Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by coldharbor1950 (administrator) on ICELAND on 22-03-2014 20:33:23
Running from C:\Users\coldharbor1950\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
() C:\Program Files (x86)\NETGEAR\WNA3100\WNA3100.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\GCalService.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Calendar\Service\HPTouchSmartSyncCalReminderApp.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
(Microsoft Corporation) C:\Windows\system32\UI0Detect.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [hpsysdrv] - c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2014-02-19] (Realtek Semiconductor)
HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-12] (PDF Complete Inc)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-10-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-387024861-1857405023-142887614-1000\...\Run: [RoboForm] - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [109784 2014-03-15] (Siber Systems)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {4F1149B4-DD36-468D-A3A7-B9D541595DEF} URL = http://www.amazon.co...s={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...w={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...w={searchTerms}
SearchScopes: HKCU - DefaultScope {71DB2072-787A-4596-A0E5-2E1030999197} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKCU - {71DB2072-787A-4596-A0E5-2E1030999197} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...w={searchTerms}
BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: RoboForm Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO-x32: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: RoboForm Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll No File
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (Siber Systems Inc.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=15.0.6.14 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.6.14 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.6.14 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=15.0.6.14 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2012-11-25]
Chrome:
=======
CHR HomePage: https://www.google.c...r/render?tab=Xc
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.2.464\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
CHR Plugin: (RealNetworks Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (Bejeweled) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm [2014-03-19]
CHR Extension: (Google Docs) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-19]
CHR Extension: (Google Drive) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-19]
CHR Extension: (YouTube) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-19]
CHR Extension: (Google Search) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-19]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2014-03-19]
CHR Extension: (Pin It Button) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2014-03-19]
CHR Extension: (Social Fixer for Facebook) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2014-03-19]
CHR Extension: (Office Apps) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdbcdbdkiaadpbkggggekjcpmgjekkke [2014-03-19]
CHR Extension: (Google Mail Checker) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-03-19]
CHR Extension: (Crosswords) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\namaaebnjgplgpilcfdllaonknandpjf [2014-03-19]
CHR Extension: (Google Wallet) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-19]
CHR Extension: (Gmail) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-19]
CHR Extension: (RoboForm) - C:\Users\coldharbor1950\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2014-03-19]
CHR HKCU\...\Chrome\Extension: [dmkpdpkjmmdacleogmmlinafnhdfdlmp] - C:\Users\coldharbor1950\AppData\Local\CRE\dmkpdpkjmmdacleogmmlinafnhdfdlmp.crx [2014-03-19]
CHR HKCU\...\Chrome\Extension: [eijoglodfkeicibboibphapnoahoaapi] - C:\Users\coldharbor1950\AppData\Local\CRE\eijoglodfkeicibboibphapnoahoaapi.crx [2014-03-19]
CHR HKLM-x32\...\Chrome\Extension: [dmkpdpkjmmdacleogmmlinafnhdfdlmp] - C:\Users\coldharbor1950\AppData\Local\CRE\dmkpdpkjmmdacleogmmlinafnhdfdlmp.crx [2014-03-19]
CHR HKLM-x32\...\Chrome\Extension: [eijoglodfkeicibboibphapnoahoaapi] - C:\Users\coldharbor1950\AppData\Local\CRE\eijoglodfkeicibboibphapnoahoaapi.crx [2014-03-19]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\PROGRA~1\AVASTS~1\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-03-19]
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2014-03-19]
CHR HKLM-x32\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-02-14]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-10-08] (Advanced Micro Devices, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-15] (McAfee, Inc.)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-12] (PDF Complete Inc)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-02-19] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 WSWNA3100; C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [303360 2011-12-07] ()
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 NPF; C:\Windows\System32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc.)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2013-12-17] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-22 20:31 - 2014-03-22 20:32 - 00047232 _____ () C:\Users\coldharbor1950\Desktop\Addition.txt
2014-03-22 20:27 - 2014-03-22 20:27 - 02157056 _____ (Farbar) C:\Users\coldharbor1950\Desktop\FRST64.exe
2014-03-22 20:06 - 2014-03-22 20:06 - 00602112 _____ (OldTimer Tools) C:\Users\coldharbor1950\Downloads\OTL.exe
2014-03-22 18:54 - 2014-03-22 18:54 - 00987448 _____ () C:\Users\coldharbor1950\Desktop\SecurityCheck.exe
2014-03-22 15:12 - 2014-03-22 15:12 - 00333712 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-22 15:12 - 2014-03-22 15:12 - 00000056 _____ () C:\Windows\setupact.log
2014-03-22 15:12 - 2014-03-22 15:12 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-21 12:55 - 2014-03-21 12:55 - 00000446 _____ () C:\Users\coldharbor1950\Documents\0321 Response.txt
2014-03-21 07:53 - 2014-03-21 07:53 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-20 10:43 - 2014-03-22 20:33 - 00020330 _____ () C:\Users\coldharbor1950\Desktop\FRST.txt
2014-03-19 15:03 - 2014-03-19 15:03 - 00002217 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-19 14:31 - 2014-03-19 14:31 - 00000000 ____D () C:\TDSSKiller_Quarantine
2014-03-19 14:24 - 2014-03-22 20:22 - 00121102 _____ () C:\Windows\WindowsUpdate.log
2014-03-19 14:14 - 2014-03-19 14:14 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\coldharbor1950\Downloads\tdsskiller.exe
2014-03-19 13:56 - 2014-03-19 13:56 - 00407789 _____ () C:\Users\coldharbor1950\Downloads\TDSS.htm
2014-03-19 13:35 - 2014-03-19 13:35 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\coldharbor1950\Desktop\tdsskiller.exe
2014-03-19 11:32 - 2014-03-19 11:32 - 00053843 _____ () C:\Users\coldharbor1950\Documents\bookmarks_3_19_14.html
2014-03-19 10:15 - 2014-03-19 11:27 - 00424787 _____ () C:\Users\coldharbor1950\Downloads\avgremover.log
2014-03-19 10:14 - 2014-03-19 10:14 - 03386520 _____ (AVG Technologies CZ, s.r.o.) C:\Users\coldharbor1950\Downloads\avg_remover_stf_x64_2014_4116.exe
2014-03-18 20:28 - 2014-03-18 20:28 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-03-18 17:23 - 2014-03-18 17:23 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-03-18 15:26 - 2014-03-18 15:26 - 00000000 ____D () C:\ProgramData\Google
2014-03-18 15:26 - 2014-03-18 15:26 - 00000000 ____D () C:\Program Files\Google
2014-03-18 14:53 - 2014-03-18 15:00 - 00000000 ____D () C:\Users\coldharbor1950\Desktop\RK_Quarantine
2014-03-18 14:50 - 2014-03-18 14:50 - 03901952 _____ () C:\Users\coldharbor1950\Desktop\RogueKiller.exe
2014-03-18 14:21 - 2014-03-18 14:21 - 01037734 _____ (Thisisu) C:\Users\coldharbor1950\Downloads\JRT.exe
2014-03-18 14:21 - 2014-03-18 14:21 - 00001157 _____ () C:\Users\coldharbor1950\Desktop\JRT - Shortcut.lnk
2014-03-18 14:09 - 2014-03-18 14:09 - 01950720 _____ () C:\Users\coldharbor1950\Downloads\AdwCleaner.exe
2014-03-18 14:09 - 2014-03-18 14:09 - 00001230 _____ () C:\Users\coldharbor1950\Desktop\AdwCleaner - Shortcut.lnk
2014-03-18 14:01 - 2014-03-22 20:25 - 00000000 ____D () C:\Users\coldharbor1950\Desktop\0318 Comp Repair
2014-03-18 13:55 - 2014-03-18 13:55 - 00000000 ____D () C:\_OTL
2014-03-18 12:36 - 2014-03-18 12:36 - 00005633 _____ () C:\Users\coldharbor1950\Documents\CompFix 031814.txt
2014-03-18 10:42 - 2014-03-18 10:42 - 00156902 _____ () C:\Users\coldharbor1950\Downloads\OTL 0318 Safe Mode.txt
2014-03-18 10:01 - 2014-03-18 10:01 - 00000382 _____ () C:\Users\coldharbor1950\Documents\cc_20140318_100102.reg
2014-03-18 08:41 - 2014-03-18 08:41 - 00160168 _____ () C:\Users\coldharbor1950\Downloads\OTL 0318.txt
2014-03-18 08:13 - 2014-03-18 08:13 - 00602112 _____ (OldTimer Tools) C:\Users\coldharbor1950\Downloads\OTL (1).com
2014-03-18 08:09 - 2014-03-18 08:09 - 00602112 _____ (OldTimer Tools) C:\Users\coldharbor1950\Desktop\OTL.com
2014-03-17 09:59 - 2014-03-17 09:59 - 00001341 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-03-17 09:44 - 2014-03-18 10:21 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster
2014-03-17 09:44 - 2014-03-17 09:44 - 00001041 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk
2014-03-17 09:44 - 2014-03-17 09:44 - 00000000 ____D () C:\ProgramData\Licenses
2014-03-17 09:44 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTDFMT.DLL
2014-03-17 09:40 - 2014-03-17 09:40 - 04095448 _____ (BrightFort LLC ) C:\Users\coldharbor1950\Downloads\spywareblastersetup50.exe
2014-03-16 13:52 - 2014-03-16 13:52 - 00000968 _____ () C:\Users\coldharbor1950\Documents\cc_20140316_135229.reg
2014-03-16 11:40 - 2014-03-18 16:41 - 00000977 _____ () C:\Users\coldharbor1950\Desktop\CCleaner.lnk
2014-03-16 11:40 - 2014-03-16 11:40 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-16 11:40 - 2014-03-16 11:40 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-03-16 11:40 - 2014-03-16 11:40 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-16 08:07 - 2014-03-16 08:07 - 00006528 _____ () C:\Users\coldharbor1950\Documents\cc_20140316_080703.reg
2014-03-16 08:06 - 2014-03-16 08:06 - 00052550 _____ () C:\Users\coldharbor1950\Documents\cc_20140316_080611.reg
2014-03-15 19:15 - 2014-03-15 19:14 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-03-15 19:14 - 2014-03-15 19:14 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-03-15 19:14 - 2014-03-15 19:14 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-03-15 19:14 - 2014-03-15 19:14 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-03-15 19:14 - 2014-03-15 19:14 - 00000000 ____D () C:\Program Files (x86)\Java
2014-03-15 19:12 - 2014-03-15 19:12 - 00921000 _____ (Oracle Corporation) C:\Users\coldharbor1950\Downloads\chromeinstall-7u51 (2).exe
2014-03-15 16:09 - 2014-03-01 00:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-15 16:09 - 2014-02-28 23:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-15 16:09 - 2014-02-28 23:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-15 16:09 - 2014-02-28 22:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-15 16:09 - 2014-02-28 22:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-15 16:09 - 2014-02-28 22:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-15 16:09 - 2014-02-28 22:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-15 16:09 - 2014-02-28 21:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-15 16:09 - 2014-02-06 20:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-15 16:09 - 2014-01-28 21:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-15 16:09 - 2014-01-28 21:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-15 16:09 - 2014-01-27 21:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-15 16:08 - 2014-03-01 01:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-15 16:08 - 2014-03-01 00:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-15 16:08 - 2014-02-28 23:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-15 16:08 - 2014-02-28 23:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-15 16:08 - 2014-02-28 23:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-15 16:08 - 2014-02-28 23:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-15 16:08 - 2014-02-28 23:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-15 16:08 - 2014-02-28 23:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-15 16:08 - 2014-02-28 23:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-15 16:08 - 2014-02-28 23:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-15 16:08 - 2014-02-28 23:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-15 16:08 - 2014-02-28 23:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-15 16:08 - 2014-02-28 23:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-15 16:08 - 2014-02-28 23:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-15 16:08 - 2014-02-28 22:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-15 16:08 - 2014-02-28 22:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-15 16:08 - 2014-02-28 22:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-15 16:08 - 2014-02-28 22:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-15 16:08 - 2014-02-28 22:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-15 16:08 - 2014-02-28 22:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-15 16:08 - 2014-02-28 22:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-15 16:08 - 2014-02-28 22:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-15 16:08 - 2014-02-28 22:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-15 16:08 - 2014-02-28 22:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-15 16:08 - 2014-02-28 22:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-15 16:08 - 2014-02-28 22:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-15 16:08 - 2014-02-28 22:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-15 16:08 - 2014-02-28 21:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-15 16:08 - 2014-02-28 21:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-15 16:08 - 2014-02-28 21:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-15 16:08 - 2014-02-28 21:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-15 16:08 - 2014-02-28 21:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-15 16:06 - 2014-02-03 21:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-15 16:06 - 2014-02-03 21:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-15 16:05 - 2014-02-03 21:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-15 16:05 - 2014-02-03 21:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-15 15:40 - 2014-03-15 15:40 - 14805000 _____ (Siber Systems) C:\Users\coldharbor1950\Downloads\RoboForm-Setup-cnetc (1).exe
2014-03-15 09:17 - 2014-03-15 13:33 - 00000000 ____D () C:\Users\coldharbor1950\Downloads\mbam-chameleon-1.62.1.1000
2014-03-15 09:16 - 2014-03-15 09:16 - 01440846 _____ () C:\Users\coldharbor1950\Downloads\mbam-chameleon-1.62.1.1000.zip
2014-03-15 08:36 - 2014-03-15 08:36 - 00071630 _____ () C:\Users\coldharbor1950\Downloads\Extras.Txt
2014-03-15 08:35 - 2014-03-22 20:21 - 00108170 _____ () C:\Users\coldharbor1950\Downloads\OTL.Txt
2014-03-14 13:30 - 2014-03-14 13:30 - 00003139 _____ () C:\Users\coldharbor1950\Documents\Google Redirect.txt
2014-03-13 21:25 - 2014-03-13 21:25 - 00020106 _____ () C:\Users\coldharbor1950\Documents\startup.txt
2014-03-13 19:31 - 2014-03-13 19:31 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Local\VS Revo Group
2014-03-13 14:21 - 2014-03-13 14:21 - 00000000 ____D () C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2014-03-12 09:41 - 2014-03-12 09:41 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
2014-03-12 09:41 - 2014-03-12 09:41 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software
2014-03-10 10:53 - 2014-03-11 20:26 - 00018052 _____ () C:\Users\coldharbor1950\Documents\eBay.odt
2014-03-10 10:08 - 2014-01-12 11:52 - 00011070 _____ () C:\Users\coldharbor1950\Documents\untitled_1.odt
2014-02-27 15:27 - 2014-02-27 15:27 - 14827320 _____ (Siber Systems) C:\Users\coldharbor1950\Downloads\RoboForm-Setup (2).exe
2014-02-25 21:16 - 2014-02-25 21:19 - 78353784 _____ (AVG) C:\Users\coldharbor1950\Downloads\avg_tuh_stf_all_2014_295.exe
2014-02-24 14:25 - 2013-12-05 21:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-24 14:25 - 2013-12-05 21:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-24 14:25 - 2013-12-05 21:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-24 14:25 - 2013-12-05 21:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-24 14:24 - 2014-03-18 16:38 - 00003676 _____ () C:\Windows\System32\Tasks\HP online update program
2014-02-24 14:24 - 2014-03-18 12:51 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler
2014-02-24 13:58 - 2014-02-24 14:00 - 78353832 _____ (AVG) C:\Users\coldharbor1950\Downloads\avg_tuh_stf_all_2014_295_24c28.exe
2014-02-23 11:51 - 2013-12-03 21:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-23 11:51 - 2013-12-03 21:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-23 11:51 - 2013-12-03 21:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-23 11:51 - 2013-12-03 21:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-23 11:51 - 2013-12-03 21:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-23 11:51 - 2013-12-03 21:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-23 11:51 - 2013-12-03 21:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-23 11:51 - 2013-12-03 21:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-23 11:51 - 2013-12-03 21:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-23 11:51 - 2013-12-03 21:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-23 11:51 - 2013-12-03 21:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-23 11:51 - 2013-12-03 21:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-23 11:51 - 2013-12-03 21:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-23 11:51 - 2013-12-03 21:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-23 11:51 - 2013-12-03 20:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-23 11:51 - 2013-12-03 20:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-23 11:51 - 2013-12-03 20:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-23 11:51 - 2013-12-03 20:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-23 11:50 - 2013-12-31 18:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-23 11:50 - 2013-12-31 18:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-23 11:50 - 2013-12-24 18:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-23 11:50 - 2013-12-24 17:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-23 11:50 - 2013-11-26 03:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-23 11:50 - 2013-11-22 17:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-23 11:48 - 2013-12-21 04:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-23 11:48 - 2013-12-21 03:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-22 12:18 - 2014-03-09 12:24 - 00001514 _____ () C:\Users\coldharbor1950\Documents\eBay Civil War.txt
2014-02-22 10:11 - 2014-02-22 10:11 - 00847856 _____ (Google Inc.) C:\Users\coldharbor1950\Downloads\ChromeSetup.exe
2014-02-21 18:52 - 2014-02-21 18:52 - 15530400 _____ (Siber Systems) C:\Users\coldharbor1950\Downloads\RoboForm-Setup (1).exe
2014-02-20 18:51 - 2014-02-20 18:51 - 00001991 _____ () C:\Users\Public\Desktop\H&R Block 2013.lnk
2014-02-20 18:48 - 2014-03-15 13:29 - 00000000 ____D () C:\Program Files (x86)\HRBlock2013
2014-02-20 13:51 - 2014-02-20 13:52 - 00000000 ____D () C:\Users\coldharbor1950\Desktop\2013 Taxes
2014-02-20 13:47 - 2014-02-20 13:49 - 03830677 _____ () C:\Users\coldharbor1950\Downloads\w2.zip
==================== One Month Modified Files and Folders =======
2014-03-22 20:33 - 2014-03-20 10:43 - 00020330 _____ () C:\Users\coldharbor1950\Desktop\FRST.txt
2014-03-22 20:33 - 2014-01-07 13:49 - 00000000 ____D () C:\FRST
2014-03-22 20:32 - 2014-03-22 20:31 - 00047232 _____ () C:\Users\coldharbor1950\Desktop\Addition.txt
2014-03-22 20:27 - 2014-03-22 20:27 - 02157056 _____ (Farbar) C:\Users\coldharbor1950\Desktop\FRST64.exe
2014-03-22 20:25 - 2014-03-18 14:01 - 00000000 ____D () C:\Users\coldharbor1950\Desktop\0318 Comp Repair
2014-03-22 20:22 - 2014-03-19 14:24 - 00121102 _____ () C:\Windows\WindowsUpdate.log
2014-03-22 20:21 - 2014-03-15 08:35 - 00108170 _____ () C:\Users\coldharbor1950\Downloads\OTL.Txt
2014-03-22 20:11 - 2012-11-02 22:25 - 00000914 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-22 20:06 - 2014-03-22 20:06 - 00602112 _____ (OldTimer Tools) C:\Users\coldharbor1950\Downloads\OTL.exe
2014-03-22 20:04 - 2012-12-28 23:20 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-22 18:57 - 2014-01-17 08:28 - 00047104 ___SH () C:\Users\coldharbor1950\Desktop\Thumbs.db
2014-03-22 18:54 - 2014-03-22 18:54 - 00987448 _____ () C:\Users\coldharbor1950\Desktop\SecurityCheck.exe
2014-03-22 16:05 - 2012-06-09 14:14 - 00003958 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{97A3A84A-CC66-4D5F-A3C7-2DF30115F961}
2014-03-22 15:19 - 2009-07-14 00:13 - 00783424 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-22 15:19 - 2009-07-13 23:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-22 15:19 - 2009-07-13 23:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-22 15:14 - 2012-11-02 22:25 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-22 15:12 - 2014-03-22 15:12 - 00333712 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-22 15:12 - 2014-03-22 15:12 - 00000056 _____ () C:\Windows\setupact.log
2014-03-22 15:12 - 2014-03-22 15:12 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-22 15:12 - 2014-01-05 19:57 - 00000000 ____D () C:\ProgramData\PDFC
2014-03-22 15:12 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-22 07:07 - 2012-12-19 20:08 - 00003240 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForcoldharbor1950
2014-03-22 07:07 - 2012-12-19 20:08 - 00000368 _____ () C:\Windows\Tasks\HPCeeScheduleForcoldharbor1950.job
2014-03-21 12:55 - 2014-03-21 12:55 - 00000446 _____ () C:\Users\coldharbor1950\Documents\0321 Response.txt
2014-03-21 07:53 - 2014-03-21 07:53 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-03-19 15:03 - 2014-03-19 15:03 - 00002217 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-19 15:03 - 2012-10-11 17:19 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Local\Google
2014-03-19 15:03 - 2012-10-11 17:19 - 00000000 ____D () C:\Program Files (x86)\Google
2014-03-19 14:31 - 2014-03-19 14:31 - 00000000 ____D () C:\TDSSKiller_Quarantine
2014-03-19 14:14 - 2014-03-19 14:14 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\coldharbor1950\Downloads\tdsskiller.exe
2014-03-19 14:11 - 2013-06-20 09:31 - 00000000 ____D () C:\Windows\pss
2014-03-19 13:56 - 2014-03-19 13:56 - 00407789 _____ () C:\Users\coldharbor1950\Downloads\TDSS.htm
2014-03-19 13:35 - 2014-03-19 13:35 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\coldharbor1950\Desktop\tdsskiller.exe
2014-03-19 11:32 - 2014-03-19 11:32 - 00053843 _____ () C:\Users\coldharbor1950\Documents\bookmarks_3_19_14.html
2014-03-19 11:27 - 2014-03-19 10:15 - 00424787 _____ () C:\Users\coldharbor1950\Downloads\avgremover.log
2014-03-19 10:16 - 2013-12-14 22:51 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-03-19 10:14 - 2014-03-19 10:14 - 03386520 _____ (AVG Technologies CZ, s.r.o.) C:\Users\coldharbor1950\Downloads\avg_remover_stf_x64_2014_4116.exe
2014-03-18 20:37 - 2013-08-15 03:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 20:33 - 2012-10-19 05:00 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-18 20:28 - 2014-03-18 20:28 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-03-18 17:23 - 2014-03-18 17:23 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-03-18 17:23 - 2013-03-06 09:13 - 00000000 ___HD () C:\Users\coldharbor1950\AppData\Local\Adobe
2014-03-18 17:23 - 2012-12-28 23:20 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-18 17:23 - 2012-10-24 21:42 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-18 17:23 - 2012-01-18 17:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-18 16:41 - 2014-03-16 11:40 - 00000977 _____ () C:\Users\coldharbor1950\Desktop\CCleaner.lnk
2014-03-18 16:38 - 2014-02-24 14:24 - 00003676 _____ () C:\Windows\System32\Tasks\HP online update program
2014-03-18 16:10 - 2012-10-15 23:53 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-03-18 16:07 - 2012-10-15 23:52 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-03-18 15:30 - 2012-10-11 17:17 - 00000000 ___HD () C:\Users\coldharbor1950\AppData\Local\Deployment
2014-03-18 15:29 - 2012-10-11 17:17 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Local\Apps\2.0
2014-03-18 15:26 - 2014-03-18 15:26 - 00000000 ____D () C:\ProgramData\Google
2014-03-18 15:26 - 2014-03-18 15:26 - 00000000 ____D () C:\Program Files\Google
2014-03-18 15:00 - 2014-03-18 14:53 - 00000000 ____D () C:\Users\coldharbor1950\Desktop\RK_Quarantine
2014-03-18 14:50 - 2014-03-18 14:50 - 03901952 _____ () C:\Users\coldharbor1950\Desktop\RogueKiller.exe
2014-03-18 14:21 - 2014-03-18 14:21 - 01037734 _____ (Thisisu) C:\Users\coldharbor1950\Downloads\JRT.exe
2014-03-18 14:21 - 2014-03-18 14:21 - 00001157 _____ () C:\Users\coldharbor1950\Desktop\JRT - Shortcut.lnk
2014-03-18 14:15 - 2013-12-17 17:09 - 00000000 ____D () C:\AdwCleaner
2014-03-18 14:09 - 2014-03-18 14:09 - 01950720 _____ () C:\Users\coldharbor1950\Downloads\AdwCleaner.exe
2014-03-18 14:09 - 2014-03-18 14:09 - 00001230 _____ () C:\Users\coldharbor1950\Desktop\AdwCleaner - Shortcut.lnk
2014-03-18 13:55 - 2014-03-18 13:55 - 00000000 ____D () C:\_OTL
2014-03-18 12:51 - 2014-02-24 14:24 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler
2014-03-18 12:36 - 2014-03-18 12:36 - 00005633 _____ () C:\Users\coldharbor1950\Documents\CompFix 031814.txt
2014-03-18 12:17 - 2012-11-02 22:25 - 00003920 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-18 12:17 - 2012-11-02 22:25 - 00003668 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-18 10:42 - 2014-03-18 10:42 - 00156902 _____ () C:\Users\coldharbor1950\Downloads\OTL 0318 Safe Mode.txt
2014-03-18 10:21 - 2014-03-17 09:44 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster
2014-03-18 10:09 - 2014-01-01 13:25 - 00003182 _____ () C:\Windows\System32\Tasks\{F876F0D1-9074-4454-9507-B66E6F1F41E7}
2014-03-18 10:08 - 2013-10-10 06:57 - 00003242 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-387024861-1857405023-142887614-1000
2014-03-18 10:01 - 2014-03-18 10:01 - 00000382 _____ () C:\Users\coldharbor1950\Documents\cc_20140318_100102.reg
2014-03-18 08:41 - 2014-03-18 08:41 - 00160168 _____ () C:\Users\coldharbor1950\Downloads\OTL 0318.txt
2014-03-18 08:13 - 2014-03-18 08:13 - 00602112 _____ (OldTimer Tools) C:\Users\coldharbor1950\Downloads\OTL (1).com
2014-03-18 08:09 - 2014-03-18 08:09 - 00602112 _____ (OldTimer Tools) C:\Users\coldharbor1950\Desktop\OTL.com
2014-03-18 07:20 - 2013-12-31 14:06 - 00003356 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-387024861-1857405023-142887614-1000
2014-03-17 22:50 - 2013-05-30 14:32 - 00000000 ____D () C:\JRT
2014-03-17 18:51 - 2013-05-30 13:52 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-17 10:02 - 2013-05-30 13:51 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-03-17 09:59 - 2014-03-17 09:59 - 00001341 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-03-17 09:44 - 2014-03-17 09:44 - 00001041 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk
2014-03-17 09:44 - 2014-03-17 09:44 - 00000000 ____D () C:\ProgramData\Licenses
2014-03-17 09:40 - 2014-03-17 09:40 - 04095448 _____ (BrightFort LLC ) C:\Users\coldharbor1950\Downloads\spywareblastersetup50.exe
2014-03-16 13:52 - 2014-03-16 13:52 - 00000968 _____ () C:\Users\coldharbor1950\Documents\cc_20140316_135229.reg
2014-03-16 11:40 - 2014-03-16 11:40 - 00002790 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-03-16 11:40 - 2014-03-16 11:40 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-03-16 11:40 - 2014-03-16 11:40 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-16 08:07 - 2014-03-16 08:07 - 00006528 _____ () C:\Users\coldharbor1950\Documents\cc_20140316_080703.reg
2014-03-16 08:06 - 2014-03-16 08:06 - 00052550 _____ () C:\Users\coldharbor1950\Documents\cc_20140316_080611.reg
2014-03-16 03:25 - 2013-12-10 10:26 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-16 03:25 - 2013-12-10 10:26 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-15 19:15 - 2014-01-18 18:59 - 00000000 ____D () C:\ProgramData\Oracle
2014-03-15 19:14 - 2014-03-15 19:15 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-03-15 19:14 - 2014-03-15 19:14 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-03-15 19:14 - 2014-03-15 19:14 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-03-15 19:14 - 2014-03-15 19:14 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-03-15 19:14 - 2014-03-15 19:14 - 00000000 ____D () C:\Program Files (x86)\Java
2014-03-15 19:12 - 2014-03-15 19:12 - 00921000 _____ (Oracle Corporation) C:\Users\coldharbor1950\Downloads\chromeinstall-7u51 (2).exe
2014-03-15 15:56 - 2012-01-18 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-03-15 15:43 - 2012-10-22 10:25 - 00004248 _____ () C:\Windows\System32\Tasks\Open URL by RoboForm
2014-03-15 15:43 - 2012-10-22 10:25 - 00003508 _____ () C:\Windows\System32\Tasks\Run RoboForm TaskBar Icon
2014-03-15 15:40 - 2014-03-15 15:40 - 14805000 _____ (Siber Systems) C:\Users\coldharbor1950\Downloads\RoboForm-Setup-cnetc (1).exe
2014-03-15 14:38 - 2012-06-09 14:07 - 00000000 ____D () C:\Users\coldharbor1950
2014-03-15 14:35 - 2013-12-17 22:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-15 14:35 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\L2Schemas
2014-03-15 13:33 - 2014-03-15 09:17 - 00000000 ____D () C:\Users\coldharbor1950\Downloads\mbam-chameleon-1.62.1.1000
2014-03-15 13:33 - 2013-11-19 21:22 - 00000000 ____D () C:\ProgramData\ProductData
2014-03-15 13:33 - 2013-02-08 17:21 - 00000000 ____D () C:\ProgramData\pdf995
2014-03-15 13:33 - 2012-12-07 10:45 - 00000000 ____D () C:\Program Files (x86)\Real
2014-03-15 13:33 - 2012-11-09 22:49 - 00000000 ____D () C:\ProgramData\IObit
2014-03-15 13:33 - 2012-10-12 15:52 - 00000000 ____D () C:\Windows\WindowsMobile
2014-03-15 13:33 - 2012-01-18 17:30 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-15 13:33 - 2009-07-13 22:20 - 00000000 __RSD () C:\Windows\Media
2014-03-15 13:33 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-15 13:33 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\schemas
2014-03-15 13:33 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-03-15 13:33 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\AppCompat
2014-03-15 13:32 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\registration
2014-03-15 13:30 - 2014-02-14 21:56 - 00000000 ____D () C:\Program Files\Java
2014-03-15 13:30 - 2012-12-07 10:45 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Roaming\Real
2014-03-15 13:30 - 2012-12-07 10:43 - 00000000 ____D () C:\ProgramData\Real
2014-03-15 13:30 - 2012-10-30 03:03 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Roaming\Skype
2014-03-15 13:29 - 2014-02-20 18:48 - 00000000 ____D () C:\Program Files (x86)\HRBlock2013
2014-03-15 13:28 - 2014-02-19 20:20 - 00000000 ____D () C:\DrvInstall
2014-03-15 09:16 - 2014-03-15 09:16 - 01440846 _____ () C:\Users\coldharbor1950\Downloads\mbam-chameleon-1.62.1.1000.zip
2014-03-15 08:36 - 2014-03-15 08:36 - 00071630 _____ () C:\Users\coldharbor1950\Downloads\Extras.Txt
2014-03-14 18:39 - 2012-10-20 18:10 - 00000000 ___HD () C:\Users\coldharbor1950\AppData\Local\CrashDumps
2014-03-14 13:30 - 2014-03-14 13:30 - 00003139 _____ () C:\Users\coldharbor1950\Documents\Google Redirect.txt
2014-03-13 21:25 - 2014-03-13 21:25 - 00020106 _____ () C:\Users\coldharbor1950\Documents\startup.txt
2014-03-13 19:31 - 2014-03-13 19:31 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Local\VS Revo Group
2014-03-13 14:21 - 2014-03-13 14:21 - 00000000 ____D () C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
2014-03-12 09:41 - 2014-03-12 09:41 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
2014-03-12 09:41 - 2014-03-12 09:41 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\TuneUp Software
2014-03-11 20:26 - 2014-03-10 10:53 - 00018052 _____ () C:\Users\coldharbor1950\Documents\eBay.odt
2014-03-09 19:26 - 2013-01-05 11:35 - 00000000 ___HD () C:\Users\coldharbor1950\Documents\HRBlock
2014-03-09 12:24 - 2014-02-22 12:18 - 00001514 _____ () C:\Users\coldharbor1950\Documents\eBay Civil War.txt
2014-03-01 01:05 - 2014-03-15 16:08 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 00:17 - 2014-03-15 16:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 00:16 - 2014-03-15 16:09 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-28 23:58 - 2014-03-15 16:09 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-28 23:52 - 2014-03-15 16:08 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-28 23:51 - 2014-03-15 16:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-28 23:42 - 2014-03-15 16:08 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-28 23:40 - 2014-03-15 16:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-28 23:37 - 2014-03-15 16:08 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-28 23:33 - 2014-03-15 16:08 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-28 23:33 - 2014-03-15 16:08 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-28 23:32 - 2014-03-15 16:08 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-28 23:30 - 2014-03-15 16:09 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-28 23:23 - 2014-03-15 16:08 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-02-28 23:17 - 2014-03-15 16:08 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-28 23:11 - 2014-03-15 16:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-28 23:02 - 2014-03-15 16:08 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-28 22:54 - 2014-03-15 16:08 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-28 22:52 - 2014-03-15 16:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-28 22:51 - 2014-03-15 16:09 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-28 22:47 - 2014-03-15 16:09 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-28 22:43 - 2014-03-15 16:09 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-28 22:43 - 2014-03-15 16:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-28 22:42 - 2014-03-15 16:08 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-28 22:40 - 2014-03-15 16:08 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-28 22:38 - 2014-03-15 16:08 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-28 22:37 - 2014-03-15 16:08 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-28 22:35 - 2014-03-15 16:08 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-28 22:18 - 2014-03-15 16:08 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-28 22:16 - 2014-03-15 16:08 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-28 22:14 - 2014-03-15 16:08 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-28 22:10 - 2014-03-15 16:08 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-28 22:03 - 2014-03-15 16:09 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-28 22:00 - 2014-03-15 16:08 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-28 21:57 - 2014-03-15 16:08 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-28 21:38 - 2014-03-15 16:08 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-28 21:32 - 2014-03-15 16:08 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-28 21:27 - 2014-03-15 16:09 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-28 21:25 - 2014-03-15 16:08 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-28 21:25 - 2014-03-15 16:08 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-27 15:27 - 2014-02-27 15:27 - 14827320 _____ (Siber Systems) C:\Users\coldharbor1950\Downloads\RoboForm-Setup (2).exe
2014-02-25 21:25 - 2013-12-14 21:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-25 21:19 - 2014-02-25 21:16 - 78353784 _____ (AVG) C:\Users\coldharbor1950\Downloads\avg_tuh_stf_all_2014_295.exe
2014-02-24 14:24 - 2012-12-28 21:07 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Local\Downloaded Installations
2014-02-24 14:24 - 2012-11-19 20:03 - 00000000 ___HD () C:\Users\coldharbor1950\AppData\Roaming\hpqLog
2014-02-24 14:24 - 2012-11-19 20:03 - 00000000 ____D () C:\ProgramData\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF}
2014-02-24 14:24 - 2012-06-10 14:41 - 00000000 ___HD () C:\Users\coldharbor1950\AppData\Roaming\HpUpdate
2014-02-24 14:04 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2014-02-24 14:00 - 2014-02-24 13:58 - 78353832 _____ (AVG) C:\Users\coldharbor1950\Downloads\avg_tuh_stf_all_2014_295_24c28.exe
2014-02-23 11:53 - 2011-02-11 12:15 - 00775546 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-22 10:11 - 2014-02-22 10:11 - 00847856 _____ (Google Inc.) C:\Users\coldharbor1950\Downloads\ChromeSetup.exe
2014-02-21 18:52 - 2014-02-21 18:52 - 15530400 _____ (Siber Systems) C:\Users\coldharbor1950\Downloads\RoboForm-Setup (1).exe
2014-02-20 18:51 - 2014-02-20 18:51 - 00001991 _____ () C:\Users\Public\Desktop\H&R Block 2013.lnk
2014-02-20 18:51 - 2013-01-05 11:37 - 00000000 ____D () C:\Users\coldharbor1950\AppData\Roaming\TaxCut
2014-02-20 18:46 - 2013-01-05 11:32 - 00000000 ____D () C:\ProgramData\TaxCut
2014-02-20 13:52 - 2014-02-20 13:51 - 00000000 ____D () C:\Users\coldharbor1950\Desktop\2013 Taxes
2014-02-20 13:49 - 2014-02-20 13:47 - 03830677 _____ () C:\Users\coldharbor1950\Downloads\w2.zip
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-20 08:59
==================== End Of Log ============================