48 - 00336896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-04-13 21:50 - 2013-12-31 20:55 - 01720560 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-04-13 21:50 - 2013-12-31 20:52 - 00481944 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2014-04-13 21:50 - 2013-12-31 19:56 - 01472048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-04-13 21:50 - 2013-12-31 19:55 - 00381168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2014-04-13 21:50 - 2013-12-31 18:59 - 00802816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2014-04-13 21:50 - 2013-12-31 18:57 - 01214976 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-04-13 21:50 - 2013-12-31 18:56 - 00960512 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2014-04-13 21:50 - 2013-12-30 18:34 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sti.dll
2014-04-13 21:50 - 2013-12-30 18:33 - 00770560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2014-04-13 21:50 - 2013-12-30 18:32 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\sti.dll
2014-04-13 21:50 - 2013-12-30 18:31 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2014-04-13 21:50 - 2013-12-30 18:31 - 00914944 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-04-13 21:50 - 2013-12-27 10:09 - 00419160 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-04-13 21:50 - 2013-12-27 03:57 - 00842752 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll
2014-04-13 21:50 - 2013-12-27 03:57 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2014-04-13 21:50 - 2013-12-27 03:23 - 00749056 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2014-04-13 21:50 - 2013-12-27 02:03 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll
2014-04-13 21:50 - 2013-12-27 02:03 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2014-04-13 21:50 - 2013-12-27 01:37 - 00588800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2014-04-13 21:50 - 2013-12-21 02:21 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2014-04-13 21:50 - 2013-12-17 02:21 - 00408576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2014-04-13 21:50 - 2013-12-13 05:54 - 00131160 _____ (Microsoft Corporation) C:\Windows\system32\easinvoker.exe
2014-04-13 21:50 - 2013-12-13 01:36 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
2014-04-13 21:50 - 2013-12-13 00:32 - 00140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
2014-04-13 21:50 - 2013-12-08 23:51 - 18643560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-04-13 21:50 - 2013-11-04 06:50 - 02143744 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-04-13 21:50 - 2013-11-03 20:30 - 01765376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2014-04-13 21:50 - 2013-10-23 06:29 - 00044936 _____ (Microsoft Corporation) C:\Windows\system32\wldp.dll
2014-04-13 21:50 - 2013-10-23 06:21 - 00155480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-04-13 21:50 - 2013-10-23 06:13 - 00171864 _____ (Microsoft Corporation) C:\Windows\system32\kd_02_8086.dll
2014-04-13 21:50 - 2013-10-22 03:18 - 00096088 _____ (Microsoft Corporation) C:\Windows\system32\embeddedapplauncher.exe
2014-04-13 21:50 - 2013-10-22 02:55 - 02328872 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-04-13 21:50 - 2013-10-22 01:03 - 02065448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-04-13 21:50 - 2013-10-22 00:15 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2014-04-13 21:50 - 2013-10-21 23:04 - 00618496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
2014-04-13 21:50 - 2013-10-21 21:38 - 01362944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2014-04-13 21:50 - 2013-10-21 21:22 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-04-13 21:50 - 2013-10-21 21:13 - 01704448 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-04-13 21:50 - 2013-10-18 23:48 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2014-04-13 21:50 - 2013-10-18 23:03 - 00531968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2014-04-13 21:50 - 2013-10-18 22:26 - 01231360 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2014-04-13 21:50 - 2013-10-18 22:14 - 00888832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2014-04-13 21:50 - 2013-10-16 04:34 - 00518656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2014-04-13 21:50 - 2013-10-16 04:33 - 00631296 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2014-04-13 21:50 - 2013-10-12 22:06 - 00258904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2014-04-13 21:50 - 2013-10-12 21:43 - 00708616 _____ (Microsoft Corporation) C:\Windows\system32\iuilp.dll
2014-04-13 21:50 - 2013-10-10 11:26 - 00317616 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-04-13 21:50 - 2013-10-10 11:26 - 00104320 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2014-04-13 21:50 - 2013-10-10 09:53 - 00235960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-04-13 21:50 - 2013-10-10 09:53 - 00088272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2014-04-13 21:50 - 2013-10-10 06:38 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-04-13 21:50 - 2013-10-08 05:28 - 00523096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2014-04-13 21:50 - 2013-10-08 01:46 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll
2014-04-13 21:50 - 2013-10-08 00:58 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shsetup.dll
2014-04-13 21:50 - 2013-10-08 00:50 - 00656384 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-04-13 21:50 - 2013-10-08 00:48 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-04-13 21:50 - 2013-10-08 00:15 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-04-13 21:50 - 2013-10-08 00:09 - 01160704 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Http.dll
2014-04-13 21:50 - 2013-10-07 23:50 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-04-13 21:50 - 2013-10-07 23:50 - 00762368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Http.dll
2014-04-13 21:50 - 2013-10-07 02:21 - 00054776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-04-13 21:50 - 2013-10-06 21:13 - 03532288 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-04-13 21:50 - 2013-10-05 10:25 - 00057176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2014-04-13 21:50 - 2013-10-05 09:21 - 02140888 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-04-13 21:50 - 2013-10-05 09:21 - 00699840 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-04-13 21:50 - 2013-10-05 09:21 - 00516496 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-04-13 21:50 - 2013-10-05 07:05 - 01765384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-04-13 21:50 - 2013-10-05 07:05 - 00578952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-04-13 21:50 - 2013-10-05 07:05 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-04-13 21:50 - 2013-10-05 04:36 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-04-13 21:50 - 2013-10-05 04:18 - 01011712 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-04-13 21:50 - 2013-10-05 04:07 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2014-04-13 21:50 - 2013-10-05 03:56 - 01147904 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2014-04-13 21:50 - 2013-10-05 03:55 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\miutils.dll
2014-04-13 21:50 - 2013-10-05 03:40 - 00795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-04-13 21:50 - 2013-10-05 03:24 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\miutils.dll
2014-04-13 21:50 - 2013-10-05 03:21 - 00920064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2014-04-13 21:50 - 2013-10-05 03:15 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\pcsvDevice.dll
2014-04-13 21:50 - 2013-10-05 02:43 - 00578560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2014-04-13 21:50 - 2013-10-05 02:35 - 00411648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2014-04-13 21:50 - 2013-10-04 03:10 - 00533504 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2014-04-13 21:50 - 2013-09-26 01:34 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\MrmIndexer.dll
2014-04-13 21:50 - 2013-09-26 01:34 - 00515072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmIndexer.dll
2014-04-13 21:50 - 2013-09-17 04:06 - 01067080 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2014-04-13 21:50 - 2013-09-17 04:06 - 00465960 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-04-13 21:50 - 2013-09-17 01:31 - 00883184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2014-04-13 21:50 - 2013-09-17 01:31 - 00326024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-04-13 21:50 - 2013-09-16 23:37 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\dafBth.dll
2014-04-13 21:50 - 2013-09-14 09:07 - 02134120 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-04-13 21:50 - 2013-09-14 09:00 - 00391512 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2014-04-13 21:50 - 2013-09-14 07:39 - 01799944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2014-04-13 21:50 - 2013-09-14 07:33 - 00345552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2014-04-13 21:50 - 2013-09-14 05:05 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2014-04-13 21:50 - 2013-09-14 04:11 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll
2014-04-13 21:50 - 2013-09-13 03:22 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe
2014-04-13 21:50 - 2013-09-13 02:47 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ftp.exe
2014-04-13 21:50 - 2013-09-12 03:45 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2014-04-13 21:50 - 2013-09-12 03:08 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2014-04-13 21:50 - 2013-09-12 03:08 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\WiFiDisplay.dll
2014-04-13 21:50 - 2013-09-12 03:02 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2014-04-13 21:50 - 2013-09-12 02:44 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2014-04-13 21:50 - 2013-09-12 02:37 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2014-04-13 21:50 - 2013-09-12 02:37 - 00184832 _____ (Microsoft Corporation) C:\Windows\system32\dafWfdProvider.dll
2014-04-13 21:50 - 2013-09-12 02:21 - 00262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2014-04-13 21:50 - 2013-09-12 02:16 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll
2014-04-13 21:50 - 2013-09-12 02:01 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll
2014-04-13 21:50 - 2013-09-09 23:52 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\msched.dll
2014-04-13 21:49 - 2013-12-08 19:34 - 01227264 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2014-04-13 21:49 - 2013-12-08 19:04 - 00980480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2014-04-13 21:49 - 2013-11-27 10:34 - 03210528 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-04-13 21:49 - 2013-11-27 10:27 - 00809872 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2014-04-13 21:49 - 2013-11-27 09:00 - 00663680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2014-04-13 21:49 - 2013-11-27 08:47 - 02804528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-04-13 21:49 - 2013-11-27 07:02 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ipnat.sys
2014-04-13 21:49 - 2013-11-27 05:24 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-04-13 21:49 - 2013-11-27 04:46 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-04-13 21:49 - 2013-11-27 04:41 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2014-04-13 21:49 - 2013-11-27 04:17 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2014-04-13 21:49 - 2013-11-27 04:10 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.dll
2014-04-13 21:49 - 2013-11-27 03:58 - 01503232 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2014-04-13 21:49 - 2013-11-27 03:56 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.dll
2014-04-13 21:49 - 2013-11-26 08:20 - 01399176 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2014-04-13 21:49 - 2013-11-26 08:20 - 01374384 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-04-13 21:49 - 2013-11-26 06:44 - 01204968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2014-04-13 21:49 - 2013-11-24 20:45 - 00142680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-04-13 21:49 - 2013-11-24 20:32 - 01119064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-04-13 21:49 - 2013-11-24 18:30 - 00513536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-04-13 21:49 - 2013-11-24 18:28 - 00589824 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-04-13 21:49 - 2013-11-23 07:47 - 00032088 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll
2014-04-13 21:49 - 2013-11-23 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\bi.dll
2014-04-13 21:49 - 2013-11-23 02:13 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys
2014-04-13 21:49 - 2013-11-23 02:08 - 00403456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-04-13 21:49 - 2013-11-22 23:50 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll
2014-04-13 21:49 - 2013-11-22 22:19 - 02617344 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-04-13 21:49 - 2013-11-22 22:15 - 02295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-04-13 21:49 - 2013-11-21 01:58 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\deviceregistration.dll
2014-04-13 21:49 - 2013-11-21 01:26 - 01415680 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-04-13 21:49 - 2013-11-15 09:59 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2014-04-13 21:49 - 2013-11-15 09:25 - 00433664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2014-04-13 21:49 - 2013-11-15 09:08 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2014-04-13 21:49 - 2013-11-15 08:24 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-04-13 21:49 - 2013-11-10 21:48 - 00039768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelpep.sys
2014-04-13 21:49 - 2013-11-09 01:37 - 01756160 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2014-04-13 21:49 - 2013-11-09 00:56 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe
2014-04-13 21:49 - 2013-11-08 05:26 - 00358896 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2014-04-13 21:49 - 2013-11-08 00:23 - 00449024 _____ (Microsoft Corporation) C:\Windows\system32\appmgr.dll
2014-04-13 21:49 - 2013-11-07 23:43 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2014-04-13 21:49 - 2013-11-07 23:42 - 00366080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appmgr.dll
2014-04-13 21:49 - 2013-11-07 23:16 - 00225792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2014-04-13 21:49 - 2013-11-07 23:15 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2014-04-13 21:49 - 2013-11-07 22:41 - 01302528 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2014-04-13 21:49 - 2013-11-07 22:14 - 00922624 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2014-04-13 21:49 - 2013-11-05 09:19 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2014-04-13 21:49 - 2013-11-04 08:07 - 01843712 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2014-04-13 21:49 - 2013-11-04 05:32 - 02570240 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2014-04-13 21:49 - 2013-11-03 21:28 - 01816576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Display.dll
2014-04-13 21:49 - 2013-11-01 06:39 - 00086872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2014-04-13 21:49 - 2013-11-01 01:08 - 00747008 _____ (Microsoft Corporation) C:\Windows\system32\wlidcli.dll
2014-04-13 21:49 - 2013-11-01 00:57 - 00544768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcli.dll
2014-04-13 21:49 - 2013-10-30 19:58 - 00372568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2014-04-13 21:49 - 2013-10-30 19:42 - 07399256 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-04-13 21:49 - 2013-10-30 19:33 - 01476184 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-04-13 21:49 - 2013-10-30 19:33 - 01345536 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-04-13 21:49 - 2013-10-30 19:29 - 00745336 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-04-13 21:49 - 2013-10-30 18:41 - 00552624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-04-13 21:49 - 2013-10-25 20:54 - 00146776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\SerCx2.sys
2014-04-13 21:49 - 2013-10-24 04:31 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\CredentialMigrationHandler.dll
2014-04-13 21:49 - 2013-10-24 04:12 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredentialMigrationHandler.dll
2014-04-13 21:49 - 2013-10-17 06:21 - 02896896 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2014-04-13 21:49 - 2013-10-17 05:36 - 02266624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2014-04-13 21:49 - 2013-10-10 06:53 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2014-04-13 21:49 - 2013-10-10 06:21 - 00139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2014-04-13 21:49 - 2013-10-10 05:34 - 01085952 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2014-04-13 21:49 - 2013-10-10 05:27 - 00869888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2014-04-13 21:48 - 2013-09-26 04:20 - 00556032 _____ (Microsoft Corporation) C:\Windows\system32\recimg.exe
2014-04-13 21:48 - 2013-09-26 02:32 - 00638464 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2014-04-13 21:48 - 2013-09-25 05:25 - 00783504 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2014-04-13 21:48 - 2013-09-25 03:58 - 00648648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2014-04-13 21:48 - 2013-09-25 02:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\BthRadioMedia.dll
2014-04-13 21:48 - 2013-09-25 00:40 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\windows.immersiveshell.serviceprovider.dll
2014-04-13 21:48 - 2013-09-24 00:54 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2014-04-13 21:48 - 2013-09-24 00:10 - 01741824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2014-04-13 21:48 - 2013-09-24 00:05 - 01245696 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2014-04-13 21:48 - 2013-09-23 22:56 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.ContentPrefetchTask.dll
2014-04-13 21:48 - 2013-09-21 07:10 - 00579416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-04-13 21:48 - 2013-09-21 07:10 - 00236376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2014-04-13 21:48 - 2013-09-21 07:10 - 00151384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2014-04-13 21:48 - 2013-09-21 06:50 - 00528048 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-04-13 21:48 - 2013-09-21 06:48 - 00534048 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-04-13 21:48 - 2013-09-21 06:48 - 00123480 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2014-04-13 21:48 - 2013-09-21 05:56 - 00101208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-04-13 21:48 - 2013-09-21 05:53 - 01534504 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-04-13 21:48 - 2013-09-21 05:53 - 00996320 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2014-04-13 21:48 - 2013-09-21 05:53 - 00934856 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2014-04-13 21:48 - 2013-09-21 05:53 - 00366688 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2014-04-13 21:48 - 2013-09-21 05:45 - 00171968 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-04-13 21:48 - 2013-09-21 04:23 - 00427096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-04-13 21:48 - 2013-09-21 04:23 - 00098104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2014-04-13 21:48 - 2013-09-21 04:12 - 01092896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2014-04-13 21:48 - 2013-09-21 04:09 - 00796928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2014-04-13 21:48 - 2013-09-21 04:09 - 00312936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2014-04-13 21:48 - 2013-09-21 02:58 - 00675328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-04-13 21:48 - 2013-09-21 02:57 - 00207360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-04-13 21:48 - 2013-09-21 02:55 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\agilevpn.sys
2014-04-13 21:48 - 2013-09-21 02:50 - 00240128 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2014-04-13 21:48 - 2013-09-21 02:17 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\BulkOperationHost.exe
2014-04-13 21:48 - 2013-09-21 01:55 - 00168448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2014-04-13 21:48 - 2013-09-21 01:33 - 11366912 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
2014-04-13 21:48 - 2013-09-21 00:59 - 00940544 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-04-13 21:48 - 2013-09-21 00:57 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\livessp.dll
2014-04-13 21:48 - 2013-09-21 00:56 - 08712704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2014-04-13 21:48 - 2013-09-21 00:43 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2014-04-13 21:48 - 2013-09-21 00:38 - 00365568 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2014-04-13 21:48 - 2013-09-21 00:34 - 01555456 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2014-04-13 21:48 - 2013-09-21 00:31 - 00756224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-04-13 21:48 - 2013-09-21 00:26 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2014-04-13 21:48 - 2013-09-21 00:10 - 12028416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2014-04-13 21:48 - 2013-09-21 00:05 - 08875008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2014-04-13 21:48 - 2013-09-21 00:02 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2014-04-13 21:48 - 2013-09-20 23:54 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2014-04-13 21:48 - 2013-09-20 23:44 - 01662464 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2014-04-13 21:48 - 2013-09-20 23:39 - 01455616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2014-04-13 21:48 - 2013-09-20 23:38 - 01057792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\printui.dll
2014-04-13 21:48 - 2013-09-20 23:37 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
2014-04-13 21:48 - 2013-09-20 23:36 - 01185280 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll
2014-04-13 21:48 - 2013-09-19 02:19 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersRes.dll
2014-04-13 21:48 - 2013-09-19 01:39 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.dll
2014-04-13 21:48 - 2013-09-19 01:23 - 00117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WorkFoldersRes.dll
2014-04-13 21:48 - 2013-09-19 01:17 - 00456192 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2014-04-13 21:48 - 2013-09-19 00:29 - 00393728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2014-04-13 21:48 - 2013-09-19 00:08 - 01150976 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2014-04-13 21:48 - 2013-09-19 00:01 - 00401920 _____ (Microsoft Corporation) C:\Windows\system32\wlidprov.dll
2014-04-13 21:48 - 2013-09-18 23:37 - 00802816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2014-04-13 21:48 - 2013-09-18 23:32 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidprov.dll
2014-04-13 21:48 - 2013-09-18 23:27 - 01730560 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2014-04-13 21:48 - 2013-09-18 23:27 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2014-04-13 21:48 - 2013-09-18 23:25 - 00471552 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-04-13 21:48 - 2013-09-18 23:11 - 01344000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dui70.dll
2014-04-13 21:48 - 2013-09-18 23:10 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2014-04-13 21:48 - 2013-09-18 22:59 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.dll
2014-04-13 21:48 - 2013-09-18 22:55 - 00552448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.dll
2014-04-13 21:48 - 2013-09-18 22:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2014-04-13 21:48 - 2013-09-18 22:32 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2014-04-13 21:48 - 2013-09-17 04:18 - 00467800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2014-04-13 21:48 - 2013-09-17 00:15 - 01225728 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-04-13 21:48 - 2013-09-17 00:00 - 00453632 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2014-04-13 21:48 - 2013-09-16 23:08 - 00738304 _____ (Microsoft Corporation) C:\Windows\system32\msctfuimanager.dll
2014-04-13 21:48 - 2013-09-16 22:28 - 00695808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctfuimanager.dll
2014-04-13 21:48 - 2013-09-14 09:06 - 00175960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\VerifierExt.sys
2014-04-13 21:48 - 2013-09-14 09:06 - 00066904 _____ (Microsoft Corporation) C:\Windows\system32\PSHED.DLL
2014-04-13 21:48 - 2013-09-13 04:52 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\SensorsClassExtension.dll
2014-04-13 21:48 - 2013-09-13 03:54 - 00426496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
2014-04-13 21:48 - 2013-09-13 03:10 - 00288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
2014-04-13 21:48 - 2013-09-13 02:55 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll
2014-04-13 21:48 - 2013-09-13 02:30 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2014-04-13 21:48 - 2013-09-12 02:37 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2014-04-13 21:48 - 2013-09-11 04:31 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2014-04-13 21:48 - 2013-09-11 04:31 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-04-13 21:48 - 2013-09-11 02:41 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2014-04-13 21:48 - 2013-09-11 02:09 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2014-04-13 21:48 - 2013-09-07 07:44 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\fdprint.dll
2014-04-13 21:48 - 2013-09-07 07:29 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCenter.dll
2014-04-13 21:48 - 2013-09-07 06:45 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\CryptoWinRT.dll
2014-04-13 21:48 - 2013-09-07 06:30 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll
2014-04-13 21:48 - 2013-09-07 06:22 - 00153600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CryptoWinRT.dll
2014-04-13 21:48 - 2013-09-07 06:13 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2014-04-13 21:48 - 2013-09-07 06:07 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\TetheringMgr.dll
2014-04-13 21:48 - 2013-09-05 02:39 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-04-13 21:48 - 2013-09-05 01:42 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\Utilman.exe
2014-04-13 21:48 - 2013-09-04 01:16 - 00358912 _____ (Microsoft Corporation) C:\Windows\system32\vmrdvcore.dll
2014-04-13 21:48 - 2013-09-04 00:47 - 00492032 _____ (Microsoft Corporation) C:\Windows\system32\tpmvsc.dll
2014-04-13 21:48 - 2013-09-04 00:12 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\DscCoreConfProv.dll
2014-04-13 21:48 - 2013-09-03 23:57 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\DscCore.dll
2014-04-13 21:48 - 2013-09-03 23:48 - 00326656 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2014-04-13 21:48 - 2013-09-03 23:35 - 00280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SessEnv.dll
2014-04-13 21:48 - 2013-08-31 09:18 - 00205024 _____ (Microsoft Corporation) C:\Windows\system32\mftranscode.dll
2014-04-13 21:48 - 2013-08-31 07:15 - 00180232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mftranscode.dll
2014-04-13 21:48 - 2013-08-31 07:04 - 00638464 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll
2014-04-13 21:48 - 2013-08-31 05:46 - 00513536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\riched20.dll
2014-04-13 21:48 - 2013-08-30 02:31 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2014-04-13 21:48 - 2013-08-29 04:02 - 00329216 _____ (Microsoft Corporation) C:\Windows\system32\rdpshell.exe
2014-04-13 21:48 - 2013-08-28 02:55 - 00334336 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2014-04-13 21:48 - 2013-08-28 02:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2014-04-13 21:48 - 2013-08-28 02:09 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\rdsdwmdr.dll
2014-04-13 21:48 - 2013-08-27 01:09 - 00970752 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
2014-04-13 21:48 - 2013-08-27 00:24 - 00813568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
2014-04-13 21:47 - 2014-04-13 23:14 - 00000000 ____D () C:\SUPERDelete
2014-04-13 21:47 - 2013-10-03 04:16 - 00294400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
2014-04-13 21:47 - 2013-10-03 04:02 - 00225792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2014-04-13 21:47 - 2013-10-02 06:00 - 01286552 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2014-04-13 21:47 - 2013-10-02 04:47 - 01018960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2014-04-13 21:47 - 2013-09-30 22:42 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2014-04-13 21:47 - 2013-09-30 22:36 - 00977408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2014-04-13 21:47 - 2013-09-26 02:14 - 00528896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2014-04-13 21:47 - 2013-09-24 01:55 - 00284160 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
2014-04-13 21:47 - 2013-09-24 00:59 - 00253952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mcbuilder.exe
2014-04-13 21:47 - 2013-09-21 01:01 - 00200704 _____ (Microsoft Corporation) C:\Windows\system32\ReInfo.dll
2014-04-13 21:47 - 2013-09-21 00:37 - 00101376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-04-13 21:47 - 2013-09-21 00:20 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2014-04-13 21:47 - 2013-09-21 00:09 - 00300544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2014-04-13 21:47 - 2013-09-20 23:38 - 00102400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
2014-04-13 21:47 - 2013-09-19 00:47 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.dll
2014-04-13 21:47 - 2013-09-17 01:58 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-04-13 21:47 - 2013-09-17 00:26 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-04-13 21:47 - 2013-09-16 23:09 - 01160704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2014-04-13 21:47 - 2013-09-14 06:39 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-04-13 21:47 - 2013-09-07 07:00 - 00256000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdprint.dll
2014-04-13 21:47 - 2013-09-07 06:50 - 00482816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DeviceCenter.dll
2014-04-13 21:47 - 2013-09-05 00:40 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Utilman.exe
2014-04-13 21:47 - 2013-08-31 05:00 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\GeofenceMonitorService.dll
2014-04-13 21:47 - 2013-08-31 04:25 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GeofenceMonitorService.dll
2014-04-13 21:46 - 2014-03-06 04:19 - 01287576 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-13 21:46 - 2014-03-06 04:02 - 01109424 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-04-13 21:46 - 2014-03-06 01:17 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-04-13 21:46 - 2014-03-06 01:10 - 01036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-13 21:46 - 2014-03-01 01:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-13 21:46 - 2014-02-28 23:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-13 21:46 - 2014-02-28 23:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-13 21:46 - 2014-02-28 23:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-13 21:46 - 2014-02-28 22:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-13 21:46 - 2014-02-28 22:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-13 21:46 - 2014-02-28 22:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-13 21:46 - 2014-02-28 22:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-13 21:46 - 2014-02-28 22:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-13 21:46 - 2014-02-28 22:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-13 21:46 - 2014-02-28 22:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-13 21:46 - 2014-02-28 21:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-13 21:46 - 2014-02-28 21:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-13 21:46 - 2014-02-28 21:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-13 21:46 - 2014-02-28 21:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-13 21:46 - 2014-02-28 21:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-13 21:46 - 2014-02-28 21:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-13 21:46 - 2014-02-22 07:16 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-04-13 21:46 - 2014-02-22 06:24 - 00124416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-04-13 21:46 - 2014-02-06 06:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-13 21:46 - 2014-02-06 06:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-13 21:46 - 2014-02-06 06:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-13 21:46 - 2014-02-06 06:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-13 21:46 - 2014-02-06 05:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-13 21:46 - 2014-02-06 05:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-13 21:46 - 2014-02-06 05:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-13 21:46 - 2014-02-06 05:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-13 21:46 - 2014-02-06 05:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-13 21:46 - 2014-02-06 05:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-13 21:46 - 2014-02-06 05:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-13 21:46 - 2014-02-06 05:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-13 21:46 - 2014-02-06 05:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-13 21:46 - 2014-02-06 04:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-13 21:46 - 2014-02-06 04:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-13 21:46 - 2014-02-06 04:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-13 21:46 - 2014-02-06 04:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-13 21:46 - 2014-02-06 04:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-13 21:46 - 2014-02-06 04:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-13 21:46 - 2014-02-06 04:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-13 21:46 - 2014-01-31 11:15 - 00311640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-04-13 21:46 - 2014-01-31 11:07 - 00233920 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-04-13 21:46 - 2014-01-31 11:06 - 02133208 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2014-04-13 21:46 - 2014-01-31 08:47 - 02143960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2014-04-13 21:46 - 2014-01-31 04:06 - 00716288 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll
2014-04-13 21:46 - 2014-01-29 03:53 - 00458616 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2014-04-13 21:46 - 2014-01-29 03:53 - 00407024 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2014-04-13 21:46 - 2014-01-29 03:49 - 01928144 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2014-04-13 21:46 - 2014-01-29 03:47 - 02543960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-04-13 21:46 - 2014-01-29 02:44 - 01371824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2014-04-13 21:46 - 2014-01-29 02:44 - 00408480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2014-04-13 21:46 - 2014-01-29 02:44 - 00369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2014-04-13 21:46 - 2014-01-29 01:41 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll
2014-04-13 21:46 - 2014-01-28 19:36 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2014-04-13 21:46 - 2014-01-27 14:07 - 04175360 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2014-04-13 21:46 - 2014-01-27 14:06 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-04-13 21:46 - 2014-01-27 14:04 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
2014-04-13 21:46 - 2014-01-27 13:23 - 02873344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2014-04-13 21:46 - 2014-01-27 13:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-04-13 21:46 - 2014-01-27 13:20 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE
2014-04-13 21:46 - 2014-01-27 13:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-04-13 21:46 - 2014-01-27 12:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-04-13 21:46 - 2014-01-27 12:18 - 01486848 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2014-04-13 21:46 - 2014-01-27 12:00 - 01238016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2014-04-13 21:46 - 2014-01-27 10:58 - 05770752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-04-13 21:46 - 2014-01-27 10:50 - 06640640 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-04-13 21:46 - 2014-01-27 06:45 - 00386722 _____ () C:\Windows\system32\ApnDatabase.xml
2014-04-13 21:46 - 2014-01-17 18:04 - 00764864 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2014-04-13 21:46 - 2014-01-17 16:54 - 00669352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2014-04-13 21:46 - 2014-01-07 00:00 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-04-13 21:46 - 2014-01-06 23:30 - 02071552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-04-13 21:46 - 2013-12-21 09:51 - 06353960 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2014-04-13 21:46 - 2013-12-21 03:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2014-04-13 21:46 - 2013-12-20 05:18 - 01643584 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-04-13 21:46 - 2013-12-20 05:18 - 01507704 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-04-13 21:46 - 2013-12-08 19:27 - 02152448 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-04-13 21:46 - 2013-12-08 19:19 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-04-13 21:46 - 2013-12-08 18:55 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-04-13 21:46 - 2013-12-08 18:54 - 01317376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-04-13 21:46 - 2013-11-27 10:36 - 03395920 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2014-04-13 21:46 - 2013-11-27 06:41 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\WSCollect.exe
2014-04-13 21:46 - 2013-11-27 03:48 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-13 21:46 - 2013-11-27 03:40 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-13 21:46 - 2013-11-27 03:17 - 00695808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-04-13 21:46 - 2013-11-27 03:12 - 00848384 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-04-13 21:46 - 2013-11-22 23:34 - 00393216 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-04-13 21:46 - 2013-11-22 23:13 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-04-13 21:46 - 2013-11-21 01:42 - 04604416 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-04-13 21:46 - 2013-11-21 00:44 - 03936256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-04-13 21:46 - 2013-10-30 19:29 - 00236888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-04-13 21:46 - 2013-10-30 19:29 - 00124760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
2014-04-13 21:46 - 2013-10-30 19:28 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-04-13 21:46 - 2013-10-23 06:01 - 00872840 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-04-13 21:46 - 2013-10-23 03:59 - 00698232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-04-13 21:46 - 2013-10-19 03:53 - 00075360 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-04-13 21:46 - 2013-10-19 02:14 - 00070680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-04-13 21:46 - 2013-10-12 21:48 - 00136536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2014-04-13 21:46 - 2013-10-12 16:48 - 00828416 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2014-04-13 21:46 - 2013-10-12 16:34 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-04-13 21:46 - 2013-10-05 09:21 - 01341288 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-04-13 21:46 - 2013-10-05 03:39 - 01067008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-04-13 21:45 - 2014-03-10 05:35 - 02008408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-13 21:45 - 2014-03-10 05:35 - 00377176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2014-04-13 21:45 - 2014-02-10 22:04 - 04189184 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-04-13 21:45 - 2014-02-10 21:43 - 00488448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-04-13 21:45 - 2014-02-10 21:04 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-04-13 21:45 - 2014-01-07 02:03 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe
2014-04-13 21:45 - 2014-01-07 00:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe
2014-04-13 21:45 - 2014-01-04 15:50 - 01462216 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-04-13 21:45 - 2014-01-04 14:22 - 01202888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-04-13 21:45 - 2014-01-04 09:30 - 13209088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-04-13 21:45 - 2014-01-04 09:23 - 11702272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-04-13 21:45 - 2014-01-04 08:42 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-04-13 21:45 - 2014-01-04 08:40 - 07416832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2014-04-13 21:45 - 2014-01-04 08:36 - 00830976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-04-13 21:45 - 2014-01-04 08:28 - 04961792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2014-04-13 21:45 - 2013-12-20 21:10 - 00009701 _____ () C:\Windows\SysWOW64\connectedsearch-results.searchconnector-ms
2014-04-13 21:45 - 2013-12-20 21:10 - 00009701 _____ () C:\Windows\system32\connectedsearch-results.searchconnector-ms
2014-04-13 21:45 - 2013-12-08 21:57 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-13 21:45 - 2013-12-08 20:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-13 21:45 - 2013-12-08 19:15 - 00787968 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2014-04-13 21:45 - 2013-11-09 01:34 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2014-04-13 21:45 - 2013-11-09 01:34 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll
2014-04-13 21:45 - 2013-11-09 00:52 - 00240128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mdmregistration.dll
2014-04-13 21:45 - 2013-10-16 10:58 - 01943536 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-04-13 21:45 - 2013-10-16 08:54 - 01581968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-04-13 21:45 - 2013-10-15 03:54 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-04-13 21:45 - 2013-10-15 03:03 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-04-13 21:43 - 2014-04-14 00:06 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2552152212-2573470380-3959478730-1001
2014-04-13 21:40 - 2014-04-14 01:39 - 00000000 ____D () C:\Users\Karl\Desktop\RemovalTool
2014-04-13 21:36 - 2014-01-09 03:25 - 02804224 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-04-13 21:36 - 2014-01-09 02:59 - 01020928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-04-13 21:36 - 2014-01-09 02:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll
2014-04-13 21:36 - 2014-01-09 02:49 - 00919040 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-04-13 21:36 - 2014-01-09 02:44 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-04-13 21:36 - 2014-01-09 02:43 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll
2014-04-13 21:36 - 2014-01-09 02:29 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll
2014-04-13 21:36 - 2014-01-09 02:28 - 04217344 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-04-13 21:36 - 2014-01-09 02:28 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2014-04-13 21:36 - 2014-01-09 02:18 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
2014-04-13 21:34 - 2014-04-13 21:34 - 00000000 ____D () C:\Windows\ERUNT
2014-04-13 20:48 - 2014-04-13 20:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Exploit
2014-04-13 20:48 - 2011-06-11 00:58 - 00773968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
2014-04-13 20:48 - 2011-06-11 00:58 - 00421200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
2014-04-13 20:48 - 2011-06-11 00:15 - 00829264 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100.dll
2014-04-13 20:48 - 2011-06-11 00:15 - 00608080 _____ (Microsoft Corporation) C:\Windows\system32\msvcp100.dll
2014-04-13 20:43 - 2014-04-13 23:41 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-13 20:26 - 2014-04-13 20:26 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-04-13 20:26 - 2014-04-13 20:26 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-04-13 20:25 - 2014-04-13 20:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-13 20:25 - 2014-04-13 20:25 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-04-13 20:25 - 2014-04-13 20:25 - 00000000 ____D () C:\Program Files\MSBuild
2014-04-13 20:24 - 2013-08-02 23:48 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2014-04-13 20:24 - 2013-08-02 23:48 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-04-13 20:24 - 2013-08-02 23:48 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-04-13 20:24 - 2013-08-02 23:41 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2014-04-13 20:24 - 2013-08-02 23:41 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-04-13 20:24 - 2013-08-02 23:41 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-04-13 20:20 - 2014-04-13 20:20 - 02157568 _____ (Farbar) C:\Users\Karl\Desktop\FRST64.exe
2014-04-13 20:20 - 2014-04-13 20:20 - 00602112 _____ (OldTimer Tools) C:\Users\Karl\Desktop\OTL.exe
2014-04-13 19:49 - 2014-04-13 19:55 - 239552832 _____ (Kaspersky Lab) C:\Users\Karl\Downloads\kis14.0.0.4651abcdeEN_5791.exe
2014-04-13 19:29 - 2014-01-19 02:38 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-04-13 19:26 - 2014-04-14 01:39 - 00000000 ___RD () C:\Users\Karl\Desktop\SkyDrive
2014-04-06 21:43 - 2014-04-13 19:18 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Mozilla
2014-04-06 21:43 - 2014-04-13 19:18 - 00000000 ____D () C:\Users\Karl\AppData\Local\Mozilla
2014-04-06 21:43 - 2014-04-06 21:43 - 00000000 ____D () C:\ProgramData\Mozilla
2014-04-06 21:43 - 2014-04-06 21:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-06 21:42 - 2014-04-06 21:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-06 20:23 - 2014-04-13 23:56 - 00000538 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 06cff99d-0889-4a8d-9d21-3d247d7b3846.job
2014-04-06 20:23 - 2014-04-13 20:23 - 00000538 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 97428f67-5333-4e96-b808-7f8e18cde318.job
2014-04-06 20:23 - 2014-04-06 20:23 - 00003602 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 06cff99d-0889-4a8d-9d21-3d247d7b3846
2014-04-06 20:23 - 2014-04-06 20:23 - 00003520 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 97428f67-5333-4e96-b808-7f8e18cde318
2014-04-06 20:23 - 2014-04-06 20:23 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\SUPERAntiSpyware.com
2014-04-06 20:23 - 2014-04-06 20:23 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-04-06 20:23 - 2014-04-06 20:23 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-04-06 20:23 - 2014-04-06 20:23 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-04-06 18:59 - 2014-04-06 20:21 - 00005054 __RSH () C:\ProgramData\ntuser.pol
2014-04-06 18:53 - 2014-04-06 18:53 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-06 18:49 - 2014-04-06 18:49 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-04-06 18:49 - 2014-04-06 18:49 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-06 18:48 - 2014-04-06 18:48 - 00000000 ____D () C:\Program Files\Speccy
2014-04-06 18:46 - 2014-04-06 18:46 - 00060601 _____ () C:\Windows\SysWOW64\CCCInstall_201404061846261068.log
2014-04-06 18:46 - 2014-04-06 18:46 - 00000000 ____D () C:\ProgramData\AMD
2014-04-06 18:46 - 2014-04-06 18:46 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-04-06 18:46 - 2014-04-06 18:46 - 00000000 ____D () C:\Program Files (x86)\Advanced Micro Devices, Inc
2014-04-06 18:45 - 2014-04-13 22:00 - 00000000 ____D () C:\AMD
2014-04-06 18:45 - 2014-04-06 18:46 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 ____D () C:\ProgramData\Package Cache
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 ____D () C:\Program Files\AMD
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 _____ () C:\Windows\ativpsrm.bin
2014-04-06 17:57 - 2014-04-06 17:57 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Macromedia
2014-04-06 17:27 - 2014-04-14 01:12 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-06 17:24 - 2014-04-14 00:01 - 00000000 ___RD () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-06 17:24 - 2014-04-14 00:01 - 00000000 ___RD () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-06 17:24 - 2014-04-06 17:24 - 00001446 _____ () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-06 17:24 - 2014-04-06 17:24 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Adobe
2014-04-06 17:24 - 2014-04-06 17:24 - 00000000 ____D () C:\Users\Karl\AppData\Local\VirtualStore
2014-04-06 17:24 - 2013-08-22 00:17 - 02407936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2014-04-06 17:23 - 2014-04-14 00:48 - 00000000 ____D () C:\Users\Karl
2014-04-06 17:23 - 2014-04-14 00:21 - 02077137 _____ () C:\Windows\WindowsUpdate.log
2014-04-06 17:23 - 2014-04-14 00:03 - 00000000 ____D () C:\Users\Karl\AppData\Local\Packages
2014-04-06 17:23 - 2014-04-06 17:23 - 00000020 ___SH () C:\Users\Karl\ntuser.ini
2014-04-06 17:23 - 2014-04-06 17:23 - 00000000 ____D () C:\Windows\CSC
2014-04-06 17:23 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-04-06 17:23 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-04-06 17:23 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-04-06 17:23 - 2013-08-22 10:36 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-04-06 16:10 - 2014-04-06 16:10 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-04-06 16:09 - 2014-04-13 23:55 - 00020824 _____ () C:\Windows\PFRO.log
2014-04-06 16:09 - 2014-04-06 17:24 - 00000000 ____D () C:\Windows\Panther
2014-04-03 23:17 - 2014-04-06 09:17 - 00000000 ___SD () C:\Recovery

==================== One Month Modified Files and Folders =======

2014-04-14 01:40 - 2014-04-14 01:40 - 00026040 _____ () C:\Users\Karl\Desktop\FRST.txt
2014-04-14 01:40 - 2014-04-14 01:40 - 00000000 ____D () C:\FRST
2014-04-14 01:39 - 2014-04-13 21:40 - 00000000 ____D () C:\Users\Karl\Desktop\RemovalTool
2014-04-14 01:39 - 2014-04-13 19:26 - 00000000 ___RD () C:\Users\Karl\Desktop\SkyDrive
2014-04-14 01:17 - 2014-04-14 01:17 - 00000978 _____ () C:\Users\Karl\Desktop\RKreport[0]_H_04142014_011711.txt
2014-04-14 01:12 - 2014-04-06 17:27 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-14 01:11 - 2013-08-22 09:46 - 00010531 _____ () C:\Windows\setupact.log
2014-04-14 01:00 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sru
2014-04-14 00:48 - 2014-04-14 00:48 - 00000000 _____ () C:\Users\Karl\defogger_reenable
2014-04-14 00:48 - 2014-04-06 17:23 - 00000000 ____D () C:\Users\Karl
2014-04-14 00:21 - 2014-04-06 17:23 - 02077137 _____ () C:\Windows\WindowsUpdate.log
2014-04-14 00:17 - 2014-04-14 00:15 - 107394336 _____ (Oracle Corporation) C:\Users\Karl\Desktop\VirtualBox-4.3.10-93012-Win.exe
2014-04-14 00:06 - 2014-04-13 21:43 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2552152212-2573470380-3959478730-1001
2014-04-14 00:03 - 2014-04-06 17:23 - 00000000 ____D () C:\Users\Karl\AppData\Local\Packages
2014-04-14 00:01 - 2014-04-14 00:01 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\ATI
2014-04-14 00:01 - 2014-04-14 00:01 - 00000000 ____D () C:\Users\Karl\AppData\Local\ATI
2014-04-14 00:01 - 2014-04-14 00:01 - 00000000 ____D () C:\Users\Karl\AppData\Local\AMD
2014-04-14 00:01 - 2014-04-14 00:01 - 00000000 ____D () C:\ProgramData\ATI
2014-04-14 00:01 - 2014-04-06 17:24 - 00000000 ___RD () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-14 00:01 - 2014-04-06 17:24 - 00000000 ___RD () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-13 23:56 - 2014-04-06 20:23 - 00000538 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 06cff99d-0889-4a8d-9d21-3d247d7b3846.job
2014-04-13 23:56 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-13 23:55 - 2014-04-06 16:09 - 00020824 _____ () C:\Windows\PFRO.log
2014-04-13 23:55 - 2013-08-22 09:44 - 00335784 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-13 23:52 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-04-13 23:49 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-04-13 23:49 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-04-13 23:49 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-04-13 23:49 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\FileManager
2014-04-13 23:49 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\Camera
2014-04-13 23:49 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-04-13 23:49 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-04-13 23:49 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\system32\Dism
2014-04-13 23:48 - 2013-08-22 10:36 - 00000000 ___RD () C:\Windows\ToastData
2014-04-13 23:48 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\WinStore
2014-04-13 23:48 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\migwiz
2014-04-13 23:48 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-13 23:48 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-04-13 23:48 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-04-13 23:47 - 2013-08-22 10:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2014-04-13 23:47 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\system32\oobe
2014-04-13 23:41 - 2014-04-13 20:43 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-13 23:17 - 2014-04-13 23:17 - 00001133 _____ () C:\Users\Public\Desktop\herdProtect.lnk
2014-04-13 23:17 - 2014-04-13 23:17 - 00000000 ____D () C:\Program Files\Reason
2014-04-13 23:14 - 2014-04-13 21:47 - 00000000 ____D () C:\SUPERDelete
2014-04-13 23:05 - 2014-04-13 23:04 - 04745728 _____ (AVAST Software) C:\Users\Karl\Desktop\MBR.com.exe
2014-04-13 23:01 - 2014-04-13 23:01 - 00003233 _____ () C:\Users\Karl\Desktop\Sophos Virus Removal Tool.lnk
2014-04-13 23:01 - 2014-04-13 22:51 - 00000000 ____D () C:\ProgramData\Sophos
2014-04-13 23:01 - 2014-04-13 22:44 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sophos
2014-04-13 23:00 - 2014-04-13 23:00 - 00000000 ____D () C:\Users\Karl\Pavark
2014-04-13 23:00 - 2014-04-13 23:00 - 00000000 ____D () C:\Program Files (x86)\Sophos
2014-04-13 22:44 - 2014-04-13 22:44 - 00000052 _____ () C:\Windows\SysWOW64\Console.log
2014-04-13 22:44 - 2014-04-13 22:44 - 00000000 ____D () C:\Sophos
2014-04-13 22:44 - 2014-04-13 22:44 - 00000000 ____D () C:\scss_10
2014-04-13 22:23 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-04-13 22:13 - 2014-04-13 22:13 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-13 22:00 - 2014-04-13 22:00 - 01189560 _____ (AMD Inc.) C:\Users\Karl\Downloads\catalyst_mobility_64-bit_util.exe
2014-04-13 22:00 - 2014-04-06 18:45 - 00000000 ____D () C:\AMD
2014-04-13 21:58 - 2014-04-13 21:58 - 02067320 _____ (AMD) C:\Users\Karl\Downloads\amdcompatibilitychecker.exe
2014-04-13 21:34 - 2014-04-13 21:34 - 00000000 ____D () C:\Windows\ERUNT
2014-04-13 20:48 - 2014-04-13 20:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Exploit
2014-04-13 20:48 - 2014-04-13 20:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-13 20:26 - 2014-04-13 20:26 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-04-13 20:26 - 2014-04-13 20:26 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-04-13 20:25 - 2014-04-13 20:25 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-04-13 20:25 - 2014-04-13 20:25 - 00000000 ____D () C:\Program Files\MSBuild
2014-04-13 20:23 - 2014-04-06 20:23 - 00000538 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 97428f67-5333-4e96-b808-7f8e18cde318.job
2014-04-13 20:20 - 2014-04-13 20:20 - 02157568 _____ (Farbar) C:\Users\Karl\Desktop\FRST64.exe
2014-04-13 20:20 - 2014-04-13 20:20 - 00602112 _____ (OldTimer Tools) C:\Users\Karl\Desktop\OTL.exe
2014-04-13 19:55 - 2014-04-13 19:49 - 239552832 _____ (Kaspersky Lab) C:\Users\Karl\Downloads\kis14.0.0.4651abcdeEN_5791.exe
2014-04-13 19:32 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-04-13 19:18 - 2014-04-06 21:43 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Mozilla
2014-04-13 19:18 - 2014-04-06 21:43 - 00000000 ____D () C:\Users\Karl\AppData\Local\Mozilla
2014-04-06 21:43 - 2014-04-06 21:43 - 00000000 ____D () C:\ProgramData\Mozilla
2014-04-06 21:43 - 2014-04-06 21:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-06 21:43 - 2014-04-06 21:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-06 20:23 - 2014-04-06 20:23 - 00003602 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 06cff99d-0889-4a8d-9d21-3d247d7b3846
2014-04-06 20:23 - 2014-04-06 20:23 - 00003520 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 97428f67-5333-4e96-b808-7f8e18cde318
2014-04-06 20:23 - 2014-04-06 20:23 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\SUPERAntiSpyware.com
2014-04-06 20:23 - 2014-04-06 20:23 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-04-06 20:23 - 2014-04-06 20:23 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-04-06 20:23 - 2014-04-06 20:23 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-04-06 20:21 - 2014-04-06 18:59 - 00005054 __RSH () C:\ProgramData\ntuser.pol
2014-04-06 18:55 - 2013-08-22 10:36 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-06 18:53 - 2014-04-06 18:53 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-06 18:49 - 2014-04-06 18:49 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-04-06 18:49 - 2014-04-06 18:49 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-06 18:48 - 2014-04-06 18:48 - 00000000 ____D () C:\Program Files\Speccy
2014-04-06 18:46 - 2014-04-06 18:46 - 00060601 _____ () C:\Windows\SysWOW64\CCCInstall_201404061846261068.log
2014-04-06 18:46 - 2014-04-06 18:46 - 00000000 ____D () C:\ProgramData\AMD
2014-04-06 18:46 - 2014-04-06 18:46 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-04-06 18:46 - 2014-04-06 18:46 - 00000000 ____D () C:\Program Files (x86)\Advanced Micro Devices, Inc
2014-04-06 18:46 - 2014-04-06 18:45 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 ____D () C:\ProgramData\Package Cache
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 ____D () C:\Program Files\AMD
2014-04-06 18:45 - 2014-04-06 18:45 - 00000000 _____ () C:\Windows\ativpsrm.bin
2014-04-06 17:57 - 2014-04-06 17:57 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Macromedia
2014-04-06 17:32 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\restore
2014-04-06 17:24 - 2014-04-06 17:24 - 00001446 _____ () C:\Users\Karl\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-06 17:24 - 2014-04-06 17:24 - 00000000 ____D () C:\Users\Karl\AppData\Roaming\Adobe
2014-04-06 17:24 - 2014-04-06 17:24 - 00000000 ____D () C:\Users\Karl\AppData\Local\VirtualStore
2014-04-06 17:24 - 2014-04-06 16:09 - 00000000 ____D () C:\Windows\Panther
2014-04-06 17:23 - 2014-04-06 17:23 - 00000020 ___SH () C:\Users\Karl\ntuser.ini
2014-04-06 17:23 - 2014-04-06 17:23 - 00000000 ____D () C:\Windows\CSC
2014-04-06 17:22 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\rescache
2014-04-06 16:11 - 2013-08-22 10:37 - 00001720 _____ () C:\Windows\DtcInstall.log
2014-04-06 16:11 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\Recovery
2014-04-06 16:10 - 2014-04-06 16:10 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-04-06 09:17 - 2014-04-03 23:17 - 00000000 ___SD () C:\Recovery
2014-04-06 09:17 - 2013-08-22 10:36 - 00262144 _____ () C:\Windows\system32\config\BCD-Template
2014-03-31 16:23 - 2013-08-22 10:38 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-31 16:23 - 2013-08-22 10:38 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-31 03:51 - 2014-04-13 22:13 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\Karl\AppData\Local\Temp\ntdll_dump.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2014-04-13 21:46] - [2014-01-31 11:15] - 0311640 ____A (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02


==================== BCD ================================

Windows Boot Manager
--------------------
identifier              {bootmgr}
device                  partition=\Device\HarddiskVolume1
description             Windows Boot Manager
locale                  en-US
inherit                 {globalsettings}
integrityservices       Enable
default                 {current}
resumeobject            {395335f7-bd96-11e3-8f32-be46429c8cde}
displayorder            {current}
toolsdisplayorder       {memdiag}
timeout                 30

Windows Boot Loader
-------------------
identifier              {043b7ab7-bdd0-11e3-824c-e1ee662508cc}
device                  ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{043b7ab8-bdd0-11e3-824c-e1ee662508cc}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment
locale                  en-US
inherit                 {bootloadersettings}
displaymessage          Recovery
displaymessageoverride  Recovery
osdevice                ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{043b7ab8-bdd0-11e3-824c-e1ee662508cc}
systemroot              \windows
nx                      OptIn
bootmenupolicy          Standard
winpe                   Yes

Windows Boot Loader
-------------------
identifier              {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description             Windows 8.1
locale                  en-US
inherit                 {bootloadersettings}
recoverysequence        {043b7ab7-bdd0-11e3-824c-e1ee662508cc}
integrityservices       Enable
recoveryenabled         Yes
allowedinmemorysettings 0x15000075
osdevice                partition=C:
systemroot              \Windows
resumeobject            {395335f7-bd96-11e3-8f32-be46429c8cde}
nx                      OptOut
bootmenupolicy          Standard

Resume from Hibernate
---------------------
identifier              {395335f7-bd96-11e3-8f32-be46429c8cde}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description             Windows Resume Application
locale                  en-US
inherit                 {resumeloadersettings}
recoverysequence        {043b7ab7-bdd0-11e3-824c-e1ee662508cc}
recoveryenabled         Yes
allowedinmemorysettings 0x15000075
filedevice              partition=C:
filepath                \hiberfil.sys
bootmenupolicy          Standard
debugoptionenabled      No

Windows Memory Tester
---------------------
identifier              {memdiag}
device                  partition=\Device\HarddiskVolume1
path                    \boot\memtest.exe
description             Windows Memory Diagnostic
locale                  en-US
inherit                 {globalsettings}
badmemoryaccess         Yes

EMS Settings
------------
identifier              {emssettings}
bootems                 No

Debugger Settings
-----------------
identifier              {dbgsettings}
debugtype               Serial
debugport               1
baudrate                115200

RAM Defects
-----------
identifier              {badmemory}

Global Settings
---------------
identifier              {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}

Boot Loader Settings
--------------------
identifier              {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}

Hypervisor Settings
-------------------
identifier              {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200

Resume Loader Settings
----------------------
identifier              {resumeloadersettings}
inherit                 {globalsettings}

Device options
--------------
identifier              {043b7ab8-bdd0-11e3-824c-e1ee662508cc}
description             Windows Recovery
ramdisksdidevice        partition=\Device\HarddiskVolume1
ramdisksdipath          \Recovery\WindowsRE\boot.sdi



LastRegBack: 2014-04-06 16:09

==================== End Of Log ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2014 01
Ran by Karl at 2014-04-14 01:41:25
Running from C:\Users\Karl\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
AMD Fuel (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center (HKLM-x32\...\{8B1A559A-FB9D-42F5-A8A7-2F132CF28414}) (Version: 1.00.0000 - )
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
herdProtect Anti-Malware Scanner (HKLM-x32\...\herdProtectScan) (Version: 1.0 - Reason Company Software Inc.)
Malwarebytes Anti-Exploit version 0.10.0.1000 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 0.10.0.1000 - Malwarebytes)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Mozilla Firefox 28.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 en-US)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
Revo Uninstaller 1.85 (HKLM-x32\...\Revo Uninstaller) (Version: 1.85 - VS Revo Group)
Sophos Computer Security Scan (HKLM-x32\...\{EDE875B0-6566-4E93-B955-C63AE5F4737C}) (Version: 1.1.0.406 - Sophos plc)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.4 - Sophos Limited)
Speccy (HKLM\...\Speccy) (Version: 1.25 - Piriform)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.7.1018 - SUPERAntiSpyware.com)

==================== Restore Points  =========================

06-04-2014 22:32:26 Windows Modules Installer
14-04-2014 01:22:51 Windows Modules Installer

==================== Hosts content: ==========================

2013-08-22 08:25 - 2014-04-14 01:17 - 00000741 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1    localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {180B1717-EFF8-41BD-9A41-CABDA1F896B9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-03-31] (Microsoft Corporation)
Task: {194B1B14-8891-47CF-95C1-3C0DF27C2638} - System32\Tasks\SUPERAntiSpyware Scheduled Task 06cff99d-0889-4a8d-9d21-3d247d7b3846 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {74876DA7-713E-4ED2-B581-BC0D544D2540} - System32\Tasks\SUPERAntiSpyware Scheduled Task 97428f67-5333-4e96-b808-7f8e18cde318 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {EA01F1E6-2D3C-4391-8217-61F2F05469D4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 06cff99d-0889-4a8d-9d21-3d247d7b3846.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 97428f67-5333-4e96-b808-7f8e18cde318.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

==================== Loaded Modules (whitelisted) =============

2013-12-06 16:06 - 2013-12-06 16:06 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2014-04-13 19:27 - 2014-04-13 19:28 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\ErrorReporting.dll
2013-12-06 16:06 - 2013-12-06 16:06 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-04-06 21:42 - 2014-03-15 03:40 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Karl\Desktop\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WLMS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WLMS => ""="Service"

==================== Disabled items from MSCONFIG ==============

MSCONFIG\Services: AMD External Events Utility => 2
MSCONFIG\Services: MozillaMaintenance => 3

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/14/2014 00:48:59 AM) (Source: Application Error) (User: )
Description: Faulting application name: socool.com, version: 1.71.0.0, time stamp: 0x44e255aa
Faulting module name: socool.com, version: 1.71.0.0, time stamp: 0x44e255aa
Exception code: 0xc0000005
Fault offset: 0x000040cd
Faulting process id: 0x8e8
Faulting application start time: 0xsocool.com0
Faulting application path: socool.com1
Faulting module path: socool.com2
Report Id: socool.com3
Faulting package full name: socool.com4
Faulting package-relative application ID: socool.com5

Error: (04/13/2014 11:44:52 PM) (Source: Application Error) (User: )
Description: Faulting application name: explorer.exe, version: 6.3.9600.16384, time stamp: 0x5215d379
Faulting module name: ntdll.dll, version: 6.3.9600.16384, time stamp: 0x5215f938
Exception code: 0xc0000005
Fault offset: 0x0000000000032739
Faulting process id: 0xc30
Faulting application start time: 0xexplorer.exe0
Faulting application path: explorer.exe1
Faulting module path: explorer.exe2
Report Id: explorer.exe3
Faulting package full name: explorer.exe4
Faulting package-relative application ID: explorer.exe5

Error: (04/13/2014 11:23:41 PM) (Source: Application Error) (User: )
Description: Faulting application name: herdProtectScan.exe, version: 1.0.3.1, time stamp: 0x534837fd
Faulting module name: LSASRV.dll, version: 6.3.9600.16384, time stamp: 0x5215e180
Exception code: 0xc0000005
Fault offset: 0x0000000000058162
Faulting process id: 0x6d0
Faulting application start time: 0xherdProtectScan.exe0
Faulting application path: herdProtectScan.exe1
Faulting module path: herdProtectScan.exe2
Report Id: herdProtectScan.exe3
Faulting package full name: herdProtectScan.exe4
Faulting package-relative application ID: herdProtectScan.exe5

Error: (04/13/2014 11:17:38 PM) (Source: Application Error) (User: )
Description: Faulting application name: herdProtectScan.exe, version: 1.0.3.1, time stamp: 0x534837fd
Faulting module name: LSASRV.dll, version: 6.3.9600.16384, time stamp: 0x5215e180
Exception code: 0xc0000005
Fault offset: 0x0000000000058162
Faulting process id: 0x6d0
Faulting application start time: 0xherdProtectScan.exe0
Faulting application path: herdProtectScan.exe1
Faulting module path: herdProtectScan.exe2
Report Id: herdProtectScan.exe3
Faulting package full name: herdProtectScan.exe4
Faulting package-relative application ID: herdProtectScan.exe5

Error: (04/13/2014 10:47:33 PM) (Source: Application Error) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.16384, time stamp: 0x5215d145
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x00007ffaa6d20000
Faulting process id: 0x1374
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
Faulting package full name: iexplore.exe4
Faulting package-relative application ID: iexplore.exe5


System errors:
=============
Error: (04/14/2014 01:41:25 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:41:23 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:40:59 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:40:59 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:40:59 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:40:59 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:40:11 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:40:11 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:40:11 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297

Error: (04/14/2014 01:40:11 AM) (Source: Service Control Manager) (User: )
Description: The Diagnostic Service Host service failed to start due to the following error:
%%1297


Microsoft Office Sessions:
=========================
Error: (04/14/2014 00:48:59 AM) (Source: Application Error)(User: )
Description: socool.com1.71.0.044e255aasocool.com1.71.0.044e255aac0000005000040cd8e801cf57a537b37559C:\Users\Karl\Desktop\socool.comC:\Users\Karl\Desktop\socool.com78cd634f-c398-11e3-824f-60a44c03c621

Error: (04/13/2014 11:44:52 PM) (Source: Application Error)(User: )
Description: explorer.exe6.3.9600.163845215d379ntdll.dll6.3.9600.163845215f938c00000050000000000032739c3001cf578a96129140C:\Windows\explorer.exeC:\Windows\SYSTEM32\ntdll.dll844315eb-c38f-11e3-824e-60a44c03c621

Error: (04/13/2014 11:23:41 PM) (Source: Application Error)(User: )
Description: herdProtectScan.exe1.0.3.1534837fdLSASRV.dll6.3.9600.163845215e180c000000500000000000581626d001cf579867483886C:\Program Files\Reason\herdProtect\Scanner\herdProtectScan.exeC:\Windows\SYSTEM32\LSASRV.dll8e7d28c8-c38c-11e3-824e-60a44c03c621

Error: (04/13/2014 11:17:38 PM) (Source: Application Error)(User: )
Description: herdProtectScan.exe1.0.3.1534837fdLSASRV.dll6.3.9600.163845215e180c000000500000000000581626d001cf579867483886C:\Program Files\Reason\herdProtect\Scanner\herdProtectScan.exeC:\Windows\SYSTEM32\LSASRV.dllb62dfb21-c38b-11e3-824e-60a44c03c621

Error: (04/13/2014 10:47:33 PM) (Source: Application Error)(User: )
Description: iexplore.exe11.0.9600.163845215d145unknown0.0.0.000000000c000000500007ffaa6d20000137401cf579442f05128C:\Program Files\Internet Explorer\iexplore.exeunknown82290fcc-c387-11e3-824e-60a44c03c621


==================== Memory info ===========================

Percentage of memory in use: 22%
Total physical RAM: 7636.27 MB
Available physical RAM: 5896.42 MB
Total Pagefile: 9492.27 MB
Available Pagefile: 7706.86 MB
Total Virtual: 131072 MB
Available Virtual: 131071.78 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:233 GB) (Free:209.14 GB) NTFS
Drive e: () (Fixed) (Total:212.07 GB) (Free:211.95 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 06F27AC6)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=212 GB) - (Type=OF Extended)

==================== End Of Log ============================


  • 0

#6
Kman4488

Kman4488

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts

# AdwCleaner v3.023 - Report created 14/04/2014 at 02:05:08
# Updated 01/04/2014 by Xplode
# Operating System : Windows 8.1 Enterprise Evaluation  (64 bits)
# Username : Karl - COMPTONCOMPUTE
# Running from : C:\Users\Karl\Desktop\ADWCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk

***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Mozilla Firefox v28.0 (en-US)

[ File : C:\Users\Karl\AppData\Roaming\Mozilla\Firefox\Profiles\8tyseozw.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [849 octets] - [14/04/2014 02:03:44]
AdwCleaner[R1].txt - [770 octets] - [14/04/2014 02:05:08]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [829 octets] ##########
 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 Enterprise Evaluation x64
Ran by Karl on Mon 04/14/2014 at  2:07:18.28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted: [Folder] C:\Users\Karl\AppData\Roaming\mozilla\firefox\profiles\8tyseozw.default\extensions\staged



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 04/14/2014 at  2:11:53.16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


  • 0

#7
Kman4488

Kman4488

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
Anyine,
  • 0

#8
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,007 posts
  • MVP

I guess the notification system is still unreliable.  Sorry.

 

Nothing in the logs indicates malware.  Something called socool.com and herdProtect Anti-Malware Scanner are not working.  May not really work on Win 8.  I would uninstall herdProtect Anti-Malware Scanner and not try to use socool.com which I believe is on your desktop.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP