Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

99-100% CPU when watching videos, playing games


  • This topic is locked This topic is locked
13 replies to this topic

#1 Jonnycbad

Jonnycbad

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:43 PM

Posted 21 February 2014 - 09:54 PM

Hello,

 

For the last few weeks a game I run on my laptop, Final Fantasy XI, has been running at unusually high CPU. It's quite an old game(came out in 2002) and my laptop should be more than capable of handling it's requirements and has done so up until now. Additionally a similar thing occurs when watching YouTube videos except it's Flashplayerplugin. The thing is, when the game or adobe flash run, my CPU will jump to 99-100% but the process will only be 50-80k of memory, but when I check resource manager CPU, I see "System Interrupts" jumping around which I can't end or terminate. Once more I haven't had this issue before and I can't use a restore point(actually I tried to restore already and it doesn't help). I'm trying to avoid reformatting or reinstalling windows as I don't have the CD anymore and it's a huge hassle/pain.

 

I've tried the following countermeasures before finding out about this forum(from prior experiences/googling).


-Full scan Malwarbytes and removed all malware found.
-Ran TDSSKiller and removed rootkits.
-Tried Rkill.
-Scanreg
-Defrag
-System Restore
-Disk error scan
-Updated drivers
-Removed shady PUP's.

 

Specs:
HP Pavilion g6 Notebook
Intel Core i3 CPU Dual Core @2.67Ghz
4.00 GB RAM

Graphics:
Intel HD Graphics
Radeon TM HD 6470M

Sound:
IDT High Definition Audio Codec
Intel Display Audio

Netcard:
Qualcomm Atheros AR9285 802.11b/g/n WiFi Adapter
Realtec PCIe FE Family Controller


It's not exactly a cutting edge system but it should be sufficient to run an 12 year old game at moderate specs. Mind you, I am supersampling however I never had random 99-100% CPU before or if I did it was extremely rare.

I have a hijackthis log report if anyone can scour it for anything noteworthy :/

Hijackthis log:

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:01:09 PM, on 2/21/2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16798)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: (no name) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - (no file)
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Run: [HP Quick Launch] "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Users\Jon\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Jon\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} (Java Plug-in 1.6.0_22) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Alcohol Virtual Drive Auto-mount Service (AxAutoMntSrv) - Alcohol Soft Development Team - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IHA_MessageCenter - Verizon - C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS360service - IObit - C:\Program Files (x86)\IObit\IObit Security 360\IS360srv.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PinnacleUpdate Service (PinnacleUpdateSvc) - PowerUp Software, LLC - C:\Program Files (x86)\PowerUp Software\Pinnacle Game Profiler\pinnacle_updater.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RoxioNow Service - Roxio - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater15.3.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12730 bytes
 


Edited by Jonnycbad, 21 February 2014 - 09:55 PM.


BC AdBot (Login to Remove)

 


m

#2 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:43 PM

Posted 24 February 2014 - 08:24 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
thisisujrt.gif Please download
Junkware Removal Tool to your Desktop.
  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.
===

Download the correct version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

===

Please paste the logs in your next reply DO NOT ATTACH THEM unless specified.

Let me know what problem persists.

#3 Jonnycbad

Jonnycbad
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:43 PM

Posted 25 February 2014 - 04:32 PM

FRST

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-02-2014 01
Ran by Jon (administrator) on JON-HP on 25-02-2014 13:23:12
Running from C:\Users\Jon\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Verizon) C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Roxio) C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Microsoft Corporation) C:\Windows\System32\dinotify.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Thisisu) C:\Users\Jon\Desktop\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-07-21] (Hewlett-Packard Company)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-10-24] (IDT, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [277504 2012-03-12] (Intel Corporation)
HKLM-x32\...\Run: [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2634666426-190400968-3393963518-1000\...\Run: [ISUSPM Startup] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-16] (InstallShield Software Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x77F0D42AE463CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
URLSearchHook: HKLM-x32 - (No Name) - {03402f96-3dc7-4285-bc50-9e81fefafe43} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKCU - {44816E91-C68A-2FF3-3D8F-8970062E5600} URL = http://www.startnow.com/s/?q={searchTerms}&src=defsearch&provider=Bing&provider_code=Z059&partner_id=308&product_id=435&affiliate_id=&channel=rjacs&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110704&user_guid=B8F2076FE0DA4AAFB979404C6FEA8326&machine_id=aa43cc81de00dd8a3056185f03df57a2&browser=IE&os=win&os_version=6.1-x64-SP0
SearchScopes: HKCU - {8EF68EE7-C7B0-4A4A-888C-131F5B94BCEC} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3286042&CUI=UN77156702623882652&UM=2
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM-x32 - No Name - {61539ecd-cc67-4437-a03c-9aaccbd14326} -  No File
Toolbar: HKCU - No Name - {61539ECD-CC67-4437-A03C-9AACCBD14326} -  No File
DPF: HKLM-x32 {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 04 %SystemRoot%\System32\nwprovau.dll File Not found ()
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default
FF Homepage: www.google.com
FF NetworkProxy: "http", "127.0.0.1"
FF NetworkProxy: "http_port", 54121
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Jon\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Jon\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\searchplugins\yahoo_ff.xml
FF Extension: AOL Messaging Toolbar - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\Extensions\{c2f863cd-0429-48c7-bb54-db756a951760} [2013-09-28]
FF Extension: PDF Download - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi [2012-07-27]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-21]
FF Extension: Adblock Plus - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-07-01]
FF HKLM\...\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-10-23]
FF HKLM-x32\...\Firefox\Extensions: [OKitSpace@OKitSpace.es] - C:\Users\Jon\AppData\Roaming\okitSpace\Firefox

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR DefaultSearchProvider: Web
CHR DefaultSearchURL: http://www.google.com
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Users\Jon\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\Jon\AppData\Local\Google\Chrome\Application\33.0.1750.117\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Jon\AppData\Local\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Jon\AppData\Local\Google\Chrome\Application\33.0.1750.117\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java™ Platform SE 6 U30) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live? Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll No File
CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2012-10-20]
CHR Extension: (Google Wallet) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-10-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Jon\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-10-01]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]

==================== Services (Whitelisted) =================

S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [47416 2014-02-05] (Hewlett-Packard Company)
R2 IHA_MessageCenter; C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [350792 2013-09-13] (Verizon)
S2 IS360service; C:\Program Files (x86)\IObit\IObit Security 360\IS360srv.exe [312152 2010-06-11] (IObit)
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2013-10-20] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
S2 PinnacleUpdateSvc; C:\Program Files (x86)\PowerUp Software\Pinnacle Game Profiler\pinnacle_updater.exe [430080 2011-05-09] (PowerUp Software, LLC)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S2 vToolbarUpdater15.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-06-26] (AVG Technologies)
S0 BootDefragDriver; C:\Windows\SysWOW64\drivers\BootDefragDriver.sys [16640 2013-04-24] (<Glarysoft Ltd>)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [24344 2012-03-12] (Intel Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 rspLLL; C:\Windows\System32\DRIVERS\rspLLL64.sys [25504 2013-10-21] (Resplendence Software Projects Sp.)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [43832 2012-11-01] (Synaptics Incorporated)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2013-10-20] (Duplex Secure Ltd.)
U3 ayiutxj7; C:\Windows\System32\Drivers\ayiutxj7.sys [0 ] (Advanced Micro Devices)
S3 52242495; system32\drivers\32899734.sys [X]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-25 13:23 - 2014-02-25 13:24 - 00022644 _____ () C:\Users\Jon\Desktop\FRST.txt
2014-02-25 13:22 - 2014-02-25 13:23 - 00000000 ____D () C:\FRST
2014-02-25 13:22 - 2014-02-25 13:22 - 02156032 _____ (Farbar) C:\Users\Jon\Desktop\FRST64.exe
2014-02-25 13:14 - 2014-02-25 13:14 - 00000000 ____D () C:\Windows\ERUNT
2014-02-25 13:13 - 2014-02-25 13:13 - 01037734 _____ (Thisisu) C:\Users\Jon\Desktop\JRT.exe
2014-02-25 13:12 - 2014-02-25 13:12 - 01241834 _____ () C:\Users\Jon\Desktop\AdwCleaner.exe
2014-02-23 23:55 - 2014-02-23 23:55 - 86989752 _____ (Intel Corporation) C:\Users\Jon\Desktop\Win7Vista_64_152258.exe
2014-02-23 23:38 - 2013-12-18 11:34 - 00888536 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2014-02-23 23:38 - 2013-12-18 11:34 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2014-02-23 23:28 - 2013-10-21 09:00 - 04022272 _____ (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys
2014-02-23 23:04 - 2014-02-23 23:04 - 00000000 ____D () C:\Program Files\LatencyMon
2014-02-23 23:04 - 2013-10-21 12:26 - 00025504 _____ (Resplendence Software Projects Sp.) C:\Windows\system32\Drivers\rspLLL64.sys
2014-02-23 23:02 - 2014-02-23 23:02 - 01956880 _____ (Resplendence Software Projects Sp. ) C:\Users\Jon\Downloads\LatencyMon.exe
2014-02-23 23:02 - 2014-02-23 23:02 - 01956880 _____ (Resplendence Software Projects Sp. ) C:\Users\Jon\Downloads\LatencyMon (1).exe
2014-02-23 22:58 - 2014-02-23 22:58 - 00000000 ____D () C:\Program Files\Microsoft SDKs
2014-02-23 22:54 - 2014-02-23 22:54 - 00509264 _____ (Microsoft Corporation) C:\Users\Jon\Downloads\winsdk_web.exe
2014-02-23 22:39 - 2014-02-23 22:39 - 00991536 _____ (Microsoft Corporation) C:\Users\Jon\Downloads\sdksetup.exe
2014-02-23 22:39 - 2014-02-23 22:39 - 00991536 _____ (Microsoft Corporation) C:\Users\Jon\Downloads\sdksetup (1).exe
2014-02-23 22:25 - 2014-02-23 22:25 - 00000000 ____D () C:\Users\Jon\Desktop\ProcessExplorer
2014-02-23 22:17 - 2014-02-23 22:25 - 00000000 ____D () C:\Program Files (x86)\PCPitstop
2014-02-23 22:17 - 2014-02-23 22:23 - 00000000 ____D () C:\ProgramData\PCPitstop
2014-02-23 21:43 - 2014-02-23 21:43 - 00000552 _____ () C:\Windows\PFRO.log
2014-02-23 21:39 - 2014-02-23 21:39 - 00043471 _____ () C:\ComboFix.txt
2014-02-23 21:19 - 2011-06-26 01:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-02-23 21:19 - 2010-11-07 12:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-02-23 21:19 - 2009-04-19 23:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-02-23 21:19 - 2000-08-30 19:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-02-23 21:19 - 2000-08-30 19:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-02-23 21:19 - 2000-08-30 19:00 - 00098816 _____ () C:\Windows\sed.exe
2014-02-23 21:19 - 2000-08-30 19:00 - 00080412 _____ () C:\Windows\grep.exe
2014-02-23 21:19 - 2000-08-30 19:00 - 00068096 _____ () C:\Windows\zip.exe
2014-02-23 21:12 - 2012-10-24 22:53 - 02189312 _____ (IDT, Inc.) C:\Windows\system32\stapo64.dll
2014-02-23 21:12 - 2012-10-24 22:53 - 00672256 ____N (IDT, Inc.) C:\Windows\system32\stapi64.dll
2014-02-23 21:12 - 2012-10-24 22:53 - 00543744 _____ (IDT, Inc.) C:\Windows\system32\Drivers\stwrt64.sys
2014-02-23 21:12 - 2012-10-24 22:53 - 00499200 _____ (IDT, Inc.) C:\Windows\system32\stcplx64.dll
2014-02-23 21:12 - 2012-10-24 22:53 - 00256000 _____ (IDT, Inc.) C:\Windows\system32\st646433.dll
2014-02-23 21:11 - 2014-02-23 21:13 - 00000000 ____D () C:\Program Files\IDT
2014-02-23 21:03 - 2012-04-26 23:39 - 00073472 ____N () C:\Windows\system32\athrextx.cat
2014-02-23 21:03 - 2012-04-19 22:56 - 02811392 ____N (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\athrx.sys
2014-02-23 21:00 - 2012-03-12 10:26 - 00627992 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorA.sys
2014-02-23 21:00 - 2012-03-12 10:26 - 00024344 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorF.sys
2014-02-22 16:11 - 2014-02-22 16:11 - 00015932 _____ () C:\Windows\system32\results.xml
2014-02-22 00:10 - 2013-02-19 13:44 - 02780160 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll
2014-02-22 00:10 - 2013-02-19 13:44 - 02191872 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll
2014-02-22 00:10 - 2013-02-19 13:44 - 00090112 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v2993.dll
2014-02-22 00:10 - 2011-08-23 05:12 - 00317440 _____ (Intel® Corporation) C:\Windows\system32\Drivers\IntcDAud.sys
2014-02-22 00:10 - 2011-08-23 05:12 - 00014848 _____ (Intel® Corporation) C:\Windows\system32\IntcDAuC.dll
2014-02-22 00:10 - 2010-11-28 23:45 - 00062464 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll
2014-02-21 23:55 - 2014-02-21 23:55 - 00000000 ____D () C:\ProgramData\Oracle
2014-02-21 23:54 - 2014-02-21 23:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-02-21 23:51 - 2014-02-21 23:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-02-21 23:51 - 2014-02-21 23:49 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-02-21 23:51 - 2014-02-21 23:49 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-02-21 23:30 - 2014-02-21 23:30 - 00003038 _____ () C:\Windows\System32\Tasks\{BDC4AA02-C4F2-4C72-BB5A-BE3C4B4C1A45}
2014-02-21 23:30 - 2014-02-21 23:30 - 00003038 _____ () C:\Windows\System32\Tasks\{8ECDD259-7B65-4C7D-89BB-9D986AFFF967}
2014-02-21 22:24 - 2014-02-21 22:24 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-02-21 22:09 - 2014-02-23 20:12 - 00000000 ____D () C:\Program Files (x86)\Raptr
2014-02-21 22:09 - 2014-02-21 22:09 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\library_dir
2014-02-21 22:08 - 2014-02-23 20:52 - 00000000 ____D () C:\AMD
2014-02-21 20:55 - 2014-02-21 20:55 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2014-02-21 20:55 - 2014-02-21 20:55 - 00000000 ____D () C:\Program Files (x86)\Trend Micro
2014-02-21 19:47 - 2014-02-21 19:47 - 00003288 ____N () C:\bootsqm.dat
2014-02-21 11:28 - 2014-02-24 21:02 - 00005907 _____ () C:\Windows\AutoKMS.log
2014-02-21 11:12 - 2014-02-25 13:14 - 00000000 ____D () C:\AdwCleaner
2014-02-21 11:03 - 2014-02-25 13:15 - 00001205 _____ () C:\Windows\setupact.log
2014-02-21 11:03 - 2014-02-21 11:03 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-21 10:54 - 2014-02-21 11:27 - 00000444 _____ () C:\Windows\Tasks\DiskDefrag.job
2014-02-21 10:54 - 2014-02-21 10:54 - 00003844 _____ () C:\Windows\System32\Tasks\DiskDefrag
2014-02-21 05:40 - 2014-02-23 21:03 - 00000184 _____ () C:\setup.log
2014-02-21 05:39 - 2014-02-21 05:39 - 00002067 _____ () C:\Users\Jon\AppData\Local\FastClean.20140221.053946.txt
2014-02-21 05:14 - 2014-02-21 05:14 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-02-21 05:14 - 2014-02-21 05:14 - 00000000 ____D () C:\Program Files\AMD
2014-02-21 05:14 - 2013-07-24 03:19 - 00229376 _____ () C:\Windows\system32\clinfo.exe
2014-02-21 05:14 - 2013-07-24 03:18 - 28193280 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2014-02-21 05:14 - 2013-07-24 03:18 - 00098816 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo64.dll
2014-02-21 05:14 - 2013-07-24 03:18 - 00086528 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode64.dll
2014-02-21 05:14 - 2013-07-24 03:18 - 00083456 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OpenVideo.dll
2014-02-21 05:14 - 2013-07-24 03:18 - 00073216 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\OVDecode.dll
2014-02-21 05:14 - 2013-07-24 03:16 - 23761408 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2014-02-21 05:14 - 2013-07-24 03:14 - 00063488 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-02-21 05:14 - 2013-07-24 03:14 - 00057344 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-02-21 05:04 - 2013-04-10 16:34 - 00332800 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODE.exe
2014-02-21 05:04 - 2013-04-10 16:34 - 00051200 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODCLI.exe
2014-02-21 05:03 - 2014-01-31 20:48 - 00044544 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2014-02-21 05:03 - 2014-01-31 20:47 - 00035840 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2014-02-21 04:56 - 2013-07-24 02:22 - 00204952 _____ () C:\Windows\SysWOW64\ativvsvl.dat
2014-02-21 04:56 - 2013-07-24 02:22 - 00204952 _____ () C:\Windows\system32\ativvsvl.dat
2014-02-21 04:56 - 2013-07-24 02:22 - 00157144 _____ () C:\Windows\SysWOW64\ativvsva.dat
2014-02-21 04:56 - 2013-07-24 02:22 - 00157144 _____ () C:\Windows\system32\ativvsva.dat
2014-02-21 04:55 - 2013-07-24 03:19 - 01187342 _____ () C:\Windows\system32\amdocl_as64.exe
2014-02-21 04:55 - 2013-07-24 03:19 - 01061902 _____ () C:\Windows\system32\amdocl_ld64.exe
2014-02-21 04:55 - 2013-07-24 03:19 - 00798734 _____ () C:\Windows\SysWOW64\amdocl_ld32.exe
2014-02-21 04:55 - 2013-07-24 03:18 - 00995342 _____ () C:\Windows\SysWOW64\amdocl_as32.exe
2014-02-21 04:15 - 2014-02-21 04:15 - 00000000 ____D () C:\Users\Jon\AppData\Local\Innovative Solutions
2014-02-21 04:11 - 2014-02-21 04:11 - 08436672 _____ (Innovative Solutions ) C:\Users\Jon\Downloads\drivermax_7_28_cnet.exe
2014-02-21 02:53 - 2013-05-10 00:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-02-21 02:53 - 2013-05-10 00:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-02-21 02:53 - 2013-05-09 23:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-02-21 02:53 - 2013-05-09 23:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-02-21 02:42 - 2014-02-21 03:32 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-21 01:58 - 2013-10-01 21:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-02-21 01:58 - 2013-10-01 21:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-02-21 01:58 - 2013-10-01 21:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-02-21 01:58 - 2013-10-01 20:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-02-21 01:58 - 2013-10-01 20:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-02-21 01:58 - 2013-10-01 20:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-02-21 01:58 - 2013-10-01 20:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-02-21 01:58 - 2013-10-01 19:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-21 01:58 - 2013-10-01 19:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-02-21 01:58 - 2013-10-01 19:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-02-21 01:58 - 2013-10-01 19:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-02-21 01:58 - 2013-10-01 19:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-02-21 01:58 - 2013-10-01 18:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-02-21 01:58 - 2013-10-01 18:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-02-21 01:58 - 2013-10-01 18:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-21 01:58 - 2013-10-01 17:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-02-21 01:58 - 2013-10-01 15:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-21 01:58 - 2013-10-01 15:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 19274240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 15403520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 14359040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-21 00:37 - 2014-02-21 00:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-21 00:37 - 2014-02-21 00:37 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-21 00:37 - 2014-02-21 00:37 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-21 00:37 - 2014-02-21 00:37 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-02-21 00:37 - 2014-02-21 00:37 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-02-21 00:37 - 2014-02-21 00:37 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-02-21 00:37 - 2014-02-21 00:37 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-02-21 00:37 - 2014-02-21 00:37 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-02-21 00:37 - 2014-02-21 00:37 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-02-21 00:37 - 2014-02-21 00:37 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-02-21 00:12 - 2012-08-23 09:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-02-21 00:12 - 2012-08-23 09:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-02-21 00:12 - 2012-08-23 08:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-02-21 00:12 - 2012-08-23 06:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2014-02-21 00:12 - 2012-08-23 05:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-02-21 00:12 - 2012-08-23 04:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-02-20 23:55 - 2014-02-20 23:55 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-02-20 22:58 - 2012-07-25 22:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-02-20 22:58 - 2012-07-25 22:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-02-20 22:58 - 2012-07-25 22:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-02-20 22:58 - 2012-07-25 22:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-02-20 22:58 - 2012-07-25 22:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-02-20 22:58 - 2012-07-25 21:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-02-20 22:58 - 2012-07-25 21:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-02-20 22:58 - 2012-06-02 09:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-02-20 22:34 - 2013-01-13 16:17 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 16:17 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 16:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 16:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-02-20 22:34 - 2013-01-13 16:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-02-20 22:34 - 2013-01-13 16:11 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 16:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 16:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 16:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:35 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:35 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:35 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:31 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-02-20 22:34 - 2013-01-13 15:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:31 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-02-20 22:34 - 2013-01-13 15:22 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-20 22:34 - 2013-01-13 15:20 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-02-20 22:34 - 2013-01-13 15:09 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-02-20 22:34 - 2013-01-13 15:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-02-20 22:34 - 2013-01-13 14:59 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-02-20 22:34 - 2013-01-13 14:58 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-02-20 22:34 - 2013-01-13 14:54 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-02-20 22:34 - 2013-01-13 14:53 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-02-20 22:34 - 2013-01-13 14:53 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-02-20 22:34 - 2013-01-13 14:51 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-20 22:34 - 2013-01-13 14:49 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-02-20 22:34 - 2013-01-13 14:48 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-02-20 22:34 - 2013-01-13 14:46 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-02-20 22:34 - 2013-01-13 14:43 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-02-20 22:34 - 2013-01-13 14:38 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-02-20 22:34 - 2013-01-13 14:38 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-02-20 22:34 - 2013-01-13 14:37 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-20 22:34 - 2013-01-13 14:25 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-02-20 22:34 - 2013-01-13 14:24 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-02-20 22:34 - 2013-01-13 14:24 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-02-20 22:34 - 2013-01-13 14:20 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-02-20 22:34 - 2013-01-13 14:20 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-02-20 22:34 - 2013-01-13 14:15 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-02-20 22:34 - 2013-01-13 14:10 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-20 22:34 - 2013-01-13 14:02 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-02-20 22:34 - 2013-01-13 13:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-02-20 22:34 - 2013-01-13 13:32 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-02-20 22:34 - 2013-01-13 13:09 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-02-20 22:34 - 2013-01-13 12:26 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-02-20 22:34 - 2013-01-13 12:05 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-02-20 22:34 - 2013-01-04 01:11 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-02-20 22:34 - 2013-01-04 01:11 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-02-20 22:14 - 2013-07-20 05:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-02-20 22:14 - 2013-07-20 05:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-02-20 22:14 - 2013-07-04 07:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-02-20 22:14 - 2013-07-04 06:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-02-20 22:14 - 2013-02-11 23:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-02-20 22:14 - 2012-11-30 00:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-02-20 22:14 - 2012-11-30 00:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-02-20 22:14 - 2012-11-30 00:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-02-20 22:13 - 2013-11-26 20:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-02-20 22:13 - 2013-11-26 20:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-02-20 22:13 - 2013-11-26 20:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-02-20 22:13 - 2013-11-26 20:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-02-20 22:13 - 2013-11-26 20:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-02-20 22:13 - 2013-11-26 20:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-02-20 22:13 - 2013-11-26 20:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-02-20 22:13 - 2013-11-26 05:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-02-20 22:13 - 2013-10-18 21:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-02-20 22:13 - 2013-10-18 20:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-02-20 22:13 - 2013-08-01 07:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-02-20 22:13 - 2013-07-12 05:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-02-20 22:13 - 2013-07-12 05:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-02-20 22:13 - 2013-07-12 05:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2014-02-20 22:13 - 2013-07-02 23:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-02-20 22:13 - 2013-07-02 23:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-02-20 22:13 - 2013-06-14 23:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-02-20 22:13 - 2013-04-25 18:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-02-20 22:13 - 2013-04-12 09:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-02-20 22:13 - 2013-04-10 01:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-02-20 22:13 - 2013-03-31 17:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-02-20 22:13 - 2012-11-02 00:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-02-20 22:13 - 2012-11-02 00:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-02-20 22:13 - 2012-10-09 13:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-02-20 22:13 - 2012-10-09 13:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-02-20 22:13 - 2012-10-09 12:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-02-20 22:13 - 2012-10-09 12:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-02-20 22:13 - 2012-08-22 13:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-02-20 22:13 - 2012-07-04 15:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-02-20 22:13 - 2011-02-03 06:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-02-20 22:12 - 2013-10-29 21:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-02-20 22:12 - 2013-10-29 21:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-02-20 22:12 - 2013-10-11 21:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-02-20 22:12 - 2013-10-11 21:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-02-20 22:12 - 2013-10-11 21:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-02-20 22:12 - 2013-10-11 21:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-02-20 22:12 - 2013-10-11 20:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-02-20 22:12 - 2013-10-11 20:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-02-20 22:12 - 2013-10-11 20:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-02-20 22:12 - 2013-10-11 20:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-02-20 22:12 - 2013-10-03 21:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-02-20 22:12 - 2013-10-03 20:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-02-20 22:12 - 2013-10-02 21:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-02-20 22:12 - 2013-10-02 21:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-02-20 22:12 - 2013-09-27 20:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-02-20 22:12 - 2013-09-07 21:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-02-20 22:12 - 2013-09-07 21:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-02-20 22:12 - 2013-07-04 07:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-02-20 22:12 - 2013-07-04 07:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-02-20 22:12 - 2013-07-04 06:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-02-20 22:12 - 2013-07-04 06:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-02-20 22:12 - 2013-07-04 05:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-02-20 22:12 - 2013-06-06 00:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-02-20 22:12 - 2013-06-06 00:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-02-20 22:12 - 2013-06-06 00:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-02-20 22:12 - 2013-06-06 00:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-02-20 22:12 - 2013-06-05 23:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-02-20 22:12 - 2013-06-05 23:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-02-20 22:12 - 2013-06-05 23:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-02-20 22:12 - 2013-06-05 22:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-02-20 22:12 - 2013-06-05 22:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-02-20 22:12 - 2013-06-05 22:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-02-20 22:12 - 2013-03-19 00:53 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-02-20 22:12 - 2013-03-19 00:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-02-20 22:12 - 2012-08-21 16:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-02-20 22:12 - 2012-04-26 00:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-02-20 22:12 - 2012-04-26 00:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-02-20 22:12 - 2012-04-26 00:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-02-20 22:11 - 2013-12-03 21:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-20 22:11 - 2013-12-03 21:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-20 22:11 - 2013-12-03 21:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-20 22:11 - 2013-12-03 21:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-20 22:11 - 2013-12-03 21:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-20 22:11 - 2013-12-03 21:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-20 22:11 - 2013-12-03 21:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-20 22:11 - 2013-12-03 21:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-20 22:11 - 2013-12-03 21:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-20 22:11 - 2013-12-03 21:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-20 22:11 - 2013-12-03 21:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-20 22:11 - 2013-12-03 21:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-20 22:11 - 2013-12-03 21:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-20 22:11 - 2013-12-03 21:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-20 22:11 - 2013-12-03 20:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-20 22:11 - 2013-12-03 20:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-20 22:11 - 2013-12-03 20:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-20 22:11 - 2013-12-03 20:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-20 22:11 - 2013-10-05 15:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-02-20 22:11 - 2013-10-05 14:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-02-20 22:11 - 2013-08-28 21:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-02-20 22:11 - 2013-08-28 21:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-02-20 22:11 - 2013-08-28 21:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-02-20 22:11 - 2013-08-28 21:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-02-20 22:11 - 2013-08-28 21:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-02-20 22:11 - 2013-08-28 20:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-02-20 22:11 - 2013-08-28 20:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-02-20 22:11 - 2013-08-28 20:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-02-20 22:11 - 2013-08-28 20:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-02-20 22:11 - 2013-08-28 20:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-02-20 22:11 - 2013-08-28 20:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-02-20 22:11 - 2013-08-28 19:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-02-20 22:11 - 2013-08-28 19:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-02-20 22:11 - 2013-08-28 19:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-02-20 22:11 - 2013-08-28 19:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-02-20 22:11 - 2013-07-09 00:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-02-20 22:11 - 2013-07-09 00:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-02-20 22:11 - 2013-07-08 23:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-02-20 22:11 - 2013-07-08 23:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-02-20 22:10 - 2013-08-01 21:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-02-20 22:10 - 2013-08-01 21:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-02-20 22:10 - 2013-08-01 21:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 21:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-02-20 22:10 - 2013-08-01 20:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 20:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-02-20 22:10 - 2013-08-01 19:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-02-20 22:10 - 2013-08-01 19:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 19:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 19:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-02-20 22:10 - 2013-08-01 19:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-02-20 22:10 - 2013-05-13 00:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-02-20 22:10 - 2013-05-12 22:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-02-20 22:10 - 2013-05-12 22:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-02-20 22:10 - 2013-05-12 22:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-02-20 22:10 - 2012-12-07 08:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-02-20 22:10 - 2012-12-07 08:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-02-20 22:10 - 2012-12-07 07:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-02-20 22:10 - 2012-12-07 07:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-02-20 22:10 - 2012-12-07 06:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-02-20 22:10 - 2012-12-07 06:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-02-20 22:10 - 2012-12-07 06:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-02-20 22:10 - 2012-12-07 06:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-02-20 22:10 - 2012-12-07 06:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-02-20 22:10 - 2012-12-07 06:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-02-20 22:10 - 2012-12-07 06:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-02-20 22:10 - 2012-12-07 06:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-02-20 22:10 - 2012-12-07 06:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-02-20 22:10 - 2012-12-07 06:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-02-20 22:10 - 2012-12-07 06:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-02-20 22:10 - 2012-12-07 06:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-02-20 22:10 - 2012-12-07 06:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-02-20 22:10 - 2012-12-07 06:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2014-02-20 22:10 - 2012-12-07 05:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2014-02-20 22:09 - 2012-11-01 00:43 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-02-20 22:09 - 2012-10-31 23:47 - 01389568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-02-20 22:09 - 2012-10-03 12:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-02-20 22:09 - 2012-10-03 12:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-02-20 22:09 - 2012-10-03 12:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-02-20 22:09 - 2012-10-03 12:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-02-20 22:09 - 2012-10-03 12:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-02-20 22:09 - 2012-10-03 12:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-02-20 22:09 - 2012-10-03 11:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2014-02-20 22:09 - 2012-10-03 11:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2014-02-20 22:09 - 2012-10-03 11:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2014-02-20 22:09 - 2012-10-03 11:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-02-20 22:09 - 2012-01-13 02:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2014-02-20 22:08 - 2013-10-03 21:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-02-20 22:08 - 2013-10-03 21:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-02-20 22:08 - 2013-10-03 21:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-02-20 22:08 - 2013-10-03 20:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2014-02-20 22:08 - 2013-10-03 20:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-02-20 22:08 - 2013-10-03 20:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2014-02-20 22:08 - 2013-09-24 21:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-02-20 22:08 - 2013-09-24 21:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-02-20 22:08 - 2013-09-24 21:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-02-20 22:08 - 2013-09-24 21:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-02-20 22:08 - 2013-09-24 21:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-02-20 22:08 - 2013-09-24 21:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-02-20 22:08 - 2013-09-24 21:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-02-20 22:08 - 2013-09-24 21:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-02-20 22:08 - 2013-09-24 21:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-02-20 22:08 - 2013-09-24 20:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-02-20 22:08 - 2013-09-24 20:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-02-20 22:08 - 2013-09-24 20:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-02-20 22:08 - 2013-09-24 20:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-02-20 22:08 - 2013-09-24 20:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-02-20 22:08 - 2013-09-24 20:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-02-20 22:08 - 2013-07-09 00:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-02-20 22:08 - 2013-07-08 23:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-02-20 22:08 - 2013-07-04 07:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-02-20 22:08 - 2013-02-27 01:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-02-20 22:08 - 2013-02-27 00:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-02-20 22:07 - 2013-07-25 21:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-02-20 22:07 - 2013-07-25 21:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-02-20 22:07 - 2013-07-25 20:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-02-20 22:07 - 2013-07-25 20:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-02-20 22:07 - 2013-07-25 04:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-02-20 22:07 - 2013-07-25 03:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-02-20 22:07 - 2013-07-09 00:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-02-20 22:07 - 2013-07-08 23:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-02-20 22:07 - 2013-05-10 00:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-02-20 22:07 - 2013-05-09 22:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2014-02-20 22:07 - 2012-11-22 00:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-02-20 22:07 - 2012-11-21 23:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-02-20 22:06 - 2013-12-31 18:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-20 22:06 - 2013-12-31 18:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-20 22:06 - 2013-12-05 21:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-20 22:06 - 2013-12-05 21:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-20 22:06 - 2013-12-05 21:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-20 22:06 - 2013-12-05 21:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-20 22:06 - 2013-11-26 06:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-02-20 22:06 - 2013-11-11 21:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-02-20 22:06 - 2013-11-11 21:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-02-20 22:06 - 2013-09-07 21:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-02-20 22:06 - 2013-08-04 21:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-02-20 22:06 - 2013-06-25 17:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-02-20 22:06 - 2013-06-04 01:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-02-20 22:06 - 2013-06-03 23:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-02-20 22:06 - 2013-04-26 00:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-02-20 22:06 - 2013-04-25 23:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-02-20 22:06 - 2013-01-24 01:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-02-20 22:06 - 2013-01-03 01:00 - 00288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-02-20 22:06 - 2012-11-28 17:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-02-20 22:06 - 2012-11-28 17:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-02-20 22:06 - 2012-11-28 17:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-02-20 22:06 - 2012-11-22 22:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-02-20 22:06 - 2012-09-25 17:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-02-20 22:06 - 2012-09-25 17:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-02-20 22:06 - 2012-08-10 19:56 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-02-20 22:06 - 2012-08-10 18:56 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-02-20 22:06 - 2012-07-04 17:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-02-20 22:06 - 2012-07-04 17:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-02-20 22:06 - 2012-07-04 17:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-02-20 22:06 - 2012-07-04 16:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-02-20 22:06 - 2012-07-04 16:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-02-20 22:06 - 2012-05-14 00:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-02-20 22:06 - 2012-05-05 03:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-02-20 22:06 - 2012-05-05 02:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-02-20 22:06 - 2012-05-04 06:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-02-20 22:06 - 2012-05-04 04:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-02-20 22:06 - 2012-05-01 00:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-02-20 22:06 - 2012-04-27 22:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-02-20 22:06 - 2012-04-07 07:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-02-20 22:06 - 2012-04-07 06:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-02-20 22:06 - 2012-03-17 02:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-02-20 22:04 - 2013-10-11 21:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-02-20 22:04 - 2013-10-11 21:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-02-20 22:04 - 2013-10-11 21:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-02-20 22:04 - 2013-10-11 21:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-02-20 22:04 - 2013-10-11 21:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-02-20 22:04 - 2012-06-06 01:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-02-20 22:04 - 2012-06-06 00:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-02-20 21:42 - 2013-08-27 20:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-02-20 21:16 - 2012-06-02 17:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-02-20 21:16 - 2012-06-02 17:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-02-20 21:16 - 2012-06-02 17:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-02-20 21:16 - 2012-06-02 17:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-02-20 21:16 - 2012-06-02 17:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-02-20 21:16 - 2012-06-02 17:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-02-20 21:16 - 2012-06-02 17:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-02-20 21:16 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-02-20 21:16 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-02-20 19:46 - 2014-02-23 20:09 - 00000324 _____ () C:\Windows\Tasks\HPCeeScheduleForJon.job
2014-02-20 19:46 - 2014-02-22 16:58 - 00003174 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForJon
2014-02-14 12:07 - 2014-02-14 12:07 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\PowerUp Software
2014-02-14 10:48 - 2014-02-14 10:48 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
2014-02-14 10:27 - 2014-02-14 10:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-14 09:38 - 2014-02-14 09:38 - 00000042 _____ () C:\Windows\SysWOW64\AK083E209605E394C.lie
2014-02-13 21:15 - 2014-02-23 21:39 - 00000000 ____D () C:\Qoobox
2014-02-13 19:29 - 2014-02-13 19:41 - 00000000 ____D () C:\Users\Jon\Downloads\The Monuments Men 2013
2014-02-13 19:26 - 2014-02-13 19:34 - 00000000 ____D () C:\Users\Jon\Downloads\The Monuments Men (2014)BDRip XviD-AN0NYM0US
2014-02-08 23:33 - 2014-02-08 23:36 - 00000000 ____D () C:\Users\Jon\Desktop\Microglia
2014-02-08 23:29 - 2014-02-08 23:32 - 00000000 ____D () C:\Users\Jon\Desktop\Resume&CV
2014-02-02 10:24 - 2014-02-08 22:56 - 00000000 ____D () C:\Users\Jon\Downloads\Kandel

==================== One Month Modified Files and Folders =======

2014-02-25 13:24 - 2014-02-25 13:23 - 00022644 _____ () C:\Users\Jon\Desktop\FRST.txt
2014-02-25 13:24 - 2012-04-13 08:56 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-25 13:23 - 2014-02-25 13:22 - 00000000 ____D () C:\FRST
2014-02-25 13:23 - 2009-07-13 23:45 - 00026192 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-25 13:23 - 2009-07-13 23:45 - 00026192 _____ () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-25 13:22 - 2014-02-25 13:22 - 02156032 _____ (Farbar) C:\Users\Jon\Desktop\FRST64.exe
2014-02-25 13:19 - 2013-05-22 10:07 - 01585007 _____ () C:\Windows\WindowsUpdate.log
2014-02-25 13:17 - 2013-07-01 12:39 - 00000328 _____ () C:\Windows\Tasks\GlaryInitialize 3.job
2014-02-25 13:15 - 2014-02-21 11:03 - 00001205 _____ () C:\Windows\setupact.log
2014-02-25 13:15 - 2011-12-23 22:17 - 00000888 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-25 13:15 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-25 13:14 - 2014-02-25 13:14 - 00000000 ____D () C:\Windows\ERUNT
2014-02-25 13:14 - 2014-02-21 11:12 - 00000000 ____D () C:\AdwCleaner
2014-02-25 13:13 - 2014-02-25 13:13 - 01037734 _____ (Thisisu) C:\Users\Jon\Desktop\JRT.exe
2014-02-25 13:12 - 2014-02-25 13:12 - 01241834 _____ () C:\Users\Jon\Desktop\AdwCleaner.exe
2014-02-25 00:28 - 2011-12-23 22:17 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-25 00:18 - 2013-08-12 10:10 - 00119296 _____ () C:\Windows\SysWOW64\zlib.dll
2014-02-24 23:53 - 2012-08-30 09:03 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2634666426-190400968-3393963518-1000UA.job
2014-02-24 22:43 - 2011-06-29 10:25 - 00000000 ____D () C:\Users\Jon\AppData\Local\CrashDumps
2014-02-24 21:02 - 2014-02-21 11:28 - 00005907 _____ () C:\Windows\AutoKMS.log
2014-02-24 21:02 - 2012-03-18 19:02 - 00003494 _____ () C:\Windows\System32\Tasks\AutoKMS
2014-02-24 21:02 - 2012-03-18 19:02 - 00000202 _____ () C:\Windows\Tasks\AutoKMSDaily.job
2014-02-24 00:37 - 2013-07-01 12:38 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 3
2014-02-23 23:55 - 2014-02-23 23:55 - 86989752 _____ (Intel Corporation) C:\Users\Jon\Desktop\Win7Vista_64_152258.exe
2014-02-23 23:04 - 2014-02-23 23:04 - 00000000 ____D () C:\Program Files\LatencyMon
2014-02-23 23:02 - 2014-02-23 23:02 - 01956880 _____ (Resplendence Software Projects Sp. ) C:\Users\Jon\Downloads\LatencyMon.exe
2014-02-23 23:02 - 2014-02-23 23:02 - 01956880 _____ (Resplendence Software Projects Sp. ) C:\Users\Jon\Downloads\LatencyMon (1).exe
2014-02-23 22:58 - 2014-02-23 22:58 - 00000000 ____D () C:\Program Files\Microsoft SDKs
2014-02-23 22:58 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-02-23 22:54 - 2014-02-23 22:54 - 00509264 _____ (Microsoft Corporation) C:\Users\Jon\Downloads\winsdk_web.exe
2014-02-23 22:39 - 2014-02-23 22:39 - 00991536 _____ (Microsoft Corporation) C:\Users\Jon\Downloads\sdksetup.exe
2014-02-23 22:39 - 2014-02-23 22:39 - 00991536 _____ (Microsoft Corporation) C:\Users\Jon\Downloads\sdksetup (1).exe
2014-02-23 22:25 - 2014-02-23 22:25 - 00000000 ____D () C:\Users\Jon\Desktop\ProcessExplorer
2014-02-23 22:25 - 2014-02-23 22:17 - 00000000 ____D () C:\Program Files (x86)\PCPitstop
2014-02-23 22:23 - 2014-02-23 22:17 - 00000000 ____D () C:\ProgramData\PCPitstop
2014-02-23 22:08 - 2009-07-14 00:08 - 00032536 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-23 21:50 - 2012-05-09 10:24 - 00796852 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-23 21:43 - 2014-02-23 21:43 - 00000552 _____ () C:\Windows\PFRO.log
2014-02-23 21:39 - 2014-02-23 21:39 - 00043471 _____ () C:\ComboFix.txt
2014-02-23 21:39 - 2014-02-13 21:15 - 00000000 ____D () C:\Qoobox
2014-02-23 21:34 - 2009-07-13 21:34 - 00000215 _____ () C:\Windows\system.ini
2014-02-23 21:13 - 2014-02-23 21:11 - 00000000 ____D () C:\Program Files\IDT
2014-02-23 21:11 - 2009-09-06 19:40 - 00000000 ____D () C:\SwSetup
2014-02-23 21:04 - 2011-12-01 20:12 - 00000000 ____D () C:\ProgramData\InstallShield
2014-02-23 21:03 - 2014-02-21 05:40 - 00000184 _____ () C:\setup.log
2014-02-23 21:03 - 2013-01-04 07:13 - 00000000 ____D () C:\Program Files (x86)\Atheros
2014-02-23 21:03 - 2011-01-16 16:42 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-02-23 21:02 - 2011-06-20 22:59 - 00000000 ____D () C:\ProgramData\Atheros
2014-02-23 21:00 - 2011-06-20 22:56 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-02-23 20:58 - 2011-06-20 23:00 - 00000000 ____D () C:\Program Files (x86)\Realtek
2014-02-23 20:52 - 2014-02-21 22:08 - 00000000 ____D () C:\AMD
2014-02-23 20:30 - 2011-12-27 18:32 - 00000000 ____D () C:\Users\Jon\Desktop\FFXIRelated
2014-02-23 20:12 - 2014-02-21 22:09 - 00000000 ____D () C:\Program Files (x86)\Raptr
2014-02-23 20:09 - 2014-02-20 19:46 - 00000324 _____ () C:\Windows\Tasks\HPCeeScheduleForJon.job
2014-02-23 19:23 - 2012-08-30 09:03 - 00000848 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2634666426-190400968-3393963518-1000Core.job
2014-02-22 17:03 - 2011-06-28 16:25 - 00000000 ____D () C:\Users\Jon
2014-02-22 16:58 - 2014-02-20 19:46 - 00003174 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForJon
2014-02-22 16:58 - 2009-07-14 00:13 - 00779266 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-22 16:11 - 2014-02-22 16:11 - 00015932 _____ () C:\Windows\system32\results.xml
2014-02-22 00:14 - 2011-06-20 22:58 - 00000000 ____D () C:\Intel
2014-02-21 23:55 - 2014-02-21 23:55 - 00000000 ____D () C:\ProgramData\Oracle
2014-02-21 23:49 - 2014-02-21 23:54 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-02-21 23:49 - 2014-02-21 23:51 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-02-21 23:49 - 2014-02-21 23:51 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-02-21 23:49 - 2014-02-21 23:51 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-02-21 23:49 - 2011-01-16 16:45 - 00000000 ____D () C:\Program Files (x86)\Java
2014-02-21 23:30 - 2014-02-21 23:30 - 00003038 _____ () C:\Windows\System32\Tasks\{BDC4AA02-C4F2-4C72-BB5A-BE3C4B4C1A45}
2014-02-21 23:30 - 2014-02-21 23:30 - 00003038 _____ () C:\Windows\System32\Tasks\{8ECDD259-7B65-4C7D-89BB-9D986AFFF967}
2014-02-21 23:28 - 2011-06-28 16:52 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-02-21 22:47 - 2011-07-22 22:39 - 00007584 _____ () C:\Users\Jon\AppData\Local\Resmon.ResmonCfg
2014-02-21 22:24 - 2014-02-21 22:24 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-02-21 22:09 - 2014-02-21 22:09 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\library_dir
2014-02-21 20:55 - 2014-02-21 20:55 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2014-02-21 20:55 - 2014-02-21 20:55 - 00000000 ____D () C:\Program Files (x86)\Trend Micro
2014-02-21 19:47 - 2014-02-21 19:47 - 00003288 ____N () C:\bootsqm.dat
2014-02-21 19:47 - 2013-07-01 12:58 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\DiskDefrag
2014-02-21 14:17 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\rescache
2014-02-21 11:27 - 2014-02-21 10:54 - 00000444 _____ () C:\Windows\Tasks\DiskDefrag.job
2014-02-21 11:03 - 2014-02-21 11:03 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-21 10:54 - 2014-02-21 10:54 - 00003844 _____ () C:\Windows\System32\Tasks\DiskDefrag
2014-02-21 10:53 - 2011-07-03 19:36 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\uTorrent
2014-02-21 10:43 - 2013-07-01 12:47 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup-Disabled
2014-02-21 10:43 - 2011-06-28 16:31 - 00000000 ___RD () C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-21 10:42 - 2012-02-18 14:49 - 00000000 ___RD () C:\Users\Jon\Dropbox
2014-02-21 10:42 - 2012-02-18 14:48 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\Dropbox
2014-02-21 05:44 - 2013-01-04 07:13 - 00000000 ____D () C:\Windows\system32\nn-NO
2014-02-21 05:44 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-02-21 05:39 - 2014-02-21 05:39 - 00002067 _____ () C:\Users\Jon\AppData\Local\FastClean.20140221.053946.txt
2014-02-21 05:14 - 2014-02-21 05:14 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-02-21 05:14 - 2014-02-21 05:14 - 00000000 ____D () C:\Program Files\AMD
2014-02-21 04:15 - 2014-02-21 04:15 - 00000000 ____D () C:\Users\Jon\AppData\Local\Innovative Solutions
2014-02-21 04:11 - 2014-02-21 04:11 - 08436672 _____ (Innovative Solutions ) C:\Users\Jon\Downloads\drivermax_7_28_cnet.exe
2014-02-21 03:59 - 2009-09-06 20:57 - 00000000 ____D () C:\Windows\Panther
2014-02-21 03:32 - 2014-02-21 02:42 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-21 03:31 - 2011-06-28 16:29 - 00109688 _____ () C:\Users\Jon\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-21 03:31 - 2009-07-14 00:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-02-21 03:30 - 2011-06-28 16:31 - 00000000 ___RD () C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-02-21 03:29 - 2011-06-28 16:31 - 00001413 _____ () C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-02-21 03:25 - 2011-01-16 16:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-02-21 03:25 - 2009-07-13 23:45 - 00415680 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-21 03:20 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-02-21 03:20 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-02-21 03:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-02-21 03:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-02-21 03:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-02-21 03:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-02-21 01:43 - 2012-01-26 15:36 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-21 01:38 - 2009-07-13 21:34 - 00000478 _____ () C:\Windows\win.ini
2014-02-21 00:37 - 2014-02-21 00:37 - 19274240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 15403520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 14359040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-21 00:37 - 2014-02-21 00:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-21 00:37 - 2014-02-21 00:37 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-21 00:37 - 2014-02-21 00:37 - 01441280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-21 00:37 - 2014-02-21 00:37 - 01400416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-02-21 00:37 - 2014-02-21 00:37 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-02-21 00:37 - 2014-02-21 00:37 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 01054720 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00905728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00719360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00523264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-02-21 00:37 - 2014-02-21 00:37 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-02-21 00:37 - 2014-02-21 00:37 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00242200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00232960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00185344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00173568 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00137216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00079872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-02-21 00:37 - 2014-02-21 00:37 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-02-21 00:37 - 2014-02-21 00:37 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-02-21 00:37 - 2014-02-21 00:37 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-02-21 00:37 - 2014-02-21 00:37 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-02-21 00:24 - 2012-04-13 08:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-21 00:24 - 2012-04-13 08:56 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-21 00:24 - 2011-06-28 22:27 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-20 23:55 - 2014-02-20 23:55 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-02-20 21:07 - 2011-06-30 19:30 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-02-20 21:06 - 2011-11-03 22:56 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-02-20 20:54 - 2012-05-09 11:13 - 00000000 ____D () C:\Program Files (x86)\HP
2014-02-18 17:23 - 2011-12-23 22:17 - 00003888 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-18 17:23 - 2011-12-23 22:17 - 00003636 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-18 12:48 - 2012-08-30 09:03 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2634666426-190400968-3393963518-1000UA
2014-02-18 12:48 - 2012-08-30 09:03 - 00003474 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2634666426-190400968-3393963518-1000Core
2014-02-17 23:34 - 2011-08-04 08:49 - 00003214 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForJON-HP$
2014-02-17 23:34 - 2011-08-04 08:49 - 00000338 _____ () C:\Windows\Tasks\HPCeeScheduleForJON-HP$.job
2014-02-17 23:01 - 2012-05-15 21:43 - 00013425 _____ () C:\Users\Jon\Desktop\EPIC.txt
2014-02-14 14:51 - 2012-05-02 17:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-14 12:07 - 2014-02-14 12:07 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\PowerUp Software
2014-02-14 10:54 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\Help
2014-02-14 10:50 - 2011-01-16 16:25 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-02-14 10:48 - 2014-02-14 10:48 - 00000000 ____D () C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
2014-02-14 10:48 - 2011-01-16 16:41 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-02-14 10:27 - 2014-02-14 10:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-14 09:38 - 2014-02-14 09:38 - 00000042 _____ () C:\Windows\SysWOW64\AK083E209605E394C.lie
2014-02-13 23:32 - 2012-02-14 23:37 - 00000000 ____D () C:\TDSSKiller_Quarantine
2014-02-13 23:20 - 2013-11-24 15:22 - 00000000 ____D () C:\ProgramData\Licenses
2014-02-13 23:20 - 2012-08-30 09:07 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-02-13 23:20 - 2012-02-25 14:36 - 00000000 ____D () C:\Windows\system32\Macromed
2014-02-13 23:20 - 2011-12-20 19:16 - 00000000 ____D () C:\Windows\ERDNT
2014-02-13 23:20 - 2011-09-22 20:10 - 00000000 ____D () C:\ProgramData\Intel
2014-02-13 23:20 - 2011-07-03 19:37 - 00000000 ____D () C:\Program Files (x86)\uTorrent
2014-02-13 23:20 - 2011-01-16 16:34 - 00000000 ____D () C:\ProgramData\RoxioNow
2014-02-13 23:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\registration
2014-02-13 23:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\AppCompat
2014-02-13 23:19 - 2013-03-27 20:24 - 00000000 ____D () C:\Users\Jon\Desktop\Windower4
2014-02-13 23:19 - 2011-12-09 08:24 - 00000000 ____D () C:\Users\Jon\Desktop\KOF
2014-02-13 23:19 - 2011-11-04 00:07 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\Malwarebytes
2014-02-13 23:19 - 2011-06-28 16:35 - 00000000 ____D () C:\Users\Jon\AppData\Roaming\Adobe
2014-02-13 23:18 - 2009-09-06 19:40 - 00000000 ____D () C:\SYSTEM.SAV
2014-02-13 23:17 - 2011-12-01 20:12 - 00000000 ____D () C:\Games
2014-02-13 19:41 - 2014-02-13 19:29 - 00000000 ____D () C:\Users\Jon\Downloads\The Monuments Men 2013
2014-02-13 19:34 - 2014-02-13 19:26 - 00000000 ____D () C:\Users\Jon\Downloads\The Monuments Men (2014)BDRip XviD-AN0NYM0US
2014-02-10 12:28 - 2011-06-30 09:37 - 00000000 ____D () C:\Users\Jon\AppData\Local\Adobe
2014-02-08 23:36 - 2014-02-08 23:33 - 00000000 ____D () C:\Users\Jon\Desktop\Microglia
2014-02-08 23:36 - 2012-08-27 18:47 - 00000000 ____D () C:\Users\Jon\Desktop\School
2014-02-08 23:32 - 2014-02-08 23:29 - 00000000 ____D () C:\Users\Jon\Desktop\Resume&CV
2014-02-08 22:56 - 2014-02-02 10:24 - 00000000 ____D () C:\Users\Jon\Downloads\Kandel
2014-02-06 23:58 - 2012-12-03 19:22 - 00000000 ____D () C:\Users\Jon\Desktop\Pics
2014-02-04 19:09 - 2011-08-19 23:57 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-31 20:48 - 2014-02-21 05:03 - 00044544 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2014-01-31 20:47 - 2014-02-21 05:03 - 00035840 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll

Files to move or delete:
====================
C:\ProgramData\83RaE5.dat


Some content of TEMP:
====================
C:\Users\Jon\AppData\Local\Temp\procexp64.exe
C:\Users\Jon\AppData\Local\Temp\Quarantine.exe
C:\Users\Jon\AppData\Local\Temp\vhbkhuei.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-20 00:31

==================== End Of Log ============================

 

Addition:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-02-2014 01
Ran by Jon at 2014-02-25 13:25:46
Running from C:\Users\Jon\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

µTorrent (HKCU\...\uTorrent) (Version: 3.3.1.30017 - BitTorrent Inc.)
µTorrent (HKLM-x32\...\uTorrent) (Version: 3.3.0.29038 - BitTorrent Inc.)
4500_G510gm_Help_Web (x32 Version: 000.0.440.000 - Hewlett-Packard) Hidden
4500G510gm_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
4500G510gm_web (x32 Version: 000.0.425.000 - Hewlett-Packard) Hidden
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version:  - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.7.0.19530 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.7.0.19530 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.5 (HKLM-x32\...\{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}) (Version: 11.5.8.612 - Adobe Systems, Inc)
Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden
AIM 7 (HKLM-x32\...\AIM_7) (Version:  - )
Amazon Kindle (HKLM-x32\...\Amazon Kindle) (Version:  - Amazon)
Amazon MP3 Downloader 1.0.17 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC)
aMule (HKLM-x32\...\aMule) (Version:  - )
Any Video Converter 3.4.1 (HKLM-x32\...\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
AOL Messaging Toolbar (HKCU\...\AOL Messaging Toolbar) (Version:  - )
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C6579A65-9CAE-4B31-8B6B-3306E0630A66}) (Version: 2.1.3.127 - Apple Inc.)
ApRadar 3.3.0.26 Update (HKLM-x32\...\{ED90F5E3-960A-4BED-B1EF-777D6E4E080F}_is1) (Version:  - ApneaSoft)
Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blasterball 3 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blio (HKLM-x32\...\{504CC891-B140-4E1B-860B-5E4C1DFBA9E3}) (Version: 2.0.5350 - K-NFB Reading Technology, Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (x32 Version: 2.2.0.95 - WildTangent) Hidden
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.1217.1530.27758 - ATI) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.1217.1530.27758 - ATI) Hidden
Catalyst Control Center Profiles Mobile (x32 Version: 2010.1217.1530.27758 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Danish (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help English (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help French (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help German (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.1217.1529.27758 - ATI) Hidden
ccc-core-static (x32 Version: 2010.1217.1530.27758 - ATI) Hidden
ccc-utility64 (Version: 2010.1217.1530.27758 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.17 - Piriform)
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Comical 0.8 (HKLM-x32\...\Comical_is1) (Version:  - James Athey)
ComicRack v0.9.154 (HKLM\...\ComicRack) (Version: v0.9.154 - cYo Soft)
CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3525 - CyberLink Corp.)
CyberLink DVD Suite (x32 Version: 7.0.3525 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.2.1.3609 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.2.1.3609 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{81FB7C60-565A-4869-9D90-3BE1D270E8B7}) (Version:  - Microsoft)
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.9 - DivX, LLC)
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.)
EndNote X5 (HKLM-x32\...\{86B3F2D6-AC2B-0015-8AE1-F2F77F781B0C}) (Version: 15.0.0.5478 - Thomson Reuters)
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
Escape Rosecliff Island (x32 Version: 2.2.0.95 - WildTangent) Hidden
ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
ExamView ActiveX Control v2 (HKLM-x32\...\ExamView ActiveX Control v2) (Version:  - )
ExamView Assessment Suite (HKLM-x32\...\ExamView Pro) (Version:  - )
ExamView Player (HKLM-x32\...\ExamView Player) (Version:  - )
Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.95 - WildTangent) Hidden
Final Drive Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
FINAL FANTASY XI Seekers of Adoulin (x32 Version: 1.50.1 - SQUARE ENIX CO., LTD.) Hidden
FINAL FANTASY XI Test Client (HKLM-x32\...\InstallShield_{27DDD216-365D-4FB8-8E2A-038B971990C2}) (Version: 1.0.0 - SQUARE ENIX CO., LTD.)
FINAL FANTASY XI Test Client (x32 Version: 1.0.0 - SQUARE ENIX CO., LTD.) Hidden
FINAL FANTASY XI: Seekers of Adoulin (HKLM-x32\...\InstallShield_{E86A33A7-6C77-48F3-9D72-2D8F4C1AD5AC}) (Version: 1.50.1 - SQUARE ENIX CO., LTD.)
FINAL FANTASY XI: Ultimate Collection - Abyssea Edition (HKLM-x32\...\Steam App 39250) (Version:  - SQUARE ENIX, INC.)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free YouTube Download 3 version 3.0.11.727 (HKLM-x32\...\Free YouTube Download 3_is1) (Version:  - DVDVideoSoft Limited.)
Free YouTube to MP3 Converter version 3.11.32.918 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.32.918 - DVDVideoSoft Ltd.)
Glary Utilities 3 (v3.5.0.121) (HKLM-x32\...\Glary Utilities 3) (Version: 3.5.0.121 - Glarysoft Ltd)
Google Chrome (HKCU\...\Google Chrome) (Version: 33.0.1750.117 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Heroes of Hellas 2 - Olympia (x32 Version: 2.2.0.95 - WildTangent) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HiJackThis (HKLM-x32\...\{45A66726-69BC-466B-A7A4-12FCBA4883D7}) (Version: 1.0.0 - Trend Micro)
HP Auto (Version: 1.0.12494.3472 - Hewlett-Packard Company) Hidden
HP Client Services (Version: 1.0.12656.3472 - Hewlett-Packard) Hidden
HP CloudDrive (HKLM-x32\...\ZumoDrive) (Version:  - Zecter Inc.)
HP Customer Experience Enhancements (x32 Version: 6.0.1.8 - Hewlett-Packard) Hidden
HP Documentation (HKLM-x32\...\{53CD60C7-12F9-420D-A9BF-EC8D815475A9}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Game Console (x32 Version:  - WildTangent) Hidden
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent)
HP MovieStore (HKLM-x32\...\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.0 - Hewlett-Packard)
HP MovieStore (x32 Version: 1.0.036 - Hewlett-Packard) Hidden
HP Officejet 4500 G510g-m (HKLM\...\{B38968E0-778F-47C3-8781-BAD4E497801C}) (Version: 13.0 - HP)
HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company)
HP Power Manager (HKLM-x32\...\{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}) (Version: 1.4.7 - Hewlett-Packard Company)
HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{802C068E-0576-4F25-8137-D54B7DB0FC5E}) (Version: 8.4.4487.3576 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.0.12845.3522 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{962CB079-85E6-405F-8704-1C62365AE46F}) (Version: 4.5.10.1 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{86FD8326-909D-45F5-BB61-0619D0D31293}) (Version: 11.50.0011 - Hewlett-Packard Company)
HP Wireless Assistant (HKLM\...\{13DCC2C7-454D-42F0-A892-E0E9A5DE4E67}) (Version: 4.0.10.0 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT)
iFunbox (v2.7.2386.747), iFunbox DevTeam (HKLM-x32\...\iFunbox_is1) (Version: v2.7.2386.747 - )
IHA_MessageCenter (HKLM-x32\...\{834265C4-CDF4-44D3-BD24-31531617EFB8}) (Version: 1.8.70 - Verizon)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2993 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 12.0.0.1013 - Intel Corporation)
IObit Security 360 (HKLM-x32\...\IObit Security 360_is1) (Version: 1.0 - IObit)
iTunes (HKLM\...\{F73A118B-8271-47E2-8790-0C636B2539C5}) (Version: 11.1.0.126 - Apple Inc.)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java™ 6 Update 22 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416022FF}) (Version: 6.0.220 - Oracle)
Java™ 6 Update 30 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022FF}) (Version: 6.0.300 - Oracle)
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kutools for Excel 6.5.0.0 (HKLM-x32\...\{A095BA43-4A97-4D55-8E25-A0BC46F10765}_is1) (Version:  - Detong)
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3429 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.3429 - CyberLink Corp.) Hidden
LatencyMon 6.00 (HKLM\...\LatencyMon_is1) (Version:  - Resplendence Software Projects Sp.)
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM-x32\...\McAfee Security Scan) (Version: 3.0.318.3 - McAfee, Inc.)
Media Go (HKLM-x32\...\{7A6C3344-5CF9-4B83-959C-6576C5B27D09}) (Version: 2.3.255 - Sony)
Media Go Video Playback Engine 1.96.117.08260 (HKLM-x32\...\{065DBB54-6E55-A609-2E1E-F0617E827D53}) (Version: 1.96.117.08260 - Sony)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 Language Pack Service Pack 1 (SP1) (HKLM-x32\...\{90140000-0100-0409-0000-0000000FF1CE}_Office14.OMUI.en-us_{02784A8B-78FA-458E-A114-308095C1814F}) (Version:  - Microsoft)
Microsoft Office 2010 Language Pack Service Pack 1 (SP1) (x32 Version:  - Microsoft) Hidden
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}) (Version:  - Microsoft)
Microsoft Office 2010 Service Pack 1 (SP1) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Language Pack 2010 - English (HKLM-x32\...\Office14.OMUI.en-us) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office O MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (Portuguese (Brazil)) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office SharePoint Designer MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office X MUI (English) 2010 (x32 Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft SharePoint Designer 2010 Service Pack 1 (SP1) (x32 Version:  - Microsoft) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft VC9 runtime libraries (x32 Version: 2.0.0 - AOL Inc.) Hidden
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.1) (HKLM\...\SDKSetup_7.1.7600.0.30514) (Version: 7.1.7600.0.30514 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.1) (Version: 7.1.30514 - Microsoft Corporation) Hidden
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0 - Microsoft Corp.) Hidden
Mozilla Firefox 27.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 27.0.1 (x86 en-US)) (Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Mumble 1.2.4 (HKLM-x32\...\{E0955568-4353-4C85-8988-285A8C0F5E87}) (Version: 1.2.4 - Thorvald Natvig)
Mystery P.I. - The London Caper (x32 Version: 2.2.0.95 - WildTangent) Hidden
Network64 (Version: 130.0.550.000 - Hewlett-Packard) Hidden
NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version:  - )
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Perfect Uninstaller v6.3.3.9 (HKLM\...\Perfect Uninstaller_is1) (Version:  - www.PerfectUninstaller.com)
PictureMover (HKLM-x32\...\{264FE20A-757B-492a-B0C3-4009E2997D8A}) (Version: 3.5.0.35 - Hewlett-Packard Company)
Pinnacle Game Profiler (HKLM-x32\...\{49BF48CC-ABB6-4795-9B35-B5DE005D8612}) (Version: 5.0.0 - )
Plants vs. Zombies (x32 Version: 2.2.0.95 - WildTangent) Hidden
PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
PlayStation®Network Downloader (HKLM-x32\...\{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}) (Version: 2.07.00849 - Sony Computer Entertainment Inc.)
PlayStation®Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.12.6.14870 - Sony Computer Entertainment Inc.)
Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
POLUtils (HKLM-x32\...\POLUtils) (Version:  - )
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4725 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.4725 - CyberLink Corp.) Hidden
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
QuickTime (HKLM-x32\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Realtek Ethernet Controller All-In-One SP Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.61.612.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.81 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 1.0.22 - Hewlett-Packard) Hidden
ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version:  - )
RGSS-RTP Standard (HKLM-x32\...\{5A9FE525-8B8F-4701-A937-7F6745A4E9C7}) (Version: 1.0.0 - Enterbrain)
RoxioNow Player (HKLM-x32\...\{0EDEB615-1A60-425E-8306-0E10519C7B55}) (Version: 1.9.5.101 - RoxioNow)
RPG Maker XP - Postality Knights Edition ENHANCED (HKLM-x32\...\{6F45C51F-A0E8-4547-83C8-CCDD4B0E4877}) (Version: 1.01 - Postality Knights Productions)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Skype™ 6.3 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.105 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.10.12 - Synaptics Incorporated)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.10 - TeamSpeak Systems GmbH)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TuxGuitar 1.2 (HKLM-x32\...\TuxGuitar_0) (Version:  - )
Ultimate Healer (HKLM-x32\...\{7B070466-3F62-4F59-989E-1C057C4BD4D3}) (Version: 2.0.3 - Arcaesis)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2836939v3) (Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2836939v3) (Version: 3 - Microsoft Corporation)
Update for Microsoft Office 2010 (KB2553065) (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{A8686D24-1E89-43A1-973E-05A258D2B3F8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{48E1B6C2-7299-4F3F-AA63-42F0ACE55AA4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{C8694FF0-8203-483B-A07A-2BC40433167D}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (HKLM-x32\...\{90140000-006E-0409-0000-0000000FF1CE}_Office14.OMUI.en-us_{73E67A3A-8D61-44EF-90C2-1697C3DBE668}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (HKLM-x32\...\{90140000-006E-0416-0000-0000000FF1CE}_Office14.PROPLUS_{BDE8DD25-D017-443C-AD04-B4FC21489EFB}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2553455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{147E3669-1EA6-454C-B53E-A2BE51D8E520}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2553455) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{147E3669-1EA6-454C-B53E-A2BE51D8E520}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2566458) (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFB525A0-E1C0-4E32-9968-FE401BC87363}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ED31DE9A-3E13-4E2C-9106-E0D8AFFB9FA6}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.OMUI.en-us_{460FF681-BC66-4C38-99DF-7012E03F1EBA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0416-0000-0000000FF1CE}_Office14.PROPLUS_{ACBCC818-8E67-43A8-B877-A821A3C6FAD2}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.OMUI.en-us_{C633216E-FF30-45B6-B2AB-21922A9353EF}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{C633216E-FF30-45B6-B2AB-21922A9353EF}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (HKLM-x32\...\{90140000-00A1-0409-0000-0000000FF1CE}_Office14.OMUI.en-us_{9865DC3A-2898-48D9-B96A-46397571C934}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (HKLM-x32\...\{90140000-00A1-0416-0000-0000000FF1CE}_Office14.PROPLUS_{435C0D41-8F38-42CE-9DCB-23676CB6A6A1}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{3613AECC-1454-4DDD-AC36-C42DC16D6DEE}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{3613AECC-1454-4DDD-AC36-C42DC16D6DEE}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{29E94638-D92F-4C40-BDA1-FEDCC92F478D}) (Version:  - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BC6DFBFD-16DD-47E1-A7EF-2C062930FA4F}) (Version:  - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0409-0000-0000000FF1CE}_Office14.OMUI.en-us_{1EEFF749-6F29-4F0B-AB08-4C6EA52AA110}) (Version:  - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0416-0000-0000000FF1CE}_Office14.PROPLUS_{B95699E7-EEEB-45EC-865F-37E3E746BFB4}) (Version:  - Microsoft)
USB Vibration Joystick (HKLM-x32\...\{4999B2F1-3E74-409A-B8B5-E94448AA9EA6}) (Version: v3.70 - )
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
Virtual Families (x32 Version: 2.2.0.95 - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
VLC media player 2.0.3 (HKLM-x32\...\VLC media player) (Version: 2.0.3 - VideoLAN)
Vz In-Home Agent (HKLM-x32\...\VzInHomeAgent) (Version: 9.0.35.0 - Verizon)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Wheel of Fortune 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Windower (HKCU\...\Windower) (Version: 4.0.0.0 - Windower Team)
Windows Driver Package - XBCD Project HID  (16/05/2008 1.1.0) (HKLM\...\C6DCA6D8EFAB374E8F91A705567555FF4DAF025D) (Version: 16/05/2008 1.1.0 - XBCD Project)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinRAR 4.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)
XBCD Uninstaller (HKLM\...\{04054166-0801-48A9-89E0-BC4B53FE7A81}_is1) (Version: 0.2.7 - XBCD Project)
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Restore Points  =========================

22-02-2014 01:54:56 Installed HiJackThis
22-02-2014 04:47:49 Installed Java 7 Update 51
24-02-2014 05:35:55 Device Driver Package Install: Advanced Micro Devices, Inc. Display adapters
24-02-2014 05:46:20 Installed AMD Display Driver for Vista
24-02-2014 05:46:31 Installed AMD Display Driver for Windows Blue

==================== Hosts content: ==========================

2012-04-12 09:41 - 2014-01-03 18:55 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {00FEAEC5-A931-4124-963B-954CA6D77A1D} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2010-12-11] (CyberLink)
Task: {010AB97F-E58F-4714-8B23-AA9C159987E6} - \LaunchApp No Task File
Task: {02146A45-F8E3-47EC-B3E1-B880237A6F14} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {128D202A-7F78-4B63-9E0F-DB6DEBD81977} - \RegClean Pro No Task File
Task: {13FE1CED-9859-4581-AECA-C1ADC241874C} - System32\Tasks\{1F0EF97A-6376-4434-9635-56A3D329D12D} => Firefox.exe http://ui.skype.com/ui/0/6.7.0.102/en/go/help.faq.installer?source=lightinstaller&amp;LastError=1603
Task: {15A04D7C-03C6-487B-8DC7-70C4201A414E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2634666426-190400968-3393963518-1000UA => C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-30] (Google Inc.)
Task: {167F6067-3239-4B08-9143-2CEC55914D0A} - System32\Tasks\AutoKMSDaily => C:\Windows\AutoKMS.exe [2013-10-20] ()
Task: {1CB154AC-6886-4578-8027-88CFD6DFE392} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-23] (Google Inc.)
Task: {287901C0-A75B-47DE-A947-3AF3113C0D06} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(Yes) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe
Task: {332063CE-7AF7-43FC-95F5-AD2B896AA70F} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-11-01] (Synaptics Incorporated)
Task: {358A9012-9922-4124-9101-9B53F956AA72} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {366E8BE6-8564-40E3-BADB-77860C75F56A} - System32\Tasks\GlaryInitialize 3 => C:\Program Files (x86)\Glary Utilities 3\Initialize.exe [2013-06-25] (Glarysoft Ltd)
Task: {3D10EACB-BD93-4E47-AEF1-9FE800AD7D27} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2634666426-190400968-3393963518-1000Core => C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-30] (Google Inc.)
Task: {7379A869-420E-4443-BABD-6407590D0E9F} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe [2013-10-20] ()
Task: {7640E52A-C671-4A83-AB32-6274726008DF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {7717BCBB-6AE4-471B-96D3-0081EC39F81F} - System32\Tasks\HPCeeScheduleForJon => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {7FA20D03-F85C-4523-A4A2-79115A6E85C7} - System32\Tasks\{D0D7B529-B2BB-497F-B2B2-254F466C3F98} => Firefox.exe http://ui.skype.com/ui/0/6.7.0.102/en/go/help.faq.installer?source=lightinstaller&amp;LastError=1603
Task: {9CADBD1F-B7A0-433E-8F0C-9C99198AF9EA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
Task: {A0C3DBCB-9C25-42FE-B4F9-3CDDB1CF8FE1} - System32\Tasks\DiskDefrag => C:\Program Files (x86)\Glary Utilities 3\DiskDefrag.exe [2013-06-25] (Glarysoft Ltd)
Task: {A1FB79E7-50E7-4D48-9396-5A8D6D974757} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(No) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe
Task: {A8782595-7477-45F1-9871-CA080BD57CF1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-21] (Adobe Systems Incorporated)
Task: {B0DD43E2-1DCB-4694-8805-2AECB8FE9393} - System32\Tasks\HPCeeScheduleForJON-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {BF7DCB15-01D4-49CE-9369-0B3AB069321B} - System32\Tasks\{BDC4AA02-C4F2-4C72-BB5A-BE3C4B4C1A45} => C:\Program Files (x86)\Steam\steamapps\common\ffxi\SquareEnix\FINAL FANTASY XI\polboot.exe [2012-08-03] (SQUARE ENIX CO., LTD.)
Task: {D39F7EBA-FD1B-434B-B8FB-2F2BC8ED54AA} - System32\Tasks\{6E4DBB80-C62D-446B-ADD1-2C095D06D37A} => Firefox.exe http://ui.skype.com/ui/0/6.7.0.102/en/go/help.faq.installer?source=lightinstaller&amp;LastError=1603
Task: {DC2648DD-B88A-466F-8FFF-A2E5335EA3DB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company)
Task: {E7B4ED73-0B91-430D-86B9-FCB43DD67CD4} - System32\Tasks\{8ECDD259-7B65-4C7D-89BB-9D986AFFF967} => C:\Program Files (x86)\Steam\steamapps\common\ffxi\SquareEnix\FINAL FANTASY XI\polboot.exe [2012-08-03] (SQUARE ENIX CO., LTD.)
Task: {EDC146F5-1D6F-45AD-9B7D-D5AA629695D0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
Task: {F38CDD81-36FD-4AD4-A898-902FC24F516D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-23] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoKMSDaily.job => C:\Windows\AutoKMS.exe
Task: C:\Windows\Tasks\DiskDefrag.job => C:\Program Files (x86)\Glary Utilities 3\DiskDefrag.exe
Task: C:\Windows\Tasks\GlaryInitialize 3.job => C:\Program Files (x86)\Glary Utilities 3\Initialize.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2634666426-190400968-3393963518-1000Core.job => C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2634666426-190400968-3393963518-1000UA.job => C:\Users\Jon\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForJON-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\Windows\Tasks\HPCeeScheduleForJon.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Loaded Modules (whitelisted) =============

2010-11-28 23:34 - 2010-11-28 23:34 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2010-07-21 17:33 - 2010-07-21 17:33 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll
2010-07-21 17:33 - 2010-07-21 17:33 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll
2010-07-21 17:33 - 2010-07-21 17:33 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll
2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2011-06-28 20:01 - 2011-05-28 21:05 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll
2012-11-28 14:13 - 2012-11-28 14:13 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-11-28 14:13 - 2012-11-28 14:13 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-02-23 21:03 - 2014-02-23 21:03 - 00016896 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\37d31005941dabc9737a127bbe5f3476\PSIClient.ni.dll
2014-02-14 10:27 - 2014-02-14 10:27 - 03578992 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:DocumentSummaryInformation
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:SummaryInformation
AlternateDataStreams: C:\Windows\SysWOW64\zlib.dll:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
AlternateDataStreams: C:\ProgramData\Temp:0B4227B4
AlternateDataStreams: C:\ProgramData\Temp:430C6D84
AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2
AlternateDataStreams: C:\ProgramData\Temp:F8AF2BB9

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\52242495.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\52242495.sys => ""="Driver"

==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupfolder: C:^Users^Jon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Malwarebytes' Anti-Malware => "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent

==================== Faulty Device Manager Devices =============

Name: HP Webcam-101
Description: USB Video Device
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/25/2014 01:16:27 PM) (Source: MsiInstaller) (User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.

Error: (02/25/2014 01:16:22 PM) (Source: MsiInstaller) (User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.

Error: (02/25/2014 00:59:29 PM) (Source: MsiInstaller) (User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.

Error: (02/25/2014 00:59:27 PM) (Source: MsiInstaller) (User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.

Error: (02/25/2014 00:19:24 AM) (Source: MsiInstaller) (User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.

Error: (02/25/2014 00:19:18 AM) (Source: MsiInstaller) (User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.

Error: (02/24/2014 10:43:24 PM) (Source: Application Error) (User: )
Description: Faulting application name: pol.exe, version: 1.18.13.0, time stamp: 0x4e3bcddc
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7
Exception code: 0xc0000005
Fault offset: 0x00038e19
Faulting process id: 0x1638
Faulting application start time: 0xpol.exe0
Faulting application path: pol.exe1
Faulting module path: pol.exe2
Report Id: pol.exe3

Error: (02/24/2014 10:00:37 PM) (Source: Application Error) (User: )
Description: Faulting application name: plugin-container.exe, version: 27.0.1.5156, time stamp: 0x52fc0fcf
Faulting module name: mozalloc.dll, version: 27.0.1.5156, time stamp: 0x52fbe972
Exception code: 0x80000003
Fault offset: 0x0000119c
Faulting process id: 0x182c
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (02/24/2014 07:33:27 PM) (Source: MsiInstaller) (User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.

Error: (02/24/2014 07:33:24 PM) (Source: MsiInstaller) (User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.


System errors:
=============
Error: (02/25/2014 01:15:57 PM) (Source: Service Control Manager) (User: )
Description: The PinnacleUpdate Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (02/25/2014 01:15:51 PM) (Source: Service Control Manager) (User: )
Description: The PNRP Machine Name Publication Service service depends on the Peer Name Resolution Protocol service which failed to start because of the following error:
%%-2140993535

Error: (02/25/2014 01:15:51 PM) (Source: Service Control Manager) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error:
%%-2140993535

Error: (02/25/2014 01:15:50 PM) (Source: Service Control Manager) (User: )
Description: The vToolbarUpdater15.3.0 service failed to start due to the following error:
%%2

Error: (02/25/2014 01:15:50 PM) (Source: Service Control Manager) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error:
%%-2140993535

Error: (02/25/2014 01:15:50 PM) (Source: PNRPSvc) (User: )
Description: 0x80630801

Error: (02/25/2014 01:15:49 PM) (Source: Service Control Manager) (User: )
Description: The IS360service service failed to start due to the following error:
%%1053

Error: (02/25/2014 01:15:49 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the IS360service service to connect.

Error: (02/25/2014 00:58:11 PM) (Source: Service Control Manager) (User: )
Description: The PinnacleUpdate Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (02/25/2014 00:58:04 PM) (Source: Service Control Manager) (User: )
Description: The PNRP Machine Name Publication Service service depends on the Peer Name Resolution Protocol service which failed to start because of the following error:
%%-2140993535


Microsoft Office Sessions:
=========================
Error: (02/25/2014 01:16:27 PM) (Source: MsiInstaller)(User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (02/25/2014 01:16:22 PM) (Source: MsiInstaller)(User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (02/25/2014 00:59:29 PM) (Source: MsiInstaller)(User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (02/25/2014 00:59:27 PM) (Source: MsiInstaller)(User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (02/25/2014 00:19:24 AM) (Source: MsiInstaller)(User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (02/25/2014 00:19:18 AM) (Source: MsiInstaller)(User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (02/24/2014 10:43:24 PM) (Source: Application Error)(User: )
Description: pol.exe1.18.13.04e3bcddcntdll.dll6.1.7601.18247521ea8e7c000000500038e19163801cf31d69baaf0e3c:\program files (x86)\steam\steamapps\common\ffxi\SquareEnix\PlayOnlineViewer\pol.exeC:\Windows\SysWOW64\ntdll.dllf9f62ee9-9dce-11e3-89d5-78e3b54fed36

Error: (02/24/2014 10:00:37 PM) (Source: Application Error)(User: )
Description: plugin-container.exe27.0.1.515652fc0fcfmozalloc.dll27.0.1.515652fbe972800000030000119c182c01cf31d12c22dd51C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllfff7fb7e-9dc8-11e3-89d5-78e3b54fed36

Error: (02/24/2014 07:33:27 PM) (Source: MsiInstaller)(User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (02/24/2014 07:33:24 PM) (Source: MsiInstaller)(User: Jon-HP)
Description: Product: RPG Maker XP - Postality Knights Edition ENHANCED -- Error 1706.No valid source could be found for product RPG Maker XP - Postality Knights Edition ENHANCED.  The Windows Installer cannot continue.(NULL)(NULL)(NULL)(NULL)(NULL)


CodeIntegrity Errors:
===================================
  Date: 2014-02-24 00:56:42.688
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Glary Utilities 3\ProcObsrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-24 00:56:42.438
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Glary Utilities 3\ProcObsrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-14 09:39:27.034
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Glary Utilities 3\ProcObsrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-14 09:39:26.956
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Glary Utilities 3\ProcObsrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-14 09:33:00.904
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Glary Utilities 3\ProcObsrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-14 09:33:00.826
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Glary Utilities 3\ProcObsrv.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-13 21:31:28.086
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-13 21:31:27.961
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-01-03 18:54:08.210
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-01-03 18:54:08.054
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Percentage of memory in use: 47%
Total physical RAM: 3893.86 MB
Available physical RAM: 2057.21 MB
Total Pagefile: 7785.9 MB
Available Pagefile: 5680.47 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:281.38 GB) (Free:141.42 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (RECOVERY) (Fixed) (Total:16.42 GB) (Free:15.03 GB) NTFS
Drive g: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.08 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: FEB7AE86)

Partition: GPT Partition Type.

==================== End Of Log ============================

 

JRT

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 7 Home Premium x64
Ran by Jon on Tue 02/25/2014 at 13:16:34.69
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2634666426-190400968-3393963518-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updatewhilokii_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updatewhilokii_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\nlalapncnp_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\nlalapncnp_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{44816E91-C68A-2FF3-3D8F-8970062E5600}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{8EF68EE7-C7B0-4A4A-888C-131F5B94BCEC}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\pc1data"
Successfully deleted: [Folder] "C:\Users\Jon\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Users\Jon\AppData\Roaming\pc cleaners"
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{02AAE206-AD04-4332-818F-B2C878D6D00D}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{031634DB-2292-40B2-B380-58E02A9F499A}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{091B16D1-3AC1-474C-9551-11FE897C0C9A}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{0C9239FC-CC98-445B-8133-E7FDB5D19351}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{0DEB46B3-EFFC-4B62-A052-B7F2BBFE8954}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{1906D496-01E1-475C-A789-F3241A4BB05F}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{24282E5E-13A0-44CA-9898-FA800CE81799}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{3324C28C-031A-49FA-AACF-3F01FADF6780}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{38712C3D-AA07-4821-935A-8890C0E05BD3}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{3C98337D-DBA8-4FFB-BB3C-F903EA704ECE}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{3EBB9217-9EB5-4580-B99E-A37667174FFF}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{417124B2-D361-4045-BAB4-4F6FA574B601}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{43201F18-4340-4276-8880-0E1F77A5D905}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{548E8FF1-D3CA-47C1-A4EF-7A0F22557CA2}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{561C87F9-307D-47FA-AE99-00465C3E36DC}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{5649A5D0-A5BB-4909-A36A-F55EB4A7C612}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{657E29DB-74F1-4A5D-93E2-C40CB5D42C1C}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{703F0902-D904-489C-8810-5AF057615A71}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{84B2EBE8-8D07-4F8A-9655-691471837D95}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{A2BDC5AA-9AF3-4CC2-A8C4-D648A27E4649}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{A72380CA-32EE-4D16-83B9-C1B496A8EB73}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{ABC5CF5F-FBD6-41EC-9081-F704EC371E8A}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{AC43D4A6-C9CD-40D8-8CB2-22627F64129E}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{B1D46CFA-58CB-4FC3-8284-83D715D9AA5D}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{B55B0023-1EF5-4770-B9C1-DE7934DE4F08}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{B8C25F30-BD35-467C-9FE8-D581E1D1B8AC}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{BC477C65-2B3C-4944-8C88-9C6B4C9BF42C}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{C0DF1816-E34C-44B5-80F7-4E03BEE3F223}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{CBBEDA29-8A65-437A-9C21-D7EA80325870}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{D7B77116-960B-411D-96CC-87D1778D8A46}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{DABE8264-32BA-47C1-B0B1-CB5DDF51ABBB}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{DFB6F1B7-1047-45CC-AAA1-B6B7593850DC}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{E21C1DC8-D979-41C7-9204-9E806B064B14}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{E69B6B9A-8125-4910-A22B-D455A41BE719}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{F36E48C6-4089-444E-AD18-6FD20B1015BD}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{F5A69BD6-BED7-4BE7-BF8E-7BE0BD1C9C03}
Successfully deleted: [Empty Folder] C:\Users\Jon\appdata\local\{F74824A2-436B-48AA-975C-BD90C2A67C49}



~~~ FireFox

Emptied folder: C:\Users\Jon\AppData\Roaming\mozilla\firefox\profiles\ejft8rfu.default\minidumps [1425 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 02/25/2014 at 13:32:16.97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

AdwCleaner:

# AdwCleaner v3.019 - Report created 25/02/2014 at 16:24:56
# Updated 17/02/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jon - JON-HP
# Running from : C:\Users\Jon\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16798


-\\ Mozilla Firefox v27.0.1 (en-US)

[ File : C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

 



#4 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:43 PM

Posted 26 February 2014 - 09:28 AM

Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.
 
start
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {44816E91-C68A-2FF3-3D8F-8970062E5600} URL = http://www.startnow.com/s/?q={searchTerms}&src=defsearch&provider=Bing&provider_code=Z059&partner_id=308&product_id=435&affiliate_id=&channel=rjacs&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110704&user_guid=B8F2076FE0DA4AAFB979404C6FEA8326&machine_id=aa43cc81de00dd8a3056185f03df57a2&browser=IE&os=win&os_version=6.1-x64-SP0
SearchScopes: HKCU - {8EF68EE7-C7B0-4A4A-888C-131F5B94BCEC} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3286042&CUI=UN77156702623882652&UM=2
Toolbar: HKLM-x32 - No Name - {61539ecd-cc67-4437-a03c-9aaccbd14326} -  No File
Toolbar: HKCU - No Name - {61539ECD-CC67-4437-A03C-9AACCBD14326} -  No File
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
Winsock: Catalog5 04 %SystemRoot%\System32\nwprovau.dll File Not found ()
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-21]
FF HKLM\...\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-10-23]
FF HKLM-x32\...\Firefox\Extensions: [OKitSpace@OKitSpace.es] - C:\Users\Jon\AppData\Roaming\okitSpace\Firefox
CHR Plugin: (Shockwave Flash) - C:\Users\Jon\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\Jon\AppData\Local\Google\Chrome\Application\33.0.1750.117\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2012-10-20]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-10-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Jon\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-10-01]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
S2 IS360service; C:\Program Files (x86)\IObit\IObit Security 360\IS360srv.exe [312152 2010-06-11] (IObit)
S2 vToolbarUpdater15.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [X]
U3 ayiutxj7; C:\Windows\System32\Drivers\ayiutxj7.sys [0 ] (Advanced Micro Devices)
S3 52242495; system32\drivers\32899734.sys [X]
C:\ProgramData\83RaE5.dat
C:\Users\Jon\AppData\Local\Temp\vhbkhuei.dll
AlternateDataStreams: C:\ProgramData\Temp:0B4227B4
AlternateDataStreams: C:\ProgramData\Temp:430C6D84
AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2
AlternateDataStreams: C:\ProgramData\Temp:F8AF2BB9

end

Save the files as fixlist.txt in to the same folder as FRST
Run FRST and click Fix only once and wait
The tool will create a log (Fixlog.txt) please post it to your reply.

====

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
p.s.
If the SecurityCheck program fails to run for any reason, run it as an Administrator.
===

Please let me know what problem persists.

#5 Jonnycbad

Jonnycbad
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:43 PM

Posted 27 February 2014 - 12:30 AM

 Results of screen317's Security Check version 0.99.79  
 Windows 7 Service Pack 1 x64 (UAC is disabled!)  
 Internet Explorer 10 Out of date!
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
 Windows Firewall Disabled!  
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Spybot - Search & Destroy
 Malwarebytes Anti-Malware version 1.75.0.1300  
 Java™ 6 Update 30  
 Java 7 Update 51  
  Adobe Flash Player 12.0.0.70 Flash Player out of Date!  
 Adobe Reader XI  
 Mozilla Firefox (27.0.1)
 Google Chrome 32.0.1700.107  
 Google Chrome 33.0.1750.117  
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbamgui.exe  
 Spybot Teatimer.exe is disabled!
 Malwarebytes' Anti-Malware mbamscheduler.exe   
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````
 

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 27-02-2014
Ran by Jon at 2014-02-27 00:22:56 Run:1
Running from C:\Users\Jon\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {44816E91-C68A-2FF3-3D8F-8970062E5600} URL = http://www.startnow.com/s/?q={searchTerms}&src=defsearch&provider=Bing&provider_code=Z059&partner_id=308&product_id=435&affiliate_id=&channel=rjacs&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110704&user_guid=B8F2076FE0DA4AAFB979404C6FEA8326&machine_id=aa43cc81de00dd8a3056185f03df57a2&browser=IE&os=win&os_version=6.1-x64-SP0
SearchScopes: HKCU - {8EF68EE7-C7B0-4A4A-888C-131F5B94BCEC} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3286042&CUI=UN77156702623882652&UM=2
Toolbar: HKLM-x32 - No Name - {61539ecd-cc67-4437-a03c-9aaccbd14326} -  No File
Toolbar: HKCU - No Name - {61539ECD-CC67-4437-A03C-9AACCBD14326} -  No File
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
Winsock: Catalog5 04 %SystemRoot%\System32\nwprovau.dll File Not found ()
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-21]
FF HKLM\...\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-10-23]
FF HKLM-x32\...\Firefox\Extensions: [OKitSpace@OKitSpace.es] - C:\Users\Jon\AppData\Roaming\okitSpace\Firefox
CHR Plugin: (Shockwave Flash) - C:\Users\Jon\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Users\Jon\AppData\Local\Google\Chrome\Application\33.0.1750.117\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2012-10-20]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-10-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Jon\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-10-01]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
S2 IS360service; C:\Program Files (x86)\IObit\IObit Security 360\IS360srv.exe [312152 2010-06-11] (IObit)
S2 vToolbarUpdater15.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [X]
U3 ayiutxj7; C:\Windows\System32\Drivers\ayiutxj7.sys [0 ] (Advanced Micro Devices)
S3 52242495; system32\drivers\32899734.sys [X]
C:\ProgramData\83RaE5.dat
C:\Users\Jon\AppData\Local\Temp\vhbkhuei.dll
AlternateDataStreams: C:\ProgramData\Temp:0B4227B4
AlternateDataStreams: C:\ProgramData\Temp:430C6D84
AlternateDataStreams: C:\ProgramData\Temp:DFC5A2B2
AlternateDataStreams: C:\ProgramData\Temp:F8AF2BB9

end

*****************

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{44816E91-C68A-2FF3-3D8F-8970062E5600} => Key not found.
HKCR\CLSID\{44816E91-C68A-2FF3-3D8F-8970062E5600} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8EF68EE7-C7B0-4A4A-888C-131F5B94BCEC} => Key not found.
HKCR\CLSID\{8EF68EE7-C7B0-4A4A-888C-131F5B94BCEC} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{61539ecd-cc67-4437-a03c-9aaccbd14326} => Value deleted successfully.
HKCR\Wow6432Node\CLSID\{61539ecd-cc67-4437-a03c-9aaccbd14326} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{61539ECD-CC67-4437-A03C-9AACCBD14326} => Value deleted successfully.
HKCR\CLSID\{61539ECD-CC67-4437-A03C-9AACCBD14326} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{6A060448-60F9-11D5-A6CD-0002B31F7455} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6A060448-60F9-11D5-A6CD-0002B31F7455} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} => Key deleted successfully.
Winsock: Catalog entry 000000000004 => Deleted successfully.
Winsock: Catalog5-x64 entry 000000000001\\LibraryPath  was set successfully to %SystemRoot%\system32\NLAapi.dll
C:\Users\Jon\AppData\Roaming\Mozilla\Firefox\Profiles\ejft8rfu.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi => Moved successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD} => Value deleted successfully.
C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\OKitSpace@OKitSpace.es => Value deleted successfully.
C:\Users\Jon\AppData\Local\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll not found.
C:\Users\Jon\AppData\Local\Google\Chrome\Application\33.0.1750.117\gcswf32.dll not found.
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll not found.
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll not found.
C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll not found.
C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp => Moved successfully.
C:\Users\Jon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm => Moved successfully.
HKCU\SOFTWARE\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp => Key deleted successfully.
C:\Users\Jon\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nneajnkjbffgblleaoojgaacokifdkhm => Key deleted successfully.
C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx => Moved successfully.
IS360service => Service deleted successfully.
vToolbarUpdater15.3.0 => Service deleted successfully.
ayiutxj7 => Service not found.
52242495 => Service deleted successfully.
C:\ProgramData\83RaE5.dat => Moved successfully.
C:\Users\Jon\AppData\Local\Temp\vhbkhuei.dll => Moved successfully.
C:\ProgramData\Temp => ":0B4227B4" ADS removed successfully.
C:\ProgramData\Temp => ":430C6D84" ADS removed successfully.
C:\ProgramData\Temp => ":DFC5A2B2" ADS removed successfully.
C:\ProgramData\Temp => ":F8AF2BB9" ADS removed successfully.

==== End of Fixlog ====



#6 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:43 PM

Posted 27 February 2014 - 08:56 AM

Remove this old bersion of Java™ 6 Update 30 using the Add/Remove Programs.

===

Adobe Flash Player 12.0.0.70 Flash Player out of Date!

This is a false positive. The Security Check tool needs to be updated.
===

Any remaining issues with this computer.

#7 Jonnycbad

Jonnycbad
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:43 PM

Posted 27 February 2014 - 11:26 AM

No this seemed to help a great deal, thanks a lot!



#8 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:43 PM

Posted 27 February 2014 - 02:16 PM


If all is well:

Please consider using these ideas to help secure your computer. While there is no way to guarantee safety when you use a computer, these steps will make it much less likely that you will need to endure another infection. While we really like to help people, we would rather help you protect yourself so that you won't need that help in the future.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates or get into the habit of checking Windows Update regularly. They usually have security updates every month. You can set Windows to notify you of Updates so that you can choose, but only do this if you believe you are able to understand which ones are needed. This is a crucial security measure.

Having an effective antivirus is a must for everyone.
In addition to many excellent commercial products there are plenty of good free antivirus programs available. I can recommend:

If you are satisfied with your current protection programs you can ignore the instructions on Antivirus or Firewall listed below.In addition to an antivirus I recommend using a firewall. A software firewall is a software program that helps screen out hackers, viruses, and worms that try to reach your computer over the Internet. I can recommend one of the following free products:Please note: Many installer offer third-party downloads that are installed automatically when you do not uncheck certain checkboxes. While most of the time not being malicious you usually do not want these on your computer. Be careful during the installation process and you will avoid seeing tons of new unwanted toolbars in your favorite web browser.

Please consider installing and running some of the following programs; they are either free or have free versions of commercial programs:

Malwarebytes Anti-Malware (MBAM)
The free version of MBAM can be used to scan the system for traces of malware. Scanning your system regularly will make it harder for malware to reside on your system.
A tutorial on using MBAM can be found here.
Please Note: Only the paid for version has real time capabilities.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent malware from ever installing on your computer may be found here.

Please keep these programs up-to-date and run them whenever you suspect a problem to prevent malware problems. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

Note that there are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:A similar category of programs is now called "scareware." Scareware programs are active infections that will pop-up on your computer and tell you that you are infected. If you look closely, it will usually have a name that looks like it might be legitimate, but it is NOT one of the programs you installed. It tells you to click and install it right away. If you click on any part of it, including the 'X' to close it, you may actually help it infect your computer further. Keeping protection updated and running resident protection can help prevent these infections. If it happens anyway, get offline as quickly as you can. Pull the internet connection cable or shut down the computer if you have to. Contact someone to help by using another computer if possible. These programs are also sometimes called 'rogues', but they are different than the older version of rogues mentioned above.

Please keep your programs up to date. This applies to Java, Adobe Flashplayer, Adobe Reader and your Internet Browsers in particular. Vulnerabilities in these programs are often exploited in order to install malware on your PC. Visiting a prepared web page suffices to infect your system.

In general Firefox, Opera and Google Chrome are considered to be more secure than Internet Explorer. In addition there are many useful add-ons that can protect you from possible risks:
  • WOT will warn you when you try to visit sites with poor reputation. The reputation is based on user ratings and is usually very accurate.
  • Script Blocker can help blocking many attempts to infect your system via malicious websites by only allowing scripts at sites you trust.
  • NoScript is a popular Firefox addon,
  • ScriptNo a popular Google Chrome addon.
For much more useful information, please also read Tony Klein's excellent article: How did I get infected in the first place

Hopefully these steps will help to keep you error free. If you run into more difficulty, we will certainly do what we can to help.
===

#9 Jonnycbad

Jonnycbad
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:43 PM

Posted 28 February 2014 - 11:44 AM

Hey I have an update. After everything I did things run a bit smoother and faster yet the 99% CPU when running a game still occurs. I tried ProcessorExplorer and saw "SystemInterrupts" eating up a lot of CPU. Then i tried LatencyMon and it gave me this, what should I do? I checked to see if I needed to update both of my network adapter drivers(they were already the most current according to device manager) but I still get latency issues relating to tcpip.sys and ndis.sys. I've checked my power options and everything is running at high performance mode and the laptop is always plugged in. I have it sitting on an external fanbed. HD0:39C Temp1:58C Temp2:62C Core1:58C Core1:54C

6aag.png


Edited by Jonnycbad, 28 February 2014 - 12:06 PM.


#10 Jonnycbad

Jonnycbad
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:43 PM

Posted 28 February 2014 - 12:09 PM

More info:

 

 

 REPORTED ISRs
_________________________________________________________________________________________________________
Interrupt service routines are routines installed by the OS and device drivers that execute in response to a hardware interrupt signal.

Highest ISR routine execution time (µs):              709.401279
Driver with highest ISR routine execution time:       ndis.sys - NDIS 6.20 driver, Microsoft Corporation

Highest reported total ISR routine time (%):          0.156676
Driver with highest ISR total time:                   i8042prt.sys - i8042 Port Driver, Microsoft Corporation

Total time spent in ISRs (%)                          0.259922

ISR count (execution time <250 µs):                   1121782
ISR count (execution time 250-500 µs):                0
ISR count (execution time 500-999 µs):                789
ISR count (execution time 1000-1999 µs):              0
ISR count (execution time 2000-3999 µs):              0
ISR count (execution time >=4000 µs):                 0


_________________________________________________________________________________________________________
REPORTED DPCs
_________________________________________________________________________________________________________
DPC routines are part of the interrupt servicing dispatch mechanism and disable the possibility for a process to utilize the CPU while it is interrupted until the DPC has finished execution.

Highest DPC routine execution time (µs):              5767.990598
Driver with highest DPC routine execution time:       ndis.sys - NDIS 6.20 driver, Microsoft Corporation

Highest reported total DPC routine time (%):          0.085105
Driver with highest DPC total execution time:         dxgkrnl.sys - DirectX Graphics Kernel, Microsoft Corporation

Total time spent in DPCs (%)                          0.428860

DPC count (execution time <250 µs):                   3741619
DPC count (execution time 250-500 µs):                0
DPC count (execution time 500-999 µs):                7441
DPC count (execution time 1000-1999 µs):              30
DPC count (execution time 2000-3999 µs):              17
DPC count (execution time >=4000 µs):                 0


_________________________________________________________________________________________________________
 REPORTED HARD PAGEFAULTS
_________________________________________________________________________________________________________
Hard pagefaults are events that get triggered by making use of virtual memory that is not resident in RAM but backed by a memory mapped file on disk. The process of resolving the hard pagefault requires reading in the memory from disk while the process is interrupted and blocked from execution.

NOTE: some processes were hit by hard pagefaults. If these were programs producing audio, they are likely to interrupt the audio stream resulting in dropouts, clicks and pops. Check the Processes tab to see which programs were hit.

Process with highest pagefault count:                 svchost.exe

Total number of hard pagefaults                       13122
Hard pagefault count of hardest hit process:          8304
Highest hard pagefault resolution time (µs):          693253.692366
Total time spent in hard pagefaults (%):              0.756146
Number of processes hit:                              36
 



#11 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:43 PM

Posted 28 February 2014 - 01:31 PM

Lets have a look at that file.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2


If your operating system is 64 bit download this tool:
SystemLook_x64.exe
  • Double-click SystemLook.exe
  • to run it.
  • Copy and paste the content
  • of the following bold text into the main textfield:
    :filefind
    ndis.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
  • Note: The log can also be found on your Desktop entitled SystemLook.txt.


#12 Jonnycbad

Jonnycbad
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:05:43 PM

Posted 28 February 2014 - 02:47 PM

SystemLook 30.07.11 by jpshortstuff
Log created at 14:24 on 28/02/2014 by Jon
Administrator - Elevation successful

========== filefind ==========

Searching for "ndis.sys"
C:\Windows\ERDNT\cache64\ndis.sys    --a---- 950128 bytes    [22:38 26/12/2011]    [18:12 22/08/2012] 760E38053BF56E501D562B70AD796B88
C:\Windows\System32\drivers\ndis.sys    --a---- 950128 bytes    [03:13 21/02/2014]    [18:12 22/08/2012] 760E38053BF56E501D562B70AD796B88
C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16385_none_03bc1d6e35c013bf\ndis.sys    --a---- 947776 bytes    [23:21 13/07/2009]    [01:48 14/07/2009] CAD515DBD07D082BB317D9928CE8962C
C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.16726_none_03fe04d8358e7a0c\ndis.sys    --a---- 947584 bytes    [03:48 21/06/2011]    [03:48 21/06/2011] A3151B3463EEA7E47F618F115D0D142E
C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7600.20867_none_045d623d4ecba2f1\ndis.sys    --a---- 947584 bytes    [03:48 21/06/2011]    [03:48 21/06/2011] 02A1D495D9CD3C787BDE560CCC6A480E
C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17514_none_05ed313632ae9759\ndis.sys    --a---- 951680 bytes    [23:11 01/07/2011]    [13:33 20/11/2010] 79B47FD40D9A817E932F9D26FAC0A81C
C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17530_none_05d3903632c269df\ndis.sys    --a---- 951680 bytes    [03:48 21/06/2011]    [03:48 21/06/2011] C38B8AE57F78915905064A9A24DC1586
C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.17939_none_05dc9a6832ba428a\ndis.sys    --a---- 950128 bytes    [03:13 21/02/2014]    [18:12 22/08/2012] 760E38053BF56E501D562B70AD796B88
C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.21628_none_066fff3d4bd0b870\ndis.sys    --a---- 950656 bytes    [03:48 21/06/2011]    [03:48 21/06/2011] 303310C91F8C0740ED1C76851C759874
C:\Windows\winsxs\amd64_microsoft-windows-ndis_31bf3856ad364e35_6.1.7601.22097_none_06232d534c0a8d67\ndis.sys    --a---- 950128 bytes    [03:13 21/02/2014]    [18:06 22/08/2012] 5E74508FCB5820B29EEAFE24E6035BCF

-= EOF =-



#13 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:43 PM

Posted 01 March 2014 - 08:26 AM

The file is good.

You may be able to find who the culprit is using this method.

Perform a Clean Startup
Follow the instructions on this page.
http://www.sevenforums.com/tutorials/179159-troubleshoot-application-conflicts-performing-clean-startup.html

#14 nasdaq

nasdaq

  • Malware Response Team
  • 38,271 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:05:43 PM

Posted 07 March 2014 - 08:47 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users