Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Task Scheduler failed to initialize LSA for starting the Task Compatib


  • This topic is locked This topic is locked

#1
IkkaMouse

IkkaMouse

    Member

  • Member
  • PipPip
  • 25 posts

64bit- Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

 

Error - 27-11-2014 23:59:02 | Computer Name = Barry-PC | Source = Microsoft-Windows-TaskScheduler | ID = 704
Description = Task Scheduler failed to initialize LSA for starting the Task Compatibility
 module. Tasks may not be able to register on previous Window versions. Additional
 Data: Error Value: 2147942402.
 
Error - 27-11-2014 23:59:02 | Computer Name = Barry-PC | Source = Microsoft-Windows-TaskScheduler | ID = 701
Description = Task Scheduler service failed to start Task Compatibility module.
Tasks may not be able to register on previous Window versions. Additional Data:
Error Value: 2147942402.

 

 

OTL logfile created on: 29-11-2014 11:37:56 - Run 5
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Barry\Desktop
64bit- Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17420)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy
 
8,00 Gb Total Physical Memory | 5,68 Gb Available Physical Memory | 71,02% Memory free
20,00 Gb Paging File | 17,49 Gb Available in Paging File | 87,45% Paging File free
Paging file location(s): c:\pagefile.sys 12286 12286 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48,73 Gb Total Space | 14,69 Gb Free Space | 30,14% Space Free | Partition Type: NTFS
Drive D: | 211,85 Gb Total Space | 15,88 Gb Free Space | 7,50% Space Free | Partition Type: NTFS
Drive E: | 299,15 Gb Total Space | 39,17 Gb Free Space | 13,09% Space Free | Partition Type: NTFS
Drive F: | 632,35 Gb Total Space | 166,31 Gb Free Space | 26,30% Space Free | Partition Type: NTFS
Drive G: | 205,08 Gb Total Space | 57,17 Gb Free Space | 27,88% Space Free | Partition Type: NTFS
 
Computer Name: BARRY-PC | User Name: Barry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 14 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Barry\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_239.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\AVAST Software\Avast\avastui.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe (RaMMicHaeL)
PRC - C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe (RaMMicHaeL)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
MOD - C:\Program Files\AVAST Software\Avast\libcef.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (RtkAudioService) -- C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Unchecky) -- C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe (RaMMicHaeL)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (MBAMSwissArmy) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys (Malwarebytes Corporation)
DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswsnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys ()
DRV:64bit: - (aswStm) -- C:\Windows\SysNative\drivers\aswStm.sys (AVAST Software)
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys ()
DRV:64bit: - (aswHwid) -- C:\Windows\SysNative\drivers\aswHwid.sys ()
DRV:64bit: - (MBAMWebAccessControl) -- C:\Windows\SysNative\drivers\mwac.sys (Malwarebytes Corporation)
DRV:64bit: - (mbamchameleon) -- C:\Windows\SysNative\drivers\mbamchameleon.sys (Malwarebytes Corporation)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (Disc Soft Ltd)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (iaStorF) -- C:\Windows\SysNative\drivers\iaStorF.sys (Intel Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation)
DRV:64bit: - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (All) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft..../?LinkId=255141
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft..../?LinkId=255141
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft..../?LinkId=255141
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =  [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft..../?LinkId=255141
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\..\SearchScopes,DefaultScope = {C2F67A18-6136-401D-9A2C-45C335CA5CD8}
IE - HKCU\..\SearchScopes\{C2F67A18-6136-401D-9A2C-45C335CA5CD8}: "URL" = https://www.google.c...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "https://www.google.com/ncr | http://www.nu.nl/"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:10.0.2502.149
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1.1
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.25.2: C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2: C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-24 04:24:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2014-11-27 03:09:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Barry\AppData\Roaming\Mozilla\Extensions
[2014-11-27 03:23:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default\extensions
[2014-11-27 03:15:32 | 000,089,442 | ---- | M] () (No name found) -- C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default\extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi
[2014-11-27 03:23:01 | 000,979,699 | ---- | M] () (No name found) -- C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014-11-27 03:08:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014-11-27 03:08:43 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014-11-24 04:24:56 | 000,000,000 | ---D | M] ("Avast Online Security") -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
 
O1 HOSTS File: ([2014-11-29 05:33:27 | 000,001,871 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1    localhost
O1 - Hosts: 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
O1 - Hosts: 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
O1 - Hosts: 0.0.0.0 media.opencandy.com
O1 - Hosts: 0.0.0.0 cdn.opencandy.com
O1 - Hosts: 0.0.0.0 tracking.opencandy.com
O1 - Hosts: 0.0.0.0 api.opencandy.com
O1 - Hosts: 0.0.0.0 installer.betterinstaller.com
O1 - Hosts: 0.0.0.0 installer.filebulldog.com
O1 - Hosts: 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
O1 - Hosts: 0.0.0.0 inno.bisrv.com
O1 - Hosts: 0.0.0.0 nsis.bisrv.com
O1 - Hosts: 0.0.0.0 cdn.file2desktop.com
O1 - Hosts: 0.0.0.0 cdn.goateastcach.us
O1 - Hosts: 0.0.0.0 cdn.guttastatdk.us
O1 - Hosts: 0.0.0.0 cdn.inskinmedia.com
O1 - Hosts: 0.0.0.0 cdn.insta.oibundles2.com
O1 - Hosts: 0.0.0.0 cdn.insta.playbryte.com
O1 - Hosts: 0.0.0.0 cdn.llogetfastcach.us
O1 - Hosts: 0.0.0.0 cdn.montiera.com
O1 - Hosts: 0.0.0.0 cdn.msdwnld.com
O1 - Hosts: 0.0.0.0 cdn.mypcbackup.com
O1 - Hosts: 0.0.0.0 cdn.ppdownload.com
O1 - Hosts: 0.0.0.0 cdn.riceateastcach.us
O1 - Hosts: 0.0.0.0 cdn.shyapotato.us
O1 - Hosts: 11 more lines...
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{29F60707-DF66-4759-8EB7-41A44A984E9B}: NameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\System32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21:64bit: - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\Windows\SysNative\WPDShServiceObj.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 14 Days ==========
 
[2014-11-29 06:30:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Barry\Desktop\OTL.exe
[2014-11-29 02:57:20 | 000,000,000 | ---D | C] -- C:\Users\Barry\Desktop\ccsetup500
[2014-11-28 23:04:28 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Roaming\PFStaticIP
[2014-11-28 22:50:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PortForward.com
[2014-11-28 22:50:18 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Roaming\PortForward.com
[2014-11-28 22:50:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Portforward
[2014-11-28 01:31:00 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\svchost.exe
[2014-11-27 03:09:07 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Roaming\Mozilla
[2014-11-27 03:09:07 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Local\Mozilla
[2014-11-27 03:08:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2014-11-27 03:08:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2014-11-27 03:08:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014-11-27 02:56:36 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Roaming\CrystalIdea Software
[2014-11-26 23:04:59 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014-11-26 01:48:06 | 000,098,216 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014-11-26 01:47:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014-11-26 01:47:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2014-11-24 04:25:31 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Roaming\AVAST Software
[2014-11-24 04:25:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2014-11-24 04:25:05 | 000,116,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2014-11-24 04:25:03 | 000,436,624 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014-11-24 04:25:02 | 000,083,280 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014-11-24 04:25:00 | 000,093,568 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014-11-24 04:24:59 | 001,050,432 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2014-11-24 04:24:57 | 000,364,512 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014-11-24 04:24:55 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2014-11-24 04:24:40 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2014-11-24 04:22:53 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2014-11-22 01:53:11 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2014-11-22 01:40:21 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2014-11-22 01:40:16 | 000,708,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014-11-22 01:40:16 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2014-11-22 01:40:16 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2014-11-22 01:40:16 | 000,478,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014-11-22 01:40:16 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2014-11-22 01:40:16 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2014-11-22 01:40:16 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2014-11-22 01:40:16 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014-11-22 01:40:16 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2014-11-22 01:40:16 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2014-11-22 01:40:16 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014-11-22 01:40:15 | 002,051,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014-11-22 01:40:15 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014-11-22 01:40:15 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014-11-22 01:40:15 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2014-11-22 01:40:15 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2014-11-22 01:40:15 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2014-11-22 01:40:15 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2014-11-22 01:40:15 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2014-11-22 01:40:15 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014-11-22 01:40:15 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2014-11-22 01:40:15 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2014-11-22 01:40:15 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2014-11-22 01:40:15 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014-11-22 01:40:15 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2014-11-22 01:40:15 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2014-11-22 01:40:15 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014-11-22 01:40:15 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014-11-22 01:40:15 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2014-11-22 01:40:15 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2014-11-22 01:40:15 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014-11-22 01:40:15 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014-11-22 01:40:15 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2014-11-22 01:40:15 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2014-11-22 01:40:14 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2014-11-22 01:40:14 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2014-11-22 01:40:14 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2014-11-22 01:40:13 | 006,040,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014-11-22 01:40:13 | 002,124,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014-11-22 01:40:13 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014-11-22 01:40:13 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014-11-22 01:40:13 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014-11-22 01:40:13 | 000,799,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014-11-22 01:40:13 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014-11-22 01:40:13 | 000,633,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014-11-22 01:40:13 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2014-11-22 01:40:13 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014-11-22 01:40:13 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2014-11-22 01:40:13 | 000,316,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014-11-22 01:40:13 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2014-11-22 01:40:13 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014-11-22 01:40:13 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2014-11-22 01:40:13 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2014-11-22 01:40:13 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2014-11-22 01:40:13 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2014-11-22 01:40:13 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2014-11-22 01:40:13 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014-11-22 01:40:13 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2014-11-22 01:40:13 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2014-11-22 01:40:13 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014-11-22 01:40:13 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2014-11-22 01:40:13 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014-11-22 01:40:13 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2014-11-22 01:40:13 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014-11-22 01:40:13 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2014-11-22 01:40:13 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2014-11-22 01:40:12 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2014-11-22 01:40:12 | 000,580,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014-11-22 01:40:12 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2014-11-22 01:40:12 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014-11-22 01:40:12 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2014-11-22 01:40:12 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014-11-22 01:40:12 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014-11-22 01:40:12 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2014-11-22 01:40:12 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014-11-22 01:40:12 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2014-11-22 01:40:12 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2014-11-22 01:40:12 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014-11-20 22:48:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2014-11-20 01:30:20 | 000,000,000 | ---D | C] -- C:\Program Files\WindowsPowerShell
[2014-11-20 01:30:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WindowsPowerShell
[2014-11-20 01:30:18 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\dsc
[2014-11-20 01:30:17 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Configuration
[2014-11-20 01:22:43 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncobjapi.dll
[2014-11-20 01:22:43 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncobjapi.dll
[2014-11-20 01:22:39 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Register-CimProvider.exe
[2014-11-20 01:22:39 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Register-CimProvider.exe
[2014-11-20 01:22:36 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winrs.exe
[2014-11-20 01:22:36 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winrshost.exe
[2014-11-20 01:22:34 | 000,001,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrsmgr.dll
[2014-11-20 01:22:34 | 000,001,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winrsmgr.dll
[2014-11-20 01:22:33 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrs.exe
[2014-11-20 01:22:33 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrshost.exe
[2014-11-20 01:22:31 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsmplpxy.dll
[2014-11-20 01:22:31 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winrssrv.dll
[2014-11-20 01:22:30 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wevtfwd.dll
[2014-11-20 01:22:30 | 000,104,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wecutil.exe
[2014-11-20 01:22:30 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wevtfwd.dll
[2014-11-20 01:22:30 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wecapi.dll
[2014-11-20 01:22:30 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wecutil.exe
[2014-11-20 01:22:30 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wecapi.dll
[2014-11-20 01:22:29 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmRes.dll
[2014-11-20 01:22:29 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmRes.dll
[2014-11-20 01:22:28 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\prvdmofcomp.dll
[2014-11-20 01:22:28 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\prvdmofcomp.dll
[2014-11-20 01:22:28 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PSModuleDiscoveryProvider.dll
[2014-11-20 01:22:28 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PSModuleDiscoveryProvider.dll
[2014-11-20 01:22:28 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmAgent.dll
[2014-11-20 01:22:28 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAgent.dll
[2014-11-20 01:22:28 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
[2014-11-20 01:22:28 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
[2014-11-20 01:22:28 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsmplpxy.dll
[2014-11-20 01:22:28 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrssrv.dll
[2014-11-20 01:22:27 | 000,108,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mi.dll
[2014-11-20 01:22:27 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winrscmd.dll
[2014-11-20 01:22:27 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrscmd.dll
[2014-11-20 01:22:27 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mi.dll
[2014-11-20 01:22:27 | 000,036,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsmprovhost.exe
[2014-11-20 01:22:27 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManHTTPConfig.exe
[2014-11-20 01:22:27 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wsmprovhost.exe
[2014-11-20 01:22:27 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManHTTPConfig.exe
[2014-11-20 01:22:26 | 000,247,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\framedynos.dll
[2014-11-20 01:22:26 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\framedyn.dll
[2014-11-20 01:22:26 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\framedynos.dll
[2014-11-20 01:22:26 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\framedyn.dll
[2014-11-20 01:22:26 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WSManMigrationPlugin.dll
[2014-11-20 01:22:26 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pwrshplugin.dll
[2014-11-20 01:22:26 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManMigrationPlugin.dll
[2014-11-20 01:22:26 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pwrshplugin.dll
[2014-11-20 01:22:24 | 000,274,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmWmiPl.dll
[2014-11-20 01:22:24 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmWmiPl.dll
[2014-11-20 01:22:24 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\miutils.dll
[2014-11-20 01:22:24 | 000,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmitomi.dll
[2014-11-20 01:22:24 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DscCore.dll
[2014-11-20 01:22:24 | 000,197,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DscCoreConfProv.dll
[2014-11-20 01:22:24 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\miutils.dll
[2014-11-20 01:22:24 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmidcom.dll
[2014-11-20 01:22:24 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmAuto.dll
[2014-11-20 01:22:24 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmitomi.dll
[2014-11-20 01:22:24 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mimofcodec.dll
[2014-11-20 01:22:24 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAuto.dll
[2014-11-20 01:22:24 | 000,125,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmidcom.dll
[2014-11-20 01:22:24 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mimofcodec.dll
[2014-11-20 01:22:24 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mibincodec.dll
[2014-11-20 01:22:24 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mibincodec.dll
[2014-11-20 01:22:23 | 000,600,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WsmGCDeps.dll
[2014-11-20 01:22:23 | 000,515,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmGCDeps.dll
[2014-11-20 01:22:23 | 000,476,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wbemcomn2.dll
[2014-11-20 01:22:23 | 000,371,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wbemcomn2.dll
[2014-11-19 02:22:05 | 000,000,000 | ---D | C] -- C:\Users\Barry\SecurityScans
[2014-11-19 01:39:49 | 004,890,736 | ---- | C] (Piriform Ltd) -- C:\Users\Barry\Desktop\spsetup126.exe
[2014-11-18 23:02:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2014-11-18 23:01:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2014-11-18 23:01:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2014-11-17 01:57:05 | 000,207,960 | ---- | C] (Sysinternals) -- C:\Windows\Contig.exe
[2014-11-17 00:34:43 | 000,000,000 | ---D | C] -- C:\Users\Barry\AppData\Roaming\vlc
[2014-11-17 00:34:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2014-11-17 00:34:03 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Barry\*.tmp files -> C:\Users\Barry\*.tmp -> ]
 
