this is the FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-06-2015
Ran by kinetz07 (administrator) on KINETZ on 27-06-2015 19:05:53
Running from C:\Users\kinetz07\Downloads
Loaded Profiles: kinetz07 (Available Profiles: kinetz07)
Platform: Windows 8.1 Connected Single Language (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
(Microsoft Corporation) C:\Users\kinetz07\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMLockHandler.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Spotify Ltd) C:\Users\kinetz07\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Spotify Ltd) C:\Users\kinetz07\AppData\Roaming\Spotify\Spotify.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
() C:\Program Files (x86)\Garena Plus\ggdllhost.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\main.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Spotify Ltd) C:\Users\kinetz07\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\kinetz07\AppData\Roaming\Spotify\Spotify.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [62208 2014-12-19] (Acer Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-05-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-04-10] (Oracle Corporation)
HKLM-x32\...\Run: [RazerCortex] => C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe [98256 2015-03-12] (Razer Inc.)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-02-25] (Qualcomm®Atheros®)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [9981888 2015-05-27] ()
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3858000 2014-07-10] (Tonec Inc.)
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1081224 2013-02-05] (Autodesk, Inc.)
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2888384 2015-05-15] (Valve Corporation)
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Run: [uTorrent] => "C:\ProgramData\McAfee\VUL\AppsDownloaderPath\utorrent__utorrent__3.4.3.40097_3.4.3.40298_en-ph" /MINIMIZED
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Run: [Spotify Web Helper] => C:\Users\kinetz07\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2023480 2015-06-24] (Spotify Ltd)
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Run: [Spotify] => C:\Users\kinetz07\AppData\Roaming\Spotify\Spotify.exe [7415864 2015-06-24] (Spotify Ltd)
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7799576 2015-05-16] (SUPERAntiSpyware)
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Policies\Explorer: []
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1081224 2013-02-05] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2013-02-08] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2014-04-21] (Tonec Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-934835943-2712293172-1038266425-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://ph.yhs4.searc...p={searchTerms}
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://ph.yhs4.searc...p={searchTerms}
SearchScopes: HKU\S-1-5-21-934835943-2712293172-1038266425-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...q={searchTerms}
SearchScopes: HKU\S-1-5-21-934835943-2712293172-1038266425-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...q={searchTerms}
SearchScopes: HKU\S-1-5-21-934835943-2712293172-1038266425-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://ph.yhs4.searc...p={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2014-07-10] (Internet Download Manager, Tonec Inc.)
BHO: uunisalleS -> {882c9713-bb16-4cf6-9171-93c7545aaeb3} -> C:\Program Files (x86)\uunisalleS\NaX1zSt2xp08JW.x64.dll No File
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2014-07-10] (Internet Download Manager, Tonec Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-17] (Oracle Corporation)
BHO-x32: uunisalleS -> {882c9713-bb16-4cf6-9171-93c7545aaeb3} -> C:\Program Files (x86)\uunisalleS\NaX1zSt2xp08JW.dll No File
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-17] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.254.254
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-05-14] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-05-14] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-17] (Oracle Corporation)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [2015-01-16] ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-27] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF HKU\S-1-5-21-934835943-2712293172-1038266425-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\kinetz07\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\kinetz07\AppData\Roaming\IDM\idmmzcc5 [2015-01-14]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\kinetz07\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\kinetz07\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-11]
CHR Extension: (IDM Integration Module) - C:\Users\kinetz07\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2015-01-14]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\kinetz07\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-27]
CHR Extension: (Google Wallet) - C:\Users\kinetz07\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-27]
CHR HKLM-x32\...\Chrome\Extension: [fgbcffenncokfocljomejddmgcpppjom] - https://clients2.goo...ice/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-07-10]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-02-25] (Windows ® Win 7 DDK provider) [File not signed]
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.) [File not signed]
U2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-06-27] (Avast Software s.r.o.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2713856 2014-12-19] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032 2014-06-12] (Acer Incorporated)
S4 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-25] (WildTangent)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [466664 2014-06-10] (Acer Incorporate)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984 2014-06-26] (Acer Incorporate)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-03-11] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-06-26] (Acer Incorporate)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-03-12] (Razer Inc.)
