Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Windows 7 pro HP microtower "I have been infected w/ransom trogen&

1-877 call alerts audio warningsms can not use internet my isp is dial up 1-877 ransom blocks all attempts to remove internet explorer 11

  • Please log in to reply

#16
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

Hi Naat, I'm sorry it's taken so long, but my computer is acting crazy, I downloaded a new copy of MBAM and didn't update until late this morning, according to the scan it's clean { But then again it never detected the ransom virus } that MSE caught; As far as Eset this is a picture of what's been going on at eset for the last 5 hrs, and I almost couldn't get on G2G, several attempts looked like this:....I Hope all is well, Best wishes, Tim :killcomp:


Edited by bonezz777, 14 March 2016 - 06:30 PM.

  • 0

Advertisements


#17
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
I am very reluctant to call this Ransomware, because ransomware behaves in a slightly different way - that was just scam advertising.

I do not see any screen attached to your post. Can you please re-do that?


Regards,

Naat
  • 1

#18
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

Hi Naat, I have tried to dwn load eset online scanner, & it wont do it; I've left it alone for hrs., nothing, I've hit f5 nothing, just the same screen, once it said allow some add on, I did still nothing; I have NEVER been able to make windows "print screen" work, so I use wolf coders snap shot, here's what I'm seeing:; BTW THANK YOU, FOR REAL, for Your dedication to G2G & MBAM & of course  US, the average joe that needs a hand,on behalf of myself & the 1000's You all Help, Thank You.


  • 0

#19
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

SNAG-16031418560700.png SNAG-16031419240400.png


  • 0

#20
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Hello Bonezz777,

 

Naathim has been called back to hospital so you will have to put up with me.

 

Something funny going on with your machine. Before we try anything else let's just have another look.

 

Please run another FRST scan with the Addition.txt box ticked and post back the two logs generated - FRST.txt and Addition.txt.


  • 0

#21
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

Hello Emeraldnzl, I am sorry to find Naat in the hospital, apologize for me, I didn't know, I thought Naat was mad at me?; Okay, I'm glad to of had two very educated people helping me Thank You, Here is Your requested files::Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 Ran by Tim (administrator) on TIM-HP (18-03-2016 18:45:13) Running from C:\Downloads Loaded Profiles: Tim (Available Profiles: Tim & General Log In & Guest) Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (AMD) C:\Windows\System32\atiesrxx.exe (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpCardEngine.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AMD) C:\Windows\System32\atieclxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe () C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Hewlett-Packard Company) C:\Windows\SysWOW64\flcdlock.exe (Hewlett-Packard Development Company) C:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_20_0_0_306_ActiveX.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7570136 2014-04-14] (Realtek Semiconductor) HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Bitdefender\Antivirus Free Edition\Install\setuplauncher.exe" /run:"C:\Program Files\Bitdefender\Antivirus Free Edition\Install\Installer.exe" HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111576 2013-08-05] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [490760 2013-08-06] (CyberLink Corp.) HKLM-x32\...\Run: [HP File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2213592 2014-02-05] (Hewlett-Packard) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2009-12-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [948672 2009-12-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [TweakDUN] => C:\Program Files (x86)\TweakDUN\tweakdun.exe splash HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe, Lsa: [Notification Packages] DPPassFilter scecli ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\..\Interfaces\{2F1E699D-E62A-4FF1-A81B-78F8012F36FF}: [NameServer] 207.69.188.165 207.69.188.166 Internet Explorer: ================== HKU\S-1-5-21-3386813744-1969293527-735481815-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM14/19 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM14/19 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/19 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/19 HKU\S-1-5-21-3386813744-1969293527-735481815-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.peoplepc.com/ SearchScopes: HKU\S-1-5-21-3386813744-1969293527-735481815-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21] (Adobe Systems Incorporated) BHO-x32: HP File Sanitizer -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2014-02-05] (Hewlett-Packard) BHO-x32: No Name -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> No File BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard) DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab FireFox: ======== FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll [2014-02-10] (DigitalPersona, Inc.) FF HKLM-x32\...\Firefox\Extensions: [dpmaxz_ng@jetpack] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome FF Extension: HP Client Security Manager - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome [2015-12-12] [not signed] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome.crx [2014-02-10] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 CtAgentService; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [7168 2014-03-31] () [File not signed] R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink) R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [500048 2014-02-10] (DigitalPersona, Inc.) R2 FLCDLOCK; c:\windows\SysWOW64\flcdlock.exe [567608 2013-11-20] (Hewlett-Packard Company) R2 HpDamServiceHost; c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [18232 2013-11-15] (Hewlett-Packard Development Company) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-11-20] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor) R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [79440 2015-08-14] (Advanced Micro Devices, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-12-03] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2013-11-20] (Intel® Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 amdkmcsp; C:\Windows\System32\DRIVERS\amdkmcsp.sys [114456 2015-08-14] (Advanced Micro Devices, Inc. ) R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-13] (Advanced Micro Devices, Inc.) R1 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [298776 2015-08-14] (Advanced Micro Devices, Inc. ) R1 CLVirtualDrive; C:\Windows\System32\DRIVERS\CLVirtualDrive.sys [90608 2011-12-27] (CyberLink) R2 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [65752 2013-10-07] (Hewlett-Packard Company) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 MODEMCSA; C:\Windows\System32\drivers\MODEMCSA.sys [24064 2009-07-13] (Microsoft Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation) R3 NETwNs64; C:\Windows\System32\DRIVERS\NETwsw02.sys [3599840 2013-10-14] (Intel Corporation) R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-17 08:27 - 2016-02-05 15:03 - 00147904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tpm.sys 2016-03-17 08:27 - 2016-02-05 14:56 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\tbs.dll 2016-03-17 08:27 - 2016-02-05 14:54 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\fveapibase.dll 2016-03-17 08:27 - 2016-02-05 13:33 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\tbs.dll 2016-03-17 08:27 - 2016-02-02 14:57 - 00511488 _____ (Microsoft Corporation) C:\windows\system32\rpcss.dll 2016-03-17 08:27 - 2015-06-03 16:21 - 00451080 _____ (Microsoft Corporation) C:\windows\system32\fveapi.dll 2016-03-17 08:25 - 2016-01-20 20:51 - 00073664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\disk.sys 2016-03-15 21:11 - 2016-02-01 15:08 - 00114624 _____ (Microsoft Corporation) C:\windows\system32\consent.exe 2016-03-15 21:11 - 2016-02-01 14:59 - 03243008 _____ (Microsoft Corporation) C:\windows\system32\msi.dll 2016-03-15 21:11 - 2016-02-01 14:59 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll 2016-03-15 21:11 - 2016-02-01 14:59 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll 2016-03-15 21:11 - 2016-02-01 14:56 - 01940992 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2016-03-15 21:11 - 2016-02-01 14:56 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll 2016-03-15 21:11 - 2016-02-01 14:49 - 02364928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll 2016-03-15 21:11 - 2016-02-01 14:49 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll 2016-03-15 21:11 - 2016-02-01 14:49 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll 2016-03-15 21:11 - 2016-02-01 14:45 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll 2016-03-15 17:40 - 2016-03-15 21:16 - 00000324 _____ C:\windows\Tasks\HPCeeScheduleForTim.job 2016-03-15 17:40 - 2016-03-15 17:40 - 00003174 _____ C:\windows\System32\Tasks\HPCeeScheduleForTim 2016-03-15 07:08 - 2016-03-16 17:00 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster 2016-03-15 07:08 - 2016-03-15 07:08 - 00001087 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk 2016-03-15 07:08 - 2016-03-15 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster 2016-03-15 07:08 - 2012-05-02 11:17 - 01070152 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSCOMCTL.OCX 2016-03-15 07:08 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSSTDFMT.DLL 2016-03-15 07:04 - 2016-03-15 07:04 - 00001016 _____ C:\Users\Tim\Desktop\adwcleaner_5.102.exe - Shortcut.lnk 2016-03-14 21:27 - 2016-03-14 21:27 - 00000000 ____D C:\Program Files (x86)\Secunia 2016-03-14 09:40 - 2016-03-14 09:40 - 00001110 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-03-13 10:28 - 2016-03-13 10:28 - 00000924 _____ C:\Users\Tim\Desktop\FRST64.exe - Shortcut.lnk 2016-03-13 10:04 - 2016-03-13 10:28 - 00000118 _____ C:\Users\Tim\Desktop\fixlist.txt 2016-03-12 21:57 - 2016-02-09 02:53 - 00387792 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2016-03-12 21:57 - 2016-02-09 02:10 - 00341200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2016-03-12 21:57 - 2016-02-08 17:05 - 20352512 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2016-03-12 21:57 - 2016-02-08 16:51 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2016-03-12 21:57 - 2016-02-08 16:39 - 00496640 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2016-03-12 21:57 - 2016-02-08 16:39 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2016-03-12 21:57 - 2016-02-08 16:38 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2016-03-12 21:57 - 2016-02-08 16:38 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2016-03-12 21:57 - 2016-02-08 16:37 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2016-03-12 21:57 - 2016-02-08 16:34 - 02280448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2016-03-12 21:57 - 2016-02-08 16:32 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2016-03-12 21:57 - 2016-02-08 16:31 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2016-03-12 21:57 - 2016-02-08 16:30 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2016-03-12 21:57 - 2016-02-08 16:28 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2016-03-12 21:57 - 2016-02-08 16:28 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2016-03-12 21:57 - 2016-02-08 16:28 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2016-03-12 21:57 - 2016-02-08 16:20 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2016-03-12 21:57 - 2016-02-08 16:16 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-03-12 21:57 - 2016-02-08 16:15 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll 2016-03-12 21:57 - 2016-02-08 16:13 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2016-03-12 21:57 - 2016-02-08 16:12 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2016-03-12 21:57 - 2016-02-08 16:11 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2016-03-12 21:57 - 2016-02-08 16:10 - 04611072 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2016-03-12 21:57 - 2016-02-08 16:10 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2016-03-12 21:57 - 2016-02-08 16:05 - 25816576 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2016-03-12 21:57 - 2016-02-08 16:03 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2016-03-12 21:57 - 2016-02-08 16:02 - 13012480 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2016-03-12 21:57 - 2016-02-08 16:02 - 00687104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2016-03-12 21:57 - 2016-02-08 16:01 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2016-03-12 21:57 - 2016-02-08 16:01 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2016-03-12 21:57 - 2016-02-08 15:43 - 02121216 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2016-03-12 21:57 - 2016-02-08 15:39 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2016-03-12 21:57 - 2016-02-08 15:38 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2016-03-12 21:57 - 2016-02-08 14:41 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2016-03-12 21:57 - 2016-02-08 14:41 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2016-03-12 21:57 - 2016-02-08 14:27 - 02887680 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2016-03-12 21:57 - 2016-02-08 14:27 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2016-03-12 21:57 - 2016-02-08 14:26 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2016-03-12 21:57 - 2016-02-08 14:26 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2016-03-12 21:57 - 2016-02-08 14:26 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2016-03-12 21:57 - 2016-02-08 14:26 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2016-03-12 21:57 - 2016-02-08 14:19 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2016-03-12 21:57 - 2016-02-08 14:18 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2016-03-12 21:57 - 2016-02-08 14:16 - 06052352 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2016-03-12 21:57 - 2016-02-08 14:15 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2016-03-12 21:57 - 2016-02-08 14:14 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2016-03-12 21:57 - 2016-02-08 14:14 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2016-03-12 21:57 - 2016-02-08 14:13 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2016-03-12 21:57 - 2016-02-08 14:13 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2016-03-12 21:57 - 2016-02-08 14:06 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2016-03-12 21:57 - 2016-02-08 14:03 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2016-03-12 21:57 - 2016-02-08 13:55 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2016-03-12 21:57 - 2016-02-08 13:54 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2016-03-12 21:57 - 2016-02-08 13:52 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2016-03-12 21:57 - 2016-02-08 13:51 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2016-03-12 21:57 - 2016-02-08 13:49 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2016-03-12 21:57 - 2016-02-08 13:47 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2016-03-12 21:57 - 2016-02-08 13:37 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2016-03-12 21:57 - 2016-02-08 13:35 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2016-03-12 21:57 - 2016-02-08 13:34 - 00798720 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2016-03-12 21:57 - 2016-02-08 13:33 - 14613504 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2016-03-12 21:57 - 2016-02-08 13:33 - 02123264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2016-03-12 21:57 - 2016-02-08 13:33 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2016-03-12 21:57 - 2016-02-08 13:19 - 02597376 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2016-03-12 21:57 - 2016-02-08 13:07 - 01546752 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2016-03-12 21:57 - 2016-02-08 12:55 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2016-03-11 10:21 - 2016-03-17 18:06 - 00000000 ____D C:\Program Files (x86)\AdwCleaner 2016-03-11 09:36 - 2016-03-11 09:36 - 00000904 _____ C:\Users\Tim\Desktop\zoek.exe - Shortcut.lnk 2016-03-11 08:40 - 2016-03-11 08:40 - 00021728 _____ C:\Users\Tim\Desktop\zoek-results.txt 2016-03-10 16:46 - 2016-02-11 14:56 - 05572032 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2016-03-10 16:46 - 2016-02-11 14:56 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2016-03-10 16:46 - 2016-02-11 14:56 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2016-03-10 16:46 - 2016-02-11 14:52 - 01733592 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2016-03-10 16:46 - 2016-02-11 14:49 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll 2016-03-10 16:46 - 2016-02-11 14:49 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll 2016-03-10 16:46 - 2016-02-11 14:49 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll 2016-03-10 16:46 - 2016-02-11 14:49 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2016-03-10 16:46 - 2016-02-11 14:49 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2016-03-10 16:46 - 2016-02-11 14:49 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2016-03-10 16:46 - 2016-02-11 14:49 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2016-03-10 16:46 - 2016-02-11 14:49 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll 2016-03-10 16:46 - 2016-02-11 14:48 - 01214464 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll 2016-03-10 16:46 - 2016-02-11 14:48 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll 2016-03-10 16:46 - 2016-02-11 14:48 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2016-03-10 16:46 - 2016-02-11 14:48 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll 2016-03-10 16:46 - 2016-02-11 14:48 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2016-03-10 16:46 - 2016-02-11 14:47 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll 2016-03-10 16:46 - 2016-02-11 14:45 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2016-03-10 16:46 - 2016-02-11 14:45 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2016-03-10 16:46 - 2016-02-11 14:45 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll 2016-03-10 16:46 - 2016-02-11 14:45 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll 2016-03-10 16:46 - 2016-02-11 14:44 - 03994560 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe 2016-03-10 16:46 - 2016-02-11 14:44 - 03938240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe 2016-03-10 16:46 - 2016-02-11 14:44 - 01461248 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2016-03-10 16:46 - 2016-02-11 14:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2016-03-10 16:46 - 2016-02-11 14:44 - 00730112 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2016-03-10 16:46 - 2016-02-11 14:44 - 00422400 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2016-03-10 16:46 - 2016-02-11 14:42 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll 2016-03-10 16:46 - 2016-02-11 14:42 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll 2016-03-10 16:46 - 2016-02-11 14:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 01314328 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00880128 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:38 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll 2016-03-10 16:46 - 2016-02-11 14:38 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll 2016-03-10 16:46 - 2016-02-11 14:38 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll 2016-03-10 16:46 - 2016-02-11 14:38 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll 2016-03-10 16:46 - 2016-02-11 14:38 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll 2016-03-10 16:46 - 2016-02-11 14:38 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll 2016-03-10 16:46 - 2016-02-11 14:38 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll 2016-03-10 16:46 - 2016-02-11 14:37 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll 2016-03-10 16:46 - 2016-02-11 14:37 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll 2016-03-10 16:46 - 2016-02-11 14:37 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll 2016-03-10 16:46 - 2016-02-11 14:35 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll 2016-03-10 16:46 - 2016-02-11 14:35 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll 2016-03-10 16:46 - 2016-02-11 14:35 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll 2016-03-10 16:46 - 2016-02-11 14:34 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll 2016-03-10 16:46 - 2016-02-11 14:33 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll 2016-03-10 16:46 - 2016-02-11 14:31 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00642560 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 13:48 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe 2016-03-10 16:46 - 2016-02-11 13:43 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe 2016-03-10 16:46 - 2016-02-11 13:41 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe 2016-03-10 16:46 - 2016-02-11 13:40 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe 2016-03-10 16:46 - 2016-02-11 13:34 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys 2016-03-10 16:46 - 2016-02-11 13:34 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys 2016-03-10 16:46 - 2016-02-11 13:33 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys 2016-03-10 16:46 - 2016-02-11 13:32 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe 2016-03-10 16:46 - 2016-02-11 13:32 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2016-03-10 16:46 - 2016-02-11 13:32 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe 2016-03-10 16:46 - 2016-02-11 13:32 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll 2016-03-10 16:46 - 2016-02-11 13:32 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe 2016-03-10 16:46 - 2016-02-11 13:32 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe 2016-03-10 16:46 - 2016-02-11 13:31 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll 2016-03-10 16:46 - 2016-02-11 13:30 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 13:30 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 13:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-03-10 16:46 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-03-10 15:53 - 2016-03-11 09:38 - 00000000 ____D C:\zoek_backup 2016-03-09 16:20 - 2016-03-18 18:45 - 00000000 ____D C:\FRST 2016-03-09 16:19 - 2016-02-04 13:52 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2016-03-09 16:19 - 2016-02-03 14:58 - 00862208 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll 2016-03-09 16:19 - 2016-02-03 14:52 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll 2016-03-09 16:19 - 2016-02-03 14:49 - 00572416 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll 2016-03-09 16:19 - 2016-02-03 14:43 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll 2016-03-09 16:19 - 2016-02-03 14:07 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS 2016-03-09 16:15 - 2016-02-04 21:19 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll 2016-03-09 16:15 - 2016-02-04 14:41 - 00296448 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll 2016-03-09 16:05 - 2016-02-05 14:54 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll 2016-03-09 16:05 - 2016-02-05 14:54 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll 2016-03-09 16:05 - 2016-02-05 14:53 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll 2016-03-09 16:05 - 2016-02-05 14:53 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll 2016-03-09 16:05 - 2016-02-05 14:50 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll 2016-03-09 16:05 - 2016-02-05 14:44 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll 2016-03-09 16:05 - 2016-02-05 14:42 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll 2016-03-09 16:05 - 2016-02-05 13:48 - 00372736 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll 2016-03-09 16:05 - 2016-02-05 13:43 - 00299520 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll 2016-03-09 16:05 - 2016-02-05 13:43 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll 2016-03-09 16:04 - 2016-02-09 05:57 - 14634496 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2016-03-09 16:04 - 2016-02-09 05:57 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2016-03-09 16:04 - 2016-02-09 05:56 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx 2016-03-09 16:04 - 2016-02-09 05:56 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll 2016-03-09 16:04 - 2016-02-09 05:55 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\seclogon.dll 2016-03-09 16:04 - 2016-02-09 05:54 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll 2016-03-09 16:04 - 2016-02-09 05:51 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL 2016-03-09 16:04 - 2016-02-09 05:51 - 11411456 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll 2016-03-09 16:04 - 2016-02-09 05:13 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll 2016-03-09 16:04 - 2016-02-09 05:13 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx 2016-03-09 16:04 - 2016-02-09 05:13 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll 2016-03-08 08:38 - 2016-02-19 15:02 - 00038336 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe 2016-03-08 08:38 - 2016-02-19 14:54 - 01168896 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2016-03-08 08:38 - 2016-02-19 10:07 - 01373184 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll 2016-03-08 08:38 - 2016-02-11 10:07 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2016-03-08 08:38 - 2016-02-05 10:07 - 00696832 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll 2016-03-08 08:38 - 2016-02-05 10:07 - 00499200 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll 2016-03-08 08:38 - 2016-02-05 10:07 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll 2016-03-07 19:31 - 2016-03-07 19:31 - 00001026 _____ C:\Users\Public\Desktop\WOLFCODERS ScreenSnag.lnk 2016-03-07 19:31 - 2016-03-07 19:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WOLFCODERS ScreenSnag 2016-03-07 19:31 - 2016-03-07 19:31 - 00000000 ____D C:\Program Files (x86)\WOLFCODERS ScreenSnag 2016-03-07 11:16 - 2016-03-07 16:06 - 23807881 _____ C:\Users\Tim\Downloads\mpas-fe.exe.26wgabc.partial 2016-03-07 11:07 - 2016-03-07 16:06 - 23800577 _____ C:\Users\Tim\Downloads\mpam-fe (1).exe.erzic1p.partial 2016-03-05 18:06 - 2016-03-09 11:18 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Free Download Manager 2016-03-05 18:06 - 2016-03-05 18:06 - 00001331 _____ C:\Users\General Log In\Desktop\Free Download Manager.lnk 2016-03-05 12:28 - 2016-03-05 12:28 - 00000673 _____ C:\windows\system32\Drivers\etc\hosts.bak 2016-03-05 12:19 - 2000-05-22 01:00 - 00140488 _____ (Microsoft Corporation) C:\windows\SysWOW64\Comdlg32.ocx 2016-03-05 12:19 - 2000-05-22 01:00 - 00115920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Msinet.ocx 2016-03-05 11:24 - 2016-03-05 11:24 - 00000000 ____D C:\Users\Tim\AppData\LocalLow\Oracle 2016-03-05 11:17 - 2016-03-05 11:23 - 00735328 _____ (Oracle Corporation) C:\Users\General Log In\Downloads\JavaSetup8u73.exe 2016-03-05 09:54 - 2016-03-05 14:03 - 00796864 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2016-03-05 09:54 - 2016-03-05 14:03 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-03-05 09:54 - 2016-03-05 09:54 - 00000000 ____D C:\windows\system32\Macromed 2016-03-05 07:18 - 2016-03-05 07:58 - 02735752 _____ C:\Users\General Log In\Downloads\install_flash_player_18_active_x.exe.ibz20af.partial 2016-03-04 09:07 - 2016-03-04 09:07 - 00000000 ____D C:\Users\General Log In\AppData\Local\DigitalPersona,_Inc 2016-03-02 22:08 - 2016-02-12 14:52 - 03169792 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll 2016-03-02 22:08 - 2016-02-12 14:52 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll 2016-03-02 22:08 - 2016-02-12 14:52 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2016-03-02 22:08 - 2016-02-12 14:44 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll 2016-03-02 22:08 - 2016-02-12 14:39 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll 2016-03-02 22:08 - 2016-02-12 14:22 - 02610688 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2016-03-02 22:08 - 2016-02-12 14:19 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2016-03-02 22:08 - 2016-02-12 14:18 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2016-03-02 22:08 - 2016-02-12 14:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll 2016-03-02 22:08 - 2016-02-12 14:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe 2016-03-02 22:08 - 2016-02-12 14:18 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll 2016-03-02 22:08 - 2016-02-12 14:18 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll 2016-03-02 22:08 - 2016-02-12 14:06 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll 2016-03-02 22:08 - 2016-02-12 14:05 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll 2016-03-02 22:08 - 2016-02-12 14:05 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe 2016-03-02 22:08 - 2016-02-12 14:05 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll 2016-03-01 15:32 - 1999-10-10 16:48 - 00206700 ____R C:\Users\General Log In\Downloads\_SETUP.LIB 2016-03-01 15:31 - 2016-03-05 18:09 - 00000000 ____D C:\Users\General Log In\AppData\Local\Adobe 2016-03-01 14:15 - 2016-03-01 14:15 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\FreeDownloadManager.ORG 2016-03-01 14:15 - 2016-03-01 14:15 - 00000000 ____D C:\Users\General Log In\AppData\Local\Free Download Manager 2016-03-01 14:15 - 2016-03-01 14:15 - 00000000 ____D C:\ProgramData\FreeDownloadManager.ORG 2016-03-01 14:15 - 2016-03-01 14:15 - 00000000 ____D C:\ProgramData\Free Download Manager 2016-02-29 17:53 - 2016-03-18 07:32 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2016-02-29 17:53 - 2016-03-14 09:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-02-29 17:52 - 2016-03-14 09:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-02-29 17:52 - 2016-02-29 17:52 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-02-29 17:52 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2016-02-29 17:52 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys 2016-02-29 16:09 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys 2016-02-29 16:06 - 2016-02-29 16:06 - 00000000 ____D C:\Users\General Log In\Downloads\mbam-chameleon-3.1.28.0 2016-02-29 15:39 - 2016-02-29 16:05 - 06392130 _____ C:\Users\General Log In\Downloads\mbam-chameleon-3.1.28.0.zip 2016-02-28 14:08 - 2016-02-28 14:08 - 47258812 _____ C:\Users\General Log In\Downloads\Windows6.1-KB947821-v34-x64.msu.zxduuzn.partial 2016-02-28 12:39 - 2016-02-28 12:39 - 00002988 _____ C:\windows\System32\Tasks\{4678693A-7E1D-4D5A-8B9C-88C09315D8A0} 2016-02-28 12:38 - 2016-02-28 12:40 - 00000000 ____D C:\ProgramData\SUPERSetup 2016-02-28 12:37 - 2016-02-28 12:37 - 00002048 _____ C:\Uninstall.dat 2016-02-28 09:56 - 2016-02-28 09:56 - 00000000 ____D C:\Users\General Log In\AppData\Local\GWX 2016-02-28 09:15 - 2016-02-28 09:16 - 00302011 _____ C:\Users\General Log In\Downloads\WindowsUpdateDiagnostic.diagcab 2016-02-28 06:53 - 2016-02-28 06:53 - 00058016 _____ C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT 2016-02-28 06:53 - 2016-02-28 06:53 - 00001421 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-02-28 06:53 - 2016-02-28 06:53 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Adobe 2016-02-28 06:53 - 2016-02-28 06:53 - 00000000 ____D C:\Users\Guest\AppData\Local\Power2Go8 2016-02-28 06:52 - 2016-02-28 06:53 - 00000000 ____D C:\Users\Guest 2016-02-28 06:52 - 2016-02-28 06:52 - 00000020 ___SH C:\Users\Guest\ntuser.ini 2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 _SHDL C:\Users\Guest\My Documents 2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 _SHDL C:\Users\Guest\Documents\My Videos 2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 _SHDL C:\Users\Guest\Documents\My Pictures 2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 _SHDL C:\Users\Guest\Documents\My Music 2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Intel 2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 ____D C:\Users\Guest\AppData\Roaming\EagleGet 2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 ____D C:\Users\Guest\AppData\Roaming\DigitalPersona 2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 ____D C:\Users\Guest\AppData\Local\DigitalPersona 2016-02-28 06:52 - 2015-12-12 03:32 - 00000000 ___HD C:\Users\Guest\Documents\hp.system.package.metadata 2016-02-28 06:52 - 2015-12-12 03:32 - 00000000 ___HD C:\Users\Guest\Documents\hp.applications.package.appdata 2016-02-28 06:52 - 2010-11-21 03:16 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Media Center Programs 2016-02-27 10:44 - 2016-02-27 10:44 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Macromedia 2016-02-27 09:06 - 2016-03-06 17:02 - 00003954 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{27A3E11A-B801-4AD0-9748-248E17739A1A} 2016-02-27 09:06 - 2016-03-01 15:31 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Adobe 2016-02-27 09:06 - 2016-02-27 09:06 - 00058016 _____ C:\Users\General Log In\AppData\Local\GDIPFONTCACHEV1.DAT 2016-02-27 09:06 - 2016-02-27 09:06 - 00001421 _____ C:\Users\General Log In\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-02-27 09:06 - 2016-02-27 09:06 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Hewlett-Packard 2016-02-27 09:06 - 2016-02-27 09:06 - 00000000 ____D C:\Users\General Log In\AppData\Local\Power2Go8 2016-02-27 09:05 - 2016-03-05 18:01 - 00000000 ____D C:\Users\General Log In\AppData\Local\VirtualStore 2016-02-27 09:05 - 2016-02-27 09:06 - 00000000 ____D C:\Users\General Log In 2016-02-27 09:05 - 2016-02-27 09:05 - 00000020 ___SH C:\Users\General Log In\ntuser.ini 2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 _SHDL C:\Users\General Log In\My Documents 2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 _SHDL C:\Users\General Log In\Documents\My Videos 2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 _SHDL C:\Users\General Log In\Documents\My Pictures 2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 _SHDL C:\Users\General Log In\Documents\My Music 2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Intel 2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\DigitalPersona 2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 ____D C:\Users\General Log In\AppData\Local\DigitalPersona 2016-02-27 09:05 - 2015-12-12 03:32 - 00000000 ___HD C:\Users\General Log In\Documents\hp.system.package.metadata 2016-02-27 09:05 - 2015-12-12 03:32 - 00000000 ___HD C:\Users\General Log In\Documents\hp.applications.package.appdata 2016-02-27 09:05 - 2010-11-21 03:16 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Media Center Programs 2016-02-26 14:59 - 2016-02-26 15:55 - 05236326 _____ C:\Users\Tim\Downloads\Windows6.1-KB947821-v34-x64 (1).msu.vc8llaf.partial 2016-02-25 16:52 - 2016-02-25 21:28 - 20707770 _____ C:\Users\Tim\Downloads\mpam-feX64.exe.7srche2.partial 2016-02-25 15:38 - 2016-02-25 21:19 - 23087326 _____ C:\Users\Tim\Downloads\mpam-fe.exe.ku2pm7u.partial 2016-02-24 23:25 - 2016-02-27 09:07 - 00002125 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2016-02-24 23:25 - 2016-02-27 09:07 - 00000000 ____D C:\Program Files\Microsoft Security Client 2016-02-24 23:25 - 2016-02-27 09:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2016-02-24 21:58 - 2016-02-25 22:01 - 14243008 _____ (Microsoft Corporation) C:\Users\Tim\Downloads\mseinstall.exe 2016-02-24 09:26 - 2016-02-24 17:29 - 00000000 ____D C:\Users\Tim\AppData\Local\F-Secure 2016-02-21 17:26 - 2016-02-21 17:28 - 00357932 _____ C:\Users\Tim\Downloads\Windows6.1-KB947821-v34-x64.msu.2mnrw7p.partial 2016-02-21 08:47 - 2016-02-21 08:48 - 00248048 _____ C:\Users\Tim\Downloads\es2282-adobe8.pdf 2016-02-21 07:44 - 2016-02-21 08:18 - 00000000 ____D C:\Users\Tim\AppData\Local\Deployment 2016-02-21 07:44 - 2016-02-21 07:44 - 00000000 ____D C:\Users\Tim\AppData\Local\Apps\2.0 2016-02-20 11:51 - 2016-02-20 11:51 - 00007597 _____ C:\Users\Tim\AppData\Local\Resmon.ResmonCfg 2016-02-18 10:19 - 2015-11-19 10:07 - 00994760 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2016-02-18 10:19 - 2015-11-19 10:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2016-02-18 10:18 - 2016-01-11 15:11 - 01684416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys 2016-02-17 11:37 - 2016-02-17 11:37 - 07970904 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiumdva.dll 2016-02-17 11:37 - 2016-02-17 11:37 - 07238984 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiumdag.dll 2016-02-17 11:37 - 2016-02-17 11:37 - 00159768 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiu9p64.dll 2016-02-17 11:37 - 2016-02-17 11:37 - 00119744 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atimpc64.dll 2016-02-17 11:37 - 2016-02-17 11:37 - 00119744 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdpcom64.dll 2016-02-17 11:37 - 2016-02-17 11:37 - 00102040 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atimpc32.dll 2016-02-17 11:37 - 2016-02-17 11:37 - 00102040 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdpcom32.dll 2016-02-17 11:35 - 2016-02-17 11:35 - 00148840 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdave64.dll 2016-02-17 11:35 - 2016-02-17 11:35 - 00135280 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdhcp32.dll 2016-02-17 11:35 - 2016-02-17 11:35 - 00130616 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdave32.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00874008 _____ (AMD) C:\windows\system32\coinst_15.20.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00243736 _____ C:\windows\system32\clinfo.exe 2016-02-17 11:34 - 2016-02-17 11:34 - 00161296 _____ C:\windows\system32\hsa-thunk64.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00151576 _____ C:\windows\SysWOW64\hsa-thunk.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00151064 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\mantle64.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00126488 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\mantle32.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00117776 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\mantleaxl64.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00098328 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\mantleaxl32.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00012824 _____ (Microsoft Corporation) C:\windows\system32\detoured.dll 2016-02-17 11:34 - 2016-02-17 11:34 - 00012816 _____ (Microsoft Corporation) C:\windows\SysWOW64\detoured.dll 2016-02-17 11:33 - 2016-02-17 11:33 - 25059344 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atioglxx.dll 2016-02-17 11:33 - 2016-02-17 11:33 - 00199704 _____ (AMD) C:\windows\system32\atitmm64.dll 2016-02-17 11:33 - 2016-02-17 11:33 - 00128536 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atisamu64.dll 2016-02-17 11:33 - 2016-02-17 11:33 - 00110104 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atisamu32.dll 2016-02-17 11:32 - 2016-02-17 11:32 - 30554640 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atio6axx.dll 2016-02-17 11:32 - 2016-02-17 11:32 - 21527568 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Drivers\atikmdag.sys 2016-02-17 11:32 - 2016-02-17 11:32 - 00493592 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Drivers\atikmpag.sys 2016-02-17 11:32 - 2016-02-17 11:32 - 00341528 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\ATIODE.exe 2016-02-17 11:32 - 2016-02-17 11:32 - 00059928 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\ATIODCLI.exe 2016-02-17 11:32 - 2016-02-17 11:32 - 00038424 _____ (AMD) C:\windows\system32\atimuixx.dll 2016-02-17 11:31 - 2016-02-17 11:31 - 14310936 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\aticaldd.dll 2016-02-17 11:31 - 2016-02-17 11:31 - 00451096 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atidemgy.dll 2016-02-17 11:31 - 2016-02-17 11:31 - 00219152 _____ C:\windows\system32\atieah64.exe 2016-02-17 11:31 - 2016-02-17 11:31 - 00198160 _____ C:\windows\SysWOW64\atieah32.exe 2016-02-17 11:31 - 2016-02-17 11:31 - 00166928 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atigktxx.dll 2016-02-17 11:31 - 2016-02-17 11:31 - 00114200 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atig6pxx.dll 2016-02-17 11:31 - 2016-02-17 11:31 - 00099352 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiglpxx.dll 2016-02-17 11:31 - 2016-02-17 11:31 - 00099352 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiglpxx.dll 2016-02-17 11:31 - 2016-02-17 11:31 - 00071192 _____ (Advanced Micro Devices Inc.) C:\windows\system32\aticalrt64.dll 2016-02-17 11:30 - 2016-02-17 11:30 - 00945680 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxy.dll 2016-02-17 11:30 - 2016-02-17 11:30 - 00945680 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxx.dll 2016-02-17 11:30 - 2016-02-17 11:30 - 00394256 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atiapfxx.exe 2016-02-17 11:30 - 2016-02-17 11:30 - 00064528 _____ (Advanced Micro Devices Inc.) C:\windows\system32\aticalcl64.dll 2016-02-17 11:30 - 2016-02-17 11:30 - 00057880 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\aticalcl.dll 2016-02-17 11:30 - 2016-02-17 11:30 - 00052248 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Drivers\ati2erec.dll 2016-02-17 11:29 - 2016-02-17 11:29 - 27544600 _____ (Advanced Micro Devices Inc.) C:\windows\system32\amdocl12cl64.dll 2016-02-17 11:29 - 2016-02-17 11:29 - 22327312 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\amdocl12cl.dll 2016-02-17 11:29 - 2016-02-17 11:29 - 01196064 _____ C:\windows\system32\amdocl_as64.exe 2016-02-17 11:29 - 2016-02-17 11:29 - 01070624 _____ C:\windows\system32\amdocl_ld64.exe 2016-02-17 11:29 - 2016-02-17 11:29 - 01004064 _____ C:\windows\SysWOW64\amdocl_as32.exe 2016-02-17 11:29 - 2016-02-17 11:29 - 00807456 _____ C:\windows\SysWOW64\amdocl_ld32.exe 2016-02-17 11:28 - 2016-02-17 11:28 - 39721496 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\amdocl.dll 2016-02-17 11:28 - 2016-02-17 11:28 - 06354456 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdmantle64.dll 2016-02-17 11:28 - 2016-02-17 11:28 - 05138448 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdmantle32.dll 2016-02-17 11:28 - 2016-02-17 11:28 - 00237584 _____ C:\windows\system32\amdgfxinfo64.dll 2016-02-17 11:28 - 2016-02-17 11:28 - 00059408 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdmmcl6.dll 2016-02-17 11:28 - 2016-02-17 11:28 - 00047120 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdmmcl.dll 2016-02-17 11:27 - 2016-02-17 11:27 - 00209936 _____ C:\windows\SysWOW64\amdgfxinfo32.dll 2016-02-17 11:27 - 2016-02-17 11:27 - 00068112 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll 2016-02-17 11:22 - 2016-02-17 11:22 - 15725584 _____ (Advanced Micro Devices Inc.) C:\windows\system32\aticaldd64.dll 2016-02-17 11:22 - 2016-02-17 11:22 - 00060952 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\aticalrt.dll 2016-02-17 11:21 - 2016-02-17 11:21 - 08705552 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiumd64.dll 2016-02-17 11:21 - 2016-02-17 11:21 - 00151456 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdhcp64.dll 2016-02-17 11:21 - 2016-02-17 11:21 - 00133240 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiu9pag.dll 2016-02-17 10:42 - 2016-02-17 10:42 - 00140240 _____ C:\windows\system32\samu_krnl_ci.sbin 2016-02-17 10:42 - 2016-02-17 10:42 - 00047664 _____ C:\windows\system32\kapp_ci.sbin 2016-02-17 10:42 - 2016-02-17 10:42 - 00043536 _____ C:\windows\system32\kapp_si.sbin 2016-02-17 10:41 - 2016-02-17 10:41 - 03471376 _____ C:\windows\SysWOW64\atiumdva.cap 2016-02-17 10:41 - 2016-02-17 10:41 - 03437632 _____ C:\windows\system32\atiumd6a.cap 2016-02-17 10:41 - 2016-02-17 10:41 - 00842001 _____ C:\windows\system32\amdicdxx.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00737410 _____ C:\windows\system32\atiicdxx.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00663856 _____ C:\windows\SysWOW64\atiapfxx.blb 2016-02-17 10:41 - 2016-02-17 10:41 - 00663856 _____ C:\windows\system32\atiapfxx.blb 2016-02-17 10:41 - 2016-02-17 10:41 - 00322868 _____ C:\windows\system32\ativvaxy_vi.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00321200 _____ C:\windows\system32\ativvaxy_vi_nd.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00255808 _____ C:\windows\system32\ativvaxy_cz_nd.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00250884 _____ C:\windows\system32\ativvaxy_FJ.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00249088 _____ C:\windows\system32\ativvaxy_FJ_nd.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00234420 _____ C:\windows\system32\ativvaxy_cik.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00232752 _____ C:\windows\system32\ativvaxy_cik_nd.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00177344 _____ C:\windows\system32\ativce03.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00175648 _____ C:\windows\system32\amde31a.dat 2016-02-17 10:41 - 2016-02-17 10:41 - 00100816 _____ C:\windows\system32\ativce02.dat ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-18 16:16 - 2016-01-14 09:31 - 00003910 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{6E4A02F4-3E64-41F3-896C-220F4F605540} 2016-03-18 11:44 - 2009-07-14 00:45 - 00016976 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-03-18 11:44 - 2009-07-14 00:45 - 00016976 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-03-18 03:05 - 2009-07-14 01:13 - 00781302 _____ C:\windows\system32\PerfStringBackup.INI 2016-03-18 03:05 - 2009-07-13 23:20 - 00000000 ____D C:\windows\inf 2016-03-18 02:59 - 2015-12-12 03:31 - 04580841 _____ C:\windows\SysWOW64\rootpa.e2e 2016-03-18 02:58 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2016-03-17 20:13 - 2015-12-12 03:28 - 00065536 _____ C:\windows\system32\spu_storage.bin 2016-03-17 19:32 - 2009-07-13 23:20 - 00000000 ____D C:\windows\rescache 2016-03-17 06:09 - 2015-12-12 03:40 - 00000000 ____D C:\ProgramData\Temp 2016-03-13 08:22 - 2015-12-28 16:22 - 00000000 ____D C:\Users\Tim\AppData\Local\ElevatedDiagnostics 2016-03-13 08:21 - 2016-01-04 18:26 - 03650866 _____ C:\windows\ntbtlog.txt 2016-03-11 08:29 - 2009-07-13 23:20 - 00000000 ___HD C:\windows\system32\GroupPolicy 2016-03-11 08:29 - 2009-07-13 23:20 - 00000000 ____D C:\windows\SysWOW64\GroupPolicy 2016-03-10 22:06 - 2016-01-31 19:50 - 00000000 ____D C:\windows\system32\MRT 2016-03-10 22:04 - 2016-01-31 19:50 - 143659408 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2016-03-10 06:54 - 2009-07-14 00:45 - 00267672 _____ C:\windows\system32\FNTCACHE.DAT 2016-03-09 21:52 - 2015-12-12 03:43 - 00002057 _____ C:\windows\epplauncher.mif 2016-03-09 12:07 - 2009-07-14 01:08 - 00032612 _____ C:\windows\Tasks\SCHEDLGU.TXT 2016-03-08 08:39 - 2016-01-12 07:17 - 00000000 ____D C:\windows\system32\appraiser 2016-03-07 19:32 - 2015-12-28 15:04 - 00000000 ____D C:\Users\Tim\AppData\Local\VirtualStore 2016-03-05 18:09 - 2016-01-07 08:12 - 00000000 ____D C:\Users\Tim\AppData\Local\Adobe 2016-03-04 08:56 - 2015-12-28 15:04 - 00000000 ____D C:\Users\Tim 2016-02-27 20:23 - 2016-01-04 18:26 - 00000000 ____D C:\windows\Minidump 2016-02-27 20:23 - 2015-12-28 19:59 - 00342324 ____N C:\windows\Minidump\022716-20997-01.dmp 2016-02-27 20:22 - 2009-07-13 23:20 - 00000000 ____D C:\windows\LiveKernelReports 2016-02-27 01:52 - 2015-12-12 03:39 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools 2016-02-27 01:45 - 2016-01-16 06:30 - 00000000 ____D C:\windows\system32\appmgmt 2016-02-26 16:34 - 2009-07-13 23:20 - 00000000 ____D C:\windows\tracing 2016-02-24 19:00 - 2016-01-03 06:33 - 00000000 ___SD C:\windows\SysWOW64\GWX 2016-02-24 19:00 - 2016-01-03 06:33 - 00000000 ___SD C:\windows\system32\GWX 2016-02-24 07:19 - 2009-07-13 23:20 - 00000000 ____D C:\windows\system32\NDF 2016-02-23 09:04 - 2015-12-12 03:39 - 00000000 ___HD C:\windows\system32\WLANProfiles 2016-02-23 09:04 - 2010-11-21 03:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-02-23 09:04 - 2009-07-13 23:20 - 00000000 ____D C:\windows\registration 2016-02-17 11:37 - 2014-04-02 08:06 - 08910672 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiumd6a.dll 2016-02-17 11:37 - 2014-04-02 08:06 - 00176848 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiuxp64.dll 2016-02-17 11:37 - 2014-04-02 08:06 - 00146728 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiuxpag.dll 2016-02-17 11:36 - 2014-04-02 08:06 - 09561688 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atidxx32.dll 2016-02-17 11:36 - 2014-04-02 08:06 - 01469808 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\aticfx64.dll 2016-02-17 11:36 - 2014-04-02 08:06 - 01214248 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\aticfx32.dll 2016-02-17 11:31 - 2014-04-02 06:58 - 00704536 _____ (AMD) C:\windows\system32\atieclxx.exe 2016-02-17 11:31 - 2014-04-02 06:57 - 00305176 _____ (AMD) C:\windows\system32\atiesrxx.exe 2016-02-17 11:31 - 2014-04-02 06:22 - 00193560 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atig6txx.dll 2016-02-17 11:30 - 2014-04-02 07:44 - 47793680 _____ (Advanced Micro Devices Inc.) C:\windows\system32\amdocl64.dll 2016-02-17 11:30 - 2014-04-02 06:23 - 01258000 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atiadlxx.dll 2016-02-17 11:27 - 2014-04-02 07:39 - 00073744 _____ (Khronos Group) C:\windows\system32\OpenCL.dll 2016-02-17 11:21 - 2014-04-02 08:06 - 11266224 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atidxx64.dll ==================== Files in the root of some directories ======= 2016-02-20 11:51 - 2016-02-20 11:51 - 0007597 _____ () C:\Users\Tim\AppData\Local\Resmon.ResmonCfg 2016-01-15 11:35 - 2016-01-15 11:35 - 0043158 _____ () C:\ProgramData\1452872097.bdinstall.bin 2016-01-15 11:36 - 2016-01-15 11:37 - 0040235 _____ () C:\ProgramData\1452872215.12020.bin 2016-01-15 11:37 - 2016-01-15 11:37 - 0001156 _____ () C:\ProgramData\1452872215.7672.bin 2016-01-15 17:50 - 2016-01-15 17:50 - 1409157 _____ () C:\ProgramData\1452872494.bdinstall.bin 2016-01-15 19:13 - 2016-01-15 19:13 - 0038453 _____ () C:\ProgramData\1452899595.bdinstall.bin 2016-01-15 19:13 - 2016-01-15 19:14 - 0004107 _____ () C:\ProgramData\1452899603.4068.bin 2016-01-15 19:13 - 2016-01-15 19:14 - 0027721 _____ () C:\ProgramData\1452899603.4640.bin 2016-01-15 19:13 - 2016-01-15 19:14 - 0003515 _____ () C:\ProgramData\1452899603.4652.bin 2016-01-15 19:13 - 2016-01-15 19:14 - 0039796 _____ () C:\ProgramData\1452899603.6328.bin 2016-01-15 20:08 - 2016-01-15 20:08 - 0032109 _____ () C:\ProgramData\1452902927.bdinstall.bin 2016-01-15 20:08 - 2016-01-15 20:08 - 0032109 _____ () C:\ProgramData\1452902928.bdinstall.bin 2016-01-15 20:09 - 2016-01-15 20:09 - 0032109 _____ () C:\ProgramData\1452902986.bdinstall.bin 2016-01-16 06:26 - 2016-01-16 06:27 - 0039479 _____ () C:\ProgramData\1452939960.1056.bin 2016-01-16 06:26 - 2016-01-16 06:27 - 0003977 _____ () C:\ProgramData\1452939960.172.bin 2016-01-16 06:26 - 2016-01-16 06:27 - 0003514 _____ () C:\ProgramData\1452939960.220.bin 2016-01-16 06:26 - 2016-01-16 06:27 - 0028823 _____ () C:\ProgramData\1452939960.4292.bin 2016-01-20 08:33 - 2016-01-20 08:44 - 0039603 _____ () C:\ProgramData\1453293207.4864.bin 2016-01-20 08:33 - 2016-01-20 08:33 - 0002898 _____ () C:\ProgramData\1453293207.4956.bin 2016-01-20 08:33 - 2016-01-20 08:44 - 0004110 _____ () C:\ProgramData\1453293207.4960.bin 2016-01-20 08:33 - 2016-01-20 08:33 - 0028823 _____ () C:\ProgramData\1453293207.5100.bin 2016-01-20 18:43 - 2016-01-20 18:43 - 0092523 _____ () C:\ProgramData\1453329302.bdinstall.bin 2016-01-22 08:54 - 2016-01-22 08:54 - 0091818 _____ () C:\ProgramData\1453467220.bdinstall.bin 2015-12-12 03:34 - 2015-12-12 03:36 - 8864026 _____ () C:\ProgramData\hpcsmmsilogs.log ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\SysWOW64\wininit.exe => File is digitally signed C:\windows\explorer.exe => File is digitally signed C:\windows\SysWOW64\explorer.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\SysWOW64\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\SysWOW64\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\SysWOW64\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\dnsapi.dll => File is digitally signed C:\windows\SysWOW64\dnsapi.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-03-09 13:19 ==================== End of FRST.txt ============================Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01 Ran by Tim (2016-03-18 18:45:44) Running from C:\Downloads Windows 7 Professional Service Pack 1 (X64) (2015-12-28 19:04:25) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3386813744-1969293527-735481815-500 - Administrator - Disabled) General Log In (S-1-5-21-3386813744-1969293527-735481815-1002 - Limited - Enabled) => C:\Users\General Log In Guest (S-1-5-21-3386813744-1969293527-735481815-501 - Limited - Disabled) => C:\Users\Guest Tim (S-1-5-21-3386813744-1969293527-735481815-1001 - Administrator - Enabled) => C:\Users\Tim ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95} AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.306 - Adobe Systems Incorporated) Adobe Reader 9.3 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A93000000001}) (Version: 9.3.0 - Adobe Systems Incorporated) Bejeweled 2 Deluxe (HKLM-x32\...\Bejeweled 2 Deluxe) (Version: - PopCap Games) Bejeweled Twist (HKLM-x32\...\Bejeweled Twist) (Version: - PopCap Games) CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.3.3207 - CyberLink Corp.) CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.) DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Client Security Manager (HKLM\...\HPProtectTools) (Version: 8.3.3.1786 - Hewlett-Packard Company) HP Deskjet 1000 J110 series Basic Device Software (HKLM\...\{883B114D-BD3E-498F-9DAD-5E4A8E1C43BA}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Deskjet 1000 J110 series Help (HKLM-x32\...\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard) HP Device Access Manager (HKLM\...\{DBE16A07-DDFF-4453-807A-212EF93916E0}) (Version: 8.3.2.0 - Hewlett-Packard Company) HP Documentation (HKLM-x32\...\{F7A8FF27-1B85-4C23-A6FA-97DE491ECC9A}) (Version: 1.1.0.0 - Hewlett-Packard) HP File Sanitizer (HKLM-x32\...\{6349342F-9CEF-4A70-995A-2CF3704C2603}) (Version: 8.4.20.1 - Hewlett-Packard Company) HP PageLift (HKLM-x32\...\{59202086-BEA1-411A-8AA4-A5DCD28FF537}) (Version: 1.0.13.1 - Hewlett-Packard Company) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3781 - HP Photo Creations Powered by RocketLife) HP Setup (HKLM-x32\...\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15453.4066 - Hewlett-Packard Company) HP SoftPaq Download Manager (HKLM-x32\...\{23544215-E6E6-448B-B6E9-6268D5B3E74D}) (Version: 3.5.0.0 - Hewlett-Packard Company) HP Software Setup (HKLM-x32\...\{F6D61EC9-347B-4019-9F8E-E24169F7C330}) (Version: 8.7.5 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{8C696B4B-6AB1-44BC-9416-96EAC474CABE}) (Version: 7.5.2.12 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard) HP Theft Recovery (HKLM-x32\...\InstallShield_{B1E569B6-A5EB-4C97-9F93-9ED2AA99AF0E}) (Version: 8.3.0.7 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) Intel® PROSet/Wireless Software (HKLM-x32\...\{440d014b-4444-4533-b96d-2910e1ca2bcf}) (Version: 16.7.0 - Intel Corporation) K-Lite Codec Pack 11.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.8.0 - ) LSI USB 2.0 Soft Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.102 - LSI Corporation) Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation) opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden Peggle Deluxe (HKLM-x32\...\Peggle Deluxe) (Version: - PopCap Games) Peggle Nights (HKLM-x32\...\Peggle Nights) (Version: - PopCap Games) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.85.423.2014 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7224 - Realtek Semiconductor Corp.) Skype 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.) SpywareBlaster 5.4 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.4.0 - BrightFort LLC) WOLFCODERS ScreenSnag (HKLM-x32\...\{481875AB-8D00-46D0-92E2-27BB13B20975}_is1) (Version: - WOLFCODERS) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0EAF5B38-B5E3-4853-9C3B-ABC026D20D6E} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2015-12-23] () Task: {220ECEBE-27F2-49F6-B940-105C91A5710F} - System32\Tasks\{AD6719E0-A35B-4FB0-9469-F3ECA6E98920} => F:\Setup.exe Task: {2BDFECED-24B7-4D8C-9025-C1502F04228B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe [2016-01-12] (Hewlett-Packard Company) Task: {574C1531-DEB3-4B46-87BF-D18E1D1B893E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2014-01-13] (Hewlett-Packard Company) Task: {5A8AB509-63B9-4177-8BFB-37259FE9108F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company) Task: {6ACD3DA3-8CDC-45B3-9B7A-E23AF4FD5272} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company) Task: {8773223F-C0F6-4256-B6AE-37485593ED18} - System32\Tasks\{B1BDA461-F2FB-4735-911B-8466740BEE40} => pcalua.exe -a F:\ISP5900\setup.exe -d F:\ISP5900 Task: {92A5803E-5154-441D-983A-B74D0B2F9E1B} - System32\Tasks\{4678693A-7E1D-4D5A-8B9C-88C09315D8A0} => C:\Users\General Log In\Downloads\SUPERAntiSpyware.exe Task: {A3201F91-388D-4F70-8D35-5431639892AA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2015-11-30] (Hewlett-Packard) Task: {AA37983A-6648-4778-BAA0-200079D6D06C} - System32\Tasks\HPCeeScheduleForTim => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard) Task: {C27BFDA4-CAB4-4ADA-BF3A-7685ABADCB4A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Service Update Utility => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\Service\ServiceUpdater.exe [2015-05-20] (Hewlett-Packard Company) Task: {D518CAEF-FE54-4352-840C-A96CB408FEAB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company) Task: {DF3F0AF7-6913-4840-8E0F-214B56FB6E4E} - System32\Tasks\{AC256CE6-2226-4B88-90C3-CDD2A645EA89} => F:\Setup.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\windows\Tasks\HPCeeScheduleForTim.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2014-03-31 17:28 - 2014-03-31 17:28 - 00007168 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe 2014-02-05 15:56 - 2014-02-05 15:56 - 02654936 _____ () C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\ShredContextMenu.dll 2015-12-12 03:41 - 2013-08-05 03:49 - 00627672 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2013-08-05 19:48 - 2013-08-05 19:48 - 00016856 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [134] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\peoplepc.com -> hxxp://webmail.c.peoplepc.com IE trusted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\usa4sale.net -> hxxp://contact.usa4sale.net IE trusted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\winndixie.com -> hxxps://www.winndixie.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\008i.com -> 008i.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\008k.com -> 008k.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\00hq.com -> 00hq.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0190-dialers.com -> 0190-dialers.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\01i.info -> 01i.info IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0411dd.com -> 0411dd.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0511zfhl.com -> 0511zfhl.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\05p.com -> 05p.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0632qyw.com -> 0632qyw.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0calories.net -> 0calories.net IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0cj.net -> 0cj.net IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0scan.com -> 0scan.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\1-domains-registrations.com -> 1-domains-registrations.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\1-se.com -> 1-se.com IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\1001movie.com -> 1001movie.com There are 6091 more sites. ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2016-03-05 12:28 - 2016-03-05 22:46 - 00000835 ____A C:\windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3386813744-1969293527-735481815-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 207.69.188.165 - 207.69.188.166 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe ==================== Restore Points ========================= 15-03-2016 21:11:57 Windows Update 16-03-2016 10:00:12 Windows Update 16-03-2016 20:58:16 Windows Update 17-03-2016 08:27:47 Windows Update 17-03-2016 20:12:44 Windows Update 18-03-2016 10:00:11 Windows Update ==================== Faulty Device Manager Devices ============= Name: Microsoft Virtual WiFi Miniport Adapter #2 Description: Microsoft Virtual WiFi Miniport Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (03/18/2016 10:02:30 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 10:00:34 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 10:00:28 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 08:37:59 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 08:37:56 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 08:37:56 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 08:37:50 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 08:33:50 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 08:33:50 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** Error: (03/18/2016 08:33:47 AM) (Source: flcdlock) (EventID: 1055) (User: ) Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2. The system error code is 0xe0000231:- ** The error code could not be translated ** System errors: ============= Error: (03/18/2016 04:20:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 2 time(s). Error: (03/18/2016 10:07:54 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211). Error: (03/18/2016 03:27:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 1 time(s). Error: (03/17/2016 08:13:21 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211). Error: (03/17/2016 08:28:46 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211). Error: (03/16/2016 09:00:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211). Error: (03/16/2016 10:08:00 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211). Error: (03/15/2016 09:44:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly. It has done this 1 time(s). Error: (03/15/2016 09:12:25 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY) Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211). Error: (03/15/2016 10:18:11 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %Tim-HP60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 115.40.0.0 Update Source: %Tim-HP51 Update Stage: 4.9.0218.00 Source Path: 4.9.0218.01 Signature Type: %Tim-HP602 Update Type: %Tim-HP604 User: Tim-HP\Tim Current Engine Version: %Tim-HP605 Previous Engine Version: %Tim-HP606 Error code: %Tim-HP607 Error description: %Tim-HP608 CodeIntegrity: =================================== Date: 2016-02-27 03:00:18.399 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-27 03:00:18.259 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-27 03:00:18.119 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-27 02:44:54.815 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-27 02:44:54.675 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-27 02:44:54.410 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-26 16:22:08.507 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-26 16:22:08.382 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-26 16:22:08.257 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. Date: 2016-02-26 16:22:08.117 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: AMD A8-6410 APU with AMD Radeon R5 Graphics Percentage of memory in use: 20% Total physical RAM: 7612.08 MB Available physical RAM: 6041.05 MB Total Virtual: 15222.37 MB Available Virtual: 12703.45 MB ==================== Drives ================================ Drive c: (Windows ) (Fixed) (Total:919.11 GB) (Free:866.78 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (HP_RECOVERY) (Fixed) (Total:11.3 GB) (Free:1.24 GB) NTFS ==>[system with boot components (obtained from drive)] Drive e: (HP_TOOLS) (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32 Drive f: () (CDROM) (Total:4.38 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6F9E5779) Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=919.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=11.3 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=100 MB) - (Type=0C) ==================== End of Addition.txt ============================ I could not, reply yesterday, my wife & I worked until late in our garden; Yes, there for sure, some thing going on, when I, for example try to come to this site or MBAM, I have to f5 several times, because "page can not be found" messages; Even now it's like my page will flicker, & key stroke & picture are out of synk, like being read briefly before letting it post, just saying?.. Thanks again Emeraldnzl. PS. look at picture of my ISP home page, the email has wacked out date, did You see the stuff I showed to Naat? ok here's the pic::SNAG-16031908181300.png


Edited by bonezz777, 19 March 2016 - 06:29 AM.

  • 0

#22
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

I am sorry to find Naat in the hospital, apologize for me, I didn't know, I thought Naat was mad at me?


No it's for us to apologize, unfortunately just one of those things which we don't have control over.
 

did You see the stuff I showed to Naat?


If you are referring to the e-mail pictures then yes. Looked like spam mail to me, if so, don't open them, they should be reported as spam (your e-mail spam controls I guess) and deleted. Same thing for the Cancer help one.

Turning to your logs:

Looks like something happened when you posted it... maybe you used Word or some such and it changed when it posted to the forum. Very difficult to read. It should work if you just copy and paste the logs generated by FRST - FRST.txt and Addition.txt. They use notepad which doesn't distort any formatting. Don't worry about it now though. As you are experiencing problems accessing this forum we will leave that for now.

Instead we will use another tool.

Please download ComboFix from this location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
 

  • Double click on ComboFix.exe & follow the prompts.
  • If you have an older Operating System you may be asked whether you want to install the Recovery Console. Click yes and follow any prompts.
  • Your desktop may go blank. This is normal.
  • ComboFix may appear to be doing nothing for quite long periods, this is normal, just leave it to do it's job.
  • ComboFix may reboot your machine. This is normal too.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

When finished, it will produce a log for you.  Please include the C:\ComboFix.txt in your next reply.
 


  • 0

#23
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

Hi Emeraldnzl, before I dwn load Combo.. do I turn off my protection Before I dwn load, Or after I dwn load, before I run it "Combo" , I'm guessing the latter;  here are my reports You ask for, perhaps You can see something while I'm dwn loading, it can take awhile, I'm on dial up..

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Tim (administrator) on TIM-HP (18-03-2016 18:45:13)
Running from C:\Downloads
Loaded Profiles: Tim (Available Profiles: Tim & General Log In & Guest)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpCardEngine.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Hewlett-Packard Company) C:\Windows\SysWOW64\flcdlock.exe
(Hewlett-Packard Development Company) C:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpAgent.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_20_0_0_306_ActiveX.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7570136 2014-04-14] (Realtek Semiconductor)
HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Bitdefender\Antivirus Free Edition\Install\setuplauncher.exe" /run:"C:\Program Files\Bitdefender\Antivirus Free Edition\Install\Installer.exe"
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111576 2013-08-05] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [490760 2013-08-06] (CyberLink Corp.)
HKLM-x32\...\Run: [HP File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2213592 2014-02-05] (Hewlett-Packard)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2009-12-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [948672 2009-12-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [TweakDUN] => C:\Program Files (x86)\TweakDUN\tweakdun.exe splash
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Lsa: [Notification Packages] DPPassFilter scecli

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{2F1E699D-E62A-4FF1-A81B-78F8012F36FF}: [NameServer] 207.69.188.165 207.69.188.166

Internet Explorer:
==================
HKU\S-1-5-21-3386813744-1969293527-735481815-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM14/19
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM14/19
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/19
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/19
HKU\S-1-5-21-3386813744-1969293527-735481815-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.peoplepc.com/
SearchScopes: HKU\S-1-5-21-3386813744-1969293527-735481815-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21] (Adobe Systems Incorporated)
BHO-x32: HP File Sanitizer -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2014-02-05] (Hewlett-Packard)
BHO-x32: No Name -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> No File
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
DPF: HKLM-x32 {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} hxxp://quickscan.bitdefender.com/qsax/qsax.cab

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\components\npChromeDPAgent.dll [2014-02-10] (DigitalPersona, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [dpmaxz_ng@jetpack] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome
FF Extension: HP Client Security Manager - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome [2015-12-12] [not signed]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome.crx [2014-02-10]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 CtAgentService; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [7168 2014-03-31] () [File not signed]
R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink)
R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [500048 2014-02-10] (DigitalPersona, Inc.)
R2 FLCDLOCK; c:\windows\SysWOW64\flcdlock.exe [567608 2013-11-20] (Hewlett-Packard Company)
R2 HpDamServiceHost; c:\Program Files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [18232 2013-11-15] (Hewlett-Packard Development Company)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-11-20] ()
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [79440 2015-08-14] (Advanced Micro Devices, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-12-03] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2013-11-20] (Intel® Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 amdkmcsp; C:\Windows\System32\DRIVERS\amdkmcsp.sys [114456 2015-08-14] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-13] (Advanced Micro Devices, Inc.)
R1 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [298776 2015-08-14] (Advanced Micro Devices, Inc. )
R1 CLVirtualDrive; C:\Windows\System32\DRIVERS\CLVirtualDrive.sys [90608 2011-12-27] (CyberLink)
R2 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [65752 2013-10-07] (Hewlett-Packard Company)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MODEMCSA; C:\Windows\System32\drivers\MODEMCSA.sys [24064 2009-07-13] (Microsoft Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
R3 NETwNs64; C:\Windows\System32\DRIVERS\NETwsw02.sys [3599840 2013-10-14] (Intel Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-17 08:27 - 2016-02-05 15:03 - 00147904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tpm.sys
2016-03-17 08:27 - 2016-02-05 14:56 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\tbs.dll
2016-03-17 08:27 - 2016-02-05 14:54 - 00109568 _____ (Microsoft Corporation) C:\windows\system32\fveapibase.dll
2016-03-17 08:27 - 2016-02-05 13:33 - 00015360 _____ (Microsoft Corporation) C:\windows\SysWOW64\tbs.dll
2016-03-17 08:27 - 2016-02-02 14:57 - 00511488 _____ (Microsoft Corporation) C:\windows\system32\rpcss.dll
2016-03-17 08:27 - 2015-06-03 16:21 - 00451080 _____ (Microsoft Corporation) C:\windows\system32\fveapi.dll
2016-03-17 08:25 - 2016-01-20 20:51 - 00073664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\disk.sys
2016-03-15 21:11 - 2016-02-01 15:08 - 00114624 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
2016-03-15 21:11 - 2016-02-01 14:59 - 03243008 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2016-03-15 21:11 - 2016-02-01 14:59 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
2016-03-15 21:11 - 2016-02-01 14:59 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
2016-03-15 21:11 - 2016-02-01 14:56 - 01940992 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2016-03-15 21:11 - 2016-02-01 14:56 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
2016-03-15 21:11 - 2016-02-01 14:49 - 02364928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2016-03-15 21:11 - 2016-02-01 14:49 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
2016-03-15 21:11 - 2016-02-01 14:49 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
2016-03-15 21:11 - 2016-02-01 14:45 - 01805824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2016-03-15 17:40 - 2016-03-15 21:16 - 00000324 _____ C:\windows\Tasks\HPCeeScheduleForTim.job
2016-03-15 17:40 - 2016-03-15 17:40 - 00003174 _____ C:\windows\System32\Tasks\HPCeeScheduleForTim
2016-03-15 07:08 - 2016-03-16 17:00 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2016-03-15 07:08 - 2016-03-15 07:08 - 00001087 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2016-03-15 07:08 - 2016-03-15 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2016-03-15 07:08 - 2012-05-02 11:17 - 01070152 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSCOMCTL.OCX
2016-03-15 07:08 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSSTDFMT.DLL
2016-03-15 07:04 - 2016-03-15 07:04 - 00001016 _____ C:\Users\Tim\Desktop\adwcleaner_5.102.exe - Shortcut.lnk
2016-03-14 21:27 - 2016-03-14 21:27 - 00000000 ____D C:\Program Files (x86)\Secunia
2016-03-14 09:40 - 2016-03-14 09:40 - 00001110 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-13 10:28 - 2016-03-13 10:28 - 00000924 _____ C:\Users\Tim\Desktop\FRST64.exe - Shortcut.lnk
2016-03-13 10:04 - 2016-03-13 10:28 - 00000118 _____ C:\Users\Tim\Desktop\fixlist.txt
2016-03-12 21:57 - 2016-02-09 02:53 - 00387792 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-03-12 21:57 - 2016-02-09 02:10 - 00341200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-03-12 21:57 - 2016-02-08 17:05 - 20352512 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-03-12 21:57 - 2016-02-08 16:51 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2016-03-12 21:57 - 2016-02-08 16:39 - 00496640 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-03-12 21:57 - 2016-02-08 16:39 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2016-03-12 21:57 - 2016-02-08 16:38 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2016-03-12 21:57 - 2016-02-08 16:38 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2016-03-12 21:57 - 2016-02-08 16:37 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-03-12 21:57 - 2016-02-08 16:34 - 02280448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-03-12 21:57 - 2016-02-08 16:32 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-03-12 21:57 - 2016-02-08 16:31 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2016-03-12 21:57 - 2016-02-08 16:30 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2016-03-12 21:57 - 2016-02-08 16:28 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-03-12 21:57 - 2016-02-08 16:28 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2016-03-12 21:57 - 2016-02-08 16:28 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2016-03-12 21:57 - 2016-02-08 16:20 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2016-03-12 21:57 - 2016-02-08 16:16 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-03-12 21:57 - 2016-02-08 16:15 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2016-03-12 21:57 - 2016-02-08 16:13 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2016-03-12 21:57 - 2016-02-08 16:12 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-03-12 21:57 - 2016-02-08 16:11 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-03-12 21:57 - 2016-02-08 16:10 - 04611072 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-03-12 21:57 - 2016-02-08 16:10 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2016-03-12 21:57 - 2016-02-08 16:05 - 25816576 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-03-12 21:57 - 2016-02-08 16:03 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-03-12 21:57 - 2016-02-08 16:02 - 13012480 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-03-12 21:57 - 2016-02-08 16:02 - 00687104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-03-12 21:57 - 2016-02-08 16:01 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-03-12 21:57 - 2016-02-08 16:01 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2016-03-12 21:57 - 2016-02-08 15:43 - 02121216 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-03-12 21:57 - 2016-02-08 15:39 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-03-12 21:57 - 2016-02-08 15:38 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-03-12 21:57 - 2016-02-08 14:41 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2016-03-12 21:57 - 2016-02-08 14:41 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2016-03-12 21:57 - 2016-02-08 14:27 - 02887680 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-03-12 21:57 - 2016-02-08 14:27 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2016-03-12 21:57 - 2016-02-08 14:26 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-03-12 21:57 - 2016-02-08 14:26 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2016-03-12 21:57 - 2016-02-08 14:26 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2016-03-12 21:57 - 2016-02-08 14:26 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2016-03-12 21:57 - 2016-02-08 14:19 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-03-12 21:57 - 2016-02-08 14:18 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2016-03-12 21:57 - 2016-02-08 14:16 - 06052352 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-03-12 21:57 - 2016-02-08 14:15 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2016-03-12 21:57 - 2016-02-08 14:14 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2016-03-12 21:57 - 2016-02-08 14:14 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2016-03-12 21:57 - 2016-02-08 14:13 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-03-12 21:57 - 2016-02-08 14:13 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2016-03-12 21:57 - 2016-02-08 14:06 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2016-03-12 21:57 - 2016-02-08 14:03 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2016-03-12 21:57 - 2016-02-08 13:55 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2016-03-12 21:57 - 2016-02-08 13:54 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2016-03-12 21:57 - 2016-02-08 13:52 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2016-03-12 21:57 - 2016-02-08 13:51 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-03-12 21:57 - 2016-02-08 13:49 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-03-12 21:57 - 2016-02-08 13:47 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2016-03-12 21:57 - 2016-02-08 13:37 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-03-12 21:57 - 2016-02-08 13:35 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-03-12 21:57 - 2016-02-08 13:34 - 00798720 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-03-12 21:57 - 2016-02-08 13:33 - 14613504 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-03-12 21:57 - 2016-02-08 13:33 - 02123264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-03-12 21:57 - 2016-02-08 13:33 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2016-03-12 21:57 - 2016-02-08 13:19 - 02597376 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-03-12 21:57 - 2016-02-08 13:07 - 01546752 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-03-12 21:57 - 2016-02-08 12:55 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-03-11 10:21 - 2016-03-17 18:06 - 00000000 ____D C:\Program Files (x86)\AdwCleaner
2016-03-11 09:36 - 2016-03-11 09:36 - 00000904 _____ C:\Users\Tim\Desktop\zoek.exe - Shortcut.lnk
2016-03-11 08:40 - 2016-03-11 08:40 - 00021728 _____ C:\Users\Tim\Desktop\zoek-results.txt
2016-03-10 16:46 - 2016-02-11 14:56 - 05572032 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-03-10 16:46 - 2016-02-11 14:56 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2016-03-10 16:46 - 2016-02-11 14:56 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2016-03-10 16:46 - 2016-02-11 14:52 - 01733592 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-03-10 16:46 - 2016-02-11 14:49 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2016-03-10 16:46 - 2016-02-11 14:49 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2016-03-10 16:46 - 2016-02-11 14:49 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2016-03-10 16:46 - 2016-02-11 14:49 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2016-03-10 16:46 - 2016-02-11 14:49 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2016-03-10 16:46 - 2016-02-11 14:49 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2016-03-10 16:46 - 2016-02-11 14:49 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2016-03-10 16:46 - 2016-02-11 14:49 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2016-03-10 16:46 - 2016-02-11 14:48 - 01214464 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2016-03-10 16:46 - 2016-02-11 14:48 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2016-03-10 16:46 - 2016-02-11 14:48 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2016-03-10 16:46 - 2016-02-11 14:48 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2016-03-10 16:46 - 2016-02-11 14:48 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2016-03-10 16:46 - 2016-02-11 14:47 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2016-03-10 16:46 - 2016-02-11 14:45 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-03-10 16:46 - 2016-02-11 14:45 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2016-03-10 16:46 - 2016-02-11 14:45 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2016-03-10 16:46 - 2016-02-11 14:45 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2016-03-10 16:46 - 2016-02-11 14:44 - 03994560 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2016-03-10 16:46 - 2016-02-11 14:44 - 03938240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2016-03-10 16:46 - 2016-02-11 14:44 - 01461248 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2016-03-10 16:46 - 2016-02-11 14:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2016-03-10 16:46 - 2016-02-11 14:44 - 00730112 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2016-03-10 16:46 - 2016-02-11 14:44 - 00422400 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-03-10 16:46 - 2016-02-11 14:42 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2016-03-10 16:46 - 2016-02-11 14:42 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2016-03-10 16:46 - 2016-02-11 14:42 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 01314328 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00880128 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:41 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:38 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2016-03-10 16:46 - 2016-02-11 14:38 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2016-03-10 16:46 - 2016-02-11 14:38 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-03-10 16:46 - 2016-02-11 14:38 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2016-03-10 16:46 - 2016-02-11 14:38 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2016-03-10 16:46 - 2016-02-11 14:38 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2016-03-10 16:46 - 2016-02-11 14:38 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2016-03-10 16:46 - 2016-02-11 14:37 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2016-03-10 16:46 - 2016-02-11 14:37 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2016-03-10 16:46 - 2016-02-11 14:37 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2016-03-10 16:46 - 2016-02-11 14:35 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-03-10 16:46 - 2016-02-11 14:35 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2016-03-10 16:46 - 2016-02-11 14:35 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2016-03-10 16:46 - 2016-02-11 14:34 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2016-03-10 16:46 - 2016-02-11 14:33 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2016-03-10 16:46 - 2016-02-11 14:31 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00642560 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 14:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 13:48 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2016-03-10 16:46 - 2016-02-11 13:43 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2016-03-10 16:46 - 2016-02-11 13:41 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2016-03-10 16:46 - 2016-02-11 13:40 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2016-03-10 16:46 - 2016-02-11 13:34 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-03-10 16:46 - 2016-02-11 13:34 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-03-10 16:46 - 2016-02-11 13:33 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2016-03-10 16:46 - 2016-02-11 13:32 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2016-03-10 16:46 - 2016-02-11 13:32 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2016-03-10 16:46 - 2016-02-11 13:32 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2016-03-10 16:46 - 2016-02-11 13:32 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2016-03-10 16:46 - 2016-02-11 13:32 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2016-03-10 16:46 - 2016-02-11 13:32 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2016-03-10 16:46 - 2016-02-11 13:31 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2016-03-10 16:46 - 2016-02-11 13:30 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 13:30 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 13:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-03-10 16:46 - 2016-02-11 13:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-03-10 15:53 - 2016-03-11 09:38 - 00000000 ____D C:\zoek_backup
2016-03-09 16:20 - 2016-03-18 18:45 - 00000000 ____D C:\FRST
2016-03-09 16:19 - 2016-02-04 13:52 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-03-09 16:19 - 2016-02-03 14:58 - 00862208 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
2016-03-09 16:19 - 2016-02-03 14:52 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2016-03-09 16:19 - 2016-02-03 14:49 - 00572416 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
2016-03-09 16:19 - 2016-02-03 14:43 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2016-03-09 16:19 - 2016-02-03 14:07 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2016-03-09 16:15 - 2016-02-04 21:19 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll
2016-03-09 16:15 - 2016-02-04 14:41 - 00296448 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll
2016-03-09 16:05 - 2016-02-05 14:54 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2016-03-09 16:05 - 2016-02-05 14:54 - 00041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
2016-03-09 16:05 - 2016-02-05 14:53 - 00046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2016-03-09 16:05 - 2016-02-05 14:53 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
2016-03-09 16:05 - 2016-02-05 14:50 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
2016-03-09 16:05 - 2016-02-05 14:44 - 00070656 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2016-03-09 16:05 - 2016-02-05 14:42 - 00010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
2016-03-09 16:05 - 2016-02-05 13:48 - 00372736 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2016-03-09 16:05 - 2016-02-05 13:43 - 00299520 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2016-03-09 16:05 - 2016-02-05 13:43 - 00034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2016-03-09 16:04 - 2016-02-09 05:57 - 14634496 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2016-03-09 16:04 - 2016-02-09 05:57 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2016-03-09 16:04 - 2016-02-09 05:56 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2016-03-09 16:04 - 2016-02-09 05:56 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2016-03-09 16:04 - 2016-02-09 05:55 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\seclogon.dll
2016-03-09 16:04 - 2016-02-09 05:54 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2016-03-09 16:04 - 2016-02-09 05:51 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2016-03-09 16:04 - 2016-02-09 05:51 - 11411456 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2016-03-09 16:04 - 2016-02-09 05:13 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2016-03-09 16:04 - 2016-02-09 05:13 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2016-03-09 16:04 - 2016-02-09 05:13 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2016-03-08 08:38 - 2016-02-19 15:02 - 00038336 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2016-03-08 08:38 - 2016-02-19 14:54 - 01168896 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-03-08 08:38 - 2016-02-19 10:07 - 01373184 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2016-03-08 08:38 - 2016-02-11 10:07 - 00689152 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-03-08 08:38 - 2016-02-05 10:07 - 00696832 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-03-08 08:38 - 2016-02-05 10:07 - 00499200 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-03-08 08:38 - 2016-02-05 10:07 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2016-03-07 19:31 - 2016-03-07 19:31 - 00001026 _____ C:\Users\Public\Desktop\WOLFCODERS ScreenSnag.lnk
2016-03-07 19:31 - 2016-03-07 19:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WOLFCODERS ScreenSnag
2016-03-07 19:31 - 2016-03-07 19:31 - 00000000 ____D C:\Program Files (x86)\WOLFCODERS ScreenSnag
2016-03-07 11:16 - 2016-03-07 16:06 - 23807881 _____ C:\Users\Tim\Downloads\mpas-fe.exe.26wgabc.partial
2016-03-07 11:07 - 2016-03-07 16:06 - 23800577 _____ C:\Users\Tim\Downloads\mpam-fe (1).exe.erzic1p.partial
2016-03-05 18:06 - 2016-03-09 11:18 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Free Download Manager
2016-03-05 18:06 - 2016-03-05 18:06 - 00001331 _____ C:\Users\General Log In\Desktop\Free Download Manager.lnk
2016-03-05 12:28 - 2016-03-05 12:28 - 00000673 _____ C:\windows\system32\Drivers\etc\hosts.bak
2016-03-05 12:19 - 2000-05-22 01:00 - 00140488 _____ (Microsoft Corporation) C:\windows\SysWOW64\Comdlg32.ocx
2016-03-05 12:19 - 2000-05-22 01:00 - 00115920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Msinet.ocx
2016-03-05 11:24 - 2016-03-05 11:24 - 00000000 ____D C:\Users\Tim\AppData\LocalLow\Oracle
2016-03-05 11:17 - 2016-03-05 11:23 - 00735328 _____ (Oracle Corporation) C:\Users\General Log In\Downloads\JavaSetup8u73.exe
2016-03-05 09:54 - 2016-03-05 14:03 - 00796864 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-03-05 09:54 - 2016-03-05 14:03 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-05 09:54 - 2016-03-05 09:54 - 00000000 ____D C:\windows\system32\Macromed
2016-03-05 07:18 - 2016-03-05 07:58 - 02735752 _____ C:\Users\General Log In\Downloads\install_flash_player_18_active_x.exe.ibz20af.partial
2016-03-04 09:07 - 2016-03-04 09:07 - 00000000 ____D C:\Users\General Log In\AppData\Local\DigitalPersona,_Inc
2016-03-02 22:08 - 2016-02-12 14:52 - 03169792 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2016-03-02 22:08 - 2016-02-12 14:52 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2016-03-02 22:08 - 2016-02-12 14:52 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2016-03-02 22:08 - 2016-02-12 14:44 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2016-03-02 22:08 - 2016-02-12 14:39 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2016-03-02 22:08 - 2016-02-12 14:22 - 02610688 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2016-03-02 22:08 - 2016-02-12 14:19 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2016-03-02 22:08 - 2016-02-12 14:18 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2016-03-02 22:08 - 2016-02-12 14:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2016-03-02 22:08 - 2016-02-12 14:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2016-03-02 22:08 - 2016-02-12 14:18 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2016-03-02 22:08 - 2016-02-12 14:18 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2016-03-02 22:08 - 2016-02-12 14:06 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2016-03-02 22:08 - 2016-02-12 14:05 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2016-03-02 22:08 - 2016-02-12 14:05 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2016-03-02 22:08 - 2016-02-12 14:05 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2016-03-01 15:32 - 1999-10-10 16:48 - 00206700 ____R C:\Users\General Log In\Downloads\_SETUP.LIB
2016-03-01 15:31 - 2016-03-05 18:09 - 00000000 ____D C:\Users\General Log In\AppData\Local\Adobe
2016-03-01 14:15 - 2016-03-01 14:15 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\FreeDownloadManager.ORG
2016-03-01 14:15 - 2016-03-01 14:15 - 00000000 ____D C:\Users\General Log In\AppData\Local\Free Download Manager
2016-03-01 14:15 - 2016-03-01 14:15 - 00000000 ____D C:\ProgramData\FreeDownloadManager.ORG
2016-03-01 14:15 - 2016-03-01 14:15 - 00000000 ____D C:\ProgramData\Free Download Manager
2016-02-29 17:53 - 2016-03-18 07:32 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-02-29 17:53 - 2016-03-14 09:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-02-29 17:52 - 2016-03-14 09:40 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-29 17:52 - 2016-02-29 17:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-02-29 17:52 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-02-29 17:52 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-02-29 16:09 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-02-29 16:06 - 2016-02-29 16:06 - 00000000 ____D C:\Users\General Log In\Downloads\mbam-chameleon-3.1.28.0
2016-02-29 15:39 - 2016-02-29 16:05 - 06392130 _____ C:\Users\General Log In\Downloads\mbam-chameleon-3.1.28.0.zip
2016-02-28 14:08 - 2016-02-28 14:08 - 47258812 _____ C:\Users\General Log In\Downloads\Windows6.1-KB947821-v34-x64.msu.zxduuzn.partial
2016-02-28 12:39 - 2016-02-28 12:39 - 00002988 _____ C:\windows\System32\Tasks\{4678693A-7E1D-4D5A-8B9C-88C09315D8A0}
2016-02-28 12:38 - 2016-02-28 12:40 - 00000000 ____D C:\ProgramData\SUPERSetup
2016-02-28 12:37 - 2016-02-28 12:37 - 00002048 _____ C:\Uninstall.dat
2016-02-28 09:56 - 2016-02-28 09:56 - 00000000 ____D C:\Users\General Log In\AppData\Local\GWX
2016-02-28 09:15 - 2016-02-28 09:16 - 00302011 _____ C:\Users\General Log In\Downloads\WindowsUpdateDiagnostic.diagcab
2016-02-28 06:53 - 2016-02-28 06:53 - 00058016 _____ C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2016-02-28 06:53 - 2016-02-28 06:53 - 00001421 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-02-28 06:53 - 2016-02-28 06:53 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Adobe
2016-02-28 06:53 - 2016-02-28 06:53 - 00000000 ____D C:\Users\Guest\AppData\Local\Power2Go8
2016-02-28 06:52 - 2016-02-28 06:53 - 00000000 ____D C:\Users\Guest
2016-02-28 06:52 - 2016-02-28 06:52 - 00000020 ___SH C:\Users\Guest\ntuser.ini
2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 _SHDL C:\Users\Guest\My Documents
2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 _SHDL C:\Users\Guest\Documents\My Videos
2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 _SHDL C:\Users\Guest\Documents\My Pictures
2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 _SHDL C:\Users\Guest\Documents\My Music
2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Intel
2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 ____D C:\Users\Guest\AppData\Roaming\EagleGet
2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 ____D C:\Users\Guest\AppData\Roaming\DigitalPersona
2016-02-28 06:52 - 2016-02-28 06:52 - 00000000 ____D C:\Users\Guest\AppData\Local\DigitalPersona
2016-02-28 06:52 - 2015-12-12 03:32 - 00000000 ___HD C:\Users\Guest\Documents\hp.system.package.metadata
2016-02-28 06:52 - 2015-12-12 03:32 - 00000000 ___HD C:\Users\Guest\Documents\hp.applications.package.appdata
2016-02-28 06:52 - 2010-11-21 03:16 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Media Center Programs
2016-02-27 10:44 - 2016-02-27 10:44 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Macromedia
2016-02-27 09:06 - 2016-03-06 17:02 - 00003954 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{27A3E11A-B801-4AD0-9748-248E17739A1A}
2016-02-27 09:06 - 2016-03-01 15:31 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Adobe
2016-02-27 09:06 - 2016-02-27 09:06 - 00058016 _____ C:\Users\General Log In\AppData\Local\GDIPFONTCACHEV1.DAT
2016-02-27 09:06 - 2016-02-27 09:06 - 00001421 _____ C:\Users\General Log In\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-02-27 09:06 - 2016-02-27 09:06 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Hewlett-Packard
2016-02-27 09:06 - 2016-02-27 09:06 - 00000000 ____D C:\Users\General Log In\AppData\Local\Power2Go8
2016-02-27 09:05 - 2016-03-05 18:01 - 00000000 ____D C:\Users\General Log In\AppData\Local\VirtualStore
2016-02-27 09:05 - 2016-02-27 09:06 - 00000000 ____D C:\Users\General Log In
2016-02-27 09:05 - 2016-02-27 09:05 - 00000020 ___SH C:\Users\General Log In\ntuser.ini
2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 _SHDL C:\Users\General Log In\My Documents
2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 _SHDL C:\Users\General Log In\Documents\My Videos
2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 _SHDL C:\Users\General Log In\Documents\My Pictures
2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 _SHDL C:\Users\General Log In\Documents\My Music
2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Intel
2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\DigitalPersona
2016-02-27 09:05 - 2016-02-27 09:05 - 00000000 ____D C:\Users\General Log In\AppData\Local\DigitalPersona
2016-02-27 09:05 - 2015-12-12 03:32 - 00000000 ___HD C:\Users\General Log In\Documents\hp.system.package.metadata
2016-02-27 09:05 - 2015-12-12 03:32 - 00000000 ___HD C:\Users\General Log In\Documents\hp.applications.package.appdata
2016-02-27 09:05 - 2010-11-21 03:16 - 00000000 ____D C:\Users\General Log In\AppData\Roaming\Media Center Programs
2016-02-26 14:59 - 2016-02-26 15:55 - 05236326 _____ C:\Users\Tim\Downloads\Windows6.1-KB947821-v34-x64 (1).msu.vc8llaf.partial
2016-02-25 16:52 - 2016-02-25 21:28 - 20707770 _____ C:\Users\Tim\Downloads\mpam-feX64.exe.7srche2.partial
2016-02-25 15:38 - 2016-02-25 21:19 - 23087326 _____ C:\Users\Tim\Downloads\mpam-fe.exe.ku2pm7u.partial
2016-02-24 23:25 - 2016-02-27 09:07 - 00002125 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2016-02-24 23:25 - 2016-02-27 09:07 - 00000000 ____D C:\Program Files\Microsoft Security Client
2016-02-24 23:25 - 2016-02-27 09:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2016-02-24 21:58 - 2016-02-25 22:01 - 14243008 _____ (Microsoft Corporation) C:\Users\Tim\Downloads\mseinstall.exe
2016-02-24 09:26 - 2016-02-24 17:29 - 00000000 ____D C:\Users\Tim\AppData\Local\F-Secure
2016-02-21 17:26 - 2016-02-21 17:28 - 00357932 _____ C:\Users\Tim\Downloads\Windows6.1-KB947821-v34-x64.msu.2mnrw7p.partial
2016-02-21 08:47 - 2016-02-21 08:48 - 00248048 _____ C:\Users\Tim\Downloads\es2282-adobe8.pdf
2016-02-21 07:44 - 2016-02-21 08:18 - 00000000 ____D C:\Users\Tim\AppData\Local\Deployment
2016-02-21 07:44 - 2016-02-21 07:44 - 00000000 ____D C:\Users\Tim\AppData\Local\Apps\2.0
2016-02-20 11:51 - 2016-02-20 11:51 - 00007597 _____ C:\Users\Tim\AppData\Local\Resmon.ResmonCfg
2016-02-18 10:19 - 2015-11-19 10:07 - 00994760 _____ (Microsoft Corporation) C:\windows\system32\ucrtbase.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00063840 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-private-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00020832 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00019808 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00017760 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00016224 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00015712 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00014176 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00013664 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-process-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00012640 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00012128 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l2-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:07 - 00011616 _____ (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-2-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00922432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ucrtbase.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00066400 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00022368 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00019808 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00017760 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00016224 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00015712 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00014176 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00013664 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00012640 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00012128 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2016-02-18 10:19 - 2015-11-19 10:06 - 00011616 _____ (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2016-02-18 10:18 - 2016-01-11 15:11 - 01684416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2016-02-17 11:37 - 2016-02-17 11:37 - 07970904 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiumdva.dll
2016-02-17 11:37 - 2016-02-17 11:37 - 07238984 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiumdag.dll
2016-02-17 11:37 - 2016-02-17 11:37 - 00159768 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiu9p64.dll
2016-02-17 11:37 - 2016-02-17 11:37 - 00119744 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atimpc64.dll
2016-02-17 11:37 - 2016-02-17 11:37 - 00119744 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdpcom64.dll
2016-02-17 11:37 - 2016-02-17 11:37 - 00102040 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atimpc32.dll
2016-02-17 11:37 - 2016-02-17 11:37 - 00102040 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdpcom32.dll
2016-02-17 11:35 - 2016-02-17 11:35 - 00148840 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdave64.dll
2016-02-17 11:35 - 2016-02-17 11:35 - 00135280 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\amdhcp32.dll
2016-02-17 11:35 - 2016-02-17 11:35 - 00130616 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdave32.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00874008 _____ (AMD) C:\windows\system32\coinst_15.20.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00243736 _____ C:\windows\system32\clinfo.exe
2016-02-17 11:34 - 2016-02-17 11:34 - 00161296 _____ C:\windows\system32\hsa-thunk64.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00151576 _____ C:\windows\SysWOW64\hsa-thunk.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00151064 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\mantle64.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00126488 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\mantle32.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00117776 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\mantleaxl64.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00098328 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\mantleaxl32.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00012824 _____ (Microsoft Corporation) C:\windows\system32\detoured.dll
2016-02-17 11:34 - 2016-02-17 11:34 - 00012816 _____ (Microsoft Corporation) C:\windows\SysWOW64\detoured.dll
2016-02-17 11:33 - 2016-02-17 11:33 - 25059344 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atioglxx.dll
2016-02-17 11:33 - 2016-02-17 11:33 - 00199704 _____ (AMD) C:\windows\system32\atitmm64.dll
2016-02-17 11:33 - 2016-02-17 11:33 - 00128536 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atisamu64.dll
2016-02-17 11:33 - 2016-02-17 11:33 - 00110104 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atisamu32.dll
2016-02-17 11:32 - 2016-02-17 11:32 - 30554640 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atio6axx.dll
2016-02-17 11:32 - 2016-02-17 11:32 - 21527568 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Drivers\atikmdag.sys
2016-02-17 11:32 - 2016-02-17 11:32 - 00493592 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Drivers\atikmpag.sys
2016-02-17 11:32 - 2016-02-17 11:32 - 00341528 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\ATIODE.exe
2016-02-17 11:32 - 2016-02-17 11:32 - 00059928 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\ATIODCLI.exe
2016-02-17 11:32 - 2016-02-17 11:32 - 00038424 _____ (AMD) C:\windows\system32\atimuixx.dll
2016-02-17 11:31 - 2016-02-17 11:31 - 14310936 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\aticaldd.dll
2016-02-17 11:31 - 2016-02-17 11:31 - 00451096 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atidemgy.dll
2016-02-17 11:31 - 2016-02-17 11:31 - 00219152 _____ C:\windows\system32\atieah64.exe
2016-02-17 11:31 - 2016-02-17 11:31 - 00198160 _____ C:\windows\SysWOW64\atieah32.exe
2016-02-17 11:31 - 2016-02-17 11:31 - 00166928 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atigktxx.dll
2016-02-17 11:31 - 2016-02-17 11:31 - 00114200 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atig6pxx.dll
2016-02-17 11:31 - 2016-02-17 11:31 - 00099352 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiglpxx.dll
2016-02-17 11:31 - 2016-02-17 11:31 - 00099352 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiglpxx.dll
2016-02-17 11:31 - 2016-02-17 11:31 - 00071192 _____ (Advanced Micro Devices Inc.) C:\windows\system32\aticalrt64.dll
2016-02-17 11:30 - 2016-02-17 11:30 - 00945680 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxy.dll
2016-02-17 11:30 - 2016-02-17 11:30 - 00945680 _____ (Advanced Micro Devices, Inc.) C:\windows\SysWOW64\atiadlxx.dll
2016-02-17 11:30 - 2016-02-17 11:30 - 00394256 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atiapfxx.exe
2016-02-17 11:30 - 2016-02-17 11:30 - 00064528 _____ (Advanced Micro Devices Inc.) C:\windows\system32\aticalcl64.dll
2016-02-17 11:30 - 2016-02-17 11:30 - 00057880 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\aticalcl.dll
2016-02-17 11:30 - 2016-02-17 11:30 - 00052248 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\Drivers\ati2erec.dll
2016-02-17 11:29 - 2016-02-17 11:29 - 27544600 _____ (Advanced Micro Devices Inc.) C:\windows\system32\amdocl12cl64.dll
2016-02-17 11:29 - 2016-02-17 11:29 - 22327312 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\amdocl12cl.dll
2016-02-17 11:29 - 2016-02-17 11:29 - 01196064 _____ C:\windows\system32\amdocl_as64.exe
2016-02-17 11:29 - 2016-02-17 11:29 - 01070624 _____ C:\windows\system32\amdocl_ld64.exe
2016-02-17 11:29 - 2016-02-17 11:29 - 01004064 _____ C:\windows\SysWOW64\amdocl_as32.exe
2016-02-17 11:29 - 2016-02-17 11:29 - 00807456 _____ C:\windows\SysWOW64\amdocl_ld32.exe
2016-02-17 11:28 - 2016-02-17 11:28 - 39721496 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\amdocl.dll
2016-02-17 11:28 - 2016-02-17 11:28 - 06354456 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdmantle64.dll
2016-02-17 11:28 - 2016-02-17 11:28 - 05138448 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdmantle32.dll
2016-02-17 11:28 - 2016-02-17 11:28 - 00237584 _____ C:\windows\system32\amdgfxinfo64.dll
2016-02-17 11:28 - 2016-02-17 11:28 - 00059408 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\amdmmcl6.dll
2016-02-17 11:28 - 2016-02-17 11:28 - 00047120 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\amdmmcl.dll
2016-02-17 11:27 - 2016-02-17 11:27 - 00209936 _____ C:\windows\SysWOW64\amdgfxinfo32.dll
2016-02-17 11:27 - 2016-02-17 11:27 - 00068112 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2016-02-17 11:22 - 2016-02-17 11:22 - 15725584 _____ (Advanced Micro Devices Inc.) C:\windows\system32\aticaldd64.dll
2016-02-17 11:22 - 2016-02-17 11:22 - 00060952 _____ (Advanced Micro Devices Inc.) C:\windows\SysWOW64\aticalrt.dll
2016-02-17 11:21 - 2016-02-17 11:21 - 08705552 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiumd64.dll
2016-02-17 11:21 - 2016-02-17 11:21 - 00151456 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\amdhcp64.dll
2016-02-17 11:21 - 2016-02-17 11:21 - 00133240 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiu9pag.dll
2016-02-17 10:42 - 2016-02-17 10:42 - 00140240 _____ C:\windows\system32\samu_krnl_ci.sbin
2016-02-17 10:42 - 2016-02-17 10:42 - 00047664 _____ C:\windows\system32\kapp_ci.sbin
2016-02-17 10:42 - 2016-02-17 10:42 - 00043536 _____ C:\windows\system32\kapp_si.sbin
2016-02-17 10:41 - 2016-02-17 10:41 - 03471376 _____ C:\windows\SysWOW64\atiumdva.cap
2016-02-17 10:41 - 2016-02-17 10:41 - 03437632 _____ C:\windows\system32\atiumd6a.cap
2016-02-17 10:41 - 2016-02-17 10:41 - 00842001 _____ C:\windows\system32\amdicdxx.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00737410 _____ C:\windows\system32\atiicdxx.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00663856 _____ C:\windows\SysWOW64\atiapfxx.blb
2016-02-17 10:41 - 2016-02-17 10:41 - 00663856 _____ C:\windows\system32\atiapfxx.blb
2016-02-17 10:41 - 2016-02-17 10:41 - 00322868 _____ C:\windows\system32\ativvaxy_vi.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00321200 _____ C:\windows\system32\ativvaxy_vi_nd.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00255808 _____ C:\windows\system32\ativvaxy_cz_nd.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00250884 _____ C:\windows\system32\ativvaxy_FJ.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00249088 _____ C:\windows\system32\ativvaxy_FJ_nd.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00234420 _____ C:\windows\system32\ativvaxy_cik.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00232752 _____ C:\windows\system32\ativvaxy_cik_nd.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00177344 _____ C:\windows\system32\ativce03.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00175648 _____ C:\windows\system32\amde31a.dat
2016-02-17 10:41 - 2016-02-17 10:41 - 00100816 _____ C:\windows\system32\ativce02.dat

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-18 16:16 - 2016-01-14 09:31 - 00003910 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{6E4A02F4-3E64-41F3-896C-220F4F605540}
2016-03-18 11:44 - 2009-07-14 00:45 - 00016976 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-18 11:44 - 2009-07-14 00:45 - 00016976 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-18 03:05 - 2009-07-14 01:13 - 00781302 _____ C:\windows\system32\PerfStringBackup.INI
2016-03-18 03:05 - 2009-07-13 23:20 - 00000000 ____D C:\windows\inf
2016-03-18 02:59 - 2015-12-12 03:31 - 04580841 _____ C:\windows\SysWOW64\rootpa.e2e
2016-03-18 02:58 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-03-17 20:13 - 2015-12-12 03:28 - 00065536 _____ C:\windows\system32\spu_storage.bin
2016-03-17 19:32 - 2009-07-13 23:20 - 00000000 ____D C:\windows\rescache
2016-03-17 06:09 - 2015-12-12 03:40 - 00000000 ____D C:\ProgramData\Temp
2016-03-13 08:22 - 2015-12-28 16:22 - 00000000 ____D C:\Users\Tim\AppData\Local\ElevatedDiagnostics
2016-03-13 08:21 - 2016-01-04 18:26 - 03650866 _____ C:\windows\ntbtlog.txt
2016-03-11 08:29 - 2009-07-13 23:20 - 00000000 ___HD C:\windows\system32\GroupPolicy
2016-03-11 08:29 - 2009-07-13 23:20 - 00000000 ____D C:\windows\SysWOW64\GroupPolicy
2016-03-10 22:06 - 2016-01-31 19:50 - 00000000 ____D C:\windows\system32\MRT
2016-03-10 22:04 - 2016-01-31 19:50 - 143659408 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-03-10 06:54 - 2009-07-14 00:45 - 00267672 _____ C:\windows\system32\FNTCACHE.DAT
2016-03-09 21:52 - 2015-12-12 03:43 - 00002057 _____ C:\windows\epplauncher.mif
2016-03-09 12:07 - 2009-07-14 01:08 - 00032612 _____ C:\windows\Tasks\SCHEDLGU.TXT
2016-03-08 08:39 - 2016-01-12 07:17 - 00000000 ____D C:\windows\system32\appraiser
2016-03-07 19:32 - 2015-12-28 15:04 - 00000000 ____D C:\Users\Tim\AppData\Local\VirtualStore
2016-03-05 18:09 - 2016-01-07 08:12 - 00000000 ____D C:\Users\Tim\AppData\Local\Adobe
2016-03-04 08:56 - 2015-12-28 15:04 - 00000000 ____D C:\Users\Tim
2016-02-27 20:23 - 2016-01-04 18:26 - 00000000 ____D C:\windows\Minidump
2016-02-27 20:23 - 2015-12-28 19:59 - 00342324 ____N C:\windows\Minidump\022716-20997-01.dmp
2016-02-27 20:22 - 2009-07-13 23:20 - 00000000 ____D C:\windows\LiveKernelReports
2016-02-27 01:52 - 2015-12-12 03:39 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2016-02-27 01:45 - 2016-01-16 06:30 - 00000000 ____D C:\windows\system32\appmgmt
2016-02-26 16:34 - 2009-07-13 23:20 - 00000000 ____D C:\windows\tracing
2016-02-24 19:00 - 2016-01-03 06:33 - 00000000 ___SD C:\windows\SysWOW64\GWX
2016-02-24 19:00 - 2016-01-03 06:33 - 00000000 ___SD C:\windows\system32\GWX
2016-02-24 07:19 - 2009-07-13 23:20 - 00000000 ____D C:\windows\system32\NDF
2016-02-23 09:04 - 2015-12-12 03:39 - 00000000 ___HD C:\windows\system32\WLANProfiles
2016-02-23 09:04 - 2010-11-21 03:16 - 00000000 ___RD C:\Users\Public\Recorded TV
2016-02-23 09:04 - 2009-07-13 23:20 - 00000000 ____D C:\windows\registration
2016-02-17 11:37 - 2014-04-02 08:06 - 08910672 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiumd6a.dll
2016-02-17 11:37 - 2014-04-02 08:06 - 00176848 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atiuxp64.dll
2016-02-17 11:37 - 2014-04-02 08:06 - 00146728 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atiuxpag.dll
2016-02-17 11:36 - 2014-04-02 08:06 - 09561688 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\atidxx32.dll
2016-02-17 11:36 - 2014-04-02 08:06 - 01469808 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\aticfx64.dll
2016-02-17 11:36 - 2014-04-02 08:06 - 01214248 _____ (Advanced Micro Devices, Inc. ) C:\windows\SysWOW64\aticfx32.dll
2016-02-17 11:31 - 2014-04-02 06:58 - 00704536 _____ (AMD) C:\windows\system32\atieclxx.exe
2016-02-17 11:31 - 2014-04-02 06:57 - 00305176 _____ (AMD) C:\windows\system32\atiesrxx.exe
2016-02-17 11:31 - 2014-04-02 06:22 - 00193560 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atig6txx.dll
2016-02-17 11:30 - 2014-04-02 07:44 - 47793680 _____ (Advanced Micro Devices Inc.) C:\windows\system32\amdocl64.dll
2016-02-17 11:30 - 2014-04-02 06:23 - 01258000 _____ (Advanced Micro Devices, Inc.) C:\windows\system32\atiadlxx.dll
2016-02-17 11:27 - 2014-04-02 07:39 - 00073744 _____ (Khronos Group) C:\windows\system32\OpenCL.dll
2016-02-17 11:21 - 2014-04-02 08:06 - 11266224 _____ (Advanced Micro Devices, Inc. ) C:\windows\system32\atidxx64.dll

==================== Files in the root of some directories =======

2016-02-20 11:51 - 2016-02-20 11:51 - 0007597 _____ () C:\Users\Tim\AppData\Local\Resmon.ResmonCfg
2016-01-15 11:35 - 2016-01-15 11:35 - 0043158 _____ () C:\ProgramData\1452872097.bdinstall.bin
2016-01-15 11:36 - 2016-01-15 11:37 - 0040235 _____ () C:\ProgramData\1452872215.12020.bin
2016-01-15 11:37 - 2016-01-15 11:37 - 0001156 _____ () C:\ProgramData\1452872215.7672.bin
2016-01-15 17:50 - 2016-01-15 17:50 - 1409157 _____ () C:\ProgramData\1452872494.bdinstall.bin
2016-01-15 19:13 - 2016-01-15 19:13 - 0038453 _____ () C:\ProgramData\1452899595.bdinstall.bin
2016-01-15 19:13 - 2016-01-15 19:14 - 0004107 _____ () C:\ProgramData\1452899603.4068.bin
2016-01-15 19:13 - 2016-01-15 19:14 - 0027721 _____ () C:\ProgramData\1452899603.4640.bin
2016-01-15 19:13 - 2016-01-15 19:14 - 0003515 _____ () C:\ProgramData\1452899603.4652.bin
2016-01-15 19:13 - 2016-01-15 19:14 - 0039796 _____ () C:\ProgramData\1452899603.6328.bin
2016-01-15 20:08 - 2016-01-15 20:08 - 0032109 _____ () C:\ProgramData\1452902927.bdinstall.bin
2016-01-15 20:08 - 2016-01-15 20:08 - 0032109 _____ () C:\ProgramData\1452902928.bdinstall.bin
2016-01-15 20:09 - 2016-01-15 20:09 - 0032109 _____ () C:\ProgramData\1452902986.bdinstall.bin
2016-01-16 06:26 - 2016-01-16 06:27 - 0039479 _____ () C:\ProgramData\1452939960.1056.bin
2016-01-16 06:26 - 2016-01-16 06:27 - 0003977 _____ () C:\ProgramData\1452939960.172.bin
2016-01-16 06:26 - 2016-01-16 06:27 - 0003514 _____ () C:\ProgramData\1452939960.220.bin
2016-01-16 06:26 - 2016-01-16 06:27 - 0028823 _____ () C:\ProgramData\1452939960.4292.bin
2016-01-20 08:33 - 2016-01-20 08:44 - 0039603 _____ () C:\ProgramData\1453293207.4864.bin
2016-01-20 08:33 - 2016-01-20 08:33 - 0002898 _____ () C:\ProgramData\1453293207.4956.bin
2016-01-20 08:33 - 2016-01-20 08:44 - 0004110 _____ () C:\ProgramData\1453293207.4960.bin
2016-01-20 08:33 - 2016-01-20 08:33 - 0028823 _____ () C:\ProgramData\1453293207.5100.bin
2016-01-20 18:43 - 2016-01-20 18:43 - 0092523 _____ () C:\ProgramData\1453329302.bdinstall.bin
2016-01-22 08:54 - 2016-01-22 08:54 - 0091818 _____ () C:\ProgramData\1453467220.bdinstall.bin
2015-12-12 03:34 - 2015-12-12 03:36 - 8864026 _____ () C:\ProgramData\hpcsmmsilogs.log

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-03-09 13:19

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Tim (2016-03-18 18:45:44)
Running from C:\Downloads
Windows 7 Professional Service Pack 1 (X64) (2015-12-28 19:04:25)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-3386813744-1969293527-735481815-500 - Administrator - Disabled)
General Log In (S-1-5-21-3386813744-1969293527-735481815-1002 - Limited - Enabled) => C:\Users\General Log In
Guest (S-1-5-21-3386813744-1969293527-735481815-501 - Limited - Disabled) => C:\Users\Guest
Tim (S-1-5-21-3386813744-1969293527-735481815-1001 - Administrator - Enabled) => C:\Users\Tim

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Adobe Reader 9.3 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A93000000001}) (Version: 9.3.0 - Adobe Systems Incorporated)
Bejeweled 2 Deluxe (HKLM-x32\...\Bejeweled 2 Deluxe) (Version:  - PopCap Games)
Bejeweled Twist (HKLM-x32\...\Bejeweled Twist) (Version:  - PopCap Games)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.3.3207 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.)
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Client Security Manager (HKLM\...\HPProtectTools) (Version: 8.3.3.1786 - Hewlett-Packard Company)
HP Deskjet 1000 J110 series Basic Device Software (HKLM\...\{883B114D-BD3E-498F-9DAD-5E4A8E1C43BA}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 1000 J110 series Help (HKLM-x32\...\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard)
HP Device Access Manager (HKLM\...\{DBE16A07-DDFF-4453-807A-212EF93916E0}) (Version: 8.3.2.0 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{F7A8FF27-1B85-4C23-A6FA-97DE491ECC9A}) (Version: 1.1.0.0 - Hewlett-Packard)
HP File Sanitizer (HKLM-x32\...\{6349342F-9CEF-4A70-995A-2CF3704C2603}) (Version: 8.4.20.1 - Hewlett-Packard Company)
HP PageLift (HKLM-x32\...\{59202086-BEA1-411A-8AA4-A5DCD28FF537}) (Version: 1.0.13.1 - Hewlett-Packard Company)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3781 - HP Photo Creations Powered by RocketLife)
HP Setup (HKLM-x32\...\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15453.4066 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{23544215-E6E6-448B-B6E9-6268D5B3E74D}) (Version: 3.5.0.0 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{F6D61EC9-347B-4019-9F8E-E24169F7C330}) (Version: 8.7.5 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{8C696B4B-6AB1-44BC-9416-96EAC474CABE}) (Version: 7.5.2.12 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
HP Theft Recovery (HKLM-x32\...\InstallShield_{B1E569B6-A5EB-4C97-9F93-9ED2AA99AF0E}) (Version: 8.3.0.7 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)
Intel® PROSet/Wireless Software (HKLM-x32\...\{440d014b-4444-4533-b96d-2910e1ca2bcf}) (Version: 16.7.0 - Intel Corporation)
K-Lite Codec Pack 11.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.8.0 - )
LSI USB 2.0 Soft Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.102 - LSI Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
Peggle Deluxe (HKLM-x32\...\Peggle Deluxe) (Version:  - PopCap Games)
Peggle Nights (HKLM-x32\...\Peggle Nights) (Version:  - PopCap Games)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.85.423.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7224 - Realtek Semiconductor Corp.)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SpywareBlaster 5.4 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.4.0 - BrightFort LLC)
WOLFCODERS ScreenSnag (HKLM-x32\...\{481875AB-8D00-46D0-92E2-27BB13B20975}_is1) (Version:  - WOLFCODERS)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0EAF5B38-B5E3-4853-9C3B-ABC026D20D6E} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2015-12-23] ()
Task: {220ECEBE-27F2-49F6-B940-105C91A5710F} - System32\Tasks\{AD6719E0-A35B-4FB0-9469-F3ECA6E98920} => F:\Setup.exe
Task: {2BDFECED-24B7-4D8C-9025-C1502F04228B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe [2016-01-12] (Hewlett-Packard Company)
Task: {574C1531-DEB3-4B46-87BF-D18E1D1B893E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [2014-01-13] (Hewlett-Packard Company)
Task: {5A8AB509-63B9-4177-8BFB-37259FE9108F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {6ACD3DA3-8CDC-45B3-9B7A-E23AF4FD5272} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {8773223F-C0F6-4256-B6AE-37485593ED18} - System32\Tasks\{B1BDA461-F2FB-4735-911B-8466740BEE40} => pcalua.exe -a F:\ISP5900\setup.exe -d F:\ISP5900
Task: {92A5803E-5154-441D-983A-B74D0B2F9E1B} - System32\Tasks\{4678693A-7E1D-4D5A-8B9C-88C09315D8A0} => C:\Users\General Log In\Downloads\SUPERAntiSpyware.exe
Task: {A3201F91-388D-4F70-8D35-5431639892AA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2015-11-30] (Hewlett-Packard)
Task: {AA37983A-6648-4778-BAA0-200079D6D06C} - System32\Tasks\HPCeeScheduleForTim => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {C27BFDA4-CAB4-4ADA-BF3A-7685ABADCB4A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Service Update Utility => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\Service\ServiceUpdater.exe [2015-05-20] (Hewlett-Packard Company)
Task: {D518CAEF-FE54-4352-840C-A96CB408FEAB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2014-01-13] (Hewlett-Packard Company)
Task: {DF3F0AF7-6913-4840-8E0F-214B56FB6E4E} - System32\Tasks\{AC256CE6-2226-4B88-90C3-CDD2A645EA89} => F:\Setup.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\HPCeeScheduleForTim.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2014-03-31 17:28 - 2014-03-31 17:28 - 00007168 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe
2014-02-05 15:56 - 2014-02-05 15:56 - 02654936 _____ () C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\ShredContextMenu.dll
2015-12-12 03:41 - 2013-08-05 03:49 - 00627672 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-08-05 19:48 - 2013-08-05 19:48 - 00016856 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [134]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\peoplepc.com -> hxxp://webmail.c.peoplepc.com
IE trusted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\usa4sale.net -> hxxp://contact.usa4sale.net
IE trusted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\winndixie.com -> hxxps://www.winndixie.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3386813744-1969293527-735481815-1001\...\1001movie.com -> 1001movie.com

There are 6091 more sites.

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-03-05 12:28 - 2016-03-05 22:46 - 00000835 ____A C:\windows\system32\Drivers\etc\hosts

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3386813744-1969293527-735481815-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 207.69.188.165 - 207.69.188.166
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe

==================== Restore Points =========================

15-03-2016 21:11:57 Windows Update
16-03-2016 10:00:12 Windows Update
16-03-2016 20:58:16 Windows Update
17-03-2016 08:27:47 Windows Update
17-03-2016 20:12:44 Windows Update
18-03-2016 10:00:11 Windows Update

==================== Faulty Device Manager Devices =============

Name: Microsoft Virtual WiFi Miniport Adapter #2
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

==================== Event log errors: =========================

Application errors:
==================
Error: (03/18/2016 10:02:30 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 10:00:34 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 10:00:28 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 08:37:59 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 08:37:56 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 08:37:56 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 08:37:50 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 08:33:50 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 08:33:50 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/18/2016 08:33:47 AM) (Source: flcdlock) (EventID: 1055) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

System errors:
=============
Error: (03/18/2016 04:20:52 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly.  It has done this 2 time(s).

Error: (03/18/2016 10:07:54 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/18/2016 03:27:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (03/17/2016 08:13:21 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/17/2016 08:28:46 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/16/2016 09:00:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/16/2016 10:08:00 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/15/2016 09:44:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The CyberLink PowerDVD 12 Media Server Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (03/15/2016 09:12:25 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/15/2016 10:18:11 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %Tim-HP60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 115.40.0.0

 Update Source: %Tim-HP51

 Update Stage: 4.9.0218.00

 Source Path: 4.9.0218.01

 Signature Type: %Tim-HP602

 Update Type: %Tim-HP604

 User: Tim-HP\Tim

 Current Engine Version: %Tim-HP605

 Previous Engine Version: %Tim-HP606

 Error code: %Tim-HP607

 Error description: %Tim-HP608

CodeIntegrity:
===================================
  Date: 2016-02-27 03:00:18.399
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 03:00:18.259
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 03:00:18.119
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 02:44:54.815
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 02:44:54.675
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 02:44:54.410
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-26 16:22:08.507
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-26 16:22:08.382
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-26 16:22:08.257
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-26 16:22:08.117
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: AMD A8-6410 APU with AMD Radeon R5 Graphics
Percentage of memory in use: 20%
Total physical RAM: 7612.08 MB
Available physical RAM: 6041.05 MB
Total Virtual: 15222.37 MB
Available Virtual: 12703.45 MB

==================== Drives ================================

Drive c: (Windows ) (Fixed) (Total:919.11 GB) (Free:866.78 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:11.3 GB) (Free:1.24 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
Drive f: () (CDROM) (Total:4.38 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6F9E5779)
Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=919.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11.3 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=100 MB) - (Type=0C)

==================== End of Addition.txt ============================...Thanks, heading to combo, Will check back Before I run the tool.


  • 0

#24
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

Hi Emeraldnzl, I'm posting my combofix logs, I will check back in a few hrs., I have some chores to do; Thank You.ComboFix 16-03-19.01 - Tim 03/20/2016   7:46.1.4 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.7612.5675 [GMT -4:00]
Running from: c:\users\Tim\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {768124D7-F5F7-6D2F-DDC2-94DFA4017C95}
SP: Microsoft Security Essentials *Disabled/Updated* {CDE0C533-D3CD-62A1-E772-AFADDF863628}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1452872097.bdinstall.bin
c:\programdata\1452872215.12020.bin
c:\programdata\1452872215.7672.bin
c:\programdata\1452872494.bdinstall.bin
c:\programdata\1452899595.bdinstall.bin
c:\programdata\1452899603.4068.bin
c:\programdata\1452899603.4640.bin
c:\programdata\1452899603.4652.bin
c:\programdata\1452899603.6328.bin
c:\programdata\1452902927.bdinstall.bin
c:\programdata\1452902928.bdinstall.bin
c:\programdata\1452902986.bdinstall.bin
c:\programdata\1452939960.1056.bin
c:\programdata\1452939960.172.bin
c:\programdata\1452939960.220.bin
c:\programdata\1452939960.4292.bin
c:\programdata\1453293207.4864.bin
c:\programdata\1453293207.4956.bin
c:\programdata\1453293207.4960.bin
c:\programdata\1453293207.5100.bin
c:\programdata\1453329302.bdinstall.bin
c:\programdata\1453467220.bdinstall.bin
c:\programdata\Roaming
c:\windows\desktop
c:\windows\desktop\1.FDPART
.
.
(((((((((((((((((((((((((   Files Created from 2016-02-20 to 2016-03-20  )))))))))))))))))))))))))))))))
.
.
2016-03-20 11:52 . 2016-03-20 11:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2016-03-20 09:52 . 2016-03-20 09:52 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8F4901DE-030A-4CB8-ACF5-E5F4B335DA3E}\offreg.948.dll
2016-03-20 09:40 . 2016-03-20 09:40 -------- d-----w- c:\users\Administrator\Roaming
2016-03-20 09:40 . 2016-03-20 09:41 -------- d-----w- c:\programdata\Intel
2016-03-20 09:40 . 2016-03-20 09:40 -------- d-----w- c:\program files\Common Files\Intel
2016-03-20 09:40 . 2016-03-20 09:40 -------- d-----w- c:\program files (x86)\Intel
2016-03-20 09:40 . 2016-03-20 09:40 -------- d-----w- c:\program files (x86)\Cisco
2016-03-20 09:39 . 2016-03-20 09:39 -------- d-----w- c:\programdata\Package Cache
2016-03-20 09:37 . 2016-02-19 01:53 11249080 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8F4901DE-030A-4CB8-ACF5-E5F4B335DA3E}\mpengine.dll
2016-03-19 11:07 . 2015-06-24 19:00 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{95273724-24ED-4F0C-ABBC-0D2DD69509CA}\gapaengine.dll
2016-03-19 11:07 . 2016-02-19 01:53 11249080 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2016-03-17 12:27 . 2016-02-05 19:03 147904 ----a-w- c:\windows\system32\drivers\tpm.sys
2016-03-17 12:27 . 2016-02-05 18:56 20480 ----a-w- c:\windows\system32\tbs.dll
2016-03-17 12:27 . 2015-06-03 20:22 257864 ----a-w- c:\windows\SysWow64\wbem\Win32_Tpm.dll
2016-03-17 12:27 . 2015-06-03 20:21 451080 ----a-w- c:\windows\system32\fveapi.dll
2016-03-17 12:27 . 2015-06-03 20:21 312600 ----a-w- c:\windows\system32\wbem\Win32_Tpm.dll
2016-03-17 12:27 . 2016-02-05 18:54 109568 ----a-w- c:\windows\system32\fveapibase.dll
2016-03-17 12:27 . 2016-02-05 18:53 8192 ----a-w- c:\windows\system32\drivers\en-US\tpm.sys.mui
2016-03-17 12:27 . 2016-02-05 17:33 15360 ----a-w- c:\windows\SysWow64\tbs.dll
2016-03-17 12:27 . 2016-02-02 18:57 511488 ----a-w- c:\windows\system32\rpcss.dll
2016-03-17 12:25 . 2016-01-21 00:51 73664 ----a-w- c:\windows\system32\drivers\disk.sys
2016-03-16 01:11 . 2016-02-01 18:59 3243008 ----a-w- c:\windows\system32\msi.dll
2016-03-16 01:11 . 2016-02-01 18:56 1940992 ----a-w- c:\windows\system32\authui.dll
2016-03-16 01:11 . 2016-02-01 18:49 2364928 ----a-w- c:\windows\SysWow64\msi.dll
2016-03-16 01:11 . 2016-02-01 19:08 114624 ----a-w- c:\windows\system32\consent.exe
2016-03-16 01:11 . 2016-02-01 18:59 504320 ----a-w- c:\windows\system32\msihnd.dll
2016-03-16 01:11 . 2016-02-01 18:59 25088 ----a-w- c:\windows\system32\msimsg.dll
2016-03-16 01:11 . 2016-02-01 18:56 70144 ----a-w- c:\windows\system32\appinfo.dll
2016-03-16 01:11 . 2016-02-01 18:49 337408 ----a-w- c:\windows\SysWow64\msihnd.dll
2016-03-16 01:11 . 2016-02-01 18:49 25088 ----a-w- c:\windows\SysWow64\msimsg.dll
2016-03-16 01:11 . 2016-02-01 18:45 1805824 ----a-w- c:\windows\SysWow64\authui.dll
2016-03-15 11:08 . 2016-03-15 11:08 -------- d-----w- c:\programdata\Licenses
2016-03-15 11:08 . 2012-05-02 15:17 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2016-03-15 11:08 . 2009-03-24 16:52 129872 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL
2016-03-15 11:08 . 2016-03-16 21:00 -------- d-----w- c:\program files (x86)\SpywareBlaster
2016-03-15 01:27 . 2016-03-15 01:27 -------- d-----w- c:\program files (x86)\Secunia
2016-03-11 14:21 . 2016-03-17 22:06 -------- d-----w- c:\program files (x86)\AdwCleaner
2016-03-11 12:36 . 2016-03-20 11:52 -------- d-----w- c:\users\Tim\AppData\Local\Temp
2016-03-10 19:53 . 2016-03-11 13:38 -------- d-----w- C:\zoek_backup
2016-03-09 21:00 . 2015-06-24 19:00 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{08EF6FF2-916E-46E3-97D1-D323CA1B2BEA}\gapaengine.dll
2016-03-09 20:20 . 2016-03-18 22:46 -------- d-----w- C:\FRST
2016-03-09 20:19 . 2016-02-04 17:52 3211264 ----a-w- c:\windows\system32\win32k.sys
2016-03-09 20:19 . 2016-02-03 18:07 91648 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS
2016-03-09 20:19 . 2016-02-03 18:58 862208 ----a-w- c:\windows\system32\oleaut32.dll
2016-03-09 20:19 . 2016-02-03 18:52 84992 ----a-w- c:\windows\system32\asycfilt.dll
2016-03-09 20:19 . 2016-02-03 18:49 572416 ----a-w- c:\windows\SysWow64\oleaut32.dll
2016-03-09 20:19 . 2016-02-03 18:43 67584 ----a-w- c:\windows\SysWow64\asycfilt.dll
2016-03-09 20:15 . 2016-02-05 01:19 381440 ----a-w- c:\windows\system32\mfds.dll
2016-03-09 20:15 . 2016-02-04 18:41 296448 ----a-w- c:\windows\SysWow64\mfds.dll
2016-03-09 20:05 . 2016-02-05 17:48 372736 ----a-w- c:\windows\system32\atmfd.dll
2016-03-09 20:05 . 2016-02-05 18:54 41472 ----a-w- c:\windows\system32\lpk.dll
2016-03-09 20:05 . 2016-02-05 18:54 100864 ----a-w- c:\windows\system32\fontsub.dll
2016-03-09 20:05 . 2016-02-05 18:53 14336 ----a-w- c:\windows\system32\dciman32.dll
2016-03-09 20:05 . 2016-02-05 18:53 46080 ----a-w- c:\windows\system32\atmlib.dll
2016-03-09 20:05 . 2016-02-05 18:50 25600 ----a-w- c:\windows\SysWow64\lpk.dll
2016-03-09 20:05 . 2016-02-05 18:44 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2016-03-09 20:05 . 2016-02-05 18:42 10240 ----a-w- c:\windows\SysWow64\dciman32.dll
2016-03-09 20:05 . 2016-02-05 17:43 299520 ----a-w- c:\windows\SysWow64\atmfd.dll
2016-03-09 20:05 . 2016-02-05 17:43 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2016-03-08 12:38 . 2016-02-11 14:07 689152 ----a-w- c:\windows\system32\generaltel.dll
2016-03-08 12:38 . 2016-02-19 19:02 38336 ----a-w- c:\windows\system32\CompatTelRunner.exe
2016-03-08 12:38 . 2016-02-19 18:54 1168896 ----a-w- c:\windows\system32\aeinv.dll
2016-03-08 12:38 . 2016-02-19 14:07 1373184 ----a-w- c:\windows\system32\appraiser.dll
2016-03-08 12:38 . 2016-02-05 14:07 696832 ----a-w- c:\windows\system32\invagent.dll
2016-03-08 12:38 . 2016-02-05 14:07 499200 ----a-w- c:\windows\system32\devinv.dll
2016-03-08 12:38 . 2016-02-05 14:07 76800 ----a-w- c:\windows\system32\acmigration.dll
2016-03-07 23:31 . 2016-03-07 23:31 -------- d-----w- c:\program files (x86)\WOLFCODERS ScreenSnag
2016-03-05 16:19 . 2000-05-22 05:00 115920 ----a-w- c:\windows\SysWow64\Msinet.ocx
2016-03-05 16:19 . 2000-05-22 05:00 140488 ----a-w- c:\windows\SysWow64\Comdlg32.ocx
2016-03-05 13:54 . 2016-03-05 18:03 796864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2016-03-05 13:54 . 2016-03-05 18:03 142528 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2016-03-05 13:54 . 2016-03-05 13:54 -------- d-----w- c:\windows\system32\Macromed
2016-03-01 18:27 . 2016-03-15 10:57 -------- d-----w- C:\Downloads
2016-03-01 18:15 . 2016-03-01 18:15 -------- d-----w- c:\programdata\FreeDownloadManager.ORG
2016-03-01 18:15 . 2016-03-01 18:15 -------- d-----w- c:\programdata\Free Download Manager
2016-02-29 21:53 . 2016-03-20 11:43 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2016-02-29 21:52 . 2016-03-14 13:40 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2016-02-29 21:52 . 2016-02-29 21:52 -------- d-----w- c:\programdata\Malwarebytes
2016-02-29 21:52 . 2015-10-05 13:50 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2016-02-29 21:52 . 2015-10-05 13:50 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2016-02-29 20:09 . 2015-10-05 13:50 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2016-02-28 16:38 . 2016-02-28 16:40 -------- d-----w- c:\programdata\SUPERSetup
2016-02-28 10:52 . 2016-02-28 10:53 -------- d-----w- c:\users\Guest
2016-02-27 13:05 . 2016-02-27 13:06 -------- d-----w- c:\users\General Log In
2016-02-26 15:22 . 2015-06-24 19:00 1190000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2016-02-25 03:25 . 2016-02-27 13:07 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2016-02-25 03:25 . 2016-02-27 13:07 -------- d-----w- c:\program files\Microsoft Security Client
2016-02-24 13:26 . 2016-02-24 21:29 -------- d-----w- c:\users\Tim\AppData\Local\F-Secure
2016-02-21 11:44 . 2016-02-21 12:18 -------- d-----w- c:\users\Tim\AppData\Local\Deployment
2016-02-21 11:44 . 2016-02-21 11:44 -------- d-----w- c:\users\Tim\AppData\Local\Apps
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-03-18 22:49 . 2015-12-12 07:28 65536 ----a-w- c:\windows\system32\spu_storage.bin
2016-03-11 02:04 . 2016-01-31 23:50 143659408 ----a-w- c:\windows\system32\MRT.exe
2016-02-17 15:37 . 2014-04-02 12:06 176848 ----a-w- c:\windows\system32\atiuxp64.dll
2016-02-17 15:37 . 2014-04-02 12:06 146728 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2016-02-17 15:37 . 2016-02-17 15:37 7970904 ----a-w- c:\windows\SysWow64\atiumdva.dll
2016-02-17 15:37 . 2016-02-17 15:37 7238984 ----a-w- c:\windows\SysWow64\atiumdag.dll
2016-02-17 15:37 . 2014-04-02 12:06 8910672 ----a-w- c:\windows\system32\atiumd6a.dll
2016-02-17 15:37 . 2016-02-17 15:37 159768 ----a-w- c:\windows\system32\atiu9p64.dll
2016-02-17 15:37 . 2016-02-17 15:37 119744 ----a-w- c:\windows\system32\atimpc64.dll
2016-02-17 15:37 . 2016-02-17 15:37 119744 ----a-w- c:\windows\system32\amdpcom64.dll
2016-02-17 15:37 . 2016-02-17 15:37 102040 ----a-w- c:\windows\SysWow64\atimpc32.dll
2016-02-17 15:37 . 2016-02-17 15:37 102040 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2016-02-17 15:36 . 2014-04-02 12:06 9561688 ----a-w- c:\windows\SysWow64\atidxx32.dll
2016-02-17 15:36 . 2014-04-02 12:06 1469808 ----a-w- c:\windows\system32\aticfx64.dll
2016-02-17 15:36 . 2014-04-02 12:06 1214248 ----a-w- c:\windows\SysWow64\aticfx32.dll
2016-02-17 15:35 . 2016-02-17 15:35 135280 ----a-w- c:\windows\SysWow64\amdhcp32.dll
2016-02-17 15:35 . 2016-02-17 15:35 148840 ----a-w- c:\windows\system32\amdave64.dll
2016-02-17 15:35 . 2016-02-17 15:35 130616 ----a-w- c:\windows\SysWow64\amdave32.dll
2016-02-17 15:34 . 2016-02-17 15:34 117776 ----a-w- c:\windows\system32\mantleaxl64.dll
2016-02-17 15:34 . 2016-02-17 15:34 98328 ----a-w- c:\windows\SysWow64\mantleaxl32.dll
2016-02-17 15:34 . 2016-02-17 15:34 151064 ----a-w- c:\windows\system32\mantle64.dll
2016-02-17 15:34 . 2016-02-17 15:34 126488 ----a-w- c:\windows\SysWow64\mantle32.dll
2016-02-17 15:34 . 2016-02-17 15:34 161296 ----a-w- c:\windows\system32\hsa-thunk64.dll
2016-02-17 15:34 . 2016-02-17 15:34 151576 ----a-w- c:\windows\SysWow64\hsa-thunk.dll
2016-02-17 15:34 . 2016-02-17 15:34 12824 ----a-w- c:\windows\system32\detoured.dll
2016-02-17 15:34 . 2016-02-17 15:34 874008 ----a-w- c:\windows\system32\coinst_15.20.dll
2016-02-17 15:34 . 2016-02-17 15:34 12816 ----a-w- c:\windows\SysWow64\detoured.dll
2016-02-17 15:34 . 2016-02-17 15:34 243736 ----a-w- c:\windows\system32\clinfo.exe
2016-02-17 15:33 . 2016-02-17 15:33 199704 ----a-w- c:\windows\system32\atitmm64.dll
2016-02-17 15:33 . 2016-02-17 15:33 128536 ----a-w- c:\windows\system32\atisamu64.dll
2016-02-17 15:33 . 2016-02-17 15:33 110104 ----a-w- c:\windows\SysWow64\atisamu32.dll
2016-02-17 15:33 . 2016-02-17 15:33 25059344 ----a-w- c:\windows\SysWow64\atioglxx.dll
2016-02-17 15:32 . 2016-02-17 15:32 341528 ----a-w- c:\windows\system32\ATIODE.exe
2016-02-17 15:32 . 2016-02-17 15:32 59928 ----a-w- c:\windows\system32\ATIODCLI.exe
2016-02-17 15:32 . 2016-02-17 15:32 30554640 ----a-w- c:\windows\system32\atio6axx.dll
2016-02-17 15:32 . 2016-02-17 15:32 493592 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2016-02-17 15:32 . 2016-02-17 15:32 38424 ----a-w- c:\windows\system32\atimuixx.dll
2016-02-17 15:32 . 2016-02-17 15:32 21527568 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2016-02-17 15:31 . 2016-02-17 15:31 99352 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2016-02-17 15:31 . 2016-02-17 15:31 99352 ----a-w- c:\windows\system32\atiglpxx.dll
2016-02-17 15:31 . 2016-02-17 15:31 166928 ----a-w- c:\windows\SysWow64\atigktxx.dll
2016-02-17 15:31 . 2016-02-17 15:31 114200 ----a-w- c:\windows\system32\atig6pxx.dll
2016-02-17 15:31 . 2014-04-02 10:22 193560 ----a-w- c:\windows\system32\atig6txx.dll
2016-02-17 15:31 . 2014-04-02 10:57 305176 ----a-w- c:\windows\system32\atiesrxx.exe
2016-02-17 15:31 . 2014-04-02 10:58 704536 ----a-w- c:\windows\system32\atieclxx.exe
2016-02-17 15:31 . 2016-02-17 15:31 219152 ----a-w- c:\windows\system32\atieah64.exe
2016-02-17 15:31 . 2016-02-17 15:31 451096 ----a-w- c:\windows\system32\atidemgy.dll
2016-02-17 15:31 . 2016-02-17 15:31 198160 ----a-w- c:\windows\SysWow64\atieah32.exe
2016-02-17 15:31 . 2016-02-17 15:31 71192 ----a-w- c:\windows\system32\aticalrt64.dll
2016-02-17 15:31 . 2016-02-17 15:31 14310936 ----a-w- c:\windows\SysWow64\aticaldd.dll
2016-02-17 15:30 . 2016-02-17 15:30 64528 ----a-w- c:\windows\system32\aticalcl64.dll
2016-02-17 15:30 . 2016-02-17 15:30 57880 ----a-w- c:\windows\SysWow64\aticalcl.dll
2016-02-17 15:30 . 2016-02-17 15:30 394256 ----a-w- c:\windows\system32\atiapfxx.exe
2016-02-17 15:30 . 2016-02-17 15:30 945680 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2016-02-17 15:30 . 2016-02-17 15:30 945680 ----a-w- c:\windows\SysWow64\atiadlxx.dll
2016-02-17 15:30 . 2014-04-02 10:23 1258000 ----a-w- c:\windows\system32\atiadlxx.dll
2016-02-17 15:30 . 2016-02-17 15:30 52248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2016-02-17 15:30 . 2014-04-02 11:44 47793680 ----a-w- c:\windows\system32\amdocl64.dll
2016-02-17 15:29 . 2016-02-17 15:29 27544600 ----a-w- c:\windows\system32\amdocl12cl64.dll
2016-02-17 15:29 . 2016-02-17 15:29 22327312 ----a-w- c:\windows\SysWow64\amdocl12cl.dll
2016-02-17 15:29 . 2016-02-17 15:29 1070624 ----a-w- c:\windows\system32\amdocl_ld64.exe
2016-02-17 15:29 . 2016-02-17 15:29 807456 ----a-w- c:\windows\SysWow64\amdocl_ld32.exe
2016-02-17 15:29 . 2016-02-17 15:29 1196064 ----a-w- c:\windows\system32\amdocl_as64.exe
2016-02-17 15:29 . 2016-02-17 15:29 1004064 ----a-w- c:\windows\SysWow64\amdocl_as32.exe
2016-02-17 15:28 . 2016-02-17 15:28 39721496 ----a-w- c:\windows\SysWow64\amdocl.dll
2016-02-17 15:28 . 2016-02-17 15:28 59408 ----a-w- c:\windows\system32\amdmmcl6.dll
2016-02-17 15:28 . 2016-02-17 15:28 47120 ----a-w- c:\windows\SysWow64\amdmmcl.dll
2016-02-17 15:28 . 2016-02-17 15:28 6354456 ----a-w- c:\windows\system32\amdmantle64.dll
2016-02-17 15:28 . 2016-02-17 15:28 5138448 ----a-w- c:\windows\SysWow64\amdmantle32.dll
2016-02-17 15:28 . 2016-02-17 15:28 237584 ----a-w- c:\windows\system32\amdgfxinfo64.dll
2016-02-17 15:27 . 2016-02-17 15:27 68112 ----a-w- c:\windows\SysWow64\OpenCL.dll
2016-02-17 15:27 . 2016-02-17 15:27 209936 ----a-w- c:\windows\SysWow64\amdgfxinfo32.dll
2016-02-17 15:27 . 2014-04-02 11:39 73744 ----a-w- c:\windows\system32\OpenCL.dll
2016-02-17 15:22 . 2016-02-17 15:22 60952 ----a-w- c:\windows\SysWow64\aticalrt.dll
2016-02-17 15:22 . 2016-02-17 15:22 15725584 ----a-w- c:\windows\system32\aticaldd64.dll
2016-02-17 15:21 . 2016-02-17 15:21 8705552 ----a-w- c:\windows\system32\atiumd64.dll
2016-02-17 15:21 . 2016-02-17 15:21 133240 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2016-02-17 15:21 . 2014-04-02 12:06 11266224 ----a-w- c:\windows\system32\atidxx64.dll
2016-02-17 15:21 . 2016-02-17 15:21 151456 ----a-w- c:\windows\system32\amdhcp64.dll
2016-02-11 18:30 . 2016-03-10 20:46 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2016-01-22 06:19 . 2016-02-05 13:41 14179840 ----a-w- c:\windows\system32\shell32.dll
2016-01-22 06:18 . 2016-02-12 14:28 961024 ----a-w- c:\windows\system32\CPFilters.dll
2016-01-22 06:18 . 2016-02-12 14:28 723968 ----a-w- c:\windows\system32\EncDec.dll
2016-01-22 06:17 . 2016-02-12 14:28 159744 ----a-w- c:\windows\system32\mtxoci.dll
2016-01-22 06:15 . 2016-02-05 13:41 1866752 ----a-w- c:\windows\system32\ExplorerFrame.dll
2016-01-22 06:04 . 2016-02-12 14:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2016-01-22 06:04 . 2016-02-12 14:28 535040 ----a-w- c:\windows\SysWow64\EncDec.dll
2016-01-22 06:02 . 2016-02-12 14:28 114176 ----a-w- c:\windows\SysWow64\mtxoci.dll
2016-01-22 06:02 . 2016-02-12 14:28 176128 ----a-w- c:\windows\SysWow64\msorcl32.dll
2016-01-22 06:00 . 2016-02-05 13:41 1498624 ----a-w- c:\windows\SysWow64\ExplorerFrame.dll
2016-01-22 05:19 . 2016-02-05 13:41 3231232 ----a-w- c:\windows\explorer.exe
2016-01-22 05:12 . 2016-02-05 13:41 2973184 ----a-w- c:\windows\SysWow64\explorer.exe
2016-01-16 19:01 . 2016-02-12 12:39 2085888 ----a-w- c:\windows\system32\ole32.dll
2016-01-16 18:36 . 2016-02-12 12:39 1413632 ----a-w- c:\windows\SysWow64\ole32.dll
2016-01-11 19:11 . 2016-02-18 14:18 1684416 ----a-w- c:\windows\system32\drivers\ntfs.sys
2016-01-07 17:42 . 2016-02-10 17:37 141312 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2016-01-06 19:02 . 2016-02-12 12:49 24576 ----a-w- c:\windows\system32\jnwmon.dll
2016-01-06 19:02 . 2016-02-12 12:49 275456 ----a-w- c:\windows\system32\InkEd.dll
2016-01-06 18:41 . 2016-02-12 12:49 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
2016-01-04 23:09 . 2016-01-04 23:09 736952 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer_For_P2G8"="c:\program files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe" [2013-08-05 111576]
"CLVirtualDrive"="c:\program files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" [2013-08-07 490760]
"HP File Sanitizer"="c:\program files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe" [2014-02-05 2213592]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ    DPPassFilter scecli
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 amdkmcsp;AMD Kernel Mode CSP Service;c:\windows\system32\DRIVERS\amdkmcsp.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmcsp.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\drivers\amd_sata.sys;c:\windows\SYSNATIVE\drivers\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\drivers\amd_xata.sys;c:\windows\SYSNATIVE\drivers\amd_xata.sys [x]
S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\drivers\amdkmpfd.sys;c:\windows\SYSNATIVE\drivers\amdkmpfd.sys [x]
S1 amdpsp;AMD PSP Service;c:\windows\system32\DRIVERS\amdpsp.sys;c:\windows\SYSNATIVE\DRIVERS\amdpsp.sys [x]
S1 CLVirtualDrive;CLVirtualDrive;c:\windows\system32\DRIVERS\CLVirtualDrive.sys;c:\windows\SYSNATIVE\DRIVERS\CLVirtualDrive.sys [x]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.EXE;c:\program files\Realtek\Audio\HDA\AERTSr64.EXE [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 CtAgentService;Absolute Software Agent Service;c:\program files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe;c:\program files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [x]
S2 CyberLink PowerDVD 12 Media Server Monitor Service;CyberLink PowerDVD 12 Media Server Monitor Service;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [x]
S2 CyberLink PowerDVD 12 Media Server Service;CyberLink PowerDVD 12 Media Server Service;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe;c:\program files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [x]
S2 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys;c:\windows\SYSNATIVE\DRIVERS\DAMDrv64.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 FLCDLOCK;HP Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe;c:\windows\SysWOW64\flcdlock.exe [x]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
S2 HpDamServiceHost;HP Device Access Manager Usage Service;c:\program files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe;c:\program files (x86)\Hewlett-Packard\HP Device Access Manager\HP.ProtectTools.DeviceAccessManager.ServiceHost.exe [x]
S2 HPFSService;HP File Sanitizer;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [x]
S2 RtkAudioService;Realtek Audio Service;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe;c:\program files\Realtek\Audio\HDA\RtkAudioService64.exe [x]
S2 tbaseprovisioning;tbaseprovisioning;c:\windows\SysWOW64\tbaseprovisioning.exe;c:\windows\SysWOW64\tbaseprovisioning.exe [x]
S2 ZeroConfigService;Intel® PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\drivers\amdhub30.sys;c:\windows\SYSNATIVE\drivers\amdhub30.sys [x]
S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\drivers\amdxhc.sys;c:\windows\SYSNATIVE\drivers\amdxhc.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ    SSDPSRV upnphost SCardSvr QWAVE wcncsvc
.
Contents of the 'Scheduled Tasks' folder
.
2016-03-19 c:\windows\Tasks\HPCeeScheduleForTim.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 12:43]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2014-04-15 7570136]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2016-01-30 1340192]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://home.peoplepc.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: peoplepc.com\webmail.c
Trusted Zone: usa4sale.net\contact
Trusted Zone: winndixie.com\www
TCP: Interfaces\{2F1E699D-E62A-4FF1-A81B-78F8012F36FF}: NameServer = 207.69.188.165 207.69.188.166
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Wow6432Node-HKLM-Run-TweakDUN - c:\program files (x86)\TweakDUN\tweakdun.exe
HKLM_Wow6432Node-ActiveSetup-{438363A8-F486-4C37-834C-4955773CB3D3} - msiexec
HKLM-Run-InstallerLauncher - c:\program files\Bitdefender\Antivirus Free Edition\Install\setuplauncher.exe
AddRemove-{440d014b-4444-4533-b96d-2910e1ca2bcf} - c:\programdata\Package Cache\{440d014b-4444-4533-b96d-2910e1ca2bcf}\Setup.exe
AddRemove-{6e8f74e0-43bd-4dce-8477-6ff6828acc07} - c:\programdata\Package Cache\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}\vcredist_x64.exe
AddRemove-{8C696B4B-6AB1-44BC-9416-96EAC474CABE} - c:\program files (x86)\InstallShield Installation Information\{8C696B4B-6AB1-44BC-9416-96EAC474CABE}\setup.exe
AddRemove-{8e70e4e1-06d7-470b-9f74-a51bef21088e} - c:\programdata\Package Cache\{8e70e4e1-06d7-470b-9f74-a51bef21088e}\vcredist_x86.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_20_0_0_306_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_20_0_0_306_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_20_0_0_306_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_20_0_0_306_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_306.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.20"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_306.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_306.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_20_0_0_306.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2016-03-20  07:55:09
ComboFix-quarantined-files.txt  2016-03-20 11:55
.
Pre-Run: 929,242,836,992 bytes free
Post-Run: 928,701,546,496 bytes free
.
- - End Of File - - 0D32FBDA3A1F889EEC5DC0C710176A16
A36C5E4F47E84449FF07ED3517B43A31
 


  • 0

#25
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

here are my reports You ask for


Thank you. Very helpful. :thumbsup:

Turning to your machine.

I think Naathim has removed the Spamware that was going on.

 

With Ransomware you can't access your data files and you get a pop up demanding money see here. Also we would see a lot of related Ransomware files on the machine. They are not there so... not Ransomware.

The problems with ESET and MBAM were most likely related to dial-up. ESET especially has a huge file of definitions it wants to download before it will work. I don't think it could easily do that through dial-up. It was likely timing out.

I see Bitdefender in your logs. Did you run a quick scan and if so, did it show anything?

And

How is your machine now?
 


  • 1

Advertisements


#26
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

Hi Emeraldnzl,  Yes I tried to run Bitdefender quick scan, but couldn't make it load/work.. As for my machine, it seems to be okay, just really slow, I'm use to it running around 48/49 KBs, it's now around 4 to 10 KBs, sometimes even slower, I'm sure that is another department; So what do You think Doc, clean bill of health ?, & any way of knowing Where this trogen came from ?....Thanks again Emeraldnzl & Naat;: Iwill wait for Your response....Tim :beer:


  • 0

#27
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

 

I'm use to it running around 48/49 KBs, it's now around 4 to 10 KBs, sometimes even slower,

 

A number of things might be the cause.

 

You should also check with your ISP for possible reasons for slowing down of your connection. Maybe throttling back or maintenance on the line?

 

There are some errors showing in the FRST log to do with your Microsoft Virtual WiFi Miniport Adapter which may have something to do with that. You might need to open a topic in the appropriate forum for that when we have finished here.

 

For now

 

Let's carry out some actions that might make a difference. After that, if need be, we will look further to see if we can find more information.

 

Firstly

 

Use the System File Checker tool (SFC.exe) to check your system and replace files where necessary.

To do this, follow these steps:

  • To do this, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator.
  • If you are prompted for an administrator password or for a confirmation, type the password, or click Allow.
  • Type the following command, and then press ENTER:
    sfc /scannow         Please note that there is a single space between sfc and /scannow.

The sfc /scannow command scans all protected system files and replaces incorrect versions with correct Microsoft versions.

You should see the following on-screen messages:

Beginning the system scan. This process will take some time.

Beginning verification phase of system scan.

Verification % complete.

Once the scan has completed you will receive an onscreen message resembling one of the following:

…found no integrity violations

…found corruption but repaired it

…found corruption that it could not repair


Please reply with the completion message that you received.

 

After that

 

Please run Chkdsk:
 

  • Right click on the Start > Open Windows Explorer.
  • Find the hard drive letter (usually local disk C)  for which you want to run the Chkdsk utility.
  • Right-click on the driver letter and select Properties > Tools.
  • Under the Error-Checking section of the window, click the Check Now button. If you have User Account Controls enabled, a window will pop up asking permission to continue. Click Continue.
  • Click to have Chkdsk Automatically fix file system errors and to Scan for and attempt recovery of bad sectors.
  • Click Start.
  • Chkdsk might take a very long time to run, depending on the number of files and folders, the size of the volume, disk performance, and available system resources (such as processor and memory).

Note: Chkdsk will not run if the drive you wish to check is in use. You will be requested to schedule Chkdsk. Click Schedule Check Disk, it then will run the next time you boot your computer.
 
Shut down your computer and then turn it back on, Chkdsk will run.
 
Come back and tell me how it went.

 

Finally in this post

 

 

Care: Do not download and use if your hard drive is SSD (Solid State Disk).

To check what type of hard drive disk you have:

  • Go to  Start > Search programs and files and type msinfo32
  • Click on msinfo32.exe (probably at the top) and look under Components > Storage > Disks

It should list somewhere there whether it is a Standard disk or a Solid State disk

Assuming you do not have an SSD drive, download Auslogics Disk Defrag  (Note - click the button that says "No, thank you Just give me the Disk Defrag Free") and save somewhere you can find it.

Double click and follow the prompts to install it. Note: only install the defrag utility. Some versions come with Askbar toolbars... do not install those or any other foistware that might be promoted.

Once installed, run the defrag utility.

At the end the utility may tell you that it has found Junk Files and recommend that you run a scan to remove. Disregard that suggestion, it is a promotion of a tool you don't need. All we are interested in here is the defrag. process.

Note: Do not download Windows Registry Cleaner which is promoted at the same site.

 

So when you return

  • Tell me how System File Checker reported
  • Tell me how chkdsk went
  • Tell me how the defrag went.

  • 1

#28
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

Hi Emeraldnzl, Sorry it took so long to get back,  the 1st test said {

found corruption but repaired it} the 2nd test had to reboot, & it ran its scan then closed, so I ???, the 3rd test showed it was fragmented ( I think ) I made a copy of it, here::

Auslogics Disk Defrag
 
3/22/2016 7:20:39 PM Report for user "Tim" Disk: Windows (C:), NTFS Disk Defragmentation Summary     Disk Size 919.11 GB Free Space Size 862.92 GB Clusters 240938495 Sectors per cluster 8 Bytes per sector 512 Defragmentation started 3/22/2016 7:20:36 PM Defragmentation completed 3/22/2016 7:20:36 PM Elapsed time 00:00:00 Total Files 0 Total Directories 0 Fragmented Files 0 Defragmented Files 0 Skipped Files 0 Fragmentation Before 0.00% Fragmentation After 0.00%
 
Disk Defragmentation Details   There are no files to defragment Defragmentation has been aborted by user
 
Disk: HP_RECOVERY (D:), NTFS Disk Defragmentation Summary     Disk Size 11.30 GB Free Space Size 1.24 GB Clusters 2962431 Sectors per cluster 8 Bytes per sector 512 Defragmentation started 3/22/2016 7:20:37 PM Defragmentation completed 3/22/2016 7:20:39 PM Elapsed time 00:00:02 Total Files 62 Total Directories 27 Fragmented Files 2 Defragmented Files 0 Skipped Files 0 Fragmentation Before 98.63% |||||||||||||||||||||||||||||||||||||||||||||||||| Fragmentation After 98.63% ||||||||||||||||||||||||||||||||||||||||||||||||||
 
Disk Defragmentation Details Fragments Clusters Size Result File Name 2 481933 / 563246 317.63 MB cancelled D:\sources\boot.wim Defragmentation has been aborted by user
 
Disk: HP_TOOLS (E:), FAT32 Disk Defragmentation Summary     Disk Size 96.00 MB Free Space Size 56.45 MB Clusters 98304 Sectors per cluster 2 Bytes per sector 512 Defragmentation started 3/22/2016 7:20:36 PM Defragmentation completed 3/22/2016 7:20:37 PM Elapsed time 00:00:00 Total Files 500 Total Directories 44 Fragmented Files 0 Defragmented Files 0 Skipped Files 0 Fragmentation Before 0.00% Fragmentation After 0.00%
 
Disk Defragmentation Details   There are no files to defragment
 
File Defragmentation Summary Result Description OK file successfully defragmented unmovable file file in use, access denied cancelled file defragmentation cancelled free space not found unable to find free contiguous disk space unable to defragment unable to defragment, defragmentation error

 

I started to hit defrag now, then remembered You said run scan only; Should I delete this tool or any of'em ??, Thanks,Tim


  • 0

#29
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

 

I started to hit defrag now, then remembered You said run scan only; Should I delete this tool or any of'em ??, Thanks,Tim

 

No it's fine to run the defrag... from what you report it looks like you already did! It's the junk files bit that you can leave. In fact we have already removed all the junk and temporary files we want removed in our earlier actions.

 

Now

 

Please download MiniToolBox to your desktop and run it.

Check the following boxes:

  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.

Click Go and post the result (Result.txt) back here. A copy of Result.txt will be saved in the same directory the tool is run.

So when you return please post:

 

  • Result.txt
  • and tell me if there was any improvement after the last actions we took

 


  • 0

#30
bonezz777

bonezz777

    Member

  • Topic Starter
  • Member
  • PipPip
  • 99 posts

Hi Emeraldnzl, Here are the results::

MiniToolBox by Farbar  Version: 07-02-2016 01
Ran by Tim (administrator) on 24-03-2016 at 08:20:36
Running from "C:\Users\Tim\Desktop"
Microsoft Windows 7 Professional  Service Pack 1 (X64)
Model: HP ProDesk 405 G2 MT Manufacturer: Hewlett-Packard
Boot Mode: Normal
***************************************************************************
========================= Hosts content: =================================
127.0.0.1       localhost
========================= IP Configuration: ================================

Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 3 (Hardware not present)
Realtek PCIe GBE Family Controller = Local Area Connection (Media disconnected)
Intel® Dual Band Wireless-N 7260 = Wireless Network Connection (Media disconnected)
Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected)

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset

popd
# End of IPv4 configuration

 

Windows IP Configuration

   Host Name . . . . . . . . . . . . : Tim-HP
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No

PPP adapter Dial-up Connectionpeoplepc123:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Dial-up Connectionpeoplepc123
   Physical Address. . . . . . . . . :
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 66.19.189.182(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.255
   Default Gateway . . . . . . . . . : 0.0.0.0
   DNS Servers . . . . . . . . . . . : 207.69.188.165
                                       207.69.188.166
   NetBIOS over Tcpip. . . . . . . . : Disabled

Wireless LAN adapter Wireless Network Connection 2:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter
   Physical Address. . . . . . . . . : AE-FD-CE-42-AB-CB
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wireless Network Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel® Dual Band Wireless-N 7260
   Physical Address. . . . . . . . . : AC-FD-CE-42-AB-CB
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Ethernet adapter Local Area Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : A0-D3-C1-4A-78-F6
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{30A6066A-07D3-407F-A120-9313DBBD8CF3}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{F5556766-CECB-4C20-BFA1-E1DC4FA3439E}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Reusable ISATAP Interface {C62B87DE-341C-4BA2-A7D2-54ED4805DE56}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{2F1E699D-E62A-4FF1-A81B-78F8012F36FF}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #4
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter 6TO4 Adapter:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2002:4213:bdb6::4213:bdb6(Preferred)
   Default Gateway . . . . . . . . . : 2002:c058:6301::c058:6301
   DNS Servers . . . . . . . . . . . : 207.69.188.165
                                       207.69.188.166
   NetBIOS over Tcpip. . . . . . . . : Disabled

Tunnel adapter Reusable ISATAP Interface {42B23572-C959-4991-A93A-01690A994A7B}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #5
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{B8692A19-E7CA-4985-B46C-556A84D4EF53}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #6
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
DNS request timed out.
    timeout was 2 seconds.
Server:  UnKnown
Address:  207.69.188.165

Name:    google.com
Addresses:  2607:f8b0:4006:809::200e
   172.217.4.78

Pinging google.com [172.217.3.14] with 32 bytes of data:
Reply from 172.217.3.14: bytes=32 time=415ms TTL=52
Reply from 172.217.3.14: bytes=32 time=393ms TTL=52

Ping statistics for 172.217.3.14:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 393ms, Maximum = 415ms, Average = 404ms
Server:  rns1.peoplepc.com
Address:  207.69.188.165

DNS request timed out.
    timeout was 2 seconds.
Name:    yahoo.com
Addresses:  2001:4998:c:a06::2:4008
   2001:4998:44:204::a7
   2001:4998:58:c02::a9

Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=422ms TTL=50
Reply from 98.139.183.24: bytes=32 time=412ms TTL=50

Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 412ms, Maximum = 422ms, Average = 417ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 20...........................Dial-up Connectionpeoplepc123
 13...ae fd ce 42 ab cb ......Microsoft Virtual WiFi Miniport Adapter
 12...ac fd ce 42 ab cb ......Intel® Dual Band Wireless-N 7260
 11...a0 d3 c1 4a 78 f6 ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 17...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 19...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
 21...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
 16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #4
 15...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 18...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #5
 34...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #6
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0         On-link     66.19.189.182     51
    66.19.189.182  255.255.255.255         On-link     66.19.189.182    306
        127.0.0.0        255.0.0.0         On-link         127.0.0.1   4531
        127.0.0.1  255.255.255.255         On-link         127.0.0.1   4531
  127.255.255.255  255.255.255.255         On-link         127.0.0.1   4531
        224.0.0.0        240.0.0.0         On-link         127.0.0.1   4531
        224.0.0.0        240.0.0.0         On-link     66.19.189.182     51
  255.255.255.255  255.255.255.255         On-link         127.0.0.1   4531
  255.255.255.255  255.255.255.255         On-link     66.19.189.182    306
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 15   1939 ::/0                     2002:c058:6301::c058:6301
  1    306 ::1/128                  On-link
 15   1050 2002::/16                On-link
 15    306 2002:4213:bdb6::4213:bdb6/128
                                    On-link
  1    306 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 06 C:\windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog9 01 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (03/24/2016 07:00:09 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 07:00:08 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 07:00:08 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 06:59:28 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 06:59:27 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 06:58:46 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 06:58:45 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 06:58:45 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 06:58:24 AM) (Source: flcdlock) (User: )
Description: An error occurred enumerating device {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #2.

The system error code is 0xe0000231:-

** The error code could not be translated **

Error: (03/24/2016 06:58:24 AM) (Source: flcdlock) (User: )
Description: Current SID profile operation failed with unknown exception.

System errors:
=============
Error: (03/24/2016 07:37:05 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 115.43.0.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.9.0218.00

 Source Path: 4.9.0218.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (03/24/2016 07:29:13 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.215.2563.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.9.0218.00

 Source Path: 4.9.0218.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (03/24/2016 07:29:13 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.215.2563.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.9.0218.00

 Source Path: 4.9.0218.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (03/24/2016 07:16:14 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.215.2563.0

 Update Source: %NT AUTHORITY59

 Update Stage: 4.9.0218.00

 Source Path: 4.9.0218.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\SYSTEM

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (03/24/2016 07:06:20 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.

Error: (03/23/2016 06:39:28 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/22/2016 07:47:40 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/22/2016 10:24:45 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: Security Update for Microsoft .NET Framework 3.5.1 on Windows 7 and Windows Server 2008 R2 SP1 for x64-based Systems (KB2972211).

Error: (03/22/2016 08:24:21 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 115.42.0.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.9.0218.00

 Source Path: 4.9.0218.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Error: (03/22/2016 08:24:21 AM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

 New Signature Version:

 Previous Signature Version: 1.215.2461.0

 Update Source: %NT AUTHORITY51

 Update Stage: 4.9.0218.00

 Source Path: 4.9.0218.01

 Signature Type: %NT AUTHORITY602

 Update Type: %NT AUTHORITY604

 User: NT AUTHORITY\NETWORK SERVICE

 Current Engine Version: %NT AUTHORITY605

 Previous Engine Version: %NT AUTHORITY606

 Error code: %NT AUTHORITY607

 Error description: %NT AUTHORITY608

Microsoft Office Sessions:
=========================
Error: (03/24/2016 07:00:09 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 07:00:08 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 07:00:08 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 06:59:28 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 06:59:27 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 06:58:46 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 06:58:45 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 06:58:45 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 06:58:24 AM) (Source: flcdlock)(User: )
Description: {4D36E972-E325-11CE-BFC1-08002BE10318}Microsoft Virtual WiFi Miniport Adapter #20xe0000231** The error code could not be translated **

Error: (03/24/2016 06:58:24 AM) (Source: flcdlock)(User: )
Description:

CodeIntegrity Errors:
===================================
  Date: 2016-03-20 07:51:50.334
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-03-20 07:51:50.256
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-02-27 03:00:18.399
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 03:00:18.259
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 03:00:18.119
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 02:44:54.815
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 02:44:54.675
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-27 02:44:54.410
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-26 16:22:08.507
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

  Date: 2016-02-26 16:22:08.382
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\EagleGet\eagleGet_x86.sys because the set of per-page image hashes could not be found on the system.

=========================== Installed Programs ============================

Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.182 - Adobe Systems Incorporated)
Adobe Reader 9.3 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A93000000001}) (Version: 9.3.0 - Adobe Systems Incorporated)
Auslogics DiskDefrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 6.2.1.0 - Auslogics Labs Pty Ltd)
Bejeweled 2 Deluxe (HKLM-x32\...\Bejeweled 2 Deluxe) (Version:  - PopCap Games)
Bejeweled Twist (HKLM-x32\...\Bejeweled Twist) (Version:  - PopCap Games)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.3.3207 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.)
DirectX for Managed Code Update (Summer 2004) (HKLM-x32\...\{E9E34215-82EF-4909-BE2F-F581F0DC9062}) (Version: 9.02.2904 - Microsoft) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Client Security Manager (HKLM\...\HPProtectTools) (Version: 8.3.3.1786 - Hewlett-Packard Company)
HP Deskjet 1000 J110 series Basic Device Software (HKLM\...\{883B114D-BD3E-498F-9DAD-5E4A8E1C43BA}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Deskjet 1000 J110 series Help (HKLM-x32\...\{DDDFCC77-7F9C-45E9-B38E-721BA599BA0C}) (Version: 140.0.65.65 - Hewlett Packard)
HP Device Access Manager (HKLM\...\{DBE16A07-DDFF-4453-807A-212EF93916E0}) (Version: 8.3.2.0 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{F7A8FF27-1B85-4C23-A6FA-97DE491ECC9A}) (Version: 1.1.0.0 - Hewlett-Packard)
HP File Sanitizer (HKLM-x32\...\{6349342F-9CEF-4A70-995A-2CF3704C2603}) (Version: 8.4.20.1 - Hewlett-Packard Company)
HP PageLift (HKLM-x32\...\{59202086-BEA1-411A-8AA4-A5DCD28FF537}) (Version: 1.0.13.1 - Hewlett-Packard Company)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.3781 - HP Photo Creations Powered by RocketLife)
HP Setup (HKLM-x32\...\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15453.4066 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{23544215-E6E6-448B-B6E9-6268D5B3E74D}) (Version: 3.5.0.0 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{F6D61EC9-347B-4019-9F8E-E24169F7C330}) (Version: 8.7.5 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{8C696B4B-6AB1-44BC-9416-96EAC474CABE}) (Version: 7.5.2.12 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
HP Theft Recovery (HKLM-x32\...\InstallShield_{B1E569B6-A5EB-4C97-9F93-9ED2AA99AF0E}) (Version: 8.3.0.7 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard)
Intel® PROSet/Wireless Software (HKLM-x32\...\{440d014b-4444-4533-b96d-2910e1ca2bcf}) (Version: 16.7.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{8e41467d-297e-496d-8b0f-e771b6c87c06}) (Version: 16.11.0 - Intel Corporation)
K-Lite Codec Pack 11.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.8.0 - )
LSI USB 2.0 Soft Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.102 - LSI Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
opensource (HKLM-x32\...\{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}) (Version: 1.0.14960.3876 - Your Company Name) Hidden
Peggle Deluxe (HKLM-x32\...\Peggle Deluxe) (Version:  - PopCap Games)
Peggle Nights (HKLM-x32\...\Peggle Nights) (Version:  - PopCap Games)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.85.423.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7224 - Realtek Semiconductor Corp.)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SpywareBlaster 5.4 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.4.0 - BrightFort LLC)
WOLFCODERS ScreenSnag (HKLM-x32\...\{481875AB-8D00-46D0-92E2-27BB13B20975}_is1) (Version:  - WOLFCODERS)

========================= Memory info: ===================================

Percentage of memory in use: 23%
Total physical RAM: 7612.08 MB
Available physical RAM: 5797.76 MB
Total Virtual: 15222.37 MB
Available Virtual: 13369.16 MB

========================= Partitions: =====================================

1 Drive c: (Windows ) (Fixed) (Total:919.11 GB) (Free:864.35 GB) NTFS
2 Drive d: (HP_RECOVERY) (Fixed) (Total:11.3 GB) (Free:1.24 GB) NTFS
3 Drive e: (HP_TOOLS) (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
4 Drive f: () (CDROM) (Total:4.38 GB) (Free:0 GB) UDF

========================= Users: ========================================

User accounts for \\TIM-HP

Administrator            General Log In           Guest                   
Tim                     

**** End of log **** Thanks Again, Tim


  • 0






Similar Topics


Also tagged with one or more of these keywords: 1-877 call alerts, audio warningsms, can not use internet, my isp is dial up, 1-877 ransom, blocks all attempts to remove, internet explorer 11

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP