It feels the same but also, when running adWcleaner I thought for sure this would be deleted but it still remains,
http://imgur.com/O2TV4vs
Also here's the FRST log
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-08-2014
Ran by USER (administrator) on USER-PC on 05-08-2014 13:11:00
Running from C:\Users\USER\Desktop\frst
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7560296 2011-12-12] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1436736 2011-06-15] (Microsoft Corporation)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840768 2013-05-10] (Adobe Systems Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3816784 2014-07-21] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3385489291-3797028483-2866025970-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7E30C97B03A0CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{B89CE93C-F058-4423-AD4F-B552A5C6E64A}: [NameServer]8.8.8.8,8.8.4.4
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF Plugin-x32: @gomtv.com/gomtvx-plugin -> C:\Program Files (x86)\Common Files\GRETECH\npgomtvx_nie.dll (Gretech Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nexon.net/NxGame -> C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012-09-29]
Chrome:
=======
CHR HomePage:
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.4.600\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (gomtvx NIE Module) - C:\Program Files (x86)\Common Files\GRETECH\npgomtvx_nie.dll (Gretech Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll No File
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll No File
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-05]
CHR Extension: (Inaba Himeko Theme) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\flooilpmbaknnlpnonlaccahmplanfln [2014-04-26]
CHR Extension: (AdBlock) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-08-04]
CHR Extension: (Google Wallet) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 EvoSvc; C:\Program Files\Echobit\Evolve\EvoSvc.exe [1579936 2014-07-18] (Echobit LLC)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2014-08-03] (SurfRight B.V.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [161560 2012-01-20] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-07-16] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [12784 2011-04-27] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [288272 2011-04-27] (Microsoft Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [614680 2013-09-12] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [21656 2014-07-18] (Echobit, LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [189440 2011-04-18] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [84864 2011-04-27] (Microsoft Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S2 {B154377D-700F-42cc-9474-23858FBDF4BD}; \??\C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-05 12:42 - 2014-08-05 12:42 - 01361309 _____ () C:\Users\USER\Downloads\AdwCleaner.exe
2014-08-05 12:38 - 2014-08-05 13:11 - 00000000 ____D () C:\Users\USER\Desktop\frst
2014-08-05 12:37 - 2014-08-05 12:39 - 00000855 _____ () C:\Users\USER\Documents\fixlist.txt
2014-08-04 14:05 - 2014-08-04 14:05 - 02807744 _____ (tuneuppro.com ) C:\Users\USER\Downloads\tupp_04080905180365495.exe
2014-08-04 13:19 - 2014-08-04 13:20 - 00038024 _____ () C:\Users\USER\Downloads\Addition.txt
2014-08-04 13:18 - 2014-08-05 13:11 - 00000000 ____D () C:\FRST
2014-08-04 13:18 - 2014-08-04 13:18 - 00415232 _____ (Farbar) C:\Users\USER\Downloads\FSS.exe
2014-08-04 13:17 - 2014-08-04 13:17 - 01084928 _____ (Farbar) C:\Users\USER\Downloads\FRST.exe
2014-08-04 13:16 - 2014-08-04 13:16 - 00000000 ____D () C:\MATS
2014-08-04 13:14 - 2014-08-04 13:15 - 00347816 _____ (Microsoft Corporation) C:\Users\USER\Downloads\MicrosoftFixit.ProgramInstallUninstall.MATSKB.Run.exe
2014-08-03 23:50 - 2014-08-05 12:56 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-03 23:50 - 2014-08-03 23:50 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-03 23:50 - 2014-08-03 23:50 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-03 23:50 - 2014-08-03 23:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-03 23:49 - 2014-08-05 12:44 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-03 23:49 - 2014-08-03 23:49 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-03 23:31 - 2014-08-03 23:31 - 00000000 ___SD () C:\32788R22FWJFW
2014-08-03 23:28 - 2014-08-03 23:28 - 00035524 _____ () C:\ComboFix.txt
2014-08-03 23:26 - 2014-08-05 12:44 - 00000504 _____ () C:\Windows\setupact.log
2014-08-03 23:26 - 2014-08-05 12:43 - 00002184 _____ () C:\Windows\PFRO.log
2014-08-03 23:26 - 2014-08-03 23:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-03 23:20 - 2014-08-03 23:31 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 23:18 - 2014-08-03 23:19 - 05566616 _____ (Swearware) C:\Users\USER\Downloads\ComboFix.exe
2014-08-03 22:16 - 2014-08-03 22:16 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-08-03 22:15 - 2014-08-03 22:16 - 02347384 _____ (ESET) C:\Users\USER\Downloads\esetsmartinstaller_enu.exe
2014-08-03 21:44 - 2014-08-03 21:44 - 00000000 ____D () C:\Users\USER\AppData\Local\Chromium
2014-08-03 21:31 - 2014-08-03 21:39 - 00007605 _____ () C:\Users\USER\AppData\Local\Resmon.ResmonCfg
2014-08-03 21:21 - 2014-08-03 21:21 - 01361309 _____ () C:\Users\USER\Downloads\adwcleaner_3.302.exe
2014-08-03 20:04 - 2014-08-03 20:04 - 00000000 ____D () C:\Users\USER\AppData\Roaming\SYSTEMAX Software Development
2014-08-03 20:04 - 2014-08-03 20:04 - 00000000 ____D () C:\ProgramData\SYSTEMAX Software Development
2014-08-03 20:03 - 2014-08-03 20:03 - 00000000 ____D () C:\Users\USER\Desktop\PaintTool SAI English Pack(2)
2014-08-03 20:01 - 2014-08-03 20:01 - 00000000 __SHD () C:\Users\USER\AppData\Local\EmieUserList
2014-08-03 20:01 - 2014-08-03 20:01 - 00000000 __SHD () C:\Users\USER\AppData\Local\EmieSiteList
2014-08-03 19:25 - 2014-08-03 19:25 - 00000702 _____ () C:\Users\USER\Desktop\JRT.txt
2014-08-03 19:19 - 2014-08-03 19:19 - 01016261 _____ (Thisisu) C:\Users\USER\Downloads\JRT.exe
2014-08-03 19:19 - 2014-08-03 19:19 - 00000000 ____D () C:\Windows\ERUNT
2014-08-03 19:09 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-03 19:08 - 2014-08-05 13:10 - 00000000 ____D () C:\AdwCleaner
2014-08-03 19:08 - 2014-08-03 19:08 - 01361309 _____ () C:\Users\USER\Desktop\AdwCleaner.exe
2014-08-03 19:06 - 2014-08-03 19:07 - 11526415 _____ () C:\Users\USER\Downloads\PaintTool SAI English Pack(2).rar
2014-08-03 18:34 - 2014-08-03 18:34 - 00001897 _____ () C:\Users\Public\Desktop\HitmanPro.lnk
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\Program Files\HitmanPro
2014-08-03 18:33 - 2014-08-03 18:36 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-08-03 18:32 - 2014-08-03 18:33 - 11188736 _____ (SurfRight B.V.) C:\Users\USER\Downloads\HitmanPro_x64.exe
2014-08-03 18:10 - 2014-08-03 18:17 - 00000000 ____D () C:\Users\USER\AppData\Local\20464
2014-08-03 18:09 - 2014-08-03 18:36 - 00002294 _____ () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-03 15:07 - 2014-08-03 15:07 - 00000874 _____ () C:\Windows\SysWOW64\msexcr.ini
2014-08-02 18:00 - 2014-08-02 18:00 - 20163174 _____ () C:\Users\USER\Downloads\Ice.zip
2014-07-22 13:54 - 2014-07-22 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-07-22 13:54 - 2014-07-22 13:54 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-07-18 16:08 - 2014-07-18 16:08 - 00021656 _____ (Echobit, LLC) C:\Windows\system32\Drivers\evolve.sys
2014-07-18 16:08 - 2014-07-18 16:08 - 00002023 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evolve.lnk
2014-07-18 16:08 - 2014-07-18 16:08 - 00002011 _____ () C:\Users\Public\Desktop\Evolve.lnk
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\Users\USER\AppData\Local\Echobit
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\ProgramData\Echobit
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\Program Files\Echobit
2014-07-18 16:07 - 2014-07-18 16:08 - 03258328 _____ (Echobit LLC) C:\Users\USER\Downloads\EvolveSetup.exe
2014-07-18 16:03 - 2014-07-18 16:03 - 00000222 _____ () C:\Users\USER\Desktop\Unturned.url
2014-07-17 22:23 - 2014-07-17 22:23 - 174178700 _____ () C:\Users\USER\Downloads\ZTST.zip
2014-07-16 13:08 - 2014-07-16 13:08 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-15 20:35 - 2014-07-15 20:35 - 00001111 _____ () C:\Users\USER\Desktop\Katawa Shoujo.lnk
2014-07-15 20:35 - 2014-07-15 20:35 - 00000000 ____D () C:\Users\USER\AppData\Roaming\RenPy
2014-07-15 20:34 - 2014-07-15 20:35 - 00000000 ____D () C:\Program Files (x86)\Katawa Shoujo
2014-07-15 20:32 - 2014-07-15 20:34 - 444251517 _____ () C:\Users\USER\Downloads\[4ls]_katawa_shoujo_1.1-[windows][8AACDD32].exe
2014-07-15 03:41 - 2014-08-04 00:11 - 00000000 ____D () C:\Users\USER\Desktop\cowboy bebop 9
2014-07-13 01:09 - 2014-08-05 03:51 - 00001237 _____ () C:\Users\USER\Desktop\manga.txt
2014-07-11 16:32 - 2014-07-11 16:32 - 00000219 _____ () C:\Users\USER\Desktop\Counter-Strike Global Offensive.url
2014-07-11 03:39 - 2014-07-11 03:39 - 27060196 _____ () C:\Users\USER\Downloads\No Game No Life.zip
2014-07-11 03:37 - 2014-07-11 03:37 - 26507407 _____ () C:\Users\USER\Downloads\Nisekoi.zip
2014-07-08 13:22 - 2014-06-20 13:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-08 13:22 - 2014-06-20 12:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-08 13:22 - 2014-06-18 18:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-08 13:22 - 2014-06-18 18:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-08 13:22 - 2014-06-18 18:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-08 13:22 - 2014-06-18 17:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-08 13:22 - 2014-06-18 17:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-08 13:22 - 2014-06-18 17:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-08 13:22 - 2014-06-18 17:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-08 13:22 - 2014-06-18 17:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-08 13:22 - 2014-06-18 17:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-08 13:22 - 2014-06-18 17:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-08 13:22 - 2014-06-18 17:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-08 13:22 - 2014-06-18 17:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-08 13:22 - 2014-06-18 17:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-08 13:22 - 2014-06-18 17:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-08 13:22 - 2014-06-18 17:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-08 13:22 - 2014-06-18 17:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-08 13:22 - 2014-06-18 17:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-08 13:22 - 2014-06-18 16:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-08 13:22 - 2014-06-18 16:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-08 13:22 - 2014-06-18 16:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-08 13:22 - 2014-06-18 16:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-08 13:22 - 2014-06-18 16:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-08 13:22 - 2014-06-18 16:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-08 13:22 - 2014-06-18 16:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-08 13:22 - 2014-06-18 16:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-08 13:22 - 2014-06-18 16:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-08 13:22 - 2014-06-18 16:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-08 13:22 - 2014-06-18 16:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-08 13:22 - 2014-06-18 16:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-08 13:22 - 2014-06-18 16:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-08 13:22 - 2014-06-18 16:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-08 13:22 - 2014-06-18 16:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-08 13:22 - 2014-06-18 16:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-08 13:22 - 2014-06-18 16:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-08 13:22 - 2014-06-18 16:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-08 13:22 - 2014-06-18 16:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-08 13:22 - 2014-06-18 16:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-08 13:22 - 2014-06-18 16:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-08 13:22 - 2014-06-18 16:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-08 13:22 - 2014-06-18 16:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-08 13:22 - 2014-06-18 15:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-08 13:22 - 2014-06-18 15:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-08 13:22 - 2014-06-18 15:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-08 13:22 - 2014-06-18 15:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-08 13:22 - 2014-06-18 15:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-08 13:22 - 2014-06-18 15:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-08 13:22 - 2014-06-18 15:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-08 13:22 - 2014-06-18 15:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-08 13:22 - 2014-06-18 15:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-08 13:22 - 2014-06-18 15:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-08 13:22 - 2014-06-18 15:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-08 13:22 - 2014-06-18 15:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-08 13:22 - 2014-06-18 15:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-08 13:22 - 2014-06-18 15:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-08 13:22 - 2014-06-17 19:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-08 13:22 - 2014-06-17 18:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-08 13:22 - 2014-06-17 18:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-08 13:22 - 2014-06-06 03:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-08 13:22 - 2014-06-06 02:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-08 13:22 - 2014-05-29 23:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-08 13:21 - 2014-06-05 07:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-08 13:21 - 2014-06-05 07:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-08 13:21 - 2014-06-05 07:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-05 13:11 - 2014-08-05 12:38 - 00000000 ____D () C:\Users\USER\Desktop\frst
2014-08-05 13:11 - 2014-08-04 13:18 - 00000000 ____D () C:\FRST
2014-08-05 13:10 - 2014-08-03 19:08 - 00000000 ____D () C:\AdwCleaner
2014-08-05 12:56 - 2014-08-03 23:50 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-05 12:52 - 2012-09-29 18:07 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-05 12:49 - 2009-07-13 21:45 - 00028128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-05 12:49 - 2009-07-13 21:45 - 00028128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-05 12:48 - 2009-07-13 22:13 - 00006742 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-05 12:47 - 2013-11-28 11:02 - 01857342 _____ () C:\Windows\WindowsUpdate.log
2014-08-05 12:45 - 2013-11-16 23:24 - 00000000 ____D () C:\Users\USER\AppData\Local\LogMeIn Hamachi
2014-08-05 12:44 - 2014-08-03 23:49 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-05 12:44 - 2014-08-03 23:26 - 00000504 _____ () C:\Windows\setupact.log
2014-08-05 12:44 - 2012-10-01 09:37 - 00003484 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-08-05 12:44 - 2009-07-13 22:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-05 12:43 - 2014-08-03 23:26 - 00002184 _____ () C:\Windows\PFRO.log
2014-08-05 12:42 - 2014-08-05 12:42 - 01361309 _____ () C:\Users\USER\Downloads\AdwCleaner.exe
2014-08-05 12:39 - 2014-08-05 12:37 - 00000855 _____ () C:\Users\USER\Documents\fixlist.txt
2014-08-05 12:37 - 2013-11-16 23:15 - 00000000 ____D () C:\Users\USER\AppData\Roaming\uTorrent
2014-08-05 03:51 - 2014-07-13 01:09 - 00001237 _____ () C:\Users\USER\Desktop\manga.txt
2014-08-05 03:28 - 2014-05-24 10:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-04 18:56 - 2009-07-13 22:32 - 00000000 ____D () C:\Windows\addins
2014-08-04 16:19 - 2013-06-24 18:48 - 00000000 ____D () C:\Program Files (x86)\osu!
2014-08-04 14:05 - 2014-08-04 14:05 - 02807744 _____ (tuneuppro.com ) C:\Users\USER\Downloads\tupp_04080905180365495.exe
2014-08-04 13:20 - 2014-08-04 13:19 - 00038024 _____ () C:\Users\USER\Downloads\Addition.txt
2014-08-04 13:18 - 2014-08-04 13:18 - 00415232 _____ (Farbar) C:\Users\USER\Downloads\FSS.exe
2014-08-04 13:17 - 2014-08-04 13:17 - 01084928 _____ (Farbar) C:\Users\USER\Downloads\FRST.exe
2014-08-04 13:16 - 2014-08-04 13:16 - 00000000 ____D () C:\MATS
2014-08-04 13:15 - 2014-08-04 13:14 - 00347816 _____ (Microsoft Corporation) C:\Users\USER\Downloads\MicrosoftFixit.ProgramInstallUninstall.MATSKB.Run.exe
2014-08-04 00:11 - 2014-07-15 03:41 - 00000000 ____D () C:\Users\USER\Desktop\cowboy bebop 9
2014-08-03 23:50 - 2014-08-03 23:50 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-03 23:50 - 2014-08-03 23:50 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-03 23:50 - 2014-08-03 23:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-03 23:50 - 2013-06-04 22:23 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-03 23:49 - 2014-08-03 23:49 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-03 23:49 - 2013-06-04 22:23 - 00000000 ____D () C:\Users\USER\AppData\Local\Deployment
2014-08-03 23:49 - 2013-06-04 22:23 - 00000000 ____D () C:\Users\USER\AppData\Local\Apps\2.0
2014-08-03 23:31 - 2014-08-03 23:31 - 00000000 ___SD () C:\32788R22FWJFW
2014-08-03 23:31 - 2014-08-03 23:20 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 23:28 - 2014-08-03 23:28 - 00035524 _____ () C:\ComboFix.txt
2014-08-03 23:28 - 2009-07-13 20:20 - 00000000 __RHD () C:\Users\Default
2014-08-03 23:27 - 2009-07-13 19:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-03 23:26 - 2014-08-03 23:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-03 23:26 - 2009-07-13 19:34 - 78381056 _____ () C:\Windows\system32\config\software.bak
2014-08-03 23:26 - 2009-07-13 19:34 - 18874368 _____ () C:\Windows\system32\config\system.bak
2014-08-03 23:26 - 2009-07-13 19:34 - 00262144 _____ () C:\Windows\system32\config\security.bak
2014-08-03 23:26 - 2009-07-13 19:34 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2014-08-03 23:26 - 2009-07-13 19:34 - 00262144 _____ () C:\Windows\system32\config\default.bak
2014-08-03 23:19 - 2014-08-03 23:18 - 05566616 _____ (Swearware) C:\Users\USER\Downloads\ComboFix.exe
2014-08-03 22:16 - 2014-08-03 22:16 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-08-03 22:16 - 2014-08-03 22:15 - 02347384 _____ (ESET) C:\Users\USER\Downloads\esetsmartinstaller_enu.exe
2014-08-03 21:44 - 2014-08-03 21:44 - 00000000 ____D () C:\Users\USER\AppData\Local\Chromium
2014-08-03 21:39 - 2014-08-03 21:31 - 00007605 _____ () C:\Users\USER\AppData\Local\Resmon.ResmonCfg
2014-08-03 21:21 - 2014-08-03 21:21 - 01361309 _____ () C:\Users\USER\Downloads\adwcleaner_3.302.exe
2014-08-03 20:09 - 2013-10-29 16:48 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Skype
2014-08-03 20:04 - 2014-08-03 20:04 - 00000000 ____D () C:\Users\USER\AppData\Roaming\SYSTEMAX Software Development
2014-08-03 20:04 - 2014-08-03 20:04 - 00000000 ____D () C:\ProgramData\SYSTEMAX Software Development
2014-08-03 20:03 - 2014-08-03 20:03 - 00000000 ____D () C:\Users\USER\Desktop\PaintTool SAI English Pack(2)
2014-08-03 20:01 - 2014-08-03 20:01 - 00000000 __SHD () C:\Users\USER\AppData\Local\EmieUserList
2014-08-03 20:01 - 2014-08-03 20:01 - 00000000 __SHD () C:\Users\USER\AppData\Local\EmieSiteList
2014-08-03 19:36 - 2009-07-13 22:08 - 00032614 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-08-03 19:25 - 2014-08-03 19:25 - 00000702 _____ () C:\Users\USER\Desktop\JRT.txt
2014-08-03 19:19 - 2014-08-03 19:19 - 01016261 _____ (Thisisu) C:\Users\USER\Downloads\JRT.exe
2014-08-03 19:19 - 2014-08-03 19:19 - 00000000 ____D () C:\Windows\ERUNT
2014-08-03 19:14 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-03 19:13 - 2013-11-16 23:24 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-08-03 19:08 - 2014-08-03 19:08 - 01361309 _____ () C:\Users\USER\Desktop\AdwCleaner.exe
2014-08-03 19:07 - 2014-08-03 19:06 - 11526415 _____ () C:\Users\USER\Downloads\PaintTool SAI English Pack(2).rar
2014-08-03 18:44 - 2012-09-29 18:23 - 00000000 ____D () C:\Program Files (x86)\GNU
2014-08-03 18:36 - 2014-08-03 18:33 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-08-03 18:36 - 2014-08-03 18:09 - 00002294 _____ () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-03 18:34 - 2014-08-03 18:34 - 00001897 _____ () C:\Users\Public\Desktop\HitmanPro.lnk
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\Program Files\HitmanPro
2014-08-03 18:33 - 2014-08-03 18:32 - 11188736 _____ (SurfRight B.V.) C:\Users\USER\Downloads\HitmanPro_x64.exe
2014-08-03 18:31 - 2013-06-10 19:05 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-03 18:18 - 2009-07-13 22:32 - 00000000 ____D () C:\Windows\Performance
2014-08-03 18:17 - 2014-08-03 18:10 - 00000000 ____D () C:\Users\USER\AppData\Local\20464
2014-08-03 15:07 - 2014-08-03 15:07 - 00000874 _____ () C:\Windows\SysWOW64\msexcr.ini
2014-08-02 18:01 - 2013-08-30 19:35 - 00000000 ____D () C:\Users\USER\Desktop\poster
2014-08-02 18:00 - 2014-08-02 18:00 - 20163174 _____ () C:\Users\USER\Downloads\Ice.zip
2014-08-02 01:11 - 2013-06-05 15:37 - 00000000 ___RD () C:\Users\USER\Desktop\folder
2014-07-30 03:17 - 2013-10-22 23:02 - 00000000 ____D () C:\Users\USER\Desktop\920
2014-07-23 18:11 - 2012-09-29 18:07 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-23 18:11 - 2012-09-29 18:07 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-23 16:17 - 2012-09-29 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-22 13:54 - 2014-07-22 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-07-22 13:54 - 2014-07-22 13:54 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-07-22 13:54 - 2013-12-16 22:32 - 00000926 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2014-07-22 01:43 - 2014-03-10 16:01 - 00000136 _____ () C:\Users\USER\Desktop\art.txt
2014-07-21 15:56 - 2014-02-15 16:34 - 00000000 ____D () C:\Users\USER\Desktop\zankyou
2014-07-18 16:08 - 2014-07-18 16:08 - 00021656 _____ (Echobit, LLC) C:\Windows\system32\Drivers\evolve.sys
2014-07-18 16:08 - 2014-07-18 16:08 - 00002023 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evolve.lnk
2014-07-18 16:08 - 2014-07-18 16:08 - 00002011 _____ () C:\Users\Public\Desktop\Evolve.lnk
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\Users\USER\AppData\Local\Echobit
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\ProgramData\Echobit
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\Program Files\Echobit
2014-07-18 16:08 - 2014-07-18 16:07 - 03258328 _____ (Echobit LLC) C:\Users\USER\Downloads\EvolveSetup.exe
2014-07-18 16:06 - 2009-07-13 20:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-07-18 16:03 - 2014-07-18 16:03 - 00000222 _____ () C:\Users\USER\Desktop\Unturned.url
2014-07-18 14:18 - 2009-07-13 22:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-07-17 22:24 - 2009-07-13 21:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-07-17 22:23 - 2014-07-17 22:23 - 174178700 _____ () C:\Users\USER\Downloads\ZTST.zip
2014-07-16 13:08 - 2014-07-16 13:08 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-15 20:35 - 2014-07-15 20:35 - 00001111 _____ () C:\Users\USER\Desktop\Katawa Shoujo.lnk
2014-07-15 20:35 - 2014-07-15 20:35 - 00000000 ____D () C:\Users\USER\AppData\Roaming\RenPy
2014-07-15 20:35 - 2014-07-15 20:34 - 00000000 ____D () C:\Program Files (x86)\Katawa Shoujo
2014-07-15 20:34 - 2014-07-15 20:32 - 444251517 _____ () C:\Users\USER\Downloads\[4ls]_katawa_shoujo_1.1-[windows][8AACDD32].exe
2014-07-13 17:19 - 2014-03-16 22:19 - 00000000 ____D () C:\Users\USER\Desktop\pzinndix
2014-07-12 14:42 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\rescache
2014-07-11 16:32 - 2014-07-11 16:32 - 00000219 _____ () C:\Users\USER\Desktop\Counter-Strike Global Offensive.url
2014-07-11 16:32 - 2013-06-10 19:19 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-11 16:18 - 2014-04-20 01:37 - 00000000 ____D () C:\Users\USER\Desktop\kimi n oknife 28
2014-07-11 16:18 - 2014-01-06 13:19 - 00000000 ___RD () C:\Users\USER\Desktop\wallpapers
2014-07-11 03:39 - 2014-07-11 03:39 - 27060196 _____ () C:\Users\USER\Downloads\No Game No Life.zip
2014-07-11 03:37 - 2014-07-11 03:37 - 26507407 _____ () C:\Users\USER\Downloads\Nisekoi.zip
2014-07-11 03:37 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\USER\Desktop\Other wallpapers
2014-07-09 09:52 - 2012-09-29 18:07 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 09:52 - 2012-09-29 18:07 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 09:52 - 2012-09-29 18:07 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-08 18:45 - 2009-07-13 21:45 - 05267168 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-08 18:44 - 2011-04-12 01:28 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-08 18:44 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-08 18:44 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-08 16:23 - 2014-05-22 12:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-08 16:22 - 2012-10-01 10:58 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-08 16:22 - 2012-10-01 09:20 - 00000000 ____D () C:\ProgramData\Microsoft Help
Files to move or delete:
====================
C:\Users\USER\jagex_cl_runescape_LIVE.dat
C:\Users\USER\jagex_cl_runescape_LIVE1.dat
C:\Users\USER\random.dat
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-31 21:55
==================== End Of Log ============================Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-08-2014
Ran by USER (administrator) on USER-PC on 05-08-2014 13:11:00
Running from C:\Users\USER\Desktop\frst
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7560296 2011-12-12] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1436736 2011-06-15] (Microsoft Corporation)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840768 2013-05-10] (Adobe Systems Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3816784 2014-07-21] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3385489291-3797028483-2866025970-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-02-14] (AMD)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7E30C97B03A0CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{B89CE93C-F058-4423-AD4F-B552A5C6E64A}: [NameServer]8.8.8.8,8.8.4.4
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF Plugin-x32: @gomtv.com/gomtvx-plugin -> C:\Program Files (x86)\Common Files\GRETECH\npgomtvx_nie.dll (Gretech Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nexon.net/NxGame -> C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012-09-29]
Chrome:
=======
CHR HomePage:
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.4.600\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (gomtvx NIE Module) - C:\Program Files (x86)\Common Files\GRETECH\npgomtvx_nie.dll (Gretech Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll No File
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll No File
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-05]
CHR Extension: (Inaba Himeko Theme) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\flooilpmbaknnlpnonlaccahmplanfln [2014-04-26]
CHR Extension: (AdBlock) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-08-04]
CHR Extension: (Google Wallet) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 EvoSvc; C:\Program Files\Echobit\Evolve\EvoSvc.exe [1579936 2014-07-18] (Echobit LLC)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2014-08-03] (SurfRight B.V.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [161560 2012-01-20] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-07-16] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [12784 2011-04-27] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [288272 2011-04-27] (Microsoft Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [614680 2013-09-12] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R3 EvolveVirtualAdapter; C:\Windows\System32\DRIVERS\evolve.sys [21656 2014-07-18] (Echobit, LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [189440 2011-04-18] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [84864 2011-04-27] (Microsoft Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S2 {B154377D-700F-42cc-9474-23858FBDF4BD}; \??\C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-05 12:42 - 2014-08-05 12:42 - 01361309 _____ () C:\Users\USER\Downloads\AdwCleaner.exe
2014-08-05 12:38 - 2014-08-05 13:11 - 00000000 ____D () C:\Users\USER\Desktop\frst
2014-08-05 12:37 - 2014-08-05 12:39 - 00000855 _____ () C:\Users\USER\Documents\fixlist.txt
2014-08-04 14:05 - 2014-08-04 14:05 - 02807744 _____ (tuneuppro.com ) C:\Users\USER\Downloads\tupp_04080905180365495.exe
2014-08-04 13:19 - 2014-08-04 13:20 - 00038024 _____ () C:\Users\USER\Downloads\Addition.txt
2014-08-04 13:18 - 2014-08-05 13:11 - 00000000 ____D () C:\FRST
2014-08-04 13:18 - 2014-08-04 13:18 - 00415232 _____ (Farbar) C:\Users\USER\Downloads\FSS.exe
2014-08-04 13:17 - 2014-08-04 13:17 - 01084928 _____ (Farbar) C:\Users\USER\Downloads\FRST.exe
2014-08-04 13:16 - 2014-08-04 13:16 - 00000000 ____D () C:\MATS
2014-08-04 13:14 - 2014-08-04 13:15 - 00347816 _____ (Microsoft Corporation) C:\Users\USER\Downloads\MicrosoftFixit.ProgramInstallUninstall.MATSKB.Run.exe
2014-08-03 23:50 - 2014-08-05 12:56 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-03 23:50 - 2014-08-03 23:50 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-03 23:50 - 2014-08-03 23:50 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-03 23:50 - 2014-08-03 23:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-03 23:49 - 2014-08-05 12:44 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-03 23:49 - 2014-08-03 23:49 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-03 23:31 - 2014-08-03 23:31 - 00000000 ___SD () C:\32788R22FWJFW
2014-08-03 23:28 - 2014-08-03 23:28 - 00035524 _____ () C:\ComboFix.txt
2014-08-03 23:26 - 2014-08-05 12:44 - 00000504 _____ () C:\Windows\setupact.log
2014-08-03 23:26 - 2014-08-05 12:43 - 00002184 _____ () C:\Windows\PFRO.log
2014-08-03 23:26 - 2014-08-03 23:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-03 23:20 - 2014-08-03 23:31 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 23:18 - 2014-08-03 23:19 - 05566616 _____ (Swearware) C:\Users\USER\Downloads\ComboFix.exe
2014-08-03 22:16 - 2014-08-03 22:16 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-08-03 22:15 - 2014-08-03 22:16 - 02347384 _____ (ESET) C:\Users\USER\Downloads\esetsmartinstaller_enu.exe
2014-08-03 21:44 - 2014-08-03 21:44 - 00000000 ____D () C:\Users\USER\AppData\Local\Chromium
2014-08-03 21:31 - 2014-08-03 21:39 - 00007605 _____ () C:\Users\USER\AppData\Local\Resmon.ResmonCfg
2014-08-03 21:21 - 2014-08-03 21:21 - 01361309 _____ () C:\Users\USER\Downloads\adwcleaner_3.302.exe
2014-08-03 20:04 - 2014-08-03 20:04 - 00000000 ____D () C:\Users\USER\AppData\Roaming\SYSTEMAX Software Development
2014-08-03 20:04 - 2014-08-03 20:04 - 00000000 ____D () C:\ProgramData\SYSTEMAX Software Development
2014-08-03 20:03 - 2014-08-03 20:03 - 00000000 ____D () C:\Users\USER\Desktop\PaintTool SAI English Pack(2)
2014-08-03 20:01 - 2014-08-03 20:01 - 00000000 __SHD () C:\Users\USER\AppData\Local\EmieUserList
2014-08-03 20:01 - 2014-08-03 20:01 - 00000000 __SHD () C:\Users\USER\AppData\Local\EmieSiteList
2014-08-03 19:25 - 2014-08-03 19:25 - 00000702 _____ () C:\Users\USER\Desktop\JRT.txt
2014-08-03 19:19 - 2014-08-03 19:19 - 01016261 _____ (Thisisu) C:\Users\USER\Downloads\JRT.exe
2014-08-03 19:19 - 2014-08-03 19:19 - 00000000 ____D () C:\Windows\ERUNT
2014-08-03 19:09 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-03 19:08 - 2014-08-05 13:10 - 00000000 ____D () C:\AdwCleaner
2014-08-03 19:08 - 2014-08-03 19:08 - 01361309 _____ () C:\Users\USER\Desktop\AdwCleaner.exe
2014-08-03 19:06 - 2014-08-03 19:07 - 11526415 _____ () C:\Users\USER\Downloads\PaintTool SAI English Pack(2).rar
2014-08-03 18:34 - 2014-08-03 18:34 - 00001897 _____ () C:\Users\Public\Desktop\HitmanPro.lnk
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\Program Files\HitmanPro
2014-08-03 18:33 - 2014-08-03 18:36 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-08-03 18:32 - 2014-08-03 18:33 - 11188736 _____ (SurfRight B.V.) C:\Users\USER\Downloads\HitmanPro_x64.exe
2014-08-03 18:10 - 2014-08-03 18:17 - 00000000 ____D () C:\Users\USER\AppData\Local\20464
2014-08-03 18:09 - 2014-08-03 18:36 - 00002294 _____ () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-03 15:07 - 2014-08-03 15:07 - 00000874 _____ () C:\Windows\SysWOW64\msexcr.ini
2014-08-02 18:00 - 2014-08-02 18:00 - 20163174 _____ () C:\Users\USER\Downloads\Ice.zip
2014-07-22 13:54 - 2014-07-22 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-07-22 13:54 - 2014-07-22 13:54 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-07-18 16:08 - 2014-07-18 16:08 - 00021656 _____ (Echobit, LLC) C:\Windows\system32\Drivers\evolve.sys
2014-07-18 16:08 - 2014-07-18 16:08 - 00002023 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evolve.lnk
2014-07-18 16:08 - 2014-07-18 16:08 - 00002011 _____ () C:\Users\Public\Desktop\Evolve.lnk
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\Users\USER\AppData\Local\Echobit
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\ProgramData\Echobit
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\Program Files\Echobit
2014-07-18 16:07 - 2014-07-18 16:08 - 03258328 _____ (Echobit LLC) C:\Users\USER\Downloads\EvolveSetup.exe
2014-07-18 16:03 - 2014-07-18 16:03 - 00000222 _____ () C:\Users\USER\Desktop\Unturned.url
2014-07-17 22:23 - 2014-07-17 22:23 - 174178700 _____ () C:\Users\USER\Downloads\ZTST.zip
2014-07-16 13:08 - 2014-07-16 13:08 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-15 20:35 - 2014-07-15 20:35 - 00001111 _____ () C:\Users\USER\Desktop\Katawa Shoujo.lnk
2014-07-15 20:35 - 2014-07-15 20:35 - 00000000 ____D () C:\Users\USER\AppData\Roaming\RenPy
2014-07-15 20:34 - 2014-07-15 20:35 - 00000000 ____D () C:\Program Files (x86)\Katawa Shoujo
2014-07-15 20:32 - 2014-07-15 20:34 - 444251517 _____ () C:\Users\USER\Downloads\[4ls]_katawa_shoujo_1.1-[windows][8AACDD32].exe
2014-07-15 03:41 - 2014-08-04 00:11 - 00000000 ____D () C:\Users\USER\Desktop\cowboy bebop 9
2014-07-13 01:09 - 2014-08-05 03:51 - 00001237 _____ () C:\Users\USER\Desktop\manga.txt
2014-07-11 16:32 - 2014-07-11 16:32 - 00000219 _____ () C:\Users\USER\Desktop\Counter-Strike Global Offensive.url
2014-07-11 03:39 - 2014-07-11 03:39 - 27060196 _____ () C:\Users\USER\Downloads\No Game No Life.zip
2014-07-11 03:37 - 2014-07-11 03:37 - 26507407 _____ () C:\Users\USER\Downloads\Nisekoi.zip
2014-07-08 13:22 - 2014-06-20 13:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-08 13:22 - 2014-06-20 12:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-08 13:22 - 2014-06-18 18:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-08 13:22 - 2014-06-18 18:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-08 13:22 - 2014-06-18 18:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-08 13:22 - 2014-06-18 17:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-08 13:22 - 2014-06-18 17:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-08 13:22 - 2014-06-18 17:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-08 13:22 - 2014-06-18 17:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-08 13:22 - 2014-06-18 17:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-08 13:22 - 2014-06-18 17:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-08 13:22 - 2014-06-18 17:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-08 13:22 - 2014-06-18 17:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-08 13:22 - 2014-06-18 17:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-08 13:22 - 2014-06-18 17:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-08 13:22 - 2014-06-18 17:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-08 13:22 - 2014-06-18 17:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-08 13:22 - 2014-06-18 17:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-08 13:22 - 2014-06-18 17:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-08 13:22 - 2014-06-18 16:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-08 13:22 - 2014-06-18 16:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-08 13:22 - 2014-06-18 16:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-08 13:22 - 2014-06-18 16:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-08 13:22 - 2014-06-18 16:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-08 13:22 - 2014-06-18 16:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-08 13:22 - 2014-06-18 16:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-08 13:22 - 2014-06-18 16:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-08 13:22 - 2014-06-18 16:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-08 13:22 - 2014-06-18 16:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-08 13:22 - 2014-06-18 16:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-08 13:22 - 2014-06-18 16:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-08 13:22 - 2014-06-18 16:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-08 13:22 - 2014-06-18 16:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-08 13:22 - 2014-06-18 16:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-08 13:22 - 2014-06-18 16:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-08 13:22 - 2014-06-18 16:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-08 13:22 - 2014-06-18 16:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-08 13:22 - 2014-06-18 16:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-08 13:22 - 2014-06-18 16:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-08 13:22 - 2014-06-18 16:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-08 13:22 - 2014-06-18 16:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-08 13:22 - 2014-06-18 16:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-08 13:22 - 2014-06-18 15:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-08 13:22 - 2014-06-18 15:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-08 13:22 - 2014-06-18 15:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-08 13:22 - 2014-06-18 15:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-08 13:22 - 2014-06-18 15:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-08 13:22 - 2014-06-18 15:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-08 13:22 - 2014-06-18 15:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-08 13:22 - 2014-06-18 15:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-08 13:22 - 2014-06-18 15:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-08 13:22 - 2014-06-18 15:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-08 13:22 - 2014-06-18 15:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-08 13:22 - 2014-06-18 15:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-08 13:22 - 2014-06-18 15:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-08 13:22 - 2014-06-18 15:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-08 13:22 - 2014-06-17 19:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-08 13:22 - 2014-06-17 18:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-08 13:22 - 2014-06-17 18:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-08 13:22 - 2014-06-06 03:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-08 13:22 - 2014-06-06 02:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-08 13:22 - 2014-05-30 01:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-08 13:22 - 2014-05-30 00:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-08 13:22 - 2014-05-29 23:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-08 13:21 - 2014-06-05 07:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-08 13:21 - 2014-06-05 07:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-08 13:21 - 2014-06-05 07:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-05 13:11 - 2014-08-05 12:38 - 00000000 ____D () C:\Users\USER\Desktop\frst
2014-08-05 13:11 - 2014-08-04 13:18 - 00000000 ____D () C:\FRST
2014-08-05 13:10 - 2014-08-03 19:08 - 00000000 ____D () C:\AdwCleaner
2014-08-05 12:56 - 2014-08-03 23:50 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-05 12:52 - 2012-09-29 18:07 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-05 12:49 - 2009-07-13 21:45 - 00028128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-05 12:49 - 2009-07-13 21:45 - 00028128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-05 12:48 - 2009-07-13 22:13 - 00006742 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-05 12:47 - 2013-11-28 11:02 - 01857342 _____ () C:\Windows\WindowsUpdate.log
2014-08-05 12:45 - 2013-11-16 23:24 - 00000000 ____D () C:\Users\USER\AppData\Local\LogMeIn Hamachi
2014-08-05 12:44 - 2014-08-03 23:49 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-05 12:44 - 2014-08-03 23:26 - 00000504 _____ () C:\Windows\setupact.log
2014-08-05 12:44 - 2012-10-01 09:37 - 00003484 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-08-05 12:44 - 2009-07-13 22:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-05 12:43 - 2014-08-03 23:26 - 00002184 _____ () C:\Windows\PFRO.log
2014-08-05 12:42 - 2014-08-05 12:42 - 01361309 _____ () C:\Users\USER\Downloads\AdwCleaner.exe
2014-08-05 12:39 - 2014-08-05 12:37 - 00000855 _____ () C:\Users\USER\Documents\fixlist.txt
2014-08-05 12:37 - 2013-11-16 23:15 - 00000000 ____D () C:\Users\USER\AppData\Roaming\uTorrent
2014-08-05 03:51 - 2014-07-13 01:09 - 00001237 _____ () C:\Users\USER\Desktop\manga.txt
2014-08-05 03:28 - 2014-05-24 10:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-04 18:56 - 2009-07-13 22:32 - 00000000 ____D () C:\Windows\addins
2014-08-04 16:19 - 2013-06-24 18:48 - 00000000 ____D () C:\Program Files (x86)\osu!
2014-08-04 14:05 - 2014-08-04 14:05 - 02807744 _____ (tuneuppro.com ) C:\Users\USER\Downloads\tupp_04080905180365495.exe
2014-08-04 13:20 - 2014-08-04 13:19 - 00038024 _____ () C:\Users\USER\Downloads\Addition.txt
2014-08-04 13:18 - 2014-08-04 13:18 - 00415232 _____ (Farbar) C:\Users\USER\Downloads\FSS.exe
2014-08-04 13:17 - 2014-08-04 13:17 - 01084928 _____ (Farbar) C:\Users\USER\Downloads\FRST.exe
2014-08-04 13:16 - 2014-08-04 13:16 - 00000000 ____D () C:\MATS
2014-08-04 13:15 - 2014-08-04 13:14 - 00347816 _____ (Microsoft Corporation) C:\Users\USER\Downloads\MicrosoftFixit.ProgramInstallUninstall.MATSKB.Run.exe
2014-08-04 00:11 - 2014-07-15 03:41 - 00000000 ____D () C:\Users\USER\Desktop\cowboy bebop 9
2014-08-03 23:50 - 2014-08-03 23:50 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-03 23:50 - 2014-08-03 23:50 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-03 23:50 - 2014-08-03 23:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-03 23:50 - 2013-06-04 22:23 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-03 23:49 - 2014-08-03 23:49 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-03 23:49 - 2013-06-04 22:23 - 00000000 ____D () C:\Users\USER\AppData\Local\Deployment
2014-08-03 23:49 - 2013-06-04 22:23 - 00000000 ____D () C:\Users\USER\AppData\Local\Apps\2.0
2014-08-03 23:31 - 2014-08-03 23:31 - 00000000 ___SD () C:\32788R22FWJFW
2014-08-03 23:31 - 2014-08-03 23:20 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 23:28 - 2014-08-03 23:28 - 00035524 _____ () C:\ComboFix.txt
2014-08-03 23:28 - 2009-07-13 20:20 - 00000000 __RHD () C:\Users\Default
2014-08-03 23:27 - 2009-07-13 19:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-03 23:26 - 2014-08-03 23:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-03 23:26 - 2009-07-13 19:34 - 78381056 _____ () C:\Windows\system32\config\software.bak
2014-08-03 23:26 - 2009-07-13 19:34 - 18874368 _____ () C:\Windows\system32\config\system.bak
2014-08-03 23:26 - 2009-07-13 19:34 - 00262144 _____ () C:\Windows\system32\config\security.bak
2014-08-03 23:26 - 2009-07-13 19:34 - 00262144 _____ () C:\Windows\system32\config\sam.bak
2014-08-03 23:26 - 2009-07-13 19:34 - 00262144 _____ () C:\Windows\system32\config\default.bak
2014-08-03 23:19 - 2014-08-03 23:18 - 05566616 _____ (Swearware) C:\Users\USER\Downloads\ComboFix.exe
2014-08-03 22:16 - 2014-08-03 22:16 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-08-03 22:16 - 2014-08-03 22:15 - 02347384 _____ (ESET) C:\Users\USER\Downloads\esetsmartinstaller_enu.exe
2014-08-03 21:44 - 2014-08-03 21:44 - 00000000 ____D () C:\Users\USER\AppData\Local\Chromium
2014-08-03 21:39 - 2014-08-03 21:31 - 00007605 _____ () C:\Users\USER\AppData\Local\Resmon.ResmonCfg
2014-08-03 21:21 - 2014-08-03 21:21 - 01361309 _____ () C:\Users\USER\Downloads\adwcleaner_3.302.exe
2014-08-03 20:09 - 2013-10-29 16:48 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Skype
2014-08-03 20:04 - 2014-08-03 20:04 - 00000000 ____D () C:\Users\USER\AppData\Roaming\SYSTEMAX Software Development
2014-08-03 20:04 - 2014-08-03 20:04 - 00000000 ____D () C:\ProgramData\SYSTEMAX Software Development
2014-08-03 20:03 - 2014-08-03 20:03 - 00000000 ____D () C:\Users\USER\Desktop\PaintTool SAI English Pack(2)
2014-08-03 20:01 - 2014-08-03 20:01 - 00000000 __SHD () C:\Users\USER\AppData\Local\EmieUserList
2014-08-03 20:01 - 2014-08-03 20:01 - 00000000 __SHD () C:\Users\USER\AppData\Local\EmieSiteList
2014-08-03 19:36 - 2009-07-13 22:08 - 00032614 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-08-03 19:25 - 2014-08-03 19:25 - 00000702 _____ () C:\Users\USER\Desktop\JRT.txt
2014-08-03 19:19 - 2014-08-03 19:19 - 01016261 _____ (Thisisu) C:\Users\USER\Downloads\JRT.exe
2014-08-03 19:19 - 2014-08-03 19:19 - 00000000 ____D () C:\Windows\ERUNT
2014-08-03 19:14 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-03 19:13 - 2013-11-16 23:24 - 00000000 ____D () C:\ProgramData\LogMeIn
2014-08-03 19:08 - 2014-08-03 19:08 - 01361309 _____ () C:\Users\USER\Desktop\AdwCleaner.exe
2014-08-03 19:07 - 2014-08-03 19:06 - 11526415 _____ () C:\Users\USER\Downloads\PaintTool SAI English Pack(2).rar
2014-08-03 18:44 - 2012-09-29 18:23 - 00000000 ____D () C:\Program Files (x86)\GNU
2014-08-03 18:36 - 2014-08-03 18:33 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-08-03 18:36 - 2014-08-03 18:09 - 00002294 _____ () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-03 18:34 - 2014-08-03 18:34 - 00001897 _____ () C:\Users\Public\Desktop\HitmanPro.lnk
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\Program Files\HitmanPro
2014-08-03 18:33 - 2014-08-03 18:32 - 11188736 _____ (SurfRight B.V.) C:\Users\USER\Downloads\HitmanPro_x64.exe
2014-08-03 18:31 - 2013-06-10 19:05 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-03 18:18 - 2009-07-13 22:32 - 00000000 ____D () C:\Windows\Performance
2014-08-03 18:17 - 2014-08-03 18:10 - 00000000 ____D () C:\Users\USER\AppData\Local\20464
2014-08-03 15:07 - 2014-08-03 15:07 - 00000874 _____ () C:\Windows\SysWOW64\msexcr.ini
2014-08-02 18:01 - 2013-08-30 19:35 - 00000000 ____D () C:\Users\USER\Desktop\poster
2014-08-02 18:00 - 2014-08-02 18:00 - 20163174 _____ () C:\Users\USER\Downloads\Ice.zip
2014-08-02 01:11 - 2013-06-05 15:37 - 00000000 ___RD () C:\Users\USER\Desktop\folder
2014-07-30 03:17 - 2013-10-22 23:02 - 00000000 ____D () C:\Users\USER\Desktop\920
2014-07-23 18:11 - 2012-09-29 18:07 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-23 18:11 - 2012-09-29 18:07 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-23 16:17 - 2012-09-29 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-22 13:54 - 2014-07-22 13:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-07-22 13:54 - 2014-07-22 13:54 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-07-22 13:54 - 2013-12-16 22:32 - 00000926 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2014-07-22 01:43 - 2014-03-10 16:01 - 00000136 _____ () C:\Users\USER\Desktop\art.txt
2014-07-21 15:56 - 2014-02-15 16:34 - 00000000 ____D () C:\Users\USER\Desktop\zankyou
2014-07-18 16:08 - 2014-07-18 16:08 - 00021656 _____ (Echobit, LLC) C:\Windows\system32\Drivers\evolve.sys
2014-07-18 16:08 - 2014-07-18 16:08 - 00002023 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evolve.lnk
2014-07-18 16:08 - 2014-07-18 16:08 - 00002011 _____ () C:\Users\Public\Desktop\Evolve.lnk
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\Users\USER\AppData\Local\Echobit
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\ProgramData\Echobit
2014-07-18 16:08 - 2014-07-18 16:08 - 00000000 ____D () C:\Program Files\Echobit
2014-07-18 16:08 - 2014-07-18 16:07 - 03258328 _____ (Echobit LLC) C:\Users\USER\Downloads\EvolveSetup.exe
2014-07-18 16:06 - 2009-07-13 20:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-07-18 16:03 - 2014-07-18 16:03 - 00000222 _____ () C:\Users\USER\Desktop\Unturned.url
2014-07-18 14:18 - 2009-07-13 22:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-07-17 22:24 - 2009-07-13 21:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-07-17 22:23 - 2014-07-17 22:23 - 174178700 _____ () C:\Users\USER\Downloads\ZTST.zip
2014-07-16 13:08 - 2014-07-16 13:08 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-15 20:35 - 2014-07-15 20:35 - 00001111 _____ () C:\Users\USER\Desktop\Katawa Shoujo.lnk
2014-07-15 20:35 - 2014-07-15 20:35 - 00000000 ____D () C:\Users\USER\AppData\Roaming\RenPy
2014-07-15 20:35 - 2014-07-15 20:34 - 00000000 ____D () C:\Program Files (x86)\Katawa Shoujo
2014-07-15 20:34 - 2014-07-15 20:32 - 444251517 _____ () C:\Users\USER\Downloads\[4ls]_katawa_shoujo_1.1-[windows][8AACDD32].exe
2014-07-13 17:19 - 2014-03-16 22:19 - 00000000 ____D () C:\Users\USER\Desktop\pzinndix
2014-07-12 14:42 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\rescache
2014-07-11 16:32 - 2014-07-11 16:32 - 00000219 _____ () C:\Users\USER\Desktop\Counter-Strike Global Offensive.url
2014-07-11 16:32 - 2013-06-10 19:19 - 00000000 ____D () C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-07-11 16:18 - 2014-04-20 01:37 - 00000000 ____D () C:\Users\USER\Desktop\kimi n oknife 28
2014-07-11 16:18 - 2014-01-06 13:19 - 00000000 ___RD () C:\Users\USER\Desktop\wallpapers
2014-07-11 03:39 - 2014-07-11 03:39 - 27060196 _____ () C:\Users\USER\Downloads\No Game No Life.zip
2014-07-11 03:37 - 2014-07-11 03:37 - 26507407 _____ () C:\Users\USER\Downloads\Nisekoi.zip
2014-07-11 03:37 - 2014-05-10 21:49 - 00000000 ____D () C:\Users\USER\Desktop\Other wallpapers
2014-07-09 09:52 - 2012-09-29 18:07 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 09:52 - 2012-09-29 18:07 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 09:52 - 2012-09-29 18:07 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-08 18:45 - 2009-07-13 21:45 - 05267168 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-08 18:44 - 2011-04-12 01:28 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-08 18:44 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-08 18:44 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-08 16:23 - 2014-05-22 12:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-08 16:22 - 2012-10-01 10:58 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-08 16:22 - 2012-10-01 09:20 - 00000000 ____D () C:\ProgramData\Microsoft Help
Files to move or delete:
====================
C:\Users\USER\jagex_cl_runescape_LIVE.dat
C:\Users\USER\jagex_cl_runescape_LIVE1.dat
C:\Users\USER\random.dat
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-31 21:55
==================== End Of Log ============================