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-04-17] (Advanced Micro Devices, Inc.)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [234240 2014-07-15] (acer)
R2 VSSS; C:\Users\kinetz07\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [101632704 2015-06-23] (Microsoft Corporation) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [92360 2015-01-20] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [264392 2015-01-20] (Advanced Micro Devices, Inc. )
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-12-20] (Advanced Micro Devices)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-25] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 BthMtpEnum; C:\Windows\system32\DRIVERS\BthMtpEnum.sys [62976 2013-08-22] (Microsoft Corporation)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80160 2015-02-13] (McAfee, Inc.)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [476888 2014-03-21] (Realsil Semiconductor Corporation)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-03-11] (Razer, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 SDGame; C:\Windows\System32\svchost.exe [38792 2014-10-29] (Microsoft Corporation)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]
R4 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-27 19:05 - 2015-06-27 19:06 - 00018498 _____ C:\Users\kinetz07\Downloads\FRST.txt
2015-06-27 19:04 - 2015-06-27 19:05 - 00000000 ____D C:\FRST
2015-06-27 19:04 - 2015-06-27 19:04 - 02112512 _____ (Farbar) C:\Users\kinetz07\Downloads\FRST64.exe
2015-06-27 17:31 - 2015-06-27 13:44 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\asw7DC3.tmp
2015-06-27 17:31 - 2015-06-27 13:44 - 00272248 _____ C:\Windows\system32\Drivers\asw7DF3.tmp
2015-06-27 17:31 - 2015-06-27 13:44 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\asw7F2C.tmp
2015-06-27 17:31 - 2015-06-27 13:44 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\asw7B9C.tmp
2015-06-27 17:31 - 2015-06-27 13:44 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\asw7D54.tmp
2015-06-27 17:31 - 2015-06-27 13:44 - 00065736 _____ C:\Windows\system32\Drivers\asw7D83.tmp
2015-06-27 17:31 - 2015-06-27 13:44 - 00029168 _____ C:\Windows\system32\Drivers\asw7D04.tmp
2015-06-27 17:31 - 2015-06-27 13:43 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\asw7B0E.tmp
2015-06-27 17:09 - 2015-06-27 13:44 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\asw339.tmp
2015-06-27 17:09 - 2015-06-27 13:44 - 00272248 _____ C:\Windows\system32\Drivers\asw34A.tmp
2015-06-27 17:09 - 2015-06-27 13:44 - 00137288 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\asw34B.tmp
2015-06-27 17:09 - 2015-06-27 13:44 - 00089944 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\asw2F9.tmp
2015-06-27 17:09 - 2015-06-27 13:44 - 00065736 _____ C:\Windows\system32\Drivers\asw2FA.tmp
2015-06-27 17:09 - 2015-06-27 13:44 - 00029168 _____ C:\Windows\system32\Drivers\asw2E8.tmp
2015-06-27 17:08 - 2015-06-27 13:44 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswFAB9.tmp
2015-06-27 17:08 - 2015-06-27 13:43 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswFAA9.tmp
2015-06-27 16:24 - 2015-06-27 16:59 - 00000530 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task d9c5f5e7-5748-4ab4-b0b7-c076810bde4f.job
2015-06-27 16:24 - 2015-06-27 16:59 - 00000530 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 16915d7c-42bf-4d4b-987e-8f54d058a8b7.job
2015-06-27 16:24 - 2015-06-27 16:24 - 00003586 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 16915d7c-42bf-4d4b-987e-8f54d058a8b7
2015-06-27 16:24 - 2015-06-27 16:24 - 00003504 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task d9c5f5e7-5748-4ab4-b0b7-c076810bde4f
2015-06-27 16:24 - 2015-06-27 16:24 - 00000000 ____D C:\Users\kinetz07\AppData\Roaming\SUPERAntiSpyware.com
2015-06-27 16:23 - 2015-06-27 16:24 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-06-27 16:23 - 2015-06-27 16:23 - 00001824 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-06-27 16:23 - 2015-06-27 16:23 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2015-06-27 16:23 - 2015-06-27 16:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-06-27 15:54 - 2015-06-27 15:54 - 00000000 ____D C:\Program Files\McAfee
2015-06-27 15:37 - 2015-06-27 15:37 - 01415680 _____ (wj32) C:\Program Files\Y02102RA.exe
2015-06-27 15:35 - 2015-06-27 15:35 - 00280992 _____ C:\Windows\Minidump\062715-18796-01.dmp
2015-06-27 15:29 - 2015-06-27 15:29 - 01415680 _____ (wj32) C:\Program Files\YUTSURJH.exe
2015-06-27 15:29 - 2015-06-27 15:29 - 01415680 _____ (wj32) C:\Program Files\K4FT4FTT.exe
2015-06-27 15:27 - 2015-06-27 15:28 - 00280992 _____ C:\Windows\Minidump\062715-21609-01.dmp
2015-06-27 15:24 - 2015-06-27 15:24 - 03219872 _____ (El Desaparecido - SosVirus.net - UsbFix.net) C:\Users\kinetz07\Downloads\UsbFix_2015_7.966.exe
2015-06-27 14:07 - 2015-06-27 14:07 - 00000000 ____D C:\Users\kinetz07\AppData\Roaming\AVAST Software
2015-06-27 13:51 - 2015-06-27 13:51 - 01415680 _____ (wj32) C:\Program Files\GEEC93TO.exe
2015-06-27 13:51 - 2015-06-27 13:51 - 01415680 _____ (wj32) C:\Program Files\AADA30XW.exe
2015-06-27 13:44 - 2015-06-27 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-06-27 13:43 - 2015-06-27 13:43 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-06-27 13:30 - 2015-06-27 13:30 - 00000000 ____D C:\Program Files\AVAST Software
2015-06-27 13:28 - 2015-06-27 13:28 - 00000000 ____D C:\ProgramData\AVAST Software
2015-06-27 13:27 - 2015-06-27 15:10 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-27 13:27 - 2015-06-27 13:27 - 00001118 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-27 13:27 - 2015-06-27 13:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-27 13:27 - 2015-06-27 13:27 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-27 13:27 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-27 13:27 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-27 13:27 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-27 13:10 - 2015-06-27 13:11 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\kinetz07\Downloads\mbam-setup-2.1.6.1022 (1).exe
2015-06-27 13:08 - 2015-06-27 13:08 - 05481344 _____ (Avast Software s.r.o.) C:\Users\kinetz07\Downloads\avast_free_antivirus_setup_online_softonic.exe
2015-06-27 12:59 - 2015-06-27 12:59 - 00000290 _____ C:\Windows\wininit.ini
2015-06-27 12:45 - 2015-06-27 12:45 - 00000000 ____D C:\KVRT_Data
2015-06-27 12:27 - 2015-06-27 12:27 - 01415680 _____ (wj32) C:\Program Files\9545475U.exe
2015-06-27 12:19 - 2015-06-27 12:19 - 01415680 _____ (wj32) C:\Program Files\EEBEHH9N.exe
2015-06-27 12:18 - 2015-06-27 12:18 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\kinetz07\Downloads\rkill.com
2015-06-27 12:18 - 2015-06-27 12:18 - 01063160 _____ (Bleeping Computer, LLC) C:\Users\kinetz07\Downloads\rkill64.com
2015-06-27 12:18 - 2015-06-27 12:18 - 00000950 _____ C:\Users\kinetz07\Desktop\Rkill.txt
2015-06-27 11:28 - 2015-06-27 11:28 - 01415680 _____ (wj32) C:\Program Files\HHCB84YE.exe
2015-06-27 11:28 - 2015-06-27 11:28 - 01415680 _____ (wj32) C:\Program Files\B850WKKE.exe
2015-06-27 10:41 - 2015-06-27 10:41 - 01415680 _____ (wj32) C:\Program Files\A633369F.exe
2015-06-27 10:39 - 2015-06-27 10:39 - 01415680 _____ (wj32) C:\Program Files\MLKJFCBA.exe
2015-06-27 10:05 - 2015-06-27 10:05 - 01415680 _____ (wj32) C:\Program Files\IHDC8OKH.exe
2015-06-27 00:22 - 2015-06-27 00:22 - 01415680 _____ (wj32) C:\Program Files\9LYDMTVC.exe
2015-06-27 00:20 - 2015-06-27 00:20 - 01415680 _____ (wj32) C:\Program Files\KJIHGCBD.exe
2015-06-27 00:20 - 2015-06-27 00:20 - 01415680 _____ (wj32) C:\Program Files\JCEEB9B5.exe
2015-06-27 00:20 - 2015-06-27 00:20 - 01415680 _____ (wj32) C:\Program Files\8376A7BZ.exe
2015-06-27 00:20 - 2015-06-27 00:20 - 01415680 _____ (wj32) C:\Program Files\6246899Y.exe
2015-06-26 16:45 - 2015-06-26 16:45 - 01415680 _____ (wj32) C:\Program Files\TWKJMMKU.exe
2015-06-26 16:45 - 2015-06-26 16:45 - 01415680 _____ (wj32) C:\Program Files\SUWVWY0S.exe
2015-06-26 13:57 - 2012-02-10 20:09 - 02704896 _____ C:\Users\kinetz07\Desktop\TWO-STOREY.xls
2015-06-26 13:20 - 2015-06-26 13:20 - 01415680 _____ (wj32) C:\Program Files\VUUWWXZH.exe
2015-06-26 11:31 - 2015-06-27 00:10 - 00000000 ____D C:\VIPRERESCUE
2015-06-26 11:31 - 2013-09-04 14:57 - 00031264 _____ (ThreatTrack Security) C:\Windows\system32\Drivers\gfiutil.sys
2015-06-26 11:31 - 2013-05-23 08:39 - 00041032 _____ (ThreatTrack Security) C:\Windows\system32\Drivers\gfiark.sys
2015-06-26 11:12 - 2015-06-26 11:16 - 04755113 _____ C:\Users\kinetz07\Downloads\AlangAlang (1).xlsm
2015-06-26 11:09 - 2015-06-26 16:43 - 04764947 _____ C:\Users\kinetz07\Downloads\AlangAlang.xlsm
2015-06-26 11:08 - 2015-06-26 11:12 - 06240460 _____ C:\Users\kinetz07\Downloads\2-Storey-Elementary-School.xlsm
2015-06-26 11:07 - 2015-06-26 11:15 - 03504792 _____ C:\Users\kinetz07\Downloads\1-Story-Warehouse.xlsm
2015-06-26 10:39 - 2015-06-26 10:39 - 01415680 _____ (wj32) C:\Program Files\PRMFHCEB.exe
2015-06-26 10:24 - 2015-06-26 10:24 - 01415680 _____ (wj32) C:\Program Files\WYUWSUSO.exe
2015-06-26 10:23 - 2015-06-26 10:23 - 01415680 _____ (wj32) C:\Program Files\SLIF6FNI.exe
2015-06-26 10:23 - 2015-06-26 10:23 - 01415680 _____ (wj32) C:\Program Files\475430XJ.exe
2015-06-26 10:20 - 2015-06-26 10:20 - 01415680 _____ (wj32) C:\Program Files\WFY9R8K0.exe
2015-06-26 10:20 - 2015-06-26 10:20 - 01415680 _____ (wj32) C:\Program Files\LORSVTKV.exe
2015-06-26 10:20 - 2015-06-26 10:20 - 01415680 _____ (wj32) C:\Program Files\8A7979IF.exe
2015-06-25 16:19 - 2015-06-25 16:19 - 01415680 _____ (wj32) C:\Program Files\PRLNIKID.exe
2015-06-25 16:19 - 2015-06-25 16:19 - 01415680 _____ (wj32) C:\Program Files\N2KZHYH0.exe
2015-06-25 11:48 - 2015-06-25 11:52 - 00000000 ____D C:\Users\kinetz07\Desktop\USAID
2015-06-25 11:09 - 2014-10-17 11:53 - 00000000 ____D C:\Users\kinetz07\Desktop\RETROFIT DESIGN REPORT
2015-06-25 10:08 - 2015-06-25 10:08 - 01415680 _____ (wj32) C:\Program Files\YVRUUROJ.exe
2015-06-25 10:08 - 2015-06-25 10:08 - 01415680 _____ (wj32) C:\Program Files\HKNKNKS3.exe
2015-06-25 10:08 - 2015-06-25 10:08 - 01415680 _____ (wj32) C:\Program Files\7995022V.exe
2015-06-25 10:08 - 2015-06-25 10:08 - 01415680 _____ (wj32) C:\Program Files\25889AC8.exe
2015-06-24 18:11 - 2015-06-24 18:11 - 01415680 _____ (wj32) C:\Program Files\VUWVXFUR.exe
2015-06-24 18:10 - 2015-06-24 18:10 - 01415680 _____ (wj32) C:\Program Files\I1K1CVDA.exe
2015-06-24 18:10 - 2015-06-24 18:10 - 01415680 _____ (wj32) C:\Program Files\35XRKA09.exe
2015-06-24 17:07 - 2015-06-24 16:57 - 19846640 _____ C:\Users\kinetz07\Desktop\Sagkahan Elementary School.zip
2015-06-24 14:30 - 2015-06-27 19:03 - 00000000 ____D C:\Users\kinetz07\AppData\Local\Spotify
2015-06-24 14:30 - 2015-06-24 14:30 - 00001868 _____ C:\Users\kinetz07\Desktop\Spotify.lnk
2015-06-24 14:30 - 2015-06-24 14:30 - 00001854 _____ C:\Users\kinetz07\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-06-24 14:26 - 2015-06-27 19:03 - 00000000 ____D C:\Users\kinetz07\AppData\Roaming\Spotify
2015-06-24 14:25 - 2015-06-24 14:25 - 00155296 _____ (Spotify Ltd) C:\Users\kinetz07\Downloads\SpotifySetup.exe
2015-06-24 13:56 - 2015-06-24 13:56 - 01415680 _____ (wj32) C:\Program Files\TMIET5FC.exe
2015-06-24 13:56 - 2015-06-24 13:56 - 01415680 _____ (wj32) C:\Program Files\51YS6IUH.exe
2015-06-24 13:29 - 2015-06-24 13:29 - 01415680 _____ (wj32) C:\Program Files\5213212B.exe
2015-06-24 13:26 - 2015-06-24 13:26 - 01415680 _____ (wj32) C:\Program Files\A8CA53YY.exe
2015-06-24 10:03 - 2015-06-24 10:03 - 01415680 _____ (wj32) C:\Program Files\UXX0Z24X.exe
2015-06-24 10:03 - 2015-06-24 10:03 - 01415680 _____ (wj32) C:\Program Files\EHEFIIH8.exe
2015-06-23 21:21 - 2015-06-23 21:21 - 01415680 _____ (wj32) C:\Program Files\VXTVTVTM.exe
2015-06-23 21:21 - 2015-06-23 21:21 - 01415680 _____ (wj32) C:\Program Files\VWXVWRL5.exe
2015-06-23 16:00 - 2015-06-23 16:00 - 01415680 _____ (wj32) C:\Program Files\LNMONMIA.exe
2015-06-23 16:00 - 2015-06-23 16:00 - 01415680 _____ (wj32) C:\Program Files\GIKMFHIX.exe
2015-06-23 15:59 - 2015-06-23 15:59 - 01415680 _____ (wj32) C:\Program Files\8T2N2N7G.exe
2015-06-23 14:16 - 2014-04-09 02:00 - 01531822 _____ C:\Users\kinetz07\Desktop\2.0 Coping Design.xlsx
2015-06-18 13:36 - 2015-06-18 13:36 - 01381357 _____ C:\Users\kinetz07\Downloads\FRP-Beam-Retrofit-Bm-486.xlsx
2015-06-18 13:33 - 2015-06-18 13:34 - 05874851 _____ C:\Users\kinetz07\Downloads\2-Storey-Elementary-School-Autosaved.xlsm
2015-06-16 22:19 - 2015-06-27 19:02 - 00003496 _____ C:\Windows\System32\Tasks\gg_uac_daemon_kinetz07
2015-06-16 10:20 - 2015-06-26 13:57 - 00002274 _____ C:\Users\kinetz07\Documents\ipmsg.log
2015-06-16 10:19 - 2015-06-16 10:19 - 00000000 ____D C:\Program Files\IPMsg
2015-06-16 10:18 - 2015-06-16 10:18 - 00514177 _____ C:\Users\kinetz07\Downloads\ipmsg350_installer64.zip
2015-06-12 22:57 - 2015-05-27 22:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-12 22:57 - 2015-05-27 22:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-12 22:57 - 2015-05-23 11:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-12 22:57 - 2015-05-23 11:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-12 22:57 - 2015-05-23 11:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-12 22:57 - 2015-05-23 11:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-12 22:57 - 2015-05-23 11:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-12 22:57 - 2015-05-23 10:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-12 22:57 - 2015-05-23 10:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-12 22:57 - 2015-05-23 10:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-12 22:57 - 2015-05-23 10:47 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-06-12 22:57 - 2015-05-23 10:43 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-06-12 22:57 - 2015-05-23 10:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-12 22:57 - 2015-05-23 10:38 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-12 22:57 - 2015-05-23 10:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-12 22:57 - 2015-05-23 10:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-12 22:57 - 2015-05-23 10:28 - 01042944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-06-12 22:57 - 2015-05-23 10:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-12 22:57 - 2015-05-23 10:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-12 22:57 - 2015-05-23 10:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-12 22:57 - 2015-05-23 03:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-12 22:57 - 2015-05-23 03:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-12 22:57 - 2015-05-23 03:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-12 22:57 - 2015-05-23 02:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-12 22:57 - 2015-05-23 02:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-12 22:57 - 2015-05-23 02:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-12 22:57 - 2015-05-23 02:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-12 22:57 - 2015-05-23 02:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-12 22:57 - 2015-05-23 02:23 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-06-12 22:57 - 2015-05-23 02:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-12 22:57 - 2015-05-23 02:15 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-06-12 22:57 - 2015-05-23 02:09 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-06-12 22:57 - 2015-05-23 02:08 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-12 22:57 - 2015-05-23 02:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-12 22:57 - 2015-05-23 02:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-12 22:57 - 2015-05-23 01:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-12 22:57 - 2015-05-23 01:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-12 22:57 - 2015-05-23 01:49 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-06-12 22:57 - 2015-05-23 01:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-12 22:57 - 2015-05-23 01:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-12 22:53 - 2015-05-22 00:47 - 04177920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-12 22:53 - 2015-04-25 10:34 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-12 22:53 - 2015-04-25 10:33 - 00549888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-12 16:36 - 2015-06-12 16:36 - 00014821 _____ C:\Users\kinetz07\Desktop\DTR MAY 25, - JUNE 11, 2015.xlsx
2015-06-11 11:24 - 2015-06-11 11:24 - 00087181 _____ C:\Users\kinetz07\Downloads\equake.xlsx
2015-06-08 12:17 - 2015-06-08 12:17 - 00000512 _____ C:\Users\kinetz07\Downloads\SAGKAHAN.slg
2015-06-08 12:17 - 2015-06-08 12:17 - 00000004 _____ C:\Users\kinetz07\Downloads\SAGKAHAN.cut
2015-06-08 11:58 - 2015-06-08 12:17 - 00043974 _____ C:\Users\kinetz07\Downloads\SAGKAHAN.UID
2015-06-08 11:58 - 2015-06-08 11:58 - 00004909 _____ C:\Users\kinetz07\Downloads\SAGKAHAN.dbi
2015-06-08 11:58 - 2015-06-08 11:58 - 00000083 _____ C:\Users\kinetz07\Downloads\SAGKAHAN.cod
2015-06-08 11:55 - 2015-06-08 11:55 - 00013900 _____ C:\Users\kinetz07\Downloads\SAGKAHAN.std
2015-06-08 00:14 - 2015-06-08 00:14 - 04047480 _____ C:\Users\kinetz07\Downloads\11188324_1656553871242227_4288093763310382384_n.psd
2015-06-05 13:40 - 2015-06-05 13:40 - 00578688 _____ C:\Users\kinetz07\Downloads\truss.dwg
2015-06-05 13:15 - 2015-06-05 13:15 - 01926316 _____ C:\Users\kinetz07\Downloads\TRUSS.rar
2015-06-04 11:38 - 2015-06-04 11:38 - 00737753 _____ C:\Users\kinetz07\Downloads\PASAC-CULCUL-2-edited (1).dwg
2015-06-04 10:12 - 2015-06-04 10:13 - 01136448 _____ C:\Users\kinetz07\Downloads\PASAC-CULCUL-2-edited.dwg
2015-06-01 16:09 - 2015-06-01 16:09 - 00000000 ____D C:\Users\kinetz07\AppData\Local\GWX
2015-06-01 11:48 - 2015-06-01 11:48 - 00030936 _____ C:\Users\kinetz07\Downloads\sadas.xlsx
2015-05-30 08:46 - 2015-05-30 08:46 - 00000000 ____D C:\Users\kinetz07\AppData\Roaming\ATI
2015-05-30 08:46 - 2015-05-30 08:46 - 00000000 ____D C:\Users\kinetz07\AppData\Local\ATI
2015-05-30 08:46 - 2015-05-30 08:46 - 00000000 ____D C:\ProgramData\ATI
2015-05-28 20:21 - 2015-05-28 20:21 - 00041472 _____ C:\Users\kinetz07\Downloads\Rampage 2015 Online Ticket Order Form.xls
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-27 19:06 - 2015-01-14 17:53 - 00000000 ____D C:\Users\kinetz07\AppData\Roaming\GarenaPlus
2015-06-27 19:06 - 2015-01-14 17:52 - 00000000 ____D C:\ProgramData\GarenaMessenger
2015-06-27 19:02 - 2015-01-11 21:12 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-27 19:01 - 2015-02-07 08:29 - 00001362 _____ C:\Windows\Tasks\NONUI.job
2015-06-27 19:01 - 2013-08-22 23:36 - 00000000 ____D C:\Windows\system32\sru
2015-06-27 18:23 - 2015-01-11 21:12 - 00000920 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-27 17:15 - 2015-01-11 21:00 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-934835943-2712293172-1038266425-1001
2015-06-27 17:00 - 2014-09-03 05:04 - 02224878 _____ C:\Windows\SysWOW64\rootpa.e2e
2015-06-27 16:59 - 2014-07-26 14:09 - 00000000 ____D C:\ProgramData\McAfee
2015-06-27 16:59 - 2013-08-22 22:46 - 00056398 _____ C:\Windows\setupact.log
2015-06-27 16:59 - 2013-08-22 22:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-27 16:58 - 2015-01-12 13:58 - 00000000 ____D C:\Users\kinetz07\AppData\Roaming\DMCache
2015-06-27 16:58 - 2015-01-11 20:53 - 00000000 ____D C:\Users\kinetz07
2015-06-27 16:58 - 2014-09-03 05:48 - 01854675 _____ C:\Windows\WindowsUpdate.log
2015-06-27 16:19 - 2015-05-04 09:10 - 00000000 ____D C:\Users\kinetz07\Desktop\Misc
2015-06-27 16:13 - 2015-01-11 21:06 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{0D196690-4AE7-4B0F-B2C9-9517BE789CD6}
2015-06-27 15:56 - 2013-08-22 23:36 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-27 15:35 - 2015-05-12 16:41 - 511887582 _____ C:\Windows\MEMORY.DMP
2015-06-27 15:35 - 2015-05-12 16:41 - 00000000 ____D C:\Windows\Minidump
2015-06-27 15:21 - 2013-08-22 23:36 - 00000000 ____D C:\Windows\AppReadiness
2015-06-27 15:06 - 2014-03-18 17:44 - 00158226 _____ C:\Windows\PFRO.log
2015-06-27 13:02 - 2015-03-13 18:19 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-06-27 12:59 - 2013-08-22 23:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2015-06-27 12:59 - 2013-08-22 21:25 - 00262144 ___SH C:\Windows\system32\config\ELAM
2015-06-27 11:32 - 2014-03-18 17:53 - 00863592 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-27 02:44 - 2013-08-22 23:36 - 00000000 ____D C:\Windows\rescache
2015-06-27 02:18 - 2015-01-11 21:12 - 00003892 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-06-27 02:18 - 2015-01-11 21:12 - 00003656 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-06-27 00:21 - 2013-08-22 21:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-06-26 13:35 - 2015-04-10 17:02 - 00000219 _____ C:\Windows\SysWOW64\lsprst7.tgz
2015-06-26 13:35 - 2015-04-10 17:02 - 00000205 _____ C:\Windows\SysWOW64\lsprst7.dll
2015-06-26 13:35 - 2015-04-10 17:02 - 00000087 _____ C:\Windows\SysWOW64\ssprs.tgz
2015-06-26 13:35 - 2014-07-26 13:46 - 00000073 _____ C:\Windows\SysWOW64\ssprs.dll
2015-06-26 10:36 - 2013-08-22 22:44 - 00567144 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-26 10:28 - 2013-08-22 23:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-22 12:55 - 2015-05-02 18:45 - 00000000 ____D C:\Users\kinetz07\Desktop\Work
2015-06-20 12:15 - 2015-01-14 17:52 - 00000000 ____D C:\Program Files (x86)\Garena Plus
2015-06-19 14:45 - 2015-04-02 21:14 - 00000000 ____D C:\Users\kinetz07\AppData\Roaming\uTorrent
2015-06-19 14:42 - 2015-01-11 21:52 - 00000000 ____D C:\Users\kinetz07\AppData\Local\CrashDumps
2015-06-18 16:29 - 2013-08-22 23:36 - 00000000 ____D C:\Windows\system32\NDF
2015-06-16 10:52 - 2015-05-12 16:38 - 00000514 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2015-06-14 16:18 - 2013-08-22 23:36 - 00000000 ____D C:\Windows\LiveKernelReports
2015-06-12 23:10 - 2015-01-15 00:13 - 00000000 ____D C:\Windows\system32\MRT
2015-06-12 23:00 - 2015-01-15 00:13 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-12 23:00 - 2013-08-22 23:20 - 00000000 ____D C:\Windows\CbsTemp
2015-06-12 16:41 - 2015-01-14 18:58 - 00000000 ____D C:\Users\kinetz07\Documents\Bluetooth Folder
2015-06-08 11:19 - 2015-01-27 19:57 - 00765440 ___SH C:\Users\kinetz07\Desktop\Thumbs.db
2015-06-08 00:11 - 2015-01-12 21:30 - 01276416 ___SH C:\Users\kinetz07\Downloads\Thumbs.db
2015-06-08 00:09 - 2015-01-11 20:54 - 00000000 ____D C:\Users\kinetz07\AppData\Roaming\Adobe
2015-06-04 00:18 - 2015-05-13 17:42 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-04 00:18 - 2015-05-13 17:42 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-03 12:02 - 2015-01-12 13:58 - 00000000 ____D C:\Users\kinetz07\Downloads\Compressed
2015-05-28 21:56 - 2015-04-06 12:05 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-05-28 21:56 - 2015-04-06 12:05 - 00000000 ___SD C:\Windows\system32\GWX
==================== Files in the root of some directories =======
2015-06-25 10:08 - 2015-06-25 10:08 - 1415680 _____ (wj32) C:\Program Files\25889AC8.exe
2015-06-24 18:10 - 2015-06-24 18:10 - 1415680 _____ (wj32) C:\Program Files\35XRKA09.exe
2015-06-26 10:23 - 2015-06-26 10:23 - 1415680 _____ (wj32) C:\Program Files\475430XJ.exe
2015-06-24 13:56 - 2015-06-24 13:56 - 1415680 _____ (wj32) C:\Program Files\51YS6IUH.exe
2015-06-24 13:29 - 2015-06-24 13:29 - 1415680 _____ (wj32) C:\Program Files\5213212B.exe
2015-06-27 00:20 - 2015-06-27 00:20 - 1415680 _____ (wj32) C:\Program Files\6246899Y.exe
2015-06-25 10:08 - 2015-06-25 10:08 - 1415680 _____ (wj32) C:\Program Files\7995022V.exe
2015-06-27 00:20 - 2015-06-27 00:20 - 1415680 _____ (wj32) C:\Program Files\8376A7BZ.exe
2015-06-26 10:20 - 2015-06-26 10:20 - 1415680 _____ (wj32) C:\Program Files\8A7979IF.exe
2015-06-23 15:59 - 2015-06-23 15:59 - 1415680 _____ (wj32) C:\Program Files\8T2N2N7G.exe
2015-06-27 12:27 - 2015-06-27 12:27 - 1415680 _____ (wj32) C:\Program Files\9545475U.exe
2015-06-27 00:22 - 2015-06-27 00:22 - 1415680 _____ (wj32) C:\Program Files\9LYDMTVC.exe
2015-06-27 10:41 - 2015-06-27 10:41 - 1415680 _____ (wj32) C:\Program Files\A633369F.exe
2015-06-24 13:26 - 2015-06-24 13:26 - 1415680 _____ (wj32) C:\Program Files\A8CA53YY.exe
2015-06-27 13:51 - 2015-06-27 13:51 - 1415680 _____ (wj32) C:\Program Files\AADA30XW.exe
2015-06-27 11:28 - 2015-06-27 11:28 - 1415680 _____ (wj32) C:\Program Files\B850WKKE.exe
2015-06-27 12:19 - 2015-06-27 12:19 - 1415680 _____ (wj32) C:\Program Files\EEBEHH9N.exe
2015-06-24 10:03 - 2015-06-24 10:03 - 1415680 _____ (wj32) C:\Program Files\EHEFIIH8.exe
2015-06-27 13:51 - 2015-06-27 13:51 - 1415680 _____ (wj32) C:\Program Files\GEEC93TO.exe
2015-06-23 16:00 - 2015-06-23 16:00 - 1415680 _____ (wj32) C:\Program Files\GIKMFHIX.exe
2015-06-27 11:28 - 2015-06-27 11:28 - 1415680 _____ (wj32) C:\Program Files\HHCB84YE.exe
2015-06-25 10:08 - 2015-06-25 10:08 - 1415680 _____ (wj32) C:\Program Files\HKNKNKS3.exe
2015-06-24 18:10 - 2015-06-24 18:10 - 1415680 _____ (wj32) C:\Program Files\I1K1CVDA.exe
2015-06-27 10:05 - 2015-06-27 10:05 - 1415680 _____ (wj32) C:\Program Files\IHDC8OKH.exe
2015-06-27 00:20 - 2015-06-27 00:20 - 1415680 _____ (wj32) C:\Program Files\JCEEB9B5.exe
2015-06-27 15:29 - 2015-06-27 15:29 - 1415680 _____ (wj32) C:\Program Files\K4FT4FTT.exe
2015-06-27 00:20 - 2015-06-27 00:20 - 1415680 _____ (wj32) C:\Program Files\KJIHGCBD.exe
2015-06-23 16:00 - 2015-06-23 16:00 - 1415680 _____ (wj32) C:\Program Files\LNMONMIA.exe
2015-06-26 10:20 - 2015-06-26 10:20 - 1415680 _____ (wj32) C:\Program Files\LORSVTKV.exe
2015-06-27 10:39 - 2015-06-27 10:39 - 1415680 _____ (wj32) C:\Program Files\MLKJFCBA.exe
2015-06-25 16:19 - 2015-06-25 16:19 - 1415680 _____ (wj32) C:\Program Files\N2KZHYH0.exe
2015-06-25 16:19 - 2015-06-25 16:19 - 1415680 _____ (wj32) C:\Program Files\PRLNIKID.exe
2015-06-26 10:39 - 2015-06-26 10:39 - 1415680 _____ (wj32) C:\Program Files\PRMFHCEB.exe
2015-06-26 10:23 - 2015-06-26 10:23 - 1415680 _____ (wj32) C:\Program Files\SLIF6FNI.exe
2015-06-26 16:45 - 2015-06-26 16:45 - 1415680 _____ (wj32) C:\Program Files\SUWVWY0S.exe
2015-06-24 13:56 - 2015-06-24 13:56 - 1415680 _____ (wj32) C:\Program Files\TMIET5FC.exe
2015-06-26 16:45 - 2015-06-26 16:45 - 1415680 _____ (wj32) C:\Program Files\TWKJMMKU.exe
2015-06-24 10:03 - 2015-06-24 10:03 - 1415680 _____ (wj32) C:\Program Files\UXX0Z24X.exe
2015-06-26 13:20 - 2015-06-26 13:20 - 1415680 _____ (wj32) C:\Program Files\VUUWWXZH.exe
2015-06-24 18:11 - 2015-06-24 18:11 - 1415680 _____ (wj32) C:\Program Files\VUWVXFUR.exe
2015-06-23 21:21 - 2015-06-23 21:21 - 1415680 _____ (wj32) C:\Program Files\VWXVWRL5.exe
2015-06-23 21:21 - 2015-06-23 21:21 - 1415680 _____ (wj32) C:\Program Files\VXTVTVTM.exe
2015-06-26 10:20 - 2015-06-26 10:20 - 1415680 _____ (wj32) C:\Program Files\WFY9R8K0.exe
2015-06-26 10:24 - 2015-06-26 10:24 - 1415680 _____ (wj32) C:\Program Files\WYUWSUSO.exe
2015-06-27 15:37 - 2015-06-27 15:37 - 1415680 _____ (wj32) C:\Program Files\Y02102RA.exe
2015-06-27 15:29 - 2015-06-27 15:29 - 1415680 _____ (wj32) C:\Program Files\YUTSURJH.exe
2015-06-25 10:08 - 2015-06-25 10:08 - 1415680 _____ (wj32) C:\Program Files\YVRUUROJ.exe
2015-01-26 00:12 - 2015-02-08 12:08 - 0000365 _____ () C:\Users\kinetz07\AppData\Roaming\NONUI
2015-02-07 08:29 - 2015-02-07 08:29 - 1829848 _____ () C:\Users\kinetz07\AppData\Roaming\NONUI.exe
2014-09-03 05:01 - 2014-09-03 05:01 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-01-24 13:31 - 2015-01-24 13:31 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2015-03-20 21:10 - 2014-10-29 09:52 - 75362304 ___SH () C:\ProgramData\msvez.exe
Files to move or delete:
====================
C:\ProgramData\msvez.exe
Some files in TEMP:
====================
C:\Users\kinetz07\AppData\Local\Temp\0212751435391706mcinst.exe
C:\Users\kinetz07\AppData\Local\Temp\cdo11314704.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo2235670817.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo2965539735.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo3392616369.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo4054691146.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo482320495.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo563211069.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo725037336.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo728608456.dll
C:\Users\kinetz07\AppData\Local\Temp\cdo89642314.dll
C:\Users\kinetz07\AppData\Local\Temp\Foxit PhantomPDF Updater.exe
C:\Users\kinetz07\AppData\Local\Temp\McCSPInstall.dll
C:\Users\kinetz07\AppData\Local\Temp\mccspuninstall.exe
C:\Users\kinetz07\AppData\Local\Temp\msvcp120.dll
C:\Users\kinetz07\AppData\Local\Temp\msvcr120.dll
C:\Users\kinetz07\AppData\Local\Temp\PH_150505to150519.exe
C:\Users\kinetz07\AppData\Local\Temp\PH_150519to150521.exe
C:\Users\kinetz07\AppData\Local\Temp\PH_150521to150602.exe
C:\Users\kinetz07\AppData\Local\Temp\PH_150602to150616.exe
C:\Users\kinetz07\AppData\Local\Temp\SRLDetectionLibrary1527105708258274435.dll
C:\Users\kinetz07\AppData\Local\Temp\SRLDetectionLibrary6136515311748987566.dll
C:\Users\kinetz07\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-27 02:27
==================== End of log ============================