Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Flickering Spastic Windows [Closed]

Malware Bug Flickering Windows 8

  • This topic is locked This topic is locked

#1
arcaneshield

arcaneshield

    New Member

  • Member
  • Pip
  • 4 posts

Hi there, I've been experiencing a strange bug since last night. The bug has two parts.

 

The first part is while in a window or a program in windowed mode, every now and again it spazzes out, like its being clicked on rapidly, the window flickers and I need to click away on my second monitor just to get it to stop.

 

Second, last night I had this error as well, my windows' z axis was off. Didn't matter which window I focused on, nothing came closer to the foreground, they all stayed in the same z-axis / overlap position.

 

I ran avast on all 3 of my drives and malwarebytes scan twice. Finally I followed this forum's directions to get this OTL log:

 

OTL logfile created on: 2014-08-24 10:50:46 AM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = E:\User\Downloads
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17239)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: yyyy-MM-dd
 
15.95 Gb Total Physical Memory | 11.17 Gb Available Physical Memory | 70.02% Memory free
31.95 Gb Paging File | 25.40 Gb Available in Paging File | 79.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 223.23 Gb Total Space | 36.01 Gb Free Space | 16.13% Space Free | Partition Type: NTFS
Drive D: | 238.47 Gb Total Space | 36.52 Gb Free Space | 15.31% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 74.28 Gb Free Space | 7.97% Space Free | Partition Type: NTFS
Drive F: | 462.11 Gb Total Space | 213.57 Gb Free Space | 46.22% Space Free | Partition Type: NTFS
 
Computer Name: STIRLING-PC | User Name: Stirling | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014-08-24 10:50:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\User\Downloads\OTL.exe
PRC - [2014-08-23 10:14:04 | 001,414,736 | ---- | M] (BitTorrent Inc.) -- C:\Users\Stirling\AppData\Roaming\uTorrent\uTorrent.exe
PRC - [2014-08-22 19:06:42 | 001,521,344 | ---- | M] (Valve Corporation) -- C:\Games\Steam\bin\steamwebhelper.exe
PRC - [2014-08-22 19:06:40 | 001,939,136 | ---- | M] (Valve Corporation) -- C:\Games\Steam\Steam.exe
PRC - [2014-08-21 12:45:15 | 001,788,072 | ---- | M] (GameRanger Technologies) -- C:\Users\Stirling\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
PRC - [2014-08-19 20:36:38 | 000,045,840 | ---- | M] (Raptr, Inc) -- C:\Program Files (x86)\Raptr\raptr_im.exe
PRC - [2014-08-19 20:36:34 | 000,066,832 | ---- | M] (Raptr, Inc) -- C:\Program Files (x86)\Raptr\raptr.exe
PRC - [2014-08-06 22:20:57 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014-08-06 09:18:23 | 003,600,728 | ---- | M] (Electronic Arts) -- C:\Games\Origin\Origin.exe
PRC - [2014-08-01 19:14:22 | 000,028,496 | ---- | M] () -- C:\Program Files (x86)\Razer\Comms\RzCommsInGameApplet\RzCommsInGameApplet.exe
PRC - [2014-08-01 19:14:20 | 011,233,088 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Comms\ChatApplet.exe
PRC - [2014-07-31 07:05:42 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastui.exe
PRC - [2014-07-15 16:51:59 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014-07-15 15:48:19 | 000,175,808 | ---- | M] () -- C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
PRC - [2014-07-03 05:58:12 | 000,213,720 | ---- | M] (Razer, Inc.) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
PRC - [2014-07-03 05:58:12 | 000,210,136 | ---- | M] (Razer, Inc.) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\RzCefRenderProcess.exe
PRC - [2014-06-27 11:52:26 | 002,088,408 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2014-06-24 10:42:12 | 004,101,576 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2014-06-24 10:41:42 | 001,738,168 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2014-06-23 10:41:22 | 000,585,560 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
PRC - [2014-06-22 09:43:48 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
PRC - [2014-06-11 17:51:54 | 000,390,256 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
PRC - [2014-06-10 11:56:06 | 001,718,560 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe
PRC - [2014-06-06 12:08:14 | 000,029,984 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe
PRC - [2014-06-06 12:08:12 | 000,072,992 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe
PRC - [2014-04-25 14:12:20 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2014-03-11 16:44:52 | 000,241,728 | ---- | M] (Foxit Corporation) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
PRC - [2014-03-05 17:12:34 | 001,195,712 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Razer Game Booster\main.exe
PRC - [2014-02-25 19:38:48 | 000,105,448 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
PRC - [2013-12-21 01:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013-04-29 03:32:22 | 000,593,408 | ---- | M] (Microsoft) -- C:\Games\Steam\SteamApps\common\diriptide\Dead Island - Riptide Helper.exe
PRC - [2012-12-06 15:08:34 | 000,980,432 | ---- | M] (Razer USA Ltd) -- C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014-08-22 19:06:54 | 002,224,320 | ---- | M] () -- C:\Games\Steam\video.dll
MOD - [2014-08-22 19:06:42 | 000,678,080 | ---- | M] () -- C:\Games\Steam\bin\chromehtml.dll
MOD - [2014-08-21 13:15:22 | 001,171,456 | ---- | M] () -- C:\Games\Steam\libavcodec-56.dll
MOD - [2014-08-21 13:15:22 | 000,485,888 | ---- | M] () -- C:\Games\Steam\libswscale-3.dll
MOD - [2014-08-21 13:15:22 | 000,442,368 | ---- | M] () -- C:\Games\Steam\libavutil-54.dll
MOD - [2014-08-21 13:15:22 | 000,403,968 | ---- | M] () -- C:\Games\Steam\libavformat-56.dll
MOD - [2014-08-21 13:15:22 | 000,332,800 | ---- | M] () -- C:\Games\Steam\libavresample-2.dll
MOD - [2014-08-20 17:38:18 | 034,589,376 | ---- | M] () -- C:\Games\Steam\bin\libcef.dll
MOD - [2014-08-20 17:38:18 | 000,837,824 | ---- | M] () -- C:\Games\Steam\bin\ffmpegsumo.dll
MOD - [2014-08-20 17:38:12 | 000,774,656 | ---- | M] () -- C:\Games\Steam\SDL2.dll
MOD - [2014-08-15 11:02:29 | 000,978,432 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\27dc8e491e32361eaff0b88f0befc197\System.Configuration.ni.dll
MOD - [2014-08-15 11:00:37 | 005,467,136 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\8006a5df62f0c127d15db16d3a8c68f8\System.Xml.ni.dll
MOD - [2014-08-15 11:00:35 | 012,436,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6ec0cbaebf2932db68d8cc77b5e9b4e9\System.Windows.Forms.ni.dll
MOD - [2014-08-15 11:00:30 | 001,593,344 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f6ff4eab6e6bb587d62c3975fcbbca30\System.Drawing.ni.dll
MOD - [2014-08-15 11:00:08 | 007,993,856 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\a500ec9c4638c6ba200d7b55324709f2\System.ni.dll
MOD - [2014-08-15 11:00:05 | 011,500,032 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\5bd3374f05d46ba0563f44d032209f08\mscorlib.ni.dll
MOD - [2014-08-06 22:20:55 | 000,353,096 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ppgooglenaclpluginchrome.dll
MOD - [2014-08-06 22:20:54 | 014,669,128 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll
MOD - [2014-08-06 22:20:53 | 008,537,928 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\pdf.dll
MOD - [2014-08-06 22:20:49 | 000,718,152 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\libglesv2.dll
MOD - [2014-08-06 22:20:47 | 000,126,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\libegl.dll
MOD - [2014-08-06 22:20:46 | 001,732,936 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ffmpegsumo.dll
MOD - [2014-08-06 09:18:22 | 000,962,560 | ---- | M] () -- C:\Games\Origin\platforms\qwindows.dll
MOD - [2014-08-06 09:18:22 | 000,302,592 | ---- | M] () -- C:\Games\Origin\imageformats\qtiff.dll
MOD - [2014-08-06 09:18:22 | 000,261,632 | ---- | M] () -- C:\Games\Origin\imageformats\qmng.dll
MOD - [2014-08-06 09:18:22 | 000,217,088 | ---- | M] () -- C:\Games\Origin\imageformats\qjpeg.dll
MOD - [2014-08-06 09:18:22 | 000,025,088 | ---- | M] () -- C:\Games\Origin\imageformats\qico.dll
MOD - [2014-08-06 09:18:22 | 000,024,064 | ---- | M] () -- C:\Games\Origin\imageformats\qgif.dll
MOD - [2014-08-06 09:18:22 | 000,019,968 | ---- | M] () -- C:\Games\Origin\imageformats\qtga.dll
MOD - [2014-08-06 09:18:22 | 000,018,944 | ---- | M] () -- C:\Games\Origin\imageformats\qwbmp.dll
MOD - [2014-08-01 19:14:22 | 000,028,496 | ---- | M] () -- C:\Program Files (x86)\Razer\Comms\RzCommsInGameApplet\RzCommsInGameApplet.exe
MOD - [2014-07-17 01:27:12 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\Razer\Comms\RzCommsInGameApplet\RzCommsInGameApplet.dll
MOD - [2014-07-15 16:51:59 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014-07-15 16:51:59 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
MOD - [2014-06-17 19:56:00 | 002,717,595 | ---- | M] () -- C:\Program Files (x86)\Raptr\heliotrope._purple.pyd
MOD - [2014-06-11 17:51:54 | 003,022,960 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
MOD - [2014-06-11 17:51:54 | 000,158,832 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\nsldap32v60.dll
MOD - [2014-06-11 17:51:54 | 000,023,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\nsldappr32v60.dll
MOD - [2014-06-06 12:07:56 | 000,348,960 | ---- | M] () -- C:\Program Files (x86)\IObit\Start Menu 8\madexcept_.bpl
MOD - [2014-06-06 12:07:54 | 000,050,976 | ---- | M] () -- C:\Program Files (x86)\IObit\Start Menu 8\maddisAsm_.bpl
MOD - [2014-06-06 12:07:50 | 000,183,584 | ---- | M] () -- C:\Program Files (x86)\IObit\Start Menu 8\madbasic_.bpl
MOD - [2014-05-25 10:32:27 | 013,567,488 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Web\90285827b1300835ca1aaff1dff83a01\System.Web.ni.dll
MOD - [2014-05-25 10:32:21 | 001,160,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data86569bbf#\3d5b722235db7e8a8c7d1344c7221c33\System.Data.OracleClient.ni.dll
MOD - [2014-05-25 10:32:20 | 000,773,120 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Ente96d83b35#\65b4d38e24dfdd935b19ba1de243c244\System.EnterpriseServices.ni.dll
MOD - [2014-05-25 10:32:20 | 000,244,736 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Ente96d83b35#\65b4d38e24dfdd935b19ba1de243c244\System.EnterpriseServices.Wrapper.dll
MOD - [2014-05-25 10:32:18 | 000,146,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Numerics\8e945b32dd6b4b00c900f6c01c0f3c62\System.Numerics.ni.dll
MOD - [2014-05-14 10:41:49 | 000,797,184 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\3e17b0be5e7a03853d44d996d366e88b\System.Runtime.Remoting.ni.dll
MOD - [2014-05-14 10:41:48 | 001,928,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\fab34eeddd8d0d9679cce669b2cff4fe\Microsoft.VisualBasic.ni.dll
MOD - [2014-05-13 18:26:54 | 001,662,464 | ---- | M] () -- C:\Program Files (x86)\Raptr\PyQt4.QtCore.pyd
MOD - [2014-05-13 18:26:54 | 000,494,592 | ---- | M] () -- C:\Program Files (x86)\Raptr\PyQt4.QtNetwork.pyd
MOD - [2014-05-13 18:26:52 | 005,812,736 | ---- | M] () -- C:\Program Files (x86)\Raptr\PyQt4.QtGui.pyd
MOD - [2014-05-13 18:26:52 | 000,313,856 | ---- | M] () -- C:\Program Files (x86)\Raptr\PyQt4.QtWebKit.pyd
MOD - [2014-05-13 18:26:40 | 000,067,584 | ---- | M] () -- C:\Program Files (x86)\Raptr\sip.pyd
MOD - [2014-05-13 12:04:48 | 000,167,768 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2014-05-13 12:04:46 | 000,109,400 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2014-05-13 12:04:42 | 000,416,600 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2014-05-05 21:21:12 | 000,065,792 | ---- | M] () -- C:\Program Files\TortoiseSVN\bin\TortoiseStub32.dll
MOD - [2014-05-05 21:20:58 | 000,071,936 | ---- | M] () -- C:\Program Files\TortoiseSVN\bin\libsasl32.dll
MOD - [2014-04-30 06:30:05 | 000,188,416 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\3be4139a741b447ab35a2c788a2f4559\UIAutomationTypes.ni.dll
MOD - [2014-04-30 06:30:04 | 000,785,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\ee53227bcc4430088d0b560752c1cd02\System.ServiceModel.Internals.ni.dll
MOD - [2014-04-30 06:30:04 | 000,118,272 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\352d34797f7cd44cd0973c33539200f1\SMDiagnostics.ni.dll
MOD - [2014-04-29 06:33:55 | 007,802,880 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\77bc1a994f64193efc124c297b93fdb7\System.Xml.ni.dll
MOD - [2014-04-29 06:33:55 | 000,392,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\6f7a4225a199ad7894379512ca6ae50c\System.Xml.Linq.ni.dll
MOD - [2014-04-29 06:33:52 | 001,874,432 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xaml\10483ca149b5c651d217edbf2f3169b4\System.Xaml.ni.dll
MOD - [2014-04-29 06:33:51 | 012,856,832 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\635558b506364815e8348217e86fdf99\System.Windows.Forms.ni.dll
MOD - [2014-04-29 06:33:45 | 000,653,312 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\95c749867e5f72a09ed1e59a57931301\System.Transactions.ni.dll
MOD - [2014-04-29 06:33:45 | 000,219,136 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\5e015d37aa3fdc75648e9d00d44d13ac\System.ServiceProcess.ni.dll
MOD - [2014-04-29 06:33:44 | 019,566,080 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\4c3126aec3364546e4ade89c24c4e742\System.ServiceModel.ni.dll
MOD - [2014-04-29 06:33:35 | 002,804,736 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\183eaaded316165bfbd32a991e4e8c8a\System.Runtime.Serialization.ni.dll
MOD - [2014-04-29 06:33:32 | 001,635,328 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\ddb52221ad0200b7c2e0a308e47d5c7c\System.Drawing.ni.dll
MOD - [2014-04-29 06:33:32 | 001,169,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Management\d1e6b39e15536aaa5fb9b1cacf8b18aa\System.Management.ni.dll
MOD - [2014-04-29 06:33:31 | 007,385,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\8a7f63a63249ceccb5c51a9a372aaf64\System.Data.ni.dll
MOD - [2014-04-29 06:33:27 | 000,968,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\c5bf2f5c3e13726b3984a900221e1778\System.Configuration.ni.dll
MOD - [2014-04-29 06:33:26 | 018,744,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\92388fbe99436e6ed1f56ee56f10c565\PresentationFramework.ni.dll
MOD - [2014-04-29 06:33:26 | 000,463,360 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\e1c86f334a29d92ca264950085cd817e\PresentationFramework.Aero2.ni.dll
MOD - [2014-04-29 06:33:17 | 011,027,456 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PresentationCore\619034abb9a9fb1b3dc32c0a9aa38d3c\PresentationCore.ni.dll
MOD - [2014-04-29 06:33:12 | 003,957,760 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\WindowsBase\9bbf715cfb5360c95acd27b199083854\WindowsBase.ni.dll
MOD - [2014-04-29 06:33:08 | 006,951,424 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\c1194e56644c7688e7eb0f68a57dcc30\System.Core.ni.dll
MOD - [2014-04-29 06:33:05 | 010,003,456 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\c24d08cc4e93fc4f6f15a637b00a2721\System.ni.dll
MOD - [2014-03-18 05:06:40 | 017,395,376 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\c90ef9a73ea0044641d31b19023aad61\mscorlib.ni.dll
MOD - [2014-01-06 17:19:12 | 034,755,072 | ---- | M] () -- C:\Program Files (x86)\Razer\InGameEngine\32bit\libcef.dll
MOD - [2014-01-06 17:19:12 | 000,970,240 | ---- | M] () -- C:\Program Files (x86)\Razer\InGameEngine\32bit\ffmpegsumo.dll
MOD - [2013-11-20 19:05:26 | 000,256,000 | ---- | M] () -- C:\Program Files (x86)\Raptr\amd_ags.dll
MOD - [2013-11-12 09:57:10 | 000,098,304 | ---- | M] () -- C:\Program Files (x86)\Razer\Razer Game Booster\EasyHook32.dll
MOD - [2013-05-09 18:52:58 | 001,183,699 | ---- | M] () -- C:\Program Files (x86)\Raptr\liboscar.dll
MOD - [2013-05-09 18:52:58 | 000,483,306 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\libicq.dll
MOD - [2013-05-09 18:52:56 | 000,495,680 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\libaim.dll
MOD - [2013-05-03 13:57:16 | 001,640,221 | ---- | M] () -- C:\Program Files (x86)\Raptr\libjabber.dll
MOD - [2013-05-03 13:57:14 | 001,053,730 | ---- | M] () -- C:\Program Files (x86)\Raptr\libymsg.dll
MOD - [2013-05-03 13:57:06 | 000,655,356 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\libirc.dll
MOD - [2013-05-03 13:57:04 | 000,603,326 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\ssl-nss.dll
MOD - [2013-05-03 13:57:02 | 000,474,199 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\ssl.dll
MOD - [2013-05-03 13:57:00 | 000,497,782 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\libyahoojp.dll
MOD - [2013-05-03 13:56:50 | 001,306,387 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\libmsn.dll
MOD - [2013-05-03 13:56:46 | 000,565,461 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\libxmpp.dll
MOD - [2013-05-03 13:56:44 | 000,506,276 | ---- | M] () -- C:\Program Files (x86)\Raptr\plugins\libyahoo.dll
MOD - [2012-12-07 09:16:49 | 022,224,096 | ---- | M] () -- C:\Users\Stirling\AppData\Roaming\GameRanger\GameRanger Prefs\Components\libcef.dll
MOD - [2012-11-20 16:13:44 | 000,264,192 | ---- | M] () -- C:\Program Files (x86)\Razer\Razer Game Booster\D3DX8Wrapper.dll
MOD - [2012-03-23 05:15:58 | 000,988,160 | ---- | M] () -- C:\Program Files (x86)\Razer\Comms\libssh2.dll
MOD - [2012-03-02 03:23:26 | 000,577,621 | ---- | M] () -- C:\Program Files (x86)\Razer\Comms\sqlite3.dll
MOD - [2011-02-15 13:17:28 | 001,213,633 | ---- | M] () -- C:\Program Files (x86)\Raptr\libxml2-2.dll
MOD - [2011-02-15 13:17:28 | 000,417,501 | ---- | M] () -- C:\Program Files (x86)\Raptr\sqlite3.dll
MOD - [2010-11-22 18:06:22 | 000,055,808 | ---- | M] () -- C:\Program Files (x86)\Raptr\zlib1.dll
MOD - [2010-11-22 17:57:34 | 000,167,936 | ---- | M] () -- C:\Program Files (x86)\Raptr\win32gui.pyd
MOD - [2010-11-22 17:57:34 | 000,111,104 | ---- | M] () -- C:\Program Files (x86)\Raptr\win32file.pyd
MOD - [2010-11-22 17:57:34 | 000,096,256 | ---- | M] () -- C:\Program Files (x86)\Raptr\win32api.pyd
MOD - [2010-11-22 17:57:34 | 000,036,352 | ---- | M] () -- C:\Program Files (x86)\Raptr\win32process.pyd
MOD - [2010-11-22 17:57:34 | 000,016,384 | ---- | M] () -- C:\Program Files (x86)\Raptr\win32trace.pyd
MOD - [2010-11-22 17:57:18 | 000,141,312 | ---- | M] () -- C:\Program Files (x86)\Raptr\gobject._gobject.pyd
MOD - [2010-11-22 17:57:06 | 000,263,168 | ---- | M] () -- C:\Program Files (x86)\Raptr\win32com.shell.shell.pyd
MOD - [2010-11-22 17:56:56 | 000,354,304 | ---- | M] () -- C:\Program Files (x86)\Raptr\pythoncom26.dll
MOD - [2010-11-22 17:56:56 | 000,110,592 | ---- | M] () -- C:\Program Files (x86)\Raptr\pywintypes26.dll
MOD - [2010-11-22 17:56:26 | 000,324,608 | ---- | M] () -- C:\Program Files (x86)\Raptr\PIL._imaging.pyd
MOD - [2010-11-22 17:56:02 | 000,805,376 | ---- | M] () -- C:\Program Files (x86)\Raptr\_ssl.pyd
MOD - [2010-11-22 17:56:02 | 000,583,680 | ---- | M] () -- C:\Program Files (x86)\Raptr\unicodedata.pyd
MOD - [2010-11-22 17:56:02 | 000,356,864 | ---- | M] () -- C:\Program Files (x86)\Raptr\_hashlib.pyd
MOD - [2010-11-22 17:56:02 | 000,127,488 | ---- | M] () -- C:\Program Files (x86)\Raptr\pyexpat.pyd
MOD - [2010-11-22 17:56:02 | 000,087,040 | ---- | M] () -- C:\Program Files (x86)\Raptr\_ctypes.pyd
MOD - [2010-11-22 17:56:02 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\Raptr\_sqlite3.pyd
MOD - [2010-11-22 17:56:02 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\Raptr\_socket.pyd
MOD - [2010-11-22 17:56:02 | 000,010,240 | ---- | M] () -- C:\Program Files (x86)\Raptr\select.pyd
MOD - [2010-11-22 17:56:02 | 000,009,216 | ---- | M] () -- C:\Program Files (x86)\Raptr\winsound.pyd
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014-08-14 08:41:13 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014-08-11 23:06:14 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2014-08-11 21:00:38 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2014-07-15 16:51:59 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2014-04-29 03:02:12 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:64bit: - [2014-04-29 03:02:12 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2014-04-06 06:20:36 | 000,201,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2014-04-02 21:51:48 | 001,584,128 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:64bit: - [2014-03-23 21:31:14 | 000,347,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:64bit: - [2014-03-23 21:31:14 | 000,023,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:64bit: - [2014-03-18 05:06:26 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2014-03-18 05:06:25 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:64bit: - [2014-03-18 05:06:21 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2014-03-18 05:06:20 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2014-03-18 05:06:18 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2014-03-18 05:06:16 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2014-03-18 05:06:16 | 000,269,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2014-03-18 05:06:13 | 000,282,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2014-03-18 04:43:28 | 000,183,296 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2014-03-18 04:43:27 | 000,090,464 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\KeyboardFilterSvc.dll -- (MsKeyboardFilter)
SRV:64bit: - [2014-03-14 01:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:64bit: - [2013-08-22 07:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2013-08-22 06:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:64bit: - [2013-08-22 06:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2013-08-22 06:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2013-08-22 06:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2013-08-22 06:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2013-08-22 05:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2013-08-22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2013-08-22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2013-08-22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2013-08-22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2013-08-22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2013-08-22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2013-08-22 05:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:64bit: - [2013-08-22 05:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:64bit: - [2013-08-22 04:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:64bit: - [2013-08-22 04:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2013-08-22 04:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2013-08-22 04:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2013-08-22 04:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:64bit: - [2013-08-22 04:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2013-08-22 04:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2013-08-22 04:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2013-07-26 05:48:28 | 000,230,416 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Common Files\Nitro\Reader\3.0\NitroPDFReaderDriverService3x64.exe -- (NitroReaderDriverReadSpool3)
SRV - [2014-08-10 15:06:52 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014-07-31 17:55:55 | 000,262,320 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014-07-26 19:12:47 | 000,477,960 | ---- | M] (BitRaider, LLC) [On_Demand | Stopped] -- C:\ProgramData\BitRaider\BRSptSvc.exe -- (BRSptSvc)
SRV - [2014-07-15 21:28:18 | 000,542,912 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014-07-15 15:48:19 | 000,175,808 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe -- (Razer Game Scanner Service)
SRV - [2014-07-07 08:23:28 | 000,107,552 | ---- | M] (EasyAntiCheat Ltd) [On_Demand | Stopped] -- C:\Windows\SysWOW64\EasyAntiCheat.exe -- (EasyAntiCheat)
SRV - [2014-06-21 08:33:43 | 002,175,264 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe -- (LiveUpdateSvc)
SRV - [2014-06-20 19:02:22 | 001,655,136 | ---- | M] (LULU SOFTWARE LIMITED) [On_Demand | Stopped] -- C:\Program Files (x86)\Soda PDF 6\ws.exe -- (Soda PDF 6)
SRV - [2014-06-20 19:02:22 | 000,744,800 | ---- | M] (LULU SOFTWARE LIMITED) [On_Demand | Stopped] -- C:\Program Files (x86)\Soda PDF 6\crash-handler-ws.exe -- (LULU Software CrashHandler)
SRV - [2014-06-09 04:49:00 | 004,250,624 | ---- | M] (A-Volute) [Auto | Running] -- C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe -- (RzMaelstromVADStreamingService)
SRV - [2014-06-06 12:08:12 | 000,072,992 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe -- (StartMenuService)
SRV - [2014-03-14 01:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2014-03-11 16:44:52 | 000,241,728 | ---- | M] (Foxit Corporation) [Auto | Running] -- C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe -- (FoxitCloudUpdateService)
SRV - [2014-02-25 19:38:48 | 000,105,448 | ---- | M] (Razer Inc.) [Auto | Running] -- C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe -- (RzKLService)
SRV - [2014-01-12 13:07:40 | 000,438,272 | ---- | M] (PowerUp Software, LLC) [Auto | Stopped] -- C:\Program Files (x86)\PowerUp Software\Pinnacle Game Profiler\pinnacle_updater.exe -- (PinnacleUpdateSvc)
SRV - [2013-12-21 01:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013-10-23 07:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013-08-22 07:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2013-08-21 22:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013-08-21 21:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014-08-11 22:24:16 | 015,961,088 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2014-08-11 20:33:58 | 000,557,056 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2014-07-15 16:52:03 | 000,427,360 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP)
DRV:64bit: - [2014-07-15 16:52:00 | 001,041,168 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:64bit: - [2014-07-15 16:52:00 | 000,224,896 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014-07-15 16:52:00 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014-07-15 16:52:00 | 000,092,008 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswstm.sys -- (aswStm)
DRV:64bit: - [2014-07-15 16:52:00 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2014-07-15 16:52:00 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2014-07-15 16:52:00 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2014-07-15 15:47:53 | 000,037,184 | ---- | M] (Razer, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rzpmgrk.sys -- (rzpmgrk)
DRV:64bit: - [2014-07-03 05:52:53 | 000,129,856 | ---- | M] (Razer, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rzpnk.sys -- (rzpnk)
DRV:64bit: - [2014-06-09 04:49:00 | 000,032,768 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RzMaelstromVAD.sys -- (RZMAELSTROMVADService)
DRV:64bit: - [2014-05-31 05:07:07 | 000,467,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2014-05-19 01:47:28 | 000,155,816 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd)
DRV:64bit: - [2014-05-01 08:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2014-04-29 03:02:12 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2014-04-29 03:02:12 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:64bit: - [2014-04-29 03:02:12 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2014-04-28 22:13:47 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014-04-01 01:23:41 | 000,384,856 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2014-03-23 21:30:57 | 000,257,880 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2014-03-23 21:30:57 | 000,123,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:64bit: - [2014-03-23 21:27:03 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2014-03-18 05:06:20 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:64bit: - [2014-03-18 05:06:17 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:64bit: - [2014-03-18 05:06:17 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2014-03-18 05:06:05 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2014-03-18 05:06:04 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2014-03-18 05:06:04 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2014-03-18 05:06:04 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2014-03-18 05:06:04 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:64bit: - [2014-03-18 05:06:04 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2014-03-18 05:06:04 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:64bit: - [2014-03-18 05:06:04 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:64bit: - [2014-03-18 05:06:04 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2014-03-18 04:43:29 | 000,022,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\kbldfltr.sys -- (kbldfltr)
DRV:64bit: - [2014-03-18 04:43:28 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2014-03-18 04:43:17 | 000,220,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Vid.sys -- (Vid)
DRV:64bit: - [2014-03-18 04:43:17 | 000,129,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbusr.sys -- (vmbusr)
DRV:64bit: - [2014-03-18 04:43:17 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsp.sys -- (storvsp)
DRV:64bit: - [2014-03-18 04:43:17 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcivsp.sys -- (vpcivsp)
DRV:64bit: - [2014-03-18 04:43:17 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2014-03-18 03:18:42 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb22.sys -- (xusb22)
DRV:64bit: - [2014-03-11 09:20:04 | 000,222,720 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdWB6.sys -- (AtiHDAudioService)
DRV:64bit: - [2014-02-16 11:23:54 | 000,060,640 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2014-02-11 17:36:52 | 000,059,616 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.3)
DRV:64bit: - [2014-01-22 08:52:12 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudserd.sys -- (ssudserd)
DRV:64bit: - [2014-01-22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2014-01-22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2014-01-21 12:11:20 | 000,025,800 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2014-01-21 12:11:18 | 000,081,608 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2013-08-22 08:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:64bit: - [2013-08-22 08:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2013-08-22 07:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:64bit: - [2013-08-22 07:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2013-08-22 07:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2013-08-22 07:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2013-08-22 07:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2013-08-22 07:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2013-08-22 07:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2013-08-22 07:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2013-08-22 07:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2013-08-22 07:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:64bit: - [2013-08-22 07:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:64bit: - [2013-08-22 07:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2013-08-22 07:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2013-08-22 07:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:64bit: - [2013-08-22 07:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2013-08-22 07:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2013-08-22 07:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2013-08-22 07:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2013-08-22 07:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2013-08-22 07:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2013-08-22 07:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2013-08-22 07:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013-08-22 07:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2013-08-22 07:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2013-08-22 07:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:64bit: - [2013-08-22 07:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:64bit: - [2013-08-22 07:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2013-08-22 06:39:58 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2013-08-22 06:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:64bit: - [2013-08-22 06:39:50 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2013-08-22 06:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2013-08-22 06:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2013-08-22 06:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2013-08-22 06:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2013-08-22 06:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2013-08-22 06:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013-08-22 06:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2013-08-22 06:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2013-08-22 06:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2013-08-22 06:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2013-08-22 06:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2013-08-22 06:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2013-08-22 06:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2013-08-22 06:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013-08-22 06:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2013-08-22 06:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2013-08-22 06:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:64bit: - [2013-08-22 06:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:64bit: - [2013-08-22 06:36:17 | 000,124,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2013-08-22 06:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2013-08-22 06:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2013-08-22 05:27:46 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2013-08-22 03:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2013-08-12 18:25:46 | 000,017,624 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:64bit: - [2013-08-09 19:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:64bit: - [2013-07-30 13:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:64bit: - [2013-07-25 14:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:64bit: - [2013-06-18 09:46:17 | 000,591,360 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2012-09-22 21:17:22 | 000,021,160 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdkmafd.sys -- (amdkmafd)
DRV:64bit: - [2009-12-30 09:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2021.112
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.23
FF - prefs.js..extensions.enabledAddons: %7Bcd617375-6743-4ee8-bac4-fbf10f35729e%7D:2.9.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.5.2: C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.5.2: C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro\Reader 3\npnitromozilla.dll (Nitro PDF)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Soda PDF 6: C:\Program Files (x86)\Soda PDF 6\np-previewer.dll (LULU SOFTWARE LIMITED)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Stirling\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Stirling\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Stirling\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Stirling\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Stirling\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-07-15 16:52:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.6.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.6.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
 
[2014-04-23 22:38:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stirling\AppData\Roaming\mozilla\Extensions
[2014-08-22 23:17:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stirling\AppData\Roaming\mozilla\Firefox\Profiles\6be3n573.default\extensions
[2014-08-13 13:23:19 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Stirling\AppData\Roaming\mozilla\Firefox\Profiles\6be3n573.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014-08-22 23:17:37 | 000,414,727 | ---- | M] () (No name found) -- C:\Users\Stirling\AppData\Roaming\mozilla\firefox\profiles\6be3n573.default\extensions\[email protected]
[2014-08-22 23:14:24 | 000,065,849 | ---- | M] () (No name found) -- C:\Users\Stirling\AppData\Roaming\mozilla\firefox\profiles\6be3n573.default\extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi
[2014-08-03 22:53:44 | 000,967,685 | ---- | M] () (No name found) -- C:\Users\Stirling\AppData\Roaming\mozilla\firefox\profiles\6be3n573.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-08-10 15:06:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014-08-10 15:06:53 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014-07-15 16:52:00 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = http://suggest.secci...={searchTerms},
CHR - homepage: http://www.google.ca/
CHR - plugin: Error reading preferences file
CHR - Extension: Chrome Currency Converter = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\anbfhidldjknonaihbalghlebaijealk\4.3.2_0\
CHR - Extension: Google Docs = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: YouTube = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.7.12_0\
CHR - Extension: Hola Better Internet = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio\1.4.431_0\
CHR - Extension: Crackle = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic\7.1.7_0\
CHR - Extension: Steam Market Auto-Agree = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlicldafjdigokihkkdlbpfgehihjodl\1.1_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.5.0.2_0\
CHR - Extension: Google Wallet = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Enhanced Steam = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\6.6_0\
CHR - Extension: SpeakIt! = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgeolalilifpodheeocdmbhehgnkkbak\0.2.93_0\
CHR - Extension: Gmail = C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2014-08-17 17:18:53 | 000,450,709 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15469 more lines...
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Razer StarcraftII Driver] C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray.exe (Razer USA Ltd)
O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
O4 - HKLM..\Run: [RazerGameBooster] C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe (Razer Inc.)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKCU..\Run: [DeadIslandRiptideHelper] C:\Games\Steam\SteamApps\common\diriptide\Dead Island - Riptide Helper.exe (Microsoft)
O4 - HKCU..\Run: [Device Doctor] C:\Program Files (x86)\Device Doctor\DDLauncher.exe (Device Doctor Software Inc.)
O4 - HKCU..\Run: [EADM] C:\Games\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [Gadwin PrintScreen (64-bit)] C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe (Gadwin Systems)
O4 - HKCU..\Run: [Raptr] C:\Program Files (x86)\Raptr\raptrstub.exe (Raptr, Inc)
O4 - HKCU..\Run: [Razer Comms] C:\Program Files (x86)\Razer\Comms\ChatApplet.exe (Razer Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Users\Stirling\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - Startup: C:\Users\Stirling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O4 - Startup: C:\Users\Stirling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameRanger.lnk = C:\Users\Stirling\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe (GameRanger Technologies)
O4 - Startup: C:\Users\Stirling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Steam.exe.lnk = C:\Games\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()
O8 - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.100.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E874055-8F56-4A06-86A0-68445774ED0C}: DhcpNameServer = 192.168.100.254
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) -  File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) -  File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014-08-24 01:27:13 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2014-08-24 01:27:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014-08-24 01:27:06 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbamchameleon.sys
[2014-08-24 01:27:06 | 000,064,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mwac.sys
[2014-08-24 01:27:06 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\mbam.sys
[2014-08-24 01:27:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014-08-24 01:27:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014-08-24 01:10:39 | 000,000,000 | ---D | C] -- E:\User\Documents\Alpha Protocol
[2014-08-23 19:09:06 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\TS3Client
[2014-08-23 19:09:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
[2014-08-23 19:09:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamSpeak 3 Client
[2014-08-23 10:56:33 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\Razer_Inc
[2014-08-23 10:56:27 | 000,000,000 | ---D | C] -- E:\User\Documents\Razer
[2014-08-22 17:42:28 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\CrashDumps
[2014-08-22 10:03:24 | 000,000,000 | ---D | C] -- E:\User\Documents\RIFT
[2014-08-22 10:03:24 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\RIFT
[2014-08-22 10:00:30 | 000,129,856 | ---- | C] (Razer, Inc.) -- C:\WINDOWS\SysNative\drivers\rzpnk.sys
[2014-08-22 10:00:24 | 000,037,184 | ---- | C] (Razer, Inc.) -- C:\WINDOWS\SysNative\drivers\rzpmgrk.sys
[2014-08-20 17:39:45 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\Cyberlink
[2014-08-20 17:35:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nikon
[2014-08-20 17:31:17 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2014-08-20 17:31:11 | 000,000,000 | ---D | C] -- C:\ProgramData\install_clap
[2014-08-19 10:15:36 | 000,000,000 | ---D | C] -- C:\ProgramData\RzMaelstromVAD_1.1.58.1854
[2014-08-18 10:14:38 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2014-08-18 10:09:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2014-08-18 10:09:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2014-08-18 10:09:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
[2014-08-17 15:14:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2014-08-17 15:14:18 | 000,021,040 | ---- | C] (Safer Networking Limited) -- C:\WINDOWS\SysNative\sdnclean64.exe
[2014-08-17 15:14:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2014-08-17 15:10:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2014-08-17 15:10:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2014-08-15 12:09:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III
[2014-08-15 11:54:40 | 000,000,000 | ---D | C] -- C:\Users\Stirling\Warcraft III 1.21b ROC Installer enUS
[2014-08-14 10:22:07 | 000,000,000 | ---D | C] -- C:\Latency Fix
[2014-08-14 08:45:36 | 002,001,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\inetcpl.cpl
[2014-08-14 08:45:35 | 000,631,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msfeeds.dll
[2014-08-14 08:45:34 | 002,087,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\inetcpl.cpl
[2014-08-14 08:45:33 | 000,452,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtmsft.dll
[2014-08-14 08:45:32 | 000,758,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9diag.dll
[2014-08-14 08:45:32 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieapfltr.dll
[2014-08-14 08:45:32 | 000,292,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxtrans.dll
[2014-08-14 08:45:32 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mshtmled.dll
[2014-08-14 08:45:31 | 005,824,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\jscript9.dll
[2014-08-14 08:45:31 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieapfltr.dll
[2014-08-14 08:45:30 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\jscript9diag.dll
[2014-08-14 08:45:30 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mshtmled.dll
[2014-08-14 08:45:24 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ie4uinit.exe
[2014-08-14 08:45:24 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vbscript.dll
[2014-08-14 08:45:24 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MshtmlDac.dll
[2014-08-14 08:45:24 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\JavaScriptCollectionAgent.dll
[2014-08-14 08:45:24 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MshtmlDac.dll
[2014-08-14 08:45:24 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\JavaScriptCollectionAgent.dll
[2014-08-14 08:45:23 | 001,273,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rpcrt4.dll
[2014-08-14 08:45:22 | 002,133,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dwmcore.dll
[2014-08-14 08:45:22 | 000,517,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dxgi.dll
[2014-08-14 08:44:46 | 003,118,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Wpc.dll
[2014-08-14 08:44:46 | 003,048,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcMon.exe
[2014-08-14 08:44:45 | 002,861,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WpcWebSync.dll
[2014-08-14 08:44:45 | 002,344,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Wpc.dll
[2014-08-14 08:44:44 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\TsWpfWrp.exe
[2014-08-14 08:44:44 | 000,035,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\TsWpfWrp.exe
[2014-08-14 08:44:39 | 004,756,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SyncEngine.dll
[2014-08-14 08:44:39 | 001,120,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDrive.exe
[2014-08-14 08:44:39 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveTelemetry.dll
[2014-08-14 08:44:35 | 002,144,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\mfcore.dll
[2014-08-14 08:44:35 | 002,140,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfcore.dll
[2014-08-14 08:44:35 | 002,125,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3d9.dll
[2014-08-14 08:44:34 | 002,844,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\actxprxy.dll
[2014-08-14 08:44:34 | 001,726,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ntdll.dll
[2014-08-14 08:44:34 | 001,025,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\localspl.dll
[2014-08-14 08:44:34 | 000,721,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fveapi.dll
[2014-08-14 08:44:34 | 000,403,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\vpnike.dll
[2014-08-14 08:44:34 | 000,301,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\framedynos.dll
[2014-08-14 08:44:34 | 000,285,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\SkyDriveShell.dll
[2014-08-14 08:44:34 | 000,265,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\SkyDriveShell.dll
[2014-08-14 08:44:33 | 000,271,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpcore6.dll
[2014-08-14 08:44:33 | 000,262,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\framedyn.dll
[2014-08-14 08:44:33 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\framedynos.dll
[2014-08-14 08:44:33 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\dhcpcore6.dll
[2014-08-14 08:44:33 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Robocopy.exe
[2014-08-14 08:44:33 | 000,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\winbici.dll
[2014-08-14 08:44:33 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Robocopy.exe
[2014-08-14 08:44:33 | 000,071,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ncobjapi.dll
[2014-08-14 08:44:33 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\dhcpcsvc6.dll
[2014-08-14 08:44:33 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ncobjapi.dll
[2014-08-14 08:44:32 | 000,997,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\reseteng.dll
[2014-08-14 08:44:32 | 000,794,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fvewiz.dll
[2014-08-14 08:44:32 | 000,311,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\fvecpl.dll
[2014-08-14 08:44:32 | 000,207,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\framedyn.dll
[2014-08-14 08:44:32 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BdeHdCfg.exe
[2014-08-14 08:44:32 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BdeHdCfgLib.dll
[2014-08-14 08:44:32 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\BulkOperationHost.exe
[2014-08-14 08:44:22 | 000,697,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-08-14 08:44:22 | 000,527,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-08-14 08:44:19 | 016,871,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\Windows.UI.Xaml.dll
[2014-08-14 08:44:18 | 012,711,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\Windows.UI.Xaml.dll
[2014-08-14 08:44:18 | 000,668,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gpprefcl.dll
[2014-08-14 08:44:18 | 000,590,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\gpprefcl.dll
[2014-08-14 08:44:18 | 000,440,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbport.sys
[2014-08-14 08:44:18 | 000,216,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\rsaenh.dll
[2014-08-14 08:44:17 | 000,655,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\cscui.dll
[2014-08-14 08:44:17 | 000,467,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\USBHUB3.SYS
[2014-08-14 08:44:17 | 000,423,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\hal.dll
[2014-08-14 08:44:17 | 000,323,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\DaOtpCredentialProvider.dll
[2014-08-14 08:44:17 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUDFHost.exe
[2014-08-14 08:44:17 | 000,270,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\DaOtpCredentialProvider.dll
[2014-08-14 08:44:17 | 000,209,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WUDFPlatform.dll
[2014-08-14 08:44:17 | 000,027,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\usbd.sys
[2014-08-14 08:43:06 | 000,623,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MDMAgent.exe
[2014-08-14 08:43:05 | 000,918,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2014-08-14 08:43:02 | 001,336,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2014-08-14 08:42:32 | 002,790,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msi.dll
[2014-08-14 08:42:32 | 002,642,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\authui.dll
[2014-08-14 08:42:32 | 002,318,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\authui.dll
[2014-08-14 08:42:32 | 000,356,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msihnd.dll
[2014-08-14 08:42:32 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msihnd.dll
[2014-08-14 08:42:32 | 000,114,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\consent.exe
[2014-08-14 08:11:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
[2014-08-14 08:04:53 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\Blizzard Entertainment
[2014-08-14 08:04:52 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\Battle.net
[2014-08-14 08:04:52 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\Battle.net
[2014-08-14 08:04:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2014-08-14 08:04:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Blizzard Entertainment
[2014-08-14 08:04:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
[2014-08-14 08:00:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net
[2014-08-13 13:34:45 | 000,000,000 | ---D | C] -- C:\SpaceSniffer
[2014-08-11 22:32:34 | 000,127,872 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\amdhcp64.dll
[2014-08-11 22:32:30 | 000,078,432 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atimpc64.dll
[2014-08-11 22:32:30 | 000,071,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atimpc32.dll
[2014-08-11 22:32:26 | 000,078,432 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdpcom64.dll
[2014-08-11 22:32:26 | 000,071,704 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdpcom32.dll
[2014-08-11 22:28:48 | 000,276,192 | ---- | C] (Advanced Micro Devices) -- C:\WINDOWS\SysNative\drivers\amdacpksd.sys
[2014-08-11 22:24:16 | 015,961,088 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\atikmdag.sys
[2014-08-11 22:09:48 | 000,098,816 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\OpenVideo64.dll
[2014-08-11 22:09:40 | 000,083,456 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\OpenVideo.dll
[2014-08-11 22:09:34 | 000,086,528 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\OVDecode64.dll
[2014-08-11 22:09:30 | 000,073,216 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\OVDecode.dll
[2014-08-11 22:09:24 | 032,877,056 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\amdocl64.dll
[2014-08-11 22:06:20 | 027,843,072 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\amdocl.dll
[2014-08-11 22:03:26 | 000,065,024 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.dll
[2014-08-11 22:03:22 | 000,058,880 | ---- | C] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.dll
[2014-08-11 21:51:08 | 000,127,488 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\mantle64.dll
[2014-08-11 21:50:48 | 000,113,664 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\mantle32.dll
[2014-08-11 21:50:26 | 005,225,472 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdmantle64.dll
[2014-08-11 21:44:12 | 027,529,216 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atio6axx.dll
[2014-08-11 21:34:14 | 004,180,992 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdmantle32.dll
[2014-08-11 21:24:04 | 023,028,224 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\atioglxx.dll
[2014-08-11 21:20:00 | 000,091,648 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\mantleaxl64.dll
[2014-08-11 21:19:48 | 000,085,504 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\mantleaxl32.dll
[2014-08-11 21:18:48 | 000,366,592 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atiapfxx.exe
[2014-08-11 21:18:40 | 000,062,464 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticalrt64.dll
[2014-08-11 21:18:38 | 000,052,224 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticalrt.dll
[2014-08-11 21:18:30 | 000,055,808 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticalcl64.dll
[2014-08-11 21:18:28 | 000,049,152 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticalcl.dll
[2014-08-11 21:18:14 | 015,716,352 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticaldd64.dll
[2014-08-11 21:14:58 | 014,302,208 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticaldd.dll
[2014-08-11 21:01:34 | 000,442,368 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atidemgy.dll
[2014-08-11 21:01:20 | 000,031,232 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\atimuixx.dll
[2014-08-11 21:01:10 | 000,588,800 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\atieclxx.exe
[2014-08-11 21:00:38 | 000,239,616 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\atiesrxx.exe
[2014-08-11 20:59:34 | 000,190,976 | ---- | C] (AMD) -- C:\WINDOWS\SysNative\atitmm64.dll
[2014-08-11 20:57:56 | 000,048,128 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdmmcl6.dll
[2014-08-11 20:57:50 | 000,037,888 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdmmcl.dll
[2014-08-11 20:34:56 | 001,207,296 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atiadlxx.dll
[2014-08-11 20:34:46 | 000,898,560 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\atiadlxy.dll
[2014-08-11 20:34:32 | 000,075,264 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atig6pxx.dll
[2014-08-11 20:34:28 | 000,069,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiglpxx.dll
[2014-08-11 20:34:28 | 000,069,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiglpxx.dll
[2014-08-11 20:34:26 | 000,146,944 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atig6txx.dll
[2014-08-11 20:34:12 | 000,133,632 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atigktxx.dll
[2014-08-11 20:34:12 | 000,095,744 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdave64.dll
[2014-08-11 20:33:58 | 000,557,056 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\atikmpag.sys
[2014-08-11 20:33:54 | 000,089,088 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atisamu64.dll
[2014-08-11 20:33:48 | 000,080,896 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atisamu32.dll
[2014-08-11 20:32:04 | 000,043,520 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\ati2erec.dll
[2014-08-11 16:53:19 | 002,526,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_43.dll
[2014-08-11 16:53:19 | 002,106,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_43.dll
[2014-08-11 16:53:19 | 000,527,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_7.dll
[2014-08-11 16:53:19 | 000,518,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_7.dll
[2014-08-11 16:53:19 | 000,239,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_7.dll
[2014-08-11 16:53:19 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_7.dll
[2014-08-11 16:53:19 | 000,077,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_5.dll
[2014-08-11 16:53:19 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_5.dll
[2014-08-11 16:53:18 | 002,401,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_43.dll
[2014-08-11 16:53:18 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_43.dll
[2014-08-11 16:53:18 | 001,907,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dcsx_43.dll
[2014-08-11 16:53:18 | 001,868,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dcsx_43.dll
[2014-08-11 16:53:18 | 000,511,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_43.dll
[2014-08-11 16:53:18 | 000,470,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_43.dll
[2014-08-11 16:53:18 | 000,276,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx11_43.dll
[2014-08-11 16:53:18 | 000,248,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx11_43.dll
[2014-08-11 16:53:17 | 002,582,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_42.dll
[2014-08-11 16:53:17 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_42.dll
[2014-08-11 16:53:17 | 000,530,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_6.dll
[2014-08-11 16:53:17 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_6.dll
[2014-08-11 16:53:17 | 000,517,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_5.dll
[2014-08-11 16:53:17 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_5.dll
[2014-08-11 16:53:17 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_6.dll
[2014-08-11 16:53:17 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_5.dll
[2014-08-11 16:53:17 | 000,176,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_6.dll
[2014-08-11 16:53:17 | 000,176,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_5.dll
[2014-08-11 16:53:17 | 000,078,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_4.dll
[2014-08-11 16:53:17 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_4.dll
[2014-08-11 16:53:17 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_7.dll
[2014-08-11 16:53:17 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_7.dll
[2014-08-11 16:53:16 | 005,554,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dcsx_42.dll
[2014-08-11 16:53:16 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dcsx_42.dll
[2014-08-11 16:53:16 | 000,523,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_42.dll
[2014-08-11 16:53:16 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_42.dll
[2014-08-11 16:53:16 | 000,285,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx11_42.dll
[2014-08-11 16:53:16 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx11_42.dll
[2014-08-11 16:53:15 | 005,425,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_41.dll
[2014-08-11 16:53:15 | 002,475,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_42.dll
[2014-08-11 16:53:15 | 002,430,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_41.dll
[2014-08-11 16:53:15 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_42.dll
[2014-08-11 16:53:15 | 000,520,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_41.dll
[2014-08-11 16:53:14 | 002,605,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_40.dll
[2014-08-11 16:53:14 | 000,521,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_4.dll
[2014-08-11 16:53:14 | 000,519,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_40.dll
[2014-08-11 16:53:14 | 000,174,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_4.dll
[2014-08-11 16:53:14 | 000,073,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_3.dll
[2014-08-11 16:53:14 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_3.dll
[2014-08-11 16:53:14 | 000,024,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_6.dll
[2014-08-11 16:53:13 | 005,631,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_40.dll
[2014-08-11 16:53:13 | 000,518,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_3.dll
[2014-08-11 16:53:13 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_3.dll
[2014-08-11 16:53:13 | 000,513,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_2.dll
[2014-08-11 16:53:13 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_2.dll
[2014-08-11 16:53:13 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_2.dll
[2014-08-11 16:53:13 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_3.dll
[2014-08-11 16:53:13 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_2.dll
[2014-08-11 16:53:13 | 000,175,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_3.dll
[2014-08-11 16:53:13 | 000,074,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_2.dll
[2014-08-11 16:53:13 | 000,072,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_1.dll
[2014-08-11 16:53:13 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_2.dll
[2014-08-11 16:53:13 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_1.dll
[2014-08-11 16:53:13 | 000,025,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_5.dll
[2014-08-11 16:53:13 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_5.dll
[2014-08-11 16:53:12 | 004,992,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_39.dll
[2014-08-11 16:53:12 | 001,942,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_39.dll
[2014-08-11 16:53:12 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_39.dll
[2014-08-11 16:53:12 | 000,511,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_1.dll
[2014-08-11 16:53:12 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_1.dll
[2014-08-11 16:53:12 | 000,068,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAPOFX1_0.dll
[2014-08-11 16:53:11 | 004,991,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_38.dll
[2014-08-11 16:53:11 | 001,941,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_38.dll
[2014-08-11 16:53:11 | 000,540,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_38.dll
[2014-08-11 16:53:11 | 000,489,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\XAudio2_0.dll
[2014-08-11 16:53:11 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_4.dll
[2014-08-11 16:53:10 | 004,910,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DX9_37.dll
[2014-08-11 16:53:10 | 001,860,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_37.dll
[2014-08-11 16:53:10 | 000,529,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_37.dll
[2014-08-11 16:53:10 | 000,177,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine3_0.dll
[2014-08-11 16:53:10 | 000,028,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_3.dll
[2014-08-11 16:53:09 | 005,081,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_36.dll
[2014-08-11 16:53:09 | 002,006,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_36.dll
[2014-08-11 16:53:09 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_36.dll
[2014-08-11 16:53:09 | 000,411,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_10.dll
[2014-08-11 16:53:09 | 000,411,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_9.dll
[2014-08-11 16:53:08 | 005,073,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_35.dll
[2014-08-11 16:53:08 | 001,985,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_35.dll
[2014-08-11 16:53:08 | 000,508,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_35.dll
[2014-08-11 16:53:08 | 000,409,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_8.dll
[2014-08-11 16:53:08 | 000,021,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\X3DAudio1_2.dll
[2014-08-11 16:53:07 | 004,496,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_34.dll
[2014-08-11 16:53:07 | 001,401,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_34.dll
[2014-08-11 16:53:07 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_34.dll
[2014-08-11 16:53:07 | 000,403,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_7.dll
[2014-08-11 16:53:07 | 000,107,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xinput1_3.dll
[2014-08-11 16:53:06 | 004,494,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_33.dll
[2014-08-11 16:53:06 | 001,400,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\D3DCompiler_33.dll
[2014-08-11 16:53:06 | 000,506,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10_33.dll
[2014-08-11 16:53:06 | 000,393,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_6.dll
[2014-08-11 16:53:06 | 000,390,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_5.dll
[2014-08-11 16:53:05 | 004,398,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_32.dll
[2014-08-11 16:53:05 | 003,977,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_31.dll
[2014-08-11 16:53:05 | 000,469,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx10.dll
[2014-08-11 16:53:05 | 000,364,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_4.dll
[2014-08-11 16:53:05 | 000,017,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\x3daudio1_1.dll
[2014-08-11 16:53:04 | 000,363,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_3.dll
[2014-08-11 16:53:04 | 000,354,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_2.dll
[2014-08-11 16:53:04 | 000,352,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_1.dll
[2014-08-11 16:53:04 | 000,083,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xinput1_2.dll
[2014-08-11 16:53:04 | 000,083,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xinput1_1.dll
[2014-08-11 16:53:02 | 003,927,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_30.dll
[2014-08-11 16:53:02 | 003,830,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_29.dll
[2014-08-11 16:53:02 | 000,355,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\xactengine2_0.dll
[2014-08-11 16:53:02 | 000,016,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\x3daudio1_0.dll
[2014-08-11 16:53:01 | 003,815,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_28.dll
[2014-08-11 16:53:01 | 003,807,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_27.dll
[2014-08-11 16:53:00 | 003,823,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_25.dll
[2014-08-11 16:53:00 | 003,767,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_26.dll
[2014-08-11 16:53:00 | 003,544,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\d3dx9_24.dll
[2014-08-11 09:34:46 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_41.dll
[2014-08-11 09:34:46 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_41.dll
[2014-08-11 09:34:46 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_4.dll
[2014-08-11 09:34:46 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_41.dll
[2014-08-11 09:34:46 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_4.dll
[2014-08-11 09:34:46 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_6.dll
[2014-08-11 09:34:45 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_40.dll
[2014-08-11 09:34:45 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_39.dll
[2014-08-11 09:34:45 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_40.dll
[2014-08-11 09:34:45 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_39.dll
[2014-08-11 09:34:45 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_1.dll
[2014-08-11 09:34:45 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_39.dll
[2014-08-11 09:34:45 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_40.dll
[2014-08-11 09:34:45 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_1.dll
[2014-08-11 09:34:45 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAPOFX1_0.dll
[2014-08-11 09:34:44 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_38.dll
[2014-08-11 09:34:44 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DX9_37.dll
[2014-08-11 09:34:44 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_38.dll
[2014-08-11 09:34:44 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_37.dll
[2014-08-11 09:34:44 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\XAudio2_0.dll
[2014-08-11 09:34:44 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_38.dll
[2014-08-11 09:34:44 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_37.dll
[2014-08-11 09:34:44 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_10.dll
[2014-08-11 09:34:44 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine3_0.dll
[2014-08-11 09:34:44 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_4.dll
[2014-08-11 09:34:44 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_3.dll
[2014-08-11 09:34:43 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_36.dll
[2014-08-11 09:34:43 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_35.dll
[2014-08-11 09:34:43 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_36.dll
[2014-08-11 09:34:43 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_35.dll
[2014-08-11 09:34:43 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_34.dll
[2014-08-11 09:34:43 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_36.dll
[2014-08-11 09:34:43 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_35.dll
[2014-08-11 09:34:43 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_34.dll
[2014-08-11 09:34:43 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_9.dll
[2014-08-11 09:34:43 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_8.dll
[2014-08-11 09:34:43 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\X3DAudio1_2.dll
[2014-08-11 09:34:42 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_34.dll
[2014-08-11 09:34:42 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_33.dll
[2014-08-11 09:34:42 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_32.dll
[2014-08-11 09:34:42 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_31.dll
[2014-08-11 09:34:42 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\D3DCompiler_33.dll
[2014-08-11 09:34:42 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10_33.dll
[2014-08-11 09:34:42 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx10.dll
[2014-08-11 09:34:42 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_7.dll
[2014-08-11 09:34:42 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_6.dll
[2014-08-11 09:34:42 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_5.dll
[2014-08-11 09:34:42 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_4.dll
[2014-08-11 09:34:42 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_3.dll
[2014-08-11 09:34:42 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xinput1_3.dll
[2014-08-11 09:34:42 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\x3daudio1_1.dll
[2014-08-11 09:34:41 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_2.dll
[2014-08-11 09:34:41 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_1.dll
[2014-08-11 09:34:41 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xinput1_2.dll
[2014-08-11 09:34:41 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xinput1_1.dll
[2014-08-11 09:34:39 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_30.dll
[2014-08-11 09:34:39 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_25.dll
[2014-08-11 09:34:39 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_29.dll
[2014-08-11 09:34:39 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_28.dll
[2014-08-11 09:34:39 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_27.dll
[2014-08-11 09:34:39 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_26.dll
[2014-08-11 09:34:39 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\d3dx9_24.dll
[2014-08-11 09:34:39 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\xactengine2_0.dll
[2014-08-11 09:34:39 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\x3daudio1_0.dll
[2014-08-10 15:06:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014-08-09 15:11:19 | 001,002,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinUSBCoInstaller2.dll
[2014-08-09 15:09:20 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\Wondershare
[2014-08-09 15:09:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wondershare
[2014-08-09 15:09:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
[2014-08-09 15:09:10 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\Wondershare
[2014-08-09 15:09:10 | 000,000,000 | ---D | C] -- C:\Users\Stirling\.android
[2014-08-09 15:09:09 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\DrFoneAndroid_Temp
[2014-08-09 15:09:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Wondershare
[2014-08-08 08:40:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014-08-05 15:48:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2014-08-05 15:48:39 | 000,129,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\MSSTDFMT.DLL
[2014-08-05 15:48:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
[2014-08-05 15:48:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpywareBlaster
[2014-08-05 15:47:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\SysNative\appmgmt
[2014-08-05 15:13:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2014-08-05 14:51:42 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\gBurner
[2014-08-05 13:54:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gBurner
[2014-08-05 13:54:51 | 000,000,000 | ---D | C] -- C:\Program Files\gBurner
[2014-08-05 08:30:49 | 000,000,000 | ---D | C] -- E:\User\Documents\Star Wars - The Old Republic
[2014-08-03 22:52:38 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\Macromedia
[2014-08-03 14:51:20 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\GameRanger
[2014-08-03 14:50:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
[2014-08-03 10:12:01 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\Adobe
[2014-08-03 10:12:00 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\Adobe
[2014-07-28 22:45:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Titanfall
[2014-07-28 11:31:36 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\Unity
[2014-07-27 20:39:05 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\SWTOR
[2014-07-27 13:01:25 | 000,000,000 | ---D | C] -- E:\User\Documents\Assassin's Creed IV Black Flag
[2014-07-27 09:55:06 | 000,000,000 | ---D | C] -- E:\User\Documents\Wizards of the Coast
[2014-07-26 19:12:47 | 000,000,000 | ---D | C] -- C:\ProgramData\BitRaider
[2014-07-26 19:11:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Star Wars - The Old Republic
[2014-07-26 19:11:04 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\EAInstaller
[2014-07-26 19:07:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin Games
[2014-07-26 19:07:03 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Roaming\Origin
[2014-07-26 19:07:02 | 000,000,000 | ---D | C] -- C:\Users\Stirling\AppData\Local\Origin
[2014-07-26 19:05:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Origin
[2014-07-26 19:05:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
[2014-07-26 19:05:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Electronic Arts
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014-08-24 10:48:30 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014-08-24 10:48:28 | 000,000,944 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4255357737-3008773102-417445480-1001UA.job
[2014-08-24 10:48:00 | 000,002,203 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014-08-24 10:48:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014-08-24 10:33:48 | 000,876,144 | ---- | M] () -- C:\WINDOWS\SysNative\PerfStringBackup.INI
[2014-08-24 10:33:48 | 000,742,820 | ---- | M] () -- C:\WINDOWS\SysNative\perfh009.dat
[2014-08-24 10:33:48 | 000,143,102 | ---- | M] () -- C:\WINDOWS\SysNative\perfc009.dat
[2014-08-24 10:32:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014-08-24 10:29:42 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014-08-24 10:28:53 | 000,034,816 | ---- | M] () -- C:\Users\Stirling\AppData\Roaming\RZR_0010a1eb4f3c8c360cca118331f7.db
[2014-08-24 10:27:44 | 000,119,296 | ---- | M] () -- C:\WINDOWS\SysWow64\zlib.dll
[2014-08-24 10:27:41 | 000,477,120 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014-08-24 10:27:39 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014-08-24 10:27:29 | 814,043,133 | -HS- | M] () -- C:\hiberfil.sys
[2014-08-24 01:27:24 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\SysNative\drivers\MBAMSwissArmy.sys
[2014-08-24 01:27:09 | 000,001,114 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014-08-23 19:09:05 | 000,001,174 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2014-08-23 17:48:00 | 000,000,892 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4255357737-3008773102-417445480-1001Core.job
[2014-08-23 10:56:04 | 000,002,141 | ---- | M] () -- C:\Users\Public\Desktop\Razer Game Booster.lnk
[2014-08-22 23:08:00 | 001,852,463 | ---- | M] () -- E:\User\Documents\Rage of Dragons Season 2.masterplan
[2014-08-22 10:00:36 | 000,001,214 | ---- | M] () -- C:\Users\Public\Desktop\Razer Comms.lnk
[2014-08-17 21:41:11 | 000,041,449 | ---- | M] () -- E:\User\Documents\1750 AM.html
[2014-08-17 20:55:54 | 000,002,089 | ---- | M] () -- E:\User\Stirling\BattleScribe Roster Editor.lnk
[2014-08-17 17:18:53 | 000,450,709 | R--- | M] () -- C:\WINDOWS\SysNative\drivers\etc\hosts
[2014-08-17 15:14:21 | 000,001,391 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2014-08-15 17:35:14 | 000,001,184 | ---- | M] () -- E:\User\Stirling\Resurrection - WC3.lnk
[2014-08-15 17:35:08 | 000,001,191 | ---- | M] () -- E:\User\Stirling\Resurrection - FT.lnk
[2014-08-15 15:49:12 | 000,000,749 | ---- | M] () -- C:\Users\Public\Desktop\Warcraft III.lnk
[2014-08-15 15:49:03 | 000,000,792 | ---- | M] () -- C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk
[2014-08-14 08:41:19 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\msrating.dll
[2014-08-14 08:41:13 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieUnatt.exe
[2014-08-14 08:41:13 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieUnatt.exe
[2014-08-14 08:41:13 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollector.exe
[2014-08-14 08:41:13 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\ieetwproxystub.dll
[2014-08-14 08:41:13 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwproxystub.dll
[2014-08-14 08:41:13 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iernonce.dll
[2014-08-14 08:41:13 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\ieetwcollectorres.dll
[2014-08-14 08:41:12 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iesetup.dll
[2014-08-14 08:41:12 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysWow64\iesetup.dll
[2014-08-14 08:41:12 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\iernonce.dll
[2014-08-14 08:41:10 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\msrating.dll
[2014-08-14 08:37:28 | 000,233,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\mfps.dll
[2014-08-14 08:32:38 | 000,428,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\drivers\FWPKCLNT.SYS
[2014-08-14 08:11:58 | 000,001,104 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2014-08-14 08:04:49 | 000,000,861 | ---- | M] () -- C:\Users\Public\Desktop\Battle.net.lnk
[2014-08-11 23:20:52 | 000,051,200 | ---- | M] () -- C:\WINDOWS\SysNative\kdbsdk64.dll
[2014-08-11 23:15:56 | 000,038,912 | ---- | M] () -- C:\WINDOWS\SysWow64\kdbsdk32.dll
[2014-08-11 22:32:34 | 000,127,872 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\amdhcp64.dll
[2014-08-11 22:32:32 | 000,117,560 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\amdhcp32.dll
[2014-08-11 22:32:30 | 000,078,432 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atimpc64.dll
[2014-08-11 22:32:30 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atimpc32.dll
[2014-08-11 22:32:26 | 000,078,432 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdpcom64.dll
[2014-08-11 22:32:26 | 000,071,704 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdpcom32.dll
[2014-08-11 22:32:24 | 000,143,304 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiuxp64.dll
[2014-08-11 22:32:24 | 000,126,336 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiuxpag.dll
[2014-08-11 22:32:22 | 000,117,584 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiu9p64.dll
[2014-08-11 22:32:22 | 000,099,520 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiu9pag.dll
[2014-08-11 22:32:20 | 001,331,424 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\aticfx64.dll
[2014-08-11 22:32:18 | 001,110,992 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\aticfx32.dll
[2014-08-11 22:32:14 | 010,521,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atidxx64.dll
[2014-08-11 22:32:10 | 009,018,320 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atidxx32.dll
[2014-08-11 22:32:04 | 007,102,496 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiumdva.dll
[2014-08-11 22:32:00 | 006,879,016 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiumdag.dll
[2014-08-11 22:31:54 | 007,892,000 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiumd6a.dll
[2014-08-11 22:31:52 | 008,108,312 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiumd64.dll
[2014-08-11 22:28:48 | 000,276,192 | ---- | M] (Advanced Micro Devices) -- C:\WINDOWS\SysNative\drivers\amdacpksd.sys
[2014-08-11 22:24:16 | 015,961,088 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\atikmdag.sys
[2014-08-11 22:10:04 | 000,231,424 | ---- | M] () -- C:\WINDOWS\SysNative\clinfo.exe
[2014-08-11 22:09:48 | 000,098,816 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\OpenVideo64.dll
[2014-08-11 22:09:40 | 000,083,456 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\OpenVideo.dll
[2014-08-11 22:09:34 | 000,086,528 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\OVDecode64.dll
[2014-08-11 22:09:30 | 000,073,216 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\OVDecode.dll
[2014-08-11 22:09:24 | 032,877,056 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\amdocl64.dll
[2014-08-11 22:06:20 | 027,843,072 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\amdocl.dll
[2014-08-11 22:03:26 | 000,065,024 | ---- | M] (Khronos Group) -- C:\WINDOWS\SysNative\OpenCL.dll
[2014-08-11 22:03:22 | 000,058,880 | ---- | M] (Khronos Group) -- C:\WINDOWS\SysWow64\OpenCL.dll
[2014-08-11 21:51:08 | 000,127,488 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\mantle64.dll
[2014-08-11 21:50:48 | 000,113,664 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\mantle32.dll
[2014-08-11 21:50:26 | 005,225,472 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdmantle64.dll
[2014-08-11 21:45:40 | 000,134,656 | ---- | M] () -- C:\WINDOWS\SysNative\amdhdl64.dll
[2014-08-11 21:45:36 | 000,123,392 | ---- | M] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2014-08-11 21:44:12 | 027,529,216 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atio6axx.dll
[2014-08-11 21:39:54 | 000,418,304 | ---- | M] () -- C:\WINDOWS\SysNative\amdmiracast.dll
[2014-08-11 21:34:14 | 004,180,992 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdmantle32.dll
[2014-08-11 21:24:04 | 023,028,224 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\atioglxx.dll
[2014-08-11 21:20:00 | 000,091,648 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\mantleaxl64.dll
[2014-08-11 21:19:48 | 000,085,504 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\mantleaxl32.dll
[2014-08-11 21:19:16 | 000,598,112 | ---- | M] () -- C:\WINDOWS\SysWow64\atiapfxx.blb
[2014-08-11 21:19:16 | 000,598,112 | ---- | M] () -- C:\WINDOWS\SysNative\atiapfxx.blb
[2014-08-11 21:18:48 | 000,366,592 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atiapfxx.exe
[2014-08-11 21:18:40 | 000,062,464 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticalrt64.dll
[2014-08-11 21:18:38 | 000,052,224 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticalrt.dll
[2014-08-11 21:18:30 | 000,055,808 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticalcl64.dll
[2014-08-11 21:18:28 | 000,049,152 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticalcl.dll
[2014-08-11 21:18:14 | 015,716,352 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysNative\aticaldd64.dll
[2014-08-11 21:14:58 | 014,302,208 | ---- | M] (Advanced Micro Devices Inc.) -- C:\WINDOWS\SysWow64\aticaldd.dll
[2014-08-11 21:01:34 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atidemgy.dll
[2014-08-11 21:01:20 | 000,031,232 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\atimuixx.dll
[2014-08-11 21:01:10 | 000,588,800 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\atieclxx.exe
[2014-08-11 21:00:38 | 000,239,616 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\atiesrxx.exe
[2014-08-11 20:59:34 | 000,190,976 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\atitmm64.dll
[2014-08-11 20:57:56 | 000,048,128 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdmmcl6.dll
[2014-08-11 20:57:50 | 000,037,888 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdmmcl.dll
[2014-08-11 20:53:52 | 003,437,632 | ---- | M] () -- C:\WINDOWS\SysNative\atiumd6a.cap
[2014-08-11 20:43:28 | 000,826,368 | ---- | M] (AMD) -- C:\WINDOWS\SysNative\coinst_14.20.dll
[2014-08-11 20:42:46 | 003,471,376 | ---- | M] () -- C:\WINDOWS\SysWow64\atiumdva.cap
[2014-08-11 20:34:56 | 001,207,296 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\atiadlxx.dll
[2014-08-11 20:34:46 | 000,898,560 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysWow64\atiadlxy.dll
[2014-08-11 20:34:32 | 000,075,264 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atig6pxx.dll
[2014-08-11 20:34:28 | 000,069,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atiglpxx.dll
[2014-08-11 20:34:28 | 000,069,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atiglpxx.dll
[2014-08-11 20:34:26 | 000,146,944 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atig6txx.dll
[2014-08-11 20:34:12 | 000,133,632 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atigktxx.dll
[2014-08-11 20:34:12 | 000,095,744 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\amdave64.dll
[2014-08-11 20:34:06 | 000,090,112 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\amdave32.dll
[2014-08-11 20:33:58 | 000,557,056 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\atikmpag.sys
[2014-08-11 20:33:54 | 000,089,088 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysNative\atisamu64.dll
[2014-08-11 20:33:48 | 000,080,896 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\WINDOWS\SysWow64\atisamu32.dll
[2014-08-11 20:32:04 | 000,043,520 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SysNative\drivers\ati2erec.dll
[2014-08-09 15:24:18 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2014-08-09 15:11:19 | 001,002,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\WinUSBCoInstaller2.dll
[2014-08-09 15:09:14 | 000,002,203 | ---- | M] () -- C:\Users\Public\Desktop\Wondershare Dr.Fone for Android.lnk
[2014-08-06 21:12:27 | 001,336,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\gdi32.dll
[2014-08-06 17:38:18 | 000,697,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aepdu.dll
[2014-08-05 23:07:18 | 000,001,015 | ---- | M] () -- C:\Users\Stirling\Application Data\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk
[2014-08-05 15:48:39 | 000,001,091 | ---- | M] () -- C:\Users\Public\Desktop\SpywareBlaster.lnk
[2014-08-05 13:55:03 | 000,000,792 | ---- | M] () -- C:\Users\Public\Desktop\gBurner.lnk
[2014-08-03 22:21:18 | 000,000,132 | ---- | M] () -- C:\Users\Stirling\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2014-08-03 14:51:37 | 000,001,140 | ---- | M] () -- C:\Users\Stirling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameRanger.lnk
[2014-08-03 14:51:37 | 000,001,106 | ---- | M] () -- C:\Users\Stirling\Application Data\Microsoft\Internet Explorer\Quick Launch\GameRanger.lnk
[2014-08-03 14:51:37 | 000,001,014 | ---- | M] () -- E:\User\Stirling\GameRanger.lnk
[2014-08-03 14:50:27 | 000,000,981 | ---- | M] () -- C:\Users\Public\Desktop\Giants – Citizen Kabuto.lnk
[2014-08-02 15:24:51 | 000,042,001 | ---- | M] () -- E:\User\Documents\1500.html
[2014-08-02 00:44:01 | 000,527,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\aeinv.dll
[2014-08-01 22:11:49 | 000,918,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SysNative\MrmCoreR.dll
[2014-08-01 19:17:43 | 000,704,480 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
[2014-08-01 19:17:43 | 000,105,440 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[2014-07-31 20:46:38 | 000,001,237 | ---- | M] () -- E:\User\Stirling\calibre.exe - Shortcut.lnk
[2014-07-28 22:45:59 | 000,000,668 | ---- | M] () -- C:\Users\Public\Desktop\Titanfall.lnk
[2014-07-27 09:07:57 | 002,066,004 | ---- | M] () -- E:\User\Documents\reisb.pdf
[2014-07-27 08:49:42 | 006,290,763 | ---- | M] () -- E:\User\Documents\RotEISB.pdf
[2014-07-26 21:31:25 | 017,988,331 | ---- | M] () -- E:\User\Documents\Ways of the Force (v1.2).pdf
[2014-07-26 19:11:05 | 000,001,322 | ---- | M] () -- C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
[2014-07-26 19:05:26 | 000,000,696 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2014-07-26 19:05:09 | 000,000,812 | ---- | M] () -- E:\User\Stirling\Uplay.lnk
[2014-07-25 12:55:09 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\WindowsAccessBridge-32.dll
[2014-07-25 12:49:57 | 000,272,808 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaws.exe
[2014-07-25 12:49:52 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\javaw.exe
[2014-07-25 12:49:19 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\SysWow64\java.exe
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014-08-24 01:27:09 | 000,001,114 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014-08-23 19:09:05 | 000,001,174 | ---- | C] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2014-08-23 10:56:04 | 000,002,141 | ---- | C] () -- C:\Users\Public\Desktop\Razer Game Booster.lnk
[2014-08-22 23:08:00 | 001,852,463 | ---- | C] () -- E:\User\Documents\Rage of Dragons Season 2.masterplan
[2014-08-22 10:01:21 | 000,034,816 | ---- | C] () -- C:\Users\Stirling\AppData\Roaming\RZR_0010a1eb4f3c8c360cca118331f7.db
[2014-08-22 10:00:36 | 000,001,214 | ---- | C] () -- C:\Users\Public\Desktop\Razer Comms.lnk
[2014-08-17 21:41:11 | 000,041,449 | ---- | C] () -- E:\User\Documents\1750 AM.html
[2014-08-17 15:14:21 | 000,001,403 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2014-08-17 15:14:21 | 000,001,391 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2014-08-15 17:35:14 | 000,001,184 | ---- | C] () -- E:\User\Stirling\Resurrection - WC3.lnk
[2014-08-15 17:35:08 | 000,001,191 | ---- | C] () -- E:\User\Stirling\Resurrection - FT.lnk
[2014-08-15 12:39:07 | 000,000,792 | ---- | C] () -- C:\Users\Public\Desktop\Warcraft III - The Frozen Throne.lnk
[2014-08-15 12:09:28 | 000,000,749 | ---- | C] () -- C:\Users\Public\Desktop\Warcraft III.lnk
[2014-08-14 08:44:32 | 000,050,745 | ---- | C] () -- C:\WINDOWS\SysNative\srms.dat
[2014-08-14 08:11:58 | 000,001,104 | ---- | C] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2014-08-14 08:04:49 | 000,000,861 | ---- | C] () -- C:\Users\Public\Desktop\Battle.net.lnk
[2014-08-11 23:20:52 | 000,051,200 | ---- | C] () -- C:\WINDOWS\SysNative\kdbsdk64.dll
[2014-08-11 23:15:56 | 000,038,912 | ---- | C] () -- C:\WINDOWS\SysWow64\kdbsdk32.dll
[2014-08-11 22:10:04 | 000,231,424 | ---- | C] () -- C:\WINDOWS\SysNative\clinfo.exe
[2014-08-11 21:45:40 | 000,134,656 | ---- | C] () -- C:\WINDOWS\SysNative\amdhdl64.dll
[2014-08-11 21:45:36 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2014-08-11 21:39:54 | 000,418,304 | ---- | C] () -- C:\WINDOWS\SysNative\amdmiracast.dll
[2014-08-11 21:19:16 | 000,598,112 | ---- | C] () -- C:\WINDOWS\SysWow64\atiapfxx.blb
[2014-08-11 21:19:16 | 000,598,112 | ---- | C] () -- C:\WINDOWS\SysNative\atiapfxx.blb
[2014-08-11 20:53:52 | 003,437,632 | ---- | C] () -- C:\WINDOWS\SysNative\atiumd6a.cap
[2014-08-11 20:42:46 | 003,471,376 | ---- | C] () -- C:\WINDOWS\SysWow64\atiumdva.cap
[2014-08-09 15:24:18 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2014-08-09 15:09:14 | 000,002,203 | ---- | C] () -- C:\Users\Public\Desktop\Wondershare Dr.Fone for Android.lnk
[2014-08-05 15:48:39 | 000,001,091 | ---- | C] () -- C:\Users\Public\Desktop\SpywareBlaster.lnk
[2014-08-05 13:55:03 | 000,000,792 | ---- | C] () -- C:\Users\Public\Desktop\gBurner.lnk
[2014-08-03 14:51:37 | 000,001,140 | ---- | C] () -- C:\Users\Stirling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameRanger.lnk
[2014-08-03 14:51:37 | 000,001,112 | ---- | C] () -- C:\Users\Stirling\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
[2014-08-03 14:51:37 | 000,001,106 | ---- | C] () -- C:\Users\Stirling\Application Data\Microsoft\Internet Explorer\Quick Launch\GameRanger.lnk
[2014-08-03 14:51:37 | 000,001,014 | ---- | C] () -- E:\User\Stirling\GameRanger.lnk
[2014-08-03 14:50:27 | 000,000,981 | ---- | C] () -- C:\Users\Public\Desktop\Giants – Citizen Kabuto.lnk
[2014-08-02 15:24:51 | 000,042,001 | ---- | C] () -- E:\User\Documents\1500.html
[2014-07-31 20:46:38 | 000,001,237 | ---- | C] () -- E:\User\Stirling\calibre.exe - Shortcut.lnk
[2014-07-28 22:45:59 | 000,000,668 | ---- | C] () -- C:\Users\Public\Desktop\Titanfall.lnk
[2014-07-27 09:07:57 | 002,066,004 | ---- | C] () -- E:\User\Documents\reisb.pdf
[2014-07-27 08:49:41 | 006,290,763 | ---- | C] () -- E:\User\Documents\RotEISB.pdf
[2014-07-26 21:31:21 | 017,988,331 | ---- | C] () -- E:\User\Documents\Ways of the Force (v1.2).pdf
[2014-07-26 19:11:05 | 000,001,322 | ---- | C] () -- C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
[2014-07-26 19:05:26 | 000,000,696 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2014-07-08 20:07:15 | 000,119,296 | ---- | C] () -- C:\WINDOWS\SysWow64\zlib.dll
[2014-07-08 20:07:15 | 000,057,344 | ---- | C] () -- C:\WINDOWS\SysWow64\ADsSecurity.dll
[2014-05-28 17:54:49 | 000,000,132 | ---- | C] () -- C:\Users\Stirling\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2014-05-28 17:37:26 | 000,000,442 | ---- | C] () -- C:\Users\Stirling\AppData\Local\UserProducts.xml
[2014-05-10 17:43:36 | 000,872,086 | ---- | C] () -- C:\WINDOWS\SysWow64\PerfStringBackup.INI
[2014-05-06 18:07:23 | 000,000,858 | ---- | C] () -- C:\Users\Stirling\AppData\Local\recently-used.xbel
[2014-05-06 17:49:43 | 000,155,696 | ---- | C] () -- C:\WINDOWS\wiainst64.exe
[2014-05-06 17:49:24 | 000,094,208 | ---- | C] () -- C:\WINDOWS\SysWow64\Ssdevm.dll
[2014-05-06 17:49:24 | 000,053,248 | ---- | C] () -- C:\WINDOWS\SysWow64\Ssusbpn.dll
[2014-05-06 17:49:23 | 001,571,160 | ---- | C] () -- C:\WINDOWS\TotalUninstaller.exe
[2014-04-28 23:04:10 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2014-04-28 23:03:59 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2014-03-18 05:06:28 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014-03-18 05:06:06 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2013-12-13 09:23:56 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2013-12-13 09:23:54 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2013-12-13 09:23:46 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2013-12-13 09:23:24 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2013-12-13 09:23:24 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013-08-22 10:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013-08-22 10:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013-08-22 09:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013-08-22 02:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013-08-21 22:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013-08-21 18:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013-08-21 18:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
 
========== ZeroAccess Check ==========
 
[2014-05-02 11:43:17 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014-04-06 11:31:39 | 021,268,952 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-04-06 10:22:20 | 018,755,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013-08-22 04:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013-08-21 21:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013-08-22 04:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 237 bytes -> C:\Users\Stirling\OneDrive:ms-properties
@Alternate Data Stream - 128 bytes -> C:\WINDOWS\SysWow64\zlib.dll:SummaryInformation
@Alternate Data Stream - 128 bytes -> C:\WINDOWS\SysWow64\zlib.dll:DocumentSummaryInformation
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34
 
< End of report >
 

  • 0

Advertisements


#2
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,583 posts

If you are still in need of assistance I would be happy to take a look.

 

There should be an Extras.txt file in your downloads folder from when you ran OTL the first time. If you could paste the contents of that in to your next post we can get started.

 

Thanks.


  • 0

#3
arcaneshield

arcaneshield

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

No extras.txt file. Only OLT.txt. Even ran it again, still no extras.txt file.


  • 0

#4
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,583 posts

No problem. Try this please. If it doesn't work there is another tool that works better with Win 8.

 

1. Move OTL.exe from your Downloads directory to your desktop. This will make things easier.
2. Open it back up by right-clicking on it and choose Run as administrator.
3. Check "Use SafeList" under the Extra Registry section.
    Extras.JPG
4. Click the Run Scan button.
5. OTL.txt and Extras.txt will be opened and created on your desktop. Since I already have the OTL, please paste the Extras.txt into your next reply.


  • 0

#5
arcaneshield

arcaneshield

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

Thanks. Here's the extras.txt. Still experiencing this problem. Sometimes its a tab in chrome, sometimes its a program here or there. It's got me worried.

 

OTL Extras logfile created on: 2014-08-26 1:52:51 PM - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = E:\User\Stirling
64bit- An unknown product  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17239)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: yyyy-MM-dd
 
15.95 Gb Total Physical Memory | 9.39 Gb Available Physical Memory | 58.87% Memory free
31.95 Gb Paging File | 22.44 Gb Available in Paging File | 70.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 223.23 Gb Total Space | 30.52 Gb Free Space | 13.67% Space Free | Partition Type: NTFS
Drive D: | 238.47 Gb Total Space | 52.32 Gb Free Space | 21.94% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 116.39 Gb Free Space | 12.49% Space Free | Partition Type: NTFS
Drive F: | 462.11 Gb Total Space | 208.44 Gb Free Space | 45.11% Space Free | Partition Type: NTFS
Drive H: | 3.07 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
 
Computer Name: STIRLING-PC | User Name: Stirling | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\WINDOWS\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] -- "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" =  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2513972C-3579-4929-821A-F86EBC23D7A5}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{395B501C-8BEE-46DD-852E-388C068DAD94}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{4364441E-A311-4A4A-9B39-245EBAA3B667}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{4FA74DFF-26B4-4E09-970A-9D38FFEC9CDD}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{86A41C9E-706E-4CE2-8E23-979CBAA9013F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{8D64D408-3A20-4F68-84AC-F6E320E1142F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{B0E1AC22-35CE-46FC-AB83-2A489349147B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{D5E35DD2-1A8D-4F90-9005-2394636E94F1}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | 
"{E0412DF3-2423-4F52-A026-2DE67BAE9300}" = lport=41780 | protocol=17 | dir=in | name=landmarkawesomiumbrowsercontroller | 
"{F06765E3-7748-49E9-A841-04E3032668AD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{F8799134-BFB6-48DE-98A3-D3510E05A074}" = lport=10243 | protocol=6 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0235A2AB-50A8-4B54-9D7A-911A24124688}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization 4 complete\warlords\civ4warlords.exe | 
"{02787A9E-4E89-451C-9141-9A74C8A1448C}" = protocol=17 | dir=in | app=c:\program files (x86)\stardock games\demigod\bin\demigod.exe | 
"{02C6F418-1DC6-4D55-9B6D-4E9C30E24FC9}" = dir=out | [email protected]{microsoft.bingnews_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | 
"{03201971-ABA3-4DE5-B6AF-C4DEB47DBE18}" = dir=in | [email protected]{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | 
"{05C09F35-206D-40DB-9A1A-1A99EC486A42}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization 4 complete\civilization4.exe | 
"{06B7E0E7-A98E-412E-836D-09792057ACFA}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung universal scan driver\scancdlm.exe | 
"{0771AF18-3DB4-4F0D-AC96-F6BBA9F8B519}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\aow3\aow3_debug.exe | 
"{0931A608-94B6-4A77-A766-4F0829F813C9}" = protocol=17 | dir=in | app=c:\users\stirling\appdata\roaming\dropbox\bin\dropbox.exe | 
"{098FECB2-2C84-4A80-ABC2-E5F603F5610D}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\aow3\aow3_debug.exe | 
"{0B467901-B51F-4070-BB20-EE694FAE8646}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\sonic generations\configurationtool.exe | 
"{0D73B63A-4CC2-4CC4-8F77-C436C1ABE6EB}" = protocol=6 | dir=in | app=c:\users\stirling\appdata\roaming\dropbox\bin\dropbox.exe | 
"{0F454C3D-75B1-4685-811A-328910902804}" = dir=out | [email protected]{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} | 
"{0FB850A9-2A8A-42DD-9BA3-33043E52B0D3}" = protocol=17 | dir=in | app=e:\steamlibrary\steamapps\common\fistful of frags\sdk\hl2.exe | 
"{12EDEA5E-9341-4838-BA1E-54B34C940879}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung universal scan driver\iccupdater.exe | 
"{15D37384-C4AA-40C2-AC5F-3C0FD22675A1}" = dir=out | [email protected]{microsoft.bingsports_3.0.2.317_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | 
"{16289CD4-EC93-4508-A8C7-3FF662101223}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | 
"{18B3192A-4682-4865-BB01-01A851E79C94}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\divinity - original sin\shipping\eocapp.exe | 
"{1919D296-25E1-49EB-AE32-7325EE7DECB9}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\aow3\aow3.exe | 
"{1B647824-538C-4943-A8B2-4E9AEA85718A}" = dir=in | name=samsung printer experience | 
"{1C9E2ED4-3B15-48C4-A2A1-F7787C4017B8}" = protocol=17 | dir=in | app=c:\users\stirling\appdata\local\apps\2.0\9xocev9v.gmv\5d58t5c1.x3h\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b6290e21932c\curseclient.exe | 
"{1D16A302-3A71-4D2E-8250-FE211FD201F2}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\floating point\floating point.exe | 
"{2015AB45-208B-4C1E-B738-19EE68890417}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\trialspc\datapack\trialsfmx.exe | 
"{20420D11-7981-4134-9823-8ED0DCA92D9C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{20801314-C0DE-412D-86BC-C0114D6C2D83}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | 
"{20A9A2DB-35B1-4E88-B2A4-6F6DE48AC16C}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\dawn of war ii - retribution\dow2.exe | 
"{2179D185-8ECF-41A9-A4A2-DA5D81998FAC}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | 
"{22B21141-A583-48AF-9281-9DF52D6A57F4}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\fallout 3 goty\falloutlauncher.exe | 
"{23859028-7E5C-4574-A312-642DC3A41156}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe | 
"{247241BF-F33A-4C00-A055-9D55F065627C}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | 
"{25046808-B2C6-4A5A-A226-B22C12C21981}" = dir=out | name=juniper networks junos pulse | 
"{25494539-C9BE-4FC7-B0B6-08AEFB970D45}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization 4 complete\civilization4.exe | 
"{258DAEE3-A42D-4F65-9767-8C20E5BE2A27}" = protocol=17 | dir=in | app=c:\games\steam\bin\steamwebhelper.exe | 
"{282511BE-9B8B-43B6-B94D-87DA5922DDDE}" = dir=in | [email protected]{microsoft.xboxcompanion_1.4.2.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxcompanion/resources/33279} | 
"{28B0149C-53F1-4083-AA03-5554C4E5A0CC}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\trialspc\datapack\trialsfmx.exe | 
"{28F427A9-9D92-4C25-A6A0-3FEEEBDF9877}" = dir=in | [email protected]{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{2A980858-AF04-4573-8788-7F7ABAFA3E45}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\war for the overworld\wfto.exe | 
"{2AD03535-9B1A-4961-A61C-4511A72A438F}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\dawn of war ii - retribution\dow2.exe | 
"{2D820112-D20A-404E-862E-276DF86F5762}" = dir=out | [email protected]{microsoft.bingtravel_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | 
"{2F38FCE4-01D6-480E-8E6E-9E10948D147F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{2F4A243C-7FEF-432F-BE1A-612EAB911666}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\precipice of darkness 3\rainslick3.exe | 
"{31797102-9DDE-4137-A45E-788D7E3B596E}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\blood bowl legendary edition\bb_le.exe | 
"{3278EE81-AE0D-45B6-A7A8-F4563B685084}" = dir=out | [email protected]{microsoft.zunevideo_2.6.215.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | 
"{353108D4-F808-4749-B840-93657DD5CD99}" = dir=out | name=samsung printer experience | 
"{36FC0B72-9403-48E1-80BC-8A1C205243C6}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\penny arcade's on the rain-slick precipice of darkness 4\rainslick4.exe | 
"{38E251DD-EA3D-4827-BB45-5C872B5C4A5D}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\state of decay\stateofdecay.exe | 
"{3AB63195-E874-4925-A553-2D031334DAFA}" = protocol=17 | dir=in | app=c:\games\steam\steam.exe | 
"{3E220B73-3262-4A7C-AD48-BBF32962A833}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\rise of the triad\ldkdedicatedserver.exe | 
"{3E9A5517-716C-4706-B9B4-B1D9FA3EFD3C}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\the binding of isaac\isaac.exe | 
"{3F7277D6-AA39-42CA-BCB2-C43547A8B86D}" = dir=out | [email protected]{microsoft.bingweather_3.0.2.309_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | 
"{40ECD4C8-E6B4-4A70-9274-119A20E4924E}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\the binding of isaac\isaac.exe | 
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | 
"{43DB4E83-02A5-465B-8C2F-302EA600BD55}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\fallout new vegas\falloutnvlauncher.exe | 
"{43F193AA-BF7E-425B-9785-598F2268383D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{44B367FC-4BDB-470D-B180-76B0A12CB430}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung universal scan driver\iccupdater.exe | 
"{44C9B947-C502-4805-81F8-B670A7255FBC}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung universal scan driver\scancdlm.exe | 
"{44D997BE-01E6-4EEB-B7F2-99165615D1CC}" = protocol=6 | dir=in | app=c:\program files (x86)\stardock games\demigod\bin\demigod.exe | 
"{47010138-04CE-4F06-B03C-2E3DF69BFD2B}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\rise of the triad\ldkdedicatedserver.exe | 
"{48F3F54A-D4B4-446B-9EA7-F01FEBD8263C}" = protocol=17 | dir=in | app=c:\program files (x86)\army builder\armybuilder.exe | 
"{4913791F-CA82-4536-8A6F-BCAC7592B9AC}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\blood bowl legendary edition\bb_le.exe | 
"{4965652A-A563-416C-936B-E4E2A997D88C}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\rise of legends\legends.exe | 
"{4A1379B2-E78E-4CE2-92CC-12675E478BDE}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{4A182C35-416B-4C93-8A3A-8B02D3C925C7}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\alpha protocol\aplauncher.exe | 
"{4A227DED-CA32-4186-A7F3-360C56B4B575}" = dir=out | [email protected]{microsoft.zunemusic_2.2.931.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | 
"{4CFDF3F2-5BA9-44F1-8F2D-A9FF1EA2930B}" = dir=out | [email protected]{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | 
"{4FCBA64F-6520-46CC-92FD-11B7F431E9C0}" = protocol=6 | dir=in | app=c:\program files (x86)\scan assistant\usdagent.exe | 
"{5026095F-A6A5-4E37-8468-CF49DEC747F9}" = dir=in | [email protected]{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{52101108-C8C2-40E6-8E3B-A5FF00AEA745}" = protocol=6 | dir=in | app=e:\steamlibrary\steamapps\common\fistful of frags\sdk\hl2.exe | 
"{52D47CED-D80C-45F8-8A5E-EB411D6E22D0}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization 4 complete\beyond the sword\civ4beyondsword.exe | 
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | [email protected]{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{54DB86A5-202D-4BDC-B556-27413EEE29B4}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\alpha protocol\aplauncher.exe | 
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | 
"{56B7DA7D-8BA5-4251-B89A-7E901E6FD49E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{57EC5A1F-4978-4578-8F96-333672B5FE11}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\precipice of darkness 3\rainslick3.exe | 
"{591DAB45-AB8E-4849-BBE3-7FE52D8C1D7B}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\magic 2014\dotp_d14.exe | 
"{5A887237-89B9-4C85-82AF-69EBD1BAF0A8}" = dir=out | name=samsung printer experience | 
"{5AAEAAC7-1EAE-440C-9ACB-AF4EFFBEDADE}" = dir=out | [email protected]{microsoft.xboxcompanion_1.4.2.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxcompanion/resources/33279} | 
"{5ED35FDD-D902-4014-BE2E-A054CCF984CF}" = dir=out | name=skype | 
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | 
"{5F834EC8-DAB3-4492-AB2A-574627322C45}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\fallout 3 goty\falloutlauncher.exe | 
"{60136008-BF0F-4F62-9678-3FE92BE07B68}" = dir=out | [email protected]{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} | 
"{60947F13-1262-47EA-80B8-8C13AAB30C82}" = protocol=6 | dir=in | app=c:\program files (x86)\namco bandai games\warhammer mark of chaos\warhammer.exe | 
"{66A5C6E1-D7D1-4B50-B044-E86EE07858C9}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe | 
"{66CA6FC2-F768-45E2-B8B3-9B29062D64AD}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\king arthur - the role-playing wargame\kingarthur.exe | 
"{66EC3CE2-05ED-4F0A-A4E5-5502AF1531AC}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\king arthur - the role-playing wargame\kingarthur.exe | 
"{67F8BCFD-37A6-4A6B-8378-86ADED871264}" = dir=out | name=windows_ie_ac_001 | 
"{68D2A135-4361-4E3E-9C4D-22995BEFCB08}" = dir=out | [email protected]{microsoft.bingfinance_3.0.2.258_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | 
"{69FFF5AD-3BDD-44D8-B5FC-248480CEB9E3}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\sonic generations\configurationtool.exe | 
"{6AB9600E-A2AF-45E4-8C63-37BCF44AF3F0}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\fallout new vegas\falloutnvlauncher.exe | 
"{6BBFA59E-E674-4CFD-B8FD-C9FB94F7876F}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\rift\riftpatchlive.exe | 
"{6C511ACC-F2D9-4768-BB5A-C8604A3C1CBF}" = dir=in | name=sonicwall mobile connect | 
"{6E73B663-1D09-4362-A55B-7443CFE23BA0}" = dir=in | name=onenote | 
"{6E763102-EEC1-4C5B-B52D-A3C346C17DD8}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\xcom-enemy-unknown\binaries\win32\xcomgame.exe | 
"{70CB85C7-9393-408B-A86A-6A94769424E1}" = dir=out | name=sonicwall mobile connect | 
"{71008914-9622-4303-A1FE-499D35E9D94B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7205A15F-CA12-4D9D-AC9D-2EA94AF0F516}" = protocol=17 | dir=in | app=c:\program files (x86)\scan assistant\usdagent.exe | 
"{72BCA9A2-5AAB-4268-B521-E55B5B952ED4}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\team fortress 2\hl2.exe | 
"{74994BD3-A168-44C5-8874-BBFFF56577D7}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\skyrim\skyrimlauncher.exe | 
"{7595D625-BC6A-4E73-9B80-06ED58B0907C}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\skyrim\skyrimlauncher.exe | 
"{7705DCCD-FA12-4987-89CA-46E89006A0DB}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\king arthur - the role-playing wargame\kingarthurmulti.exe | 
"{7765E119-D3C6-4324-B47A-2A9F31C9729F}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | 
"{7829C487-6B00-411D-B01C-0D294E91F51C}" = dir=out | [email protected]{microsoft.binghealthandfitness_3.0.2.315_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | 
"{7B5F3B49-5800-40C4-A2C7-FBF1B48ADA06}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\warmachine tactics\warmachinegame\binaries\win64\warmachinegame-win64-shipping.exe | 
"{7E3D6748-A3E5-4B0B-9222-7A148269E0F8}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\dont_starve\bin\dontstarve_steam.exe | 
"{7FDD39A9-CCED-4CF6-85E4-11F865A53C4F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\rise of legends\legends.exe | 
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | [email protected]{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{80A65F7E-CDA1-494D-BEC1-189A10C25EA2}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\resident evil 5\launcher.exe | 
"{815BF3A1-5696-4379-B9DA-53B32DE988E5}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\sonic adventure 2\launcher.exe | 
"{81C30BF4-E0B8-405C-B4EC-F51E5A3DEA29}" = dir=out | [email protected]{microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{871CA88C-9CF0-4625-8CFD-4A9D233F9AEE}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\sid meier's civilization v\launcher.exe | 
"{885CB77F-87F1-45A9-BB76-64906551B92B}" = protocol=6 | dir=in | app=c:\games\battle.net\battle.net.exe | 
"{8A050227-3E55-4A99-8153-C13D6AAB2BFB}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\the walking dead season two\thewalkingdead2.exe | 
"{8C126BED-1CAF-452E-BBFC-899FB422DC9D}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{8C5A6725-1FC0-476E-B9B4-713F67B93E65}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{8C6F6863-EB00-44D6-939E-94CD89A481C9}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\war for the overworld\wfto.exe | 
"{8D9D76F7-1056-48A1-8D75-3910ACC044A6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{8FC7649C-809A-4205-848F-29B664576DA9}" = dir=in | name=f5 vpn | 
"{919B3848-C9F2-4C0E-A67F-91D12EE58CC6}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\dont_starve\bin\dontstarve_steam.exe | 
"{926D1389-021A-4042-9FCF-B8A981604AF0}" = dir=in | name=juniper networks junos pulse | 
"{93EAB0E8-61B1-4727-83F9-DD6EB8DBEF29}" = protocol=17 | dir=in | app=c:\games\battle.net\battle.net.exe | 
"{95CF9C2A-DC48-4B89-AA34-1259A62ED8E7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{96899406-30E4-4FF9-A3C3-E974798D124B}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\rise of the triad\binaries\rottlauncher.exe | 
"{96D47310-E4F4-4F2B-9BF3-0DE4E9CFE994}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\rift\riftpatchlive.exe | 
"{98F4EF2A-A7A7-479F-B148-D519F7A2D6D8}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\morrowind\morrowind launcher.exe | 
"{9919D2D1-3108-4E5E-9715-6FF965EDBE60}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe | 
"{994AEC92-5524-4738-A5AC-3C717D2590D1}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\resident evil 5\launcher.exe | 
"{9963F12D-51D7-4C3F-A8E9-566B6666919A}" = protocol=17 | dir=in | app=c:\program files (x86)\namco bandai games\warhammer mark of chaos\warhammer.exe | 
"{9AB20CBF-D04B-4609-A742-14586C0D6F35}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | 
"{9AE53E78-3496-41C8-9958-776CBA573B81}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | 
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | [email protected]{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{9E59EA8B-B111-48D7-B1D5-8248CDE2CAB3}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization 4 complete\beyond the sword\civ4beyondsword.exe | 
"{A032F577-450C-4A56-BCE7-968004F005A0}" = protocol=17 | dir=in | app=c:\users\stirling\appdata\local\apps\2.0\9xocev9v.gmv\5d58t5c1.x3h\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b6290e21932c\curseclient.exe | 
"{A138F683-A198-4691-B3C3-E9E2393DA911}" = protocol=6 | dir=in | app=c:\games\steam\bin\steamwebhelper.exe | 
"{A1BB164E-BA98-4B99-8D28-ED93D89C1D6E}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\divinity - original sin\shipping\eocapp.exe | 
"{A63C007B-C423-4037-AC35-04C9FE7B1AD3}" = dir=in | name=skype | 
"{AACD2782-4FC7-4150-954C-7A612F9D84D8}" = protocol=6 | dir=in | app=c:\users\stirling\appdata\roaming\utorrent\utorrent.exe | 
"{AC66DAB6-A7C8-4FC9-A942-0EE57E2278E4}" = protocol=6 | dir=in | app=c:\users\stirling\appdata\local\apps\2.0\9xocev9v.gmv\5d58t5c1.x3h\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b6290e21932c\curseclient.exe | 
"{ADFC9950-0BA4-474C-8CAB-DFD38691E6B0}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\magic 2015\dotp_d15.exe | 
"{B0335876-996B-418A-B792-9DA14A06DDA8}" = protocol=6 | dir=in | app=e:\steamlibrary\steamapps\common\dino d-day\dinodday.exe | 
"{B10A1095-4887-45BB-80A3-A1AC139A5D5E}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\state of decay\stateofdecay.exe | 
"{B27591E6-922E-4164-839D-7240C4EB7E17}" = protocol=6 | dir=out | app=system | 
"{B2A843BA-4F3F-452D-B3CE-EBCB45703759}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\rise of the triad\binaries\rottlauncher.exe | 
"{B2DEF2B7-29CC-44D2-8ECB-6E69EA77E90B}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\aow3\aow3.exe | 
"{B39B7AAF-9AF8-41EA-A87B-46847DD6EA28}" = dir=out | name=windows_ie_ac_001 | 
"{B44CD2F3-FE18-43EE-871A-D02612EA7970}" = dir=out | [email protected]{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} | 
"{B94F1290-BF6F-4DEB-8745-72B3B4C4A272}" = dir=out | [email protected]{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{BD5A12B7-AA9A-4DB0-80B2-9F04966CE03D}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\warmachine tactics\warmachinegame\binaries\win64\warmachinegame-win64-shipping.exe | 
"{BF4A8E0A-5B1E-42C9-A6B6-9216EF1C336D}" = dir=in | [email protected]{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{C0FB9BB2-5E15-4067-9E96-7AFCABC58581}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\dawn of war soulstorm\soulstorm.exe | 
"{C4C525AB-8A96-45FC-BB7F-BED402E896FB}" = dir=out | [email protected]{microsoft.bingmaps_2.1.2922.2139_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | 
"{C53448C3-3795-4DA0-BDAD-C7056806D135}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | 
"{C793193D-B413-4E7D-8C58-326267A6F1C2}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\psychonauts\psychonauts.exe | 
"{C85D628D-4499-47B2-B5F7-6A8D0FC72360}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\star wars - the old republic\launcher.exe | 
"{C968546E-E8B9-4035-B5E4-E33B68B247FA}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\morrowind\morrowind launcher.exe | 
"{CAB910CC-5842-4702-9EC2-4592504CF1A2}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\the walking dead season two\thewalkingdead2.exe | 
"{CAD67B94-3143-46AD-BC87-293033D0E6BE}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{CAF304BD-7362-4AF6-949A-275275649E31}" = protocol=17 | dir=in | app=c:\games\steam\steamapps\common\floating point\floating point.exe | 
"{CCE0A112-9E89-47C7-B83E-ED35930CC506}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\sid meier's civilization v\launcher.exe | 
"{CE89DB41-782F-4008-9506-E6CF7237BC94}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe | 
"{CEBB996B-9FDF-4888-B394-D4A234B49E55}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\king arthur - the role-playing wargame\kingarthurmulti.exe | 
"{D00FA2FA-2181-4DBC-94B1-8968A4ED0AB7}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization 4 complete\warlords\civ4warlords.exe | 
"{D223F15E-5FCC-4A1B-85AC-A6CB16C6A40E}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\xcom-enemy-unknown\binaries\win32\xcomgame.exe | 
"{D3F2E192-F222-4166-A5C1-7B4917F09057}" = dir=in | name=check point vpn | 
"{D5887092-A19F-4DA0-8E3F-EEE2CE423A9D}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\psychonauts\psychonauts.exe | 
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | 
"{D8034649-04F1-452E-B29B-D1348995EA9C}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\magic 2014\dotp_d14.exe | 
"{D92ECAB1-DE3B-4B6F-B32E-9CF7593B591C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | 
"{DA46F2AE-5C6D-455C-8B17-AD1B24E22F35}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\magic 2015\dotp_d15.exe | 
"{DAD4354F-80B5-41AE-8F1A-83A05A3A57FC}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\sonic generations\sonicgenerations.exe | 
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | 
"{DC69F516-FA92-4633-BD36-AB3F390D38C0}" = protocol=17 | dir=in | app=e:\steamlibrary\steamapps\common\dino d-day\dinodday.exe | 
"{DE63BF52-BE99-4CEB-AB19-3607A484D4C4}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\sonic adventure 2\launcher.exe | 
"{DE79CD19-40F2-4293-AA1E-A9A7660FB76B}" = dir=out | [email protected]{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | 
"{DF515D7B-9F94-4578-B1E6-6956BF700480}" = dir=out | name=f5 vpn | 
"{E0E8FCE7-251D-4AC2-83FB-4E5DACC19AA1}" = dir=out | [email protected]{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} | 
"{E587EF6F-64E5-4E27-B4FF-6E775FB6A3B3}" = dir=out | [email protected]{microsoft.bingfoodanddrink_3.0.2.313_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | 
"{E5E9CE79-3646-4672-AABE-351AD34CB73C}" = dir=out | [email protected]{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} | 
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | [email protected]{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{E7F6F3D9-2F9E-4505-BC39-9C26C7A3C085}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{E96253E3-0D2F-4C60-9FBA-B9739A15DC27}" = dir=out | name=check point vpn | 
"{E98F13D0-6D2F-49FC-92FF-77989D8B8919}" = protocol=17 | dir=in | app=c:\users\stirling\appdata\roaming\utorrent\utorrent.exe | 
"{EAF5FCCF-DB17-4EFA-9A9E-1C8286F7C123}" = dir=in | name=samsung printer experience | 
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | 
"{F14821E4-6F14-43C6-8916-948EE0372C11}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | 
"{F28B9FB9-1469-4014-B7E9-4286D91400F3}" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\team fortress 2\hl2.exe | 
"{F4106A7B-4D07-444C-AE98-213B37F28B95}" = dir=out | [email protected]{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} | 
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | 
"{F74E376A-0DB4-4788-9F12-AFCF0A911516}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\sonic generations\sonicgenerations.exe | 
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | 
"{F7B93713-41FD-4D15-9174-058E7A8718FF}" = dir=out | name=onenote | 
"{F809F5EE-96BE-431F-A88D-ED50897B061A}" = dir=out | [email protected]{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | 
"{FA449477-5E7E-4820-B38A-AEA61ED34121}" = protocol=6 | dir=in | app=c:\program files (x86)\army builder\armybuilder.exe | 
"{FABBC0A0-2E74-48F6-9A06-78668C06DE69}" = dir=out | [email protected]{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} | 
"{FAC2F7C4-07F8-4345-803D-5F2EFE391EED}" = dir=out | [email protected]{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} | 
"{FAD24B29-4A3D-46E6-9D87-C02A5053B7B9}" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\penny arcade's on the rain-slick precipice of darkness 4\rainslick4.exe | 
"{FB4F263D-9EB5-49F6-9117-4620D9E26B71}" = protocol=6 | dir=in | app=c:\users\stirling\appdata\local\apps\2.0\9xocev9v.gmv\5d58t5c1.x3h\curs..tion_9e9e83ddf3ed3ead_0005.0001_36a9b6290e21932c\curseclient.exe | 
"{FCA347B7-1546-42B5-93F0-962D44F1B17A}" = dir=out | [email protected]{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | 
"{FD034E4F-E2DA-4943-99F5-B4216BA7274D}" = protocol=6 | dir=in | app=c:\games\steam\steam.exe | 
"{FEE7F3E3-68A2-4CDA-A18F-FB639162ED6D}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\star wars - the old republic\launcher.exe | 
"{FFA49424-A72D-4F50-ABEE-DBB144B15DEC}" = protocol=6 | dir=in | app=c:\games\steam\steamapps\common\dawn of war soulstorm\soulstorm.exe | 
"TCP Query User{0187627B-F493-4726-95FF-1F3BCFF8C71F}C:\program files\comicrack\comicrack.exe" = protocol=6 | dir=in | app=c:\program files\comicrack\comicrack.exe | 
"TCP Query User{0AD9152C-9392-4C9D-B2A7-B571201E7309}C:\program files (x86)\xbmc\xbmc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xbmc\xbmc.exe | 
"TCP Query User{0F08B043-FB7C-41BE-BE5D-A4CB9788AE03}C:\program files (x86)\java\jre7\launch4j-tmp\strange-eons.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\launch4j-tmp\strange-eons.exe | 
"TCP Query User{2957E020-7238-49A0-AA6B-26D30F1BF838}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"TCP Query User{5597CE19-3BFB-40D9-9FA9-02C6E70AE7CC}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
"TCP Query User{6827F992-01B8-4A9A-9743-90A4EAE03068}D:\steam games\steamapps\common\rise of the triad\binaries\win32\rott.exe" = protocol=6 | dir=in | app=d:\steam games\steamapps\common\rise of the triad\binaries\win32\rott.exe | 
"TCP Query User{7762238E-B407-47BF-9839-C18CC736D8E5}C:\program files (x86)\xbmc\xbmc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xbmc\xbmc.exe | 
"TCP Query User{9ACC37FF-B9D5-4879-A829-370DD1D4B1E4}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | 
"TCP Query User{B020E449-CCD9-469D-B796-60E48A0687F7}C:\games\baldur's gate enhanced edition\bgee.exe" = protocol=6 | dir=in | app=c:\games\baldur's gate enhanced edition\bgee.exe | 
"TCP Query User{B268BAF2-ED65-4E73-B567-44ED1FB0F195}C:\program files (x86)\mediamonkey\mediamonkey.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mediamonkey\mediamonkey.exe | 
"TCP Query User{F55F823B-325B-4902-8038-ADD96A2071F5}C:\games\baldur's gate ii enhanced edition\bg2ee.exe" = protocol=6 | dir=in | app=c:\games\baldur's gate ii enhanced edition\bg2ee.exe | 
"TCP Query User{FAE9BD4A-8B59-4E7C-BCC8-18BE1D5C7999}C:\windows\system32\javaw.exe" = protocol=6 | dir=in | app=c:\windows\system32\javaw.exe | 
"UDP Query User{0C4A40A3-DB64-42B4-A550-BF60A8A0FDD1}C:\program files (x86)\xbmc\xbmc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xbmc\xbmc.exe | 
"UDP Query User{25622E68-DCF7-4866-A32A-8D56D5DBBAAE}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe | 
"UDP Query User{509AE4F9-5FF4-4B94-A234-91DDF76C2C92}C:\program files (x86)\mediamonkey\mediamonkey.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mediamonkey\mediamonkey.exe | 
"UDP Query User{8171360A-7B30-4639-A6A4-4C209FECE03C}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"UDP Query User{8D86CF63-C7DB-4116-85C8-FF4AF5C36A89}D:\steam games\steamapps\common\rise of the triad\binaries\win32\rott.exe" = protocol=17 | dir=in | app=d:\steam games\steamapps\common\rise of the triad\binaries\win32\rott.exe | 
"UDP Query User{9D8B8BD9-A84C-4101-991E-2F9B98506E4A}C:\games\baldur's gate ii enhanced edition\bg2ee.exe" = protocol=17 | dir=in | app=c:\games\baldur's gate ii enhanced edition\bg2ee.exe | 
"UDP Query User{A53D2BED-E1E3-4B71-97CE-EA3CE79EBA38}C:\program files (x86)\xbmc\xbmc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xbmc\xbmc.exe | 
"UDP Query User{AC4BF9B1-B98B-4393-964B-26CAEDB25AC3}C:\program files\comicrack\comicrack.exe" = protocol=17 | dir=in | app=c:\program files\comicrack\comicrack.exe | 
"UDP Query User{BD691F5F-00F8-4986-B1E5-3C8800E9E785}C:\games\baldur's gate enhanced edition\bgee.exe" = protocol=17 | dir=in | app=c:\games\baldur's gate enhanced edition\bgee.exe | 
"UDP Query User{C036C887-4175-4E01-9E97-3291639A5798}C:\windows\system32\javaw.exe" = protocol=17 | dir=in | app=c:\windows\system32\javaw.exe | 
"UDP Query User{E8C21B8C-DCC4-42FC-92CF-E85C043268C5}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | 
"UDP Query User{F63E1EF7-EAD0-455E-88F2-9FDE338B4774}C:\program files (x86)\java\jre7\launch4j-tmp\strange-eons.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\launch4j-tmp\strange-eons.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC6
"{0C719EDD-2815-500E-2193-E5793926EB04}" = AMD Fuel
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F06417065FF}" = Java 7 Update 65 (64-bit)
"{26A24AE4-039D-4CA4-87B4-2F86418005FF}" = Java 8 Update 5 (64-bit)
"{28336922-26D1-4638-B4D7-790A7F8F922E}" = PDF Split And Merge Basic
"{2A271428-D127-40B1-9728-662DAA3472F6}" = Gadwin PrintScreen (64-Bit)
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{3C4513C1-8A04-3381-0AED-FC1A59B5B255}" = AMD Wireless Display v3.0
"{5A53DBA6-9B15-450F-EDF3-C01E12E9C61F}" = AMD Catalyst Install Manager
"{5FC3AA31-66F9-0844-0B77-D51DAD5E1293}" = ccc-utility64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 3.0.8
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90C96F50-6055-4E41-A143-B0B02383223F}" = calibre 64bit
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{9EA981E5-EE67-4662-86F1-58937D31FE07}" = Nitro Reader 3
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{A8573F59-C080-4495-A9A8-EC32D8A4ECFF}" = TortoiseSVN 1.8.7.25475 (64 bit)
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{CAE09645-C59C-82E4-C676-73B7BD5EC34E}" = AMD Accelerated Video Transcoding
"{fa451eea-8a73-486b-9ea0-9628c2c2c3ad}.sdb" = alien_crossfire
"{fe81cd48-2ed2-4e7d-886c-b65767350095}.sdb" = alpha_centauri
"0581-5195-2362-0248" = Strange Eons 3745
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"CCleaner" = CCleaner
"ComicRack" = ComicRack v0.9.175
"Speccy" = Speccy
"VASSAL (3.2.11)" = VASSAL (3.2.11)
"VASSAL (3.2.12)" = VASSAL (3.2.12)
"WinRAR archiver" = WinRAR 5.10 beta 3 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0166E190-92D7-482A-A220-DE8B7354383A}" = Demigod
"{01712CA4-357E-B173-896C-75F612318729}" = CCC Help Japanese
"{01DEE6F4-E8AD-56B3-23CD-85CE71C08C57}" = CCC Help Danish
"{0203374B-2FFF-346D-0CC3-CACA1E85AD2C}" = CCC Help Greek
"{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}" = Razer Synapse 2.0
"{11074A02-0E73-7CD6-5A95-42B3EF438B7E}" = CCC Help Portuguese
"{111EE7DF-FC45-40C7-98A7-753AC46B12FB}" = QuickTime 7
"{13309695-DDAB-4DAA-FE9A-EE3DCCDC8D19}" = CCC Help Czech
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
"{1D568381-5001-403E-8D65-4A0D6E2ACC03}" = Soda PDF 6 View Module
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
"{253B90F3-7907-FB4B-7A62-6DE51B7A905D}" = CCC Help Chinese Traditional
"{25A3B953-1423-3F15-640E-B620DD0F419A}" = Catalyst Control Center - Branding
"{26A24AE4-039D-4CA4-87B4-2F83217055FF}" = Java 7 Update 67
"{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
"{30D1F3D2-54CF-481D-A005-F94B0E98FEEC}" = Sid Meier's Civilization 4 Complete
"{345C749F-8136-46C6-A174-9F2947429E0F}" = Warcraft 2.5
"{3B11D799-48E0-48ED-BFD7-EA655676D8BB}" = Star Wars: The Old Republic
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{3FDC2029-3012-C74C-9036-9E7C942EB0A2}" = CCC Help Thai
"{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1" = Foxit Cloud
"{43867B63-C464-4570-823D-D92DC08E3400}_is1" = Army Builder 3.4
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{49BF48CC-ABB6-4795-9B35-B5DE005D8612}" = Pinnacle Game Profiler
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A449AED-BFFA-A416-99F2-BF2462968370}" = CCC Help Italian
"{59E4543A-D49D-4489-B445-473D763C79AF}" = Microsoft Games for Windows - LIVE Redistributable
"{5A913692-7B91-486C-AA38-60E87C11BD7B}" = Razer StarCraft II
"{5F374D5D-DB43-4263-9C29-BAB2C93FEFE6}" = Warhammer Mark of Chaos
"{5F3E61A8-6465-4F78-B6BC-758A8FCDA736}" = CCC Help French
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{626C034B-50B8-47BD-AF93-EEFD0FA78FF4}" = Character Builder
"{661456B2-8102-D50F-CACD-7D7290716644}" = AMD Catalyst Control Center
"{69F64374-D859-E478-3BE7-DF995BB45A72}" = CCC Help Chinese Standard
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.18
"{7BF6AB6F-353B-6F9A-98D7-682429B63197}" = Catalyst Control Center InstallProxy
"{7f51bdb9-ee21-49ee-94d6-90afc321780e}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
"{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{842F265F-32FE-C610-78DA-F5CE882EFA32}" = CCC Help English
"{85579986-337B-C4C3-E86D-8E39F1D2A4A8}" = CCC Help Hungarian
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{925ADFF9-CFF2-57DC-1D09-664BE1306998}" = CCC Help Korean
"{940CFCDC-086A-E320-21DF-8AEB71D6F817}" = CCC Help Norwegian
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{971F06EE-6075-B8CE-115E-D2C74BE124C1}" = CCC Help Dutch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A838EB7-B0EE-F822-FE93-5B38B04C6E18}" = CCC Help Russian
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F609522-2B52-5EC4-6E5F-070E5EB47275}" = Catalyst Control Center Graphics Previews Common
"{9F850990-19CD-8CF4-D772-F84ECAAFEB7A}" = CCC Help Turkish
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A8EF51A6-F00D-6050-81F3-0AF338B81B04}" = CCC Help Polish
"{AB7C9BA6-37B6-4B4D-82A6-C6E97242C1AE}" = C&C:Online
"{ABC91C39-266D-4042-828E-4386E0F25218}" = Warhammer Battle March
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.08)
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B9372168-0CCC-3F40-B16F-A7AF1DB67149}" = CCC Help Finnish
"{C1E3DFE7-4EAD-3E9E-A826-E06055BA5921}" = Google Talk Plugin
"{CACB117C-8574-E9EA-C605-84673E9A7DDF}" = CCC Help Spanish
"{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{DC7734A3-535B-6FC6-39EE-A62E71FCAE63}" = Catalyst Control Center Localization All
"{DD131D15-2FD4-B0B1-6F7F-2312CBE77799}" = CCC Help Swedish
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{EF36A836-BF89-4A4F-B079-057B0C68C1E0}" = Sid Meier's Civilization IV Colonization
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8135163-F185-895A-C4CD-AB316D585030}" = CCC Help German
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player Plugin" = Adobe Flash Player 14 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.1
"Avast" = avast! Free Antivirus
"Baldur's Gate Enhanced Edition" = Baldur's Gate Enhanced Edition
"Baldur's Gate II Enhanced Edition" = Baldur's Gate II Enhanced Edition
"Battle.net" = Battle.net
"BeyondCompare3_is1" = Beyond Compare 3.3.10
"BitRaider Web Client" = BitRaider Web Client
"DAEMON Tools Lite" = DAEMON Tools Lite
"Device Doctor_is1" = Device Doctor v2.1
"Foxit Reader_is1" = Foxit Reader
"gBurner" = gBurner
"GIF Viewer" = GIF Viewer
"GOGPACKNWN2COMPLETE_is1" = Neverwinter Nights 2 Complete
"GOGPACKSIDMEIERSALPHACENTAURI_is1" = Sid Meier's Alpha Centauri
"GOGPACKTAKINGDOMS_is1" = Total Annihilation Kingdoms
"Google Chrome" = Google Chrome
"Impulse" = Impulse
"InstallShield_{CADDE354-C78C-46CB-A006-E2B178EFC271}" = Rise Of Legends
"IObit_StartMenu8_is1" = Start Menu 8
"IrfanView" = IrfanView (remove only)
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.2.1012
"MediaMonkey_is1" = MediaMonkey 4.1
"MiPony" = MiPony 2.1.4
"Mozilla Firefox 31.0 (x86 en-US)" = Mozilla Firefox 31.0 (x86 en-US)
"Mozilla Thunderbird 24.6.0 (x86 en-US)" = Mozilla Thunderbird 24.6.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Notepad++" = Notepad++
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"OpenAL" = OpenAL
"Origin" = Origin
"Raptr" = Raptr
"Razer Surround" = Razer Surround
"RPGVXAce_RTP_is1" = RPG MAKER VX Ace RTP
"Samsung Scan Assistant" = Samsung Scan Assistant
"Samsung SCX-3400 Series XPS (Windows 8)" = Samsung SCX-3400 Series XPS (Windows 8)
"Samsung Universal Scan Driver" = Samsung Universal Scan Driver
"Soda6" = Soda PDF 6
"SpywareBlaster_is1" = SpywareBlaster 5.0
"Steam" = Steam
"Steam App 113200" = The Binding of Isaac
"Steam App 200510" = XCOM: Enemy Unknown
"Steam App 213030" = Penny Arcade's On the Rain-Slick Precipice of Darkness 3
"Steam App 213610" = Sonic Adventure™ 2 
"Steam App 213850" = Magic 2014 
"Steam App 21690" = Resident Evil 5
"Steam App 217140" = Rise of the Triad
"Steam App 219740" = Don't Starve
"Steam App 220160" = Trials Evolution Gold Edition
"Steam App 22320" = The Elder Scrolls III: Morrowind
"Steam App 22370" = Fallout 3 - Game of the Year Edition
"Steam App 22380" = Fallout: New Vegas
"Steam App 226840" = Age of Wonders III
"Steam App 230190" = War for the Overworld Bedrock Beta
"Steam App 230230" = Divinity: Original Sin
"Steam App 237570" = Penny Arcade's On the Rain-Slick Precipice of Darkness 4
"Steam App 241540" = State of Decay
"Steam App 24400" = King Arthur - The Role-playing Wargame
"Steam App 253510" = Warmachine Tactics
"Steam App 255420" = Magic 2015
"Steam App 261030" = The Walking Dead: Season Two
"Steam App 265630" = Fistful of Frags
"Steam App 302380" = Floating Point
"Steam App 34010" = Alpha Protocol
"Steam App 3830" = Psychonauts
"Steam App 39120" = RIFT™
"Steam App 440" = Team Fortress 2
"Steam App 49520" = Borderlands 2
"Steam App 56400" = Warhammer® 40,000™: Dawn of War® II – Retribution™
"Steam App 58520" = Blood Bowl: Legendary Edition
"Steam App 70000" = Dino D-Day
"Steam App 71340" = Sonic Generations
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 9450" = Warhammer 40,000: Dawn of War – Soulstorm
"swtor_swtor" = Star Wars The Old Republic
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Uplay" = Uplay
"VLC media player" = VLC media player 2.1.3
"Warcraft III" = Warcraft III
"World of Warcraft" = World of Warcraft
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"101a9f93b8f0bb6f" = Curse Client
"Dropbox" = Dropbox
"GameRanger" = GameRanger
"Soulstorm Bugfix Mod" = Soulstorm Bugfix Mod
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent
"XBMC" = XBMC
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 2014-08-24 2:28:02 AM | Computer Name = Stirling-PC | Source = Application Error | ID = 1000
Description = Faulting application name: 7zptydhz.exe, version: 2.1.19357.0, time
 stamp: 0x52e7ea83  Faulting module name: 7zptydhz.exe, version: 2.1.19357.0, time
 stamp: 0x52e7ea83  Exception code: 0xc0000005  Fault offset: 0x000011aa  Faulting process
 id: 0x3898  Faulting application start time: 0x01cfbf647cc12b34  Faulting application
 path: E:\User\Downloads\7zptydhz.exe  Faulting module path: E:\User\Downloads\7zptydhz.exe
Report
 Id: cbd8573a-2b57-11e4-bef9-5404a6385e96  Faulting package full name:   Faulting package-relative
 application ID: 
 
Error - 2014-08-24 2:28:48 AM | Computer Name = Stirling-PC | Source = Application Error | ID = 1000
Description = Faulting application name: 7zptydhz.exe, version: 2.1.19357.0, time
 stamp: 0x52e7ea83  Faulting module name: 7zptydhz.exe, version: 2.1.19357.0, time
 stamp: 0x52e7ea83  Exception code: 0xc0000005  Fault offset: 0x000011aa  Faulting process
 id: 0x3868  Faulting application start time: 0x01cfbf6497d0c485  Faulting application
 path: E:\User\Downloads\7zptydhz.exe  Faulting module path: E:\User\Downloads\7zptydhz.exe
Report
 Id: e7d56149-2b57-11e4-bef9-5404a6385e96  Faulting package full name:   Faulting package-relative
 application ID: 
 
Error - 2014-08-24 2:29:25 AM | Computer Name = Stirling-PC | Source = Application Error | ID = 1000
Description = Faulting application name: 7zptydhz.exe, version: 2.1.19357.0, time
 stamp: 0x52e7ea83  Faulting module name: 7zptydhz.exe, version: 2.1.19357.0, time
 stamp: 0x52e7ea83  Exception code: 0xc0000005  Fault offset: 0x000011aa  Faulting process
 id: 0x3fec  Faulting application start time: 0x01cfbf64ada02034  Faulting application
 path: E:\User\Downloads\7zptydhz.exe  Faulting module path: E:\User\Downloads\7zptydhz.exe
Report
 Id: fd957a7b-2b57-11e4-bef9-5404a6385e96  Faulting package full name:   Faulting package-relative
 application ID: 
 
Error - 2014-08-24 2:44:11 AM | Computer Name = Stirling-PC | Source = Application Error | ID = 1000
Description = Faulting application name: 7zptydhz.exe, version: 2.1.19357.0, time
 stamp: 0x52e7ea83  Faulting module name: 7zptydhz.exe, version: 2.1.19357.0, time
 stamp: 0x52e7ea83  Exception code: 0xc0000005  Fault offset: 0x000011aa  Faulting process
 id: 0x40c8  Faulting application start time: 0x01cfbf66ba7e815d  Faulting application
 path: E:\User\Downloads\7zptydhz.exe  Faulting module path: E:\User\Downloads\7zptydhz.exe
Report
 Id: 0d74518f-2b5a-11e4-bef9-5404a6385e96  Faulting package full name:   Faulting package-relative
 application ID: 
 
Error - 2014-08-24 2:59:42 AM | Computer Name = Stirling-PC | Source = Application Hang | ID = 1002
Description = The program SDT_v1.21b.exe version 11.0.1.152 stopped interacting 
with Windows and was closed. To see if more information about the problem is available,
 check the problem history in the Action Center control panel.    Process ID: 3bc4    Start
 Time: 01cfbf653ce13b4b    Termination Time: 9    Application Path: E:\Stuff\SuperDeepThroat\SDT_v1.21b.exe
 
Report
 Id: 369b38bf-2b5c-11e4-bef9-5404a6385e96    Faulting package full name:     Faulting package-relative
 application ID:   
 
Error - 2014-08-24 2:46:37 PM | Computer Name = Stirling-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = Activation of app FileManager_cw5n1h2txyewy:Microsoft.Windows.PhotoManager
 failed with error: -2144927150 See the Microsoft-Windows-TWinUI/Operational log
 for additional information.
 
Error - 2014-08-25 5:58:08 PM | Computer Name = Stirling-PC | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
 in the System Writer Object.  Details: AddCoreCsiFiles : GetNextFileMapContent() failed.
 
System
 Error: The parameter is incorrect.  .
 
Error - 2014-08-25 5:58:59 PM | Computer Name = Stirling-PC | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = Activation of app FileManager_cw5n1h2txyewy:Microsoft.Windows.PhotoManager
 failed with error: -2144927150 See the Microsoft-Windows-TWinUI/Operational log
 for additional information.
 
Error - 2014-08-26 2:18:54 AM | Computer Name = Stirling-PC | Source = Application Hang | ID = 1002
Description = The program SDT_v1.21b.exe version 11.0.1.152 stopped interacting 
with Windows and was closed. To see if more information about the problem is available,
 check the problem history in the Action Center control panel.    Process ID: 480    Start
 Time: 01cfc0f3d28c6545    Termination Time: 7    Application Path: F:\Stuff\Hentai\xxx_Games\Super
 Deep Throat\SDT_v1.21b.exe    Report Id: d93e0309-2ce8-11e4-befc-5404a6385e96    Faulting
 package full name:     Faulting package-relative application ID:   
 
Error - 2014-08-26 2:20:57 AM | Computer Name = Stirling-PC | Source = Application Hang | ID = 1002
Description = The program SDT_v1.21b.exe version 11.0.1.152 stopped interacting 
with Windows and was closed. To see if more information about the problem is available,
 check the problem history in the Action Center control panel.    Process ID: 1788    Start
 Time: 01cfc0f59ecf62ca    Termination Time: 7    Application Path: F:\Stuff\Hentai\xxx_Games\Super
 Deep Throat\SDT_v1.21b.exe    Report Id: 22d82882-2ce9-11e4-befc-5404a6385e96    Faulting
 package full name:     Faulting package-relative application ID:   
 
[ System Events ]
Error - 2014-08-25 6:06:59 PM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7034
Description = The RzKLService service terminated unexpectedly.  It has done this
 1 time(s).
 
Error - 2014-08-25 6:07:22 PM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7031
Description = The Razer Game Scanner service terminated unexpectedly.  It has done
 this 1 time(s).  The following corrective action will be taken in 5000 milliseconds:
 Restart the service.
 
Error - 2014-08-25 6:20:25 PM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7000
Description = The UAC File Virtualization service failed to start due to the following
 error:   %%1275
 
Error - 2014-08-25 6:20:28 PM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7000
Description = The BuddyVM service failed to start due to the following error:   %%3
 
Error - 2014-08-25 6:20:33 PM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7034
Description = The PinnacleUpdate Service service terminated unexpectedly.  It has
 done this 1 time(s).
 
Error - 2014-08-25 11:21:18 PM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
 Client Service service to connect.
 
Error - 2014-08-25 11:21:18 PM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
 error:   %%1053
 
Error - 2014-08-26 9:29:47 AM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7000
Description = The UAC File Virtualization service failed to start due to the following
 error:   %%1275
 
Error - 2014-08-26 9:29:50 AM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7000
Description = The BuddyVM service failed to start due to the following error:   %%3
 
Error - 2014-08-26 9:29:55 AM | Computer Name = Stirling-PC | Source = Service Control Manager | ID = 7034
Description = The PinnacleUpdate Service service terminated unexpectedly.  It has
 done this 1 time(s).
 
 
< End of report >

  • 0

#6
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,583 posts

The good news is that I don't think you have any malware on your machine. I would like to do two scans to be sure. I also have some suggestions/warnings I would like to provide. Please follow instructions below.

 

Step#1 - Warnings

 

1. The Dangers of P2P Programs

IMPORTANT: I noticed that you have a P2P (Person to Person) file sharing program on your computer. I cannot stress highly enough the danger in using these types of programs. P2P programs are one of the major avenues of infection these days. The files downloaded with these programs are more than likely infected with trojans, malware, rootkits, etc.

You run the risk of getting an infection that can compromise your sensitive data, such as financial records, personal information, etc. That is just the infection aspect of using P2P programs. You also run the risk of possible arrest, fines, or in severe cases, jail time for illegal downloading of copyrighted material.

Here are some information sources about the dangers of P2P programs:

 

FBI - Peer to Peer Scams
USA Today Artticle on P2P Programs
File Sharing Infects 500,000 Computers

 

I very much recommend you uninstall this program from your machine. If not, you will likely be back needing help with your machine again. The risks of infections from content downloaded with P2P programs far outweigh any benefit of using them.

 

It is, of course, your choice as to whether or not you remove the program from your machine. It is my duty though, to point out how dangerous it is to use these programs. However, I must request that you do not use it while we are cleaning your machine.

 

Please uninstall the following Peer-to-Peer program(s): uTorrent

 

2. CCleaner
I see that you have CCleaner installed. This is indeed a good product but I wanted to caution you on running the registry cleaning functionality of the tool. Please avoid this as it can do more harm than good.

 

3. Low Disk Space

Your C:\ drive and E:\ drive are low on disk space. It is recommend that you have at least 15% free space so that the built-in defragger can run properly and to keep you running optimally. You may want to try and clean some things up to gain more disk space.

 

4. Outdated programs

I see that you have Spybot Search & Destroy as well as Spyware Blaster installed. We no longer recommend either of these programs as they are not effective and/or necessary any more. You should uninstall both of these programs.

 

 

Step#2 - Adware Cleaner

1. Please download AdwCleaner by Xplode onto your desktop.

2. Close all open programs and internet browsers.

3. Double click on AdwCleaner.exe to run the tool.

4. Click on Scan.

5. After the scan is complete click on "Clean"

6. Confirm each time with Ok.

7. Your computer will be rebooted automatically. A text file will open after the restart.

8. Please post the content of that logfile with your next answer.

9. You can find the logfile at C:\AdwCleaner[S1].txt as well.

 

 

Step#3 - MBR Check

1. Download aswMBR to your desktop.
2. Right click on the aswMBR.exe file and select Run as Administrator.

3. Answer yes if you are prompted that your computer supports Virtualization Technology.
4. If you see this question: Would you like to download latest Avast! virus definitions?" say "No".
5. Click the "Scan" button to start scan.
6. On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

 

 

Step#4 - Question

1. Did you happen to install an updated video card driver on August 11th of this month?

 

  

 

Items for your next post

1. Contents of the AdwCleaner log

2. Contents of the AswMbr log.

3. Answer to my question
 


Edited by BrianDrab, 27 August 2014 - 06:50 AM.

  • 0

#7
arcaneshield

arcaneshield

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts

ADW CLEANER 

 

# AdwCleaner v3.308 - Report created 28/08/2014 at 01:44:18

# Updated 20/08/2014 by Xplode
# Operating System : Windows 8.1 Pro with Media Center  (64 bits)
# Username : Stirling - STIRLING-PC
# Running from : E:\User\Stirling\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio
 
***** [ Scheduled Tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Conduit
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17239
 
 
-\\ Mozilla Firefox v31.0 (x86 en-US)
 
[ File : C:\Users\Stirling\AppData\Roaming\Mozilla\Firefox\Profiles\6be3n573.default\prefs.js ]
 
 
-\\ Google Chrome v36.0.1985.143
 
[ File : C:\Users\Stirling\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted [Extension] : gkojfkhlekighikafcpjkiklfbnlmeio
 
*************************
 
AdwCleaner[R0].txt - [2107 octets] - [24/06/2014 12:35:29]
AdwCleaner[R1].txt - [2167 octets] - [24/06/2014 12:36:41]
AdwCleaner[R2].txt - [1853 octets] - [09/07/2014 16:20:50]
AdwCleaner[R3].txt - [3191 octets] - [18/08/2014 18:42:58]
AdwCleaner[R4].txt - [1493 octets] - [18/08/2014 18:47:36]
AdwCleaner[R5].txt - [1696 octets] - [28/08/2014 01:38:26]
AdwCleaner[R6].txt - [1755 octets] - [28/08/2014 01:43:00]
AdwCleaner[S0].txt - [2225 octets] - [24/06/2014 12:50:19]
AdwCleaner[S1].txt - [1768 octets] - [09/07/2014 16:22:03]
AdwCleaner[S2].txt - [3215 octets] - [18/08/2014 18:45:14]
AdwCleaner[S3].txt - [1612 octets] - [18/08/2014 20:00:44]
AdwCleaner[S4].txt - [1682 octets] - [28/08/2014 01:44:18]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [1742 octets] ##########
 
MBR 
aswMBR version 1.0.1.2041 Copyright© 2014 AVAST Software
Run date: 2014-08-28 01:46:58
-----------------------------
01:46:58.079    OS Version: Windows x64 6.2.9200 
01:46:58.079    Number of processors: 8 586 0x200
01:46:58.080    ComputerName: STIRLING-PC  UserName: Stirling
01:46:58.474    Initialize success
01:46:58.475    VM: initialized successfully
01:46:58.482    VM: Amd CPU supported virtualized 
01:47:01.669    VM: supported disk I/O storport.sys
01:47:04.516    AVAST engine defs: 14082701
01:47:16.494    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002f
01:47:16.496    Disk 0 Vendor: Corsair_Force_GT 5.02 Size: 228936MB BusType: 11
01:47:16.498    Disk 1  \Device\Harddisk1\DR1 -> \Device\00000030
01:47:16.500    Disk 1 Vendor: ADATA_SP900 5.0.2a Size: 244198MB BusType: 11
01:47:16.503    Disk 2  \Device\Harddisk2\DR2 -> \Device\00000031
01:47:16.505    Disk 2 Vendor: WDC_WD1002FAEX-00Y9A0 05.01D05 Size: 953869MB BusType: 11
01:47:16.514    Disk 0 MBR read successfully
01:47:16.516    Disk 0 MBR scan
01:47:16.519    Disk 0 Windows 7 default MBR code
01:47:16.522    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       228585 MB offset 2048
01:47:16.535    Disk 0 scanning C:\WINDOWS\system32\drivers
01:47:19.079    Service scanning
01:47:24.415    Modules scanning
01:47:24.419    Disk 0 trace - called modules:
01:47:24.427    ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys amd_sata.sys hal.dll 
01:47:24.430    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001690d7060]
01:47:24.434    3 CLASSPNP.SYS[fffff800e120227b] -> nt!IofCallDriver -> [0xffffe00168f3a8e0]
01:47:24.437    5 amd_xata.sys[fffff800e0d28a5e] -> nt!IofCallDriver -> \Device\0000002f[0xffffe00167ffc510]
01:47:24.736    AVAST engine scan C:\WINDOWS
01:47:25.139    AVAST engine scan C:\WINDOWS\system32
01:48:13.995    AVAST engine scan C:\WINDOWS\system32\drivers
01:48:17.667    AVAST engine scan C:\Users\Stirling
01:50:26.193    AVAST engine scan C:\ProgramData
01:50:37.720    Scan finished successfully
01:54:04.646    Disk 0 MBR has been saved successfully to "E:\User\Stirling\MBR.dat"
01:54:04.649    The log file has been saved successfully to "E:\User\Stirling\aswMBR.txt"
 
Question #4:
 
I downloaded the update for my amd video card on the 12th. Used the beta because I keep waiting for them to fix the issues with Wildstar.

Edited by arcaneshield, 28 August 2014 - 12:55 AM.

  • 0

#8
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,583 posts

OK, the good news is that your computer is free from malware. I have a couple suggestions for you to try to see if it resolves your issues however.

Step#1 - Uninstall Beta Video Driver
1. Try going back to a previous non-beta version of the Video Driver just to see if it resolves your issue.

Step#2 - Windows Updates
Microsoft had a bad batch of updates this month that caused z order issues on windows amongst other things.

 

1. I see you brought your start button back (smile) so go ahead and go to Control Panel.
2. Click Uninstall a Program
3. Click the link on the left that says View installed updates.
4. In the upper right corner of the window where it says Search Programs and Features, please copy and paste the following KB numbers into it one at a time. If found, please select and uninstall.
If asked to reboot, please do each time.
KB2965768, KB2970228, KB2973201, KB2975719, KB2993651
5. You may want to temporarily stop your Windows Update service so they don't reinstall while you are testing. Instructions for doing this are below if you need.
6. Once these are uninstalled please let me know if the issue goes away.

Stopping Windows Update Service While Testing
1. Bring up your Start Screen.
2. Start typing Windows Update and click on the entry when found in the search.
3. Click on Change settings and change it to not install.


Let me know how it goes.


  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics


Also tagged with one or more of these keywords: Malware, Bug, Flickering, Windows 8

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP