Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Previous crypto infection


  • This topic is locked This topic is locked
51 replies to this topic

#1 bellagirl

bellagirl

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 12 December 2014 - 04:50 PM

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 11.0.9600.17420
Run by debbie at 8:10:13 on 2014-12-13
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.61.1033.18.4044.1411 [GMT 11:00]
.
AV: AVG AntiVirus Free Edition 2015 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2015 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
C:\Windows\system32\rundll32.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\wscript.exe
C:\Windows\SysWow64\cscript.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\HPDownload.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{CABDE4F5-8A57-48D9-B63E-4BA4DFAED174} : DHCPNameServer = 192.168.2.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2014-6-18 190744]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2014-7-18 313624]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2014-10-5 124184]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2014-6-18 31512]
R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2014-6-18 153368]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2014-10-29 263960]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2014-8-28 243480]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2014-10-10 274200]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-6-25 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-6-25 203776]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2014-11-9 3488784]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2014-11-9 298080]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-2-18 265544]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-1 92216]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-1-27 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-10 26680]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-6-25 13336]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-6-26 523944]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-6-25 2656280]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-29 31088]
R3 hpCMSrv;HP Connection Manager 4.0 Service;C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-2-16 1071160]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-6-25 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-6-25 12273408]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-12-11 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-12-11 181248]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-6-25 333928]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-25 428136]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-6-26 207528]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-2-17 42392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-1-24 58128]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-1-24 274944]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072]
S3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-1-24 59904]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-12-3 114688]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-2-5 340240]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-12-3 1255736]
S4 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-1-25 901184]
S4 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-1-25 1298496]
S4 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-1-25 991296]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2014-12-12 00:06:11 -------- d-----w- C:\Users\debbie\AppData\Local\{EE5C689F-B943-4055-AB93-60209DE73A16}
2014-12-12 00:06:11 -------- d-----w- C:\Users\debbie\AppData\Local\{0FB2EC8F-25F7-47AF-847C-768D717462D6}
2014-12-09 23:36:45 -------- d-----w- C:\Windows\System32\appraiser
2014-12-09 22:44:46 55808 ----a-w- C:\Windows\System32\rrinstaller.exe
2014-12-09 22:44:46 50176 ----a-w- C:\Windows\SysWow64\rrinstaller.exe
2014-12-09 22:44:46 24576 ----a-w- C:\Windows\System32\mfpmp.exe
2014-12-09 22:44:46 23040 ----a-w- C:\Windows\SysWow64\mfpmp.exe
2014-12-09 22:44:46 2048 ----a-w- C:\Windows\SysWow64\mferror.dll
2014-12-09 22:44:46 2048 ----a-w- C:\Windows\System32\mferror.dll
2014-12-09 22:44:45 4121600 ----a-w- C:\Windows\System32\mf.dll
2014-12-09 22:44:45 3209728 ----a-w- C:\Windows\SysWow64\mf.dll
2014-12-09 22:44:45 206848 ----a-w- C:\Windows\System32\mfps.dll
2014-12-09 22:44:45 103424 ----a-w- C:\Windows\SysWow64\mfps.dll
2014-12-09 21:06:37 -------- d-sh--w- C:\$RECYCLE.BIN
2014-12-09 20:55:40 98816 ----a-w- C:\Windows\sed.exe
2014-12-09 20:55:40 256000 ----a-w- C:\Windows\PEV.exe
2014-12-09 20:55:40 208896 ----a-w- C:\Windows\MBR.exe
2014-12-09 20:13:25 830976 ----a-w- C:\Windows\System32\appraiser.dll
2014-12-09 20:13:25 192000 ----a-w- C:\Windows\System32\aepic.dll
2014-12-09 20:13:25 1232040 ----a-w- C:\Windows\System32\aitstatic.exe
2014-12-09 20:13:25 1083392 ----a-w- C:\Windows\System32\aeinv.dll
2014-12-09 20:13:24 741376 ----a-w- C:\Windows\System32\invagent.dll
2014-12-09 20:13:24 413184 ----a-w- C:\Windows\System32\generaltel.dll
2014-12-09 20:13:24 396800 ----a-w- C:\Windows\System32\devinv.dll
2014-12-09 20:13:23 227328 ----a-w- C:\Windows\System32\aepdu.dll
2014-12-09 20:11:38 187904 ----a-w- C:\Windows\System32\cryptsvc.dll
2014-12-09 20:11:38 1480192 ----a-w- C:\Windows\System32\crypt32.dll
2014-12-09 20:11:38 143872 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2014-12-09 20:11:38 1174528 ----a-w- C:\Windows\SysWow64\crypt32.dll
2014-12-09 20:06:30 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-12-09 20:06:30 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-12-09 20:06:19 119296 ----a-w- C:\Windows\System32\drivers\tdx.sys
2014-12-09 20:00:07 165888 ----a-w- C:\Windows\System32\charmap.exe
2014-12-09 20:00:07 155136 ----a-w- C:\Windows\SysWow64\charmap.exe
2014-12-09 20:00:03 346624 ----a-w- C:\Windows\System32\WSManMigrationPlugin.dll
2014-12-09 20:00:03 310272 ----a-w- C:\Windows\System32\WsmWmiPl.dll
2014-12-09 20:00:03 266240 ----a-w- C:\Windows\System32\WSManHTTPConfig.exe
2014-12-09 20:00:03 248832 ----a-w- C:\Windows\SysWow64\WSManMigrationPlugin.dll
2014-12-09 20:00:03 214016 ----a-w- C:\Windows\SysWow64\WsmWmiPl.dll
2014-12-09 20:00:03 2020352 ----a-w- C:\Windows\System32\WsmSvc.dll
2014-12-09 20:00:03 198656 ----a-w- C:\Windows\SysWow64\WSManHTTPConfig.exe
2014-12-09 20:00:03 181248 ----a-w- C:\Windows\System32\WsmAuto.dll
2014-12-09 20:00:03 145920 ----a-w- C:\Windows\SysWow64\WsmAuto.dll
2014-12-09 20:00:03 1177088 ----a-w- C:\Windows\SysWow64\WsmSvc.dll
2014-12-09 19:59:51 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-12-09 19:59:51 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-12-09 09:56:25 -------- d-----w- C:\Users\debbie\AppData\Local\Adobe
2014-12-09 09:50:03 -------- d--h--w- C:\ProgramData\CanonIJScan
2014-12-08 12:51:06 -------- d-----w- C:\Users\debbie\AppData\Local\Diagnostics
2014-12-08 07:39:26 -------- d-----w- C:\Users\debbie\AppData\Roaming\IDT
2014-12-08 00:08:25 -------- d-sh--w- C:\Users\debbie\AppData\Local\EmieUserList
2014-12-08 00:08:25 -------- d-sh--w- C:\Users\debbie\AppData\Local\EmieSiteList
2014-12-08 00:08:25 -------- d-sh--w- C:\Users\debbie\AppData\Local\EmieBrowserModeList
2014-12-03 00:36:31 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2014-12-03 00:36:31 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2014-12-02 23:35:29 2871808 ----a-w- C:\Windows\explorer.exe
2014-12-02 23:35:29 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2014-12-02 23:19:17 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2014-12-02 23:19:17 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2014-12-02 23:14:07 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2014-12-02 23:14:07 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2014-12-02 23:12:43 7168 ----a-w- C:\Windows\SysWow64\KBDYAK.DLL
2014-12-02 23:12:43 7168 ----a-w- C:\Windows\System32\KBDYAK.DLL
2014-12-02 23:12:43 7168 ----a-w- C:\Windows\System32\KBDBASH.DLL
2014-12-02 23:12:43 6656 ----a-w- C:\Windows\SysWow64\KBDBASH.DLL
2014-12-02 23:12:32 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-12-02 21:48:55 3928064 ----a-w- C:\Windows\System32\d2d1.dll
2014-12-02 21:48:55 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll
2014-12-02 20:54:44 -------- d-----w- C:\Windows\Migration
2014-12-02 20:34:25 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-02 20:26:24 -------- d-----w- C:\Windows\System32\MRT
2014-12-02 20:23:29 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2014-12-02 20:23:29 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2014-12-02 20:23:29 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2014-12-02 20:23:29 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2014-12-02 20:23:27 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2014-12-02 20:23:27 8856 ----a-w- C:\Windows\System32\icardres.dll
2014-12-02 20:23:11 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2014-12-02 20:23:11 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2014-12-02 19:36:54 3722240 ----a-w- C:\Windows\System32\mstscax.dll
2014-12-02 19:36:54 3221504 ----a-w- C:\Windows\SysWow64\mstscax.dll
2014-12-02 19:36:52 455168 ----a-w- C:\Windows\System32\winlogon.exe
2014-12-02 19:36:52 235520 ----a-w- C:\Windows\System32\winsta.dll
2014-12-02 19:36:52 212480 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2014-12-02 19:36:52 157696 ----a-w- C:\Windows\SysWow64\winsta.dll
2014-12-02 19:36:52 150528 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2014-12-02 19:36:52 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2014-12-02 19:36:52 1118720 ----a-w- C:\Windows\System32\mstsc.exe
2014-12-02 19:36:52 1051136 ----a-w- C:\Windows\SysWow64\mstsc.exe
2014-12-02 19:36:51 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
2014-12-02 19:32:54 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2014-12-02 19:32:54 52224 ----a-w- C:\Windows\System32\certenc.dll
2014-12-02 19:32:54 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2014-12-02 19:32:54 1192448 ----a-w- C:\Windows\System32\certutil.exe
2014-12-02 19:31:11 793600 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-12-02 19:31:11 1031168 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-12-02 19:31:05 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2014-12-02 19:31:05 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2014-12-02 19:13:04 -------- d-----w- C:\Windows\SysWow64\Wat
2014-12-02 19:13:03 -------- d-----w- C:\Windows\System32\Wat
2014-12-02 09:28:28 -------- d-----w- C:\Users\debbie\AppData\Local\Microsoft Help
2014-12-02 07:59:27 -------- d-s---w- C:\Windows\System32\CompatTel
2014-12-02 06:59:07 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-12-02 06:59:07 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-12-02 06:59:06 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-12-02 06:59:06 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-12-02 04:12:18 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2014-12-02 03:42:32 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2014-12-02 03:42:32 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2014-12-02 03:42:31 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2014-12-02 03:42:31 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2014-12-02 03:42:31 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2014-12-02 03:42:31 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2014-12-02 03:42:30 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2014-12-02 03:36:40 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2014-12-02 03:36:40 5120 ----a-w- C:\Windows\System32\wmi.dll
2014-12-02 03:36:40 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2014-12-02 03:07:27 658432 ----a-w- C:\Windows\System32\RMActivate_isv.exe
2014-12-02 02:58:30 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-12-02 02:57:37 683520 ----a-w- C:\Windows\System32\termsrv.dll
2014-12-02 02:57:37 681984 ----a-w- C:\Windows\SysWow64\adtschema.dll
2014-12-02 02:57:37 681984 ----a-w- C:\Windows\System32\adtschema.dll
2014-12-02 02:57:36 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2014-12-02 02:57:36 146432 ----a-w- C:\Windows\System32\msaudite.dll
2014-12-02 02:55:47 878080 ----a-w- C:\Windows\System32\advapi32.dll
2014-12-02 02:55:47 859648 ----a-w- C:\Windows\System32\tdh.dll
2014-12-02 02:55:47 640512 ----a-w- C:\Windows\SysWow64\advapi32.dll
2014-12-02 02:55:47 619520 ----a-w- C:\Windows\SysWow64\tdh.dll
2014-12-02 02:55:47 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2014-12-02 02:55:47 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2014-12-02 02:55:02 1354240 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2014-12-02 02:55:01 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-12-02 02:54:06 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2014-12-02 02:52:22 46592 ----a-w- C:\Windows\SysWow64\fpb.rs
2014-12-02 02:51:54 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll
2014-12-02 02:51:54 44032 ----a-w- C:\Windows\SysWow64\dhcpcsvc6.dll
2014-12-02 02:51:54 226816 ----a-w- C:\Windows\System32\dhcpcore6.dll
2014-12-02 02:51:54 193536 ----a-w- C:\Windows\SysWow64\dhcpcore6.dll
2014-12-02 02:51:50 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2014-12-02 02:51:50 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2014-12-02 02:51:14 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2014-12-02 02:51:14 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2014-12-02 02:51:14 1118720 ----a-w- C:\Windows\System32\sbe.dll
2014-12-02 02:51:13 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
2014-12-02 02:51:13 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2014-12-02 02:51:13 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2014-12-02 02:50:56 327168 ----a-w- C:\Windows\System32\mswsock.dll
2014-12-02 02:50:56 231424 ----a-w- C:\Windows\SysWow64\mswsock.dll
2014-12-02 02:50:45 1684928 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-12-02 02:48:48 3198976 ----a-w- C:\Windows\System32\win32k.sys
2014-12-02 02:48:43 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2014-12-02 02:48:43 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2014-12-02 02:48:22 449024 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-12-02 02:48:21 692736 ----a-w- C:\Windows\System32\osk.exe
2014-12-02 02:48:21 646144 ----a-w- C:\Windows\SysWow64\osk.exe
2014-12-02 02:48:04 404480 ----a-w- C:\Windows\System32\gdi32.dll
2014-12-02 02:48:03 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2014-12-02 02:46:45 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2014-12-02 02:45:49 27584 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-12-02 02:44:54 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2014-12-02 02:43:54 155584 ----a-w- C:\Windows\System32\drivers\ataport.sys
2014-12-02 02:42:58 9216 ----a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll
2014-12-02 02:41:50 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2014-12-02 02:40:58 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2014-12-02 02:40:58 31232 ----a-w- C:\Windows\System32\prevhost.exe
2014-12-02 00:50:07 -------- d-----w- C:\Users\debbie\AppData\Local\{B1323411-70A2-4BB9-80EB-DD9D355984B3}
2014-12-02 00:46:27 -------- d--h--w- C:\ProgramData\CanonIJEPPEX2
2014-12-02 00:46:27 -------- d--h--w- C:\ProgramData\CanonEPP
2014-12-02 00:46:05 -------- d-----w- C:\ProgramData\Canon IJ Network Tool
2014-12-02 00:45:59 307200 ----a-w- C:\Windows\SysWow64\CNC495L.dll
2014-12-02 00:45:59 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2014-12-02 00:45:59 106496 ----a-w- C:\Windows\SysWow64\CNC495U.dll
2014-12-02 00:45:20 -------- d-----w- C:\ProgramData\CanonIJMSetup
2014-12-02 00:45:04 -------- d-----w- C:\Program Files\Common Files\CANON
2014-12-02 00:44:56 -------- d-----w- C:\ProgramData\CanonIJWSpt
2014-12-02 00:43:29 -------- d-----w- C:\Program Files\Canon
2014-12-02 00:42:46 87040 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPA9.DLL
2014-12-02 00:42:46 28672 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDA9.DLL
2014-12-02 00:42:18 361472 ----a-w- C:\Windows\System32\CNMLMA9.DLL
2014-12-02 00:42:07 248320 ----a-w- C:\Windows\System32\CNMIUA9.DLL
2014-12-02 00:41:48 37376 ----a-w- C:\Windows\System32\CNMN6UI.DLL
2014-12-02 00:41:48 327680 ----a-w- C:\Windows\System32\CNMN6PPM.DLL
2014-12-02 00:41:48 -------- d-----w- C:\Windows\System32\STRING
2014-12-02 00:41:07 -------- d-----w- C:\Program Files (x86)\Canon
2014-12-02 00:20:37 -------- d-----w- C:\Users\debbie\AppData\Roaming\SoftGrid Client
2014-12-02 00:20:37 -------- d-----w- C:\Users\debbie\AppData\Local\SoftGrid Client
2014-12-02 00:19:57 -------- d-----w- C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-12-02 00:19:46 -------- d-----w- C:\Users\debbie\AppData\Roaming\TP
2014-12-01 23:43:17 -------- d-----w- C:\Users\debbie\AppData\Local\Google
2014-12-01 23:42:39 -------- d-----w- C:\Users\debbie\AppData\Local\Deployment
2014-12-01 23:42:39 -------- d-----w- C:\Users\debbie\AppData\Local\Apps
2014-12-01 22:56:33 -------- d-----w- C:\Users\debbie\AppData\Roaming\AVG2015
2014-12-01 22:55:46 -------- d-----w- C:\Users\debbie\AppData\Roaming\TuneUp Software
2014-12-01 22:55:33 -------- d-----w- C:\$AVG
2014-12-01 22:55:32 -------- d-----w- C:\ProgramData\AVG2015
2014-12-01 22:54:56 -------- d-----w- C:\Program Files (x86)\AVG
2014-12-01 22:36:57 -------- d--h--w- C:\ProgramData\Common Files
2014-12-01 22:36:57 -------- d-----w- C:\Users\debbie\AppData\Local\MFAData
2014-12-01 22:36:57 -------- d-----w- C:\Users\debbie\AppData\Local\Avg2015
2014-12-01 22:36:57 -------- d-----w- C:\ProgramData\MFAData
2014-12-01 22:27:19 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2014-12-01 22:27:19 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2014-12-01 22:27:19 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2014-12-01 22:15:52 -------- d-----w- C:\Users\debbie\AppData\Local\ATI
2014-12-01 22:14:52 -------- d-----w- C:\Users\debbie\AppData\Roaming\Intel Corporation
2014-12-01 22:14:51 -------- d-----w- C:\Users\debbie\AppData\Roaming\hpqLog
2014-12-01 22:14:50 -------- d-----w- C:\Users\debbie\AppData\Roaming\Synaptics
2014-12-01 22:14:01 -------- d-----w- C:\Users\debbie\AppData\Local\RemEngine
2014-12-01 22:09:54 36864 ----a-w- C:\Windows\System32\wuapp.exe
2014-12-01 22:09:54 33792 ----a-w- C:\Windows\SysWow64\wuapp.exe
2014-12-01 22:09:54 198600 ----a-w- C:\Windows\System32\wuwebv.dll
2014-12-01 22:09:54 179656 ----a-w- C:\Windows\SysWow64\wuwebv.dll
.
==================== Find3M  ====================
.
2014-12-02 20:34:25 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-11-11 03:08:52 241152 ----a-w- C:\Windows\System32\pku2u.dll
2014-11-11 02:44:32 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll
2014-11-11 02:44:25 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-10-29 10:35:16 263960 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
2014-10-25 01:57:59 77824 ----a-w- C:\Windows\System32\packager.dll
2014-10-25 01:32:37 67584 ----a-w- C:\Windows\SysWow64\packager.dll
2014-10-18 02:05:23 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2014-10-18 01:33:18 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2014-10-14 02:16:37 155064 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-10-14 02:13:00 3241984 ----a-w- C:\Windows\System32\msi.dll
2014-10-14 02:12:57 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-10-14 01:50:47 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-10-14 01:50:41 2363904 ----a-w- C:\Windows\SysWow64\msi.dll
2014-10-14 01:49:38 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-10-10 03:14:32 274200 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2014-10-05 09:41:40 124184 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
2014-10-03 02:12:00 500224 ----a-w- C:\Windows\System32\AUDIOKSE.dll
2014-10-03 02:11:54 284672 ----a-w- C:\Windows\System32\EncDump.dll
2014-10-03 02:11:51 680960 ----a-w- C:\Windows\System32\audiosrv.dll
2014-10-03 02:11:51 440832 ----a-w- C:\Windows\System32\AudioEng.dll
2014-10-03 02:11:51 296448 ----a-w- C:\Windows\System32\AudioSes.dll
2014-10-03 01:44:42 442880 ----a-w- C:\Windows\SysWow64\AUDIOKSE.dll
2014-10-03 01:44:26 374784 ----a-w- C:\Windows\SysWow64\AudioEng.dll
2014-10-03 01:44:26 195584 ----a-w- C:\Windows\SysWow64\AudioSes.dll
2014-09-25 02:08:38 371712 ----a-w- C:\Windows\System32\qdvd.dll
2014-09-25 01:40:50 519680 ----a-w- C:\Windows\SysWow64\qdvd.dll
2014-09-19 09:42:52 210944 ----a-w- C:\Windows\System32\wdigest.dll
2014-09-19 09:42:51 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2014-09-19 09:42:49 342016 ----a-w- C:\Windows\System32\schannel.dll
2014-09-19 09:42:47 314880 ----a-w- C:\Windows\System32\msv1_0.dll
2014-09-19 09:42:47 309760 ----a-w- C:\Windows\System32\ncrypt.dll
2014-09-19 09:42:41 22016 ----a-w- C:\Windows\System32\credssp.dll
2014-09-19 09:23:55 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll
2014-09-19 09:23:52 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2014-09-19 09:23:49 248832 ----a-w- C:\Windows\SysWow64\schannel.dll
2014-09-19 09:23:46 221184 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2014-09-19 09:23:45 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2014-09-19 09:23:36 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
.
============= FINISH:  8:11:18.08 ===============
 
 
I previously had the crypto infection.  I didnt pay the ransom.  I instead did a factory reset and re installed the files i needed from a backup.
 
Everything seems to be working ok except it takes a long time to start up and occasionally i cant access the internet and i get DNS_PROBE_FINISHED_NO_INTERNET
 
I didnt  read the clear instructions and i downloaded combofix.  It never saved to my desktop like it said it would but instead i can go to search and enter combofix in the box and find it.  Also following the instructions for this it went straight from when i clicked to download the DDS it also went straight to the settings screen without having to save and run ect.
 
thanks in advance for all your help.Attached File  attach.txt   7.24KB   0 downloads

Attached Files



BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:04 AM

Posted 17 December 2014 - 04:55 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/559636 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 17 December 2014 - 05:22 PM

Yes i still need help.

 

My laptop came already pre loaded with windows 7 so i dont have an installation c.d

 

My problem is that i had the cryptovirus a few months ago.  i did a factory reset with hp support assistant.  all the software that was preloaded...re loaded and then it updated all the windows etc.

Since then i find that sometimes i have trouble with internet connection...pages not opening and not connecting to the internet.  I hasnt been to bad the last couple of days though.

I only use avg2015 free edition.  

Basically i would like to know the following

* Can you see if i have any malware or viruses

*should i be using some other checkers like adware or anything else ???

* are there too many programs on startup and often when i shut down it usually comes up with "waiting for program to shut down" when i have closed all windows etc.

Thanks for you help

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 11.0.9600.17496
Run by debbie at 9:04:28 on 2014-12-18
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.61.1033.18.4044.2077 [GMT 11:00]
.
AV: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{CABDE4F5-8A57-48D9-B63E-4BA4DFAED174} : DHCPNameServer = 192.168.2.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
x64-Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
x64-RunOnce: [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2014-6-18 190744]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2014-7-18 313624]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2014-10-5 124184]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2014-6-18 31512]
R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2014-6-18 153368]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2014-10-29 263960]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2014-8-28 243480]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2014-10-10 274200]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-6-25 89600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-6-25 203776]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2014-11-9 298080]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2013-4-22 822504]
R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-2-18 265544]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-1 92216]
R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2011-1-27 30520]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-10 26680]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-6-25 13336]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2013-6-26 523944]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-6-25 2656280]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-29 31088]
R3 hpCMSrv;HP Connection Manager 4.0 Service;C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-2-16 1071160]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-6-25 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-6-25 12273408]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-12-11 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-12-11 181248]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-6-25 333928]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-25 428136]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2013-6-26 767144]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2013-6-26 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2013-6-26 28840]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2013-6-26 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2013-6-26 207528]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-2-17 42392]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2014-11-9 3488784]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S3 btmaux;Intel Bluetooth Auxiliary Service;C:\Windows\System32\drivers\btmaux.sys [2011-1-24 58128]
S3 btmhsf;btmhsf;C:\Windows\System32\drivers\btmhsf.sys [2011-1-24 274944]
S3 GamesAppIntegrationService;GamesAppIntegrationService;C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2014-11-20 227904]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2014-11-15 259664]
S3 iBtFltCoex;iBtFltCoex;C:\Windows\System32\drivers\iBtFltCoex.sys [2011-1-24 59904]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-12-13 114688]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-2-5 340240]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-12-3 1255736]
S4 Bluetooth Device Monitor;Bluetooth Device Monitor;C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2011-1-25 901184]
S4 Bluetooth Media Service;Bluetooth Media Service;C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2011-1-25 1298496]
S4 Bluetooth OBEX Service;Bluetooth OBEX Service;C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2011-1-25 991296]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2014-12-13 11:44:28 -------- d-----w- C:\Users\debbie\AppData\Roaming\{90140011-0066-0409-0000-0000000FF1CE}
2014-12-13 11:43:34 -------- d-----w- C:\ProgramData\Virtualized Applications
2014-12-13 07:00:51 -------- d-----w- C:\ProgramData\BlueStacks
2014-12-13 07:00:28 -------- d-----w- C:\Users\debbie\AppData\Roaming\WildTangent
2014-12-13 06:53:59 -------- d-----w- C:\Users\debbie\AppData\Local\Microsoft Games
2014-12-12 00:06:11 -------- d-----w- C:\Users\debbie\AppData\Local\{EE5C689F-B943-4055-AB93-60209DE73A16}
2014-12-12 00:06:11 -------- d-----w- C:\Users\debbie\AppData\Local\{0FB2EC8F-25F7-47AF-847C-768D717462D6}
2014-12-09 23:36:45 -------- d-----w- C:\Windows\System32\appraiser
2014-12-09 22:44:46 55808 ----a-w- C:\Windows\System32\rrinstaller.exe
2014-12-09 22:44:46 50176 ----a-w- C:\Windows\SysWow64\rrinstaller.exe
2014-12-09 22:44:46 24576 ----a-w- C:\Windows\System32\mfpmp.exe
2014-12-09 22:44:46 23040 ----a-w- C:\Windows\SysWow64\mfpmp.exe
2014-12-09 22:44:46 2048 ----a-w- C:\Windows\SysWow64\mferror.dll
2014-12-09 22:44:46 2048 ----a-w- C:\Windows\System32\mferror.dll
2014-12-09 22:44:45 4121600 ----a-w- C:\Windows\System32\mf.dll
2014-12-09 22:44:45 3209728 ----a-w- C:\Windows\SysWow64\mf.dll
2014-12-09 22:44:45 206848 ----a-w- C:\Windows\System32\mfps.dll
2014-12-09 22:44:45 103424 ----a-w- C:\Windows\SysWow64\mfps.dll
2014-12-09 21:06:37 -------- d-sh--w- C:\$RECYCLE.BIN
2014-12-09 20:55:40 98816 ----a-w- C:\Windows\sed.exe
2014-12-09 20:55:40 256000 ----a-w- C:\Windows\PEV.exe
2014-12-09 20:55:40 208896 ----a-w- C:\Windows\MBR.exe
2014-12-09 20:13:25 830976 ----a-w- C:\Windows\System32\appraiser.dll
2014-12-09 20:13:25 192000 ----a-w- C:\Windows\System32\aepic.dll
2014-12-09 20:13:25 1232040 ----a-w- C:\Windows\System32\aitstatic.exe
2014-12-09 20:13:25 1083392 ----a-w- C:\Windows\System32\aeinv.dll
2014-12-09 20:13:24 741376 ----a-w- C:\Windows\System32\invagent.dll
2014-12-09 20:13:24 413184 ----a-w- C:\Windows\System32\generaltel.dll
2014-12-09 20:13:24 396800 ----a-w- C:\Windows\System32\devinv.dll
2014-12-09 20:13:23 227328 ----a-w- C:\Windows\System32\aepdu.dll
2014-12-09 20:06:30 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-12-09 20:06:30 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-12-09 20:06:19 119296 ----a-w- C:\Windows\System32\drivers\tdx.sys
2014-12-09 20:00:07 165888 ----a-w- C:\Windows\System32\charmap.exe
2014-12-09 20:00:07 155136 ----a-w- C:\Windows\SysWow64\charmap.exe
2014-12-09 20:00:03 346624 ----a-w- C:\Windows\System32\WSManMigrationPlugin.dll
2014-12-09 20:00:03 310272 ----a-w- C:\Windows\System32\WsmWmiPl.dll
2014-12-09 20:00:03 266240 ----a-w- C:\Windows\System32\WSManHTTPConfig.exe
2014-12-09 20:00:03 248832 ----a-w- C:\Windows\SysWow64\WSManMigrationPlugin.dll
2014-12-09 20:00:03 214016 ----a-w- C:\Windows\SysWow64\WsmWmiPl.dll
2014-12-09 20:00:03 2020352 ----a-w- C:\Windows\System32\WsmSvc.dll
2014-12-09 20:00:03 198656 ----a-w- C:\Windows\SysWow64\WSManHTTPConfig.exe
2014-12-09 20:00:03 181248 ----a-w- C:\Windows\System32\WsmAuto.dll
2014-12-09 20:00:03 145920 ----a-w- C:\Windows\SysWow64\WsmAuto.dll
2014-12-09 20:00:03 1177088 ----a-w- C:\Windows\SysWow64\WsmSvc.dll
2014-12-09 19:59:51 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-12-09 19:59:51 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-12-09 09:56:25 -------- d-----w- C:\Users\debbie\AppData\Local\Adobe
2014-12-09 09:50:03 -------- d--h--w- C:\ProgramData\CanonIJScan
2014-12-08 12:51:06 -------- d-----w- C:\Users\debbie\AppData\Local\Diagnostics
2014-12-08 07:39:26 -------- d-----w- C:\Users\debbie\AppData\Roaming\IDT
2014-12-08 00:08:25 -------- d-sh--w- C:\Users\debbie\AppData\Local\EmieUserList
2014-12-08 00:08:25 -------- d-sh--w- C:\Users\debbie\AppData\Local\EmieSiteList
2014-12-08 00:08:25 -------- d-sh--w- C:\Users\debbie\AppData\Local\EmieBrowserModeList
2014-12-03 00:36:31 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2014-12-03 00:36:31 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2014-12-02 23:35:29 2871808 ----a-w- C:\Windows\explorer.exe
2014-12-02 23:35:29 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2014-12-02 23:19:17 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2014-12-02 23:19:17 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll
2014-12-02 23:14:07 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2014-12-02 23:14:07 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2014-12-02 23:12:43 7168 ----a-w- C:\Windows\SysWow64\KBDYAK.DLL
2014-12-02 23:12:43 7168 ----a-w- C:\Windows\System32\KBDYAK.DLL
2014-12-02 23:12:43 7168 ----a-w- C:\Windows\System32\KBDBASH.DLL
2014-12-02 23:12:43 6656 ----a-w- C:\Windows\SysWow64\KBDBASH.DLL
2014-12-02 21:48:55 3928064 ----a-w- C:\Windows\System32\d2d1.dll
2014-12-02 21:48:55 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll
2014-12-02 20:54:44 -------- d-----w- C:\Windows\Migration
2014-12-02 20:34:25 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-02 20:26:24 -------- d-----w- C:\Windows\System32\MRT
2014-12-02 20:23:29 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2014-12-02 20:23:29 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2014-12-02 20:23:29 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2014-12-02 20:23:29 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2014-12-02 20:23:27 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2014-12-02 20:23:27 8856 ----a-w- C:\Windows\System32\icardres.dll
2014-12-02 20:23:11 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2014-12-02 20:23:11 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2014-12-02 19:36:54 3722240 ----a-w- C:\Windows\System32\mstscax.dll
2014-12-02 19:36:54 3221504 ----a-w- C:\Windows\SysWow64\mstscax.dll
2014-12-02 19:36:52 455168 ----a-w- C:\Windows\System32\winlogon.exe
2014-12-02 19:36:52 235520 ----a-w- C:\Windows\System32\winsta.dll
2014-12-02 19:36:52 212480 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2014-12-02 19:36:52 157696 ----a-w- C:\Windows\SysWow64\winsta.dll
2014-12-02 19:36:52 150528 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2014-12-02 19:36:52 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll
2014-12-02 19:36:52 1118720 ----a-w- C:\Windows\System32\mstsc.exe
2014-12-02 19:36:52 1051136 ----a-w- C:\Windows\SysWow64\mstsc.exe
2014-12-02 19:36:51 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
2014-12-02 19:32:54 903168 ----a-w- C:\Windows\SysWow64\certutil.exe
2014-12-02 19:32:54 52224 ----a-w- C:\Windows\System32\certenc.dll
2014-12-02 19:32:54 43008 ----a-w- C:\Windows\SysWow64\certenc.dll
2014-12-02 19:32:54 1192448 ----a-w- C:\Windows\System32\certutil.exe
2014-12-02 19:31:11 793600 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-12-02 19:31:11 1031168 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-12-02 19:31:05 30720 ----a-w- C:\Windows\System32\cryptdlg.dll
2014-12-02 19:31:05 24576 ----a-w- C:\Windows\SysWow64\cryptdlg.dll
2014-12-02 19:13:04 -------- d-----w- C:\Windows\SysWow64\Wat
2014-12-02 19:13:03 -------- d-----w- C:\Windows\System32\Wat
2014-12-02 09:28:28 -------- d-----w- C:\Users\debbie\AppData\Local\Microsoft Help
2014-12-02 07:59:27 -------- d-s---w- C:\Windows\System32\CompatTel
2014-12-02 06:59:07 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-12-02 06:59:07 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-12-02 06:59:06 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-12-02 06:59:06 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-12-02 04:12:18 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2014-12-02 03:42:32 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2014-12-02 03:42:32 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2014-12-02 03:42:31 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2014-12-02 03:42:31 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2014-12-02 03:42:31 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2014-12-02 03:42:31 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2014-12-02 03:42:30 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2014-12-02 03:36:40 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2014-12-02 03:36:40 5120 ----a-w- C:\Windows\System32\wmi.dll
2014-12-02 03:36:40 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2014-12-02 03:07:27 658432 ----a-w- C:\Windows\System32\RMActivate_isv.exe
2014-12-02 02:58:30 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-12-02 02:57:37 683520 ----a-w- C:\Windows\System32\termsrv.dll
2014-12-02 02:57:37 681984 ----a-w- C:\Windows\SysWow64\adtschema.dll
2014-12-02 02:57:37 681984 ----a-w- C:\Windows\System32\adtschema.dll
2014-12-02 02:57:36 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2014-12-02 02:57:36 146432 ----a-w- C:\Windows\System32\msaudite.dll
2014-12-02 02:55:47 878080 ----a-w- C:\Windows\System32\advapi32.dll
2014-12-02 02:55:47 859648 ----a-w- C:\Windows\System32\tdh.dll
2014-12-02 02:55:47 640512 ----a-w- C:\Windows\SysWow64\advapi32.dll
2014-12-02 02:55:47 619520 ----a-w- C:\Windows\SysWow64\tdh.dll
2014-12-02 02:55:47 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2014-12-02 02:55:47 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2014-12-02 02:55:02 1354240 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2014-12-02 02:55:01 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-12-02 02:54:06 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
2014-12-02 02:52:22 46592 ----a-w- C:\Windows\SysWow64\fpb.rs
2014-12-02 02:51:54 55296 ----a-w- C:\Windows\System32\dhcpcsvc6.dll
2014-12-02 02:51:54 44032 ----a-w- C:\Windows\SysWow64\dhcpcsvc6.dll
2014-12-02 02:51:54 226816 ----a-w- C:\Windows\System32\dhcpcore6.dll
2014-12-02 02:51:54 193536 ----a-w- C:\Windows\SysWow64\dhcpcore6.dll
2014-12-02 02:51:50 1887232 ----a-w- C:\Windows\System32\d3d11.dll
2014-12-02 02:51:50 1505280 ----a-w- C:\Windows\SysWow64\d3d11.dll
2014-12-02 02:51:14 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2014-12-02 02:51:14 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2014-12-02 02:51:14 1118720 ----a-w- C:\Windows\System32\sbe.dll
2014-12-02 02:51:13 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
2014-12-02 02:51:13 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2014-12-02 02:51:13 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2014-12-02 02:50:56 327168 ----a-w- C:\Windows\System32\mswsock.dll
2014-12-02 02:50:56 231424 ----a-w- C:\Windows\SysWow64\mswsock.dll
2014-12-02 02:50:45 1684928 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-12-02 02:48:48 3198976 ----a-w- C:\Windows\System32\win32k.sys
2014-12-02 02:48:43 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2014-12-02 02:48:43 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2014-12-02 02:48:22 449024 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-12-02 02:48:21 692736 ----a-w- C:\Windows\System32\osk.exe
2014-12-02 02:48:21 646144 ----a-w- C:\Windows\SysWow64\osk.exe
2014-12-02 02:48:04 404480 ----a-w- C:\Windows\System32\gdi32.dll
2014-12-02 02:48:03 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2014-12-02 02:46:45 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2014-12-02 02:45:49 27584 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-12-02 02:44:54 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2014-12-02 02:43:54 155584 ----a-w- C:\Windows\System32\drivers\ataport.sys
2014-12-02 02:42:58 9216 ----a-w- C:\Program Files (x86)\Windows Defender\MpAsDesc.dll
2014-12-02 02:41:50 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2014-12-02 02:40:58 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2014-12-02 02:40:58 31232 ----a-w- C:\Windows\System32\prevhost.exe
2014-12-02 00:50:07 -------- d-----w- C:\Users\debbie\AppData\Local\{B1323411-70A2-4BB9-80EB-DD9D355984B3}
2014-12-02 00:46:27 -------- d--h--w- C:\ProgramData\CanonIJEPPEX2
2014-12-02 00:46:27 -------- d--h--w- C:\ProgramData\CanonEPP
2014-12-02 00:46:05 -------- d-----w- C:\ProgramData\Canon IJ Network Tool
2014-12-02 00:45:59 307200 ----a-w- C:\Windows\SysWow64\CNC495L.dll
2014-12-02 00:45:59 15872 ----a-w- C:\Windows\SysWow64\CNHMCA.dll
2014-12-02 00:45:59 106496 ----a-w- C:\Windows\SysWow64\CNC495U.dll
2014-12-02 00:45:20 -------- d-----w- C:\ProgramData\CanonIJMSetup
2014-12-02 00:45:04 -------- d-----w- C:\Program Files\Common Files\CANON
2014-12-02 00:44:56 -------- d-----w- C:\ProgramData\CanonIJWSpt
2014-12-02 00:43:29 -------- d-----w- C:\Program Files\Canon
2014-12-02 00:42:46 87040 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPA9.DLL
2014-12-02 00:42:46 28672 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDA9.DLL
2014-12-02 00:42:18 361472 ----a-w- C:\Windows\System32\CNMLMA9.DLL
2014-12-02 00:42:07 248320 ----a-w- C:\Windows\System32\CNMIUA9.DLL
2014-12-02 00:41:48 37376 ----a-w- C:\Windows\System32\CNMN6UI.DLL
2014-12-02 00:41:48 327680 ----a-w- C:\Windows\System32\CNMN6PPM.DLL
2014-12-02 00:41:48 -------- d-----w- C:\Windows\System32\STRING
2014-12-02 00:41:07 -------- d-----w- C:\Program Files (x86)\Canon
2014-12-02 00:20:37 -------- d-----w- C:\Users\debbie\AppData\Roaming\SoftGrid Client
2014-12-02 00:20:37 -------- d-----w- C:\Users\debbie\AppData\Local\SoftGrid Client
2014-12-02 00:19:57 -------- d-----w- C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-12-02 00:19:46 -------- d-----w- C:\Users\debbie\AppData\Roaming\TP
2014-12-01 23:43:17 -------- d-----w- C:\Users\debbie\AppData\Local\Google
2014-12-01 23:42:39 -------- d-----w- C:\Users\debbie\AppData\Local\Deployment
2014-12-01 23:42:39 -------- d-----w- C:\Users\debbie\AppData\Local\Apps
2014-12-01 22:56:33 -------- d-----w- C:\Users\debbie\AppData\Roaming\AVG2015
2014-12-01 22:55:46 -------- d-----w- C:\Users\debbie\AppData\Roaming\TuneUp Software
2014-12-01 22:55:33 -------- d-----w- C:\$AVG
2014-12-01 22:55:32 -------- d-----w- C:\ProgramData\AVG2015
2014-12-01 22:54:56 -------- d-----w- C:\Program Files (x86)\AVG
2014-12-01 22:36:57 -------- d--h--w- C:\ProgramData\Common Files
2014-12-01 22:36:57 -------- d-----w- C:\Users\debbie\AppData\Local\MFAData
2014-12-01 22:36:57 -------- d-----w- C:\Users\debbie\AppData\Local\Avg2015
2014-12-01 22:36:57 -------- d-----w- C:\ProgramData\MFAData
2014-12-01 22:27:19 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2014-12-01 22:27:19 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2014-12-01 22:27:19 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2014-12-01 22:15:52 -------- d-----w- C:\Users\debbie\AppData\Local\ATI
2014-12-01 22:14:52 -------- d-----w- C:\Users\debbie\AppData\Roaming\Intel Corporation
2014-12-01 22:14:51 -------- d-----w- C:\Users\debbie\AppData\Roaming\hpqLog
2014-12-01 22:14:50 -------- d-----w- C:\Users\debbie\AppData\Roaming\Synaptics
2014-12-01 22:14:01 -------- d-----w- C:\Users\debbie\AppData\Local\RemEngine
2014-12-01 22:09:54 36864 ----a-w- C:\Windows\System32\wuapp.exe
2014-12-01 22:09:54 33792 ----a-w- C:\Windows\SysWow64\wuapp.exe
2014-12-01 22:09:54 198600 ----a-w- C:\Windows\System32\wuwebv.dll
2014-12-01 22:09:54 179656 ----a-w- C:\Windows\SysWow64\wuwebv.dll
.
==================== Find3M  ====================
.
2014-12-02 20:34:25 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-11-22 03:06:23 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-11-22 03:06:11 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-11-22 02:50:39 66560 ----a-w- C:\Windows\System32\iesetup.dll
2014-11-22 02:50:10 580096 ----a-w- C:\Windows\System32\vbscript.dll
2014-11-22 02:49:54 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-11-22 02:48:20 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2014-11-22 02:35:43 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-11-22 02:35:29 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-11-22 02:34:51 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-11-22 02:34:07 6039552 ----a-w- C:\Windows\System32\jscript9.dll
2014-11-22 02:26:31 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-11-22 02:20:44 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-11-22 02:14:16 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-11-22 02:07:43 501248 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-11-22 02:07:17 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-11-22 02:06:32 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-11-22 02:05:02 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2014-11-22 01:55:16 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-11-22 01:54:30 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-11-22 01:47:10 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-11-22 01:46:58 2125312 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-11-22 01:40:04 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-11-22 01:29:26 4299264 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-11-22 01:28:21 2358272 ----a-w- C:\Windows\System32\wininet.dll
2014-11-22 01:22:49 2052096 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-11-22 01:21:57 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-11-22 01:00:20 1888256 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-11-11 03:08:52 241152 ----a-w- C:\Windows\System32\pku2u.dll
2014-11-11 02:44:32 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll
2014-11-11 02:44:25 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-10-29 10:35:16 263960 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
2014-10-25 01:57:59 77824 ----a-w- C:\Windows\System32\packager.dll
2014-10-25 01:32:37 67584 ----a-w- C:\Windows\SysWow64\packager.dll
2014-10-18 02:05:23 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2014-10-18 01:33:18 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2014-10-14 02:16:37 155064 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-10-14 02:13:00 3241984 ----a-w- C:\Windows\System32\msi.dll
2014-10-14 02:12:57 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-10-14 01:50:47 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-10-14 01:50:41 2363904 ----a-w- C:\Windows\SysWow64\msi.dll
2014-10-14 01:49:38 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-10-10 03:14:32 274200 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2014-10-05 09:41:40 124184 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
2014-10-03 02:12:00 500224 ----a-w- C:\Windows\System32\AUDIOKSE.dll
2014-10-03 02:11:54 284672 ----a-w- C:\Windows\System32\EncDump.dll
2014-10-03 02:11:51 680960 ----a-w- C:\Windows\System32\audiosrv.dll
2014-10-03 02:11:51 440832 ----a-w- C:\Windows\System32\AudioEng.dll
2014-10-03 02:11:51 296448 ----a-w- C:\Windows\System32\AudioSes.dll
2014-10-03 01:44:42 442880 ----a-w- C:\Windows\SysWow64\AUDIOKSE.dll
2014-10-03 01:44:26 374784 ----a-w- C:\Windows\SysWow64\AudioEng.dll
2014-10-03 01:44:26 195584 ----a-w- C:\Windows\SysWow64\AudioSes.dll
2014-09-25 02:08:38 371712 ----a-w- C:\Windows\System32\qdvd.dll
2014-09-25 01:40:50 519680 ----a-w- C:\Windows\SysWow64\qdvd.dll
2014-09-19 09:42:52 210944 ----a-w- C:\Windows\System32\wdigest.dll
2014-09-19 09:42:51 86528 ----a-w- C:\Windows\System32\TSpkg.dll
2014-09-19 09:42:49 342016 ----a-w- C:\Windows\System32\schannel.dll
2014-09-19 09:42:47 314880 ----a-w- C:\Windows\System32\msv1_0.dll
2014-09-19 09:42:47 309760 ----a-w- C:\Windows\System32\ncrypt.dll
2014-09-19 09:42:41 22016 ----a-w- C:\Windows\System32\credssp.dll
2014-09-19 09:23:55 172032 ----a-w- C:\Windows\SysWow64\wdigest.dll
2014-09-19 09:23:52 65536 ----a-w- C:\Windows\SysWow64\TSpkg.dll
2014-09-19 09:23:49 248832 ----a-w- C:\Windows\SysWow64\schannel.dll
2014-09-19 09:23:46 221184 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2014-09-19 09:23:45 259584 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2014-09-19 09:23:36 17408 ----a-w- C:\Windows\SysWow64\credssp.dll
.
============= FINISH:  9:04:40.98 ===============


#4 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 17 December 2014 - 05:27 PM

Attached File  Attach2.txt   10.54KB   1 downloads  Here is the other log.  thanks.



#5 OCD

OCD

  • Malware Response Team
  • 172 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:05:04 AM

Posted 18 December 2014 - 10:49 PM

Hi bellagirl,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

bullseye_zpse9eaf36e.gif Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

bullseye_zpse9eaf36e.gif aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Save this file, do not post it.
=========================

bullseye_zpse9eaf36e.gif Download Farbar Recovery Scan Tool and save to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click and select "Run as Administrator" to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • FRST.txt
  • Addition.txt

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days

#6 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 19 December 2014 - 12:17 AM

Results of screen317's Security Check version 0.99.93  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
AVG AntiVirus Free Edition 2015   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:`````````
 Java™ 6 Update 24  
 Java version 32-bit out of Date!
 Adobe Flash Player 10 Flash Player out of Date!
 Google Chrome (39.0.2171.71) 
 Google Chrome (39.0.2171.95) 
````````Process Check: objlist.exe by Laurent````````
 AVG avgwdsvc.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 3% 
````````````````````End of Log``````````````````````
 
 
 
 

Attached Files



#7 OCD

OCD

  • Malware Response Team
  • 172 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:05:04 AM

Posted 19 December 2014 - 01:59 AM

Hi bellagirl,
 

Basically i would like to know the following
1 - Can you see if i have any malware or viruses
2 - should i be using some other checkers like adware or anything else ???
3 - are there too many programs on startup and often when i shut down it usually comes up with "waiting for program to shut down" when i have closed all windows etc.


1 - We are checking for any malware, and will remove whatever we find.
2 - I will give some recommendations for any additional software needed at the end of the process.
3 - I can't say at the moment if you have too many programs running at start up, we will look into that.

=========================

Please post logs directly into the reply, do not attach unless requested to do so.

=========================

bullseye_zpse9eaf36e.gif FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt
 

Start
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
EmptyTemp:
CMD: ipconfig /flushdns
End

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

Locate this Combofix log and post in your next reply.
C:\ComboFix.txt

=========================

bullseye_zpse9eaf36e.gif AdwCleaner v3: Scan & Clean

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
  • Click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a log file report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that log file in your next reply.
  • A copy of that log file will also be saved in the C:\AdwCleaner folder.

=========================

bullseye_zpse9eaf36e.gif Junkware Removal Tool

Download Junkware Removal Tool to your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

=========================

bullseye_zpse9eaf36e.gif MiniToolBox

Please download MiniToolBox, save it to your desktop and run it.
Right click and select "Run as Administrator".

Check-mark the following check-boxes:

  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List IP configuration

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.

=========================

In your next post please provide the following:

  • Fixlog.txt
  • ComboFix.txt
  • AdwCleaner[S0].txt
  • JRT.txt
  • Result.txt

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days

#8 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 19 December 2014 - 09:11 AM

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-12-2014
Ran by debbie at 2014-12-20 00:10:24 Run:1
Running from C:\Users\debbie\Downloads
Loaded Profile: debbie (Available profiles: debbie)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
Start
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
EmptyTemp:
CMD: ipconfig /flushdns
End
*****************
 
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
"HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key not found.
"HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key deleted successfully.
"HKCR\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}" => Key not found.
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
EmptyTemp: => Removed 830.1 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog ====


#9 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 19 December 2014 - 09:13 AM

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2014
Ran by debbie (administrator) on DEBBIE-HP on 19-12-2014 16:02:58
Running from C:\Users\debbie\Downloads
Loaded Profile: debbie (Available profiles: debbie)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPConnectionManager.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-11] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-17] (Synaptics Incorporated)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2011-02-05] (Intel® Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-13] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-16] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-18] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-16] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-10] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-28] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [249064 2010-10-30] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3653136 2014-11-09] (AVG Technologies CZ, s.r.o.)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-12-16] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.jp.msn.com/HPALL/14
HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://au.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://au.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://au.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
 
Chrome: 
=======
CHR Profile: C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-02]
CHR Extension: (Website Logon) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe [2014-12-02]
CHR Extension: (Google Docs) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-02]
CHR Extension: (Google Drive) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-02]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-02]
CHR Extension: (YouTube) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-02]
CHR Extension: (Google Search) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-02]
CHR Extension: (Google Sheets) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-02]
CHR Extension: (BMI Calculator and Weight Tracker) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcfnndhdcbgbkcecgkafjdgonpmlnpof [2014-12-02]
CHR Extension: (Google Wallet) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-02]
CHR Extension: (Gmail) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-02]
CHR HKLM-x32\...\Chrome\Extension: [aepeildmfnnehghlknddebgjghlompfe] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-02-11]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3488784 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-11-09] (AVG Technologies CZ, s.r.o.)
S4 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [901184 2011-01-25] (Intel Corporation) [File not signed]
S4 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2011-01-25] (Intel Corporation) [File not signed]
S4 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [991296 2011-01-25] (Intel Corporation) [File not signed]
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-11-20] (WildTangent)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-02-05] ()
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [263960 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U3 aswMBR; \??\C:\Users\debbie\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\debbie\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-12-19 16:02 - 2014-12-19 16:03 - 00019385 _____ () C:\Users\debbie\Downloads\FRST.txt
2014-12-19 16:02 - 2014-12-19 16:03 - 00000000 ____D () C:\FRST
2014-12-19 16:02 - 2014-12-19 16:02 - 00001435 _____ () C:\Users\debbie\Desktop\FRST - Shortcut.lnk
2014-12-19 16:01 - 2014-12-19 16:02 - 00001455 _____ () C:\Users\debbie\Desktop\FRST64 - Shortcut.lnk
2014-12-19 16:00 - 2014-12-19 16:01 - 02121216 _____ (Farbar) C:\Users\debbie\Downloads\FRST64.exe
2014-12-19 16:00 - 2014-12-19 16:00 - 01113600 _____ (Farbar) C:\Users\debbie\Downloads\FRST.exe
2014-12-19 15:57 - 2014-12-19 15:57 - 00001995 _____ () C:\Users\debbie\Desktop\aswMBR.txt
2014-12-19 15:57 - 2014-12-19 15:57 - 00000512 _____ () C:\Users\debbie\Desktop\MBR.dat
2014-12-19 15:19 - 2014-12-19 15:19 - 00001455 _____ () C:\Users\debbie\Desktop\aswMBR - Shortcut.lnk
2014-12-19 15:17 - 2014-12-19 15:19 - 05198336 _____ (AVAST Software) C:\Users\debbie\Downloads\aswMBR.exe
2014-12-19 15:12 - 2014-12-19 15:12 - 00001097 _____ () C:\Users\debbie\Desktop\SecurityCheck - Shortcut.lnk
2014-12-19 15:11 - 2014-12-19 15:11 - 00001075 _____ () C:\Users\debbie\Downloads\SecurityCheck - Shortcut.lnk
2014-12-19 15:04 - 2014-12-19 15:04 - 00852505 _____ () C:\Users\debbie\Downloads\SecurityCheck.exe
2014-12-18 09:24 - 2014-12-18 09:24 - 00010793 _____ () C:\Users\debbie\Desktop\Attach2.txt
2014-12-18 09:03 - 2014-12-18 09:03 - 00688992 ____R (Swearware) C:\Users\debbie\Downloads\dds (2).com
2014-12-18 09:00 - 2014-12-18 09:00 - 00688992 ____R (Swearware) C:\Users\debbie\Downloads\dds (1).com
2014-12-18 07:58 - 2014-12-18 07:58 - 00002660 _____ () C:\Users\debbie\Downloads\this_message_in_html.html
2014-12-13 22:44 - 2014-12-13 22:44 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\{90140011-0066-0409-0000-0000000FF1CE}
2014-12-13 22:43 - 2014-12-13 22:43 - 00000000 ____D () C:\ProgramData\Virtualized Applications
2014-12-13 18:00 - 2014-12-13 18:00 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\WildTangent
2014-12-13 18:00 - 2014-12-13 18:00 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-12-13 17:56 - 2014-12-13 17:56 - 00002444 _____ () C:\Users\Public\Desktop\WildTangent Games App - hp.lnk
2014-12-13 17:53 - 2014-12-13 18:40 - 00000000 ____D () C:\Users\debbie\AppData\Local\Microsoft Games
2014-12-13 13:15 - 2014-11-27 12:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-13 13:15 - 2014-11-27 12:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-13 13:15 - 2014-11-22 14:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-13 13:15 - 2014-11-22 14:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-13 13:15 - 2014-11-22 14:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-13 13:15 - 2014-11-22 13:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-13 13:15 - 2014-11-22 13:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-13 13:15 - 2014-11-22 13:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-13 13:15 - 2014-11-22 13:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-13 13:15 - 2014-11-22 13:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-13 13:15 - 2014-11-22 13:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-13 13:15 - 2014-11-22 13:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-13 13:15 - 2014-11-22 13:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-13 13:15 - 2014-11-22 13:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-13 13:15 - 2014-11-22 13:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-13 13:15 - 2014-11-22 13:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-13 13:15 - 2014-11-22 13:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-13 13:15 - 2014-11-22 13:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-13 13:15 - 2014-11-22 13:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-13 13:15 - 2014-11-22 13:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-13 13:15 - 2014-11-22 13:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-13 13:15 - 2014-11-22 13:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-13 13:15 - 2014-11-22 13:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-13 13:15 - 2014-11-22 13:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-13 13:15 - 2014-11-22 13:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-13 13:15 - 2014-11-22 13:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-13 13:15 - 2014-11-22 13:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-13 13:15 - 2014-11-22 13:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-13 13:15 - 2014-11-22 13:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-13 13:15 - 2014-11-22 13:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-13 13:15 - 2014-11-22 12:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-13 13:15 - 2014-11-22 12:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-13 13:15 - 2014-11-22 12:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-13 13:15 - 2014-11-22 12:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-13 13:15 - 2014-11-22 12:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-13 13:15 - 2014-11-22 12:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-13 13:15 - 2014-11-22 12:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-13 13:15 - 2014-11-22 12:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-13 13:15 - 2014-11-22 12:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-13 13:15 - 2014-11-22 12:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-13 13:15 - 2014-11-22 12:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-13 13:15 - 2014-11-22 12:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-13 13:15 - 2014-11-22 12:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-13 13:15 - 2014-11-22 12:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-13 13:15 - 2014-11-22 12:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-13 13:15 - 2014-11-22 12:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-13 13:15 - 2014-11-22 12:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-13 13:15 - 2014-11-22 12:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-13 13:15 - 2014-11-22 12:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-13 13:15 - 2014-11-22 12:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-13 13:15 - 2014-11-22 12:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-13 13:15 - 2014-11-22 12:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-13 13:15 - 2014-11-22 12:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-13 13:15 - 2014-11-22 12:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-13 13:15 - 2014-11-22 11:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-13 13:15 - 2014-11-22 11:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-13 08:11 - 2014-12-18 09:04 - 00035678 _____ () C:\Users\debbie\Desktop\dds.txt
2014-12-13 08:11 - 2014-12-18 09:04 - 00010793 _____ () C:\Users\debbie\Desktop\attach.txt
2014-12-13 08:08 - 2014-12-13 08:08 - 00688992 ____R (Swearware) C:\Users\debbie\Downloads\dds.com
2014-12-12 23:34 - 2014-12-12 23:34 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\InstallShield
2014-12-12 11:06 - 2014-12-12 11:06 - 00000000 ____D () C:\Users\debbie\AppData\Local\{EE5C689F-B943-4055-AB93-60209DE73A16}
2014-12-12 11:06 - 2014-12-12 11:06 - 00000000 ____D () C:\Users\debbie\AppData\Local\{0FB2EC8F-25F7-47AF-847C-768D717462D6}
2014-12-10 10:36 - 2014-12-10 10:36 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-10 09:44 - 2014-10-18 13:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-10 09:44 - 2014-10-18 12:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-10 09:44 - 2014-07-07 13:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-10 09:44 - 2014-07-07 13:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-10 09:44 - 2014-07-07 13:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-10 09:44 - 2014-07-07 13:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-10 09:44 - 2014-07-07 12:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-10 09:44 - 2014-07-07 12:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-10 09:44 - 2014-07-07 12:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-10 09:44 - 2014-07-07 12:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-10 08:06 - 2014-12-10 08:06 - 00027117 _____ () C:\ComboFix.txt
2014-12-10 07:55 - 2014-12-10 08:06 - 00000000 ____D () C:\Qoobox
2014-12-10 07:55 - 2014-12-10 08:04 - 00000000 ____D () C:\Windows\erdnt
2014-12-10 07:55 - 2011-06-26 17:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-10 07:55 - 2010-11-08 04:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-10 07:55 - 2009-04-20 15:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-10 07:52 - 2014-12-10 07:54 - 05601243 ____R (Swearware) C:\Users\debbie\Downloads\ComboFix.exe
2014-12-10 07:13 - 2014-12-04 13:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-10 07:13 - 2014-12-04 13:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-10 07:13 - 2014-12-02 10:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-10 07:06 - 2014-11-11 14:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 07:06 - 2014-11-11 13:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 07:06 - 2014-11-11 12:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-10 07:00 - 2014-10-30 13:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-10 07:00 - 2014-10-30 12:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-10 07:00 - 2014-10-03 13:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-10 07:00 - 2014-10-03 13:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 07:00 - 2014-10-03 13:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-10 07:00 - 2014-10-03 13:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-10 07:00 - 2014-10-03 13:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 07:00 - 2014-10-03 12:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-10 07:00 - 2014-10-03 12:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 07:00 - 2014-10-03 12:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-10 07:00 - 2014-10-03 12:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-10 07:00 - 2014-10-03 12:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-10 06:59 - 2014-11-08 14:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-10 06:59 - 2014-11-08 13:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-09 20:56 - 2014-12-09 20:56 - 00000000 ____D () C:\Users\debbie\AppData\Local\Adobe
2014-12-09 20:50 - 2014-12-09 20:50 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2014-12-08 18:39 - 2014-12-08 18:39 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\IDT
2014-12-08 11:11 - 2014-12-08 11:12 - 00262144 _____ () C:\Windows\Minidump\120814-52151-01.dmp
2014-12-08 11:11 - 2014-12-08 11:11 - 481596912 _____ () C:\Windows\MEMORY.DMP
2014-12-08 11:11 - 2014-12-08 11:11 - 00000000 ____D () C:\Windows\Minidump
2014-12-08 11:08 - 2014-12-08 11:08 - 00000000 __SHD () C:\Users\debbie\AppData\Local\EmieUserList
2014-12-08 11:08 - 2014-12-08 11:08 - 00000000 __SHD () C:\Users\debbie\AppData\Local\EmieSiteList
2014-12-08 11:08 - 2014-12-08 11:08 - 00000000 __SHD () C:\Users\debbie\AppData\Local\EmieBrowserModeList
2014-12-07 13:00 - 2014-12-07 13:00 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-12-05 10:52 - 2014-12-05 10:52 - 00002461 _____ () C:\Users\debbie\Desktop\Microsoft Word Starter 2010.lnk
2014-12-04 01:47 - 2014-12-17 23:01 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-12-03 11:36 - 2014-06-27 13:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-12-03 11:36 - 2014-06-27 12:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-12-03 10:35 - 2011-02-25 17:19 - 02871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-12-03 10:35 - 2011-02-25 16:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-12-03 10:19 - 2013-11-24 05:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-12-03 10:19 - 2013-11-24 04:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-12-03 10:14 - 2014-06-24 14:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-12-03 10:14 - 2014-06-24 13:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-12-03 10:12 - 2014-07-09 13:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-12-03 10:12 - 2014-07-09 13:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-12-03 10:12 - 2014-07-09 13:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-12-03 10:12 - 2014-07-09 13:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-12-03 10:12 - 2014-07-09 13:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-12-03 10:12 - 2014-07-09 09:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-12-03 10:12 - 2014-07-09 09:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-12-03 08:48 - 2013-11-26 19:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-12-03 08:48 - 2013-11-23 09:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-12-03 08:46 - 2012-07-07 07:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2014-12-03 08:46 - 2012-02-11 17:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-12-03 08:46 - 2012-02-11 17:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2014-12-03 08:46 - 2011-04-28 14:54 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2014-12-03 08:46 - 2011-03-11 17:41 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2014-12-03 08:46 - 2011-03-11 17:41 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2014-12-03 08:46 - 2011-03-11 17:41 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2014-12-03 08:46 - 2011-03-11 17:41 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2014-12-03 08:46 - 2011-03-11 17:41 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2014-12-03 08:46 - 2011-03-11 17:33 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2014-12-03 08:46 - 2011-03-11 17:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2014-12-03 08:46 - 2011-03-11 16:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2014-12-03 08:46 - 2011-03-11 16:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2014-12-03 08:46 - 2011-03-11 15:37 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-12-03 07:53 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2014-12-03 07:50 - 2014-12-03 07:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-12-03 07:50 - 2014-12-03 07:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-12-03 07:50 - 2014-12-03 07:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-12-03 07:50 - 2014-12-03 07:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-12-03 07:50 - 2014-12-03 07:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-12-03 07:50 - 2014-12-03 07:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-12-03 07:50 - 2014-12-03 07:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-12-03 07:34 - 2014-12-03 07:34 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-12-03 07:32 - 2014-12-03 07:53 - 00009225 _____ () C:\Windows\IE11_main.log
2014-12-03 07:31 - 2014-12-14 14:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-03 07:30 - 2014-12-14 17:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-03 07:30 - 2014-12-14 17:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-03 07:26 - 2014-12-10 09:49 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-03 07:26 - 2014-12-10 09:45 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-03 07:23 - 2014-07-01 09:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-12-03 07:23 - 2014-07-01 09:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-12-03 07:23 - 2014-06-06 17:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-12-03 07:23 - 2014-06-06 17:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-12-03 07:23 - 2014-03-10 08:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-12-03 07:23 - 2014-03-10 08:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-12-03 07:23 - 2014-03-10 08:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-12-03 07:23 - 2014-03-10 08:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-12-03 06:36 - 2014-07-17 13:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-12-03 06:36 - 2014-07-17 13:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-12-03 06:36 - 2014-07-17 13:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-12-03 06:36 - 2014-07-17 13:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-12-03 06:36 - 2014-07-17 13:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-12-03 06:36 - 2014-07-17 12:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-12-03 06:36 - 2014-07-17 12:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-12-03 06:36 - 2014-07-17 12:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-12-03 06:36 - 2014-07-17 12:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-12-03 06:36 - 2014-07-17 12:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-12-03 06:36 - 2014-07-17 12:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-12-03 06:32 - 2013-05-13 16:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-12-03 06:32 - 2013-05-13 14:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-12-03 06:32 - 2013-05-13 14:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-12-03 06:32 - 2013-05-13 14:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-12-03 06:31 - 2014-08-01 22:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-12-03 06:31 - 2014-08-01 22:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-12-03 06:31 - 2013-05-10 16:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-12-03 06:31 - 2013-05-10 14:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2014-12-02 20:31 - 2014-12-02 20:31 - 00000000 ___RD () C:\MSOCache
2014-12-02 20:28 - 2014-12-02 20:28 - 00000000 ____D () C:\Users\debbie\AppData\Local\Microsoft Help
2014-12-02 20:28 - 2014-12-02 20:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-02 18:59 - 2014-12-10 10:36 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-02 17:59 - 2013-05-10 16:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-12-02 17:59 - 2013-05-10 16:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-12-02 17:59 - 2013-05-10 15:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-12-02 17:59 - 2013-05-10 15:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-12-02 14:42 - 2012-07-26 14:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-12-02 14:42 - 2012-07-26 14:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-12-02 14:42 - 2012-07-26 14:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-12-02 14:42 - 2012-07-26 14:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-12-02 14:42 - 2012-07-26 14:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-12-02 14:42 - 2012-07-26 13:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-12-02 14:42 - 2012-07-26 13:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-12-02 14:42 - 2012-06-03 01:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-12-02 14:36 - 2012-03-01 17:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-12-02 14:36 - 2012-03-01 17:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-12-02 14:36 - 2012-03-01 16:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-12-02 14:12 - 2014-03-04 20:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-12-02 14:12 - 2014-03-04 20:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-12-02 14:12 - 2014-03-04 20:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-12-02 14:12 - 2014-03-04 20:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-12-02 14:12 - 2014-03-04 20:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-12-02 14:12 - 2014-03-04 20:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-12-02 14:12 - 2014-03-04 20:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-12-02 14:12 - 2014-03-04 20:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-12-02 14:12 - 2013-08-02 13:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-12-02 14:12 - 2013-08-02 13:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-12-02 14:12 - 2013-08-02 12:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-12-02 14:12 - 2013-08-02 11:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-12-02 14:07 - 2013-12-04 13:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-12-02 14:07 - 2013-12-04 13:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-12-02 14:07 - 2013-12-04 13:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-12-02 14:07 - 2013-12-04 13:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-12-02 14:07 - 2013-12-04 13:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-12-02 14:07 - 2013-12-04 13:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-12-02 14:07 - 2013-12-04 13:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-12-02 14:07 - 2013-12-04 13:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-12-02 14:07 - 2013-12-04 13:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-12-02 14:07 - 2013-12-04 13:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-12-02 14:07 - 2013-12-04 13:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-12-02 14:07 - 2013-12-04 13:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-12-02 14:07 - 2013-12-04 13:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-12-02 14:07 - 2013-12-04 13:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-12-02 14:07 - 2013-12-04 12:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-12-02 14:07 - 2013-12-04 12:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-12-02 14:07 - 2013-12-04 12:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-12-02 14:07 - 2013-12-04 12:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-12-02 13:58 - 2014-11-11 14:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-12-02 13:58 - 2014-11-11 14:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-12-02 13:58 - 2014-11-11 13:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-12-02 13:58 - 2014-11-11 13:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-12-02 13:58 - 2014-10-14 13:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-12-02 13:58 - 2014-10-14 13:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-12-02 13:58 - 2014-10-14 12:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-12-02 13:58 - 2014-10-14 12:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-12-02 13:58 - 2014-04-12 13:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-12-02 13:58 - 2014-04-12 13:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-12-02 13:58 - 2014-04-12 13:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-12-02 13:58 - 2014-04-12 13:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-12-02 13:58 - 2014-04-12 13:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-12-02 13:58 - 2012-10-04 04:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-12-02 13:58 - 2012-10-04 03:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2014-12-02 13:58 - 2012-10-04 03:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2014-12-02 13:58 - 2012-10-04 03:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2014-12-02 13:58 - 2012-10-04 03:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-12-02 13:58 - 2012-01-13 18:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2014-12-02 13:57 - 2014-10-14 13:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-12-02 13:57 - 2014-10-14 13:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-12-02 13:57 - 2014-10-14 13:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-12-02 13:57 - 2014-10-14 12:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-12-02 13:57 - 2014-10-14 12:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-12-02 13:56 - 2013-07-26 13:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-12-02 13:56 - 2013-07-26 12:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-12-02 13:55 - 2013-08-29 13:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-12-02 13:55 - 2013-08-29 13:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-12-02 13:55 - 2013-08-29 13:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-12-02 13:55 - 2013-08-29 12:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-12-02 13:55 - 2013-08-29 12:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-12-02 13:55 - 2013-08-29 12:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-12-02 13:54 - 2013-07-04 23:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-12-02 13:53 - 2014-09-19 20:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-12-02 13:53 - 2013-07-09 16:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-12-02 13:53 - 2013-07-09 15:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-12-02 13:52 - 2012-12-08 00:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-12-02 13:52 - 2012-12-08 00:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-12-02 13:52 - 2012-12-07 23:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-12-02 13:52 - 2012-12-07 23:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-12-02 13:52 - 2012-12-07 22:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2014-12-02 13:51 - 2013-04-26 10:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-12-02 13:51 - 2013-04-01 09:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-12-02 13:51 - 2012-10-10 05:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-12-02 13:51 - 2012-10-10 05:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-12-02 13:51 - 2012-10-10 04:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-12-02 13:51 - 2012-10-10 04:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-12-02 13:51 - 2010-12-23 21:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-12-02 13:51 - 2010-12-23 21:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-12-02 13:51 - 2010-12-23 21:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-12-02 13:51 - 2010-12-23 16:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-12-02 13:51 - 2010-12-23 16:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-12-02 13:51 - 2010-12-23 16:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-12-02 13:50 - 2014-01-24 13:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-12-02 13:50 - 2013-09-08 13:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-12-02 13:50 - 2013-09-08 13:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-12-02 13:49 - 2014-04-05 13:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-12-02 13:49 - 2014-04-05 13:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-12-02 13:49 - 2013-11-26 22:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-12-02 13:49 - 2011-05-04 16:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2014-12-02 13:49 - 2011-05-04 16:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-12-02 13:49 - 2011-05-04 16:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-12-02 13:49 - 2011-05-04 16:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-12-02 13:49 - 2011-05-04 15:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2014-12-02 13:49 - 2011-05-04 15:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2014-12-02 13:49 - 2011-05-04 15:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2014-12-02 13:49 - 2011-05-04 15:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2014-12-02 13:48 - 2014-10-10 11:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-12-02 13:48 - 2014-08-23 13:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-12-02 13:48 - 2014-08-23 12:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-12-02 13:48 - 2014-06-25 13:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-12-02 13:48 - 2014-06-25 12:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-12-02 13:48 - 2014-06-18 13:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-12-02 13:48 - 2014-06-18 12:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-12-02 13:48 - 2012-01-04 21:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-12-02 13:48 - 2012-01-04 19:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2014-12-02 13:47 - 2014-07-14 13:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-12-02 13:47 - 2014-07-14 12:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-12-02 13:47 - 2014-03-27 01:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-12-02 13:47 - 2014-03-27 01:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-12-02 13:47 - 2014-03-27 01:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-12-02 13:47 - 2014-03-27 01:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-12-02 13:47 - 2013-07-25 20:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-12-02 13:47 - 2013-07-25 19:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-12-02 13:47 - 2013-06-26 09:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-12-02 13:47 - 2012-11-29 09:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-12-02 13:47 - 2012-11-29 09:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-12-02 13:47 - 2012-11-29 09:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-12-02 13:47 - 2011-03-11 17:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-12-02 13:47 - 2011-03-11 17:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-12-02 13:47 - 2011-03-11 16:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-12-02 13:47 - 2011-03-11 16:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-12-02 13:46 - 2014-10-03 13:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-12-02 13:46 - 2014-10-03 13:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-12-02 13:46 - 2014-10-03 13:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-12-02 13:46 - 2014-10-03 13:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-12-02 13:46 - 2014-10-03 13:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-12-02 13:46 - 2014-10-03 12:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-12-02 13:46 - 2014-10-03 12:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-12-02 13:46 - 2014-10-03 12:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-12-02 13:46 - 2013-10-06 07:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-12-02 13:46 - 2013-10-06 06:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-12-02 13:46 - 2013-07-09 16:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-12-02 13:46 - 2013-07-09 16:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-12-02 13:46 - 2013-07-09 15:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-12-02 13:46 - 2013-07-09 15:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-12-02 13:46 - 2012-08-22 08:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-12-02 13:46 - 2011-10-15 17:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-12-02 13:46 - 2011-10-15 16:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-12-02 13:46 - 2011-04-09 17:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-12-02 13:46 - 2011-04-09 16:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-12-02 13:45 - 2014-12-02 14:32 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-12-02 13:45 - 2014-10-14 13:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-12-02 13:45 - 2014-10-14 12:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-12-02 13:45 - 2014-06-03 21:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-12-02 13:45 - 2014-06-03 21:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-12-02 13:45 - 2014-06-03 21:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-12-02 13:45 - 2014-06-03 20:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-12-02 13:45 - 2014-06-03 20:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-12-02 13:45 - 2014-03-04 20:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-12-02 13:45 - 2014-03-04 20:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-12-02 13:45 - 2014-03-04 20:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-12-02 13:45 - 2014-03-04 20:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-12-02 13:45 - 2014-03-04 19:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-12-02 13:45 - 2014-03-04 19:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-12-02 13:45 - 2014-02-04 13:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-12-02 13:45 - 2014-02-04 13:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-12-02 13:45 - 2014-02-04 13:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-12-02 13:45 - 2014-02-04 13:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-12-02 13:45 - 2014-02-04 13:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-12-02 13:45 - 2013-08-28 12:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-12-02 13:45 - 2013-08-02 13:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-12-02 13:45 - 2013-08-02 11:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 11:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 11:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 11:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-12-02 13:45 - 2013-07-04 23:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-12-02 13:45 - 2013-07-04 23:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-12-02 13:45 - 2013-07-04 22:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-12-02 13:45 - 2013-07-04 22:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-12-02 13:45 - 2013-07-04 21:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-12-02 13:45 - 2013-02-27 16:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-12-02 13:45 - 2011-11-17 17:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-12-02 13:45 - 2011-11-17 16:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-12-02 13:45 - 2011-08-27 16:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-12-02 13:45 - 2011-08-27 15:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-12-02 13:45 - 2011-02-06 04:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-12-02 13:45 - 2011-02-06 04:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-12-02 13:45 - 2011-02-06 04:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-12-02 13:45 - 2011-02-06 04:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-12-02 13:45 - 2011-02-06 04:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-12-02 13:45 - 2011-02-06 04:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-12-02 13:45 - 2011-02-06 04:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-12-02 13:44 - 2014-08-21 17:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-12-02 13:44 - 2014-08-21 17:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-12-02 13:44 - 2014-08-21 17:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-12-02 13:44 - 2014-08-21 17:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-12-02 13:44 - 2013-10-12 13:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-12-02 13:44 - 2013-10-12 13:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-12-02 13:44 - 2013-10-12 13:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-12-02 13:44 - 2013-10-12 13:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-12-02 13:44 - 2013-10-12 13:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-12-02 13:44 - 2013-10-04 13:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-12-02 13:44 - 2013-10-04 13:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-12-02 13:44 - 2013-10-04 12:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2014-12-02 13:44 - 2013-10-04 12:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2014-12-02 13:44 - 2012-06-06 17:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-12-02 13:44 - 2012-06-06 16:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-12-02 13:44 - 2011-04-29 14:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-12-02 13:44 - 2011-04-29 14:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-12-02 13:44 - 2011-04-29 14:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-12-02 13:43 - 2014-08-12 13:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-12-02 13:43 - 2014-08-12 12:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-12-02 13:43 - 2014-06-16 13:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-12-02 13:43 - 2014-06-06 21:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-12-02 13:43 - 2014-06-06 20:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-12-02 13:43 - 2013-08-05 13:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-12-02 13:43 - 2013-06-06 16:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-12-02 13:43 - 2013-06-06 16:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-12-02 13:43 - 2013-06-06 16:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-12-02 13:43 - 2013-06-06 16:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-12-02 13:43 - 2013-06-06 15:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-12-02 13:43 - 2013-06-06 15:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-12-02 13:43 - 2013-06-06 15:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-12-02 13:43 - 2013-06-06 14:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-12-02 13:43 - 2013-06-06 14:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-12-02 13:43 - 2013-06-06 14:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-12-02 13:43 - 2013-04-26 16:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-12-02 13:43 - 2013-04-26 15:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-12-02 13:43 - 2013-04-10 17:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-12-02 13:43 - 2013-02-15 17:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-12-02 13:43 - 2013-02-15 17:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-12-02 13:43 - 2013-02-15 14:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-12-02 13:43 - 2012-05-05 19:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-12-02 13:43 - 2012-05-05 18:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-12-02 13:43 - 2011-10-26 16:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-12-02 13:43 - 2011-10-26 15:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-12-02 13:43 - 2011-08-17 16:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-12-02 13:43 - 2011-08-17 16:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-12-02 13:43 - 2011-08-17 15:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-12-02 13:43 - 2011-08-17 15:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-12-02 13:43 - 2011-06-15 21:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-12-02 13:43 - 2011-06-15 21:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-12-02 13:43 - 2011-06-15 21:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-12-02 13:43 - 2011-06-15 21:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-12-02 13:43 - 2011-02-03 22:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-12-02 13:42 - 2014-10-18 13:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-12-02 13:42 - 2014-10-18 12:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-12-02 13:42 - 2014-09-25 13:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-12-02 13:42 - 2014-09-25 12:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-12-02 13:42 - 2014-09-04 16:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-12-02 13:42 - 2014-09-04 16:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-12-02 13:42 - 2014-05-30 17:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-12-02 13:42 - 2014-04-25 13:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-12-02 13:42 - 2014-04-25 13:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-12-02 13:42 - 2014-01-29 13:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-12-02 13:42 - 2014-01-29 13:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-12-02 13:42 - 2014-01-28 13:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-12-02 13:42 - 2013-11-27 12:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-12-02 13:42 - 2013-11-27 12:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-12-02 13:42 - 2013-11-27 12:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-12-02 13:42 - 2013-11-27 12:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-12-02 13:42 - 2013-11-27 12:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-12-02 13:42 - 2013-10-12 13:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-12-02 13:42 - 2013-10-12 13:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-12-02 13:42 - 2013-10-12 13:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-12-02 13:42 - 2013-10-12 13:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-12-02 13:42 - 2013-10-12 12:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-12-02 13:42 - 2013-10-12 12:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-12-02 13:42 - 2013-10-12 12:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-12-02 13:42 - 2013-10-12 12:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-12-02 13:42 - 2013-07-20 21:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-12-02 13:42 - 2013-07-20 21:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-12-02 13:42 - 2013-07-12 21:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-12-02 13:42 - 2013-07-12 21:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-12-02 13:42 - 2013-07-03 15:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-12-02 13:42 - 2013-07-03 15:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-12-02 13:42 - 2013-03-19 16:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-12-02 13:42 - 2013-01-24 17:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-12-02 13:42 - 2012-05-14 16:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-12-02 13:42 - 2012-03-17 18:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-12-02 13:42 - 2011-12-16 19:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-12-02 13:42 - 2011-12-16 18:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-12-02 13:42 - 2011-07-09 13:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-12-02 13:42 - 2011-05-24 22:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-12-02 13:42 - 2011-05-24 21:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-12-02 13:42 - 2011-05-24 21:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-12-02 13:42 - 2011-05-24 21:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-12-02 13:42 - 2011-05-24 21:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-12-02 13:42 - 2011-04-27 13:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-12-02 13:42 - 2011-04-27 13:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-12-02 13:42 - 2011-03-03 17:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-12-02 13:42 - 2011-03-03 17:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-12-02 13:42 - 2011-03-03 17:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-12-02 13:42 - 2011-03-03 16:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-12-02 13:42 - 2011-03-03 16:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-12-02 13:42 - 2011-02-23 15:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-12-02 13:42 - 2011-02-12 22:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-12-02 13:41 - 2014-10-25 12:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-12-02 13:41 - 2014-10-25 12:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-12-02 13:41 - 2013-10-30 13:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-12-02 13:41 - 2013-10-30 13:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-12-02 13:41 - 2013-10-19 13:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-12-02 13:41 - 2013-10-19 12:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-12-02 13:41 - 2013-10-04 13:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-12-02 13:41 - 2013-10-04 12:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-12-02 13:41 - 2013-07-04 23:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-12-02 13:41 - 2013-07-04 22:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-12-02 13:41 - 2013-02-12 15:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-12-02 13:41 - 2012-11-23 14:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-12-02 13:41 - 2012-11-02 16:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-12-02 13:41 - 2012-11-02 16:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-12-02 13:41 - 2012-09-26 09:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-12-02 13:41 - 2012-09-26 09:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-12-02 13:41 - 2012-08-23 05:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-12-02 13:41 - 2012-07-05 09:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-12-02 13:41 - 2012-07-05 09:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-12-02 13:41 - 2012-07-05 09:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-12-02 13:41 - 2012-07-05 08:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-12-02 13:41 - 2012-07-05 08:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-12-02 13:41 - 2012-07-05 07:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-12-02 13:41 - 2012-05-01 16:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-12-02 13:41 - 2012-04-26 16:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-12-02 13:41 - 2012-04-26 16:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-12-02 13:41 - 2011-12-30 17:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-12-02 13:41 - 2011-12-30 16:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2014-12-02 13:41 - 2011-06-16 16:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2014-12-02 13:41 - 2011-06-16 15:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
2014-12-02 13:41 - 2011-05-03 16:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-12-02 13:41 - 2011-05-03 15:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-12-02 13:40 - 2011-02-18 21:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2014-12-02 13:40 - 2011-02-18 16:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2014-12-02 12:41 - 2014-12-15 21:36 - 00000000 ____D () C:\Users\debbie\Desktop\scanner
2014-12-02 12:15 - 2014-12-12 10:48 - 00000000 ____D () C:\Users\debbie\Desktop\Training Officer
2014-12-02 11:52 - 2014-12-17 13:32 - 00000000 ____D () C:\Users\debbie\Desktop\Mark worksheets
2014-12-02 11:52 - 2014-12-14 18:48 - 00000000 ____D () C:\Users\debbie\Desktop\Max work
2014-12-02 11:51 - 2014-12-10 10:59 - 00000000 ____D () C:\Users\debbie\Desktop\Job Applications
2014-12-02 11:50 - 2014-12-02 11:51 - 00000000 ____D () C:\Users\debbie\Desktop\Cert IV
2014-12-02 11:50 - 2014-12-02 11:50 - 00000000 ____D () C:\Users\debbie\AppData\Local\{B1323411-70A2-4BB9-80EB-DD9D355984B3}
2014-12-02 11:47 - 2014-12-09 20:50 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Canon
2014-12-02 11:46 - 2014-12-02 11:46 - 00000000 ___HD () C:\ProgramData\CanonIJEPPEX2
2014-12-02 11:46 - 2014-12-02 11:46 - 00000000 ___HD () C:\ProgramData\CanonEPP
2014-12-02 11:46 - 2014-12-02 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon IJ Network Utilities
2014-12-02 11:46 - 2014-12-02 11:46 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool
2014-12-02 11:45 - 2014-12-02 11:45 - 00000000 ____D () C:\ProgramData\CanonIJMSetup
2014-12-02 11:45 - 2014-12-02 11:45 - 00000000 ____D () C:\Program Files\Common Files\CANON
2014-12-02 11:45 - 2010-03-18 19:25 - 00307200 _____ (CANON INC.) C:\Windows\SysWOW64\CNC495L.dll
2014-12-02 11:45 - 2010-03-18 17:11 - 00106496 _____ (CANON INC.) C:\Windows\SysWOW64\CNC495U.dll
2014-12-02 11:45 - 2009-11-13 14:35 - 00012800 _____ () C:\Windows\SysWOW64\CNC1747D.TBL
2014-12-02 11:45 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2014-12-02 11:44 - 2014-12-02 11:44 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-12-02 11:43 - 2014-12-03 12:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-12-02 11:43 - 2014-12-02 11:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP495 series Manual
2014-12-02 11:43 - 2014-12-02 11:43 - 00000000 ____D () C:\Program Files\Canon
2014-12-02 11:42 - 2014-12-02 11:42 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2014-12-02 11:42 - 2014-12-02 11:42 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-12-02 11:42 - 2014-12-02 11:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP495 series
2014-12-02 11:42 - 2010-08-25 05:00 - 00361472 _____ (CANON INC.) C:\Windows\system32\CNMLMA9.DLL
2014-12-02 11:42 - 2010-03-11 19:57 - 00248320 _____ (CANON INC.) C:\Windows\system32\CNMIUA9.DLL
2014-12-02 11:41 - 2014-12-03 12:00 - 00000000 ____D () C:\Program Files (x86)\Canon
2014-12-02 11:41 - 2014-12-02 11:41 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-12-02 11:41 - 2014-12-02 11:41 - 00000000 ____D () C:\Windows\system32\STRING
2014-12-02 11:41 - 2010-02-05 21:37 - 00327680 _____ (CANON INC.) C:\Windows\system32\CNMN6PPM.DLL
2014-12-02 11:41 - 2010-02-05 21:37 - 00037376 _____ (CANON INC.) C:\Windows\system32\CNMN6UI.DLL
2014-12-02 11:20 - 2014-12-17 13:33 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\SoftGrid Client
2014-12-02 11:20 - 2014-12-13 22:44 - 00000000 ____D () C:\Users\debbie\AppData\Local\SoftGrid Client
2014-12-02 11:20 - 2014-12-03 11:39 - 00766566 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-12-02 11:20 - 2014-12-02 11:20 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-12-02 11:20 - 2014-12-02 11:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
2014-12-02 11:19 - 2014-12-03 07:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-12-02 11:19 - 2014-12-02 11:20 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\TP
2014-12-02 11:19 - 2014-12-02 11:19 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-12-02 10:55 - 2014-12-13 14:20 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-02 10:55 - 2014-12-12 23:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-02 10:43 - 2014-12-19 15:50 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-02 10:43 - 2014-12-19 12:42 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-02 10:43 - 2014-12-02 10:55 - 00000000 ____D () C:\Users\debbie\AppData\Local\Google
2014-12-02 10:43 - 2014-12-02 10:54 - 00000000 ____D () C:\Program Files (x86)\Google
2014-12-02 10:43 - 2014-12-02 10:43 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-12-02 10:43 - 2014-12-02 10:43 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-12-02 10:42 - 2014-12-02 10:43 - 00000000 ____D () C:\Users\debbie\AppData\Local\Deployment
2014-12-02 10:42 - 2014-12-02 10:42 - 00000000 ____D () C:\Users\debbie\AppData\Local\Apps\2.0
2014-12-02 09:56 - 2014-12-02 09:56 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\AVG2015
2014-12-02 09:55 - 2014-12-02 09:56 - 00000000 ____D () C:\ProgramData\AVG2015
2014-12-02 09:55 - 2014-12-02 09:55 - 00000965 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2014-12-02 09:55 - 2014-12-02 09:55 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\TuneUp Software
2014-12-02 09:55 - 2014-12-02 09:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-12-02 09:55 - 2014-12-02 09:55 - 00000000 ____D () C:\$AVG
2014-12-02 09:54 - 2014-12-02 09:54 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-12-02 09:36 - 2014-12-19 12:41 - 00000000 ____D () C:\ProgramData\MFAData
2014-12-02 09:36 - 2014-12-02 10:23 - 00000000 ____D () C:\Users\debbie\AppData\Local\Avg2015
2014-12-02 09:36 - 2014-12-02 09:36 - 00000000 ____D () C:\Users\debbie\AppData\Local\MFAData
2014-12-02 09:27 - 2012-02-17 17:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-12-02 09:27 - 2012-02-17 16:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-12-02 09:27 - 2012-02-17 15:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-12-02 09:25 - 2014-12-09 20:56 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Adobe
2014-12-02 09:25 - 2014-12-02 09:25 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Macromedia
2014-12-02 09:20 - 2014-12-18 21:20 - 00003220 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForDEBBIE-HP$
2014-12-02 09:20 - 2014-12-18 21:20 - 00000344 _____ () C:\Windows\Tasks\HPCeeScheduleForDEBBIE-HP$.job
2014-12-02 09:15 - 2014-12-02 09:15 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\ATI
2014-12-02 09:15 - 2014-12-02 09:15 - 00000000 ____D () C:\Users\debbie\AppData\Local\ATI
2014-12-02 09:14 - 2014-12-19 07:11 - 00003934 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{2306AC12-20CF-4890-9F68-79953A28AD4F}
2014-12-02 09:14 - 2014-12-18 09:14 - 00003192 _____ () C:\Windows\System32\Tasks\HPCeeScheduleFordebbie
2014-12-02 09:14 - 2014-12-18 09:14 - 00000336 _____ () C:\Windows\Tasks\HPCeeScheduleFordebbie.job
2014-12-02 09:14 - 2014-12-12 23:06 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\hpqLog
2014-12-02 09:14 - 2014-12-03 08:03 - 00001417 _____ () C:\Users\debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-02 09:14 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Synaptics
2014-12-02 09:14 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Intel Corporation
2014-12-02 09:14 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Local\RemEngine
2014-12-02 09:13 - 2014-12-02 19:14 - 00058016 _____ () C:\Users\debbie\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-02 09:10 - 2014-12-10 23:08 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Hewlett-Packard
2014-12-02 09:10 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Local\Hewlett-Packard_Company
2014-12-02 09:10 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Local\Hewlett-Packard
2014-12-02 09:10 - 2014-12-02 09:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music and Media
2014-12-02 09:10 - 2014-05-15 03:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-12-02 09:10 - 2014-05-15 03:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-12-02 09:10 - 2014-05-15 03:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-12-02 09:10 - 2014-05-15 03:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-12-02 09:10 - 2014-05-15 03:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-12-02 09:10 - 2011-06-25 10:58 - 00002177 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicStation.lnk
2014-12-02 09:09 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-12-02 09:09 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-12-02 09:09 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-12-02 09:09 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-12-02 09:08 - 2014-12-13 00:01 - 00000000 ____D () C:\Users\debbie
2014-12-02 09:08 - 2014-12-02 09:08 - 00000020 ___SH () C:\Users\debbie\ntuser.ini
2014-12-02 09:08 - 2014-12-02 09:08 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Intel
2014-12-02 09:08 - 2014-12-02 09:08 - 00000000 ____D () C:\Users\debbie\AppData\Local\VirtualStore
2014-12-02 09:08 - 2009-07-14 15:54 - 00000000 ___RD () C:\Users\debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-02 09:08 - 2009-07-14 15:49 - 00000000 ___RD () C:\Users\debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-12-19 15:56 - 2011-06-25 10:51 - 01706270 _____ () C:\Windows\WindowsUpdate.log
2014-12-18 06:29 - 2009-07-14 15:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-18 06:29 - 2009-07-14 15:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-18 06:28 - 2009-07-14 16:13 - 00782228 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-18 06:21 - 2009-07-14 16:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-18 06:21 - 2009-07-14 15:51 - 00056714 _____ () C:\Windows\setupact.log
2014-12-14 13:52 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\rescache
2014-12-14 07:33 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-13 18:05 - 2011-04-24 08:44 - 00000000 ____D () C:\ProgramData\WildTangent
2014-12-13 18:00 - 2011-04-24 08:44 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2014-12-13 17:56 - 2009-07-14 16:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-12-13 12:01 - 2009-07-14 16:08 - 00019694 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-12 23:57 - 2011-06-25 10:47 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-12-12 23:57 - 2011-04-24 08:49 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-12-12 23:57 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-12 23:57 - 2009-07-14 14:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-12-12 23:56 - 2011-04-24 08:58 - 00000000 ____D () C:\Windows\System32\Tasks\Hewlett-Packard
2014-12-12 23:56 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\registration
2014-12-12 23:56 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\Help
2014-12-12 23:55 - 2011-06-25 10:46 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-12-12 23:55 - 2011-04-24 08:55 - 00000000 ____D () C:\ProgramData\Adobe
2014-12-12 23:55 - 2011-04-24 08:50 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-12-12 23:55 - 2011-04-24 08:42 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-12-10 10:36 - 2010-11-21 14:47 - 00240414 _____ () C:\Windows\PFRO.log
2014-12-10 08:04 - 2009-07-14 13:34 - 00000215 _____ () C:\Windows\system.ini
2014-12-08 23:51 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-08 13:14 - 2009-07-14 16:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-12-03 13:41 - 2009-07-14 15:45 - 00268392 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-03 07:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-12-03 07:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-12-03 07:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-12-03 07:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-12-03 04:03 - 2009-07-14 16:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-12-03 04:03 - 2009-07-14 16:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-12-03 03:04 - 2007-01-02 12:25 - 00000000 ____D () C:\Windows\Panther
2014-12-02 18:59 - 2009-07-14 16:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-12-02 18:59 - 2009-07-14 16:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-12-02 18:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-12-02 18:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-12-02 18:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-12-02 11:45 - 2009-07-14 14:20 - 00000000 __RSD () C:\Windows\Media
2014-12-02 11:19 - 2011-04-24 08:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-12-02 09:19 - 2011-06-25 11:01 - 00000000 ____D () C:\ProgramData\Norton
2014-12-02 09:10 - 2011-04-24 08:56 - 00000000 ___RD () C:\Program Files\Online Services
2014-12-02 09:10 - 2011-04-24 08:50 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services
2014-12-02 09:10 - 2011-04-24 08:44 - 00000000 ___RD () C:\Program Files (x86)\Online Services
2014-12-02 09:10 - 2009-07-14 16:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-12-02 09:10 - 2009-07-14 16:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2014-12-02 09:09 - 2011-02-11 06:23 - 00000000 ____D () C:\SYSTEM.SAV
2014-12-02 09:09 - 2011-02-11 06:23 - 00000000 ____D () C:\SWSetup
2014-12-02 09:09 - 2009-07-14 16:32 - 00000000 ____D () C:\Windows\system32\restore
2014-12-02 09:09 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\Recovery
2014-12-02 09:09 - 2007-01-02 12:32 - 00000000 ____D () C:\Recovery
2014-12-02 09:07 - 2009-07-14 14:20 - 00000000 __RHD () C:\Users\Public\Libraries
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-12-15 14:48
 
==================== End Of Log ============================


#10 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 19 December 2014 - 09:15 AM

# AdwCleaner v4.105 - Report created 20/12/2014 at 00:34:53
# Updated 08/12/2014 by Xplode
# Database : 2014-12-16.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : debbie - DEBBIE-HP
# Running from : C:\Users\debbie\Downloads\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
 
***** [ Scheduled Tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17496
 
 
-\\ Google Chrome v39.0.2171.95
 
 
*************************
 
AdwCleaner[R0].txt - [1538 octets] - [20/12/2014 00:32:44]
AdwCleaner[S0].txt - [1449 octets] - [20/12/2014 00:34:53]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1509 octets] ##########


#11 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 19 December 2014 - 09:17 AM

Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Home Premium x64
Ran by debbie on Sat 20/12/2014 at  0:44:14.55
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\debbie\appdata\local\{0FB2EC8F-25F7-47AF-847C-768D717462D6}
Successfully deleted: [Empty Folder] C:\Users\debbie\appdata\local\{B1323411-70A2-4BB9-80EB-DD9D355984B3}
Successfully deleted: [Empty Folder] C:\Users\debbie\appdata\local\{EE5C689F-B943-4055-AB93-60209DE73A16}
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 20/12/2014 at  0:47:53.73
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

MiniToolBox by Farbar  Version: 30-11-2014
Ran by debbie (administrator) on 20-12-2014 at 00:50:39
Running from "C:\Users\debbie\Downloads"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= IP Configuration: ================================
 
Intel® Centrino® Wireless-N 1030 = Wireless Network Connection (Connected)
Realtek PCIe GBE Family Controller = Local Area Connection (Media disconnected)
Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected)
Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 3 (Media disconnected)
 
 
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
add route prefix=169.254.0.0/16 interface="iftype0_0" nexthop=192.168.2.5 metric=1 publish=Yes
 
 
popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : debbie-HP
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : Belkin
 
Wireless LAN adapter Wireless Network Connection 3:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter #2
   Physical Address. . . . . . . . . : BC-77-37-8B-85-E0
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Wireless Network Connection 2:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter
   Physical Address. . . . . . . . . : BC-77-37-8B-85-E0
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Wireless Network Connection:
 
   Connection-specific DNS Suffix  . : Belkin
   Description . . . . . . . . . . . : Intel® Centrino® Wireless-N 1030
   Physical Address. . . . . . . . . : BC-77-37-8B-85-DF
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::b57d:804:7e67:d090%15(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.2.5(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Saturday, 20 December 2014 12:36:58 AM
   Lease Expires . . . . . . . . . . : Tuesday, 26 January 2151 7:19:02 AM
   Default Gateway . . . . . . . . . : 192.168.2.1
   DHCP Server . . . . . . . . . . . : 192.168.2.1
   DHCPv6 IAID . . . . . . . . . . . : 381450039
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-96-DB-42-2C-27-D7-AD-0A-67
   DNS Servers . . . . . . . . . . . : 192.168.2.1
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Ethernet adapter Local Area Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : 2C-27-D7-AD-0A-67
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Local Area Connection* 11:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.Belkin:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : Belkin
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Teredo Tunneling Pseudo-Interface:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2001:0:9d38:6ab8:1805:ae7:9150:51b8(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::1805:ae7:9150:51b8%18(Preferred) 
   Default Gateway . . . . . . . . . : ::
   NetBIOS over Tcpip. . . . . . . . : Disabled
Server:  router
Address:  192.168.2.1
 
Name:    google.com
Addresses:  2404:6800:4006:805::1001
 74.125.237.168
 74.125.237.169
 74.125.237.165
 74.125.237.160
 74.125.237.174
 74.125.237.167
 74.125.237.162
 74.125.237.164
 74.125.237.166
 74.125.237.161
 74.125.237.163
 
 
Pinging google.com [74.125.237.168] with 32 bytes of data:
Reply from 74.125.237.168: bytes=32 time=22ms TTL=57
Reply from 74.125.237.168: bytes=32 time=21ms TTL=57
 
Ping statistics for 74.125.237.168:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 21ms, Maximum = 22ms, Average = 21ms
Server:  router
Address:  192.168.2.1
 
Name:    yahoo.com
Addresses:  98.139.183.24
 98.138.253.109
 206.190.36.45
 
 
Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=255ms TTL=44
Reply from 98.139.183.24: bytes=32 time=259ms TTL=44
 
Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 255ms, Maximum = 259ms, Average = 257ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 17...bc 77 37 8b 85 e0 ......Microsoft Virtual WiFi Miniport Adapter #2
 16...bc 77 37 8b 85 e0 ......Microsoft Virtual WiFi Miniport Adapter
 15...bc 77 37 8b 85 df ......Intel® Centrino® Wireless-N 1030
 13...2c 27 d7 ad 0a 67 ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 14...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 21...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
 18...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.2.1      192.168.2.5     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      169.254.0.0      255.255.0.0         On-link       192.168.2.5     26
  169.254.255.255  255.255.255.255         On-link       192.168.2.5    281
      192.168.2.0    255.255.255.0         On-link       192.168.2.5    281
      192.168.2.5  255.255.255.255         On-link       192.168.2.5    281
    192.168.2.255  255.255.255.255         On-link       192.168.2.5    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link       192.168.2.5    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link       192.168.2.5    281
===========================================================================
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
      169.254.0.0      255.255.0.0      192.168.2.5       1
===========================================================================
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 18     58 ::/0                     On-link
  1    306 ::1/128                  On-link
 18     58 2001::/32                On-link
 18    306 2001:0:9d38:6ab8:1805:ae7:9150:51b8/128
                                    On-link
 15    281 fe80::/64                On-link
 18    306 fe80::/64                On-link
 18    306 fe80::1805:ae7:9150:51b8/128
                                    On-link
 15    281 fe80::b57d:804:7e67:d090/128
                                    On-link
  1    306 ff00::/8                 On-link
 18    306 ff00::/8                 On-link
 15    281 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
 
**** End of log ****


#12 OCD

OCD

  • Malware Response Team
  • 172 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:05:04 AM

Posted 19 December 2014 - 10:27 AM

Hi bellagirl,

Kindly post all logs requested into one reply (if they will fit).

Please locate the ComboFix log and post it. C:\ComboFix.txt

Thank you for the FRST log you posted, but it is the orginal FRST log. Please run FRST again to generate a new log.

bullseye_zpse9eaf36e.gif Re-run Farbar Recovery Scan Tool it should be on your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
=========================

In your next post please provide the following:
  • FRST.txt
  • Any change in performance?

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days

#13 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 19 December 2014 - 04:35 PM

this is the only combofix.txt that i have:

ComboFix 14-12-08.01 - debbie 10/12/2014   7:57.1.8 - x64

Microsoft Windows 7 Home Premium   6.1.7601.1.1252.61.1033.18.4044.1801 [GMT 11:00]
Running from: c:\users\debbie\Downloads\ComboFix.exe
AV: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
.
.
(((((((((((((((((((((((((   Files Created from 2014-11-09 to 2014-12-09  )))))))))))))))))))))))))))))))
.
.
2014-12-09 21:04 . 2014-12-09 21:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-12-09 09:50 . 2014-12-09 09:50 -------- d--h--w- c:\programdata\CanonIJScan
2014-12-03 00:36 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2014-12-03 00:36 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2014-12-02 23:35 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
2014-12-02 23:35 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
2014-12-02 23:19 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2014-12-02 23:19 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2014-12-02 23:14 . 2014-06-24 03:29 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-12-02 23:14 . 2014-06-24 02:59 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-12-02 23:12 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDYAK.DLL
2014-12-02 23:12 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDTAT.DLL
2014-12-02 23:12 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDRU1.DLL
2014-12-02 23:12 . 2014-07-09 02:03 6656 ----a-w- c:\windows\system32\KBDRU.DLL
2014-12-02 23:12 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDBASH.DLL
2014-12-02 23:12 . 2014-07-09 01:31 7168 ----a-w- c:\windows\SysWow64\KBDYAK.DLL
2014-12-02 23:12 . 2014-07-09 01:31 6656 ----a-w- c:\windows\SysWow64\KBDBASH.DLL
2014-12-02 23:12 . 2014-11-06 03:20 968704 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-12-02 21:48 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-12-02 21:48 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-12-02 20:54 . 2014-12-02 20:54 -------- d-----w- c:\program files (x86)\Microsoft.NET
2014-12-02 20:54 . 2014-12-02 20:54 -------- d-----w- c:\windows\Migration
2014-12-02 20:53 . 2013-10-14 07:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2014-12-02 20:34 . 2014-12-02 20:34 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-02 20:30 . 2014-12-02 20:30 -------- d-----w- c:\program files\Microsoft Silverlight
2014-12-02 20:30 . 2014-12-02 20:30 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
2014-12-02 20:26 . 2014-12-02 20:29 -------- d-----w- c:\windows\system32\MRT
2014-12-02 20:23 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
2014-12-02 20:23 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
2014-12-02 20:23 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
2014-12-02 20:23 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
2014-12-02 20:23 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
2014-12-02 20:23 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
2014-12-02 20:23 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
2014-12-02 20:23 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
2014-12-02 19:36 . 2014-07-17 02:07 3722240 ----a-w- c:\windows\system32\mstscax.dll
2014-12-02 19:36 . 2014-07-17 01:39 3221504 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-12-02 19:36 . 2014-07-17 02:07 235520 ----a-w- c:\windows\system32\winsta.dll
2014-12-02 19:36 . 2014-07-17 02:07 150528 ----a-w- c:\windows\system32\rdpcorekmts.dll
2014-12-02 19:36 . 2014-07-17 02:07 455168 ----a-w- c:\windows\system32\winlogon.exe
2014-12-02 19:36 . 2014-07-17 02:07 1118720 ----a-w- c:\windows\system32\mstsc.exe
2014-12-02 19:36 . 2014-07-17 01:40 157696 ----a-w- c:\windows\SysWow64\winsta.dll
2014-12-02 19:36 . 2014-07-17 01:39 131584 ----a-w- c:\windows\SysWow64\aaclient.dll
2014-12-02 19:36 . 2014-07-17 01:39 1051136 ----a-w- c:\windows\SysWow64\mstsc.exe
2014-12-02 19:36 . 2014-07-17 01:21 212480 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-12-02 19:36 . 2014-07-17 01:21 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
2014-12-02 19:32 . 2013-05-13 05:50 52224 ----a-w- c:\windows\system32\certenc.dll
2014-12-02 19:32 . 2013-05-13 03:43 1192448 ----a-w- c:\windows\system32\certutil.exe
2014-12-02 19:32 . 2013-05-13 03:08 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2014-12-02 19:32 . 2013-05-13 03:08 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2014-12-02 19:31 . 2014-08-01 11:53 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-12-02 19:31 . 2014-08-01 11:35 793600 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-12-02 19:31 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2014-12-02 19:31 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2014-12-02 19:13 . 2014-12-02 19:13 -------- d-----w- c:\windows\SysWow64\Wat
2014-12-02 19:13 . 2014-12-02 19:13 -------- d-----w- c:\windows\system32\Wat
2014-12-02 09:31 . 2014-12-02 09:31 -------- d-----r- C:\MSOCache
2014-12-02 09:28 . 2014-12-02 09:28 -------- d-----w- c:\programdata\Microsoft Help
2014-12-02 07:59 . 2014-12-02 07:59 -------- d-s---w- c:\windows\system32\CompatTel
2014-12-02 06:59 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2014-12-02 06:59 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2014-12-02 06:59 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2014-12-02 06:59 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2014-12-02 06:59 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2014-12-02 04:12 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2014-12-02 03:42 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-12-02 03:42 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-12-02 03:42 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2014-12-02 03:42 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-12-02 03:42 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-12-02 03:42 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-12-02 03:42 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2014-12-02 03:36 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-12-02 03:36 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-12-02 03:36 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-12-02 03:07 . 2013-12-04 02:16 658432 ----a-w- c:\windows\system32\RMActivate_isv.exe
2014-12-02 03:06 . 2014-11-05 17:56 304640 ----a-w- c:\windows\system32\generaltel.dll
2014-12-02 03:06 . 2014-11-05 17:56 228864 ----a-w- c:\windows\system32\aepdu.dll
2014-12-02 03:06 . 2014-11-05 17:52 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-12-02 02:57 . 2014-10-14 02:13 683520 ----a-w- c:\windows\system32\termsrv.dll
2014-12-02 02:57 . 2014-10-14 02:07 681984 ----a-w- c:\windows\system32\adtschema.dll
2014-12-02 02:57 . 2014-10-14 01:46 681984 ----a-w- c:\windows\SysWow64\adtschema.dll
2014-12-02 02:57 . 2014-10-14 02:09 146432 ----a-w- c:\windows\system32\msaudite.dll
2014-12-02 02:57 . 2014-10-14 01:47 146432 ----a-w- c:\windows\SysWow64\msaudite.dll
2014-12-02 02:56 . 2013-07-26 02:24 197120 ----a-w- c:\windows\system32\shdocvw.dll
2014-12-02 02:55 . 2013-08-29 02:16 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-12-02 02:55 . 2013-08-29 02:16 859648 ----a-w- c:\windows\system32\tdh.dll
2014-12-02 02:55 . 2013-08-29 02:13 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-12-02 02:55 . 2013-08-29 01:50 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-12-02 02:55 . 2013-08-29 01:50 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-12-02 02:55 . 2013-08-29 01:48 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-12-02 02:55 . 2014-06-03 10:02 1354240 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-12-02 02:55 . 2014-06-03 09:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-12-02 02:54 . 2013-07-04 12:18 458712 ----a-w- c:\windows\system32\drivers\cng.sys
2014-12-02 02:52 . 2012-12-07 11:20 43520 ----a-w- c:\windows\system32\csrr.rs
2014-12-02 02:51 . 2012-10-09 18:17 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2014-12-02 02:51 . 2012-10-09 18:17 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2014-12-02 02:51 . 2012-10-09 17:40 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2014-12-02 02:51 . 2012-10-09 17:40 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2014-12-02 02:51 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-12-02 02:51 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-12-02 02:51 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
2014-12-02 02:51 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll
2014-12-02 02:51 . 2010-12-23 05:54 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2014-12-02 02:51 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax
2014-12-02 02:51 . 2010-12-23 05:54 850944 ----a-w- c:\windows\SysWow64\sbe.dll
2014-12-02 02:51 . 2010-12-23 05:50 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
2014-12-02 02:50 . 2013-09-08 02:27 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-12-02 02:50 . 2013-09-08 02:03 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-12-02 02:50 . 2014-09-09 22:11 2048 ----a-w- c:\windows\system32\tzres.dll
2014-12-02 02:50 . 2014-09-09 21:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-12-02 02:50 . 2014-01-24 02:37 1684928 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-12-02 02:48 . 2014-10-10 00:57 3198976 ----a-w- c:\windows\system32\win32k.sys
2014-12-02 02:48 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2014-12-02 02:48 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2014-12-02 02:48 . 2014-06-18 02:19 449024 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-12-02 02:48 . 2014-06-18 02:18 692736 ----a-w- c:\windows\system32\osk.exe
2014-12-02 02:48 . 2014-06-18 01:51 646144 ----a-w- c:\windows\SysWow64\osk.exe
2014-12-02 02:48 . 2014-06-25 02:05 14175744 ----a-w- c:\windows\system32\shell32.dll
2014-12-02 02:48 . 2014-08-23 02:07 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-12-02 02:48 . 2014-08-23 01:45 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-12-02 02:46 . 2013-10-05 20:25 1474048 ----a-w- c:\windows\system32\crypt32.dll
2014-12-02 02:45 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys
2014-12-02 02:44 . 2012-06-06 06:05 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2014-12-02 02:43 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-12-01 22:09 . 2010-06-24 18:33 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-10-29 10:35 . 2014-10-29 10:35 263960 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2014-10-10 03:14 . 2014-10-10 03:14 274200 ----a-w- c:\windows\system32\drivers\avgtdia.sys
2014-10-05 09:41 . 2014-10-05 09:41 124184 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-01-13 283160]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-15 336384]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-02-15 94264]
"HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2010-11-09 586296]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-16 35736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-16 932288]
"HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-01-27 318520]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"AVG_UI"="c:\program files (x86)\AVG\AVG2015\avgui.exe" [2014-11-09 3653136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
R3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
R4 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
R4 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsdrivera.sys [x]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 FPLService;TrueSuiteService;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe [x]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 hpCMSrv;HP Connection Manager 4.0 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-12-01 23:54 1087304 ----a-w- c:\program files (x86)\Google\Chrome\Application\39.0.2171.71\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-12-01 23:43]
.
2014-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-12-01 23:43]
.
2014-12-05 c:\windows\Tasks\HPCeeScheduleForDEBBIE-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
2014-12-09 c:\windows\Tasks\HPCeeScheduleFordebbie.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-27 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-27 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-27 418328]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-03-11 1128448]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-02-04 1933584]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-01-24 10355200]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-{E92D47A1-D27D-430A-8368-0BAFD956507D} - c:\program files (x86)\InstallShield Installation Information\{E92D47A1-D27D-430A-8368-0BAFD956507D}\setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-12-10  08:06:29
ComboFix-quarantined-files.txt  2014-12-09 21:06
.
Pre-Run: 571,631,603,712 bytes free
Post-Run: 571,176,128,512 bytes free
.
- - End Of File - - 89AF611C4EC22C5E67B864293E1BE520
 
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-12-2014
Ran by debbie (administrator) on DEBBIE-HP on 20-12-2014 08:24:29
Running from C:\Users\debbie\Downloads
Loaded Profile: debbie (Available profiles: debbie)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPConnectionManager.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-03-11] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-17] (Synaptics Incorporated)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2011-02-05] (Intel® Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-13] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-16] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-18] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [94264 2011-02-16] (Hewlett-Packard Development Company L.P.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [586296 2010-11-10] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [318520 2011-01-28] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [249064 2010-10-30] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3653136 2014-11-09] (AVG Technologies CZ, s.r.o.)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-12-16] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.jp.msn.com/HPALL/14
HKU\S-1-5-21-4131636085-3478570718-1191354020-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-4131636085-3478570718-1191354020-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/5221-111072-7833-3/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
 
Chrome: 
=======
CHR Profile: C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-02]
CHR Extension: (Website Logon) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeildmfnnehghlknddebgjghlompfe [2014-12-02]
CHR Extension: (Google Docs) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-02]
CHR Extension: (Google Drive) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-02]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-02]
CHR Extension: (YouTube) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-02]
CHR Extension: (Google Search) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-02]
CHR Extension: (Google Sheets) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-02]
CHR Extension: (BMI Calculator and Weight Tracker) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcfnndhdcbgbkcecgkafjdgonpmlnpof [2014-12-02]
CHR Extension: (Google Wallet) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-02]
CHR Extension: (Gmail) - C:\Users\debbie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-02]
CHR HKLM-x32\...\Chrome\Extension: [aepeildmfnnehghlknddebgjghlompfe] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-02-11]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3488784 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-11-09] (AVG Technologies CZ, s.r.o.)
S4 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [901184 2011-01-25] (Intel Corporation) [File not signed]
S4 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2011-01-25] (Intel Corporation) [File not signed]
S4 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [991296 2011-01-25] (Intel Corporation) [File not signed]
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-11-20] (WildTangent)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-02-05] ()
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [263960 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-12-20 00:51 - 2014-12-20 00:51 - 00009723 _____ () C:\Users\debbie\Desktop\Result.txt
2014-12-20 00:50 - 2014-12-20 00:50 - 00009723 _____ () C:\Users\debbie\Downloads\Result.txt
2014-12-20 00:49 - 2014-12-20 00:49 - 00401920 _____ (Farbar) C:\Users\debbie\Downloads\MiniToolBox.exe
2014-12-20 00:47 - 2014-12-20 00:47 - 00001105 _____ () C:\Users\debbie\Desktop\JRT.txt
2014-12-20 00:44 - 2014-12-20 00:44 - 00000000 ____D () C:\Windows\ERUNT
2014-12-20 00:42 - 2014-12-20 00:42 - 01707646 _____ (Thisisu) C:\Users\debbie\Downloads\JRT.exe
2014-12-20 00:37 - 2014-12-20 00:37 - 00001613 _____ () C:\Users\debbie\Desktop\AdwCleaner[S0].txt
2014-12-20 00:32 - 2014-12-20 00:34 - 00000000 ____D () C:\AdwCleaner
2014-12-20 00:30 - 2014-12-20 00:30 - 02166272 _____ () C:\Users\debbie\Downloads\AdwCleaner.exe
2014-12-20 00:03 - 2014-12-20 00:03 - 00000688 _____ () C:\Users\debbie\Desktop\fixlist.txt.txt
2014-12-19 16:16 - 2014-12-19 16:16 - 00027980 _____ () C:\Users\debbie\Desktop\Addition.txt
2014-12-19 16:09 - 2014-12-19 16:09 - 00123601 _____ () C:\Users\debbie\Desktop\FRST.txt
2014-12-19 16:04 - 2014-12-19 16:05 - 00027980 _____ () C:\Users\debbie\Downloads\Addition.txt
2014-12-19 16:02 - 2014-12-20 08:24 - 00017216 _____ () C:\Users\debbie\Downloads\FRST.txt
2014-12-19 16:02 - 2014-12-20 08:24 - 00000000 ____D () C:\FRST
2014-12-19 16:02 - 2014-12-19 16:02 - 00001435 _____ () C:\Users\debbie\Desktop\FRST - Shortcut.lnk
2014-12-19 16:01 - 2014-12-19 16:02 - 00001455 _____ () C:\Users\debbie\Desktop\FRST64 - Shortcut.lnk
2014-12-19 16:00 - 2014-12-19 16:01 - 02121216 _____ (Farbar) C:\Users\debbie\Downloads\FRST64.exe
2014-12-19 16:00 - 2014-12-19 16:00 - 01113600 _____ (Farbar) C:\Users\debbie\Downloads\FRST.exe
2014-12-19 15:57 - 2014-12-19 15:57 - 00001995 _____ () C:\Users\debbie\Desktop\aswMBR.txt
2014-12-19 15:57 - 2014-12-19 15:57 - 00000512 _____ () C:\Users\debbie\Desktop\MBR.dat
2014-12-19 15:19 - 2014-12-19 15:19 - 00001455 _____ () C:\Users\debbie\Desktop\aswMBR - Shortcut.lnk
2014-12-19 15:17 - 2014-12-19 15:19 - 05198336 _____ (AVAST Software) C:\Users\debbie\Downloads\aswMBR.exe
2014-12-19 15:12 - 2014-12-19 15:12 - 00001097 _____ () C:\Users\debbie\Desktop\SecurityCheck - Shortcut.lnk
2014-12-19 15:11 - 2014-12-19 15:11 - 00001075 _____ () C:\Users\debbie\Downloads\SecurityCheck - Shortcut.lnk
2014-12-19 15:04 - 2014-12-19 15:04 - 00852505 _____ () C:\Users\debbie\Downloads\SecurityCheck.exe
2014-12-18 09:24 - 2014-12-18 09:24 - 00010793 _____ () C:\Users\debbie\Desktop\Attach2.txt
2014-12-18 09:03 - 2014-12-18 09:03 - 00688992 ____R (Swearware) C:\Users\debbie\Downloads\dds (2).com
2014-12-18 09:00 - 2014-12-18 09:00 - 00688992 ____R (Swearware) C:\Users\debbie\Downloads\dds (1).com
2014-12-18 07:58 - 2014-12-18 07:58 - 00002660 _____ () C:\Users\debbie\Downloads\this_message_in_html.html
2014-12-13 22:44 - 2014-12-13 22:44 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\{90140011-0066-0409-0000-0000000FF1CE}
2014-12-13 22:43 - 2014-12-13 22:43 - 00000000 ____D () C:\ProgramData\Virtualized Applications
2014-12-13 18:00 - 2014-12-13 18:00 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\WildTangent
2014-12-13 18:00 - 2014-12-13 18:00 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-12-13 17:56 - 2014-12-13 17:56 - 00002444 _____ () C:\Users\Public\Desktop\WildTangent Games App - hp.lnk
2014-12-13 17:53 - 2014-12-13 18:40 - 00000000 ____D () C:\Users\debbie\AppData\Local\Microsoft Games
2014-12-13 13:15 - 2014-11-27 12:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-13 13:15 - 2014-11-27 12:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-13 13:15 - 2014-11-22 14:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-13 13:15 - 2014-11-22 14:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-13 13:15 - 2014-11-22 14:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-13 13:15 - 2014-11-22 13:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-13 13:15 - 2014-11-22 13:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-13 13:15 - 2014-11-22 13:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-13 13:15 - 2014-11-22 13:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-13 13:15 - 2014-11-22 13:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-13 13:15 - 2014-11-22 13:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-13 13:15 - 2014-11-22 13:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-13 13:15 - 2014-11-22 13:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-13 13:15 - 2014-11-22 13:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-13 13:15 - 2014-11-22 13:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-13 13:15 - 2014-11-22 13:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-13 13:15 - 2014-11-22 13:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-13 13:15 - 2014-11-22 13:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-13 13:15 - 2014-11-22 13:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-13 13:15 - 2014-11-22 13:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-13 13:15 - 2014-11-22 13:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-13 13:15 - 2014-11-22 13:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-13 13:15 - 2014-11-22 13:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-13 13:15 - 2014-11-22 13:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-13 13:15 - 2014-11-22 13:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-13 13:15 - 2014-11-22 13:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-13 13:15 - 2014-11-22 13:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-13 13:15 - 2014-11-22 13:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-13 13:15 - 2014-11-22 13:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-13 13:15 - 2014-11-22 13:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-13 13:15 - 2014-11-22 12:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-13 13:15 - 2014-11-22 12:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-13 13:15 - 2014-11-22 12:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-13 13:15 - 2014-11-22 12:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-13 13:15 - 2014-11-22 12:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-13 13:15 - 2014-11-22 12:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-13 13:15 - 2014-11-22 12:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-13 13:15 - 2014-11-22 12:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-13 13:15 - 2014-11-22 12:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-13 13:15 - 2014-11-22 12:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-13 13:15 - 2014-11-22 12:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-13 13:15 - 2014-11-22 12:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-13 13:15 - 2014-11-22 12:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-13 13:15 - 2014-11-22 12:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-13 13:15 - 2014-11-22 12:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-13 13:15 - 2014-11-22 12:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-13 13:15 - 2014-11-22 12:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-13 13:15 - 2014-11-22 12:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-13 13:15 - 2014-11-22 12:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-13 13:15 - 2014-11-22 12:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-13 13:15 - 2014-11-22 12:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-13 13:15 - 2014-11-22 12:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-13 13:15 - 2014-11-22 12:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-13 13:15 - 2014-11-22 12:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-13 13:15 - 2014-11-22 11:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-13 13:15 - 2014-11-22 11:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-13 08:11 - 2014-12-18 09:04 - 00035678 _____ () C:\Users\debbie\Desktop\dds.txt
2014-12-13 08:11 - 2014-12-18 09:04 - 00010793 _____ () C:\Users\debbie\Desktop\attach.txt
2014-12-13 08:08 - 2014-12-13 08:08 - 00688992 ____R (Swearware) C:\Users\debbie\Downloads\dds.com
2014-12-12 23:34 - 2014-12-12 23:34 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\InstallShield
2014-12-10 10:36 - 2014-12-10 10:36 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-10 09:44 - 2014-10-18 13:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-10 09:44 - 2014-10-18 12:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-10 09:44 - 2014-07-07 13:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-10 09:44 - 2014-07-07 13:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-10 09:44 - 2014-07-07 13:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-10 09:44 - 2014-07-07 13:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-10 09:44 - 2014-07-07 12:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-10 09:44 - 2014-07-07 12:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-10 09:44 - 2014-07-07 12:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-10 09:44 - 2014-07-07 12:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-10 08:06 - 2014-12-10 08:06 - 00027117 _____ () C:\ComboFix.txt
2014-12-10 07:55 - 2014-12-10 08:06 - 00000000 ____D () C:\Qoobox
2014-12-10 07:55 - 2014-12-10 08:04 - 00000000 ____D () C:\Windows\erdnt
2014-12-10 07:55 - 2011-06-26 17:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-10 07:55 - 2010-11-08 04:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-10 07:55 - 2009-04-20 15:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-10 07:55 - 2000-08-31 11:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-10 07:52 - 2014-12-10 07:54 - 05601243 ____R (Swearware) C:\Users\debbie\Downloads\ComboFix.exe
2014-12-10 07:13 - 2014-12-04 13:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-10 07:13 - 2014-12-04 13:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-10 07:13 - 2014-12-04 13:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-10 07:13 - 2014-12-02 10:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-10 07:06 - 2014-11-11 14:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 07:06 - 2014-11-11 13:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 07:06 - 2014-11-11 12:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-10 07:00 - 2014-10-30 13:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-10 07:00 - 2014-10-30 12:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-10 07:00 - 2014-10-03 13:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-10 07:00 - 2014-10-03 13:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 07:00 - 2014-10-03 13:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-10 07:00 - 2014-10-03 13:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-10 07:00 - 2014-10-03 13:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 07:00 - 2014-10-03 12:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-10 07:00 - 2014-10-03 12:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 07:00 - 2014-10-03 12:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-10 07:00 - 2014-10-03 12:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-10 07:00 - 2014-10-03 12:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-10 06:59 - 2014-11-08 14:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-10 06:59 - 2014-11-08 13:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-09 20:56 - 2014-12-09 20:56 - 00000000 ____D () C:\Users\debbie\AppData\Local\Adobe
2014-12-09 20:50 - 2014-12-09 20:50 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2014-12-08 18:39 - 2014-12-08 18:39 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\IDT
2014-12-08 11:11 - 2014-12-08 11:12 - 00262144 _____ () C:\Windows\Minidump\120814-52151-01.dmp
2014-12-08 11:11 - 2014-12-08 11:11 - 481596912 _____ () C:\Windows\MEMORY.DMP
2014-12-08 11:11 - 2014-12-08 11:11 - 00000000 ____D () C:\Windows\Minidump
2014-12-08 11:08 - 2014-12-08 11:08 - 00000000 __SHD () C:\Users\debbie\AppData\Local\EmieUserList
2014-12-08 11:08 - 2014-12-08 11:08 - 00000000 __SHD () C:\Users\debbie\AppData\Local\EmieSiteList
2014-12-08 11:08 - 2014-12-08 11:08 - 00000000 __SHD () C:\Users\debbie\AppData\Local\EmieBrowserModeList
2014-12-07 13:00 - 2014-12-07 13:00 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-12-05 10:52 - 2014-12-05 10:52 - 00002461 _____ () C:\Users\debbie\Desktop\Microsoft Word Starter 2010.lnk
2014-12-04 01:47 - 2014-12-17 23:01 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-12-03 11:36 - 2014-06-27 13:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-12-03 11:36 - 2014-06-27 12:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-12-03 10:35 - 2011-02-25 17:19 - 02871808 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-12-03 10:35 - 2011-02-25 16:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-12-03 10:19 - 2013-11-24 05:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-12-03 10:19 - 2013-11-24 04:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-12-03 10:14 - 2014-06-24 14:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-12-03 10:14 - 2014-06-24 13:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-12-03 10:12 - 2014-07-09 13:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-12-03 10:12 - 2014-07-09 13:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-12-03 10:12 - 2014-07-09 13:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-12-03 10:12 - 2014-07-09 13:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-12-03 10:12 - 2014-07-09 13:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-12-03 10:12 - 2014-07-09 12:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-12-03 10:12 - 2014-07-09 09:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-12-03 10:12 - 2014-07-09 09:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-12-03 08:48 - 2013-11-26 19:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-12-03 08:48 - 2013-11-23 09:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-12-03 08:46 - 2012-07-07 07:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2014-12-03 08:46 - 2012-02-11 17:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-12-03 08:46 - 2012-02-11 17:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2014-12-03 08:46 - 2011-04-28 14:54 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2014-12-03 08:46 - 2011-03-11 17:41 - 00410496 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2014-12-03 08:46 - 2011-03-11 17:41 - 00166272 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2014-12-03 08:46 - 2011-03-11 17:41 - 00148352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2014-12-03 08:46 - 2011-03-11 17:41 - 00107904 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2014-12-03 08:46 - 2011-03-11 17:41 - 00027008 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2014-12-03 08:46 - 2011-03-11 17:33 - 02565632 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2014-12-03 08:46 - 2011-03-11 17:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2014-12-03 08:46 - 2011-03-11 16:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2014-12-03 08:46 - 2011-03-11 16:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fsutil.exe
2014-12-03 08:46 - 2011-03-11 15:37 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-12-03 07:53 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2014-12-03 07:50 - 2014-12-03 07:50 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-12-03 07:50 - 2014-12-03 07:50 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-12-03 07:50 - 2014-12-03 07:50 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-12-03 07:50 - 2014-12-03 07:50 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-12-03 07:50 - 2014-12-03 07:50 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-12-03 07:50 - 2014-12-03 07:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-12-03 07:50 - 2014-12-03 07:50 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-12-03 07:50 - 2014-12-03 07:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-12-03 07:50 - 2014-12-03 07:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-12-03 07:34 - 2014-12-03 07:34 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-12-03 07:34 - 2014-12-03 07:34 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-12-03 07:32 - 2014-12-03 07:53 - 00009225 _____ () C:\Windows\IE11_main.log
2014-12-03 07:31 - 2014-12-14 14:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-03 07:30 - 2014-12-14 17:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-03 07:30 - 2014-12-14 17:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-03 07:26 - 2014-12-10 09:49 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-03 07:26 - 2014-12-10 09:45 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-03 07:23 - 2014-07-01 09:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-12-03 07:23 - 2014-07-01 09:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-12-03 07:23 - 2014-06-06 17:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-12-03 07:23 - 2014-06-06 17:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-12-03 07:23 - 2014-03-10 08:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-12-03 07:23 - 2014-03-10 08:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-12-03 07:23 - 2014-03-10 08:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-12-03 07:23 - 2014-03-10 08:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-12-03 06:36 - 2014-07-17 13:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-12-03 06:36 - 2014-07-17 13:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-12-03 06:36 - 2014-07-17 13:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-12-03 06:36 - 2014-07-17 13:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-12-03 06:36 - 2014-07-17 13:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-12-03 06:36 - 2014-07-17 12:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-12-03 06:36 - 2014-07-17 12:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-12-03 06:36 - 2014-07-17 12:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-12-03 06:36 - 2014-07-17 12:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-12-03 06:36 - 2014-07-17 12:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-12-03 06:36 - 2014-07-17 12:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-12-03 06:32 - 2013-05-13 16:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-12-03 06:32 - 2013-05-13 14:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-12-03 06:32 - 2013-05-13 14:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-12-03 06:32 - 2013-05-13 14:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-12-03 06:31 - 2014-08-01 22:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-12-03 06:31 - 2014-08-01 22:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-12-03 06:31 - 2013-05-10 16:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-12-03 06:31 - 2013-05-10 14:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2014-12-02 20:31 - 2014-12-02 20:31 - 00000000 ___RD () C:\MSOCache
2014-12-02 20:28 - 2014-12-02 20:28 - 00000000 ____D () C:\Users\debbie\AppData\Local\Microsoft Help
2014-12-02 20:28 - 2014-12-02 20:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-02 18:59 - 2014-12-10 10:36 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-02 17:59 - 2013-05-10 16:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-12-02 17:59 - 2013-05-10 16:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-12-02 17:59 - 2013-05-10 15:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-12-02 17:59 - 2013-05-10 15:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-12-02 14:42 - 2012-07-26 14:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-12-02 14:42 - 2012-07-26 14:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-12-02 14:42 - 2012-07-26 14:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-12-02 14:42 - 2012-07-26 14:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-12-02 14:42 - 2012-07-26 14:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-12-02 14:42 - 2012-07-26 13:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-12-02 14:42 - 2012-07-26 13:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-12-02 14:42 - 2012-06-03 01:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-12-02 14:36 - 2012-03-01 17:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-12-02 14:36 - 2012-03-01 17:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-12-02 14:36 - 2012-03-01 16:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-12-02 14:12 - 2014-03-04 20:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-12-02 14:12 - 2014-03-04 20:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-12-02 14:12 - 2014-03-04 20:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-12-02 14:12 - 2014-03-04 20:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-12-02 14:12 - 2014-03-04 20:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-12-02 14:12 - 2014-03-04 20:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-12-02 14:12 - 2014-03-04 20:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-12-02 14:12 - 2014-03-04 20:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-12-02 14:12 - 2014-03-04 20:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-12-02 14:12 - 2014-03-04 20:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-12-02 14:12 - 2013-08-02 13:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-12-02 14:12 - 2013-08-02 13:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-12-02 14:12 - 2013-08-02 12:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-12-02 14:12 - 2013-08-02 11:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-12-02 14:07 - 2013-12-04 13:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-12-02 14:07 - 2013-12-04 13:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-12-02 14:07 - 2013-12-04 13:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-12-02 14:07 - 2013-12-04 13:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-12-02 14:07 - 2013-12-04 13:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-12-02 14:07 - 2013-12-04 13:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-12-02 14:07 - 2013-12-04 13:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-12-02 14:07 - 2013-12-04 13:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-12-02 14:07 - 2013-12-04 13:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-12-02 14:07 - 2013-12-04 13:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-12-02 14:07 - 2013-12-04 13:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-12-02 14:07 - 2013-12-04 13:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-12-02 14:07 - 2013-12-04 13:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-12-02 14:07 - 2013-12-04 13:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-12-02 14:07 - 2013-12-04 12:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-12-02 14:07 - 2013-12-04 12:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-12-02 14:07 - 2013-12-04 12:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-12-02 14:07 - 2013-12-04 12:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-12-02 13:58 - 2014-11-11 14:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-12-02 13:58 - 2014-11-11 14:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-12-02 13:58 - 2014-11-11 13:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-12-02 13:58 - 2014-11-11 13:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-12-02 13:58 - 2014-10-14 13:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-12-02 13:58 - 2014-10-14 13:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-12-02 13:58 - 2014-10-14 12:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-12-02 13:58 - 2014-10-14 12:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-12-02 13:58 - 2014-04-12 13:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-12-02 13:58 - 2014-04-12 13:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-12-02 13:58 - 2014-04-12 13:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-12-02 13:58 - 2014-04-12 13:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-12-02 13:58 - 2014-04-12 13:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-12-02 13:58 - 2012-10-04 04:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-12-02 13:58 - 2012-10-04 04:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-12-02 13:58 - 2012-10-04 03:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2014-12-02 13:58 - 2012-10-04 03:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2014-12-02 13:58 - 2012-10-04 03:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2014-12-02 13:58 - 2012-10-04 03:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-12-02 13:58 - 2012-01-13 18:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2014-12-02 13:57 - 2014-10-14 13:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-12-02 13:57 - 2014-10-14 13:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-12-02 13:57 - 2014-10-14 13:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-12-02 13:57 - 2014-10-14 12:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-12-02 13:57 - 2014-10-14 12:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-12-02 13:56 - 2013-07-26 13:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-12-02 13:56 - 2013-07-26 12:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-12-02 13:55 - 2013-08-29 13:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-12-02 13:55 - 2013-08-29 13:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-12-02 13:55 - 2013-08-29 13:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-12-02 13:55 - 2013-08-29 12:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-12-02 13:55 - 2013-08-29 12:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-12-02 13:55 - 2013-08-29 12:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-12-02 13:54 - 2013-07-04 23:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-12-02 13:53 - 2014-09-19 20:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-12-02 13:53 - 2014-09-19 20:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-12-02 13:53 - 2014-09-19 20:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-12-02 13:53 - 2013-07-09 16:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-12-02 13:53 - 2013-07-09 15:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-12-02 13:52 - 2012-12-08 00:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-12-02 13:52 - 2012-12-08 00:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-12-02 13:52 - 2012-12-07 23:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-12-02 13:52 - 2012-12-07 23:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-12-02 13:52 - 2012-12-07 22:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-12-02 13:52 - 2012-12-07 22:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-12-02 13:52 - 2012-12-07 22:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2014-12-02 13:52 - 2012-12-07 21:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2014-12-02 13:51 - 2013-04-26 10:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-12-02 13:51 - 2013-04-01 09:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-12-02 13:51 - 2012-10-10 05:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-12-02 13:51 - 2012-10-10 05:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-12-02 13:51 - 2012-10-10 04:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2014-12-02 13:51 - 2012-10-10 04:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2014-12-02 13:51 - 2010-12-23 21:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-12-02 13:51 - 2010-12-23 21:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-12-02 13:51 - 2010-12-23 21:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-12-02 13:51 - 2010-12-23 16:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-12-02 13:51 - 2010-12-23 16:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-12-02 13:51 - 2010-12-23 16:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-12-02 13:50 - 2014-01-24 13:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-12-02 13:50 - 2013-09-08 13:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-12-02 13:50 - 2013-09-08 13:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-12-02 13:49 - 2014-04-05 13:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-12-02 13:49 - 2014-04-05 13:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-12-02 13:49 - 2013-11-26 22:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-12-02 13:49 - 2011-05-04 16:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2014-12-02 13:49 - 2011-05-04 16:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2014-12-02 13:49 - 2011-05-04 16:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-12-02 13:49 - 2011-05-04 16:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-12-02 13:49 - 2011-05-04 16:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-12-02 13:49 - 2011-05-04 15:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2014-12-02 13:49 - 2011-05-04 15:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2014-12-02 13:49 - 2011-05-04 15:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2014-12-02 13:49 - 2011-05-04 15:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2014-12-02 13:49 - 2011-05-04 15:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2014-12-02 13:48 - 2014-10-10 11:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-12-02 13:48 - 2014-08-23 13:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-12-02 13:48 - 2014-08-23 12:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-12-02 13:48 - 2014-06-25 13:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-12-02 13:48 - 2014-06-25 12:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-12-02 13:48 - 2014-06-18 13:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-12-02 13:48 - 2014-06-18 12:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-12-02 13:48 - 2012-01-04 21:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-12-02 13:48 - 2012-01-04 19:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2014-12-02 13:47 - 2014-07-14 13:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-12-02 13:47 - 2014-07-14 12:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-12-02 13:47 - 2014-03-27 01:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-12-02 13:47 - 2014-03-27 01:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-12-02 13:47 - 2014-03-27 01:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-12-02 13:47 - 2014-03-27 01:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-12-02 13:47 - 2013-07-25 20:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-12-02 13:47 - 2013-07-25 19:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-12-02 13:47 - 2013-06-26 09:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-12-02 13:47 - 2012-11-29 09:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-12-02 13:47 - 2012-11-29 09:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-12-02 13:47 - 2012-11-29 09:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-12-02 13:47 - 2011-03-11 17:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-12-02 13:47 - 2011-03-11 17:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-12-02 13:47 - 2011-03-11 16:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-12-02 13:47 - 2011-03-11 16:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-12-02 13:46 - 2014-10-03 13:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-12-02 13:46 - 2014-10-03 13:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-12-02 13:46 - 2014-10-03 13:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-12-02 13:46 - 2014-10-03 13:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-12-02 13:46 - 2014-10-03 13:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-12-02 13:46 - 2014-10-03 12:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-12-02 13:46 - 2014-10-03 12:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-12-02 13:46 - 2014-10-03 12:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-12-02 13:46 - 2013-10-06 07:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-12-02 13:46 - 2013-10-06 06:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-12-02 13:46 - 2013-07-09 16:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-12-02 13:46 - 2013-07-09 16:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-12-02 13:46 - 2013-07-09 15:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-12-02 13:46 - 2013-07-09 15:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-12-02 13:46 - 2012-08-22 08:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-12-02 13:46 - 2011-10-15 17:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-12-02 13:46 - 2011-10-15 16:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-12-02 13:46 - 2011-04-09 17:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-12-02 13:46 - 2011-04-09 16:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-12-02 13:45 - 2014-12-02 14:32 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-12-02 13:45 - 2014-10-14 13:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-12-02 13:45 - 2014-10-14 12:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-12-02 13:45 - 2014-06-03 21:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-12-02 13:45 - 2014-06-03 21:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-12-02 13:45 - 2014-06-03 21:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-12-02 13:45 - 2014-06-03 20:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-12-02 13:45 - 2014-06-03 20:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-12-02 13:45 - 2014-03-04 20:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-12-02 13:45 - 2014-03-04 20:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-12-02 13:45 - 2014-03-04 20:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-12-02 13:45 - 2014-03-04 20:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-12-02 13:45 - 2014-03-04 20:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-12-02 13:45 - 2014-03-04 19:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-12-02 13:45 - 2014-03-04 19:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-12-02 13:45 - 2014-02-04 13:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-12-02 13:45 - 2014-02-04 13:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-12-02 13:45 - 2014-02-04 13:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-12-02 13:45 - 2014-02-04 13:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-12-02 13:45 - 2014-02-04 13:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-12-02 13:45 - 2013-08-28 12:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-12-02 13:45 - 2013-08-02 13:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 13:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 12:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-12-02 13:45 - 2013-08-02 11:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 11:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 11:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-12-02 13:45 - 2013-08-02 11:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-12-02 13:45 - 2013-07-04 23:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-12-02 13:45 - 2013-07-04 23:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-12-02 13:45 - 2013-07-04 22:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-12-02 13:45 - 2013-07-04 22:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-12-02 13:45 - 2013-07-04 21:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-12-02 13:45 - 2013-02-27 16:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-12-02 13:45 - 2011-11-17 17:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-12-02 13:45 - 2011-11-17 16:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-12-02 13:45 - 2011-08-27 16:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-12-02 13:45 - 2011-08-27 15:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-12-02 13:45 - 2011-02-06 04:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-12-02 13:45 - 2011-02-06 04:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-12-02 13:45 - 2011-02-06 04:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-12-02 13:45 - 2011-02-06 04:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-12-02 13:45 - 2011-02-06 04:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-12-02 13:45 - 2011-02-06 04:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-12-02 13:45 - 2011-02-06 04:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-12-02 13:44 - 2014-08-21 17:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-12-02 13:44 - 2014-08-21 17:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-12-02 13:44 - 2014-08-21 17:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-12-02 13:44 - 2014-08-21 17:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-12-02 13:44 - 2014-06-19 09:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-12-02 13:44 - 2013-10-12 13:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-12-02 13:44 - 2013-10-12 13:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-12-02 13:44 - 2013-10-12 13:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-12-02 13:44 - 2013-10-12 13:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-12-02 13:44 - 2013-10-12 13:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-12-02 13:44 - 2013-10-04 13:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-12-02 13:44 - 2013-10-04 13:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-12-02 13:44 - 2013-10-04 12:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2014-12-02 13:44 - 2013-10-04 12:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2014-12-02 13:44 - 2012-06-06 17:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-12-02 13:44 - 2012-06-06 16:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-12-02 13:44 - 2011-04-29 14:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-12-02 13:44 - 2011-04-29 14:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-12-02 13:44 - 2011-04-29 14:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-12-02 13:43 - 2014-08-12 13:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-12-02 13:43 - 2014-08-12 12:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-12-02 13:43 - 2014-06-16 13:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-12-02 13:43 - 2014-06-06 21:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-12-02 13:43 - 2014-06-06 20:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-12-02 13:43 - 2013-08-05 13:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-12-02 13:43 - 2013-06-06 16:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-12-02 13:43 - 2013-06-06 16:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-12-02 13:43 - 2013-06-06 16:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-12-02 13:43 - 2013-06-06 16:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-12-02 13:43 - 2013-06-06 15:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-12-02 13:43 - 2013-06-06 15:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-12-02 13:43 - 2013-06-06 15:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-12-02 13:43 - 2013-06-06 14:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-12-02 13:43 - 2013-06-06 14:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-12-02 13:43 - 2013-06-06 14:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-12-02 13:43 - 2013-04-26 16:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-12-02 13:43 - 2013-04-26 15:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-12-02 13:43 - 2013-04-10 17:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-12-02 13:43 - 2013-02-15 17:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-12-02 13:43 - 2013-02-15 17:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-12-02 13:43 - 2013-02-15 14:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-12-02 13:43 - 2012-05-05 19:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-12-02 13:43 - 2012-05-05 18:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-12-02 13:43 - 2011-10-26 16:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-12-02 13:43 - 2011-10-26 15:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-12-02 13:43 - 2011-08-17 16:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-12-02 13:43 - 2011-08-17 16:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-12-02 13:43 - 2011-08-17 15:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-12-02 13:43 - 2011-08-17 15:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-12-02 13:43 - 2011-06-15 21:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-12-02 13:43 - 2011-06-15 21:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-12-02 13:43 - 2011-06-15 21:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-12-02 13:43 - 2011-06-15 21:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-12-02 13:43 - 2011-06-15 19:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-12-02 13:43 - 2011-02-03 22:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-12-02 13:42 - 2014-10-18 13:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-12-02 13:42 - 2014-10-18 12:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-12-02 13:42 - 2014-09-25 13:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-12-02 13:42 - 2014-09-25 12:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-12-02 13:42 - 2014-09-04 16:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-12-02 13:42 - 2014-09-04 16:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-12-02 13:42 - 2014-05-30 17:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-12-02 13:42 - 2014-04-25 13:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-12-02 13:42 - 2014-04-25 13:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-12-02 13:42 - 2014-01-29 13:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-12-02 13:42 - 2014-01-29 13:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-12-02 13:42 - 2014-01-28 13:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-12-02 13:42 - 2013-11-27 12:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-12-02 13:42 - 2013-11-27 12:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-12-02 13:42 - 2013-11-27 12:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-12-02 13:42 - 2013-11-27 12:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-12-02 13:42 - 2013-11-27 12:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-12-02 13:42 - 2013-10-12 13:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-12-02 13:42 - 2013-10-12 13:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-12-02 13:42 - 2013-10-12 13:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-12-02 13:42 - 2013-10-12 13:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-12-02 13:42 - 2013-10-12 12:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-12-02 13:42 - 2013-10-12 12:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-12-02 13:42 - 2013-10-12 12:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-12-02 13:42 - 2013-10-12 12:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-12-02 13:42 - 2013-07-20 21:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-12-02 13:42 - 2013-07-20 21:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-12-02 13:42 - 2013-07-12 21:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-12-02 13:42 - 2013-07-12 21:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-12-02 13:42 - 2013-07-03 15:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-12-02 13:42 - 2013-07-03 15:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-12-02 13:42 - 2013-03-19 16:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-12-02 13:42 - 2013-01-24 17:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-12-02 13:42 - 2012-05-14 16:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-12-02 13:42 - 2012-03-17 18:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-12-02 13:42 - 2011-12-16 19:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-12-02 13:42 - 2011-12-16 18:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-12-02 13:42 - 2011-07-09 13:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-12-02 13:42 - 2011-05-24 22:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-12-02 13:42 - 2011-05-24 21:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-12-02 13:42 - 2011-05-24 21:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-12-02 13:42 - 2011-05-24 21:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-12-02 13:42 - 2011-05-24 21:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-12-02 13:42 - 2011-04-27 13:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-12-02 13:42 - 2011-04-27 13:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-12-02 13:42 - 2011-03-03 17:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-12-02 13:42 - 2011-03-03 17:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-12-02 13:42 - 2011-03-03 17:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-12-02 13:42 - 2011-03-03 16:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-12-02 13:42 - 2011-03-03 16:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-12-02 13:42 - 2011-02-23 15:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-12-02 13:42 - 2011-02-12 22:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-12-02 13:41 - 2014-10-25 12:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-12-02 13:41 - 2014-10-25 12:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-12-02 13:41 - 2013-10-30 13:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-12-02 13:41 - 2013-10-30 13:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2014-12-02 13:41 - 2013-10-19 13:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-12-02 13:41 - 2013-10-19 12:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-12-02 13:41 - 2013-10-04 13:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-12-02 13:41 - 2013-10-04 12:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-12-02 13:41 - 2013-07-04 23:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-12-02 13:41 - 2013-07-04 22:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-12-02 13:41 - 2013-02-12 15:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-12-02 13:41 - 2012-11-23 14:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-12-02 13:41 - 2012-11-02 16:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-12-02 13:41 - 2012-11-02 16:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-12-02 13:41 - 2012-09-26 09:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-12-02 13:41 - 2012-09-26 09:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-12-02 13:41 - 2012-08-23 05:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-12-02 13:41 - 2012-07-05 09:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-12-02 13:41 - 2012-07-05 09:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-12-02 13:41 - 2012-07-05 09:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-12-02 13:41 - 2012-07-05 08:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-12-02 13:41 - 2012-07-05 08:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-12-02 13:41 - 2012-07-05 07:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-12-02 13:41 - 2012-05-01 16:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-12-02 13:41 - 2012-04-26 16:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-12-02 13:41 - 2012-04-26 16:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-12-02 13:41 - 2011-12-30 17:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-12-02 13:41 - 2011-12-30 16:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2014-12-02 13:41 - 2011-06-16 16:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2014-12-02 13:41 - 2011-06-16 15:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
2014-12-02 13:41 - 2011-05-03 16:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-12-02 13:41 - 2011-05-03 15:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-12-02 13:40 - 2011-02-18 21:51 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2014-12-02 13:40 - 2011-02-18 16:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2014-12-02 12:41 - 2014-12-15 21:36 - 00000000 ____D () C:\Users\debbie\Desktop\scanner
2014-12-02 12:15 - 2014-12-12 10:48 - 00000000 ____D () C:\Users\debbie\Desktop\Training Officer
2014-12-02 11:52 - 2014-12-17 13:32 - 00000000 ____D () C:\Users\debbie\Desktop\Mark worksheets
2014-12-02 11:52 - 2014-12-14 18:48 - 00000000 ____D () C:\Users\debbie\Desktop\Max work
2014-12-02 11:51 - 2014-12-10 10:59 - 00000000 ____D () C:\Users\debbie\Desktop\Job Applications
2014-12-02 11:50 - 2014-12-02 11:51 - 00000000 ____D () C:\Users\debbie\Desktop\Cert IV
2014-12-02 11:47 - 2014-12-09 20:50 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Canon
2014-12-02 11:46 - 2014-12-02 11:46 - 00000000 ___HD () C:\ProgramData\CanonIJEPPEX2
2014-12-02 11:46 - 2014-12-02 11:46 - 00000000 ___HD () C:\ProgramData\CanonEPP
2014-12-02 11:46 - 2014-12-02 11:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon IJ Network Utilities
2014-12-02 11:46 - 2014-12-02 11:46 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool
2014-12-02 11:45 - 2014-12-02 11:45 - 00000000 ____D () C:\ProgramData\CanonIJMSetup
2014-12-02 11:45 - 2014-12-02 11:45 - 00000000 ____D () C:\Program Files\Common Files\CANON
2014-12-02 11:45 - 2010-03-18 19:25 - 00307200 _____ (CANON INC.) C:\Windows\SysWOW64\CNC495L.dll
2014-12-02 11:45 - 2010-03-18 17:11 - 00106496 _____ (CANON INC.) C:\Windows\SysWOW64\CNC495U.dll
2014-12-02 11:45 - 2009-11-13 14:35 - 00012800 _____ () C:\Windows\SysWOW64\CNC1747D.TBL
2014-12-02 11:45 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2014-12-02 11:44 - 2014-12-02 11:44 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-12-02 11:43 - 2014-12-03 12:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-12-02 11:43 - 2014-12-02 11:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP495 series Manual
2014-12-02 11:43 - 2014-12-02 11:43 - 00000000 ____D () C:\Program Files\Canon
2014-12-02 11:42 - 2014-12-02 11:42 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2014-12-02 11:42 - 2014-12-02 11:42 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-12-02 11:42 - 2014-12-02 11:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP495 series
2014-12-02 11:42 - 2010-08-25 05:00 - 00361472 _____ (CANON INC.) C:\Windows\system32\CNMLMA9.DLL
2014-12-02 11:42 - 2010-03-11 19:57 - 00248320 _____ (CANON INC.) C:\Windows\system32\CNMIUA9.DLL
2014-12-02 11:41 - 2014-12-03 12:00 - 00000000 ____D () C:\Program Files (x86)\Canon
2014-12-02 11:41 - 2014-12-02 11:41 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-12-02 11:41 - 2014-12-02 11:41 - 00000000 ____D () C:\Windows\system32\STRING
2014-12-02 11:41 - 2010-02-05 21:37 - 00327680 _____ (CANON INC.) C:\Windows\system32\CNMN6PPM.DLL
2014-12-02 11:41 - 2010-02-05 21:37 - 00037376 _____ (CANON INC.) C:\Windows\system32\CNMN6UI.DLL
2014-12-02 11:20 - 2014-12-17 13:33 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\SoftGrid Client
2014-12-02 11:20 - 2014-12-13 22:44 - 00000000 ____D () C:\Users\debbie\AppData\Local\SoftGrid Client
2014-12-02 11:20 - 2014-12-03 11:39 - 00766566 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-12-02 11:20 - 2014-12-02 11:20 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-12-02 11:20 - 2014-12-02 11:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
2014-12-02 11:19 - 2014-12-03 07:58 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-12-02 11:19 - 2014-12-02 11:20 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\TP
2014-12-02 11:19 - 2014-12-02 11:19 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-12-02 10:55 - 2014-12-13 14:20 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-02 10:55 - 2014-12-12 23:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-02 10:43 - 2014-12-20 08:21 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-02 10:43 - 2014-12-20 00:37 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-02 10:43 - 2014-12-02 10:55 - 00000000 ____D () C:\Users\debbie\AppData\Local\Google
2014-12-02 10:43 - 2014-12-02 10:54 - 00000000 ____D () C:\Program Files (x86)\Google
2014-12-02 10:43 - 2014-12-02 10:43 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-12-02 10:43 - 2014-12-02 10:43 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-12-02 10:42 - 2014-12-02 10:43 - 00000000 ____D () C:\Users\debbie\AppData\Local\Deployment
2014-12-02 10:42 - 2014-12-02 10:42 - 00000000 ____D () C:\Users\debbie\AppData\Local\Apps\2.0
2014-12-02 09:56 - 2014-12-02 09:56 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\AVG2015
2014-12-02 09:55 - 2014-12-02 09:56 - 00000000 ____D () C:\ProgramData\AVG2015
2014-12-02 09:55 - 2014-12-02 09:55 - 00000965 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2014-12-02 09:55 - 2014-12-02 09:55 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\TuneUp Software
2014-12-02 09:55 - 2014-12-02 09:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-12-02 09:55 - 2014-12-02 09:55 - 00000000 ____D () C:\$AVG
2014-12-02 09:54 - 2014-12-02 09:54 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-12-02 09:36 - 2014-12-20 00:18 - 00000000 ____D () C:\ProgramData\MFAData
2014-12-02 09:36 - 2014-12-02 10:23 - 00000000 ____D () C:\Users\debbie\AppData\Local\Avg2015
2014-12-02 09:36 - 2014-12-02 09:36 - 00000000 ____D () C:\Users\debbie\AppData\Local\MFAData
2014-12-02 09:27 - 2012-02-17 17:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-12-02 09:27 - 2012-02-17 16:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-12-02 09:27 - 2012-02-17 15:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-12-02 09:25 - 2014-12-09 20:56 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Adobe
2014-12-02 09:25 - 2014-12-02 09:25 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Macromedia
2014-12-02 09:20 - 2014-12-18 21:20 - 00003220 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForDEBBIE-HP$
2014-12-02 09:20 - 2014-12-18 21:20 - 00000344 _____ () C:\Windows\Tasks\HPCeeScheduleForDEBBIE-HP$.job
2014-12-02 09:15 - 2014-12-02 09:15 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\ATI
2014-12-02 09:15 - 2014-12-02 09:15 - 00000000 ____D () C:\Users\debbie\AppData\Local\ATI
2014-12-02 09:14 - 2014-12-20 08:19 - 00003934 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{2306AC12-20CF-4890-9F68-79953A28AD4F}
2014-12-02 09:14 - 2014-12-20 00:13 - 00000336 _____ () C:\Windows\Tasks\HPCeeScheduleFordebbie.job
2014-12-02 09:14 - 2014-12-18 09:14 - 00003192 _____ () C:\Windows\System32\Tasks\HPCeeScheduleFordebbie
2014-12-02 09:14 - 2014-12-12 23:06 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\hpqLog
2014-12-02 09:14 - 2014-12-03 08:03 - 00001417 _____ () C:\Users\debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-02 09:14 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Synaptics
2014-12-02 09:14 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Intel Corporation
2014-12-02 09:14 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Local\RemEngine
2014-12-02 09:13 - 2014-12-02 19:14 - 00058016 _____ () C:\Users\debbie\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-02 09:10 - 2014-12-10 23:08 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Hewlett-Packard
2014-12-02 09:10 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Local\Hewlett-Packard_Company
2014-12-02 09:10 - 2014-12-02 09:14 - 00000000 ____D () C:\Users\debbie\AppData\Local\Hewlett-Packard
2014-12-02 09:10 - 2014-12-02 09:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music and Media
2014-12-02 09:10 - 2014-05-15 03:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-12-02 09:10 - 2014-05-15 03:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-12-02 09:10 - 2014-05-15 03:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-12-02 09:10 - 2014-05-15 03:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-12-02 09:10 - 2014-05-15 03:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-12-02 09:10 - 2014-05-15 03:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-12-02 09:10 - 2011-06-25 10:58 - 00002177 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicStation.lnk
2014-12-02 09:09 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-12-02 09:09 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-12-02 09:09 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-12-02 09:09 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-12-02 09:08 - 2014-12-13 00:01 - 00000000 ____D () C:\Users\debbie
2014-12-02 09:08 - 2014-12-02 09:08 - 00000020 ___SH () C:\Users\debbie\ntuser.ini
2014-12-02 09:08 - 2014-12-02 09:08 - 00000000 ____D () C:\Users\debbie\AppData\Roaming\Intel
2014-12-02 09:08 - 2014-12-02 09:08 - 00000000 ____D () C:\Users\debbie\AppData\Local\VirtualStore
2014-12-02 09:08 - 2009-07-14 15:54 - 00000000 ___RD () C:\Users\debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-02 09:08 - 2009-07-14 15:49 - 00000000 ___RD () C:\Users\debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-12-20 01:30 - 2011-06-25 10:51 - 01738775 _____ () C:\Windows\WindowsUpdate.log
2014-12-20 00:45 - 2009-07-14 15:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-20 00:45 - 2009-07-14 15:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-20 00:41 - 2009-07-14 16:13 - 00782228 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-20 00:36 - 2010-11-21 14:47 - 00240728 _____ () C:\Windows\PFRO.log
2014-12-20 00:36 - 2009-07-14 16:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-20 00:36 - 2009-07-14 15:51 - 00056826 _____ () C:\Windows\setupact.log
2014-12-14 13:52 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\rescache
2014-12-14 07:33 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-13 18:05 - 2011-04-24 08:44 - 00000000 ____D () C:\ProgramData\WildTangent
2014-12-13 18:00 - 2011-04-24 08:44 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2014-12-13 17:56 - 2009-07-14 16:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-12-13 12:01 - 2009-07-14 16:08 - 00020202 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-12 23:57 - 2011-06-25 10:47 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-12-12 23:57 - 2011-04-24 08:49 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-12-12 23:57 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-12 23:57 - 2009-07-14 14:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-12-12 23:56 - 2011-04-24 08:58 - 00000000 ____D () C:\Windows\System32\Tasks\Hewlett-Packard
2014-12-12 23:56 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\registration
2014-12-12 23:56 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\Help
2014-12-12 23:55 - 2011-06-25 10:46 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-12-12 23:55 - 2011-04-24 08:55 - 00000000 ____D () C:\ProgramData\Adobe
2014-12-12 23:55 - 2011-04-24 08:50 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-12-12 23:55 - 2011-04-24 08:42 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-12-10 08:04 - 2009-07-14 13:34 - 00000215 _____ () C:\Windows\system.ini
2014-12-08 23:51 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-08 13:14 - 2009-07-14 16:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-12-03 13:41 - 2009-07-14 15:45 - 00268392 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-03 07:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-12-03 07:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-12-03 07:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-12-03 07:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-12-03 04:03 - 2009-07-14 16:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-12-03 04:03 - 2009-07-14 16:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-12-03 03:04 - 2007-01-02 12:25 - 00000000 ____D () C:\Windows\Panther
2014-12-02 18:59 - 2009-07-14 16:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-12-02 18:59 - 2009-07-14 16:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-12-02 18:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-12-02 18:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-12-02 18:59 - 2009-07-14 14:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-12-02 11:45 - 2009-07-14 14:20 - 00000000 __RSD () C:\Windows\Media
2014-12-02 11:19 - 2011-04-24 08:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-12-02 09:19 - 2011-06-25 11:01 - 00000000 ____D () C:\ProgramData\Norton
2014-12-02 09:10 - 2011-04-24 08:56 - 00000000 ___RD () C:\Program Files\Online Services
2014-12-02 09:10 - 2011-04-24 08:50 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services
2014-12-02 09:10 - 2011-04-24 08:44 - 00000000 ___RD () C:\Program Files (x86)\Online Services
2014-12-02 09:10 - 2009-07-14 16:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-12-02 09:10 - 2009-07-14 16:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2014-12-02 09:09 - 2011-02-11 06:23 - 00000000 ____D () C:\SYSTEM.SAV
2014-12-02 09:09 - 2011-02-11 06:23 - 00000000 ____D () C:\SWSetup
2014-12-02 09:09 - 2009-07-14 16:32 - 00000000 ____D () C:\Windows\system32\restore
2014-12-02 09:09 - 2009-07-14 14:20 - 00000000 ____D () C:\Windows\system32\Recovery
2014-12-02 09:09 - 2007-01-02 12:32 - 00000000 ____D () C:\Recovery
2014-12-02 09:07 - 2009-07-14 14:20 - 00000000 __RHD () C:\Users\Public\Libraries
 
Some content of TEMP:
====================
C:\Users\debbie\AppData\Local\Temp\Quarantine.exe
C:\Users\debbie\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-12-15 14:48
 
==================== End Of Log ============================
 
Yes...i have noticed some changes....it seems a lot faster.
 
p.s....i tried to past them all into one post but it i think it was too much and for some reason after waiting about 15 minutes it still wouldnt post the reply saying it was "saving post".
 
thanks again for all your help..i appreciate it.


#14 OCD

OCD

  • Malware Response Team
  • 172 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:05:04 AM

Posted 19 December 2014 - 09:49 PM

Hi bellagirl ,

Your logs are looking good, let's continue.
bullseye_zpse9eaf36e.gif Malwarebytes' Anti-Malware

Download Malwarebytes' Anti-Malware (save it to your desktop).
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Select Scan tab.
    MBAMDashboard_zpsddef9b5f.gif
  • Select type of scan to perform:
    MBAMScanTab_zps2c5e74bd.gif
    • Threat Scan < --- Select this type of scan
    • Custom Scan
    • Hyper Scan
  • Next click the Scan button.
  • When the scan is complete, if no malicious items are found you can close the program.
  • If malicious items are found be sure that everything is checked, and click Quarantine .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
=========================

bullseye_zpse9eaf36e.gif ESET Online Scanner

*Note:
  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Checked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
=========================

In your next post please provide the following:
  • MBAM log
  • ESET's log.txt
  • How's the computer running, any symptoms?

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days

#15 bellagirl

bellagirl
  • Topic Starter

  • Members
  • 48 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 20 December 2014 - 08:00 PM

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 21/12/2014
Scan Time: 10:06:59 AM
Logfile: malwarebytes log.txt
Administrator: Yes
 
Version: 2.00.4.1028
Malware Database: v2014.12.20.07
Rootkit Database: v2014.12.14.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: debbie
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 333874
Time Elapsed: 27 min, 43 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
D:\recovery\HOW_DECRYPT.HTML Win32/Filecoder.CO trojan deleted - quarantined
D:\recovery\HOW_DECRYPT.TXT Win32/Filecoder.CO trojan deleted - quarantined
 
 
 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users