========== Files - Modified Within 14 Days ==========
 
[2014-11-29 09:27:58 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014-11-29 09:12:02 | 000,026,336 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014-11-29 09:12:02 | 000,026,336 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014-11-29 06:30:12 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Barry\Desktop\OTL.exe
[2014-11-29 06:06:50 | 000,852,490 | ---- | M] () -- C:\Users\Barry\Desktop\SecurityCheck.exe
[2014-11-29 05:35:28 | 000,821,598 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014-11-29 05:35:28 | 000,680,114 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014-11-29 05:35:28 | 000,126,788 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014-11-29 05:33:27 | 000,001,871 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014-11-29 05:31:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014-11-28 22:50:19 | 000,002,815 | ---- | M] () -- C:\Users\Public\Desktop\PortForward Network Utilities.lnk
[2014-11-28 22:17:23 | 000,000,000 | -H-- | M] () -- C:\Users\Barry\Documents\Default.rdp
[2014-11-26 02:22:21 | 002,148,864 | ---- | M] () -- C:\Users\Barry\Desktop\adwcleaner_4.102.exe
[2014-11-26 01:47:52 | 000,098,216 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2014-11-26 01:36:05 | 000,701,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014-11-26 01:36:05 | 000,071,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014-11-25 22:35:41 | 001,066,038 | ---- | M] () -- C:\Users\Barry\Desktop\FixDotNet20141125213536005.cab
[2014-11-24 04:25:18 | 001,050,432 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswsnx.sys
[2014-11-24 04:24:55 | 000,436,624 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2014-11-24 04:24:55 | 000,364,512 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2014-11-24 04:24:55 | 000,267,632 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014-11-24 04:24:55 | 000,116,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2014-11-24 04:24:55 | 000,093,568 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2014-11-24 04:24:55 | 000,083,280 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2014-11-24 04:24:55 | 000,065,776 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014-11-24 04:24:55 | 000,043,152 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2014-11-24 04:24:55 | 000,029,208 | ---- | M] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2014-11-23 04:36:11 | 000,001,559 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts (1)
[2014-11-22 03:28:44 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Barry\Desktop\HijackThis.exe
[2014-11-22 01:40:21 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2014-11-22 01:40:16 | 002,051,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014-11-22 01:40:16 | 000,708,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014-11-22 01:40:16 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2014-11-22 01:40:16 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2014-11-22 01:40:16 | 000,478,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014-11-22 01:40:16 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2014-11-22 01:40:16 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2014-11-22 01:40:16 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2014-11-22 01:40:16 | 000,168,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014-11-22 01:40:16 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2014-11-22 01:40:16 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2014-11-22 01:40:16 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2014-11-22 01:40:15 | 001,155,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2014-11-22 01:40:15 | 000,620,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014-11-22 01:40:15 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2014-11-22 01:40:15 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2014-11-22 01:40:15 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2014-11-22 01:40:15 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2014-11-22 01:40:15 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2014-11-22 01:40:15 | 000,115,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014-11-22 01:40:15 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2014-11-22 01:40:15 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2014-11-22 01:40:15 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2014-11-22 01:40:15 | 000,076,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014-11-22 01:40:15 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2014-11-22 01:40:15 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2014-11-22 01:40:15 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2014-11-22 01:40:15 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014-11-22 01:40:15 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2014-11-22 01:40:15 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2014-11-22 01:40:15 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014-11-22 01:40:15 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014-11-22 01:40:15 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2014-11-22 01:40:15 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2014-11-22 01:40:15 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2014-11-22 01:40:14 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2014-11-22 01:40:14 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2014-11-22 01:40:14 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2014-11-22 01:40:13 | 006,040,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014-11-22 01:40:13 | 002,124,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014-11-22 01:40:13 | 001,359,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2014-11-22 01:40:13 | 000,814,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014-11-22 01:40:13 | 000,800,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014-11-22 01:40:13 | 000,799,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014-11-22 01:40:13 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014-11-22 01:40:13 | 000,633,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014-11-22 01:40:13 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2014-11-22 01:40:13 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014-11-22 01:40:13 | 000,490,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2014-11-22 01:40:13 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2014-11-22 01:40:13 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2014-11-22 01:40:13 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2014-11-22 01:40:13 | 000,199,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014-11-22 01:40:13 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2014-11-22 01:40:13 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2014-11-22 01:40:13 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2014-11-22 01:40:13 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2014-11-22 01:40:13 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2014-11-22 01:40:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014-11-22 01:40:13 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2014-11-22 01:40:13 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2014-11-22 01:40:13 | 000,077,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2014-11-22 01:40:13 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2014-11-22 01:40:13 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014-11-22 01:40:13 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2014-11-22 01:40:13 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014-11-22 01:40:13 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2014-11-22 01:40:13 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2014-11-22 01:40:13 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2014-11-22 01:40:12 | 000,774,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2014-11-22 01:40:12 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2014-11-22 01:40:12 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014-11-22 01:40:12 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2014-11-22 01:40:12 | 000,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014-11-22 01:40:12 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2014-11-22 01:40:12 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2014-11-22 01:40:12 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014-11-22 01:40:12 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2014-11-22 01:40:12 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2014-11-22 01:40:12 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014-11-21 04:03:17 | 000,001,441 | ---- | M] () -- C:\Users\Barry\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014-11-19 01:39:53 | 004,890,736 | ---- | M] (Piriform Ltd) -- C:\Users\Barry\Desktop\spsetup126.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Barry\*.tmp files -> C:\Users\Barry\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014-11-29 06:01:58 | 000,852,490 | ---- | C] () -- C:\Users\Barry\Desktop\SecurityCheck.exe
[2014-11-28 22:50:19 | 000,002,815 | ---- | C] () -- C:\Users\Public\Desktop\PortForward Network Utilities.lnk
[2014-11-28 22:17:23 | 000,000,000 | -H-- | C] () -- C:\Users\Barry\Documents\Default.rdp
[2014-11-27 03:08:45 | 000,001,163 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2014-11-26 02:22:16 | 002,148,864 | ---- | C] () -- C:\Users\Barry\Desktop\adwcleaner_4.102.exe
[2014-11-25 22:35:41 | 001,066,038 | ---- | C] () -- C:\Users\Barry\Desktop\FixDotNet20141125213536005.cab
[2014-11-24 04:25:04 | 000,267,632 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys
[2014-11-24 04:25:02 | 000,065,776 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2014-11-24 04:25:01 | 000,029,208 | ---- | C] () -- C:\Windows\SysNative\drivers\aswHwid.sys
[2014-11-22 01:40:15 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2014-11-22 01:40:13 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2014-11-21 04:38:48 | 000,001,377 | ---- | C] () -- C:\Users\Barry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014-11-21 03:32:10 | 000,001,441 | ---- | C] () -- C:\Users\Barry\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014-11-20 01:22:34 | 000,204,105 | ---- | C] () -- C:\Windows\SysWow64\winrm.vbs
[2014-11-20 01:22:34 | 000,204,105 | ---- | C] () -- C:\Windows\SysNative\winrm.vbs
[2014-11-20 01:22:33 | 000,004,675 | ---- | C] () -- C:\Windows\SysNative\wsmanconfig_schema.xml
[2014-11-20 01:22:31 | 000,004,675 | ---- | C] () -- C:\Windows\SysWow64\wsmanconfig_schema.xml
[2014-11-20 01:22:28 | 000,004,148 | ---- | C] () -- C:\Windows\SysNative\psmodulediscoveryprovider.mof
[2014-10-07 23:06:55 | 000,000,696 | ---- | C] () -- C:\Users\Barry\AppData\Local\recently-used.xbel
[2014-09-28 08:06:17 | 000,020,560 | ---- | C] () -- C:\Windows\prodsett_copy.ini
[2014-09-14 23:03:35 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\zlib.dll
[2014-09-08 21:26:05 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-BARRY-PC-Microsoft-Windows-7-Enterprise-(64-bit).dat
[2014-08-22 20:14:42 | 000,064,720 | ---- | C] () -- C:\Windows\SysWow64\drivers\OADriver.sys
[2014-08-22 20:14:42 | 000,062,008 | ---- | C] () -- C:\Windows\SysWow64\drivers\oahlp64.sys
[2014-08-11 21:27:14 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2014-08-03 23:24:20 | 000,000,020 | ---- | C] () -- C:\Windows\cmm.dat
[2014-06-01 22:38:41 | 000,001,996 | ---- | C] () -- C:\Windows\SysWow64\SearchIndexer.exe.virtual.lnk
[2014-05-23 17:38:59 | 000,000,000 | ---- | C] () -- C:\ProgramData\DP45977C.lfl
[2014-05-17 21:59:38 | 000,007,660 | ---- | C] () -- C:\Users\Barry\AppData\Local\resmon.resmoncfg
[2014-05-15 18:16:00 | 000,000,085 | ---- | C] () -- C:\Windows\wininit.ini
[2014-04-24 22:11:32 | 000,001,580 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014-04-12 18:39:35 | 000,218,200 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2014-04-11 23:14:19 | 000,784,114 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013-04-30 03:37:40 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013-04-30 03:37:40 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
 
========== ZeroAccess Check ==========
 
[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014-06-25 03:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014-06-25 02:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013-09-27 03:52:49 | 000,843,264 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = c:\windows\syswow64\wbem\fastprox.dll -- [2013-09-27 02:14:40 | 000,634,880 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013-09-27 03:50:16 | 000,435,200 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014-10-13 23:56:15 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\abgx360
[2014-11-24 04:25:31 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\AVAST Software
[2014-11-27 04:18:35 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\CrystalIdea Software
[2014-09-13 08:25:21 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\DAEMON Tools Lite
[2014-04-28 13:08:29 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\ImgBurn
[2014-10-27 19:53:04 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\JAM Software
[2014-08-11 21:17:48 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\library_dir
[2014-11-25 21:02:30 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\NewsLeecher
[2014-11-29 02:25:05 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\PFStaticIP
[2014-11-28 23:01:31 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\PortForward.com
[2014-09-21 00:56:18 | 000,000,000 | ---D | M] -- C:\Users\Barry\AppData\Roaming\XBMC
 
========== Purity Check ==========
 
 

< End of report >
 


  • 0

Advertisements


#2
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts
Please download FRST (by Farbar) from the link below and save it to your Desktop.

Download Mirror #1

If you are unsure whether you have 32-Bit or 64-Bit Windows, see here
  • Disable all anti-virus and anti-malware software to prevent them inhibiting FRST in any way. If you are unsure how to do this, see THIS.
  • Double-click FRST.exe/FRST64.exe (depending on which version you downloaded) to run it. (if you have Windows Vista / Windows 7 / Windows 8: Please do a Right click on the FRST icon and select Run as Administrator)
  • When the disclaimer appears, click Yes.
  • Click Scan to start FRST.
  • When FRST finishes scanning, two logs, FRST.txt and Addition.txt will open.
  • Copy (Ctrl+C) and Paste (Ctrl+V) the contents of both of these logs into your next post please.

  • 0

#3
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Thankz Machiavelli for your support .

 

 

here the log files :

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-11-2014
Ran by Barry (administrator) on BARRY-PC on 30-11-2014 18:17:30
Running from C:\Users\Barry\Desktop
Loaded Profile: Barry (Available profiles: Barry & Administrator)
Platform: Windows 7 Enterprise Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-05-09] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-24] (AVAST Software)
HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\Windows\system32\WPDShServiceObj.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [0_sxBZOverlayIcon] -> {6457FB0A-5C02-4393-909C-2139A5D5571F} =>  No File
ShellIconOverlayIdentifiers: [0_sxConfidentialOIcon] -> {871FE18B-B68D-4437-BC76-6634996CDB97} =>  No File
ShellIconOverlayIdentifiers: [0_sxForbiddenOIcon] -> {1F03249C-6AB2-4E31-8C10-86F7E31E3B4E} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...d=ie&ar=msnhome
HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-1267563920-2322599392-2657086146-1001 -> DefaultScope {C2F67A18-6136-401D-9A2C-45C335CA5CD8} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1267563920-2322599392-2657086146-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1267563920-2322599392-2657086146-1001 -> {C2F67A18-6136-401D-9A2C-45C335CA5CD8} URL = https://www.google.c...q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{29F60707-DF66-4759-8EB7-41A44A984E9B}: [NameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default
FF Homepage: https://www.google.com/ncr | hxxp://www.nu.nl/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Extension: Password Exporter - C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi [2014-11-27]
FF Extension: Adblock Plus - C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-27]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-24]
FF Extension: No Name - [email protected] [Not Found]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2014-11-24]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-24]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-24] (AVAST Software)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S4 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [111208 2014-11-23] (RaMMicHaeL)
S4 AdobeARMservice; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-24] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-24] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-24] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-24] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-11] (Disc Soft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation)
R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [93400 2014-10-01] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [465624 2014-01-03] (Realsil Semiconductor Corporation)
U3 DfSdkS; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-30 18:17 - 2014-11-30 18:17 - 00010231 _____ () C:\Users\Barry\Desktop\FRST.txt
2014-11-30 18:17 - 2014-11-30 18:17 - 00000000 ____D () C:\FRST
2014-11-30 18:11 - 2014-11-30 18:11 - 02117120 _____ (Farbar) C:\Users\Barry\Desktop\FRST64.exe
2014-11-29 11:43 - 2014-11-29 11:43 - 00052922 _____ () C:\Users\Barry\Desktop\Extras.Txt
2014-11-29 11:42 - 2014-11-29 11:42 - 00149290 _____ () C:\Users\Barry\Desktop\OTL.Txt
2014-11-29 06:30 - 2014-11-29 06:30 - 00602112 _____ (OldTimer Tools) C:\Users\Barry\Desktop\OTL.exe
2014-11-29 06:01 - 2014-11-29 06:06 - 00852490 _____ () C:\Users\Barry\Desktop\SecurityCheck.exe
2014-11-29 05:39 - 2014-11-29 05:39 - 00011331 _____ () C:\Users\Barry\Desktop\startuplist.txt
2014-11-29 05:06 - 2014-11-29 05:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-11-29 05:06 - 2014-11-29 05:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-11-29 05:05 - 2014-11-29 05:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\AVAST Software
2014-11-29 02:57 - 2014-11-29 03:08 - 00000000 ____D () C:\Users\Barry\Desktop\ccsetup500
2014-11-28 23:04 - 2014-11-29 02:25 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\PFStaticIP
2014-11-28 22:50 - 2014-11-28 23:01 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\PortForward.com
2014-11-28 22:50 - 2014-11-28 22:50 - 00002815 _____ () C:\Users\Public\Desktop\PortForward Network Utilities.lnk
2014-11-28 22:50 - 2014-11-28 22:50 - 00002815 _____ () C:\ProgramData\Desktop\PortForward Network Utilities.lnk
2014-11-28 22:50 - 2014-11-28 22:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PortForward.com
2014-11-28 22:50 - 2014-11-28 22:50 - 00000000 ____D () C:\Program Files (x86)\Portforward
2014-11-28 22:17 - 2014-11-28 22:17 - 00000000 ____H () C:\Users\Barry\Documents\Default.rdp
2014-11-28 01:31 - 2011-03-01 09:07 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\svchost.exe
2014-11-28 01:31 - 2011-03-01 09:05 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
2014-11-27 03:09 - 2014-11-27 03:09 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\Mozilla
2014-11-27 03:09 - 2014-11-27 03:09 - 00000000 ____D () C:\Users\Barry\AppData\Local\Mozilla
2014-11-27 03:08 - 2014-11-27 03:08 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-27 03:08 - 2014-11-27 03:08 - 00000000 ____D () C:\ProgramData\Mozilla
2014-11-27 03:08 - 2014-11-27 03:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-27 03:08 - 2014-11-27 03:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-27 02:56 - 2014-11-27 04:18 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\CrystalIdea Software
2014-11-26 02:22 - 2014-11-26 02:22 - 02148864 _____ () C:\Users\Barry\Desktop\adwcleaner_4.102.exe
2014-11-26 01:48 - 2014-11-26 01:47 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-11-26 01:47 - 2014-11-26 01:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-11-26 01:47 - 2014-11-26 01:47 - 00000000 ____D () C:\Program Files (x86)\Java
2014-11-25 22:35 - 2014-11-25 22:35 - 01066038 _____ () C:\Users\Barry\Desktop\FixDotNet20141125213536005.cab
2014-11-24 04:25 - 2014-11-27 06:00 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-11-24 04:25 - 2014-11-24 04:25 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\AVAST Software
2014-11-24 04:25 - 2014-11-24 04:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2014-11-24 04:25 - 2014-11-24 04:24 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-11-24 04:24 - 2014-11-24 04:25 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-11-24 04:24 - 2014-11-24 04:24 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-11-24 04:24 - 2014-11-24 04:24 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-11-24 04:24 - 2014-11-24 04:24 - 00000000 ____D () C:\Program Files\AVAST Software
2014-11-24 04:22 - 2014-11-24 04:24 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-11-23 22:24 - 2014-11-23 22:24 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-11-23 22:24 - 2014-11-23 22:24 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-11-23 04:37 - 2014-11-24 04:17 - 00000000 ____D () C:\Windows\System32\Tasks\Doctor Web
2014-11-23 04:36 - 2014-11-23 04:36 - 00001559 _____ () C:\Windows\system32\Drivers\etc\hosts (1)
2014-11-22 01:53 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-22 01:40 - 2014-11-22 01:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-22 01:40 - 2014-11-22 01:40 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-22 01:40 - 2014-11-22 01:40 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-22 01:40 - 2014-11-22 01:40 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-11-22 01:40 - 2014-11-22 01:40 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-11-22 01:40 - 2014-11-22 01:40 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-11-22 01:40 - 2014-11-22 01:40 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-11-22 01:40 - 2014-11-22 01:40 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-11-22 01:40 - 2014-11-22 01:40 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-11-22 01:40 - 2014-11-22 01:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-21 04:38 - 2014-11-22 01:44 - 00001377 _____ () C:\Users\Barry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-21 03:48 - 2014-11-21 03:49 - 00003249 _____ () C:\Windows\IE9_main.log
2014-11-21 03:43 - 2014-11-21 04:36 - 00017415 _____ () C:\Windows\IE10_main.log
2014-11-20 01:30 - 2014-11-20 01:30 - 00000000 ____D () C:\Windows\system32\dsc
2014-11-20 01:30 - 2014-11-20 01:30 - 00000000 ____D () C:\Windows\system32\Configuration
2014-11-20 01:30 - 2014-11-20 01:30 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2014-11-20 01:30 - 2014-11-20 01:30 - 00000000 ____D () C:\Program Files (x86)\WindowsPowerShell
2014-11-20 01:22 - 2013-09-27 04:37 - 00001536 _____ (Microsoft Corporation) C:\Windows\system32\winrsmgr.dll
2014-11-20 01:22 - 2013-09-27 04:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2014-11-20 01:22 - 2013-09-27 04:20 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\mimofcodec.dll
2014-11-20 01:22 - 2013-09-27 04:19 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\ncobjapi.dll
2014-11-20 01:22 - 2013-09-27 04:18 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\mi.dll
2014-11-20 01:22 - 2013-09-27 04:18 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
2014-11-20 01:22 - 2013-09-27 04:17 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\mibincodec.dll
2014-11-20 01:22 - 2013-09-27 04:16 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\wecapi.dll
2014-11-20 01:22 - 2013-09-27 04:16 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2014-11-20 01:22 - 2013-09-27 04:16 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\winrssrv.dll
2014-11-20 01:22 - 2013-09-27 04:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\wevtfwd.dll
2014-11-20 01:22 - 2013-09-27 04:03 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\Register-CimProvider.exe
2014-11-20 01:22 - 2013-09-27 03:59 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\wecutil.exe
2014-11-20 01:22 - 2013-09-27 03:58 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\wecsvc.dll
2014-11-20 01:22 - 2013-09-27 03:53 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\wmitomi.dll
2014-11-20 01:22 - 2013-09-27 03:53 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\prvdmofcomp.dll
2014-11-20 01:22 - 2013-09-27 03:50 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\wmidcom.dll
2014-11-20 01:22 - 2013-09-27 03:49 - 00476672 _____ (Microsoft Corporation) C:\Windows\system32\wbemcomn2.dll
2014-11-20 01:22 - 2013-09-27 03:48 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\miutils.dll
2014-11-20 01:22 - 2013-09-27 03:46 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-11-20 01:22 - 2013-09-27 03:45 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-11-20 01:22 - 2013-09-27 03:40 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\WsmAgent.dll
2014-11-20 01:22 - 2013-09-27 03:34 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\DscCoreConfProv.dll
2014-11-20 01:22 - 2013-09-27 03:27 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\winrshost.exe
2014-11-20 01:22 - 2013-09-27 03:21 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\WsmGCDeps.dll
2014-11-20 01:22 - 2013-09-27 03:20 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\winrs.exe
2014-11-20 01:22 - 2013-09-27 03:19 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-11-20 01:22 - 2013-09-27 03:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2014-11-20 01:22 - 2013-09-27 03:18 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-11-20 01:22 - 2013-09-27 03:17 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-11-20 01:22 - 2013-09-27 03:17 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\winrscmd.dll
2014-11-20 01:22 - 2013-09-27 03:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\PSModuleDiscoveryProvider.dll
2014-11-20 01:22 - 2013-09-27 03:06 - 02475008 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-11-20 01:22 - 2013-09-27 03:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\pwrshplugin.dll
2014-11-20 01:22 - 2013-09-27 02:53 - 00001536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrsmgr.dll
2014-11-20 01:22 - 2013-09-27 02:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2014-11-20 01:22 - 2013-09-27 02:38 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mimofcodec.dll
2014-11-20 01:22 - 2013-09-27 02:36 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncobjapi.dll
2014-11-20 01:22 - 2013-09-27 02:36 - 00013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
2014-11-20 01:22 - 2013-09-27 02:35 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mi.dll
2014-11-20 01:22 - 2013-09-27 02:34 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mibincodec.dll
2014-11-20 01:22 - 2013-09-27 02:34 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wecapi.dll
2014-11-20 01:22 - 2013-09-27 02:34 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2014-11-20 01:22 - 2013-09-27 02:34 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrssrv.dll
2014-11-20 01:22 - 2013-09-27 02:31 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtfwd.dll
2014-11-20 01:22 - 2013-09-27 02:25 - 00013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Register-CimProvider.exe
2014-11-20 01:22 - 2013-09-27 02:21 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wecutil.exe
2014-11-20 01:22 - 2013-09-27 02:15 - 00057856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prvdmofcomp.dll
2014-11-20 01:22 - 2013-09-27 02:14 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmitomi.dll
2014-11-20 01:22 - 2013-09-27 02:12 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmidcom.dll
2014-11-20 01:22 - 2013-09-27 02:11 - 00371712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wbemcomn2.dll
2014-11-20 01:22 - 2013-09-27 02:11 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\miutils.dll
2014-11-20 01:22 - 2013-09-27 02:09 - 00192512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll
2014-11-20 01:22 - 2013-09-27 02:08 - 00190464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll
2014-11-20 01:22 - 2013-09-27 02:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAgent.dll
2014-11-20 01:22 - 2013-09-27 02:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-11-20 01:22 - 2013-09-27 01:54 - 00020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrshost.exe
2014-11-20 01:22 - 2013-09-27 01:50 - 00515584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmGCDeps.dll
2014-11-20 01:22 - 2013-09-27 01:49 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrs.exe
2014-11-20 01:22 - 2013-09-27 01:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2014-11-20 01:22 - 2013-09-27 01:48 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-11-20 01:22 - 2013-09-27 01:48 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-11-20 01:22 - 2013-09-27 01:47 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-11-20 01:22 - 2013-09-27 01:47 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrscmd.dll
2014-11-20 01:22 - 2013-09-27 01:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PSModuleDiscoveryProvider.dll
2014-11-20 01:22 - 2013-09-27 01:38 - 02026496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-11-20 01:22 - 2013-09-27 01:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pwrshplugin.dll
2014-11-20 01:22 - 2013-09-27 00:52 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-11-20 01:22 - 2013-09-26 23:48 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\DscCore.dll
2014-11-20 01:22 - 2013-09-16 08:34 - 00204105 _____ () C:\Windows\SysWOW64\winrm.vbs
2014-11-20 01:22 - 2013-09-16 08:34 - 00204105 _____ () C:\Windows\system32\winrm.vbs
2014-11-20 01:22 - 2013-09-16 08:34 - 00004675 _____ () C:\Windows\SysWOW64\wsmanconfig_schema.xml
2014-11-20 01:22 - 2013-09-16 08:34 - 00004675 _____ () C:\Windows\system32\wsmanconfig_schema.xml
2014-11-20 01:22 - 2013-09-16 08:33 - 00004148 _____ () C:\Windows\system32\psmodulediscoveryprovider.mof
2014-11-20 01:21 - 2014-11-20 03:20 - 00015509 _____ () C:\Windows\wsusofflineupdate.log
2014-11-19 02:22 - 2014-11-19 03:45 - 00000000 ____D () C:\Users\Barry\SecurityScans
2014-11-19 01:39 - 2014-11-19 01:39 - 04890736 _____ (Piriform Ltd) C:\Users\Barry\Desktop\spsetup126.exe
2014-11-18 23:02 - 2014-11-18 23:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-11-18 23:01 - 2014-11-18 23:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-11-18 23:01 - 2014-11-18 23:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-11-18 21:49 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-18 21:49 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-18 21:49 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-18 21:49 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-17 01:57 - 2012-11-14 10:22 - 00207960 _____ (Sysinternals) C:\Windows\Contig.exe
2014-11-17 00:34 - 2014-11-27 01:17 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\vlc
2014-11-17 00:34 - 2014-11-17 00:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-11-17 00:34 - 2014-11-17 00:34 - 00000000 ____D () C:\Program Files\VideoLAN
2014-11-13 23:25 - 2014-11-30 18:08 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-13 23:24 - 2014-11-13 23:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-13 23:24 - 2014-11-13 23:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-13 23:24 - 2014-11-13 23:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-13 23:24 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-13 23:24 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-13 23:24 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-13 01:53 - 2014-11-13 01:53 - 00238157 _____ () C:\Windows\FSUNINST.log
2014-11-13 01:53 - 2014-11-13 01:53 - 00012684 _____ () C:\Windows\uninstaller.log
2014-11-13 01:53 - 2014-11-13 01:53 - 00000926 _____ () C:\Windows\fsavunin_2.log
2014-11-12 21:35 - 2014-11-22 01:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-11-12 04:08 - 2014-11-12 04:08 - 00000000 __SHD () C:\Users\Barry\AppData\Local\EmieBrowserModeList
2014-11-12 02:56 - 2014-11-13 01:53 - 22661121 _____ () C:\Windows\FSISU.log
2014-11-12 02:56 - 2014-11-13 01:53 - 00353444 _____ () C:\Windows\FSDEPH.log
2014-11-12 02:56 - 2014-11-13 01:53 - 00029416 _____ () C:\Windows\fsavunin.log
2014-11-12 02:56 - 2014-11-13 01:53 - 00008328 _____ () C:\Windows\FSGKIAIN.log
2014-11-12 02:56 - 2014-11-13 01:53 - 00003588 _____ () C:\Windows\FSLDIN.LOG
2014-11-12 02:56 - 2014-11-13 01:53 - 00000687 _____ () C:\Windows\fstnbins.LOG
2014-11-12 02:56 - 2014-11-12 02:56 - 00856630 _____ () C:\Windows\FSSFM.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00709426 _____ () C:\Windows\FSSETUP.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00136077 _____ () C:\Windows\FSPROD.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00088551 _____ () C:\Windows\RunSetup.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00070989 _____ () C:\Windows\FSAVINST.LOG
2014-11-12 02:56 - 2014-11-12 02:56 - 00019322 _____ () C:\Windows\fspplugin.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00009874 _____ () C:\Windows\FSAVCSIN.LOG
2014-11-12 02:56 - 2014-11-12 02:56 - 00000657 _____ () C:\Windows\fsav_db_setup.log
2014-11-11 22:05 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-11 22:05 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-11 22:05 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-11 22:04 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-11 22:04 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-11 22:04 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-11 22:04 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-11 22:04 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-11 22:04 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-11 22:04 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-11 22:04 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-11 22:04 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-11 22:04 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-11 22:04 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-11 22:04 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-11 22:04 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-11 22:04 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-11 22:04 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-11 22:04 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-11 22:04 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-11 22:04 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-11 22:04 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-11 22:04 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-11 22:04 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-11 22:04 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-11 22:04 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-11 22:02 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-11 22:02 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-11 22:02 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-11 22:02 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-09 06:53 - 2014-11-09 06:53 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-11-09 02:45 - 2014-11-29 05:29 - 00000000 ____D () C:\AdwCleaner
2014-11-08 02:01 - 2014-11-08 02:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-11-08 02:00 - 2014-11-08 02:40 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-11-08 01:59 - 2014-11-08 01:59 - 00000000 ____D () C:\Windows\PCHEALTH
2014-11-08 01:59 - 2014-11-08 01:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio
2014-11-08 01:57 - 2014-11-19 03:42 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-11-08 01:57 - 2014-11-08 01:57 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-11-08 01:57 - 2014-11-08 01:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-11-08 01:55 - 2014-11-08 01:55 - 00000000 __RHD () C:\MSOCache
2014-11-07 23:47 - 2014-11-22 01:42 - 00070940 _____ () C:\Windows\IE11_main.log
2014-11-05 20:39 - 2014-11-05 20:39 - 00639400 _____ (Akeo Consulting (http://akeo.ie)) C:\Users\Barry\Desktop\rufus(1).exe
2014-11-05 14:18 - 2014-11-28 05:51 - 00000000 ____D () C:\Users\Barry\Desktop\system-ninja-portable-3.0.4
2014-11-03 22:42 - 2014-11-09 07:44 - 00109696 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-31 21:14 - 2014-10-31 21:14 - 00000000 ____D () C:\Program Files\Realtek
2014-10-31 21:14 - 2014-05-14 18:37 - 03962840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2014-10-31 21:14 - 2014-05-14 16:00 - 01099203 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-10-31 21:14 - 2014-05-12 20:11 - 60636160 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2014-10-31 21:14 - 2014-05-09 11:17 - 00628952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2014-10-31 21:14 - 2014-04-30 11:34 - 00948952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2014-10-31 21:14 - 2014-04-28 15:48 - 02800344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2014-10-31 21:14 - 2014-04-25 13:51 - 02834648 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2014-10-31 21:14 - 2014-04-25 13:23 - 01022168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2014-10-31 21:14 - 2014-03-06 16:35 - 01959128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2014-10-31 21:14 - 2014-02-18 17:04 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2014-10-31 21:14 - 2014-01-28 11:48 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2014-10-31 21:14 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2014-10-31 21:14 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2014-10-31 21:14 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2014-10-31 21:14 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2014-10-31 21:14 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2014-10-31 21:14 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2014-10-31 21:14 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2014-10-31 21:13 - 2013-10-16 03:43 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2014-10-31 21:13 - 2013-10-11 12:47 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-10-31 21:13 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2014-10-31 20:46 - 2014-10-31 21:14 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-10-31 20:22 - 2014-10-31 20:22 - 00000000 ____D () C:\ProgramData\ATI
2014-10-31 20:22 - 2014-10-31 20:22 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-10-31 20:22 - 2014-10-31 20:22 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-10-31 20:22 - 2014-10-31 20:22 - 00000000 ____D () C:\Program Files (x86)\AMD APP
2014-10-31 20:21 - 2014-10-31 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2014-10-31 20:20 - 2014-10-31 20:21 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-10-31 20:20 - 2014-10-31 20:20 - 00000000 ____D () C:\Program Files\ATI
2014-10-31 20:20 - 2014-10-31 20:20 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-30 18:14 - 2009-07-14 05:45 - 00026336 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-30 18:14 - 2009-07-14 05:45 - 00026336 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-30 18:11 - 2009-07-14 06:13 - 00821598 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-30 18:07 - 2014-10-25 23:49 - 00015301 _____ () C:\Windows\setupact.log
2014-11-29 05:31 - 2014-10-27 23:21 - 01601656 _____ () C:\Windows\PFRO.log
2014-11-29 05:30 - 2014-08-01 22:09 - 01124061 _____ () C:\Windows\WindowsUpdate.log
2014-11-29 04:27 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Public\Libraries
2014-11-29 04:22 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-27 03:09 - 2014-09-26 01:26 - 00000000 ____D () C:\ProgramData\Unchecky
2014-11-26 23:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-26 03:31 - 2014-05-22 19:23 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-11-26 01:36 - 2014-08-20 20:45 - 00000000 ____D () C:\Users\Barry\AppData\Local\Adobe
2014-11-26 01:36 - 2014-04-11 21:48 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-26 01:36 - 2014-04-11 21:48 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-25 21:02 - 2014-05-18 00:02 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\NewsLeecher
2014-11-24 04:36 - 2014-04-11 20:02 - 00000000 ____D () C:\Users\Barry
2014-11-23 22:24 - 2014-04-11 21:49 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-11-22 03:28 - 2014-08-28 22:10 - 00388608 _____ (Trend Micro Inc.) C:\Users\Barry\Desktop\HijackThis.exe
2014-11-22 02:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-11-22 01:42 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-11-21 23:30 - 2014-04-30 20:00 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\dvdcss
2014-11-21 04:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\servicing
2014-11-20 22:48 - 2014-04-11 21:48 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\Adobe
2014-11-20 22:48 - 2014-04-11 21:37 - 00000000 ____D () C:\ProgramData\Adobe
2014-11-20 22:37 - 2014-04-14 22:48 - 00000000 ____D () C:\Windows\Sun
2014-11-19 00:42 - 2009-07-14 06:08 - 00032602 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-11-15 03:11 - 2014-05-22 21:42 - 00000000 ____D () C:\Users\Barry\AppData\Local\Downloaded Installations
2014-11-15 02:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-11-14 02:17 - 2014-08-28 04:05 - 00000000 ____D () C:\Windows\Minidump
2014-11-12 02:56 - 2014-09-28 08:06 - 00020560 _____ () C:\Windows\prodsett_copy.ini
2014-11-12 01:08 - 2014-04-14 22:13 - 00000000 ____D () C:\Users\Administrator
2014-11-11 23:55 - 2014-08-01 22:09 - 01107932 _____ () C:\Windows\WindowsUpdate(12).log
2014-11-11 22:51 - 2014-05-17 21:59 - 00007660 _____ () C:\Users\Barry\AppData\Local\resmon.resmoncfg
2014-11-11 22:13 - 2014-10-25 23:49 - 00411360 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-11 22:11 - 2014-04-12 19:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-11 22:08 - 2014-04-11 20:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-10 23:24 - 2014-10-23 21:08 - 00000000 ____D () C:\ProgramData\Spotnet
2014-11-09 07:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system
2014-11-09 06:08 - 2014-04-11 23:14 - 00784114 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-11-09 03:32 - 2014-10-25 21:34 - 00109696 _____ () C:\Users\Barry\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-08 02:54 - 2009-07-14 03:34 - 00000514 _____ () C:\Windows\win.ini
2014-11-08 02:28 - 2014-04-12 19:17 - 00000000 ____D () C:\Users\Barry\Desktop\NoPE
2014-11-08 02:00 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-11-08 01:59 - 2011-04-12 08:45 - 00000000 ____D () C:\Windows\ShellNew
2014-11-07 23:53 - 2014-04-12 05:55 - 00000000 ____D () C:\Windows\Panther
2014-11-04 14:30 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-31 23:26 - 2014-04-11 20:51 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-31 21:15 - 2014-04-11 20:57 - 00000000 ___HD () C:\Program Files (x86)\Temp
2014-10-31 21:13 - 2014-04-11 20:57 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-10-31 21:11 - 2014-04-11 20:57 - 00000000 ____D () C:\Program Files (x86)\Realtek
2014-10-31 20:22 - 2014-10-10 21:24 - 00000000 ____D () C:\ProgramData\AMD

Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\temp\Quarantine.exe
C:\Users\Administrator\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-25 20:23

==================== End Of Log ============================

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-11-2014
Ran by Barry at 2014-11-30 18:18:05
Running from C:\Users\Barry\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.34 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0934-000001000000}) (Version: 9.34.00.0 - Igor Pavlov)
abgx360 v1.0.6 (HKLM-x32\...\abgx360) (Version:  - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.4.154 - Adobe Systems, Inc.)
AMD Catalyst Install Manager (HKLM\...\{37FCE154-7F59-74F0-3A35-BF503CEB230B}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{26784146-6E05-3FF9-9335-786C7C0FB5BE}) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Ultimate 2007 (HKLM-x32\...\ULTIMATER) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 33.1.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 33.1.1 (x86 en-US)) (Version: 33.1.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.1.1 - Mozilla)
NewsLeecher v6.5 Beta 4 (HKLM-x32\...\NewsLeecher_is1) (Version:  - )
Port Forward Network Utilities (HKLM-x32\...\{88B1D36C-7B70-4C48-8D2F-AAB956ECF4C3}) (Version: 2.0.5 - Portforward, LLC)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.273.37 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.89.716.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7246 - Realtek Semiconductor Corp.)
Spotnet (HKLM-x32\...\{12947715-B6F0-4597-816F-5E13FB647921}_is1) (Version: 1.8.1 - Spotnet)
Spotnet Improver Local v2.0c (HKLM-x32\...\Spotnet Improver Local_is1) (Version: 2.0c - Ps3udO)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TreeSize Free V3.2.1 (HKLM-x32\...\TreeSize Free_is1) (Version: 3.2.1 - JAM Software)
Unchecky v0.3.4 (HKLM-x32\...\Unchecky) (Version: 0.3.4 - RaMMicHaeL)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
XBMC (HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\...\XBMC) (Version:  - Team XBMC)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2014-11-12 22:58 - 2014-11-30 18:09 - 00001871 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1    localhost
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
0.0.0.0 cdn.appround.biz
0.0.0.0 cdn.bigspeedpro.com

There are 5 more lines.


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0AC66A00-65B1-47A1-A727-9F841D74F4C5} - \{2F626C7B-808F-4644-AF43-074102A74B2B} No Task File <==== ATTENTION
Task: {633AC11E-4FF5-4BA3-8B42-DEA2E60AB395} - \{B9122C87-33C0-4FB3-BF5B-D3158301A467} No Task File <==== ATTENTION
Task: {6CC63A8F-968A-4677-AC72-A88B7BEBF0CD} - \{DB8B0CC0-1D42-4817-85C7-A76F9CB03048} No Task File <==== ATTENTION
Task: {E3CB05EB-B745-4EF2-A358-F0694EEED0ED} - \{F5AFC657-924F-4A30-B953-F5F348C262DB} No Task File <==== ATTENTION
Task: {EFA25EE9-DFB2-4B25-BBCD-46CA68470FBF} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-24] (AVAST Software)

==================== Loaded Modules (whitelisted) =============

2013-06-18 15:49 - 2013-06-18 15:49 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2013-04-29 23:08 - 2013-04-29 23:08 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-11-30 18:08 - 2014-11-30 18:08 - 02904064 _____ () C:\Program Files\AVAST Software\Avast\defs\14113000\algo.dll
2014-11-24 04:24 - 2014-11-24 04:24 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-11-27 03:08 - 2014-11-14 03:42 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows\SysWOW64:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Windows\Temp:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\AppData:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\Application Data:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\Local Settings:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\AppData\Local:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\AppData\Roaming:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\AppData\Roaming\Macromedia:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\AppData\Roaming\Microsoft:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Application Data:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Microsoft:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Administrator\AppData\Local\Temporary Internet Files:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\AppData:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\Application Data:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\Local Settings:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\AppData\Local:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\AppData\Roaming:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\AppData\Roaming\Macromedia:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\AppData\Roaming\Microsoft:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\AppData\Local\Application Data:BZ-VIRTUAL-LINK
AlternateDataStreams: C:\Users\Barry\AppData\Local\Microsoft:BZ-VIRTUAL-LINK

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\48686678.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\48686678.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: aspnet_state => 2
MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: CscService => 2
MSCONFIG\Services: defragsvc => 3
MSCONFIG\Services: GlassWire => 2
MSCONFIG\Services: idsvc => 3
MSCONFIG\Services: IEEtwCollectorService => 3
MSCONFIG\Services: Microsoft Office Groove Audit Service => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: napagent => 3
MSCONFIG\Services: odserv => 3
MSCONFIG\Services: ProtectedStorage => 3
MSCONFIG\Services: RasAuto => 3
MSCONFIG\Services: RasMan => 3
MSCONFIG\Services: RemoteRegistry => 3
MSCONFIG\Services: RtkAudioService => 2
MSCONFIG\Services: SCardSvr => 3
MSCONFIG\Services: SCPolicySvc => 3
MSCONFIG\Services: SessionEnv => 3
MSCONFIG\Services: Spooler => 2
MSCONFIG\Services: TabletInputService => 3
MSCONFIG\Services: TapiSrv => 3
MSCONFIG\Services: UmRdpService => 3
MSCONFIG\Services: W3SVC => 2
MSCONFIG\Services: WebClient => 3
MSCONFIG\Services: WPCSvc => 3
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AvastUI.exe => "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: RTHDVCPL => "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s

========================= Accounts: ==========================

Administrator (S-1-5-21-1267563920-2322599392-2657086146-500 - Administrator - Enabled) => C:\Users\Administrator
Barry (S-1-5-21-1267563920-2322599392-2657086146-1001 - Administrator - Enabled) => C:\Users\Barry
Guest (S-1-5-21-1267563920-2322599392-2657086146-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1267563920-2322599392-2657086146-1010 - Limited - Enabled)

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/28/2014 09:30:43 PM) (Source: Windows Activation Technologies) (EventID: 3) (User: )
Description: Health check failure:
 hr = 0x8004FE21, HealthStatus: 0x0001000000000000

Error: (11/28/2014 01:43:53 AM) (Source: Windows Activation Technologies) (EventID: 3) (User: )
Description: Health check failure:
 hr = 0x8004FE21, HealthStatus: 0x0001000000000000

Error: (11/28/2014 01:39:06 AM) (Source: Windows Activation Technologies) (EventID: 3) (User: )
Description: Health check failure:
 hr = 0x8004FE21, HealthStatus: 0x0001000000000000

Error: (11/24/2014 04:24:26 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.


Details:
AddLegacyDriverFiles: Unable to back up image of binary cfyhzdut.

System Error:
The system cannot find the file specified.
.

Error: (11/23/2014 04:37:11 AM) (Source: DrWebFWSvc) (EventID: 3) (User: )
Description: Service start failed20x2Can't open \\.\DRWEBAF device.

Error: (11/23/2014 04:37:10 AM) (Source: DrWebFWSvc) (EventID: 3) (User: )
Description: Failed to initialize application identity cache20x2Can't open kernel cache manager.

Error: (11/21/2014 04:06:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 9.0.8112.16592, time stamp: 0x544ea588
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeb033f
Exception code: 0xc0000005
Fault offset: 0x0000000000002853
Faulting process id: 0xfbc
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3

Error: (11/19/2014 05:28:24 AM) (Source: PerfNet) (EventID: 2004) (User: )
Description:

Error: (11/19/2014 05:20:24 AM) (Source: PerfNet) (EventID: 2004) (User: )
Description:

Error: (11/19/2014 05:14:24 AM) (Source: PerfNet) (EventID: 2004) (User: )
Description:


System errors:
=============
Error: (11/30/2014 06:07:39 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 701) (User: NT AUTHORITY)
Description: Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/30/2014 06:07:39 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 704) (User: NT AUTHORITY)
Description: Task Scheduler failed to initialize LSA for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/29/2014 05:31:23 AM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 701) (User: NT AUTHORITY)
Description: Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/29/2014 05:31:23 AM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 704) (User: NT AUTHORITY)
Description: Task Scheduler failed to initialize LSA for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/29/2014 05:04:58 AM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 701) (User: NT AUTHORITY)
Description: Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/29/2014 05:04:58 AM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 704) (User: NT AUTHORITY)
Description: Task Scheduler failed to initialize LSA for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/29/2014 03:20:31 AM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 701) (User: NT AUTHORITY)
Description: Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/29/2014 03:20:31 AM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 704) (User: NT AUTHORITY)
Description: Task Scheduler failed to initialize LSA for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/28/2014 09:25:32 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 701) (User: NT AUTHORITY)
Description: Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

Error: (11/28/2014 09:25:32 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 704) (User: NT AUTHORITY)
Description: Task Scheduler failed to initialize LSA for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-06-03 17:47:43.068
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-03 16:30:33.717
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-02 01:46:08.909
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-02 00:43:27.153
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-02 00:26:56.315
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-02 00:11:56.859
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-01 23:57:31.622
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-01 23:53:49.355
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-01 23:34:06.984
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-01 22:30:28.760
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\BufferZone\RlHook64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel® Core™2 Duo CPU E7300 @ 2.66GHz
Percentage of memory in use: 22%
Total physical RAM: 8191.23 MB
Available physical RAM: 6375.32 MB
Total Pagefile: 20475.41 MB
Available Pagefile: 18429.74 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:48.73 GB) (Free:14.47 GB) NTFS
Drive d: (Movies) (Fixed) (Total:211.85 GB) (Free:15.88 GB) NTFS
Drive e: (Backup) (Fixed) (Total:299.15 GB) (Free:39.17 GB) NTFS
Drive f: () (Fixed) (Total:632.35 GB) (Free:166.31 GB) NTFS
Drive g: (Muziek) (Fixed) (Total:205.08 GB) (Free:57.17 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C9FC170E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=48.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=205.1 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=211.9 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 06839D06)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=OF Extended)

==================== End Of Log ============================


  • 0

#4
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

after disalbeling Avast and running FRST , my Avast Webshield could not be turned on .

After reboot it says it is turned on but I have my doubtes , as I do not see the counter going up whwn checking Http ot https entries .


  • 0

#5
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts
Step 1: Adwarecleaner

Please download AdwCleaner (by Xplode) from the link below and save it to your Desktop:

Download Mirror #1
  • Right-click on AdwCleaner.exe and select Run as administrator. (If you have Windows XP the just run it)
  • Click Scan and let the scan run.
  • When it finishes, click Clean, following the on screen prompts
  • After your computer reboots, a log will open. Please Copy (Ctrl+C) and Paste (Ctrl+V) this into your next post.
Note: The log can also be found in here: C:\AdwCleaner\

Step 2: Malwarebytes

Please download Malwarebytes Anti-Malware to your desktop Install the progamme and select update
Once it has updated select Settings > Detection and Protection
Tick Scan for rootkits

MBAMsettings.JPG

Go back to the Dashboard and select Scan Now

MBAMScan.JPG

If threats are detected, click the Apply Actions button, MBAM will ask for a reboot.

MBAMReboot.JPG

MBAMLog.JPG

On completion of the scan (or after the reboot) select View Detailed Log
Select Export > Select text file and save to the desktop
Attach/Post that log

Step 3: Junkware Removal Tool

thisisujrt.gif  Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 4: FRST Scan
  • Run FRST. (if you have Windows Vista / Windows 7 / Windows 8: Please do a Right click on the FRST icon and select Run as Administrator)
  • Click Scan to start FRST.
  • When FRST finishes scanning, a log, FRST.txt, will open.
  • Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this log into your next post please.

  • 0

#6
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

# AdwCleaner v4.102 - Report created 30/11/2014 at 19:45:09
# Updated 23/11/2014 by Xplode
# Database : 2014-11-27.1 [Live]
# Operating System : Windows 7 Enterprise Service Pack 1 (64 bits)
# Username : Barry - BARRY-PC
# Running from : C:\Users\Barry\Desktop\Mwcheck\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17420


-\\ Mozilla Firefox v33.1.1 (x86 en-US)


*************************

AdwCleaner[R0].txt - [895 octets] - [09/11/2014 02:45:45]
AdwCleaner[R1].txt - [954 octets] - [09/11/2014 02:50:53]
AdwCleaner[R2].txt - [934 octets] - [26/11/2014 02:23:21]
AdwCleaner[R3].txt - [993 octets] - [26/11/2014 02:31:08]
AdwCleaner[R4].txt - [1111 octets] - [29/11/2014 05:24:04]
AdwCleaner[R5].txt - [1171 octets] - [29/11/2014 05:27:15]
AdwCleaner[R6].txt - [976 octets] - [30/11/2014 19:45:09]
AdwCleaner[S0].txt - [1011 octets] - [09/11/2014 02:52:58]
AdwCleaner[S1].txt - [1235 octets] - [29/11/2014 05:29:57]

########## EOF - C:\AdwCleaner\AdwCleaner[R6].txt - [1155 octets] ##########
 


  • 0

#7
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 30-11-2014
Scan Time: 19:51:06
Logfile: mbamlog.txt
Administrator: Yes

Version: 2.00.3.1025
Malware Database: v2014.11.30.06
Rootkit Database: v2014.11.30.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Barry

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 376172
Time Elapsed: 15 min, 17 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)


  • 0

#8
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Enterprise x64
Ran by Barry on zo 30-11-2014 at 20:08:26,23
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] "C:\Windows\wininit.ini"



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on zo 30-11-2014 at 20:12:38,51
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


  • 0

#9
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-11-2014
Ran by Barry (administrator) on BARRY-PC on 30-11-2014 20:15:11
Running from C:\Users\Barry\Desktop\Mwcheck
Loaded Profile: Barry (Available profiles: Barry & Administrator)
Platform: Windows 7 Enterprise Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672152 2014-05-09] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-24] (AVAST Software)
HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\Windows\system32\WPDShServiceObj.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [0_sxBZOverlayIcon] -> {6457FB0A-5C02-4393-909C-2139A5D5571F} =>  No File
ShellIconOverlayIdentifiers: [0_sxConfidentialOIcon] -> {871FE18B-B68D-4437-BC76-6634996CDB97} =>  No File
ShellIconOverlayIdentifiers: [0_sxForbiddenOIcon] -> {1F03249C-6AB2-4E31-8C10-86F7E31E3B4E} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...d=ie&ar=msnhome
HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1267563920-2322599392-2657086146-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-1267563920-2322599392-2657086146-1001 -> DefaultScope {C2F67A18-6136-401D-9A2C-45C335CA5CD8} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1267563920-2322599392-2657086146-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1267563920-2322599392-2657086146-1001 -> {C2F67A18-6136-401D-9A2C-45C335CA5CD8} URL = https://www.google.c...q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{29F60707-DF66-4759-8EB7-41A44A984E9B}: [NameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default
FF Homepage: https://www.google.com/ncr | hxxp://www.nu.nl/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Extension: Password Exporter - C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi [2014-11-27]
FF Extension: Adblock Plus - C:\Users\Barry\AppData\Roaming\Mozilla\Firefox\Profiles\hfxqhesj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-27]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-24]
FF Extension: No Name - [email protected] [Not Found]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2014-11-24]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-24]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-24] (AVAST Software)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S4 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [111208 2014-11-23] (RaMMicHaeL)
S4 AdobeARMservice; "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-24] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-24] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-24] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-24] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-11] (Disc Soft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation)
R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [93400 2014-10-01] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [465624 2014-01-03] (Realsil Semiconductor Corporation)
U3 DfSdkS; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-30 18:37 - 2014-11-30 20:15 - 00000000 ____D () C:\Users\Barry\Desktop\Mwcheck
2014-11-30 18:17 - 2014-11-30 20:15 - 00000000 ____D () C:\FRST
2014-11-29 05:39 - 2014-11-29 05:39 - 00011331 _____ () C:\Users\Barry\Desktop\startuplist.txt
2014-11-29 05:06 - 2014-11-29 05:06 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-11-29 05:06 - 2014-11-29 05:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-11-29 05:05 - 2014-11-29 05:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\AVAST Software
2014-11-29 02:57 - 2014-11-29 03:08 - 00000000 ____D () C:\Users\Barry\Desktop\ccsetup500
2014-11-28 23:04 - 2014-11-29 02:25 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\PFStaticIP
2014-11-28 22:50 - 2014-11-28 23:01 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\PortForward.com
2014-11-28 22:50 - 2014-11-28 22:50 - 00002815 _____ () C:\Users\Public\Desktop\PortForward Network Utilities.lnk
2014-11-28 22:50 - 2014-11-28 22:50 - 00002815 _____ () C:\ProgramData\Desktop\PortForward Network Utilities.lnk
2014-11-28 22:50 - 2014-11-28 22:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PortForward.com
2014-11-28 22:50 - 2014-11-28 22:50 - 00000000 ____D () C:\Program Files (x86)\Portforward
2014-11-28 22:17 - 2014-11-28 22:17 - 00000000 ____H () C:\Users\Barry\Documents\Default.rdp
2014-11-28 01:31 - 2011-03-01 09:07 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\svchost.exe
2014-11-28 01:31 - 2011-03-01 09:05 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
2014-11-27 03:09 - 2014-11-27 03:09 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\Mozilla
2014-11-27 03:09 - 2014-11-27 03:09 - 00000000 ____D () C:\Users\Barry\AppData\Local\Mozilla
2014-11-27 03:08 - 2014-11-27 03:08 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-27 03:08 - 2014-11-27 03:08 - 00000000 ____D () C:\ProgramData\Mozilla
2014-11-27 03:08 - 2014-11-27 03:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-27 03:08 - 2014-11-27 03:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-27 02:56 - 2014-11-27 04:18 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\CrystalIdea Software
2014-11-26 01:48 - 2014-11-26 01:47 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-11-26 01:47 - 2014-11-26 01:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-11-26 01:47 - 2014-11-26 01:47 - 00000000 ____D () C:\Program Files (x86)\Java
2014-11-25 22:35 - 2014-11-25 22:35 - 01066038 _____ () C:\Users\Barry\Desktop\FixDotNet20141125213536005.cab
2014-11-24 04:25 - 2014-11-27 06:00 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-11-24 04:25 - 2014-11-24 04:25 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\AVAST Software
2014-11-24 04:25 - 2014-11-24 04:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2014-11-24 04:25 - 2014-11-24 04:24 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-11-24 04:25 - 2014-11-24 04:24 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-11-24 04:24 - 2014-11-24 04:25 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-11-24 04:24 - 2014-11-24 04:24 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-11-24 04:24 - 2014-11-24 04:24 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-11-24 04:24 - 2014-11-24 04:24 - 00000000 ____D () C:\Program Files\AVAST Software
2014-11-24 04:22 - 2014-11-24 04:24 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-11-23 22:24 - 2014-11-23 22:24 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-11-23 22:24 - 2014-11-23 22:24 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-11-23 04:37 - 2014-11-24 04:17 - 00000000 ____D () C:\Windows\System32\Tasks\Doctor Web
2014-11-23 04:36 - 2014-11-23 04:36 - 00001559 _____ () C:\Windows\system32\Drivers\etc\hosts (1)
2014-11-22 01:53 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-22 01:40 - 2014-11-22 01:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-22 01:40 - 2014-11-22 01:40 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-22 01:40 - 2014-11-22 01:40 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-22 01:40 - 2014-11-22 01:40 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-11-22 01:40 - 2014-11-22 01:40 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-11-22 01:40 - 2014-11-22 01:40 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-11-22 01:40 - 2014-11-22 01:40 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-11-22 01:40 - 2014-11-22 01:40 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-11-22 01:40 - 2014-11-22 01:40 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-11-22 01:40 - 2014-11-22 01:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-11-22 01:40 - 2014-11-22 01:40 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-11-22 01:40 - 2014-11-22 01:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-21 04:38 - 2014-11-22 01:44 - 00001377 _____ () C:\Users\Barry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-21 03:48 - 2014-11-21 03:49 - 00003249 _____ () C:\Windows\IE9_main.log
2014-11-21 03:43 - 2014-11-21 04:36 - 00017415 _____ () C:\Windows\IE10_main.log
2014-11-20 01:30 - 2014-11-20 01:30 - 00000000 ____D () C:\Windows\system32\dsc
2014-11-20 01:30 - 2014-11-20 01:30 - 00000000 ____D () C:\Windows\system32\Configuration
2014-11-20 01:30 - 2014-11-20 01:30 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2014-11-20 01:30 - 2014-11-20 01:30 - 00000000 ____D () C:\Program Files (x86)\WindowsPowerShell
2014-11-20 01:22 - 2013-09-27 04:37 - 00001536 _____ (Microsoft Corporation) C:\Windows\system32\winrsmgr.dll
2014-11-20 01:22 - 2013-09-27 04:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2014-11-20 01:22 - 2013-09-27 04:20 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\mimofcodec.dll
2014-11-20 01:22 - 2013-09-27 04:19 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\ncobjapi.dll
2014-11-20 01:22 - 2013-09-27 04:18 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\mi.dll
2014-11-20 01:22 - 2013-09-27 04:18 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
2014-11-20 01:22 - 2013-09-27 04:17 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\mibincodec.dll
2014-11-20 01:22 - 2013-09-27 04:16 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\wecapi.dll
2014-11-20 01:22 - 2013-09-27 04:16 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2014-11-20 01:22 - 2013-09-27 04:16 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\winrssrv.dll
2014-11-20 01:22 - 2013-09-27 04:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\wevtfwd.dll
2014-11-20 01:22 - 2013-09-27 04:03 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\Register-CimProvider.exe
2014-11-20 01:22 - 2013-09-27 03:59 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\wecutil.exe
2014-11-20 01:22 - 2013-09-27 03:58 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\wecsvc.dll
2014-11-20 01:22 - 2013-09-27 03:53 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\wmitomi.dll
2014-11-20 01:22 - 2013-09-27 03:53 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\prvdmofcomp.dll
2014-11-20 01:22 - 2013-09-27 03:50 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\wmidcom.dll
2014-11-20 01:22 - 2013-09-27 03:49 - 00476672 _____ (Microsoft Corporation) C:\Windows\system32\wbemcomn2.dll
2014-11-20 01:22 - 2013-09-27 03:48 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\miutils.dll
2014-11-20 01:22 - 2013-09-27 03:46 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-11-20 01:22 - 2013-09-27 03:45 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-11-20 01:22 - 2013-09-27 03:40 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\WsmAgent.dll
2014-11-20 01:22 - 2013-09-27 03:34 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\DscCoreConfProv.dll
2014-11-20 01:22 - 2013-09-27 03:27 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\winrshost.exe
2014-11-20 01:22 - 2013-09-27 03:21 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\WsmGCDeps.dll
2014-11-20 01:22 - 2013-09-27 03:20 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\winrs.exe
2014-11-20 01:22 - 2013-09-27 03:19 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-11-20 01:22 - 2013-09-27 03:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2014-11-20 01:22 - 2013-09-27 03:18 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-11-20 01:22 - 2013-09-27 03:17 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-11-20 01:22 - 2013-09-27 03:17 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\winrscmd.dll
2014-11-20 01:22 - 2013-09-27 03:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\PSModuleDiscoveryProvider.dll
2014-11-20 01:22 - 2013-09-27 03:06 - 02475008 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-11-20 01:22 - 2013-09-27 03:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\pwrshplugin.dll
2014-11-20 01:22 - 2013-09-27 02:53 - 00001536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrsmgr.dll
2014-11-20 01:22 - 2013-09-27 02:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2014-11-20 01:22 - 2013-09-27 02:38 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mimofcodec.dll
2014-11-20 01:22 - 2013-09-27 02:36 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncobjapi.dll
2014-11-20 01:22 - 2013-09-27 02:36 - 00013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Management.Infrastructure.Native.Unmanaged.dll
2014-11-20 01:22 - 2013-09-27 02:35 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mi.dll
2014-11-20 01:22 - 2013-09-27 02:34 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mibincodec.dll
2014-11-20 01:22 - 2013-09-27 02:34 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wecapi.dll
2014-11-20 01:22 - 2013-09-27 02:34 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2014-11-20 01:22 - 2013-09-27 02:34 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrssrv.dll
2014-11-20 01:22 - 2013-09-27 02:31 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtfwd.dll
2014-11-20 01:22 - 2013-09-27 02:25 - 00013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Register-CimProvider.exe
2014-11-20 01:22 - 2013-09-27 02:21 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wecutil.exe
2014-11-20 01:22 - 2013-09-27 02:15 - 00057856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prvdmofcomp.dll
2014-11-20 01:22 - 2013-09-27 02:14 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmitomi.dll
2014-11-20 01:22 - 2013-09-27 02:12 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmidcom.dll
2014-11-20 01:22 - 2013-09-27 02:11 - 00371712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wbemcomn2.dll
2014-11-20 01:22 - 2013-09-27 02:11 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\miutils.dll
2014-11-20 01:22 - 2013-09-27 02:09 - 00192512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll
2014-11-20 01:22 - 2013-09-27 02:08 - 00190464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll
2014-11-20 01:22 - 2013-09-27 02:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAgent.dll
2014-11-20 01:22 - 2013-09-27 02:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-11-20 01:22 - 2013-09-27 01:54 - 00020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrshost.exe
2014-11-20 01:22 - 2013-09-27 01:50 - 00515584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmGCDeps.dll
2014-11-20 01:22 - 2013-09-27 01:49 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrs.exe
2014-11-20 01:22 - 2013-09-27 01:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2014-11-20 01:22 - 2013-09-27 01:48 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-11-20 01:22 - 2013-09-27 01:48 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-11-20 01:22 - 2013-09-27 01:47 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-11-20 01:22 - 2013-09-27 01:47 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winrscmd.dll
2014-11-20 01:22 - 2013-09-27 01:47 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PSModuleDiscoveryProvider.dll
2014-11-20 01:22 - 2013-09-27 01:38 - 02026496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-11-20 01:22 - 2013-09-27 01:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pwrshplugin.dll
2014-11-20 01:22 - 2013-09-27 00:52 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-11-20 01:22 - 2013-09-26 23:48 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\DscCore.dll
2014-11-20 01:22 - 2013-09-16 08:34 - 00204105 _____ () C:\Windows\SysWOW64\winrm.vbs
2014-11-20 01:22 - 2013-09-16 08:34 - 00204105 _____ () C:\Windows\system32\winrm.vbs
2014-11-20 01:22 - 2013-09-16 08:34 - 00004675 _____ () C:\Windows\SysWOW64\wsmanconfig_schema.xml
2014-11-20 01:22 - 2013-09-16 08:34 - 00004675 _____ () C:\Windows\system32\wsmanconfig_schema.xml
2014-11-20 01:22 - 2013-09-16 08:33 - 00004148 _____ () C:\Windows\system32\psmodulediscoveryprovider.mof
2014-11-20 01:21 - 2014-11-20 03:20 - 00015509 _____ () C:\Windows\wsusofflineupdate.log
2014-11-19 02:22 - 2014-11-19 03:45 - 00000000 ____D () C:\Users\Barry\SecurityScans
2014-11-19 01:39 - 2014-11-19 01:39 - 04890736 _____ (Piriform Ltd) C:\Users\Barry\Desktop\spsetup126.exe
2014-11-18 23:02 - 2014-11-18 23:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-11-18 23:01 - 2014-11-18 23:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-11-18 23:01 - 2014-11-18 23:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-11-18 21:49 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-18 21:49 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-18 21:49 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-18 21:49 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-17 01:57 - 2012-11-14 10:22 - 00207960 _____ (Sysinternals) C:\Windows\Contig.exe
2014-11-17 00:34 - 2014-11-27 01:17 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\vlc
2014-11-17 00:34 - 2014-11-17 00:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-11-17 00:34 - 2014-11-17 00:34 - 00000000 ____D () C:\Program Files\VideoLAN
2014-11-13 23:25 - 2014-11-30 19:49 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-13 23:24 - 2014-11-13 23:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-13 23:24 - 2014-11-13 23:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-13 23:24 - 2014-11-13 23:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-13 23:24 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-13 23:24 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-13 23:24 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-13 01:53 - 2014-11-13 01:53 - 00238157 _____ () C:\Windows\FSUNINST.log
2014-11-13 01:53 - 2014-11-13 01:53 - 00012684 _____ () C:\Windows\uninstaller.log
2014-11-13 01:53 - 2014-11-13 01:53 - 00000926 _____ () C:\Windows\fsavunin_2.log
2014-11-12 21:35 - 2014-11-22 01:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-11-12 04:08 - 2014-11-12 04:08 - 00000000 __SHD () C:\Users\Barry\AppData\Local\EmieBrowserModeList
2014-11-12 02:56 - 2014-11-13 01:53 - 22661121 _____ () C:\Windows\FSISU.log
2014-11-12 02:56 - 2014-11-13 01:53 - 00353444 _____ () C:\Windows\FSDEPH.log
2014-11-12 02:56 - 2014-11-13 01:53 - 00029416 _____ () C:\Windows\fsavunin.log
2014-11-12 02:56 - 2014-11-13 01:53 - 00008328 _____ () C:\Windows\FSGKIAIN.log
2014-11-12 02:56 - 2014-11-13 01:53 - 00003588 _____ () C:\Windows\FSLDIN.LOG
2014-11-12 02:56 - 2014-11-13 01:53 - 00000687 _____ () C:\Windows\fstnbins.LOG
2014-11-12 02:56 - 2014-11-12 02:56 - 00856630 _____ () C:\Windows\FSSFM.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00709426 _____ () C:\Windows\FSSETUP.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00136077 _____ () C:\Windows\FSPROD.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00088551 _____ () C:\Windows\RunSetup.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00070989 _____ () C:\Windows\FSAVINST.LOG
2014-11-12 02:56 - 2014-11-12 02:56 - 00019322 _____ () C:\Windows\fspplugin.log
2014-11-12 02:56 - 2014-11-12 02:56 - 00009874 _____ () C:\Windows\FSAVCSIN.LOG
2014-11-12 02:56 - 2014-11-12 02:56 - 00000657 _____ () C:\Windows\fsav_db_setup.log
2014-11-11 22:05 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-11 22:05 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-11 22:05 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-11 22:04 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-11 22:04 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-11 22:04 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-11 22:04 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-11 22:04 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-11 22:04 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-11 22:04 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-11 22:04 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-11 22:04 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-11 22:04 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-11 22:04 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-11 22:04 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-11 22:04 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-11 22:04 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-11 22:04 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-11 22:04 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-11 22:04 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-11 22:04 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-11 22:04 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-11 22:04 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-11 22:04 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-11 22:04 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-11 22:04 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-11 22:04 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-11 22:04 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-11 22:02 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-11 22:02 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-11 22:02 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-11 22:02 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-09 06:53 - 2014-11-09 06:53 - 00000000 ___HD () C:\Windows\msdownld.tmp
2014-11-09 02:45 - 2014-11-30 19:47 - 00000000 ____D () C:\AdwCleaner
2014-11-08 02:01 - 2014-11-08 02:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-11-08 02:00 - 2014-11-08 02:40 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-11-08 01:59 - 2014-11-08 01:59 - 00000000 ____D () C:\Windows\PCHEALTH
2014-11-08 01:59 - 2014-11-08 01:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio
2014-11-08 01:57 - 2014-11-19 03:42 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-11-08 01:57 - 2014-11-08 01:57 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-11-08 01:57 - 2014-11-08 01:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2014-11-08 01:55 - 2014-11-08 01:55 - 00000000 __RHD () C:\MSOCache
2014-11-07 23:47 - 2014-11-22 01:42 - 00070940 _____ () C:\Windows\IE11_main.log
2014-11-05 20:39 - 2014-11-05 20:39 - 00639400 _____ (Akeo Consulting (http://akeo.ie)) C:\Users\Barry\Desktop\rufus(1).exe
2014-11-05 14:18 - 2014-11-28 05:51 - 00000000 ____D () C:\Users\Barry\Desktop\system-ninja-portable-3.0.4
2014-11-03 22:42 - 2014-11-09 07:44 - 00109696 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-31 21:14 - 2014-10-31 21:14 - 00000000 ____D () C:\Program Files\Realtek
2014-10-31 21:14 - 2014-05-14 18:37 - 03962840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2014-10-31 21:14 - 2014-05-14 16:00 - 01099203 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2014-10-31 21:14 - 2014-05-12 20:11 - 60636160 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2014-10-31 21:14 - 2014-05-09 11:17 - 00628952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2014-10-31 21:14 - 2014-04-30 11:34 - 00948952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2014-10-31 21:14 - 2014-04-28 15:48 - 02800344 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2014-10-31 21:14 - 2014-04-25 13:51 - 02834648 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2014-10-31 21:14 - 2014-04-25 13:23 - 01022168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2014-10-31 21:14 - 2014-03-06 16:35 - 01959128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2014-10-31 21:14 - 2014-02-18 17:04 - 02770976 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2014-10-31 21:14 - 2014-01-28 11:48 - 01286872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2014-10-31 21:14 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2014-10-31 21:14 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2014-10-31 21:14 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2014-10-31 21:14 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2014-10-31 21:14 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2014-10-31 21:14 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2014-10-31 21:14 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2014-10-31 21:14 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2014-10-31 21:13 - 2013-10-16 03:43 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2014-10-31 21:13 - 2013-10-11 12:47 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-10-31 21:13 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2014-10-31 20:46 - 2014-10-31 21:14 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-10-31 20:22 - 2014-10-31 20:22 - 00000000 ____D () C:\ProgramData\ATI
2014-10-31 20:22 - 2014-10-31 20:22 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-10-31 20:22 - 2014-10-31 20:22 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-10-31 20:22 - 2014-10-31 20:22 - 00000000 ____D () C:\Program Files (x86)\AMD APP
2014-10-31 20:21 - 2014-10-31 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2014-10-31 20:20 - 2014-10-31 20:21 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-10-31 20:20 - 2014-10-31 20:20 - 00000000 ____D () C:\Program Files\ATI
2014-10-31 20:20 - 2014-10-31 20:20 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-30 19:56 - 2009-07-14 05:45 - 00026336 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-30 19:56 - 2009-07-14 05:45 - 00026336 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-30 19:53 - 2009-07-14 06:13 - 00821598 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-30 19:48 - 2014-10-27 23:21 - 01601974 _____ () C:\Windows\PFRO.log
2014-11-30 19:48 - 2014-10-25 23:49 - 00015413 _____ () C:\Windows\setupact.log
2014-11-30 19:47 - 2014-08-01 22:09 - 01155173 _____ () C:\Windows\WindowsUpdate.log
2014-11-29 04:27 - 2009-07-14 04:20 - 00000000 ___RD () C:\Users\Public\Libraries
2014-11-29 04:22 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-27 03:09 - 2014-09-26 01:26 - 00000000 ____D () C:\ProgramData\Unchecky
2014-11-26 23:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-26 03:31 - 2014-05-22 19:23 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-11-26 01:36 - 2014-08-20 20:45 - 00000000 ____D () C:\Users\Barry\AppData\Local\Adobe
2014-11-26 01:36 - 2014-04-11 21:48 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-26 01:36 - 2014-04-11 21:48 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-25 21:02 - 2014-05-18 00:02 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\NewsLeecher
2014-11-24 04:36 - 2014-04-11 20:02 - 00000000 ____D () C:\Users\Barry
2014-11-23 22:24 - 2014-04-11 21:49 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-11-22 03:28 - 2014-08-28 22:10 - 00388608 _____ (Trend Micro Inc.) C:\Users\Barry\Desktop\HijackThis.exe
2014-11-22 02:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-11-22 01:42 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-11-21 23:30 - 2014-04-30 20:00 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\dvdcss
2014-11-21 04:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\servicing
2014-11-20 22:48 - 2014-04-11 21:48 - 00000000 ____D () C:\Users\Barry\AppData\Roaming\Adobe
2014-11-20 22:48 - 2014-04-11 21:37 - 00000000 ____D () C:\ProgramData\Adobe
2014-11-20 22:37 - 2014-04-14 22:48 - 00000000 ____D () C:\Windows\Sun
2014-11-19 00:42 - 2009-07-14 06:08 - 00032602 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-11-15 03:11 - 2014-05-22 21:42 - 00000000 ____D () C:\Users\Barry\AppData\Local\Downloaded Installations
2014-11-15 02:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-11-14 02:17 - 2014-08-28 04:05 - 00000000 ____D () C:\Windows\Minidump
2014-11-12 02:56 - 2014-09-28 08:06 - 00020560 _____ () C:\Windows\prodsett_copy.ini
2014-11-12 01:08 - 2014-04-14 22:13 - 00000000 ____D () C:\Users\Administrator
2014-11-11 23:55 - 2014-08-01 22:09 - 01107932 _____ () C:\Windows\WindowsUpdate(12).log
2014-11-11 22:51 - 2014-05-17 21:59 - 00007660 _____ () C:\Users\Barry\AppData\Local\resmon.resmoncfg
2014-11-11 22:13 - 2014-10-25 23:49 - 00411360 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-11 22:11 - 2014-04-12 19:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-11 22:08 - 2014-04-11 20:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-10 23:24 - 2014-10-23 21:08 - 00000000 ____D () C:\ProgramData\Spotnet
2014-11-09 07:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system
2014-11-09 06:08 - 2014-04-11 23:14 - 00784114 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-11-09 03:32 - 2014-10-25 21:34 - 00109696 _____ () C:\Users\Barry\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-08 02:54 - 2009-07-14 03:34 - 00000514 _____ () C:\Windows\win.ini
2014-11-08 02:28 - 2014-04-12 19:17 - 00000000 ____D () C:\Users\Barry\Desktop\NoPE
2014-11-08 02:00 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-11-08 01:59 - 2011-04-12 08:45 - 00000000 ____D () C:\Windows\ShellNew
2014-11-07 23:53 - 2014-04-12 05:55 - 00000000 ____D () C:\Windows\Panther
2014-11-04 14:30 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-31 23:26 - 2014-04-11 20:51 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-31 21:15 - 2014-04-11 20:57 - 00000000 ___HD () C:\Program Files (x86)\Temp
2014-10-31 21:13 - 2014-04-11 20:57 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-10-31 21:11 - 2014-04-11 20:57 - 00000000 ____D () C:\Program Files (x86)\Realtek
2014-10-31 20:22 - 2014-10-10 21:24 - 00000000 ____D () C:\ProgramData\AMD

Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\temp\Quarantine.exe
C:\Users\Administrator\AppData\Local\temp\sqlite3.dll
C:\Users\Barry\AppData\Local\temp\Quarantine.exe
C:\Users\Barry\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-11-25 20:23

==================== End Of Log ============================


  • 0

#10
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts
Step 1: FRST Fix
  • Please download the attached fixlist.txt file and save it to the same location as FRST

    Note: It's important that both files, FRST.exe/FRST64.exe and fixlist.txt are in the same location or the fix will not work
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run FRST.exe/FRST64.exe and press the Fix button just once and wait
  • If for some reason the tool needs a restart, please make sure you let the system restart normally, then let the tool complete its run
  • When finished, FRST will generate a log (Fixlog.txt) in the same location the tool was run, please post it to your reply
Step 2: FRST Scan
  • Run FRST. (if you have Windows Vista / Windows 7 / Windows 8: Please do a Right click on the FRST icon and select Run as Administrator)
  • Click Scan to start FRST.
  • When FRST finishes scanning, a log, FRST.txt, will open.
  • Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this log into your next post please.
Step 3: ESET

Please run a free online scan with the ESET Online Scanner:

IMPORTANT: You MUST use Internet Explorer for this step!
  • Visit the ESET Online Scanner Web Page
  • Select the blue Run ESET Online Scanner button:
    ESET1_zps23a5e840.png
  • Tick the box next to YES, I accept the Terms of Use and click Start
    ESET_EULA2_zps9451f1c3.png
  • When asked, allow the ActiveX control to install.
  • Select Enable detection of potentially unwanted applications and select Advanced Settings:
    ESET2_zpsc701c045.png
  • Make sure to check the options Remove found threats and Enable Anti-Stealth technology are checked:
    ESET4_zps0afafd0d.png
  • Click Start. (This scan can take several hours, so please be patient):
    ESET3_zpsccd1657d.png
  • Once the scan is completed, select List of found threats:
    ESET5_zpsd27be299.png
  • Select Export to text file... and save the file as ESETlog.txt on your Desktop:
    ESET6_zpsc17d154e.png
  • Click the Back button.
  • Click the Finish button:
    ESET9_zps51587217.png
  • Use Notepad to open the saved log file (on your Desktop- ESET.txt)[/b]
  • Copy and paste that log as a reply to this topic.
Step 4: Question

How is your PC running?

Attached Files


  • 0

Advertisements


#11
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts


  • 0

#12
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Esset found no threats .

 

[email protected] as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# product=EOS
# version=8
# IEXPLORE.EXE=11.00.9600.16428 (winblue_gdr.131013-1700)
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=161eb148f2f39c4e95390071e4c9a052
# engine=21335
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-11-30 09:02:52
# local_time=2014-11-30 10:02:52 (+0100, W. Europe Standard Time)
# country="Netherlands"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 71 87 442686 585595 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 176842 169011222 0 0
# scanned=120937
# found=0
# cleaned=0
# scan_time=1441


  • 0

#13
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Machiavelli ,

 

system runs fine , better then before but i still got the same errors in my event viewer .

I also  have to put UAC control of to even view  files on the C drive .


  • 0

#14
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts

better then before but i still got the same errors in my event viewer .

Which?

I also have to put UAC control of to even view files on the C drive .

What is UAC Control?
  • 0

#15
IkkaMouse

IkkaMouse

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

UAC = User Account Control

 

 

Task Scheduler service failed to start Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.

 

Task Scheduler failed to initialize LSA for starting the Task Compatibility module. Tasks may not be able to register on previous Window versions. Additional Data: Error Value: 2147942402.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP