Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

New Player Virus


  • This topic is locked This topic is locked
65 replies to this topic

#1 riley45

riley45

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 04 September 2014 - 08:15 PM

I have new ASUS Windows 8.1 64 bit PC. Not realizing that it was a piece of malware, yesterday I inadvertently downloaded New Player as I thought that it was an update of the audio/video player which came with my system.

The download caused several other unwanted programs to be installed on my PC, removed my MSN browser, and changed my Internet Explorer browser to Snap.Do. It also made it harder (sometimes impossible) to connect to the internet and disabled the sound on my PC.

When this download occurred, my McAfee Antivirus detected one Trojan which it quarantined. It detected no other malicious files.

The unwanted programs installed on my PC include the following:

Browse Safe by GratifyingApps
Browse Safe Settings
Uninstall
Desktop Weather Alerts by Local Weather LLC
Freesofttoday by FREESOFTTODAY
Configure
MyPCBackup by JDi Backup Ltd.
Remote Desktop Access (VuuPC) by CMI Limited
Settings Manager by Aztec Media Inc.
Snap.Do by ReSoft Ltd.
SnapDo Engine by ReSoft Ltd.
Continue Live Installation
New Player
Speed Up My PC

I uninstalled the latter two items using the uninstall utility on my PC's control panel (not the rogue utility listed above.)

I need assistance in removing these unwanted software items from my PC and restoring my MSN and Internet Explorer browsers as well as the sound to my PC.

I have read that one way to do this is to use the system restore utility on my PC. Since my PC is new and does not have newly created user files on it, I am willing to go this route. If the route is appropriate, I would still need help in going through the steps.

BC AdBot (Login to Remove)

 


#2 olgun52

olgun52

  • Malware Response Team
  • 3,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:54 AM

Posted 05 September 2014 - 04:56 PM

Hello  riley45 and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

 

My name is Yılmaz and I'll help you with the cleanup of malware from your computer.

Before we move on, please read the following points carefully.
 

  • Please complete all steps in the specified order.
  • Even if tools don't find malware, I want you to post the logfiles anyway.
  • Please copy and paste the logfiles directly into your posts. Please do not attach them unless you are instructed to do so.
  • Read the instructions carefully. If you have problems, stop what you  were doing and describe the problems you encountered as precisely as  you can.
  • Don't install or uninstall software during the cleanup unless you are told to do so.
  • If you can't answer for the next few days, please let me know. If  you haven't answered within 5 days, I am assuming that you don't need  help anymore and your topic will be closed.
  • I can not guarantee that we will find and be able to remove all  malware. The cleaning process is not instant. Please continue to review  my answers until I tell you that your computer is clean
  • Please reply to this thread. Do not start a new topic
  • As my first language is not English, please do not use slang or idioms. It could be hard for me to understand.

 

  • Please open as administrator  the computer. How is open as administrator  the computer?
  • Disable your AntiVirus and AntiSpyware applications, as they will  interfere with our tools and the removal. If you are unsure how to do  this, please refer to get help here

Thanks

---------------------------------------------------------------------------------------------------------

 

 

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Thanks


Edited by olgun52, 05 September 2014 - 05:03 PM.

Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#3 riley45

riley45
  • Topic Starter

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 05 September 2014 - 10:54 PM

thanks

Here are the logs

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02
Ran by knemlick (administrator) on KENPC on 05-09-2014 22:12:54
Running from C:\Users\knemlick\Desktop
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\AvrcpService.exe
(Just Develop It) C:\Program Files (x86)\MyPC Backup\BackupStack.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Program Files (x86)\LPT\srpts.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Users\knemlick\AppData\Roaming\VOPackage\VOsrv.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
() C:\Program Files (x86)\LPT\srptsl.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe
() C:\Program Files (x86)\ASUS\ASUS Manager\PC Cleanup\SecureDeleteBackground.exe
(ASUSTeK) C:\Program Files (x86)\ASUS\ASUS Manager\Power Manager\Power Manager_background.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
() C:\Users\knemlick\AppData\Local\fst_us_239\upfst_us_239.exe
() C:\Users\knemlick\AppData\Local\LPT\srptm.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Smartbar) C:\Users\knemlick\AppData\Local\Smartbar\Application\SnapDo.exe
() C:\Users\knemlick\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe
(MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
(Local Weather LLC) C:\Users\knemlick\AppData\Local\WeatherAlerts\WeatherAlerts.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
() C:\Program Files (x86)\Bench\BService\1.1\bservice.exe
() C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe
() C:\Program Files (x86)\Bench\Wd\wd.exe
() C:\Program Files (x86)\Bench\Proxy\pwdg.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSPanel.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Program Files (x86)\Bench\Proxy\proc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\Core\mchost.exe
() C:\Users\knemlick\AppData\Local\Smartbar\Application\Lrcnta.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7199448 2013-09-05] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-30] (Realtek Semiconductor)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [280576 2013-09-25] (Realtek Semiconductor Corporation)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3216032 2014-04-25] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\ASUSWSLoader.exe [63296 2013-08-16] ()
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [fst_us_239] => "C:\Program Files (x86)\fst_us_239\fst_us_239.exe"
HKLM-x32\...\Run: [BService] => C:\Program Files (x86)\Bench\BService\1.1\bservice.exe [52736 2014-08-20] ()
HKLM-x32\...\Run: [BService64] => C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe [110592 2014-08-20] ()
HKLM-x32\...\Run: [Wd] => C:\Program Files (x86)\Bench\Wd\wd.exe [92672 2014-08-20] ()
HKLM-x32\...\Run: [Bench Communicator Watcher] => C:\Program Files (x86)\Bench\Proxy\pwdg.exe [127488 2014-08-20] ()
HKLM-x32\...\Run: [Bench Settings Cleaner] => C:\Program Files (x86)\Bench\Proxy\cl.exe [55296 2014-08-20] ()
HKLM-x32\...\RunOnce: [Browse Safe-repairJob] => wscript.exe "C:\Users\knemlick\AppData\Local\Browse Safe\repair.js" "Browse Safe-repairJob"
HKLM-x32\...\RunOnce: [upfst_us_239.exe] => C:\Users\knemlick\AppData\Local\fst_us_239\upfst_us_239.exe [3303416 2014-09-02] ()
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3351969478-1937094124-811777867-1002\...\Run: [Browser Infrastructure Helper] => C:\Users\knemlick\AppData\Local\Smartbar\Application\SnapDo.exe [28192 2014-08-27] (Smartbar)
Startup: C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopWeatherAlerts.lnk
ShortcutTarget: DesktopWeatherAlerts.lnk -> C:\Users\knemlick\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe ()
Startup: C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
Startup: C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Weather Alerts.lnk
ShortcutTarget: Weather Alerts.lnk -> C:\Users\knemlick\AppData\Local\WeatherAlerts\WeatherAlerts.exe (Local Weather LLC)
ShellIconOverlayIdentifiers: !AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: !AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: !AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:3128
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_l8fMQr5kRlG85BSpMSdBZGcvqlzOo64mHLGhfVxfLfiwY6ozy-2b6KCnwvSqHfAHlbp9JM9bN0uKditBDw5TvC12p61sBlosRo_uFdHc_F59gkxI9fNoV0qCeiSxjWw3vcnYDPJwKCLO&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.default-search.net?sid=514&aid=102&itype=n&ver=13892&tm=-15857&src=hmp
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com/?pc=ASJB
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_l8fMQr5kRlG85BSpMSdBZGcvqlzOo64mHLGhfVxfLfiwY6ozy-2b6KCnwvSqHfAHlbp9JM9bN0uKditBDw5TvC12p61sBlosRo_uFdHc_F59gkxI9fNoV0qCeiSxjWw3vcnYDPJwKCLO&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=ASJB
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=ASJB
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2514} URL = http://www.default-search.net/search?sid=514&aid=102&itype=n&ver=13892&tm=-15857&src=ds&p={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_l8fMQr5kRlG85BSpMSdBZGcvqlzOo64mHLGhfVxfLfiwY6ozy-2b6KCnwvSqHfAHlbp9JM9bN0uKditBDw5TvC12p61sBlosRo_uFdHc_F59gkxI9fNoV0qCeiSxjWw3vcnYDPJwKCLO&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_l8fMQr5kRlG85BSpMSdBZGcvqlzOo64mHLGhfVxfLfiwY6ozy-2b6KCnwvSqHfAHlbp9JM9bN0uKditBDw5TvC12p61sBlosRo_uFdHc_F59gkxI9fNoV0qCeiSxjWw3vcnYDPJwKCLO&q={searchTerms}
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=ASJB
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2514} URL = http://www.default-search.net/search?sid=514&aid=102&itype=n&ver=13892&tm=-15857&src=ds&p={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_l8fMQr5kRlG85BSpMSdBZGcvqlzOo64mHLGhfVxfLfiwY6ozy-2b6KCnwvSqHfAHlbp9JM9bN0uKditBDw5TvC12p61sBlosRo_uFdHc_F59gkxI9fNoV0qCeiSxjWw3vcnYDPJwKCLO&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fR3s5PAVMZpZbM61lWNTdgwQHuH_l8fMQr5kRlG85BSpMSdBZGcvqlzOo64mHLGhfVxfLfiwY6ozy-2b6KCnwvSqHfAHlbp9JM9bN0uKditBDw5TvC12p61sBlosRo_uFdHc_F59gkxI9fNoV0qCeiSxjWw3vcnYDPJwKCLO&q={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2514} URL = http://www.default-search.net/search?sid=514&aid=102&itype=n&ver=13892&tm=-15857&src=ds&p={searchTerms}
BHO: Snap.DoEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Browse Safe BHO -> {8E56A02B-46FE-4490-B169-F16E5231533B} -> C:\Program Files (x86)\Browse Safe\FrameworkBHO64.dll ()
BHO-x32: Snap.DoEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Browse Safe BHO -> {8E56A02B-46FE-4490-B169-F16E5231533B} -> C:\Program Files (x86)\Browse Safe\FrameworkBHO.dll ()
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-04-25]

Chrome:
=======

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-08-19] (Advanced Micro Devices, Inc.) [File not signed]
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2013-11-06] ()
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe [71680 2013-08-16] (ASUS Cloud Corporation) [File not signed]
R2 AvrcpService; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\AvrcpService.exe [35328 2013-05-07] (Realtek Semiconductor Corporation) [File not signed]
R2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [36424 2014-08-27] (Just Develop It)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [59392 2013-09-26] () [File not signed]
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-21] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
R2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [32800 2014-08-27] ()
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-29] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-07-24] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 servervo; C:\Users\knemlick\AppData\Roaming\VOPackage\VOsrv.exe [71680 2014-09-03] () [File not signed]
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-21] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-21] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-23] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-23] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R0 assdv2; C:\Windows\System32\Drivers\assdv2.sys [21816 2013-12-05] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-12] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [444720 2014-07-24] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-07-24] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [548056 2013-09-05] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2944216 2013-08-21] (Realtek Semiconductor Corporation                           )
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-23] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-05 22:12 - 2014-09-05 22:13 - 00019171 _____ () C:\Users\knemlick\Desktop\FRST.txt
2014-09-05 22:12 - 2014-09-05 22:12 - 00000000 ____D () C:\FRST
2014-09-05 22:09 - 2014-09-05 22:04 - 02104832 _____ (Farbar) C:\Users\knemlick\Desktop\FRST64.exe
2014-09-05 21:38 - 2014-09-05 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-09-04 19:57 - 2014-09-04 19:57 - 00139488 _____ () C:\Windows\SysWOW64\XMLOperations.xml
2014-09-03 20:11 - 2014-09-05 22:03 - 00001111 _____ () C:\Users\knemlick\Desktop\Continue Live Installation.lnk
2014-09-03 19:48 - 2014-09-05 21:41 - 00000003 _____ () C:\Users\knemlick\AppData\Local\proxy.log
2014-09-03 19:48 - 2014-09-03 19:48 - 00000000 ____D () C:\Users\knemlick\AppData\Local\BenchUpdater
2014-09-03 19:46 - 2014-09-04 20:22 - 00000362 _____ () C:\Windows\Tasks\bench-sys.job
2014-09-03 19:46 - 2014-09-03 19:52 - 00000362 _____ () C:\Windows\Tasks\bench-S-1-5-21-3351969478-1937094124-811777867-1002.job
2014-09-03 19:46 - 2014-09-03 19:48 - 00003216 _____ () C:\Windows\System32\Tasks\bench-S-1-5-21-3351969478-1937094124-811777867-1002
2014-09-03 19:46 - 2014-09-03 19:48 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browse Safe
2014-09-03 19:46 - 2014-09-03 19:48 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Browse Safe
2014-09-03 19:46 - 2014-09-03 19:48 - 00000000 ____D () C:\Program Files (x86)\Bench
2014-09-03 19:46 - 2014-09-03 19:46 - 00003232 _____ () C:\Windows\System32\Tasks\bench-sys
2014-09-03 19:46 - 2014-09-03 19:46 - 00000000 ____D () C:\Program Files (x86)\Browse Safe
2014-09-03 19:45 - 2014-09-03 19:45 - 00000000 ____D () C:\ProgramData\smdmf
2014-09-03 19:45 - 2014-09-03 19:45 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
2014-09-03 17:12 - 2014-09-05 21:33 - 00001364 _____ () C:\Windows\Tasks\RGMDMNF.job
2014-09-03 17:12 - 2014-09-05 21:33 - 00001362 _____ () C:\Windows\Tasks\TCUCBK.job
2014-09-03 17:12 - 2014-09-05 21:15 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-03 17:12 - 2014-09-03 17:12 - 01994144 _____ (enter) C:\Users\knemlick\AppData\Roaming\TCUCBK.exe
2014-09-03 17:12 - 2014-09-03 17:12 - 01541024 _____ (enter) C:\Users\knemlick\AppData\Roaming\RGMDMNF.exe
2014-09-03 17:12 - 2014-09-03 17:12 - 00004370 _____ () C:\Windows\System32\Tasks\RGMDMNF
2014-09-03 17:12 - 2014-09-03 17:12 - 00004368 _____ () C:\Windows\System32\Tasks\TCUCBK
2014-09-03 17:12 - 2014-09-03 17:12 - 00002512 _____ () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-03 17:12 - 2014-09-03 17:12 - 00000000 ____D () C:\Users\knemlick\AppData\Local\globalUpdate
2014-09-03 17:12 - 2014-09-03 17:12 - 00000000 ____D () C:\Users\knemlick\AppData\Local\com
2014-09-03 17:12 - 2014-09-03 17:12 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-09-03 17:11 - 2014-09-03 17:11 - 00004026 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-09-03 17:11 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts
2014-09-03 17:11 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Smartbar
2014-09-03 17:11 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Local\LPT
2014-09-03 17:11 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Local_Weather_LLC
2014-09-03 17:10 - 2014-09-05 21:46 - 00000000 ____D () C:\Users\knemlick\AppData\Local\WeatherAlerts
2014-09-03 17:10 - 2014-09-05 21:36 - 00000000 ____D () C:\Users\knemlick\AppData\Local\fst_us_239
2014-09-03 17:10 - 2014-09-03 17:54 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2014-09-03 17:10 - 2014-09-03 17:50 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2014-09-03 17:10 - 2014-09-03 17:11 - 00000004 _____ () C:\end
2014-09-03 17:10 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\VOPackage
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREESOFTTODAY
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____D () C:\Program Files (x86)\fst_us_239
2014-09-02 16:35 - 2014-09-02 16:35 - 00030374 _____ () C:\Users\knemlick\Downloads\bk-coretag (1).js
2014-09-02 15:32 - 2014-09-02 15:29 - 00012800 _____ () C:\Users\knemlick\Documents\NASA Federal Credit Union CD2.wps
2014-09-02 14:25 - 2014-09-02 14:25 - 00030374 _____ () C:\Users\knemlick\Downloads\bk-coretag.js
2014-09-01 03:18 - 2014-09-01 03:18 - 00002086 _____ () C:\Users\knemlick\AppData\Roaming\RGMDMNF
2014-09-01 03:18 - 2014-09-01 03:18 - 00001248 _____ () C:\Users\knemlick\AppData\Roaming\TCUCBK
2014-08-30 22:41 - 2014-08-30 22:41 - 00000000 ____D () C:\Program Files (x86)\MSECache
2014-08-30 22:30 - 2014-08-30 22:30 - 00002599 _____ () C:\Users\Public\Desktop\GPower 3.1.lnk
2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GPower
2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\Program Files (x86)\GPower 3.1
2014-08-30 22:28 - 2014-08-30 22:28 - 00000000 ____D () C:\Users\knemlick\Downloads\GPowerWin_3.1.9.2
2014-08-30 22:27 - 2014-08-30 22:27 - 13451133 _____ () C:\Users\knemlick\Downloads\GPowerWin_3.1.9.2.zip
2014-08-30 22:05 - 2014-08-30 22:06 - 00000000 ____D () C:\Users\knemlick\Documents\My Documents Mike 12-12-07
2014-08-30 21:30 - 2014-08-30 21:30 - 00000000 ____D () C:\Users\knemlick\Documents\Solomon Schechter
2014-08-30 21:30 - 2014-08-30 21:30 - 00000000 ____D () C:\Users\knemlick\Documents\SAT Reasoning Test
2014-08-30 21:30 - 2014-08-29 17:54 - 00023552 _____ () C:\Users\knemlick\Documents\Tutoring Income.xlr
2014-08-30 21:30 - 2014-08-27 18:56 - 00066048 _____ () C:\Users\knemlick\Documents\Tutoring Clients.xlr
2014-08-30 21:30 - 2014-06-06 20:25 - 00018944 _____ () C:\Users\knemlick\Documents\USAA Gibraltar IRAs Al.xlr
2014-08-30 21:30 - 2014-04-02 20:09 - 00167703 _____ () C:\Users\knemlick\Documents\Windows 8 Upgrade Assistant.mht
2014-08-30 21:30 - 2014-01-01 17:12 - 00020992 _____ () C:\Users\knemlick\Documents\TeachingAssignmentsWinterSpring2014.wps
2014-08-30 21:30 - 2013-09-17 17:05 - 00011264 _____ () C:\Users\knemlick\Documents\Risk Manager Essex County.wps
2014-08-30 21:30 - 2013-07-23 21:19 - 00017408 _____ () C:\Users\knemlick\Documents\Verizon Fios.wps
2014-08-30 21:30 - 2013-07-05 10:04 - 00014336 _____ () C:\Users\knemlick\Documents\Regal Bank Mike.xlr
2014-08-30 21:30 - 2013-06-27 12:44 - 00019968 _____ () C:\Users\knemlick\Documents\Teaching Schedule July -December 2013.wps
2014-08-30 21:30 - 2013-06-03 20:18 - 00019968 _____ () C:\Users\knemlick\Documents\TUESDAYTALMUDWINTERSPRING2013.wps
2014-08-30 21:30 - 2013-03-13 16:38 - 00055808 _____ () C:\Users\knemlick\Documents\Test-Schedule-Spring-2012-13-revised-2.wps
2014-08-30 21:30 - 2012-11-14 23:53 - 00009728 _____ () C:\Users\knemlick\Documents\St. Lukes.wps
2014-08-30 21:30 - 2012-09-14 09:00 - 00061952 _____ () C:\Users\knemlick\Documents\Test-Schedule-2012-13-fall-Final.wps
2014-08-30 21:30 - 2012-09-07 13:40 - 00016896 _____ () C:\Users\knemlick\Documents\Tutoring email template.wps
2014-08-30 21:30 - 2012-07-30 15:31 - 00017408 _____ () C:\Users\knemlick\Documents\TEACHING SCHEDULE JULY - DEC 2012.wps
2014-08-30 21:30 - 2012-07-28 15:13 - 00011264 _____ () C:\Users\knemlick\Documents\Tisha b'Av Ticket.wps
2014-08-30 21:30 - 2012-06-20 10:40 - 00027136 _____ () C:\Users\knemlick\Documents\Summer Letter and Outline BC 2012-13.wps
2014-08-30 21:30 - 2012-06-20 10:30 - 00015872 _____ () C:\Users\knemlick\Documents\Summer Assignment Ch P - 1 - 2 - 2012-2013.wps
2014-08-30 21:30 - 2012-06-03 22:26 - 00013312 _____ () C:\Users\knemlick\Documents\Statement of Mathematics Teaching Philosophy.wps
2014-08-30 21:30 - 2011-12-22 10:32 - 00018432 _____ () C:\Users\knemlick\Documents\TEACHINGASSIGNMENTSandCONGREGATION WINTER SPRING 2012.wps
2014-08-30 21:30 - 2011-10-01 16:17 - 12620832 _____ (SUPERAntiSpyware.com) C:\Users\knemlick\Documents\SUPERAntiSpyware.exe
2014-08-30 21:30 - 2011-10-01 15:27 - 00002800 _____ () C:\Users\knemlick\Documents\rapport.txt
2014-08-30 21:30 - 2011-10-01 14:48 - 00705952 _____ (Enigma Software Group USA, LLC.) C:\Users\knemlick\Documents\SpyHunter-Installer.exe
2014-08-30 21:30 - 2011-09-12 11:45 - 00337408 _____ () C:\Users\knemlick\Documents\Tennessee Commerce Bank CD Ken.wps
2014-08-30 21:30 - 2011-08-17 20:39 - 00011264 _____ () C:\Users\knemlick\Documents\Wedbush Bank Closure Letter Ken Wire Transfer.wps
2014-08-30 21:30 - 2011-08-12 21:26 - 00011264 _____ () C:\Users\knemlick\Documents\Wedbush Bank Closure Letter Ken 09-08-2011.wps
2014-08-30 21:30 - 2011-08-12 21:24 - 00012288 _____ () C:\Users\knemlick\Documents\Wedbush Bank Closure Letter Ken 09-02-2011.wps
2014-08-30 21:30 - 2011-08-03 21:00 - 00012146 _____ () C:\Users\knemlick\Documents\report.txt
2014-08-30 21:30 - 2011-06-28 18:20 - 00017408 _____ () C:\Users\knemlick\Documents\TEACHING ASSIGNMENTS and CONGREGATION SUMMER FALL 2011.wps
2014-08-30 21:30 - 2010-12-29 14:28 - 00011264 _____ () C:\Users\knemlick\Documents\PWC Cover Letter2.wps
2014-08-30 21:30 - 2010-08-29 11:20 - 00009728 _____ () C:\Users\knemlick\Documents\Torus Envelope.wps
2014-08-30 21:30 - 2010-08-29 11:17 - 00013824 _____ () C:\Users\knemlick\Documents\Torus Cover Letter.wps
2014-08-30 21:30 - 2010-08-23 14:22 - 00022528 _____ () C:\Users\knemlick\Documents\resumeKW201009.wps
2014-08-30 21:30 - 2010-08-12 13:30 - 00036352 _____ () C:\Users\knemlick\Documents\SC International Jobs.wps
2014-08-30 21:30 - 2010-07-18 23:41 - 00011776 _____ () C:\Users\knemlick\Documents\RMS Cover Letter.wps
2014-08-30 21:30 - 2010-07-15 18:30 - 00013824 _____ () C:\Users\knemlick\Documents\Tennessee Commerce Bank 1099 Error Al Myra.wps
2014-08-30 21:30 - 2010-07-14 21:25 - 00016384 _____ () C:\Users\knemlick\Documents\TEACHING ASSIGNMENTS and CONGREGATIONS SUMMER - FALL 2010.wps
2014-08-30 21:30 - 2010-05-19 01:22 - 00012288 _____ () C:\Users\knemlick\Documents\PWC Cover Letter.wps
2014-08-30 21:30 - 2010-05-11 11:42 - 00018944 _____ () C:\Users\knemlick\Documents\Untitled Document.wps
2014-08-30 21:30 - 2010-01-26 23:11 - 00012800 _____ () C:\Users\knemlick\Documents\Toys R Us Cover Letter.wps
2014-08-30 21:30 - 2010-01-13 18:29 - 00010240 _____ () C:\Users\knemlick\Documents\Reckitt Benckiser Senior Research Associate Response.wps
2014-08-30 21:30 - 2009-12-27 22:34 - 00017920 _____ () C:\Users\knemlick\Documents\Reckitt Benckiser Cover Letter.wps
2014-08-30 21:30 - 2009-12-11 00:28 - 00349184 _____ () C:\Users\knemlick\Documents\State Bank of India Close-Out Fax Myra 12122009.wps
2014-08-30 21:30 - 2009-12-10 23:42 - 00015360 _____ () C:\Users\knemlick\Documents\Retail Decisions, Inc. Cover Letter.wps
2014-08-30 21:30 - 2009-12-10 23:42 - 00009728 _____ () C:\Users\knemlick\Documents\Retail Decisions, Inc. Envelope.wps
2014-08-30 21:30 - 2009-12-07 15:19 - 00349184 _____ () C:\Users\knemlick\Documents\State Bank of India Close-Out Fax Ken 12082009.wps
2014-08-30 21:30 - 2009-11-09 15:23 - 00010752 _____ () C:\Users\knemlick\Documents\Senior Analyst (contract) JVS.wps
2014-08-30 21:30 - 2009-07-31 09:10 - 00337408 _____ () C:\Users\knemlick\Documents\Virtual Bank Close-Out Fax 08022009.wps
2014-08-30 21:30 - 2009-07-26 22:08 - 00010752 _____ () C:\Users\knemlick\Documents\Quantifi Envelope.wps
2014-08-30 21:30 - 2009-07-26 20:43 - 00014336 _____ () C:\Users\knemlick\Documents\Quantifi Cover Letter.wps
2014-08-30 21:30 - 2009-07-24 10:25 - 00337408 _____ () C:\Users\knemlick\Documents\Virtual Bank Close-Out Fax 07252009.wps
2014-08-30 21:30 - 2009-07-12 23:04 - 00013824 _____ () C:\Users\knemlick\Documents\Yamato Transport Cover Letter.wps
2014-08-30 21:30 - 2009-07-12 22:59 - 00009728 _____ () C:\Users\knemlick\Documents\Yamato Transport Envelope.wps
2014-08-30 21:30 - 2009-06-09 16:03 - 00009728 _____ () C:\Users\knemlick\Documents\Rider Insurance Company Envelope.wps
2014-08-30 21:30 - 2009-06-09 16:01 - 00012288 _____ () C:\Users\knemlick\Documents\Rider Insurance Company Cover Letter.wps
2014-08-30 21:30 - 2009-05-21 17:12 - 00009728 _____ () C:\Users\knemlick\Documents\Thank You RAI Group Envelope.wps
2014-08-30 21:30 - 2009-05-21 17:10 - 00012800 _____ () C:\Users\knemlick\Documents\Thank You RAI Group.wps
2014-08-30 21:30 - 2009-04-26 20:15 - 00423424 _____ () C:\Users\knemlick\Documents\Sample-GenLiab.xls
2014-08-30 21:30 - 2009-01-10 18:13 - 03401728 _____ () C:\Users\knemlick\Documents\top50models.pps
2014-08-30 21:30 - 2008-12-31 15:34 - 00015360 _____ () C:\Users\knemlick\Documents\Roman Contractors Cover Letter.wps
2014-08-30 21:30 - 2008-12-23 16:20 - 00334336 _____ () C:\Users\knemlick\Documents\Tennessee Commerce Bank IRA CD2 Ken.wps
2014-08-30 21:30 - 2008-12-17 11:26 - 00012288 _____ () C:\Users\knemlick\Documents\Zurich Cover Letter.wps
2014-08-30 21:30 - 2008-09-09 16:32 - 00334336 _____ () C:\Users\knemlick\Documents\Tennessee Commerce Bank IRA CD Ken.wps
2014-08-30 21:30 - 2008-08-01 11:11 - 00334848 _____ () C:\Users\knemlick\Documents\Virtual Fax2.wps
2014-08-30 21:30 - 2008-07-25 15:08 - 00334336 _____ () C:\Users\knemlick\Documents\Virtual Fax.wps
2014-08-30 21:30 - 2008-07-18 14:32 - 00334336 _____ () C:\Users\knemlick\Documents\Transportation Alliance Fax for Mike.wps
2014-08-30 21:30 - 2008-07-18 11:15 - 00334336 _____ () C:\Users\knemlick\Documents\Transportation Alliance Fax.wps
2014-08-30 21:30 - 2008-05-20 15:01 - 00121856 _____ () C:\Users\knemlick\Documents\weiss.ppt
2014-08-30 21:30 - 2008-05-09 16:57 - 00649728 _____ () C:\Users\knemlick\Documents\schober.ppt
2014-08-30 21:30 - 2008-03-19 14:48 - 02519552 _____ () C:\Users\knemlick\Documents\Vogt.ppt
2014-08-30 21:30 - 2008-03-19 14:13 - 02078720 _____ () C:\Users\knemlick\Documents\Vogt2.ppt
2014-08-30 21:30 - 2008-03-17 14:21 - 00758784 _____ () C:\Users\knemlick\Documents\stenmark.ppt
2014-08-30 21:30 - 2008-03-16 17:57 - 00025088 _____ () C:\Users\knemlick\Documents\Scott's Pension.xlr
2014-08-30 21:30 - 2007-11-07 13:35 - 01236992 _____ () C:\Users\knemlick\Documents\worth.ppt
2014-08-30 21:30 - 2007-11-07 13:35 - 00046080 _____ () C:\Users\knemlick\Documents\tritz.ppt
2014-08-30 21:30 - 2007-11-04 17:24 - 00001505 _____ () C:\Users\knemlick\Documents\Travelers Cover Letter.wps.txt
2014-08-30 21:30 - 2007-11-04 17:23 - 00012800 _____ () C:\Users\knemlick\Documents\Travelers Cover Letter.wps
2014-08-30 21:30 - 2007-09-26 09:55 - 00078702 _____ () C:\Users\knemlick\Documents\winmail.dat
2014-08-30 21:30 - 2007-07-20 14:14 - 00334848 _____ () C:\Users\knemlick\Documents\Transportation Alliance CD Mike.wps
2014-08-30 21:30 - 2007-07-20 14:06 - 00335360 _____ () C:\Users\knemlick\Documents\Transportation Alliance CD Ken.wps
2014-08-30 21:30 - 2007-05-25 18:53 - 00013824 _____ () C:\Users\knemlick\Documents\Thank You Global Aerospace.wps
2014-08-30 21:30 - 2007-05-25 18:53 - 00011776 _____ () C:\Users\knemlick\Documents\Thank You Global Aerospace Envelope.wps
2014-08-30 21:30 - 2007-05-23 16:50 - 00011776 _____ () C:\Users\knemlick\Documents\Thank You MBA Actuaries Envelope.wps
2014-08-30 21:30 - 2007-05-23 16:14 - 00013312 _____ () C:\Users\knemlick\Documents\Thank You MBA Actuaries.wps
2014-08-30 21:30 - 2007-05-19 10:10 - 00012800 _____ () C:\Users\knemlick\Documents\Thank You SGRisk.wps
2014-08-30 21:30 - 2007-05-19 00:23 - 00012800 _____ () C:\Users\knemlick\Documents\Thank You SGRisk Envelope.wps
2014-08-30 21:30 - 2007-05-12 13:17 - 00448000 _____ () C:\Users\knemlick\Documents\witcraft.ppt
2014-08-30 21:30 - 2007-05-10 10:05 - 03466240 _____ () C:\Users\knemlick\Documents\underwood.ppt
2014-08-30 21:30 - 2007-04-26 16:22 - 00013312 _____ () C:\Users\knemlick\Documents\Ryan Beck Internet Letter of Instructions.wps
2014-08-30 21:30 - 2007-04-23 23:15 - 00013824 _____ () C:\Users\knemlick\Documents\Thank You Mapfre RE.wps
2014-08-30 21:30 - 2007-04-23 22:23 - 00011776 _____ () C:\Users\knemlick\Documents\Thank You Mapfre RE Envelope.wps
2014-08-30 21:30 - 2007-04-09 17:49 - 00010752 _____ () C:\Users\knemlick\Documents\Thank You Holborn Envelope.wps
2014-08-30 21:30 - 2007-04-09 16:29 - 00013312 _____ () C:\Users\knemlick\Documents\Thank You Holborn.wps
2014-08-30 21:30 - 2007-03-07 12:38 - 00000146 _____ () C:\Users\knemlick\Documents\Robyn Taylor.vcf
2014-08-30 21:29 - 2014-08-30 21:29 - 00000000 ____D () C:\Users\knemlick\Documents\VincentPapa
2014-08-30 21:29 - 2014-08-30 21:29 - 00000000 ____D () C:\Users\knemlick\Documents\Stifel
2014-08-30 21:29 - 2014-08-30 21:29 - 00000000 ____D () C:\Users\knemlick\Documents\Stephanie Ingber
2014-08-30 21:29 - 2014-07-20 00:10 - 00017408 _____ () C:\Users\knemlick\Documents\Grade 5 Core Curriculum Math.wps
2014-08-30 21:29 - 2014-07-16 15:46 - 00012800 _____ () C:\Users\knemlick\Documents\NASA Federal Credit Union Savings and CD.wps
2014-08-30 21:29 - 2014-07-03 11:17 - 00010240 _____ () C:\Users\knemlick\Documents\Doral Bank CD3.wps
2014-08-30 21:29 - 2014-06-27 23:53 - 00334336 _____ () C:\Users\knemlick\Documents\Cross River Closeout Fax Ken.wps
2014-08-30 21:29 - 2014-06-11 22:15 - 00016896 _____ () C:\Users\knemlick\Documents\LHS AP Calculus Statistics Summer Assignemnts.wps
2014-08-30 21:29 - 2014-05-15 22:50 - 00025798 _____ () C:\Users\knemlick\Documents\103s14GeneralSyllabus.zip
2014-08-30 21:29 - 2014-04-28 12:47 - 00058880 _____ () C:\Users\knemlick\Documents\Columbia Bank Online Banking Add Account.wps
2014-08-30 21:29 - 2014-04-21 14:15 - 00003833 _____ () C:\Users\knemlick\Documents\American Academy of Actuaries - Receipt.mht
2014-08-30 21:29 - 2014-03-27 09:56 - 00333824 _____ () C:\Users\knemlick\Documents\Cross River Closeout Fax Myra.wps
2014-08-30 21:29 - 2014-03-27 09:43 - 00011776 _____ () C:\Users\knemlick\Documents\Doral Bank CD2.wps
2014-08-30 21:29 - 2014-03-17 12:05 - 00016896 _____ () C:\Users\knemlick\Documents\Catlin(Various)-314-Director of Actuarial Pricing, US.wps
2014-08-30 21:29 - 2014-01-09 14:19 - 00010752 _____ () C:\Users\knemlick\Documents\Clifton Savings Bank IRA.xlr
2014-08-30 21:29 - 2014-01-08 16:40 - 00011776 _____ () C:\Users\knemlick\Documents\Pentagon Federal Credit Union IRA Rollover.wps
2014-08-30 21:29 - 2013-12-17 22:30 - 00011776 _____ () C:\Users\knemlick\Documents\Pentagon Federal Credit Union IRA 2013 Contribution.wps
2014-08-30 21:29 - 2013-11-03 21:56 - 00010752 _____ () C:\Users\knemlick\Documents\Mary Lloyd Invoice.wps
2014-08-30 21:29 - 2013-11-01 12:52 - 00333824 _____ () C:\Users\knemlick\Documents\Angiogram CD Release.wps
2014-08-30 21:29 - 2013-08-31 21:41 - 00012800 _____ () C:\Users\knemlick\Documents\How to Run the Mann-Whitney U Test in SPSS.wps
2014-08-30 21:29 - 2013-08-06 21:31 - 00010240 _____ () C:\Users\knemlick\Documents\Medical Records Request for Dr. Roubin.wps
2014-08-30 21:29 - 2013-07-24 00:38 - 00010752 _____ () C:\Users\knemlick\Documents\Doros Argyriadis.xlr
2014-08-30 21:29 - 2013-07-22 00:05 - 00011776 _____ () C:\Users\knemlick\Documents\Formosa Plastics Cover Letter.wps
2014-08-30 21:29 - 2013-07-21 23:45 - 00010752 _____ () C:\Users\knemlick\Documents\Formosa Plastics Envelope.wps
2014-08-30 21:29 - 2013-07-17 21:51 - 00019456 _____ () C:\Users\knemlick\Documents\CAS Continuing Education Log.xlr
2014-08-30 21:29 - 2013-07-17 12:00 - 00435435 _____ () C:\Users\knemlick\Documents\FW__IHC_Rates0.zip
2014-08-30 21:29 - 2013-07-15 16:51 - 00009728 _____ () C:\Users\knemlick\Documents\KB2833941.wps
2014-08-30 21:29 - 2013-07-09 17:21 - 01759754 _____ () C:\Users\knemlick\Documents\New_Jersey_HMO0.zip
2014-08-30 21:29 - 2013-07-08 11:09 - 01053736 _____ () C:\Users\knemlick\Documents\Form_Request0.zip
2014-08-30 21:29 - 2013-06-28 21:43 - 00018944 _____ () C:\Users\knemlick\Documents\AP Statististics Grade Conversion Chart.xlr
2014-08-30 21:29 - 2013-06-26 20:58 - 00055296 _____ () C:\Users\knemlick\Documents\CommentaryArticle.wps
2014-08-30 21:29 - 2013-06-13 00:23 - 00036864 _____ () C:\Users\knemlick\Documents\JKHA Seventh Grade Mathematics Final Exam Review Sheet.wps
2014-08-30 21:29 - 2013-06-10 16:49 - 00013312 _____ () C:\Users\knemlick\Documents\Earnix(Israel)-612-P&C Modeler-Consultant.wps
2014-08-30 21:29 - 2013-06-03 09:32 - 00016384 _____ () C:\Users\knemlick\Documents\AIG PC(NY)-313-Head of Pricing, Global SME #83656.wps
2014-08-30 21:29 - 2013-05-29 13:00 - 00526021 _____ () C:\Users\knemlick\Documents\Daniel_AP_Award_5-28-2013.mp4
2014-08-30 21:29 - 2013-05-21 21:17 - 00334848 _____ () C:\Users\knemlick\Documents\Clifton Savings Bank Trustee Transfer Forms Request.wps
2014-08-30 21:29 - 2013-05-21 12:18 - 00013824 _____ () C:\Users\knemlick\Documents\Doral Bank CD.wps
2014-08-30 21:29 - 2013-05-20 15:28 - 00010240 _____ () C:\Users\knemlick\Documents\KMK Consulting Cover Letter.wps
2014-08-30 21:29 - 2013-05-15 23:35 - 00010752 _____ () C:\Users\knemlick\Documents\Academy of St Elizabeth Response.wps
2014-08-30 21:29 - 2013-05-13 14:43 - 00015360 _____ () C:\Users\knemlick\Documents\MA222 Statistics Central Limit Theorem.xlr
2014-08-30 21:29 - 2013-05-13 05:08 - 00041854 _____ () C:\Users\knemlick\Documents\Project 2 MA222 Statistics.xlsx
2014-08-30 21:29 - 2013-05-08 11:49 - 00012288 _____ () C:\Users\knemlick\Documents\North Jersey Developmental Center.wps
2014-08-30 21:29 - 2013-05-07 10:14 - 00011264 _____ () C:\Users\knemlick\Documents\Perfect Square Numbers and Prime Numbers.xlr
2014-08-30 21:29 - 2013-05-02 12:02 - 00013312 _____ () C:\Users\knemlick\Documents\Properties and Exponents-Radicals and Logarithms.wps
2014-08-30 21:29 - 2013-04-29 16:28 - 00337408 _____ () C:\Users\knemlick\Documents\Girls High School Math Teacher.wps
2014-08-30 21:29 - 2013-04-13 20:16 - 00010240 _____ () C:\Users\knemlick\Documents\Lauren Markon United Health Care.wps
2014-08-30 21:29 - 2013-03-08 19:21 - 00012288 _____ () C:\Users\knemlick\Documents\furniture list.wps
2014-08-30 21:29 - 2013-02-25 21:53 - 00011776 _____ () C:\Users\knemlick\Documents\Lauren Markon.wps
2014-08-30 21:29 - 2013-02-19 16:07 - 00012800 _____ () C:\Users\knemlick\Documents\Capital One Myra Al.xlr
2014-08-30 21:29 - 2013-01-16 01:33 - 00010752 _____ () C:\Users\knemlick\Documents\Horizon Nursing Home Surgery.wps
2014-08-30 21:29 - 2013-01-14 16:27 - 00016384 _____ () C:\Users\knemlick\Documents\Pentagon Federal Credit Union CD.wps
2014-08-30 21:29 - 2012-12-19 20:20 - 00334336 _____ () C:\Users\knemlick\Documents\Nell Marootian fax.wps
2014-08-30 21:29 - 2012-12-06 13:57 - 00012288 _____ () C:\Users\knemlick\Documents\Britton Agency.wps
2014-08-30 21:29 - 2012-11-27 01:31 - 00016531 _____ () C:\Users\knemlick\Documents\ELMP6005 Final Exam.xlr
2014-08-30 21:29 - 2012-11-17 14:11 - 00010752 _____ () C:\Users\knemlick\Documents\Microsoft Update.wps
2014-08-30 21:29 - 2012-10-24 22:49 - 00030720 _____ () C:\Users\knemlick\Documents\Painting the wrong house.wps
2014-08-30 21:29 - 2012-10-24 22:49 - 00010240 _____ () C:\Users\knemlick\Documents\NJStatute-whenmustpayinNJ.wps
2014-08-30 21:29 - 2012-09-08 13:18 - 00010752 _____ () C:\Users\knemlick\Documents\Capital One.xlr
2014-08-30 21:29 - 2012-09-05 16:04 - 00010752 _____ () C:\Users\knemlick\Documents\Exchange Bank CD3.wps
2014-08-30 21:29 - 2012-08-15 12:00 - 00010752 _____ () C:\Users\knemlick\Documents\Exchange Bank CD2.wps
2014-08-30 21:29 - 2012-08-15 10:53 - 00013824 _____ () C:\Users\knemlick\Documents\Exchange Bank Myra and Al.xlr
2014-08-30 21:29 - 2012-08-09 13:45 - 00337920 _____ () C:\Users\knemlick\Documents\Flagstar Closeout Fax 2012 Ken.wps
2014-08-30 21:29 - 2012-08-01 14:30 - 00009728 _____ () C:\Users\knemlick\Documents\collecting_for_nosh_supplies_12-13.wps
2014-08-30 21:29 - 2012-07-03 01:47 - 00063488 _____ () C:\Users\knemlick\Documents\Happy Birthday Mike.wps
2014-08-30 21:29 - 2012-06-20 10:43 - 00011776 _____ () C:\Users\knemlick\Documents\AP_Stats_Summer_Assignment.wps
2014-08-30 21:29 - 2012-06-19 10:46 - 00019968 _____ () C:\Users\knemlick\Documents\Aegis, Senior Actuary - Ezra Penland Actuarial Recruitment.wps
2014-08-30 21:29 - 2012-06-11 11:22 - 00010240 _____ () C:\Users\knemlick\Documents\Exchange Bank CD.wps
2014-08-30 21:29 - 2012-06-04 11:20 - 00011776 _____ () C:\Users\knemlick\Documents\CSE Tutor.wps
2014-08-30 21:29 - 2012-05-08 15:00 - 00010240 _____ () C:\Users\knemlick\Documents\Infection Control Procedures.wps
2014-08-30 21:29 - 2012-04-30 16:47 - 00009216 _____ () C:\Users\knemlick\Documents\Amanda's Comments on Hali Harvin.wps
2014-08-30 21:29 - 2012-04-19 20:49 - 00105472 _____ () C:\Users\knemlick\Documents\2012-2013 Reenrollment Calendar.xls
2014-08-30 21:29 - 2012-03-31 16:10 - 00010240 _____ () C:\Users\knemlick\Documents\Daniel Lee Letter.wps
2014-08-30 21:29 - 2012-03-23 20:49 - 00076288 _____ () C:\Users\knemlick\Documents\GSB Email Addresses.wps
2014-08-30 21:29 - 2012-01-27 10:22 - 00333312 _____ () C:\Users\knemlick\Documents\Fax Cover Sheet Sister Patricia Costello.wps
2014-08-30 21:29 - 2011-12-05 17:55 - 00011776 _____ () C:\Users\knemlick\Documents\Medicare Repayment.wps
2014-08-30 21:29 - 2011-11-29 22:24 - 00010752 _____ () C:\Users\knemlick\Documents\Mid-America Cross River Al.xlr
2014-08-30 21:29 - 2011-11-17 15:30 - 00010240 _____ () C:\Users\knemlick\Documents\KMK Consulting Envelope.wps
2014-08-30 21:29 - 2011-11-14 13:47 - 00009216 _____ () C:\Users\knemlick\Documents\Cover Letter.wps
2014-08-30 21:29 - 2011-10-24 20:42 - 00011264 _____ () C:\Users\knemlick\Documents\fsbnj.xlr
2014-08-30 21:29 - 2011-10-04 00:07 - 00012288 _____ () C:\Users\knemlick\Documents\Accenture Cover Letter3.wps
2014-08-30 21:29 - 2011-09-30 23:57 - 00388608 _____ (Trend Micro Inc.) C:\Users\knemlick\Documents\HiJackThis.exe
2014-08-30 21:29 - 2011-09-20 18:26 - 00010752 _____ () C:\Users\knemlick\Documents\Ken IRA Splitting Worksheet 2011.xlr
2014-08-30 21:29 - 2011-09-15 09:31 - 00052736 _____ () C:\Users\knemlick\Documents\Comparison%20of%20Table%2010%20HW%202
2014-08-30 21:29 - 2011-08-31 08:22 - 00010240 _____ () C:\Users\knemlick\Documents\Maven Survey on Personal Auto Underwriting 08-30-2011.wps
2014-08-30 21:29 - 2011-08-22 12:19 - 00049152 _____ () C:\Users\knemlick\Documents\2011-2012 Re-enrollment Calendar.xls
2014-08-30 21:29 - 2011-08-03 22:26 - 09466208 _____ (Malwarebytes Corporation ) C:\Users\knemlick\Documents\mbam-setup-1.51.1.1800.exe
2014-08-30 21:29 - 2011-06-06 10:51 - 00010752 _____ () C:\Users\knemlick\Documents\Independence Federal Savings Bank Closure Letter Ken.wps
2014-08-30 21:29 - 2011-05-09 16:00 - 00062464 _____ () C:\Users\knemlick\Documents\Hon. geom syllabus.wps
2014-08-30 21:29 - 2011-02-28 13:40 - 00010752 _____ () C:\Users\knemlick\Documents\Orange County FL Bond.xlr
2014-08-30 21:29 - 2011-01-07 11:39 - 00010752 _____ () C:\Users\knemlick\Documents\Clifton Savings Bank Fax Ken.wps
2014-08-30 21:29 - 2010-12-15 23:00 - 00012288 _____ () C:\Users\knemlick\Documents\Kenneth Nemlick Top Areas of Expertise1.wps
2014-08-30 21:29 - 2010-12-15 19:29 - 00013312 _____ () C:\Users\knemlick\Documents\Magnolia Draft.wps
2014-08-30 21:29 - 2010-11-11 12:29 - 00011776 _____ () C:\Users\knemlick\Documents\Jose Crespo Envelope.wps
2014-08-30 21:29 - 2010-10-22 15:55 - 00011776 _____ () C:\Users\knemlick\Documents\ISO Cover Letter.wps
2014-08-30 21:29 - 2010-10-22 14:40 - 00011264 _____ () C:\Users\knemlick\Documents\Kenneth Nemlick Top Areas of Expertise.wps
2014-08-30 21:29 - 2010-10-15 11:34 - 00011264 _____ () C:\Users\knemlick\Documents\FTI Cover Letter.wps
2014-08-30 21:29 - 2010-09-25 20:26 - 00011264 _____ () C:\Users\knemlick\Documents\Horizon Letter William Skiba.wps
2014-08-30 21:29 - 2010-09-16 16:19 - 00012288 _____ () C:\Users\knemlick\Documents\Essex County College Math Syllabus.wps
2014-08-30 21:29 - 2010-09-07 15:23 - 00012288 _____ () C:\Users\knemlick\Documents\Accenture Cover Letter2.wps
2014-08-30 21:29 - 2010-09-06 18:02 - 00011776 _____ () C:\Users\knemlick\Documents\Montclair State Tutoring Reference.wps
2014-08-30 21:29 - 2010-08-16 13:01 - 00012288 _____ () C:\Users\knemlick\Documents\McKinsey Cover Letter.wps
2014-08-30 21:29 - 2010-07-31 00:51 - 00273920 _____ () C:\Users\knemlick\Documents\Amanda's Comments on Briarwood Farm.wps
2014-08-30 21:29 - 2010-07-20 13:20 - 00014848 _____ () C:\Users\knemlick\Documents\Flooring Wholesale Resources Cover Letter.wps
2014-08-30 21:29 - 2010-07-20 13:08 - 00009728 _____ () C:\Users\knemlick\Documents\Flooring Wholesale Resources Envelope.wps
2014-08-30 21:29 - 2010-05-19 21:15 - 00009728 _____ () C:\Users\knemlick\Documents\Alfred S. Nemlick, M.D. Letter Head.wps
2014-08-30 21:29 - 2010-03-16 00:01 - 00253952 _____ () C:\Users\knemlick\Documents\Amanda Facebook Discussion Grange Finn Sparrow.wps
2014-08-30 21:29 - 2010-02-11 17:00 - 00013824 _____ () C:\Users\knemlick\Documents\Barbara Vitkowsky Summary of Dermatological Care.wps
2014-08-30 21:29 - 2010-02-10 16:31 - 00334848 _____ () C:\Users\knemlick\Documents\Flagstar Fax 2010 Ken.wps
2014-08-30 21:29 - 2010-01-23 21:52 - 00025088 _____ () C:\Users\knemlick\Documents\Alfred S. Nemlick, M.D. Fax Cover Page.wps
2014-08-30 21:29 - 2010-01-23 21:43 - 00013312 _____ () C:\Users\knemlick\Documents\Frank Smith Summary of Dermatological Care.wps
2014-08-30 21:29 - 2010-01-22 14:43 - 00010752 _____ () C:\Users\knemlick\Documents\Elizabeth Mele Summary of Dermatological Care.wps
2014-08-30 21:29 - 2010-01-18 16:29 - 00012800 _____ () C:\Users\knemlick\Documents\John Anagnostou Summary of Dermatological Visits.wps
2014-08-30 21:29 - 2010-01-07 12:41 - 00334848 _____ () C:\Users\knemlick\Documents\One West Bank Close-Out Fax-Mike 01072010.wps
2014-08-30 21:29 - 2010-01-07 10:32 - 00334848 _____ () C:\Users\knemlick\Documents\One West Bank Close-Out Fax-Ken 01072010.wps
2014-08-30 21:29 - 2010-01-03 22:25 - 00014848 _____ () C:\Users\knemlick\Documents\Nuwave Investment Management Cover Letter.wps
2014-08-30 21:29 - 2010-01-03 21:57 - 00009728 _____ () C:\Users\knemlick\Documents\Nuwave Investment Management Envelope.wps
2014-08-30 21:29 - 2009-12-22 22:49 - 00012800 _____ () C:\Users\knemlick\Documents\Hertz Cover Letter.wps
2014-08-30 21:29 - 2009-12-13 23:52 - 00012288 _____ () C:\Users\knemlick\Documents\Avis Budget Cover Letter.wps
2014-08-30 21:29 - 2009-12-07 17:38 - 00695808 _____ () C:\Users\knemlick\Documents\Candidate initial contact questionnaire.wps
2014-08-30 21:29 - 2009-11-21 15:43 - 00037888 _____ () C:\Users\knemlick\Documents\Polynomial.xlr
2014-08-30 21:29 - 2009-11-18 15:42 - 00012800 _____ () C:\Users\knemlick\Documents\Accenture Cover Letter.wps
2014-08-30 21:29 - 2009-11-17 12:26 - 00026624 _____ () C:\Users\knemlick\Documents\Bank of America Actuary-Pricing Description.wps
2014-08-30 21:29 - 2009-11-17 01:00 - 00011776 _____ () C:\Users\knemlick\Documents\Alcatel-Lucent Cover Letter.wps
2014-08-30 21:29 - 2009-11-11 18:35 - 00013824 _____ () C:\Users\knemlick\Documents\NJIT Cover Letter.wps
2014-08-30 21:29 - 2009-11-11 00:46 - 00015360 _____ () C:\Users\knemlick\Documents\Damco USA Cover Letter.wps
2014-08-30 21:29 - 2009-11-09 17:16 - 00010752 _____ () C:\Users\knemlick\Documents\Damco USA Envelope.wps
2014-08-30 21:29 - 2009-11-03 21:53 - 00016896 _____ () C:\Users\knemlick\Documents\Medical Office Available.wps
2014-08-30 21:29 - 2009-10-26 13:06 - 00015872 _____ () C:\Users\knemlick\Documents\Al's Office Income.xlr
2014-08-30 21:29 - 2009-10-02 16:58 - 00333824 _____ () C:\Users\knemlick\Documents\Affiliated Management Fax.wps
2014-08-30 21:29 - 2009-09-27 16:49 - 00010240 _____ () C:\Users\knemlick\Documents\CSAV Agency Envelope.wps
2014-08-30 21:29 - 2009-09-27 16:46 - 00013312 _____ () C:\Users\knemlick\Documents\CSAV Agency Cover Letter.wps
2014-08-30 21:29 - 2009-09-09 17:25 - 00060928 _____ () C:\Users\knemlick\Documents\Boistatistics syllabus_fall_09 (2).wps
2014-08-30 21:29 - 2009-09-09 16:37 - 00040937 _____ () C:\Users\knemlick\Documents\Boistatistics syllabus_fall_09.zip
2014-08-30 21:29 - 2009-09-06 20:57 - 00351744 _____ () C:\Users\knemlick\Documents\Hapag-Lloyd Cover Letter Fax.wps
2014-08-30 21:29 - 2009-09-06 20:57 - 00014336 _____ () C:\Users\knemlick\Documents\Hapag-Lloyd Cover Letter.wps
2014-08-30 21:29 - 2009-08-31 18:02 - 00009728 _____ () C:\Users\knemlick\Documents\Healthmonitor Envelope.wps
2014-08-30 21:29 - 2009-08-31 18:01 - 00014336 _____ () C:\Users\knemlick\Documents\Healthmonitor Cover Letter.wps
2014-08-30 21:29 - 2009-08-22 22:35 - 00011264 _____ () C:\Users\knemlick\Documents\Morgan Stanley Cover Letter.wps
2014-08-30 21:29 - 2009-08-02 21:05 - 00013824 _____ () C:\Users\knemlick\Documents\Panalpina Cover Letter.wps
2014-08-30 21:29 - 2009-08-02 20:54 - 00009728 _____ () C:\Users\knemlick\Documents\Panalpina Envelope.wps
2014-08-30 21:29 - 2009-07-13 10:06 - 00334848 _____ () C:\Users\knemlick\Documents\One West Bank Close-Out Fax-Ken 07132009.wps
2014-08-30 21:29 - 2009-07-09 14:31 - 00014848 _____ () C:\Users\knemlick\Documents\DSI Video Systems Cover Letter.wps
2014-08-30 21:29 - 2009-07-09 13:31 - 00009728 _____ () C:\Users\knemlick\Documents\DSI Video Systems Envelope.wps
2014-08-30 21:29 - 2009-07-09 09:26 - 00337408 _____ () C:\Users\knemlick\Documents\One West Bank Close-Out Fax-Ken 07092009.wps
2014-08-30 21:29 - 2009-06-24 14:26 - 00102912 _____ () C:\Users\knemlick\Documents\Personal Deposit App(David)2.xls
2014-08-30 21:29 - 2009-06-24 11:35 - 00337408 _____ () C:\Users\knemlick\Documents\One West Bank Close-Out Fax-Ken.wps
2014-08-30 21:29 - 2009-06-21 21:53 - 00010752 _____ () C:\Users\knemlick\Documents\Pan Oceanic Chartering Envelope.wps
2014-08-30 21:29 - 2009-06-21 21:43 - 00015360 _____ () C:\Users\knemlick\Documents\Pan Oceanic Chartering Cover Letter.wps
2014-08-30 21:29 - 2009-06-12 00:24 - 00012288 _____ () C:\Users\knemlick\Documents\Amanda Facebook Post 02-07-2009.wps
2014-08-30 21:29 - 2009-05-31 20:10 - 00329216 _____ () C:\Users\knemlick\Documents\hotelandmotel.xls
2014-08-30 21:29 - 2009-05-26 09:15 - 00652800 _____ () C:\Users\knemlick\Documents\KENNETH J[1]. NEMLICK - ESPRiT v4.wps
2014-08-30 21:29 - 2009-05-25 20:25 - 00653312 _____ () C:\Users\knemlick\Documents\KENNETH J[2]. NEMLICK - ESPRiT.wps
2014-08-30 21:29 - 2009-05-19 12:00 - 00086528 _____ () C:\Users\knemlick\Documents\Companies Hiring with the Type of Positions April 2009 SS.wps
2014-08-30 21:29 - 2009-05-11 17:05 - 00013312 _____ () C:\Users\knemlick\Documents\IRS Refund Check Return.wps
2014-08-30 21:29 - 2009-05-03 18:17 - 00009728 _____ () C:\Users\knemlick\Documents\Collaborative Consulting Envelope.wps
2014-08-30 21:29 - 2009-05-03 18:12 - 00029696 _____ () C:\Users\knemlick\Documents\Collaborative Consulting Cover Letter.wps
2014-08-30 21:29 - 2009-04-20 10:26 - 00013824 _____ () C:\Users\knemlick\Documents\Front Desk Insurance Position.wps
2014-08-30 21:29 - 2009-04-12 18:16 - 00017920 _____ () C:\Users\knemlick\Documents\J&J Biostatistician Cover Letter.wps
2014-08-30 21:29 - 2009-03-24 09:34 - 00334336 _____ () C:\Users\knemlick\Documents\Indymac Federal Bank Close-Out Fax-Ken.wps
2014-08-30 21:29 - 2009-03-23 01:04 - 00018432 _____ () C:\Users\knemlick\Documents\Lightspeed Cover Letter.wps
2014-08-30 21:29 - 2009-03-22 23:18 - 00009728 _____ () C:\Users\knemlick\Documents\Lightspeed Envelope.wps
2014-08-30 21:29 - 2009-03-16 00:15 - 00011776 _____ () C:\Users\knemlick\Documents\IRS Letter Form 5329 Al.wps
2014-08-30 21:29 - 2009-03-12 20:24 - 00017920 _____ () C:\Users\knemlick\Documents\CAS Dues Waiver.wps
2014-08-30 21:29 - 2009-02-22 21:55 - 00009728 _____ () C:\Users\knemlick\Documents\K.J. Sessa Envelope.wps
2014-08-30 21:29 - 2009-02-22 21:52 - 00017920 _____ () C:\Users\knemlick\Documents\K.J. Sessa Cover Letter.wps
2014-08-30 21:29 - 2009-02-20 19:20 - 00338432 _____ () C:\Users\knemlick\Documents\Flagstar Fax McCabe.wps
2014-08-30 21:29 - 2009-02-08 22:56 - 00015360 _____ () C:\Users\knemlick\Documents\GMEC Cover Letter.wps
2014-08-30 21:29 - 2009-02-08 22:54 - 00010752 _____ () C:\Users\knemlick\Documents\GMEC Envelope.wps
2014-08-30 21:29 - 2009-02-06 13:09 - 00335360 _____ () C:\Users\knemlick\Documents\Flagstar Fax.wps
2014-08-30 21:29 - 2009-01-23 15:53 - 00051074 _____ () C:\Users\knemlick\Documents\application.tif
2014-08-30 21:29 - 2008-12-21 23:53 - 00337408 _____ () C:\Users\knemlick\Documents\CPCU Fax.wps
2014-08-30 21:29 - 2008-12-12 13:34 - 00016443 _____ () C:\Users\knemlick\Documents\osam121208-1234pm.log
2014-08-30 21:29 - 2008-12-11 23:03 - 00042362 _____ () C:\Users\knemlick\Documents\osam.html
2014-08-30 21:29 - 2008-12-01 09:53 - 00046592 _____ () C:\Users\knemlick\Documents\Active Job Log as of 11-26-08.xls
2014-08-30 21:29 - 2008-11-27 00:49 - 00024064 _____ () C:\Users\knemlick\Documents\Basic Operation Facts.xlr
2014-08-30 21:29 - 2008-11-24 12:45 - 00010240 _____ () C:\Users\knemlick\Documents\Apple Fax Mike.wps
2014-08-30 21:29 - 2008-11-21 17:58 - 00017920 _____ () C:\Users\knemlick\Documents\Diedre Moire Email 11212008.wps
2014-08-30 21:29 - 2008-11-21 17:31 - 00012800 _____ () C:\Users\knemlick\Documents\Apple Fax Ken.wps
2014-08-30 21:29 - 2008-11-20 22:37 - 00015360 _____ () C:\Users\knemlick\Documents\Apple Fax Al Myra Joint.wps
2014-08-30 21:29 - 2008-11-20 22:34 - 00015360 _____ () C:\Users\knemlick\Documents\Apple Fax Myra.wps
2014-08-30 21:29 - 2008-11-17 16:43 - 00012800 _____ () C:\Users\knemlick\Documents\Apple Fax Al.wps
2014-08-30 21:29 - 2008-11-14 23:58 - 00011264 _____ () C:\Users\knemlick\Documents\Chyten.wps
2014-08-30 21:29 - 2008-10-28 15:27 - 00010240 _____ () C:\Users\knemlick\Documents\Horseshoe Group.wps
2014-08-30 21:29 - 2008-10-12 11:17 - 00010240 _____ () C:\Users\knemlick\Documents\Hubie Eyres.wps
2014-08-30 21:29 - 2008-09-24 12:52 - 00335360 _____ () C:\Users\knemlick\Documents\First State Bank-Ken Renewal Letter.wps
2014-08-30 21:29 - 2008-09-23 10:56 - 00335360 _____ () C:\Users\knemlick\Documents\First State Bank-Mike Renewal Letter.wps
2014-08-30 21:29 - 2008-09-12 13:51 - 00010240 _____ () C:\Users\knemlick\Documents\North American Search Group Positions.wps
2014-08-30 21:29 - 2008-08-29 10:38 - 00334848 _____ () C:\Users\knemlick\Documents\National Bank of KC Close-Out Fax-Ken 15283.wps
2014-08-30 21:29 - 2008-08-27 10:51 - 00334336 _____ () C:\Users\knemlick\Documents\National Bank of KC Close-Out Fax-Mike 15135.wps
2014-08-30 21:29 - 2008-08-27 10:36 - 00334336 _____ () C:\Users\knemlick\Documents\National Bank of KC Close-Out Fax-Ken 15132.wps
2014-08-30 21:29 - 2008-07-30 23:10 - 00010752 _____ () C:\Users\knemlick\Documents\Beatrice Thompson.xlr
2014-08-30 21:29 - 2008-07-22 19:26 - 00334336 _____ () C:\Users\knemlick\Documents\Indymac Federal Bank Close-Out Fax-Mike.wps
2014-08-30 21:29 - 2008-07-20 21:08 - 00038754 _____ () C:\Users\knemlick\Documents\PH_pictorials_1969-1999[1].txt.zip
2014-08-30 21:29 - 2008-07-10 12:00 - 00334336 _____ () C:\Users\knemlick\Documents\Ascencia Fax.wps
2014-08-30 21:29 - 2008-06-02 15:36 - 00011264 _____ () C:\Users\knemlick\Documents\Mutual Bank CDs.wps
2014-08-30 21:29 - 2008-05-20 17:08 - 00391680 _____ () C:\Users\knemlick\Documents\johnson.ppt
2014-08-30 21:29 - 2008-05-20 16:45 - 03238912 _____ () C:\Users\knemlick\Documents\gegax.ppt
2014-08-30 21:29 - 2008-05-20 13:38 - 00553472 _____ () C:\Users\knemlick\Documents\petlick.ppt
2014-08-30 21:29 - 2008-05-01 14:18 - 00333824 _____ () C:\Users\knemlick\Documents\Countrywide CD Title.wps
2014-08-30 21:29 - 2008-04-09 12:42 - 00333824 _____ () C:\Users\knemlick\Documents\ETRADE IRA CD.wps
2014-08-30 21:29 - 2008-03-19 15:22 - 00118272 _____ () C:\Users\knemlick\Documents\krautheim.ppt
2014-08-30 21:29 - 2008-03-17 17:07 - 00366592 _____ () C:\Users\knemlick\Documents\philbrick.ppt
2014-08-30 21:29 - 2008-03-17 14:14 - 00110592 _____ () C:\Users\knemlick\Documents\jiang.ppt
2014-08-30 21:29 - 2008-02-11 19:10 - 00012800 _____ () C:\Users\knemlick\Documents\NCCI Actuary Position.wps
2014-08-30 21:29 - 2008-01-31 14:32 - 00334848 _____ () C:\Users\knemlick\Documents\NYCB IRA Accounts.wps
2014-08-30 21:29 - 2008-01-29 14:20 - 02121728 _____ () C:\Users\knemlick\Documents\back on the career track postcard.pub
2014-08-30 21:29 - 2008-01-25 15:55 - 00334848 _____ () C:\Users\knemlick\Documents\Indymac Fax.wps
2014-08-30 21:29 - 2007-11-16 14:49 - 01194496 _____ () C:\Users\knemlick\Documents\madden1.ppt
2014-08-30 21:29 - 2007-11-16 14:05 - 00591360 _____ () C:\Users\knemlick\Documents\kahn.ppt
2014-08-30 21:29 - 2007-11-04 17:30 - 00013312 _____ () C:\Users\knemlick\Documents\HRH Cover Letter.wps
2014-08-30 21:29 - 2007-11-04 17:13 - 00026624 _____ () C:\Users\knemlick\Documents\HRH Envelope.wps
2014-08-30 21:29 - 2007-10-12 12:32 - 00100864 _____ () C:\Users\knemlick\Documents\hazard_groups.xlr
2014-08-30 21:29 - 2007-10-12 12:32 - 00022016 _____ () C:\Users\knemlick\Documents\hazard-group-rel-all-states.xls
2014-08-30 21:29 - 2007-10-12 12:30 - 00090112 _____ () C:\Users\knemlick\Documents\hazard-groups.xls
2014-08-30 21:29 - 2007-07-16 13:54 - 00010752 _____ () C:\Users\knemlick\Documents\NCCI Questions.wps
2014-08-30 21:29 - 2007-07-10 12:55 - 00010752 _____ () C:\Users\knemlick\Documents\Milliman 401k Note.wps
2014-08-30 21:29 - 2007-07-02 10:56 - 00334336 _____ () C:\Users\knemlick\Documents\Intervest Nat Bank IRA CD Ken.wps
2014-08-30 21:29 - 2007-06-11 14:06 - 00010752 _____ () C:\Users\knemlick\Documents\ebay Description Ken's Skipper Bike.wps
2014-08-30 21:29 - 2007-06-11 14:06 - 00000497 _____ () C:\Users\knemlick\Documents\ebay Description Ken's Skipper Bike.wps.txt
2014-08-30 21:29 - 2007-06-08 11:42 - 00012800 _____ () C:\Users\knemlick\Documents\Mapfre RE Casualty Result Projections.xlr
2014-08-30 21:29 - 2007-06-08 11:20 - 00436736 _____ () C:\Users\knemlick\Documents\clark.ppt
2014-08-30 21:29 - 2007-05-31 15:20 - 00039424 _____ () C:\Users\knemlick\Documents\Mapfre RE Casualty Reinsurance Business Plan 2.wps
2014-08-30 21:29 - 2007-05-19 00:02 - 00011776 _____ () C:\Users\knemlick\Documents\Ken's Bike Payment Receipt.wps
2014-08-30 21:29 - 2007-05-16 15:48 - 00010752 _____ () C:\Users\knemlick\Documents\ebay Description Ken's Bike.wps
2014-08-30 21:29 - 2007-05-14 14:56 - 00920244 _____ () C:\Users\knemlick\Documents\Ilfs1999 incl Med Prof.123
2014-08-30 21:29 - 2007-05-12 13:19 - 00330752 _____ () C:\Users\knemlick\Documents\mount.ppt
2014-08-30 21:29 - 2007-05-12 13:13 - 00165888 _____ () C:\Users\knemlick\Documents\magarelli.ppt
2014-08-30 21:29 - 2007-05-12 13:07 - 00144896 _____ () C:\Users\knemlick\Documents\kantor.ppt
2014-08-30 21:29 - 2007-05-12 12:43 - 00672768 _____ () C:\Users\knemlick\Documents\gluck.ppt
2014-08-30 21:29 - 2007-05-12 12:41 - 00493056 _____ () C:\Users\knemlick\Documents\mango.ppt
2014-08-30 21:29 - 2007-05-10 12:54 - 00191488 _____ () C:\Users\knemlick\Documents\hoch.ppt
2014-08-30 21:29 - 2007-05-10 12:31 - 00314880 _____ () C:\Users\knemlick\Documents\mango2.ppt
2014-08-30 21:29 - 2007-05-10 10:34 - 00530944 _____ () C:\Users\knemlick\Documents\arnold.ppt
2014-08-30 21:29 - 2007-05-10 10:34 - 00412672 _____ () C:\Users\knemlick\Documents\howard.ppt
2014-08-30 21:29 - 2007-05-10 10:34 - 00291840 _____ () C:\Users\knemlick\Documents\madden.ppt
2014-08-30 21:29 - 2007-05-10 10:05 - 00488448 _____ () C:\Users\knemlick\Documents\clark2.ppt
2014-08-30 21:29 - 2007-05-09 11:45 - 00022528 _____ () C:\Users\knemlick\Documents\Casualty Premium Level Changes.xlr
2014-08-30 21:29 - 2007-05-07 15:48 - 00000421 _____ () C:\Users\knemlick\Documents\ebay Description Ken's Bike.wps.txt
2014-08-30 21:29 - 2007-05-06 21:00 - 00033280 _____ () C:\Users\knemlick\Documents\Mapfre RE Casualty Reinsurance Business Plan.wps
2014-08-30 21:29 - 2007-05-03 13:10 - 00335360 _____ () C:\Users\knemlick\Documents\Intervest Nat Bank CD Mike.wps
2014-08-30 21:29 - 2007-05-03 11:03 - 00335360 _____ () C:\Users\knemlick\Documents\Intervest Nat Bank CD Ken.wps
2014-08-30 21:29 - 2007-04-23 17:19 - 00011264 _____ () C:\Users\knemlick\Documents\ARCH INSURANCE GROUP INC[1]., NYC.wps
2014-08-30 21:29 - 2007-02-25 15:18 - 00788064 _____ (Symantec Corporation) C:\Users\knemlick\Documents\Norton_Removal_Tool.exe
2014-08-30 21:29 - 2006-10-23 20:11 - 00331776 _____ () C:\Users\knemlick\Documents\Countrywide CD Myra.wps
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\My PSP8 Files
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\MTH 2111
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Moodys
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Montclair Radiology Chest Xray Ken 10-14-2013
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\McGladrey
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\McAfee Removal Tool-2005,2006,2007
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Mapfre RE
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\LHS Statistics CP
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\LHS Algebra 2 Summer Assignments
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\LHS Algebra 2
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\LHS Accounting 1
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\ISEE Tutoring
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Ilana Kamber
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Hillsborough County Public Schools
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Heather
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Hayek Dissertation
2014-08-30 15:01 - 2014-08-30 16:07 - 00000000 ____D () C:\Users\knemlick\Documents\Algebra 2 Tutoring
2014-08-30 15:01 - 2014-08-30 15:59 - 00000000 ____D () C:\Users\knemlick\Documents\Balpreet Thesis
2014-08-30 15:01 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\GMHS 7508
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\GMHS 7500
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\George Mason avonargy Files
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\FW__IHC_Rates0
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Form_Request0
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Equinox
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Eleanor Puerto Rico January 2010
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Danielle Sammarone
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\CyberLink
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Comcast Internet Rebate Forms
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Columbia High School AP Calculus AB
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Columbia Academy
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Claire Louis
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chubb
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chelsea
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chatham HS AP Calc AB
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chartis2012
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chartis
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Cesar Munoz
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\BQUA2811
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\BMBA 9113
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\BMBA 9111
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\BIOL 6113
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Bermudian Captive Project
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Audrey Mahl
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\AuclairRe
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Allison Para
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Ali Skinder
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Algebra Workshop
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\2008 Virus Fix Scanning Reports
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\103s14GeneralSyllabus
2014-08-30 14:57 - 2014-08-30 16:08 - 00000000 ____D () C:\Users\knemlick\Documents\Resume
2014-08-30 14:57 - 2014-08-30 15:42 - 00000000 ____D () C:\Users\knemlick\Documents\Timeless Hits
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Thesis
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Taxes
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Symantec
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\SuperAntiSpyware Installer Program
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\RKYHS
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\RegRun2
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\PXRESeverenceAgreement
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Pingry Geometry
2014-08-30 14:56 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\PhyllisDeAngelis
2014-08-30 14:56 - 2014-08-30 14:56 - 00000000 ____D () C:\Users\knemlick\Documents\New_Jersey_HMO0
2014-08-30 14:56 - 2014-08-30 14:56 - 00000000 ____D () C:\Users\knemlick\Documents\NCCI
2014-08-28 07:22 - 2014-08-22 19:42 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-28 07:22 - 2014-08-06 21:12 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 07:22 - 2014-08-01 22:56 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-25 18:13 - 2014-08-25 18:13 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-08-25 18:07 - 2014-08-25 18:07 - 04166656 _____ () C:\Users\knemlick\Downloads\lecture_10_independent_t-test.ppt
2014-08-25 13:52 - 2011-10-29 00:24 - 00654848 _____ () C:\Users\knemlick\Downloads\Two–Way(1)-2.ppt
2014-08-21 21:46 - 2014-08-21 21:46 - 00000000 ___RD () C:\Users\knemlick\AppData\Roaming\Brother
2014-08-20 22:21 - 2011-09-26 21:17 - 02020352 _____ () C:\Users\knemlick\Downloads\lecture_12_anova_one-way.ppt
2014-08-20 22:21 - 2011-09-02 09:46 - 03249152 _____ () C:\Users\knemlick\Downloads\lecture_10.ppt
2014-08-20 11:36 - 2014-09-01 12:55 - 00000426 _____ () C:\Windows\BRWMARK.INI
2014-08-20 11:36 - 2014-08-20 11:36 - 00000034 _____ () C:\Windows\SysWOW64\BD2040.DAT
2014-08-20 11:11 - 2014-08-20 11:11 - 00147501 _____ () C:\Users\knemlick\Downloads\Tutoring_Sign_Files_0.zip
2014-08-17 20:24 - 2014-04-13 22:29 - 01018880 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-08-17 20:15 - 2014-05-08 18:06 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-08-17 20:15 - 2014-04-08 17:46 - 00086688 _____ (Microsoft Corporation) C:\Windows\system32\mrt_map.dll
2014-08-17 20:15 - 2014-04-08 17:46 - 00028320 _____ (Microsoft Corporation) C:\Windows\system32\mrt100.dll
2014-08-17 20:15 - 2014-04-08 13:54 - 00080032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mrt_map.dll
2014-08-17 20:15 - 2014-04-08 13:54 - 00026784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mrt100.dll
2014-08-17 20:15 - 2014-03-13 02:42 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-08-17 20:15 - 2014-03-13 01:51 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-08-17 00:37 - 2014-08-17 00:37 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Adobe
2014-08-16 17:44 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2014-08-16 00:14 - 2014-08-01 19:17 - 00704480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-16 00:14 - 2014-08-01 19:17 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-16 00:01 - 2014-09-05 21:43 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3351969478-1937094124-811777867-1002
2014-08-16 00:01 - 2014-08-16 00:01 - 00000000 __SHD () C:\Users\knemlick\AppData\Local\EmieUserList
2014-08-16 00:01 - 2014-08-16 00:01 - 00000000 __SHD () C:\Users\knemlick\AppData\Local\EmieSiteList
2014-08-16 00:00 - 2014-08-16 00:00 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Macromedia
2014-08-15 23:59 - 2014-08-15 23:59 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\WebStorage
2014-08-15 23:56 - 2014-08-17 00:37 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Adobe
2014-08-15 23:56 - 2014-08-15 23:56 - 00001449 _____ () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\ATI
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Local\ATI
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Local\ASUS
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Local\AMD
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\ProgramData\ATI
2014-08-15 23:55 - 2014-09-05 21:34 - 00151377 _____ () C:\Users\knemlick\AppData\Local\BTServer.log
2014-08-15 23:55 - 2014-09-04 20:30 - 00000000 ____D () C:\Users\knemlick
2014-08-15 23:55 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Packages
2014-08-15 23:55 - 2014-08-15 23:55 - 00000020 ___SH () C:\Users\knemlick\ntuser.ini
2014-08-15 23:55 - 2014-08-15 23:55 - 00000000 ____D () C:\Users\knemlick\Documents\My Bluetooth
2014-08-15 23:55 - 2014-08-15 23:55 - 00000000 ____D () C:\Users\knemlick\AppData\Local\VirtualStore
2014-08-15 23:55 - 2014-03-12 10:16 - 00000000 ___RD () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-08-15 23:55 - 2014-03-12 10:16 - 00000000 ___RD () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-15 23:55 - 2014-03-12 10:12 - 00000369 _____ () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-08-15 23:55 - 2014-03-12 10:12 - 00000369 _____ () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-08-15 23:55 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-15 23:55 - 2013-08-22 10:36 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-08-15 22:57 - 2014-08-15 22:57 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 22:57 - 2014-07-31 23:41 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-15 22:52 - 2014-07-15 13:16 - 03048880 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2014-08-15 22:52 - 2014-07-15 03:29 - 03118080 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-08-15 22:52 - 2014-07-15 03:22 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2014-08-15 22:52 - 2014-07-15 03:03 - 02344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-08-15 22:52 - 2014-07-11 23:17 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2014-08-15 22:52 - 2014-06-05 09:13 - 00216368 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll
2014-08-15 22:52 - 2014-06-05 08:14 - 00189016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2014-08-15 22:52 - 2014-06-01 21:10 - 00423768 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-08-15 22:52 - 2014-05-31 05:07 - 00467800 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2014-08-15 22:52 - 2014-05-31 05:07 - 00440664 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-08-15 22:52 - 2014-05-31 05:07 - 00419672 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-08-15 22:52 - 2014-05-31 05:07 - 00089944 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-08-15 22:52 - 2014-05-31 05:07 - 00027480 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-08-15 22:52 - 2014-05-31 01:30 - 00037376 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-08-15 22:52 - 2014-05-31 01:27 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-08-15 22:52 - 2014-05-31 01:26 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-08-15 22:52 - 2014-05-30 23:01 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-08-15 22:52 - 2014-05-30 23:01 - 00209408 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-08-15 22:52 - 2014-05-30 23:01 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-08-15 22:52 - 2014-05-27 10:53 - 02518360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-08-15 22:52 - 2014-05-27 04:56 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\DaOtpCredentialProvider.dll
2014-08-15 22:52 - 2014-05-27 04:53 - 00270848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DaOtpCredentialProvider.dll
2014-08-15 22:52 - 2014-05-16 23:59 - 16871936 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2014-08-15 22:52 - 2014-05-16 23:13 - 12711424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2014-08-15 22:52 - 2014-05-01 08:31 - 00055328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wpcfltr.sys
2014-08-15 22:51 - 2014-07-09 23:16 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-08-15 22:51 - 2014-07-09 23:03 - 04756992 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-08-15 22:51 - 2014-07-09 22:33 - 01120256 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
2014-08-15 22:51 - 2014-05-31 01:27 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-08-15 22:51 - 2014-05-13 02:01 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\BulkOperationHost.exe
2014-08-15 22:51 - 2014-05-13 00:07 - 02844160 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-08-15 22:51 - 2014-05-12 23:41 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll
2014-08-15 22:51 - 2014-05-12 23:26 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll
2014-08-15 22:51 - 2014-05-12 22:59 - 01035264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-08-15 22:51 - 2014-05-12 22:31 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll
2014-08-15 22:51 - 2014-05-03 06:29 - 01726224 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-08-15 22:51 - 2014-05-03 04:20 - 01473080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-08-15 22:51 - 2014-05-03 00:36 - 00997888 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2014-08-15 22:51 - 2014-05-03 00:19 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\ncobjapi.dll
2014-08-15 22:51 - 2014-05-03 00:08 - 00301056 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-08-15 22:51 - 2014-05-03 00:07 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-08-15 22:51 - 2014-05-02 23:46 - 00052736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncobjapi.dll
2014-08-15 22:51 - 2014-05-02 23:37 - 00235008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll
2014-08-15 22:51 - 2014-05-02 23:37 - 00207360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll
2014-08-15 22:51 - 2014-05-02 18:26 - 00050745 _____ () C:\Windows\system32\srms.dat
2014-08-15 22:51 - 2014-05-01 00:44 - 01025536 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-08-15 22:51 - 2014-04-30 01:43 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwififlt.sys
2014-08-15 22:51 - 2014-04-30 01:41 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-08-15 22:51 - 2014-04-30 01:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\agilevpn.sys
2014-08-15 22:51 - 2014-04-30 01:41 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwifimp.sys
2014-08-15 22:51 - 2014-04-30 00:45 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe
2014-08-15 22:51 - 2014-04-29 23:48 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2014-08-15 22:51 - 2014-04-29 23:24 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-08-15 22:51 - 2014-04-29 23:23 - 00353280 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2014-08-15 22:51 - 2014-04-29 23:23 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-08-15 22:51 - 2014-04-29 23:23 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll
2014-08-15 22:51 - 2014-04-29 23:14 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2014-08-15 22:51 - 2014-04-29 22:59 - 01063424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-08-15 22:51 - 2014-04-29 22:46 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore.dll
2014-08-15 22:51 - 2014-04-29 22:46 - 00229888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-08-15 22:51 - 2014-04-29 22:46 - 00056320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-08-15 22:51 - 2014-04-29 22:45 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc.dll
2014-08-15 22:51 - 2014-04-29 22:42 - 00403968 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2014-08-15 22:51 - 2014-04-28 17:40 - 00721408 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2014-08-15 22:51 - 2014-04-26 17:03 - 02140888 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2014-08-15 22:51 - 2014-04-26 15:14 - 02144984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2014-08-15 22:51 - 2014-04-26 11:39 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll
2014-08-15 22:51 - 2014-04-14 04:37 - 02125344 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-08-15 22:51 - 2014-04-14 03:08 - 01797896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2014-08-15 22:51 - 2014-04-14 00:18 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d8thk.dll
2014-08-15 22:51 - 2014-04-09 01:11 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-08-15 22:51 - 2014-04-09 00:20 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-08-15 22:50 - 2014-08-01 22:11 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-08-15 22:50 - 2014-06-19 20:48 - 01273184 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-15 22:50 - 2014-06-19 18:52 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-15 22:50 - 2014-06-12 20:15 - 00517528 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-08-15 22:50 - 2014-06-12 20:14 - 01557848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-15 22:50 - 2014-06-12 19:10 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-08-15 22:50 - 2014-06-06 06:34 - 02133504 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-08-15 22:50 - 2014-06-04 04:27 - 00114520 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-15 22:50 - 2014-06-04 00:31 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-15 22:50 - 2014-06-04 00:22 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-15 22:50 - 2014-06-03 23:43 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-15 22:50 - 2014-06-03 23:38 - 03304448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-15 22:50 - 2014-06-03 21:15 - 02642944 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-15 22:50 - 2014-06-03 21:14 - 02318336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-15 22:49 - 2014-06-09 17:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 22:49 - 2014-06-09 17:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-15 22:46 - 2014-07-25 09:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-15 22:46 - 2014-07-25 08:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-15 22:46 - 2014-07-25 08:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-15 22:46 - 2014-07-25 08:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-15 22:46 - 2014-07-25 08:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-15 22:46 - 2014-07-25 07:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-15 22:46 - 2014-07-25 07:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-15 22:46 - 2014-07-25 07:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-15 22:46 - 2014-07-25 07:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-15 22:46 - 2014-07-25 07:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-15 22:46 - 2014-07-25 07:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-15 22:46 - 2014-07-25 07:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-15 22:46 - 2014-07-25 07:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-15 22:46 - 2014-07-25 07:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-15 22:46 - 2014-07-25 07:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-15 22:46 - 2014-07-25 07:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-15 22:46 - 2014-07-25 06:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-15 22:46 - 2014-07-25 06:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-15 22:46 - 2014-07-25 06:43 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-15 22:46 - 2014-07-25 06:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-15 22:46 - 2014-07-25 06:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-15 22:46 - 2014-07-25 06:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-15 22:46 - 2014-07-25 06:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-15 22:46 - 2014-07-25 06:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-15 22:46 - 2014-07-25 06:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-15 22:46 - 2014-07-25 06:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-15 22:46 - 2014-07-25 06:09 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-15 22:46 - 2014-07-25 06:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-15 22:46 - 2014-07-25 06:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-15 22:46 - 2014-07-25 05:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-15 22:46 - 2014-07-25 05:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-15 22:46 - 2014-07-25 05:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-15 22:46 - 2014-07-25 05:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-15 22:46 - 2014-07-25 05:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-15 22:46 - 2014-07-25 05:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-15 22:44 - 2014-05-31 05:07 - 00054776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-15 22:44 - 2014-05-31 05:06 - 00555736 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2014-08-15 22:44 - 2014-05-30 22:40 - 13287936 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-08-15 22:44 - 2014-05-30 22:30 - 11792384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-08-15 22:44 - 2014-05-30 22:12 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-15 22:44 - 2014-05-30 22:06 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-15 22:44 - 2014-05-30 22:03 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-15 22:44 - 2014-05-30 22:01 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-08-15 22:44 - 2014-05-30 21:56 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-15 22:44 - 2014-05-30 21:54 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-15 22:44 - 2014-05-30 21:48 - 03463680 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-15 22:44 - 2014-05-30 21:37 - 01054208 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2014-08-15 22:44 - 2014-05-30 21:36 - 00923136 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-08-15 22:44 - 2014-05-30 21:35 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2014-08-15 22:44 - 2014-05-30 21:32 - 00756224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-08-15 22:44 - 2014-05-29 07:02 - 00565576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-08-15 22:44 - 2014-05-29 02:55 - 00735232 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-08-15 22:44 - 2014-05-29 01:40 - 00735232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-08-15 22:44 - 2014-05-29 01:37 - 00436224 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2014-08-15 22:44 - 2014-05-29 00:34 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2014-08-15 22:44 - 2014-05-29 00:27 - 01417216 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-08-15 22:44 - 2014-04-11 03:25 - 00419928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2014-08-15 22:44 - 2014-04-11 01:04 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-15 22:44 - 2014-04-11 00:53 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\WSReset.exe
2014-08-15 22:44 - 2014-04-11 00:22 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-15 22:43 - 2014-06-16 17:26 - 00779264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-08-15 22:43 - 2014-06-16 17:24 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-08-15 22:43 - 2014-06-06 08:04 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-08-15 22:43 - 2014-06-06 07:18 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-08-15 22:43 - 2014-05-29 22:03 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-08-15 22:43 - 2014-03-19 19:53 - 00950784 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-08-15 22:43 - 2014-03-19 19:48 - 00201216 _____ (Microsoft Corporation) C:\Windows\system32\ReInfo.dll
2014-08-15 22:43 - 2014-03-19 18:55 - 01036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-08-15 22:43 - 2014-03-19 18:39 - 00800256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2014-08-15 22:43 - 2014-03-19 18:36 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReInfo.dll
2014-08-15 22:43 - 2014-03-13 07:35 - 00157016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wof.sys
2014-08-15 22:43 - 2014-03-11 09:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2014-08-15 22:43 - 2014-03-08 03:33 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll
2014-08-15 22:43 - 2014-03-08 02:47 - 00222720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spp.dll
2014-08-15 22:43 - 2014-03-08 02:04 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2014-08-15 22:43 - 2014-03-08 01:40 - 00139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2014-08-15 22:43 - 2014-03-08 01:31 - 00222720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2014-08-15 22:43 - 2014-03-08 01:30 - 00197632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2014-08-15 22:43 - 2014-03-08 00:11 - 00924160 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2014-08-15 22:43 - 2014-03-06 07:51 - 00488280 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2014-08-15 22:43 - 2014-03-06 06:19 - 00390488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll
2014-08-15 22:43 - 2014-03-06 06:13 - 01779800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-08-15 22:43 - 2014-03-06 01:23 - 02270208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2014-08-15 22:43 - 2014-03-06 01:23 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\dafWfdProvider.dll
2014-08-15 22:43 - 2014-03-06 01:09 - 01764864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2014-08-15 22:43 - 2014-03-04 07:14 - 00360512 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2014-08-15 22:43 - 2014-03-04 06:16 - 02088160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-08-15 22:43 - 2014-03-04 06:10 - 00355832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2014-08-15 22:43 - 2014-03-04 02:00 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\wlidprov.dll
2014-08-15 22:43 - 2014-03-04 01:32 - 00356864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidprov.dll
2014-08-15 22:42 - 2014-03-19 23:19 - 01291200 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-08-15 22:42 - 2014-03-19 22:41 - 02013016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-08-15 22:42 - 2014-03-19 22:41 - 00376152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2014-08-15 22:42 - 2014-03-19 22:40 - 01112536 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-08-15 22:42 - 2014-03-19 02:13 - 00836096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-08-15 22:42 - 2014-03-19 00:50 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\w32tm.exe
2014-08-15 22:42 - 2014-03-19 00:31 - 01656832 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2014-08-15 22:42 - 2014-03-19 00:20 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\w32tm.exe
2014-08-15 22:42 - 2014-03-19 00:08 - 01351168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2014-08-15 22:42 - 2014-03-12 08:45 - 00387210 _____ () C:\Windows\system32\ApnDatabase.xml
2014-08-15 22:42 - 2014-03-11 10:45 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\BdeHdCfgLib.dll
2014-08-15 22:42 - 2014-03-11 10:18 - 01015808 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll
2014-08-15 22:42 - 2014-03-11 10:02 - 00794112 _____ (Microsoft Corporation) C:\Windows\system32\fvewiz.dll
2014-08-15 22:42 - 2014-03-11 09:28 - 00887296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aclui.dll
2014-08-15 22:42 - 2014-03-11 09:25 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerDeviceEncryption.exe
2014-08-15 22:42 - 2014-03-08 15:40 - 00136024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2014-08-15 22:42 - 2014-03-08 15:38 - 01542768 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-08-15 22:42 - 2014-03-08 10:29 - 00356848 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2014-08-15 22:42 - 2014-03-08 06:34 - 01095488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2014-08-15 22:42 - 2014-03-08 04:02 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\sxproxy.dll
2014-08-15 22:42 - 2014-03-08 03:25 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\SetNetworkLocation.dll
2014-08-15 22:42 - 2014-03-08 03:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxproxy.dll
2014-08-15 22:42 - 2014-03-08 02:03 - 00939520 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-08-15 22:42 - 2014-03-08 01:48 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2014-08-15 22:42 - 2014-03-08 01:41 - 00412672 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-08-15 22:42 - 2014-03-08 01:37 - 00755712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-08-15 22:42 - 2014-03-08 01:25 - 00264192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-08-15 22:42 - 2014-03-08 01:04 - 00717312 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-08-15 22:42 - 2014-03-08 00:58 - 00567296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-08-15 22:42 - 2014-03-08 00:41 - 01306624 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2014-08-15 22:42 - 2014-03-06 09:34 - 02331000 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-08-15 22:42 - 2014-03-06 09:34 - 00113648 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2014-08-15 22:42 - 2014-03-06 07:53 - 02141912 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-08-15 22:42 - 2014-03-06 07:51 - 00379224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-15 22:42 - 2014-03-06 07:39 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-15 22:42 - 2014-03-06 06:19 - 00094016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2014-08-15 22:42 - 2014-03-06 05:46 - 01679128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-08-15 22:42 - 2014-03-06 04:24 - 00111616 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-08-15 22:42 - 2014-03-06 04:24 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-08-15 22:42 - 2014-03-06 04:24 - 00033280 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2014-08-15 22:42 - 2014-03-06 04:22 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-08-15 22:42 - 2014-03-06 04:22 - 00134144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-08-15 22:42 - 2014-03-06 04:19 - 00283648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-08-15 22:42 - 2014-03-06 04:19 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-08-15 22:42 - 2014-03-06 04:19 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-08-15 22:42 - 2014-03-06 04:08 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\l2gpstore.dll
2014-08-15 22:42 - 2014-03-06 03:41 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\DevPropMgr.dll
2014-08-15 22:42 - 2014-03-06 03:38 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-08-15 22:42 - 2014-03-06 03:10 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\l2gpstore.dll
2014-08-15 22:42 - 2014-03-06 03:00 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2014-08-15 22:42 - 2014-03-06 02:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-08-15 22:42 - 2014-03-06 02:16 - 00171008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2014-08-15 22:42 - 2014-03-06 02:02 - 00834560 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2014-08-15 22:42 - 2014-03-06 01:51 - 02900992 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2014-08-15 22:42 - 2014-03-06 01:31 - 02479616 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-08-15 22:42 - 2014-03-06 01:29 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll
2014-08-15 22:42 - 2014-03-06 01:27 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-08-15 22:42 - 2014-03-06 01:24 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll
2014-08-15 22:42 - 2014-03-06 01:21 - 00291840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
2014-08-15 22:42 - 2014-03-06 01:13 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll
2014-08-15 22:42 - 2014-03-06 01:11 - 02030080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-08-15 22:42 - 2014-03-06 01:06 - 00386560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlangpui.dll
2014-08-15 22:42 - 2014-03-06 01:04 - 00226304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2014-08-15 22:42 - 2014-03-06 01:01 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
2014-08-15 22:42 - 2014-03-06 00:51 - 00151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2014-08-15 22:42 - 2014-03-06 00:47 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2014-08-15 22:42 - 2014-03-06 00:42 - 00280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SessEnv.dll
2014-08-15 22:42 - 2014-03-04 07:25 - 02373784 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-08-15 22:42 - 2014-03-04 02:16 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-08-15 22:42 - 2014-03-04 02:13 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-08-15 22:42 - 2014-03-04 02:08 - 00299008 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2014-08-15 22:42 - 2014-03-04 01:56 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RMapi.dll
2014-08-15 22:42 - 2014-03-04 01:50 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-08-15 22:42 - 2014-03-04 01:42 - 00494592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-08-15 22:42 - 2014-03-04 01:39 - 00254976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2014-08-15 22:42 - 2014-03-04 01:15 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.dll
2014-08-15 22:42 - 2014-03-04 01:05 - 00402432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.dll
2014-08-15 22:42 - 2014-03-04 01:03 - 00669696 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2014-08-15 22:42 - 2014-03-04 01:03 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\CredentialMigrationHandler.dll
2014-08-15 22:42 - 2014-03-04 00:54 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredentialMigrationHandler.dll
2014-08-15 22:42 - 2014-03-04 00:52 - 00605184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2014-08-15 22:42 - 2013-12-23 18:28 - 00262656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2014-08-15 22:42 - 2013-12-23 18:26 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2014-08-15 22:40 - 2014-05-09 22:46 - 02151424 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-08-15 22:40 - 2014-05-09 22:22 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-08-15 22:40 - 2014-05-04 23:02 - 03360256 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-08-15 22:40 - 2014-04-29 23:43 - 01975296 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-08-15 22:40 - 2014-04-29 23:26 - 01345536 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-08-15 22:40 - 2014-04-29 22:47 - 01509888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-08-15 22:40 - 2014-04-18 03:21 - 01126912 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-08-15 22:40 - 2014-04-18 03:09 - 08652800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2014-08-15 22:40 - 2014-04-18 02:49 - 05833216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2014-08-15 22:40 - 2014-04-11 01:13 - 01200128 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2014-08-15 22:40 - 2014-04-06 11:31 - 21268952 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-15 22:40 - 2014-04-06 11:20 - 01403856 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2014-08-15 22:40 - 2014-04-06 11:20 - 01379064 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-08-15 22:40 - 2014-04-06 11:20 - 00765408 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2014-08-15 22:40 - 2014-04-06 11:20 - 00364640 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-08-15 22:40 - 2014-04-06 10:22 - 18755672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-15 22:40 - 2014-04-06 10:16 - 00669856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2014-08-15 22:40 - 2014-04-06 05:52 - 00955904 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2014-08-15 22:40 - 2014-04-06 05:05 - 01222656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2014-08-15 22:40 - 2014-04-02 21:53 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-08-15 22:40 - 2014-04-02 21:51 - 01584128 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll
2014-08-15 22:40 - 2014-03-30 17:54 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2014-08-15 22:40 - 2014-03-28 10:58 - 00407016 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2014-08-15 22:40 - 2014-03-27 01:16 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-08-15 22:40 - 2014-03-19 19:44 - 06645248 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-08-15 22:40 - 2014-03-19 18:33 - 05774848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-08-15 22:40 - 2014-03-19 03:07 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2014-08-15 22:40 - 2014-03-19 00:02 - 01527296 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2014-08-15 22:40 - 2014-03-18 23:18 - 02688000 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2014-08-15 22:40 - 2014-03-18 00:00 - 07173120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2014-08-15 22:40 - 2014-03-17 23:52 - 05104640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2014-08-15 22:40 - 2014-03-17 00:09 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-08-15 22:40 - 2014-03-16 22:01 - 00486912 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2014-08-15 22:40 - 2014-03-14 01:26 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\GeofenceMonitorService.dll
2014-08-15 22:39 - 2014-04-18 09:57 - 00032600 _____ (Microsoft Corporation) C:\Windows\system32\ploptin.dll
2014-08-15 22:39 - 2014-04-18 09:44 - 01466856 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-08-15 22:39 - 2014-04-18 08:29 - 01200288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-08-15 22:39 - 2014-04-18 04:44 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\energyprov.dll
2014-08-15 22:39 - 2014-04-18 03:32 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-08-15 22:39 - 2014-04-18 02:51 - 00836608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-08-15 22:39 - 2014-04-14 04:20 - 00324888 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
2014-08-15 22:39 - 2014-04-14 03:01 - 00285144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFCaptureEngine.dll
2014-08-15 22:39 - 2014-04-10 23:51 - 00250368 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2014-08-15 22:39 - 2014-04-10 23:23 - 00209920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll
2014-08-15 22:39 - 2014-04-10 22:30 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\defragsvc.dll
2014-08-15 22:39 - 2014-04-09 06:53 - 00337240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-08-15 22:39 - 2014-04-09 01:39 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2014-08-15 22:39 - 2014-04-09 00:44 - 00144384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2014-08-15 22:39 - 2014-04-08 22:33 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2014-08-15 22:39 - 2014-04-07 21:01 - 00589656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-08-15 22:39 - 2014-04-06 11:34 - 00372568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-08-15 22:39 - 2014-04-06 11:34 - 00275800 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-08-15 22:39 - 2014-04-06 11:32 - 00125496 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2014-08-15 22:39 - 2014-04-06 11:30 - 00201920 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll
2014-08-15 22:39 - 2014-04-06 11:24 - 00360792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2014-08-15 22:39 - 2014-04-06 11:20 - 00881616 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-08-15 22:39 - 2014-04-06 11:20 - 00609448 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-08-15 22:39 - 2014-04-06 11:20 - 00491744 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2014-08-15 22:39 - 2014-04-06 11:20 - 00467496 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-08-15 22:39 - 2014-04-06 11:20 - 00463256 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-08-15 22:39 - 2014-04-06 11:20 - 00244880 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-08-15 22:39 - 2014-04-06 11:20 - 00028408 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-08-15 22:39 - 2014-04-06 10:23 - 00098584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2014-08-15 22:39 - 2014-04-06 10:22 - 00178184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVideoDSP.dll
2014-08-15 22:39 - 2014-04-06 10:16 - 01209616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2014-08-15 22:39 - 2014-04-06 10:16 - 00707048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-08-15 22:39 - 2014-04-06 10:16 - 00518544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-08-15 22:39 - 2014-04-06 10:16 - 00406504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-08-15 22:39 - 2014-04-06 10:16 - 00387896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2014-08-15 22:39 - 2014-04-06 10:16 - 00326024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-08-15 22:39 - 2014-04-06 10:16 - 00305768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-08-15 22:39 - 2014-04-06 07:58 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-08-15 22:39 - 2014-04-06 07:51 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-08-15 22:39 - 2014-04-06 07:33 - 00335872 _____ (Microsoft Corporation) C:\Windows\system32\MDEServer.exe
2014-08-15 22:39 - 2014-04-06 07:24 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-08-15 22:39 - 2014-04-06 07:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-08-15 22:39 - 2014-04-06 06:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2014-08-15 22:39 - 2014-04-06 06:20 - 00201216 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2014-08-15 22:39 - 2014-04-06 06:01 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-08-15 22:39 - 2014-04-06 05:51 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2014-08-15 22:39 - 2014-04-06 05:37 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2014-08-15 22:39 - 2014-04-06 05:36 - 00888320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2014-08-15 22:39 - 2014-04-06 04:59 - 00982016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2014-08-15 22:39 - 2014-04-03 03:12 - 00307304 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-08-15 22:39 - 2014-04-03 03:12 - 00130144 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2014-08-15 22:39 - 2014-04-02 23:03 - 00230808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-08-15 22:39 - 2014-04-02 23:03 - 00111528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2014-08-15 22:39 - 2014-04-02 21:23 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tlscsp.dll
2014-08-15 22:39 - 2014-04-02 21:22 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2014-08-15 22:39 - 2014-04-01 01:23 - 00384856 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2014-08-15 22:39 - 2014-03-31 00:42 - 07425368 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-08-15 22:39 - 2014-03-31 00:35 - 00428888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-08-15 22:39 - 2014-03-30 19:01 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersShell.dll
2014-08-15 22:39 - 2014-03-30 18:43 - 00761856 _____ (Microsoft Corporation) C:\Windows\system32\WorkfoldersControl.dll
2014-08-15 22:39 - 2014-03-30 17:49 - 01287168 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2014-08-15 22:39 - 2014-03-30 17:35 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2014-08-15 22:39 - 2014-03-27 00:36 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2014-08-15 22:39 - 2014-03-26 23:59 - 00426496 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2014-08-15 22:39 - 2014-03-26 23:48 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2014-08-15 22:39 - 2014-03-26 23:19 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2014-08-15 22:39 - 2014-03-26 22:46 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-08-15 22:39 - 2014-03-26 22:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll
2014-08-15 22:39 - 2014-03-26 22:10 - 01436160 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2014-08-15 22:39 - 2014-03-19 22:48 - 00263424 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2014-08-15 22:39 - 2014-03-19 03:15 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2014-08-15 22:39 - 2014-03-19 02:24 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-08-15 22:39 - 2014-03-19 02:17 - 00011264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2014-08-15 22:39 - 2014-03-19 01:36 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-08-15 22:39 - 2014-03-19 00:56 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-08-15 22:39 - 2014-03-19 00:45 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2014-08-15 22:39 - 2014-03-19 00:19 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2014-08-15 22:39 - 2014-03-19 00:07 - 00370176 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2014-08-15 22:39 - 2014-03-19 00:00 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2014-08-15 22:39 - 2014-03-18 23:51 - 00300544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2014-08-15 22:39 - 2014-03-18 23:31 - 02100736 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlowUI.dll
2014-08-15 22:39 - 2014-03-18 03:19 - 00077312 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-08-15 22:39 - 2014-03-16 23:11 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-08-15 22:39 - 2014-03-16 21:45 - 00370176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
2014-08-15 22:39 - 2014-03-14 01:10 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GeofenceMonitorService.dll
2014-08-15 22:39 - 2014-03-11 08:02 - 00629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2014-08-15 22:39 - 2014-03-08 15:47 - 00180056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-08-15 22:39 - 2014-03-06 07:42 - 00310616 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-08-15 22:39 - 2014-03-06 04:19 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.Search.UriHandler.dll
2014-08-15 22:39 - 2014-03-06 03:20 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Shell.Search.UriHandler.dll
2014-08-15 22:39 - 2014-01-27 13:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-08-15 22:38 - 2014-05-19 01:31 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\drvcfg.exe
2014-08-15 22:38 - 2014-05-19 01:21 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe
2014-08-15 22:38 - 2014-05-19 00:23 - 00098816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-08-15 22:38 - 2014-05-01 00:24 - 02834944 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2014-08-15 22:38 - 2014-04-10 22:54 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2014-08-15 22:38 - 2014-04-10 22:06 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-15 22:38 - 2014-04-10 22:05 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-15 22:38 - 2014-04-10 22:02 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-15 22:38 - 2014-04-10 22:01 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-15 22:38 - 2014-04-10 21:57 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-08-15 22:38 - 2014-04-10 21:56 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-08-15 22:38 - 2014-04-10 21:46 - 01705472 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-15 22:37 - 2014-03-23 21:30 - 00257880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-08-15 22:37 - 2014-03-23 21:30 - 00123224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
2014-08-15 22:37 - 2014-03-23 21:27 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-08-15 22:35 - 2014-08-20 19:45 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-08-15 22:35 - 2014-08-15 22:35 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-08-15 22:35 - 2014-08-15 22:35 - 00000000 ____D () C:\Program Files (x86)\Adobe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-05 22:13 - 2014-09-05 22:12 - 00019171 _____ () C:\Users\knemlick\Desktop\FRST.txt
2014-09-05 22:12 - 2014-09-05 22:12 - 00000000 ____D () C:\FRST
2014-09-05 22:10 - 2014-04-25 17:32 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-05 22:04 - 2014-09-05 22:09 - 02104832 _____ (Farbar) C:\Users\knemlick\Desktop\FRST64.exe
2014-09-05 22:03 - 2014-09-03 20:11 - 00001111 _____ () C:\Users\knemlick\Desktop\Continue Live Installation.lnk
2014-09-05 22:00 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\sru
2014-09-05 21:46 - 2014-09-03 17:10 - 00000000 ____D () C:\Users\knemlick\AppData\Local\WeatherAlerts
2014-09-05 21:44 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-05 21:43 - 2014-08-16 00:01 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3351969478-1937094124-811777867-1002
2014-09-05 21:41 - 2014-09-03 19:48 - 00000003 _____ () C:\Users\knemlick\AppData\Local\proxy.log
2014-09-05 21:38 - 2014-09-05 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-09-05 21:36 - 2014-09-03 17:10 - 00000000 ____D () C:\Users\knemlick\AppData\Local\fst_us_239
2014-09-05 21:34 - 2014-08-15 23:55 - 00151377 _____ () C:\Users\knemlick\AppData\Local\BTServer.log
2014-09-05 21:33 - 2014-09-03 17:12 - 00001364 _____ () C:\Windows\Tasks\RGMDMNF.job
2014-09-05 21:33 - 2014-09-03 17:12 - 00001362 _____ () C:\Windows\Tasks\TCUCBK.job
2014-09-05 21:32 - 2013-08-22 09:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-05 21:31 - 2014-05-26 02:56 - 01495098 _____ () C:\Windows\WindowsUpdate.log
2014-09-05 21:15 - 2014-09-03 17:12 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-05 21:14 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-09-05 21:13 - 2013-08-22 08:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-09-04 20:30 - 2014-08-15 23:55 - 00000000 ____D () C:\Users\knemlick
2014-09-04 20:22 - 2014-09-03 19:46 - 00000362 _____ () C:\Windows\Tasks\bench-sys.job
2014-09-04 19:57 - 2014-09-04 19:57 - 00139488 _____ () C:\Windows\SysWOW64\XMLOperations.xml
2014-09-03 19:52 - 2014-09-03 19:46 - 00000362 _____ () C:\Windows\Tasks\bench-S-1-5-21-3351969478-1937094124-811777867-1002.job
2014-09-03 19:48 - 2014-09-03 19:48 - 00000000 ____D () C:\Users\knemlick\AppData\Local\BenchUpdater
2014-09-03 19:48 - 2014-09-03 19:46 - 00003216 _____ () C:\Windows\System32\Tasks\bench-S-1-5-21-3351969478-1937094124-811777867-1002
2014-09-03 19:48 - 2014-09-03 19:46 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browse Safe
2014-09-03 19:48 - 2014-09-03 19:46 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Browse Safe
2014-09-03 19:48 - 2014-09-03 19:46 - 00000000 ____D () C:\Program Files (x86)\Bench
2014-09-03 19:46 - 2014-09-03 19:46 - 00003232 _____ () C:\Windows\System32\Tasks\bench-sys
2014-09-03 19:46 - 2014-09-03 19:46 - 00000000 ____D () C:\Program Files (x86)\Browse Safe
2014-09-03 19:45 - 2014-09-03 19:45 - 00000000 ____D () C:\ProgramData\smdmf
2014-09-03 19:45 - 2014-09-03 19:45 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
2014-09-03 17:54 - 2014-09-03 17:10 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2014-09-03 17:52 - 2014-04-25 16:22 - 00006804 _____ () C:\Windows\PFRO.log
2014-09-03 17:50 - 2014-09-03 17:10 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2014-09-03 17:12 - 2014-09-03 17:12 - 01994144 _____ (enter) C:\Users\knemlick\AppData\Roaming\TCUCBK.exe
2014-09-03 17:12 - 2014-09-03 17:12 - 01541024 _____ (enter) C:\Users\knemlick\AppData\Roaming\RGMDMNF.exe
2014-09-03 17:12 - 2014-09-03 17:12 - 00004370 _____ () C:\Windows\System32\Tasks\RGMDMNF
2014-09-03 17:12 - 2014-09-03 17:12 - 00004368 _____ () C:\Windows\System32\Tasks\TCUCBK
2014-09-03 17:12 - 2014-09-03 17:12 - 00002512 _____ () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-09-03 17:12 - 2014-09-03 17:12 - 00000000 ____D () C:\Users\knemlick\AppData\Local\globalUpdate
2014-09-03 17:12 - 2014-09-03 17:12 - 00000000 ____D () C:\Users\knemlick\AppData\Local\com
2014-09-03 17:12 - 2014-09-03 17:12 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-09-03 17:11 - 2014-09-03 17:11 - 00004026 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-09-03 17:11 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts
2014-09-03 17:11 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Smartbar
2014-09-03 17:11 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Local\LPT
2014-09-03 17:11 - 2014-09-03 17:11 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Local_Weather_LLC
2014-09-03 17:11 - 2014-09-03 17:10 - 00000004 _____ () C:\end
2014-09-03 17:11 - 2014-09-03 17:10 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\VOPackage
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREESOFTTODAY
2014-09-03 17:10 - 2014-09-03 17:10 - 00000000 ____D () C:\Program Files (x86)\fst_us_239
2014-09-03 17:10 - 2013-08-22 10:36 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-09-03 17:10 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-09-03 17:10 - 2013-08-22 09:46 - 00014611 _____ () C:\Windows\setupact.log
2014-09-03 08:21 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-09-02 16:35 - 2014-09-02 16:35 - 00030374 _____ () C:\Users\knemlick\Downloads\bk-coretag (1).js
2014-09-02 15:29 - 2014-09-02 15:32 - 00012800 _____ () C:\Users\knemlick\Documents\NASA Federal Credit Union CD2.wps
2014-09-02 14:25 - 2014-09-02 14:25 - 00030374 _____ () C:\Users\knemlick\Downloads\bk-coretag.js
2014-09-01 12:55 - 2014-08-20 11:36 - 00000426 _____ () C:\Windows\BRWMARK.INI
2014-09-01 03:18 - 2014-09-01 03:18 - 00002086 _____ () C:\Users\knemlick\AppData\Roaming\RGMDMNF
2014-09-01 03:18 - 2014-09-01 03:18 - 00001248 _____ () C:\Users\knemlick\AppData\Roaming\TCUCBK
2014-08-30 22:41 - 2014-08-30 22:41 - 00000000 ____D () C:\Program Files (x86)\MSECache
2014-08-30 22:30 - 2014-08-30 22:30 - 00002599 _____ () C:\Users\Public\Desktop\GPower 3.1.lnk
2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GPower
2014-08-30 22:30 - 2014-08-30 22:30 - 00000000 ____D () C:\Program Files (x86)\GPower 3.1
2014-08-30 22:28 - 2014-08-30 22:28 - 00000000 ____D () C:\Users\knemlick\Downloads\GPowerWin_3.1.9.2
2014-08-30 22:27 - 2014-08-30 22:27 - 13451133 _____ () C:\Users\knemlick\Downloads\GPowerWin_3.1.9.2.zip
2014-08-30 22:06 - 2014-08-30 22:05 - 00000000 ____D () C:\Users\knemlick\Documents\My Documents Mike 12-12-07
2014-08-30 21:30 - 2014-08-30 21:30 - 00000000 ____D () C:\Users\knemlick\Documents\Solomon Schechter
2014-08-30 21:30 - 2014-08-30 21:30 - 00000000 ____D () C:\Users\knemlick\Documents\SAT Reasoning Test
2014-08-30 21:29 - 2014-08-30 21:29 - 00000000 ____D () C:\Users\knemlick\Documents\VincentPapa
2014-08-30 21:29 - 2014-08-30 21:29 - 00000000 ____D () C:\Users\knemlick\Documents\Stifel
2014-08-30 21:29 - 2014-08-30 21:29 - 00000000 ____D () C:\Users\knemlick\Documents\Stephanie Ingber
2014-08-30 16:08 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Resume
2014-08-30 16:07 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Algebra 2 Tutoring
2014-08-30 15:59 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Balpreet Thesis
2014-08-30 15:42 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Timeless Hits
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\My PSP8 Files
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\MTH 2111
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Moodys
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Montclair Radiology Chest Xray Ken 10-14-2013
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\McGladrey
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\McAfee Removal Tool-2005,2006,2007
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Mapfre RE
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\LHS Statistics CP
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\LHS Algebra 2 Summer Assignments
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\LHS Algebra 2
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\LHS Accounting 1
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\ISEE Tutoring
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Ilana Kamber
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Hillsborough County Public Schools
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Heather
2014-08-30 15:02 - 2014-08-30 15:02 - 00000000 ____D () C:\Users\knemlick\Documents\Hayek Dissertation
2014-08-30 15:02 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\GMHS 7508
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\GMHS 7500
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\George Mason avonargy Files
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\FW__IHC_Rates0
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Form_Request0
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Equinox
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Eleanor Puerto Rico January 2010
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Danielle Sammarone
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\CyberLink
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Comcast Internet Rebate Forms
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Columbia High School AP Calculus AB
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Columbia Academy
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Claire Louis
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chubb
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chelsea
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chatham HS AP Calc AB
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chartis2012
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Chartis
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Cesar Munoz
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\BQUA2811
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\BMBA 9113
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\BMBA 9111
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\BIOL 6113
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Bermudian Captive Project
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Audrey Mahl
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\AuclairRe
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Allison Para
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Ali Skinder
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\Algebra Workshop
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\2008 Virus Fix Scanning Reports
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\knemlick\Documents\103s14GeneralSyllabus
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Thesis
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Taxes
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Symantec
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\SuperAntiSpyware Installer Program
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\RKYHS
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\RegRun2
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\PXRESeverenceAgreement
2014-08-30 14:57 - 2014-08-30 14:57 - 00000000 ____D () C:\Users\knemlick\Documents\Pingry Geometry
2014-08-30 14:57 - 2014-08-30 14:56 - 00000000 ____D () C:\Users\knemlick\Documents\PhyllisDeAngelis
2014-08-30 14:56 - 2014-08-30 14:56 - 00000000 ____D () C:\Users\knemlick\Documents\New_Jersey_HMO0
2014-08-30 14:56 - 2014-08-30 14:56 - 00000000 ____D () C:\Users\knemlick\Documents\NCCI
2014-08-29 17:54 - 2014-08-30 21:30 - 00023552 _____ () C:\Users\knemlick\Documents\Tutoring Income.xlr
2014-08-28 17:33 - 2013-08-22 09:44 - 00424008 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-28 10:18 - 2013-08-22 10:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-27 22:13 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-08-27 18:56 - 2014-08-30 21:30 - 00066048 _____ () C:\Users\knemlick\Documents\Tutoring Clients.xlr
2014-08-25 18:13 - 2014-08-25 18:13 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-08-25 18:07 - 2014-08-25 18:07 - 04166656 _____ () C:\Users\knemlick\Downloads\lecture_10_independent_t-test.ppt
2014-08-22 19:42 - 2014-08-28 07:22 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 09:13 - 2014-04-25 17:57 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-08-22 09:03 - 2014-04-25 17:57 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-08-21 21:46 - 2014-08-21 21:46 - 00000000 ___RD () C:\Users\knemlick\AppData\Roaming\Brother
2014-08-20 19:45 - 2014-08-15 22:35 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-08-20 11:36 - 2014-08-20 11:36 - 00000034 _____ () C:\Windows\SysWOW64\BD2040.DAT
2014-08-20 11:11 - 2014-08-20 11:11 - 00147501 _____ () C:\Users\knemlick\Downloads\Tutoring_Sign_Files_0.zip
2014-08-19 10:09 - 2014-04-25 17:50 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-18 11:01 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\rescache
2014-08-18 10:47 - 2013-08-22 14:11 - 00000000 ____D () C:\Program Files\Windows Journal
2014-08-18 10:47 - 2013-08-22 14:09 - 00000000 ____D () C:\Windows\SysWOW64\winrm
2014-08-18 10:47 - 2013-08-22 14:09 - 00000000 ____D () C:\Windows\SysWOW64\WCN
2014-08-18 10:47 - 2013-08-22 14:09 - 00000000 ____D () C:\Windows\SysWOW64\slmgr
2014-08-18 10:47 - 2013-08-22 14:09 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\WinStore
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\SysWOW64\Com
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\IME
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\System
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2014-08-18 10:47 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-08-18 10:47 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\SysWOW64\oobe
2014-08-18 10:47 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-08-18 10:47 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\servicing
2014-08-18 10:46 - 2013-08-22 14:09 - 00000000 ____D () C:\Windows\system32\winrm
2014-08-18 10:46 - 2013-08-22 10:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2014-08-18 10:46 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\migwiz
2014-08-18 10:46 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-18 10:45 - 2013-08-22 14:09 - 00000000 ____D () C:\Windows\system32\WCN
2014-08-18 10:45 - 2013-08-22 14:09 - 00000000 ____D () C:\Windows\system32\slmgr
2014-08-18 10:45 - 2013-08-22 14:09 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2014-08-18 10:45 - 2013-08-22 10:36 - 00000000 ___SD () C:\Windows\system32\dsc
2014-08-18 10:45 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\SystemResetPlatform
2014-08-18 10:45 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\MUI
2014-08-18 10:45 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\Com
2014-08-18 10:45 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\Help
2014-08-18 10:45 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-08-18 10:45 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\system32\oobe
2014-08-18 10:45 - 2013-08-22 08:36 - 00000000 ____D () C:\Windows\system32\Dism
2014-08-17 20:24 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-08-17 00:37 - 2014-08-17 00:37 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Adobe
2014-08-17 00:37 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Adobe
2014-08-16 17:43 - 2013-08-22 10:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-08-16 17:42 - 2014-04-25 17:57 - 00000000 ____D () C:\ProgramData\McAfee
2014-08-16 00:11 - 2013-08-22 10:36 - 00000000 ___RD () C:\Windows\ToastData
2014-08-16 00:11 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-08-16 00:11 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-08-16 00:11 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-08-16 00:10 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\FileManager
2014-08-16 00:10 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\Camera
2014-08-16 00:09 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-16 00:09 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-08-16 00:09 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\setup
2014-08-16 00:01 - 2014-08-16 00:01 - 00000000 __SHD () C:\Users\knemlick\AppData\Local\EmieUserList
2014-08-16 00:01 - 2014-08-16 00:01 - 00000000 __SHD () C:\Users\knemlick\AppData\Local\EmieSiteList
2014-08-16 00:00 - 2014-08-16 00:00 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Macromedia
2014-08-15 23:59 - 2014-08-15 23:59 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\WebStorage
2014-08-15 23:56 - 2014-08-15 23:56 - 00001449 _____ () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Roaming\ATI
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Local\ATI
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Local\ASUS
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\Users\knemlick\AppData\Local\AMD
2014-08-15 23:56 - 2014-08-15 23:56 - 00000000 ____D () C:\ProgramData\ATI
2014-08-15 23:56 - 2014-08-15 23:55 - 00000000 ____D () C:\Users\knemlick\AppData\Local\Packages
2014-08-15 23:55 - 2014-08-15 23:55 - 00000020 ___SH () C:\Users\knemlick\ntuser.ini
2014-08-15 23:55 - 2014-08-15 23:55 - 00000000 ____D () C:\Users\knemlick\Documents\My Bluetooth
2014-08-15 23:55 - 2014-08-15 23:55 - 00000000 ____D () C:\Users\knemlick\AppData\Local\VirtualStore
2014-08-15 22:57 - 2014-08-15 22:57 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 22:53 - 2013-08-22 10:36 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-08-15 22:35 - 2014-08-15 22:35 - 00002046 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-08-15 22:35 - 2014-08-15 22:35 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-15 22:19 - 2014-04-25 17:22 - 00000000 ____D () C:\Windows\Panther
2014-08-06 21:12 - 2014-08-28 07:22 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll

Some content of TEMP:
====================
C:\Users\knemlick\AppData\Local\Temp\BackupSetup.exe
C:\Users\knemlick\AppData\Local\Temp\ins1F52.tmp.exe
C:\Users\knemlick\AppData\Local\Temp\post1.exe
C:\Users\knemlick\AppData\Local\Temp\post2.dll
C:\Users\knemlick\AppData\Local\Temp\post2.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-09-05 21:27

==================== End Of Log ============================

 

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-09-2014 02
Ran by knemlick at 2014-09-05 22:13:38
Running from C:\Users\knemlick\Desktop
Boot Mode: Normal
==========================================================

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Disabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Reader XI (11.0.08) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader Driver  (HKLM-x32\...\InstallShield_{07CCA4AC-FCC6-4A0A-B87A-26F6F50A7E31}) (Version: 20.2.44.03548 - Alcor Micro Corp.)
Alcor Micro USB Card Reader Driver  (x32 Version: 20.2.44.03548 - Alcor Micro Corp.) Hidden
AMD Accelerated Video Transcoding (Version: 13.15.100.30819 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.0819.1344.22803 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{BCF4DA9E-A219-2BFF-8A17-81BB135E9BCA}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Fuel (Version: 2013.0819.1344.22803 - Advanced Micro Devices, Inc.) Hidden
ASUS Manager - Ai Booting (HKLM-x32\...\{2DCE446C-D090-4458-8782-8F16DF94351E}) (Version: 2.01.12 - ASUSTeK Computer Inc.)
ASUS Manager - Backup & Recovery (HKLM-x32\...\{34D67DE5-2ECF-4E6B-A243-2C16E2792787}) (Version: 2.01.10 - ASUSTeK Computer Inc.)
ASUS Manager - Family Safety (HKLM-x32\...\{016AFF97-4E18-4560-B8E5-B684BB124E32}) (Version: 2.00.03 - ASUSTeK Computer Inc.)
ASUS Manager - PC Cleanup (HKLM-x32\...\{E22A19AE-7DDB-4959-B1DB-A0996294352A}) (Version: 2.01.08 - ASUSTeK Computer Inc.)
ASUS Manager - Power Manager (HKLM-x32\...\{DD248BEE-E925-4720-A775-9A42276BB6EA}) (Version: 2.02.02 - ASUSTeK Computer Inc.)
ASUS Manager - Update (HKLM-x32\...\{675BBE8A-0ED3-4048-8723-BA51EAB8E1A8}) (Version: 2.02.04 - ASUSTeK Computer Inc.)
ASUS Manager (HKLM-x32\...\{F5E5AD85-4A90-4604-A887-464D3818D8FD}) (Version: 2.08.00 - ASUSTeK Computer Inc.)
ASUS Music Maker (HKLM-x32\...\MAGIX_{AB515018-7F9D-4047-B0C0-F26BAC30F3E1}) (Version: 18.0.4.1 - MAGIX AG)
ASUS Music Maker (Version: 18.0.4.1 - MAGIX AG) Hidden
ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5424.52 - CyberLink Corp.)
ASUSDVD (x32 Version: 10.0.5424.52 - CyberLink Corp.) Hidden
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.12.311 - ASUSTEK)
Browse Safe (HKLM-x32\...\38985_Browse Safe) (Version: 1.0 - Gratifying Apps)
Catalyst Control Center InstallProxy (x32 Version: 2013.0819.1344.22803 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.0819.1344.22803 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Profiles Mobile (x32 Version: 2013.0819.1344.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.0819.1343.22803 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.0819.1344.22803 - Advanced Micro Devices, Inc.) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.4428 - CyberLink Corp.)
CyberLink PhotoDirector 3 (x32 Version: 3.0.4428 - CyberLink Corp.) Hidden
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DesktopWeatherAlerts (HKCU\...\DesktopWeatherAlerts) (Version: 1.0.29.0 - Local Weather LLC)
eManual (HKLM-x32\...\{0C84E634-EB68-4A54-B21E-A05EC87A4CC5}) (Version: 1.00.07 - ASUSTeK Computer Inc.)
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)
FreeSoftToday 025.239 (HKLM-x32\...\fst_us_239_is1) (Version:  - FREESOFTTODAY) <==== ATTENTION
G*Power 3.1.9.2 (HKLM-x32\...\{F9C59D86-6F65-4EDB-89A2-FBA1F78762D2}) (Version: 3.1.92 - Franz Faul, Uni Kiel, Germany)
Galería de fotos (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
LPT System Updater Service (x32 Version: 1.0.0.0 - LPT) Hidden <==== ATTENTION
McAfee Internet Security (HKLM-x32\...\MSC) (Version: 12.8.988 - McAfee, Inc.)
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Movie Maker (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MyPC Backup  (HKLM\...\MyPC Backup) (Version:  - JDi Backup Ltd) <==== ATTENTION
Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.769.769.092613 - REALTEK Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.18.621.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7035 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0224 - REALTEK Semiconductor Corp.)
Remote Desktop Access (VuuPC) (HKLM-x32\...\VOPackage) (Version: 1.0.0.0 - CMI Limited) <==== ATTENTION
Settings Manager (HKLM-x32\...\Settings Manager) (Version: 5.0.0.13892 - Aztec Media Inc) <==== ATTENTION
Snap.Do (HKLM-x32\...\{4130EAB4-F6D3-4981-A6DC-82CBCC308208}) (Version: 11.112.1.19229 - ReSoft Ltd.) <==== ATTENTION
Snap.Do Engine (HKCU\...\{97a00666-c001-48aa-a95c-6d6301ef2e63}) (Version: 11.112.1.19229 - ReSoft Ltd.) <==== ATTENTION
WebStorage (HKLM-x32\...\WebStorage) (Version: 2.0.3.226 - ASUS Cloud Corporation)
Windows Live (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3522.0110 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

==================== Restore Points  =========================

18-08-2014 15:27:52 Language Pack Removal
26-08-2014 13:30:25 Scheduled Checkpoint
31-08-2014 03:30:21 Installed G*Power 3.1.9.2
03-09-2014 22:10:25 Uniblue SpeedUpMyPC installation

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {234C0AE7-C6F8-446E-A107-78E0DB38DE20} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-03-12] (Microsoft Corporation)
Task: {24342115-2504-456E-9ED5-D6AAD941C84D} - System32\Tasks\TCUCBK => C:\Users\knemlick\AppData\Roaming\TCUCBK.exe [2014-09-03] (enter) <==== ATTENTION
Task: {2ABF8B6F-6F5E-4C1B-A610-60C721CEF48B} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {330C8483-BA2B-4404-AA96-F9D1E315163B} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-08-20] () <==== ATTENTION
Task: {33FE46FD-5C77-4248-8B22-CE4564BD2180} - System32\Tasks\bench-S-1-5-21-3351969478-1937094124-811777867-1002 => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-08-20] () <==== ATTENTION
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3A08A402-D0A5-4D51-AA26-1F3778796EFE} - System32\Tasks\ASUS\ASUS Manager - PC Cleanup - SecureDeleteBackground => C:\Program Files (x86)\ASUS\ASUS Manager\PC Cleanup\SecureDeleteBackground.exe [2014-03-25] ()
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {3BE6FE78-F14D-45DC-B3F4-0604C48685D2} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {64676BAD-8D49-4734-8158-CA1C2BC72699} - System32\Tasks\ASUS\Power_Manager_background => C:\Program Files (x86)\ASUS\ASUS Manager\Power Manager\Power Manager_background.exe [2014-02-20] (ASUSTeK)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6B8E08C4-9E6B-4AC6-B492-82A34A6F1D57} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {753CF806-F121-43A5-9038-3897EAF9F01C} - System32\Tasks\ASUS\ASUS Updater => C:\Program Files (x86)\ASUS\ASUS Manager\Application Update\ASUSFourceUpdater.exe [2013-11-28] ()
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {819BC78E-B32D-4338-B5C7-92DF6D40FDD8} - System32\Tasks\RGMDMNF => C:\Users\knemlick\AppData\Roaming\RGMDMNF.exe [2014-09-03] (enter) <==== ATTENTION
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {8F87E0FE-6D5F-4B0C-BB36-3F7053D9E760} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-07-31] (Microsoft Corporation)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {AD80ACCC-F72E-4658-A974-E780C077FD40} - System32\Tasks\ASUS\ASUS Manager HotKey Service => C:\Program Files (x86)\ASUS\ASUS Manager\AsHKService.exe [2013-11-26] (ASUSTeK Computer Inc.)
Task: {ADE918B4-222F-4966-9DFC-75966C6FF395} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe [2014-08-27] (MyPC Backup) <==== ATTENTION
Task: {B613415E-AE44-4BB1-BD5F-AED3987CFB32} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E5A061BF-5EC9-429C-A5BE-EAB1F46A861E} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {F4D94CF8-C709-430A-8189-3FF8DEA2EAD1} - System32\Tasks\ASUS\ASUS Manager BackgroundWindow => C:\Program Files (x86)\ASUS\ASUS Manager\BackgroundWindow.exe [2013-08-23] ()
Task: {FC30E395-67BD-44E4-A584-FA0BE1E343BB} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2013-11-04] ()
Task: {FD4680B3-313C-4D58-9059-89A4961E4946} - System32\Tasks\ASUS\ASUS Update Checker => C:\Program Files (x86)\ASUS\ASUS Manager\Application Update\ASUSUpdateChecker.exe [2013-11-27] ()
Task: C:\Windows\Tasks\bench-S-1-5-21-3351969478-1937094124-811777867-1002.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\RGMDMNF.job => C:\Users\knemlick\AppData\Roaming\RGMDMNF.exe
Task: C:\Windows\Tasks\TCUCBK.job => C:\Users\knemlick\AppData\Roaming\TCUCBK.exe

==================== Loaded Modules (whitelisted) =============

2013-08-19 16:47 - 2013-08-19 16:47 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2014-08-27 09:00 - 2014-08-27 09:00 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll
2014-05-26 02:59 - 2013-09-26 13:15 - 00059392 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2014-08-27 16:20 - 2014-08-27 16:20 - 00032800 _____ () C:\Program Files (x86)\LPT\srpts.exe
2014-04-25 18:02 - 2012-04-24 05:43 - 00390632 ____R () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-09-03 17:11 - 2014-09-03 17:11 - 00071680 _____ () C:\Users\knemlick\AppData\Roaming\VOPackage\VOsrv.exe
2014-08-27 16:20 - 2014-08-27 16:20 - 00034848 _____ () C:\Program Files (x86)\LPT\srptsl.exe
2014-04-25 17:52 - 2014-03-25 20:36 - 00929936 _____ () C:\Program Files (x86)\ASUS\ASUS Manager\PC Cleanup\SecureDeleteBackground.exe
2014-08-20 10:14 - 2014-08-20 10:14 - 00110592 _____ () C:\Program Files (x86)\Bench\BService\1.1\bhelper64.dll
2014-04-25 17:52 - 2014-03-12 17:51 - 00907776 _____ () C:\Windows\PCCleanupContextMenu\x64\ContextMenuHandler.dll
2014-09-03 17:10 - 2014-09-02 11:42 - 03303416 _____ () C:\Users\knemlick\AppData\Local\fst_us_239\upfst_us_239.exe
2014-08-27 16:20 - 2014-08-27 16:20 - 00023072 _____ () C:\Users\knemlick\AppData\Local\LPT\srptm.exe
2014-02-25 12:00 - 2014-02-25 12:00 - 00550952 _____ () C:\Users\knemlick\AppData\Local\WeatherAlerts\DesktopWeatherAlertsApp.exe
2014-08-27 09:05 - 2014-08-27 09:05 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll
2014-08-20 10:14 - 2014-08-20 10:14 - 00052736 _____ () C:\Program Files (x86)\Bench\BService\1.1\bservice.exe
2014-08-20 10:14 - 2014-08-20 10:14 - 00110592 _____ () C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe
2014-08-20 10:15 - 2014-08-20 10:15 - 00092672 _____ () C:\Program Files (x86)\Bench\Wd\wd.exe
2014-08-20 10:09 - 2014-08-20 10:09 - 00127488 _____ () C:\Program Files (x86)\Bench\Proxy\pwdg.exe
2014-04-25 17:51 - 2013-11-06 05:58 - 00920736 ____R () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
2012-03-07 21:27 - 2012-03-07 21:27 - 00016384 _____ () C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\ACVsWin.dll
2013-08-19 16:47 - 2013-08-19 16:47 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-08-20 10:09 - 2014-08-20 10:09 - 00430592 _____ () C:\Program Files (x86)\Bench\Proxy\proc.exe
2014-08-27 16:19 - 2014-08-27 16:19 - 00023584 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Lrcnta.exe
2014-08-27 16:20 - 2014-08-27 16:20 - 00042528 _____ () C:\Program Files (x86)\LPT\srptc.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00018976 _____ () C:\Program Files (x86)\LPT\Smartbar.Common.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00070176 _____ () C:\Program Files (x86)\LPT\srut.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00081952 _____ () C:\Users\knemlick\AppData\Local\LPT\srpt.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00042528 _____ () C:\Users\knemlick\AppData\Local\LPT\srptc.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00018976 _____ () C:\Users\knemlick\AppData\Local\LPT\Smartbar.Common.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00070176 _____ () C:\Users\knemlick\AppData\Local\LPT\srut.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00067616 _____ () C:\Users\knemlick\AppData\Local\LPT\sppsm.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00158240 _____ () C:\Users\knemlick\AppData\Local\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00027168 _____ () C:\Users\knemlick\AppData\Local\LPT\Smartbar.Personalization.Common.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00165920 _____ () C:\Users\knemlick\AppData\Local\LPT\Smartbar.Infrastructure.Utilities.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00047136 _____ () C:\Users\knemlick\AppData\Local\LPT\srbu.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00024608 _____ () C:\Users\knemlick\AppData\Local\LPT\srpdm.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00026144 _____ () C:\Users\knemlick\AppData\Local\LPT\ProxySettings.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00044064 _____ () C:\Users\knemlick\AppData\Local\LPT\Smartbar.Monetization.Proxy.ProxyService.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00027680 _____ () C:\Users\knemlick\AppData\Local\LPT\sreu.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00050208 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00086048 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\srau.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00165920 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 02425376 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00067104 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\spbl.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00158240 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00014368 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\siem.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00067616 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\sppsm.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00696864 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00014880 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00078880 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00027168 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00070176 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\srut.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00029216 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\srsbs.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00065568 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00150560 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\smti.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00073760 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\smsp.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00011808 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\sidc.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00030752 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\smtu.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00038432 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\smta.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00031264 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\srom.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00047136 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\srbu.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00024096 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\sgml.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00061984 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00024608 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\srpdm.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00043552 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\MACTrackBarLib.dll
2014-08-20 10:14 - 2014-08-20 10:14 - 00053248 _____ () C:\Program Files (x86)\Bench\BService\1.1\bhelper.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00035360 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00193056 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\sgmu.dll
2014-05-12 11:21 - 2014-05-12 11:21 - 00061440 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll
2014-08-27 16:20 - 2014-08-27 16:20 - 00255008 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\srns.dll
2014-04-25 17:51 - 2014-09-05 21:35 - 00026624 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.19\PEbiosinterface32.dll
2014-04-25 17:51 - 2010-06-28 21:58 - 00104448 ____R () C:\Program Files (x86)\ASUS\AXSP\1.00.19\ATKEX.dll
2014-08-27 16:19 - 2014-08-27 16:19 - 00033312 _____ () C:\Users\knemlick\AppData\Local\Smartbar\Application\lrcnt.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
==================
Error: (09/04/2014 08:08:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: FrameworkEngine.exe, version: 1.1.0.0, time stamp: 0x53880a5f
Faulting module name: ntdll.dll, version: 6.3.9600.17114, time stamp: 0x53648f36
Exception code: 0xc0000005
Fault offset: 0x0003f92d
Faulting process id: 0xe1c
Faulting application start time: 0xFrameworkEngine.exe0
Faulting application path: FrameworkEngine.exe1
Faulting module path: FrameworkEngine.exe2
Report Id: FrameworkEngine.exe3
Faulting package full name: FrameworkEngine.exe4
Faulting package-relative application ID: FrameworkEngine.exe5

Error: (09/04/2014 07:55:11 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (09/03/2014 08:11:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: nsg9F28.tmp, version: 0.0.0.0, time stamp: 0x2a425e19
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x777d8a5d
Faulting process id: 0x1948
Faulting application start time: 0xnsg9F28.tmp0
Faulting application path: nsg9F28.tmp1
Faulting module path: nsg9F28.tmp2
Report Id: nsg9F28.tmp3
Faulting package full name: nsg9F28.tmp4
Faulting package-relative application ID: nsg9F28.tmp5

Error: (09/03/2014 05:54:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program nspD65D.tmp version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1238

Start Time: 01cfc7c9f022723c

Termination Time: 4294967295

Application Path: C:\Users\knemlick\AppData\Local\Temp\nspD65D.tmp

Report Id: 3a80a52d-33bd-11e4-8263-54271e5be0f6

Faulting package full name:

Faulting package-relative application ID:

Error: (09/03/2014 05:54:15 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (09/03/2014 01:55:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17239 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 52c48

Start Time: 01cfc7a81988495c

Termination Time: 31

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id: db491013-339b-11e4-8262-54271e5be0f6

Faulting package full name:

Faulting package-relative application ID:

Error: (09/03/2014 01:53:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17239 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 501dc

Start Time: 01cfc7a8131bdcc1

Termination Time: 62

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id: a11ef6b1-339b-11e4-8262-54271e5be0f6

Faulting package full name:

Faulting package-relative application ID:

Error: (09/02/2014 01:00:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17239 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 33060

Start Time: 01cfc6d752eaeab5

Termination Time: 32

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id: f76eee98-32ca-11e4-8262-54271e5be0f6

Faulting package full name:

Faulting package-relative application ID:

Error: (09/02/2014 00:57:12 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17239 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 32bf4

Start Time: 01cfc6d72651b4ec

Termination Time: 31

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id: 8ea78ba4-32ca-11e4-8262-54271e5be0f6

Faulting package full name:

Faulting package-relative application ID:

Error: (09/02/2014 00:55:57 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17239 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 41764

Start Time: 01cfc6ccca0b2383

Termination Time: 52

Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Report Id: 61fc69fd-32ca-11e4-8262-54271e5be0f6

Faulting package full name:

Faulting package-relative application ID:

System errors:
=============
Error: (09/05/2014 09:28:10 PM) (Source: DCOM) (EventID: 10010) (User: KenPC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (09/05/2014 09:27:40 PM) (Source: DCOM) (EventID: 10010) (User: KenPC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (09/05/2014 09:13:37 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Superfetch service terminated with the following error:
%%1062

Error: (09/04/2014 07:52:31 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 32212256841145152

Error: (09/04/2014 07:52:47 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 9:12:08 PM on ‎9/‎3/‎2014 was unexpected.

Error: (09/03/2014 07:39:57 PM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 32212256841144480

Error: (09/03/2014 07:40:16 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:52:55 PM on ‎9/‎3/‎2014 was unexpected.

Error: (09/03/2014 08:37:18 AM) (Source: DCOM) (EventID: 10010) (User: KenPC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (09/03/2014 08:36:48 AM) (Source: DCOM) (EventID: 10010) (User: KenPC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (09/02/2014 09:49:53 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Microsoft Office Sessions:
=========================
Error: (09/04/2014 08:08:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: FrameworkEngine.exe1.1.0.053880a5fntdll.dll6.3.9600.1711453648f36c00000050003f92de1c01cfc8a5dd172771C:\Program Files (x86)\Browse Safe\FrameworkEngine.exeC:\Windows\SYSTEM32\ntdll.dll1bf4e044-3499-11e4-8265-54271e5be0f6

Error: (09/04/2014 07:55:11 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (09/03/2014 08:11:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nsg9F28.tmp0.0.0.02a425e19unknown0.0.0.000000000c0000005777d8a5d194801cfc7dd1f191db1C:\Users\knemlick\AppData\Local\Temp\nsg9F28.tmpunknown67a6cf6b-33d0-11e4-8264-54271e5be0f6

Error: (09/03/2014 05:54:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: nspD65D.tmp0.0.0.0123801cfc7c9f022723c4294967295C:\Users\knemlick\AppData\Local\Temp\nspD65D.tmp3a80a52d-33bd-11e4-8263-54271e5be0f6

Error: (09/03/2014 05:54:15 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (09/03/2014 01:55:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.1723952c4801cfc7a81988495c31C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEdb491013-339b-11e4-8262-54271e5be0f6

Error: (09/03/2014 01:53:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17239501dc01cfc7a8131bdcc162C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEa11ef6b1-339b-11e4-8262-54271e5be0f6

Error: (09/02/2014 01:00:08 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.172393306001cfc6d752eaeab532C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEf76eee98-32ca-11e4-8262-54271e5be0f6

Error: (09/02/2014 00:57:12 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.1723932bf401cfc6d72651b4ec31C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE8ea78ba4-32ca-11e4-8262-54271e5be0f6

Error: (09/02/2014 00:55:57 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.172394176401cfc6ccca0b238352C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE61fc69fd-32ca-11e4-8262-54271e5be0f6

==================== Memory info ===========================

Processor: AMD A10-6700 APU with Radeon™ HD Graphics
Percentage of memory in use: 23%
Total physical RAM: 7367.27 MB
Available physical RAM: 5599.48 MB
Total Pagefile: 8519.27 MB
Available Pagefile: 6435.86 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:916.66 GB) (Free:849.66 GB) NTFS
Drive d: (USB DISK) (Removable) (Total:7.46 GB) (Free:6.77 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: AB9D20B2)

Partition: GPT Partition Type.

========================================================
Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End Of Log ============================



#4 olgun52

olgun52

  • Malware Response Team
  • 3,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:54 AM

Posted 06 September 2014 - 05:36 AM

Thanks riley45,

 

I Would like you to do the following. Please.

 

 

Step1:

Please download AdwCleaner by Xplode onto your desktop.

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search, then Clean.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Step2:

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

 

Step3:

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

Please download Rkill by Grinler and save it to your desktop.

  • Link 1
    Link 2
    Link 3
  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7, right-click on it and Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • If the tool does not run from any of the links provided, please let me know.
  • If your antivirus program gives a prompt message, respond positive to allow RKILL to run.
  • If a malware-rogue gives a message regarding RKILL, proceed forward to running RKILL

IF you still have a problem running RKILL, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.

When all done, rkill.txt log file will be on your desktop. Copy & Paste contents of Rkill.txt into a new reply.

More Information about Rkill can be found at this link: http://www.bleepingc...opic308364.html

 

Last...

 

Step4:

Scan with Malwarebytes Antimalware:

Please download Malwarebytes Anti-Malware to your desktop.

  • Double-click the downloaded setup file and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
  • Launch Malwarebytes Anti-Malware
  • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply

Thanks

 


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#5 riley45

riley45
  • Topic Starter

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 06 September 2014 - 01:02 PM

Here are the logs from the AdwCleaner and Junkware Removal Tool:

 

# AdwCleaner v3.309 - Report created 06/09/2014 at 13:08:03

# Updated 02/09/2014 by Xplode

# Operating System : Windows 8.1 (64 bits)

# Username : knemlick - KENPC

# Running from : C:\Users\knemlick\Desktop\adwcleaner_3.309.exe

# Option : Clean

***** [ Services ] *****

Service Deleted : BackupStack

Service Deleted : LPTSystemUpdater

Service Deleted : servervo

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\smdmf

Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freesofttoday

Folder Deleted : C:\Program Files (x86)\Bench

Folder Deleted : C:\Program Files (x86)\Browse Safe

Folder Deleted : C:\Program Files (x86)\globalUpdate

Folder Deleted : C:\Program Files (x86)\LPT

Folder Deleted : C:\Program Files (x86)\MyPC Backup

Folder Deleted : C:\Program Files (x86)\Settings Manager

Folder Deleted : C:\Program Files (x86)\fst_us_239

Folder Deleted : C:\Users\knemlick\AppData\Local\BenchUpdater

Folder Deleted : C:\Users\knemlick\AppData\Local\Browse Safe

Folder Deleted : C:\Users\knemlick\AppData\Local\globalUpdate

Folder Deleted : C:\Users\knemlick\AppData\Local\Local_Weather_LLC

Folder Deleted : C:\Users\knemlick\AppData\Local\LPT

Folder Deleted : C:\Users\knemlick\AppData\Local\Smartbar

Folder Deleted : C:\Users\knemlick\AppData\Local\WeatherAlerts

Folder Deleted : C:\Users\knemlick\AppData\Local\fst_us_239

Folder Deleted : C:\Users\knemlick\AppData\Local\Temp\Smartbar

Folder Deleted : C:\Users\knemlick\AppData\LocalLow\Smartbar

Folder Deleted : C:\Users\knemlick\AppData\Roaming\VOPackage

Folder Deleted : C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browse Safe

Folder Deleted : C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup

Folder Deleted : C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage

Folder Deleted : C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Alerts

File Deleted : C:\END

File Deleted : C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopWeatherAlerts.lnk

File Deleted : C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk

File Deleted : C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Weather Alerts.lnk

File Deleted : C:\Users\knemlick\Desktop\Continue Live Installation.lnk

***** [ Scheduled Tasks ] *****

Task Deleted : bench-sys

Task Deleted : LaunchSignup

Task Deleted : bench-S-1-5-21-3351969478-1937094124-811777867-1002

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\knemlick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk

***** [ Registry ] *****

Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]

Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute

Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.bho

Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel

Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar

Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject

Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate

Key Deleted : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform

Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc

Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.bench.nmhost

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\DesktopWeatherAlertsApp_RASAPI32

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\DesktopWeatherAlertsApp_RASMANCS

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32

Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Bench Communicator Watcher]

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Bench Settings Cleaner]

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [BService]

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Wd]

Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]

Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]

Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [fst_us_239]

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2B47855E-B429-4DF6-8293-E1DBF2381A07}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8E56A02B-46FE-4490-B169-F16E5231533B}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E56A02B-46FE-4490-B169-F16E5231533B}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E56A02B-46FE-4490-B169-F16E5231533B}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E56A02B-46FE-4490-B169-F16E5231533B}

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}

Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}

Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{2B47855E-B429-4DF6-8293-E1DBF2381A07}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{8E56A02B-46FE-4490-B169-F16E5231533B}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}

Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E56A02B-46FE-4490-B169-F16E5231533B}

Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

Key Deleted : HKCU\Software\Compete

Key Deleted : HKCU\Software\FreeSoftToday

Key Deleted : HKCU\Software\GlobalUpdate

Key Deleted : HKCU\Software\Proxy

Key Deleted : HKCU\Software\SmartBar

Key Deleted : HKCU\Software\smartbarbackup

Key Deleted : HKCU\Software\smartbarlog

Key Deleted : HKCU\Software\SmdmF

Key Deleted : HKCU\Software\Tutorials

Key Deleted : HKCU\Software\TutoTag

Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider

Key Deleted : HKLM\SOFTWARE\AdvertisingSupport

Key Deleted : HKLM\SOFTWARE\Bench

Key Deleted : HKLM\SOFTWARE\FreeSoftToday

Key Deleted : HKLM\SOFTWARE\GlobalUpdate

Key Deleted : HKLM\SOFTWARE\Proxy

Key Deleted : HKLM\SOFTWARE\SmdmF

Key Deleted : HKLM\SOFTWARE\Tutorials

Key Deleted : HKLM\SOFTWARE\Uniblue

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DesktopWeatherAlerts

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\fst_us_239_is1

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467

Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17239

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

*************************

AdwCleaner[R0].txt - [12620 octets] - [06/09/2014 13:06:40]

AdwCleaner[S0].txt - [10351 octets] - [06/09/2014 13:08:03]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10412 octets] ##########

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 6.1.4 (04.06.2014:1)

OS: Windows 8.1 x64

Ran by knemlick on Sat 09/06/2014 at 13:14:47.79

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

~~~ Services

 

 

~~~ Registry Values

 

 

~~~ Registry Keys

 

 

~~~ Files

 

 

~~~ Folders

 

 

~~~ Event Viewer Logs were cleared

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Sat 09/06/2014 at 13:18:42.87

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



#6 riley45

riley45
  • Topic Starter

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 06 September 2014 - 01:10 PM

Here are the logs from the Rkill and Malwarebytes scans.  As I point of information, I can now connect to the internet on my PC, but I still have the Snap.Do browser.

 

Rkill 2.6.8 by Lawrence Abrams (Grinler)

http://www.bleepingcomputer.com/

Copyright 2008-2014 BleepingComputer.com

More Information about Rkill can be found at this link:

http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 09/06/2014 01:21:58 PM in x64 mode.

Windows Version: Windows 8.1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* Windows Defender Disabled

[HKLM\SOFTWARE\Microsoft\Windows Defender]

"DisableAntiSpyware" = dword:00000001

Checking Windows Service Integrity:

* MsKeyboardFilter [Missing Service]

* CSC [Missing Service]

* E1G60 [Missing Service]

* kbldfltr [Missing Service]

* storvsp [Missing Service]

* Vid [Missing Service]

* vmbusr [Missing Service]

* vpcivsp [Missing Service]

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 09/06/2014 01:22:40 PM

Execution time: 0 hours(s), 0 minute(s), and 41 seconds(s)

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 9/6/2014
Scan Time: 1:29:45 PM
Logfile:
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.03.04.09
Rootkit Database: v2014.02.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: knemlick

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 230671
Time Elapsed: 9 min, 0 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 4
PUP.Optional.SpeedUpMyPC, C:\Users\knemlick\AppData\Local\Temp\6921tmp\speedupmypc.exe, Quarantined, [75d4ef10fe7cef47796e316f60a10ef2],
PUP.Optional.WeatherAlerts.A, C:\Users\knemlick\AppData\Local\Temp\6927tmp\desktopweatheralertssetup.exe, Quarantined, [e6631ee16416c6704ad7c493986cc838],
PUP.Optional.SpeedUpMyPC, C:\Users\knemlick\AppData\Local\Temp\is-K5KDQ.tmp\SpeedUpMyPC-standalone-setup.exe, Quarantined, [d970b9463c3e93a34d9a425e15ec28d8],
PUP.Optional.SmartBar.A, C:\Windows\Installer\1ed1e0e9.msi, Quarantined, [d97027d8601a3afc912d6114d927a65a],

Physical Sectors: 0
(No malicious items detected)

(end)



#7 olgun52

olgun52

  • Malware Response Team
  • 3,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:54 AM

Posted 06 September 2014 - 02:19 PM

Hi riley45,

 

Please run the following;

 

Step 1:

Run Eset Online Scan

Please run this online scan to help look for remnants. Ensure your external and/or USB drives are inserted during the scan.

In Microsoft Windows Vista/Win7, you must open the Web browser via a right-click using the Run as Administrator command.

Please go to here to run the online scannner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option "Scan Archives" and Remove found threats is ticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file....
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.

And please now PC restart

 

Step 2:

 

Please post a fresh FRST logfile for my review.

 

Regards.

 


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#8 riley45

riley45
  • Topic Starter

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 06 September 2014 - 03:17 PM

I attempted to run the ESET scan.  After accessing the link to the ESET website and checking the box indicating that I accept the terms of use, I clicked the Start button.  Instead of the scan starting at this point, I was taken to the following blank page

 

http://www.eset.com/us/online-scanner-popup/

 

It appears that the malware on my computer is preventing me from running this scan.

 

Is there an alternate way for me to access and run the ESET scan that would bypass this problem?

 

Please advise. 



#9 olgun52

olgun52

  • Malware Response Team
  • 3,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:54 AM

Posted 06 September 2014 - 03:29 PM

Please try again with Internet Explorer  browser.


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#10 riley45

riley45
  • Topic Starter

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 06 September 2014 - 03:58 PM

I cannot do this, as my real Internet Explorer browser was either deleted or replaced by the virus.  The current browser on my PC is called Internet Explorer, but it does not look like or behave like the real Internet Explorer. 



#11 olgun52

olgun52

  • Malware Response Team
  • 3,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:54 AM

Posted 06 September 2014 - 04:14 PM

I cannot do this, as my real Internet Explorer browser was either deleted or replaced by the virus.  The current browser on my PC is called Internet Explorer, but it does not look like or behave like the real Internet Explorer. 

 

Do you have run the browser as an administrator ?


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#12 riley45

riley45
  • Topic Starter

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 06 September 2014 - 04:22 PM

I am the administrator on this PC, so I do not think that that is the problem.

#13 olgun52

olgun52

  • Malware Response Team
  • 3,807 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:54 AM

Posted 06 September 2014 - 04:37 PM

Transactions should be done as an administrator. otherwise it may fail.

 

-------------

 

Please do the following

 

Run HitmanPro:

Please download HitmanPro 32-Bit version // 64-Bit version.

  • Launch the program by double clicking on the Hitmanicon_zpsda033e21.jpg icon. (Windows Vista/7 users right click on the HitmanPro icon and select run as administrator).
  • Click on the next button. You must agree with the terms of EULA.
  • Check the box beside "No, I only want to perform a one-time scan to check this computer".
  • Click on the next button.
  • The program will start to scan the computer. The scan will typically take no more than 2-3 minutes.
  • When the scan is done click on drop-down menu of the found entries (if any) and choose - Apply to all => Ignore <= IMPORTANT!
  • Click on the next button.
  • Click on the "Export scan results to XML file".
  • Save that file to your desktop and zip and attach it in your next reply.

 

Regards.


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#14 riley45

riley45
  • Topic Starter

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 06 September 2014 - 04:58 PM

Attached are the results of the HitmanPro scan.

 

 


Attached are the results of the HitmanPro scan.

Attached Files



#15 riley45

riley45
  • Topic Starter

  • Members
  • 154 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:54 PM

Posted 06 September 2014 - 06:45 PM

Attached are the results of the HitmanPro scan saved as a zipped XML file.

Attached Files






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users