Help! My 11 year old got a new laptop while I was away. By the time I got home he already is so infected with Malware that I can barely get this topic started! I know the folks here will be able to get him clean and set up for a long, malware free future.
When using Chrome to browse, every time I click I get a new tab of ads as well as constant pop-up ads.
I downloaded and ran the scan tool as instructed Here are the two logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2015 02
Ran by adami_000 (administrator) on MAXROSENFELD on 14-05-2015 17:15:43
Running from C:\Users\adami_000\Desktop
Loaded Profiles: adami_000 (Available profiles: adami_000)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\Toshiba\PasswordUtility\GFNEXSrv.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth Filter Driver Package\BTDevMgr.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel® Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Program Files (x86)\Toshiba\TOSHIBA System Driver\TOSTABSYSSVC.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Toshiba Corporation) C:\Program Files\TOSHIBA\Teco\TecoService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Teco\TecoResident.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Pokki) C:\Users\adami_000\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Super PC Tools Ltd) C:\ProgramData\{c4f23f34-8405-3a0c-c4f2-23f34840fcd2}\hqghumeaylnlf.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Pokki) C:\Users\adami_000\AppData\Local\Pokki\Engine\HostAppService.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\PluginContainer.exe
() C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\plugins\4\Plugin.exe
() C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\plugins\3\Plugin.exe
() C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\plugins\5\Plugin.exe
() C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\plugins\3\Plugin.exe
() C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\plugins\2\Plugin.exe
() C:\Program Files (x86)\Common Files\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\updater.exe
() C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\plugins\8\Plugin.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [TecoResident] => C:\Program Files\TOSHIBA\Teco\TecoResident.exe [179288 2014-04-17] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe [2556768 2013-10-08] (TOSHIBA Corporation)
HKLM\...\Run: [TSSSrv] => C:\Program Files (x86)\TOSHIBA\System Setting\TSSSrv.exe [296008 2013-10-21] (TOSHIBA Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM-x32\...\Run: [TSVU] => c:\Program Files\TOSHIBA\TOSHIBA Smart View Utility\TosSmartViewLauncher.exe [517536 2014-04-06] (TOSHIBA)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1190642625-1873434813-491721638-1001\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
HKU\S-1-5-21-1190642625-1873434813-491721638-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.)
HKU\S-1-5-21-1190642625-1873434813-491721638-1001\...\RunOnce: [Application Restart #4] => C:\Users\adami_000\AppData\Local\Pokki\Engine\HostAppService.exe [7853056 2015-05-05] (Pokki)
HKU\S-1-5-18\...\Run: [] => [X]
AppInit_DLLs-x32: c:\progra~2\amazon\amazon~1\amazon~3.dll => c:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE.dll [106304 2014-05-23] (Amazon Inc.)
Startup: C:\Users\adami_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-04-20]
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{c4f23f34-8405-3a0c-c4f2-23f34840fcd2}\hqghumeaylnlf.exe (Super PC Tools Ltd)
Startup: C:\Users\adami_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-04-21]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1190642625-1873434813-491721638-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com/?pc=TNJB
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com/?pc=TNJB
HKU\S-1-5-21-1190642625-1873434813-491721638-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSE1
HKU\S-1-5-21-1190642625-1873434813-491721638-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba13.msn.com/?pc=TNJB
HKU\S-1-5-21-1190642625-1873434813-491721638-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://mystart.toshiba.com
HKU\S-1-5-21-1190642625-1873434813-491721638-1001\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft....q={searchTerms}
SearchScopes: HKLM -> DefaultScope {105EC9BF-C5FC-429A-80DA-B7D7AAFD3C20} URL = http://www.bing.com/...=MSSEDF&pc=MSE1
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {105EC9BF-C5FC-429A-80DA-B7D7AAFD3C20} URL = http://www.bing.com/...=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL = http://us.yhs4.searc...5_17&os=Windows8.1&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1190642625-1873434813-491721638-1001 -> DefaultScope {0C181DD7-EC66-11E4-826C-D61CB079928F} URL = http://www.bing.com/...=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-1190642625-1873434813-491721638-1001 -> {0C181DD7-EC66-11E4-826C-D61CB079928F} URL = http://www.bing.com/...=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-1190642625-1873434813-491721638-1001 -> {8CDE19E6-71C2-4B46-89B7-35F6A18C571A} URL =
BHO: roCckietsalle -> {30869705-DAFB-4A89-9932-C459F4447A83} -> C:\Program Files (x86)\roCckietsalle\I9dCTYV0j2bHxe.x64.dll [2015-05-13] ()
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-04-21] (Microsoft Corporation)
BHO: dailypriize -> {6FE5178B-B276-4B67-B9B9-9A0FD6113F5C} -> C:\Program Files (x86)\dailypriize\riOroizAPbt8Tk.x64.dll [2015-05-13] ()
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-04-21] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-04-21] (Microsoft Corporation)
BHO-x32: roCckietsalle -> {30869705-DAFB-4A89-9932-C459F4447A83} -> C:\Program Files (x86)\roCckietsalle\I9dCTYV0j2bHxe.dll [2015-05-13] ()
BHO-x32: dailypriize -> {6FE5178B-B276-4B67-B9B9-9A0FD6113F5C} -> C:\Program Files (x86)\dailypriize\riOroizAPbt8Tk.dll [2015-05-13] ()
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-29] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-04-21] (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-29] (Oracle Corporation)
BHO-x32: browse pulse -> {ed8e593d-1965-4e45-9d55-d56162dcde14} -> C:\Program Files (x86)\browse pulse\Extensions\ed8e593d-1965-4e45-9d55-d56162dcde14.dll [2015-04-20] ()
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-04-17] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-04-17] (McAfee, Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-04-21] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-04-17] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-04-17] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll [2014-12-22] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll [2014-12-22] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-29] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-04-21] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-19] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2014-12-22]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ggbc_15_17¶m1=1¶m2=f%3D1%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyE0C0B0ByDzzyC0FtB0FyBtByDzz0AyBtN0D0Tzu0StCtBtDyDtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StCtDtD0Ezy0CzzyBtG0FtByByEtG0A0A0ByBtG0C0AyBzytGyDtDyE0F0E0BtC0CtCyByC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyE0F0CtB0ByDyCtGtA0F0E0CtGyEyDtD0AtG0ByDtC0DtG0F0CtCzytDyB0B0E0EyCtB0A2QtN0A0LzuyE%26cr%3D426752944%26a%3Dwny_ggbc_15_17%26os%3DWindows 8.1
CHR StartupUrls: Default -> "hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ggbc_15_17¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1QzuyE0C0B0ByDzzyC0FtB0FyBtByDzz0AyBtN0D0Tzu0StCtBtDyDtN1L2XzutAtFzytFzztFtDtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StCtDtD0Ezy0CzzyBtG0FtByByEtG0A0A0ByBtG0C0AyBzytGyDtDyE0F0E0BtC0CtCyByC0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CyE0F0CtB0ByDyCtGtA0F0E0CtGyEyDtD0AtG0ByDtC0DtG0F0CtCzytDyB0B0E0EyCtB0A2QtN0A0LzuyE%26cr%3D426752944%26a%3Dwny_ggbc_15_17%26os%3DWindows 8.1"
CHR DefaultSearchKeyword: Default -> homepage-web.com
CHR DefaultSearchURL: Default -> http://search.homepa...q={searchTerms}
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\adami_000\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\adami_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-04-19]
CHR Extension: (Google Search) - C:\Users\adami_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-19]
CHR Extension: (SiteAdvisor) - C:\Users\adami_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-04-19]
CHR Extension: (IMG inspector) - C:\Users\adami_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpogobkggapdhmfnamfnhmchcbmehokb [2015-05-13]
CHR Extension: (browse pulse) - C:\Users\adami_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\oohaifmlpecbkpanlpandmagoinoogjn [2015-04-30]
CHR Extension: (Gmail) - C:\Users\adami_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-19]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-05-06]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-05-06]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 580a4029; c:\Program Files (x86)\IncrementInstance\IncrementInstance.dll [2431488 2015-05-12] () [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth Filter Driver Package\BTDevMgr.exe [121856 2014-07-15] () [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 DptfParticipantAcpiProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [117704 2013-09-17] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [150760 2013-09-17] (Intel Corporation)
R3 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [21816 2014-08-26] ()
R2 GFNEXSrv; C:\Program Files (x86)\Toshiba\PasswordUtility\GFNEXSrv.exe [163168 2013-03-27] ()
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [318568 2014-08-21] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel® Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [154856 2015-04-17] (McAfee, Inc.)
S2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1050952 2014-11-06] (McAfee, Inc.)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1854056 2012-12-07] (Microsoft Corporation)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [291032 2014-08-18] (Realtek Semiconductor)
R2 Service Mgr browsepulse; C:\ProgramData\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\PluginContainer.exe [556304 2015-05-14] ()
R2 TOSTABSYSSVC; C:\Program Files (x86)\TOSHIBA\TOSHIBA System Driver\TOSTABSYSSVC.exe [34680 2014-08-01] ()
R2 Update Mgr browsepulse; C:\Program Files (x86)\Common Files\5b4b2b13-bc3c-4690-a9ac-2f28c7e74c15\updater.exe [478992 2015-05-14] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
S2 McNaiAnn; "C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S3 McODS; "C:\ProgramData\McAfee\Update\Installs\pkg_default\Download_Files\default\vso\vso_li_cat\%VSINSTALL_DIR64%\mcods.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AX88179; C:\Windows\system32\DRIVERS\ax88179_178a.sys [70104 2013-07-08] (ASIX Electronics Corp.)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 DptfDevAcpiProc; C:\Windows\system32\DRIVERS\DptfDevAcpiProc.sys [198808 2013-09-17] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [493240 2013-09-17] (Intel Corporation)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-10] (Intel Corporation)
S3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [447440 2014-09-19] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96600 2014-09-19] (McAfee, Inc.)
R2 PEGAGFN; C:\Program Files (x86)\Toshiba\PasswordUtility\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
R3 RtkBtFilter2; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [48856 2013-09-05] (Realtek Microelectronics)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3560664 2014-09-04] (Realtek Semiconductor Corporation )
R3 SensorsHIDClassDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-28] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-28] (Microsoft Corporation)
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [27136 2014-03-24] (Windows ® Win 7 DDK provider)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-14 17:15 - 2015-05-14 17:16 - 00023618 _____ () C:\Users\adami_000\Desktop\FRST.txt
2015-05-14 17:07 - 2015-05-14 17:14 - 00024471 _____ () C:\Users\adami_000\Downloads\FRST.txt
2015-05-14 17:06 - 2015-05-14 17:16 - 00000000 ____D () C:\FRST
2015-05-14 17:05 - 2015-05-14 17:06 - 02106368 _____ (Farbar) C:\Users\adami_000\Desktop\FRST64.exe
2015-05-14 17:04 - 2015-05-14 17:04 - 01145856 _____ (Farbar) C:\Users\adami_000\Downloads\FRST.exe
2015-05-13 17:37 - 2015-05-13 17:37 - 02875575 _____ () C:\Users\adami_000\Desktop\max_rosenfeld_9R.pptx
2015-05-13 14:48 - 2015-05-13 14:48 - 00005632 ___SH () C:\Users\adami_000\Desktop\Thumbs.db
2015-05-13 14:04 - 2015-05-13 14:04 - 00000000 ____D () C:\Program Files (x86)\IMG inspector
2015-05-13 14:03 - 2015-05-13 14:04 - 00000000 ____D () C:\Program Files (x86)\roCckietsalle
2015-05-13 14:03 - 2015-05-13 14:03 - 00000000 ____D () C:\Program Files (x86)\dailypriize
2015-05-13 14:03 - 2015-05-13 14:03 - 00000000 ____D () C:\Program Files (x86)\coOlnecheaap
2015-05-13 13:53 - 2015-05-13 13:53 - 00604894 _____ () C:\Users\adami_000\Documents\14-year-old girl killed after planned videotaped fight - CNN.com.html
2015-05-13 13:53 - 2015-05-13 13:53 - 00000000 ____D () C:\Users\adami_000\Documents\14-year-old girl killed after planned videotaped fight - CNN.com_files
2015-05-13 04:29 - 2015-05-13 04:29 - 00447542 _____ () C:\Users\adami_000\Downloads\max_rosenfeld_9R (3).pptx
2015-05-13 04:25 - 2015-05-13 04:25 - 00447542 _____ () C:\Users\adami_000\Downloads\max_rosenfeld_9R (2).pptx
2015-05-12 17:15 - 2015-05-12 17:17 - 00000000 ____D () C:\Users\adami_000\Desktop\Building Homes of Our Own
2015-05-12 16:27 - 2015-05-12 16:27 - 00000424 _____ () C:\Users\adami_000\Desktop\This PC.lnk
2015-05-12 14:51 - 2015-05-12 14:51 - 00000000 ____D () C:\Users\adami_000\AppData\Local\IsolatedStorage
2015-05-12 13:58 - 2015-05-12 13:58 - 00000000 ____D () C:\Program Files (x86)\IncrementInstance
2015-05-12 13:56 - 2015-05-12 13:58 - 00000000 ____D () C:\ProgramData\db17de9200004904
2015-05-12 13:28 - 2015-05-12 13:28 - 00000000 ____D () C:\Program Files (x86)\DriverRestore
2015-05-11 17:31 - 2015-05-11 17:31 - 00000000 ____D () C:\Users\adami_000\Desktop\mp3
2015-05-11 17:13 - 2015-05-11 17:13 - 00000000 ____D () C:\Program Files (x86)\Paste Lorem ipsum
2015-05-11 17:12 - 2015-05-13 15:53 - 00000000 ____D () C:\Program Files (x86)\bRowseandshop
2015-05-11 17:12 - 2015-05-13 15:52 - 00000000 ____D () C:\Program Files (x86)\OOfferapp
2015-05-11 17:12 - 2015-05-11 17:12 - 00000000 ____D () C:\Program Files (x86)\oFferaPop
2015-05-11 16:24 - 2015-05-11 16:24 - 00004030 _____ () C:\Windows\System32\Tasks\LaunchApp
2015-05-11 15:44 - 2015-05-14 16:28 - 00005004 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for MAXROSENFELD-adami_000 MaxRosenfeld
2015-05-11 15:29 - 2015-05-11 15:30 - 00074917 _____ () C:\Users\adami_000\Downloads\shrinking_cars_current_events.pptx
2015-05-10 17:15 - 2015-05-10 17:15 - 00000000 ____D () C:\Users\adami_000\Documents\under water walking
2015-05-10 17:15 - 2015-05-10 17:15 - 00000000 ____D () C:\Users\adami_000\Documents\tek it
2015-05-10 17:15 - 2015-05-10 17:15 - 00000000 ____D () C:\Users\adami_000\Documents\technology
2015-05-10 17:15 - 2015-05-10 17:15 - 00000000 ____D () C:\Users\adami_000\Documents\spanish
2015-05-10 17:15 - 2015-05-10 17:15 - 00000000 ____D () C:\Users\adami_000\Documents\other computer files
2015-05-10 17:15 - 2015-04-21 17:16 - 00009568 _____ () C:\Users\adami_000\Documents\kayak fundraiser.xlsx
2015-05-10 17:15 - 2015-04-20 12:49 - 00001886 _____ () C:\Users\adami_000\Documents\MyPC Backup.lnk
2015-05-10 17:14 - 2015-05-10 17:15 - 00000000 ____D () C:\Users\adami_000\Documents\kindle
2015-05-10 17:14 - 2015-05-10 17:14 - 00000000 ____D () C:\Users\adami_000\Documents\100PHOTO
2015-05-10 17:14 - 2015-05-06 14:40 - 00791853 _____ () C:\Users\adami_000\Documents\stuff.zip
2015-05-10 17:14 - 2015-05-01 15:00 - 00000000 ____D () C:\Users\adami_000\Documents\english
2015-05-05 18:36 - 2015-05-05 18:36 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2015-05-05 18:12 - 2015-05-05 18:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-05-05 18:11 - 2015-05-05 18:36 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-05 18:11 - 2015-05-05 18:11 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-05-05 16:38 - 2015-03-03 06:17 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-05-05 16:33 - 2015-05-05 16:33 - 00000000 ___HD () C:\kleaner.tmp
2015-05-05 16:28 - 2015-05-05 16:28 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
2015-05-02 10:42 - 2015-05-02 10:42 - 00073593 _____ () C:\Users\adami_000\Downloads\Introduction_Directions.pptx
2015-05-01 18:42 - 2015-05-01 18:42 - 00002807 _____ () C:\Users\adami_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CNN.lnk
2015-05-01 15:01 - 2015-05-13 17:38 - 00000000 ____D () C:\Users\adami_000\Desktop\technology
2015-05-01 15:00 - 2015-05-13 04:28 - 00000000 ____D () C:\Users\adami_000\Desktop\spanish
2015-05-01 15:00 - 2015-05-12 15:42 - 00000000 ____D () C:\Users\adami_000\Desktop\english
2015-05-01 14:59 - 2015-05-13 04:27 - 01185887 _____ () C:\Users\adami_000\Desktop\stuff.zip
2015-05-01 14:29 - 2015-05-01 14:29 - 00446714 _____ () C:\Users\adami_000\Downloads\max_rosenfeld_9R (1).pptx
2015-05-01 14:23 - 2015-05-01 14:40 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-01 14:23 - 2015-04-01 11:16 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-30 16:58 - 2014-10-28 20:59 - 00014144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\swenum.sys
2015-04-30 16:58 - 2014-10-28 20:58 - 00014528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmkaud.sys
2015-04-30 16:58 - 2014-10-28 18:01 - 00843776 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2015-04-30 16:58 - 2014-10-28 18:00 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll
2015-04-30 16:58 - 2014-10-28 17:50 - 12749824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2015-04-30 16:58 - 2014-10-28 17:46 - 09530368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2015-04-30 16:58 - 2014-10-28 17:45 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-04-30 16:58 - 2014-10-28 17:39 - 02814464 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-04-30 16:58 - 2014-10-28 17:34 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-04-30 16:58 - 2014-10-08 02:24 - 00467776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2015-04-30 16:58 - 2014-09-26 21:59 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-04-30 16:58 - 2014-09-24 20:42 - 00373568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2015-04-30 16:57 - 2014-10-28 20:52 - 02485056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2015-04-30 16:57 - 2014-10-28 19:08 - 18822656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2015-04-30 16:57 - 2014-10-28 18:33 - 15157760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2015-04-30 16:57 - 2014-10-28 18:02 - 14354944 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2015-04-30 16:57 - 2014-10-28 17:52 - 15432704 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-04-30 16:57 - 2014-10-28 17:52 - 01275904 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2015-04-30 16:57 - 2014-10-28 17:37 - 06386176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2015-04-30 16:55 - 2014-10-28 17:45 - 13318144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-04-30 16:53 - 2014-10-28 20:59 - 03460472 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2015-04-30 16:53 - 2014-10-28 19:19 - 03320320 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-04-30 16:53 - 2014-10-28 18:43 - 07075328 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
2015-04-30 16:53 - 2014-10-28 18:16 - 05267968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2015-04-30 16:53 - 2014-10-28 17:58 - 00926208 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2015-04-30 16:53 - 2014-10-28 17:54 - 07784960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2015-04-30 16:53 - 2014-10-28 17:38 - 07032320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-04-30 16:53 - 2014-10-28 17:33 - 06213632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-04-30 16:53 - 2014-10-06 23:45 - 03307112 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2015-04-30 16:52 - 2014-10-28 20:59 - 02529856 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-04-30 16:52 - 2014-10-28 20:52 - 02334080 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2015-04-30 16:52 - 2014-10-28 19:29 - 04483072 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2015-04-30 16:52 - 2014-10-28 18:45 - 03607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-04-30 16:52 - 2014-10-28 18:45 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\rdpinput.exe
2015-04-30 16:52 - 2014-10-28 18:40 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2015-04-30 16:52 - 2014-10-28 18:35 - 04709888 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-04-30 16:52 - 2014-10-28 18:28 - 03820544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-04-30 16:52 - 2014-10-28 18:22 - 03633664 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-04-30 16:52 - 2014-10-28 17:43 - 05264384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2015-04-30 16:52 - 2014-10-06 20:44 - 02890296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2015-04-30 16:51 - 2014-10-28 20:57 - 03138720 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2015-04-30 16:51 - 2014-10-28 20:57 - 01286048 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2015-04-30 16:51 - 2014-10-28 20:13 - 01901240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-04-30 16:51 - 2014-10-28 20:11 - 02689392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVCORE.DLL
2015-04-30 16:51 - 2014-10-28 20:07 - 02324208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2015-04-30 16:51 - 2014-10-28 19:59 - 03109376 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-04-30 16:51 - 2014-10-28 19:24 - 04418560 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2015-04-30 16:51 - 2014-10-28 18:56 - 03754496 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2015-04-30 16:51 - 2014-10-28 18:51 - 00941056 _____ (Microsoft Corporation) C:\Windows\system32\XpsFilt.dll
2015-04-30 16:51 - 2014-10-28 18:39 - 02896384 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2015-04-30 16:51 - 2014-10-28 18:38 - 04690432 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2015-04-30 16:51 - 2014-10-28 18:26 - 03561984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2015-04-30 16:51 - 2014-10-28 18:24 - 02464768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-04-30 16:51 - 2014-10-28 18:12 - 02749952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2015-04-30 16:51 - 2014-10-28 18:08 - 02608640 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-04-30 16:51 - 2014-10-28 18:08 - 02542080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2015-04-30 16:51 - 2014-10-28 18:05 - 03273216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2015-04-30 16:51 - 2014-10-28 18:03 - 04067840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2015-04-30 16:51 - 2014-10-28 17:52 - 02554880 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-04-30 16:51 - 2014-10-28 17:48 - 03056128 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2015-04-30 16:51 - 2014-10-28 17:42 - 01922560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2015-04-30 16:50 - 2014-10-28 21:00 - 02314952 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2015-04-30 16:50 - 2014-10-28 21:00 - 02229168 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2015-04-30 16:50 - 2014-10-28 20:57 - 03118096 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2015-04-30 16:50 - 2014-10-28 20:57 - 02745160 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2015-04-30 16:50 - 2014-10-28 20:55 - 02174976 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2015-04-30 16:50 - 2014-10-28 20:55 - 01660528 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-04-30 16:50 - 2014-10-28 20:52 - 01518504 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2015-04-30 16:50 - 2014-10-28 20:52 - 01509688 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2015-04-30 16:50 - 2014-10-28 20:51 - 01310912 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-04-30 16:50 - 2014-10-28 20:12 - 01907384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2015-04-30 16:50 - 2014-10-28 20:11 - 02528760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2015-04-30 16:50 - 2014-10-28 20:11 - 01024200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2015-04-30 16:50 - 2014-10-28 20:10 - 01564464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2015-04-30 16:50 - 2014-10-28 19:10 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2015-04-30 16:50 - 2014-10-28 18:57 - 02924032 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2015-04-30 16:50 - 2014-10-28 18:47 - 02072064 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2015-04-30 16:50 - 2014-10-28 18:44 - 02984448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2015-04-30 16:50 - 2014-10-28 18:42 - 01999872 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-04-30 16:50 - 2014-10-28 18:35 - 03256320 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2015-04-30 16:50 - 2014-10-28 18:31 - 02941952 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2015-04-30 16:50 - 2014-10-28 18:15 - 02259456 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-04-30 16:50 - 2014-10-28 18:10 - 02344960 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-30 16:50 - 2014-10-28 18:08 - 02174976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-04-30 16:50 - 2014-10-28 18:08 - 01822720 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
2015-04-30 16:50 - 2014-10-28 17:54 - 01945600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-04-30 16:50 - 2014-10-28 17:52 - 02170368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2015-04-30 16:50 - 2014-10-28 17:51 - 01554432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-04-30 16:50 - 2014-10-28 17:46 - 01919488 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2015-04-30 16:50 - 2014-10-28 17:46 - 01348096 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2015-04-30 16:50 - 2014-10-28 17:35 - 01668096 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll
2015-04-30 16:49 - 2014-10-28 21:10 - 01816008 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2015-04-30 16:49 - 2014-10-28 20:57 - 02450216 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL
2015-04-30 16:49 - 2014-10-28 20:55 - 01543768 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2015-04-30 16:49 - 2014-10-28 20:52 - 01288096 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2015-04-30 16:49 - 2014-10-28 20:52 - 01165744 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2015-04-30 16:49 - 2014-10-28 20:52 - 00952384 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2015-04-30 16:49 - 2014-10-28 20:12 - 01946144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2015-04-30 16:49 - 2014-10-28 20:11 - 02447104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVENCOD.DLL
2015-04-30 16:49 - 2014-10-28 20:10 - 01209624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-04-30 16:49 - 2014-10-28 20:07 - 01321192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2015-04-30 16:49 - 2014-10-28 19:25 - 00785920 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-04-30 16:49 - 2014-10-28 19:17 - 02003456 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2015-04-30 16:49 - 2014-10-28 19:00 - 02162176 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2015-04-30 16:49 - 2014-10-28 18:55 - 01697280 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-04-30 16:49 - 2014-10-28 18:53 - 01101824 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-04-30 16:49 - 2014-10-28 18:24 - 02364928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2015-04-30 16:49 - 2014-10-28 18:23 - 01500672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2015-04-30 16:49 - 2014-10-28 18:22 - 02410496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2015-04-30 16:49 - 2014-10-28 18:22 - 01084416 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2015-04-30 16:49 - 2014-10-28 18:21 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2015-04-30 16:49 - 2014-10-28 18:18 - 01753600 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2015-04-30 16:49 - 2014-10-28 18:17 - 01360896 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2015-04-30 16:49 - 2014-10-28 18:14 - 03553280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2015-04-30 16:49 - 2014-10-28 18:11 - 01639424 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2015-04-30 16:49 - 2014-10-28 18:10 - 02469888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2015-04-30 16:49 - 2014-10-28 18:03 - 02635264 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2015-04-30 16:49 - 2014-10-28 17:59 - 01490944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2015-04-30 16:49 - 2014-10-28 17:52 - 01461248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dui70.dll
2015-04-30 16:49 - 2014-10-28 17:50 - 02317824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2015-04-30 16:49 - 2014-10-28 17:45 - 01725952 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-04-30 16:49 - 2014-10-28 17:42 - 01221120 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2015-04-30 16:49 - 2014-10-28 17:39 - 01000448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2015-04-30 16:49 - 2014-10-28 17:34 - 01544192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-04-30 16:49 - 2014-10-15 01:32 - 02025792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2015-04-30 16:48 - 2014-10-28 21:00 - 01385216 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-30 16:48 - 2014-10-28 20:57 - 01576312 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2015-04-30 16:48 - 2014-10-28 20:55 - 01133200 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-04-30 16:48 - 2014-10-28 20:52 - 01064720 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-04-30 16:48 - 2014-10-28 20:52 - 00988544 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2015-04-30 16:48 - 2014-10-28 20:52 - 00962216 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-04-30 16:48 - 2014-10-28 20:52 - 00850656 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2015-04-30 16:48 - 2014-10-28 20:52 - 00821696 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2015-04-30 16:48 - 2014-10-28 20:18 - 00016504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psapi.dll
2015-04-30 16:48 - 2014-10-28 20:10 - 01178104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2015-04-30 16:48 - 2014-10-28 20:07 - 01115104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2015-04-30 16:48 - 2014-10-28 20:07 - 00959112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2015-04-30 16:48 - 2014-10-28 20:07 - 00857384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2015-04-30 16:48 - 2014-10-28 20:07 - 00785568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2015-04-30 16:48 - 2014-10-28 20:05 - 00890128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2015-04-30 16:48 - 2014-10-28 19:50 - 01192960 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2015-04-30 16:48 - 2014-10-28 19:31 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\sqlceqp40.dll
2015-04-30 16:48 - 2014-10-28 19:28 - 01502208 _____ (Microsoft Corporation) C:\Windows\system32\xpssvcs.dll
2015-04-30 16:48 - 2014-10-28 19:08 - 01540096 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2015-04-30 16:48 - 2014-10-28 18:56 - 01526784 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2015-04-30 16:48 - 2014-10-28 18:50 - 01289216 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll
2015-04-30 16:48 - 2014-10-28 18:48 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2015-04-30 16:48 - 2014-10-28 18:45 - 00618496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2015-04-30 16:48 - 2014-10-28 18:43 - 00933376 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2015-04-30 16:48 - 2014-10-28 18:42 - 03724800 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2015-04-30 16:48 - 2014-10-28 18:37 - 01563136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2015-04-30 16:48 - 2014-10-28 18:34 - 01114624 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2015-04-30 16:48 - 2014-10-28 18:33 - 01056768 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
2015-04-30 16:48 - 2014-10-28 18:32 - 01843712 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2015-04-30 16:48 - 2014-10-28 18:32 - 01390080 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-04-30 16:48 - 2014-10-28 18:25 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2015-04-30 16:48 - 2014-10-28 18:25 - 01534464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2015-04-30 16:48 - 2014-10-28 18:21 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-04-30 16:48 - 2014-10-28 18:20 - 01492480 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2015-04-30 16:48 - 2014-10-28 18:19 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2015-04-30 16:48 - 2014-10-28 18:17 - 01402368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2015-04-30 16:48 - 2014-10-28 18:16 - 01696256 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2015-04-30 16:48 - 2014-10-28 18:09 - 01335296 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2015-04-30 16:48 - 2014-10-28 18:08 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-04-30 16:48 - 2014-10-28 18:06 - 00747520 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2015-04-30 16:48 - 2014-10-28 18:03 - 02487296 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll
2015-04-30 16:48 - 2014-10-28 18:03 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2015-04-30 16:48 - 2014-10-28 18:01 - 01710592 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2015-04-30 16:48 - 2014-10-28 18:00 - 01705984 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-04-30 16:48 - 2014-10-28 17:59 - 01454080 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2015-04-30 16:48 - 2014-10-28 17:59 - 01021440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2015-04-30 16:48 - 2014-10-28 17:56 - 01337344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2015-04-30 16:48 - 2014-10-28 17:56 - 01248256 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2015-04-30 16:48 - 2014-10-28 17:56 - 01028608 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2015-04-30 16:48 - 2014-10-28 17:56 - 01001984 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll
2015-04-30 16:48 - 2014-10-28 17:47 - 02090496 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2015-04-30 16:48 - 2014-10-28 17:45 - 00887296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2015-04-30 16:48 - 2014-10-28 17:41 - 02880000 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2015-04-30 16:48 - 2014-10-28 17:41 - 01317376 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2015-04-30 16:48 - 2014-10-28 17:40 - 02104832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsservices.dll
2015-04-30 16:48 - 2014-10-28 17:36 - 00954880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2015-04-30 16:48 - 2014-10-28 17:33 - 01102848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2015-04-30 16:47 - 2014-10-28 21:09 - 01950280 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2015-04-30 16:47 - 2014-10-28 21:09 - 01239576 _____ (Microsoft Corporation) C:\Windows\system32\Taskmgr.exe
2015-04-30 16:47 - 2014-10-28 21:00 - 01540696 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-04-30 16:47 - 2014-10-28 21:00 - 00740664 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-04-30 16:47 - 2014-10-28 20:57 - 01552704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2015-04-30 16:47 - 2014-10-28 20:57 - 01210176 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2015-04-30 16:47 - 2014-10-28 20:57 - 00643064 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2015-04-30 16:47 - 2014-10-28 20:55 - 01063432 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2015-04-30 16:47 - 2014-10-28 20:55 - 00730824 _____ (Microsoft Corporation) C:\Windows\system32\clbcatq.dll
2015-04-30 16:47 - 2014-10-28 20:52 - 00734448 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-04-30 16:47 - 2014-10-28 20:52 - 00634768 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-04-30 16:47 - 2014-10-28 20:52 - 00580024 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmdev.dll
2015-04-30 16:47 - 2014-10-28 20:18 - 01782912 _____ (M
...