Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Slow computer, numerous tabs open at each click, pop ups etc...


  • This topic is locked This topic is locked
2 replies to this topic

#1 duffster

duffster

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Arizona
  • Local time:03:04 PM

Posted 07 May 2015 - 09:09 PM

Haveing this issue for the last week. I found @ 8 programs installed that weren't asked for, deleted them via the control paage/uninstall page, then they would come back. Had to uninstall/restart 2 or 3 times to get them all uninstalled. Then I ran MBAM(which is still running) and they haven't re-installed. I then ran adwcleaner and JRT and maybe one other I don't recall. I'm still having a issue of multiple tabs opening each time I click on something to open such as a forum topic/post and a extremely slow internet browser activity. Thanks You for your help, Rich

Here's my FRST log.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2015 01
Ran by Owner (administrator) on OWNER-PC on 07-05-2015 18:32:32
Running from C:\Users\Owner\Downloads
Loaded Profiles: Owner (Available profiles: Owner)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Windows\hnq.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Windows\mhnq.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Network Accelerater\v5\winvxm.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Farbar) C:\Users\Owner\Downloads\FRST64(2).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2013-10-24] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [3D BubbleSound] => "C:\Program Files\BubbleSound\3D BubbleSound.exe"
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3903853910-2449996960-2627829725-1000\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1403224 2015-04-23] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3903853910-2449996960-2627829725-1000\...\RunOnce: [Adobe Speed Launcher] => 1431046339
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-05-02]
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{f58d5abd-1bb7-a2c7-f58d-d5abd1bb6af4}\hqghumeaylnlf.exe (No File)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup.lnk [2015-03-03]
ShortcutTarget: setup.lnk -> C:\ProgramData\{9eaef950-eef0-fae1-9eae-ef950eefe543}\setup.exe (No File)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Owner\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2014-06-19] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Owner\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2014-06-19] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Owner\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2014-06-19] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Owner\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2014-06-19] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3903853910-2449996960-2627829725-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3903853910-2449996960-2627829725-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cox.com/myconnection/home.cox
HKU\S-1-5-21-3903853910-2449996960-2627829725-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
URLSearchHook: HKLM-x32 - Default Value = {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3903853910-2449996960-2627829725-1000 -> {3F1C35BA-5BF6-43F2-A3A4-CFA07B31DFFA} URL =
SearchScopes: HKU\S-1-5-21-3903853910-2449996960-2627829725-1000 -> {5EE7417C-5FFC-417B-B619-E71BFAD382CE} URL =
SearchScopes: HKU\S-1-5-21-3903853910-2449996960-2627829725-1000 -> {83C8CD89-5EBE-41EF-B9AB-D266E9F59912} URL =
SearchScopes: HKU\S-1-5-21-3903853910-2449996960-2627829725-1000 -> {88DB4AC2-E689-4228-AD81-723782969115} URL =
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-07] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-07] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\y4hv4d0w.default
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://www.cox.com/myconnection/home.cox
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-05-02] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-05-02] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll [2014-06-24] (Adobe Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-06-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-08-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-08-07] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-07] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-07] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Extension: ossenyandexru - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\y4hv4d0w.default\Extensions\ossen@yandex.ru [2015-03-08]

Chrome:
=======
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-04]
CHR Extension: (Google Docs) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-04]
CHR Extension: (Google Drive) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-04]
CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-04]
CHR Extension: (Google Search) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-04]
CHR Extension: (Google Sheets) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-04]
CHR Extension: (Bookmark Manager) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-04]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-03]
CHR Extension: (Google Wallet) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-03]
CHR Extension: (Gmail) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-04]
CHR HKU\S-1-5-21-3903853910-2449996960-2627829725-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [jlcgehabolcakkjhgmgpkagpolbjlhfa] - https://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [713736 2015-04-23] (Garmin Ltd. or its subsidiaries)
R2 hnq; c:\windows\hnq.exe [417792 2015-05-02] () [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 mhnq; c:\windows\mhnq.exe [408576 2015-05-02] () [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [289496 2013-10-16] (Realtek Semiconductor)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 WindowsVNT_R5; C:\Program Files (x86)\Windows Network Accelerater\v5\winvxm.exe [2976880 2015-03-24] (Microsoft Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-05] (Intel Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [129224 2013-07-17] (Qualcomm Atheros Co., Ltd.)
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [44480 2013-09-23] (http://libusb-win32.sourceforge.net)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-07] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-07 18:30 - 2015-05-07 18:30 - 02102272 _____ (Farbar) C:\Users\Owner\Downloads\FRST64(2).exe
2015-05-06 22:03 - 2015-05-06 22:04 - 00029908 _____ () C:\Users\Owner\Downloads\Addition.txt
2015-05-06 21:57 - 2015-05-07 18:32 - 00013037 _____ () C:\Users\Owner\Downloads\FRST.txt
2015-05-06 21:54 - 2015-05-07 18:32 - 00000000 ____D () C:\FRST
2015-05-06 21:52 - 2015-05-06 21:52 - 02102272 _____ (Farbar) C:\Users\Owner\Downloads\FRST64.exe
2015-05-06 21:51 - 2015-05-06 21:53 - 02102272 _____ (Farbar) C:\Users\Owner\Downloads\FRST64(1).exe
2015-05-06 20:36 - 2015-05-06 20:36 - 02204160 _____ () C:\Users\Owner\Downloads\adwcleaner_4.203(1).exe
2015-05-06 19:42 - 2015-05-06 19:42 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-OWNER-PC-Windows-7-Home-Premium-(64-bit).dat
2015-05-06 19:42 - 2015-05-06 19:42 - 00000000 ____D () C:\RegBackup
2015-05-06 19:40 - 2015-05-06 19:41 - 02716843 _____ (Thisisu) C:\Users\Owner\Downloads\JRT.exe
2015-05-05 22:34 - 2015-05-06 20:40 - 00000000 ____D () C:\AdwCleaner
2015-05-05 22:33 - 2015-05-05 22:33 - 02204160 _____ () C:\Users\Owner\Downloads\adwcleaner_4.203.exe
2015-05-05 21:29 - 2015-05-05 22:25 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-05-05 21:21 - 2015-05-05 21:22 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Owner\Downloads\mbar-1.09.1.1004.exe
2015-05-04 20:32 - 2015-05-07 18:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-04 20:29 - 2015-05-04 20:29 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-04 20:29 - 2015-05-04 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-04 20:28 - 2015-05-05 21:28 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-04 20:28 - 2015-05-04 20:29 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-04 20:28 - 2015-05-04 20:28 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-04 20:28 - 2015-04-14 09:47 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-04 20:28 - 2015-04-14 09:46 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-04 20:24 - 2015-05-04 20:26 - 21547816 _____ (Malwarebytes Corporation ) C:\Users\Owner\Downloads\mbam-setup.exe
2015-05-04 17:37 - 2015-05-04 17:37 - 00000177 _____ () C:\Windows\SysWOW64\SetupComponents.exe
2015-05-03 17:08 - 2015-05-03 17:08 - 00243304 _____ () C:\Users\Owner\Downloads\Firefox Setup Stub 37.0.2.exe
2015-05-03 12:09 - 2015-05-03 12:10 - 00000000 ____D () C:\Users\Owner\AppData\Local\Garmin_Ltd._or_its_subsid
2015-05-03 12:09 - 2015-05-03 12:09 - 00000000 ____D () C:\ProgramData\Ant
2015-05-03 12:09 - 2015-05-03 12:09 - 00000000 ____D () C:\Program Files\DIFX
2015-05-03 12:08 - 2015-05-03 12:08 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Garmin
2015-05-03 12:07 - 2015-05-03 12:07 - 00000000 ____D () C:\ProgramData\Garmin
2015-05-03 12:06 - 2015-05-03 12:06 - 00001890 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2015-05-03 12:06 - 2015-05-03 12:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2015-05-03 12:05 - 2015-05-03 12:09 - 00000000 ____D () C:\Program Files (x86)\Garmin
2015-05-03 12:04 - 2015-05-03 12:04 - 00003554 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask
2015-05-03 12:02 - 2015-05-03 12:03 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-03 11:59 - 2015-05-03 11:59 - 40605392 _____ (Garmin Ltd or its subsidiaries) C:\Users\Owner\Downloads\GarminExpressInstaller.exe
2015-05-03 11:35 - 2015-05-03 11:35 - 00000000 ____D () C:\Users\Owner\AppData\Local\gegl-0.2
2015-05-03 11:35 - 2015-05-03 11:35 - 00000000 ____D () C:\Users\Owner\.gimp-2.8
2015-05-03 11:29 - 2015-05-07 17:52 - 00001024 _____ () C:\Windows\Tasks\QSx4mPCRXgVp3vx17I8SPjzMlB.job
2015-05-03 11:29 - 2015-05-07 17:52 - 00001012 _____ () C:\Windows\Tasks\xkLc3uuMHcyRR6cmoFug.job
2015-05-03 11:29 - 2015-05-03 11:29 - 00004050 _____ () C:\Windows\System32\Tasks\QSx4mPCRXgVp3vx17I8SPjzMlB
2015-05-03 11:29 - 2015-05-03 11:29 - 00004038 _____ () C:\Windows\System32\Tasks\xkLc3uuMHcyRR6cmoFug
2015-05-03 10:32 - 2015-05-03 10:32 - 00003592 _____ () C:\Windows\System32\Tasks\SMWUpd
2015-05-03 09:38 - 2015-05-03 09:38 - 00000000 ____D () C:\Users\Owner\.cache
2015-05-03 09:20 - 2015-05-03 09:20 - 00000000 ____D () C:\ProgramData\Windows VXM
2015-05-03 09:20 - 2015-05-03 09:20 - 00000000 ____D () C:\Program Files (x86)\Windows Network Accelerater
2015-05-03 08:56 - 2015-05-03 09:31 - 00000000 ___HD () C:\ProgramData\hnq
2015-05-03 08:39 - 2015-05-03 08:39 - 00613255 _____ (CMI Limited) C:\Users\Owner\AppData\Local\nscE964.tmp
2015-05-03 08:35 - 2015-05-05 19:59 - 00000000 ____D () C:\ProgramData\Optimizer
2015-05-03 08:35 - 2015-05-03 08:35 - 00000000 ____D () C:\Users\Owner\Documents\DreamVideoSoft
2015-05-03 08:35 - 2015-05-03 08:35 - 00000000 ____D () C:\Program Files (x86)\Windows Audio
2015-05-02 23:32 - 2015-05-02 23:31 - 00613255 _____ (CMI Limited) C:\Users\Owner\AppData\Local\nsr8C65.tmp
2015-05-02 23:17 - 2015-05-02 23:17 - 00000000 ____D () C:\ProgramData\Radio
2015-05-02 23:12 - 2015-05-02 23:12 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2015-05-02 23:05 - 2015-05-02 23:04 - 00613255 _____ (CMI Limited) C:\Users\Owner\AppData\Local\nszFB57.tmp
2015-05-02 20:31 - 2015-05-07 17:52 - 00001010 _____ () C:\Windows\Tasks\GTADpvow8oqf2kN80ud.job
2015-05-02 20:31 - 2015-05-07 17:52 - 00000988 _____ () C:\Windows\Tasks\TdJ7xwKd.job
2015-05-02 20:31 - 2015-05-02 20:31 - 00004036 _____ () C:\Windows\System32\Tasks\GTADpvow8oqf2kN80ud
2015-05-02 20:31 - 2015-05-02 20:31 - 00004014 _____ () C:\Windows\System32\Tasks\TdJ7xwKd
2015-05-02 18:52 - 2015-05-02 18:52 - 00003558 _____ () C:\Windows\System32\Tasks\AUDFQV
2015-05-02 18:51 - 2015-05-07 17:52 - 00000330 _____ () C:\Windows\Tasks\SJEJD1.job
2015-05-02 18:51 - 2015-05-04 21:21 - 00000000 ____D () C:\ProgramData\fba3b93ddef444d4a5a4e589601c5891
2015-05-02 18:51 - 2015-05-02 18:51 - 00002852 _____ () C:\Windows\System32\Tasks\SJEJD1
2015-05-02 18:51 - 2015-05-02 18:51 - 00000000 ____D () C:\ProgramData\e5abc1d3717843ae810c5bb59d3b9009
2015-05-02 18:39 - 2015-05-02 23:27 - 00000000 ____D () C:\Users\Owner\AppData\Roaming\Skype
2015-05-02 18:39 - 2015-05-02 18:39 - 00000000 ____D () C:\Users\Owner\AppData\Local\Skype
2015-05-02 18:38 - 2015-05-03 00:05 - 00000000 ____D () C:\ProgramData\Skype
2015-05-02 18:37 - 2015-05-02 18:37 - 00631296 _____ () C:\Windows\hnq.dat
2015-05-02 18:37 - 2015-05-02 18:37 - 00417792 _____ () C:\Windows\hnq.exe
2015-05-02 18:37 - 2015-05-02 18:37 - 00408576 _____ () C:\Windows\mhnq.exe
2015-05-02 18:28 - 2015-05-02 18:28 - 00000000 ____D () C:\Users\Owner\AppData\Local\CrashRpt
2015-05-02 17:45 - 2015-05-02 17:51 - 00000000 ____D () C:\Users\Owner\Documents\MaxComputerCleaner
2015-05-02 17:43 - 2015-05-07 17:52 - 00001684 _____ () C:\Windows\Tasks\YOXALEU.job
2015-05-02 17:43 - 2015-05-02 17:44 - 00004710 _____ () C:\Windows\System32\Tasks\YOXALEU
2015-05-02 17:29 - 2015-05-02 17:33 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-02 17:29 - 2015-05-02 17:29 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-05-02 11:29 - 2015-03-24 20:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-05-02 11:29 - 2015-03-24 20:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-05-02 11:29 - 2015-03-24 20:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-05-02 11:29 - 2015-03-24 20:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-05-02 11:29 - 2015-03-24 20:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-05-02 11:29 - 2015-03-24 20:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-05-02 11:29 - 2015-03-24 20:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-05-02 11:29 - 2015-03-24 20:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-05-02 11:29 - 2015-03-24 20:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-05-02 11:29 - 2015-03-24 20:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-05-02 11:29 - 2015-03-24 20:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-05-02 11:29 - 2015-03-24 20:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-05-02 11:29 - 2015-03-24 20:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-05-02 11:29 - 2015-03-24 20:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-05-02 11:29 - 2015-03-24 20:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-05-02 11:29 - 2015-03-24 20:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-05-02 11:28 - 2015-03-22 20:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-05-02 11:28 - 2015-03-22 20:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-05-02 11:28 - 2015-03-22 20:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-05-02 11:28 - 2015-03-22 20:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-05-02 11:28 - 2015-03-22 20:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-05-02 11:28 - 2015-03-22 20:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-05-02 11:28 - 2015-03-22 20:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-05-02 11:28 - 2015-03-22 20:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-05-02 11:28 - 2015-03-16 22:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-02 11:28 - 2015-03-16 22:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-02 11:28 - 2015-03-16 22:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-02 11:28 - 2015-03-16 22:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-02 11:28 - 2015-03-16 22:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-05-02 11:28 - 2015-03-16 22:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-05-02 11:28 - 2015-03-16 22:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-02 11:28 - 2015-03-16 22:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-02 11:28 - 2015-03-16 22:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-02 11:28 - 2015-03-16 22:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-05-02 11:28 - 2015-03-16 22:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-05-02 11:28 - 2015-03-16 22:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-02 11:28 - 2015-03-16 22:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-02 11:28 - 2015-03-16 22:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-02 11:28 - 2015-03-16 22:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 22:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-05-02 11:28 - 2015-03-16 22:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-05-02 11:28 - 2015-03-16 21:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-05-02 11:28 - 2015-03-16 21:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-05-02 11:28 - 2015-03-16 21:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-05-02 11:28 - 2015-03-16 21:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-05-02 11:28 - 2015-03-16 21:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-05-02 11:28 - 2015-03-16 21:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-05-02 11:28 - 2015-03-16 21:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-05-02 11:28 - 2015-03-16 21:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-05-02 11:28 - 2015-03-16 21:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-05-02 11:28 - 2015-03-16 21:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-05-02 11:28 - 2015-03-16 21:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 20:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-05-02 11:28 - 2015-03-16 20:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-05-02 11:28 - 2015-03-16 20:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 20:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 20:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-02 11:28 - 2015-03-16 20:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-02 11:28 - 2015-03-09 20:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-05-02 11:28 - 2015-03-09 20:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-05-02 11:28 - 2015-03-09 20:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-05-02 11:28 - 2015-03-09 20:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-05-02 11:28 - 2015-03-04 22:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-05-02 11:28 - 2015-03-04 21:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-05-02 11:28 - 2015-02-24 20:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-05-02 11:27 - 2015-04-01 17:17 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-02 11:27 - 2015-04-01 16:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-02 11:27 - 2015-03-12 21:32 - 24980480 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-02 11:27 - 2015-03-12 21:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-02 11:27 - 2015-03-12 21:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-02 11:27 - 2015-03-12 21:09 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-02 11:27 - 2015-03-12 21:08 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-02 11:27 - 2015-03-12 21:08 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-02 11:27 - 2015-03-12 21:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-02 11:27 - 2015-03-12 21:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-02 11:27 - 2015-03-12 21:06 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-02 11:27 - 2015-03-12 21:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-02 11:27 - 2015-03-12 20:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-02 11:27 - 2015-03-12 20:55 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-02 11:27 - 2015-03-12 20:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-02 11:27 - 2015-03-12 20:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-02 11:27 - 2015-03-12 20:53 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-02 11:27 - 2015-03-12 20:50 - 06025216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-02 11:27 - 2015-03-12 20:44 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-02 11:27 - 2015-03-12 20:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-02 11:27 - 2015-03-12 20:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-05-02 11:27 - 2015-03-12 20:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-02 11:27 - 2015-03-12 20:32 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-02 11:27 - 2015-03-12 20:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-02 11:27 - 2015-03-12 20:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-05-02 11:27 - 2015-03-12 20:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-02 11:27 - 2015-03-12 20:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-02 11:27 - 2015-03-12 20:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-05-02 11:27 - 2015-03-12 20:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-02 11:27 - 2015-03-12 20:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-05-02 11:27 - 2015-03-12 20:23 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-02 11:27 - 2015-03-12 20:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-02 11:27 - 2015-03-12 20:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-05-02 11:27 - 2015-03-12 20:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-05-02 11:27 - 2015-03-12 20:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-05-02 11:27 - 2015-03-12 20:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-05-02 11:27 - 2015-03-12 20:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-05-02 11:27 - 2015-03-12 20:08 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-02 11:27 - 2015-03-12 20:07 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-02 11:27 - 2015-03-12 20:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-05-02 11:27 - 2015-03-12 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-02 11:27 - 2015-03-12 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-02 11:27 - 2015-03-12 20:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-05-02 11:27 - 2015-03-12 20:00 - 14397440 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-02 11:27 - 2015-03-12 19:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-05-02 11:27 - 2015-03-12 19:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-02 11:27 - 2015-03-12 19:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-02 11:27 - 2015-03-12 19:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-02 11:27 - 2015-03-12 19:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-02 11:27 - 2015-03-12 19:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-02 11:27 - 2015-03-12 19:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-02 11:27 - 2015-03-12 19:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-05-02 11:27 - 2015-03-12 19:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-02 11:27 - 2015-03-12 19:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-02 11:27 - 2015-03-12 19:22 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-02 11:27 - 2015-03-12 19:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-02 11:27 - 2015-03-12 19:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-02 11:27 - 2015-03-12 19:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-02 11:27 - 2015-03-03 21:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-05-02 11:27 - 2015-03-03 21:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-05-02 11:27 - 2015-03-03 21:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-19 05:20 - 2015-04-19 05:20 - 00005872 _____ () C:\Users\Owner\AppData\Roaming\xkLc3uuMHcyRR6cmoFug
2015-04-19 05:20 - 2015-04-19 05:20 - 00005872 _____ () C:\Users\Owner\AppData\Roaming\TdJ7xwKd
2015-04-14 09:28 - 2015-04-14 09:28 - 00004387 _____ () C:\Users\Owner\AppData\Roaming\QSx4mPCRXgVp3vx17I8SPjzMlB
2015-04-14 09:28 - 2015-04-14 09:28 - 00004387 _____ () C:\Users\Owner\AppData\Roaming\GTADpvow8oqf2kN80ud

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-07 18:34 - 2009-07-13 21:45 - 00029120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-07 18:34 - 2009-07-13 21:45 - 00029120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-07 18:22 - 2014-07-23 19:03 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-07 18:21 - 2014-07-09 09:50 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-07 17:24 - 2009-07-13 22:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-07 17:24 - 2009-07-13 21:51 - 00032744 _____ () C:\Windows\setupact.log
2015-05-06 22:35 - 2014-07-03 11:22 - 01347409 _____ () C:\Windows\WindowsUpdate.log
2015-05-05 22:48 - 2015-03-01 09:30 - 00001290 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-05 22:48 - 2014-07-09 09:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-05 22:48 - 2014-07-09 09:47 - 00001065 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-05 22:48 - 2014-07-03 11:27 - 00000959 _____ () C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-05-05 20:37 - 2014-07-09 09:47 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-05-05 19:59 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\Resources
2015-05-04 21:33 - 2010-11-20 20:47 - 00841598 _____ () C:\Windows\PFRO.log
2015-05-04 21:30 - 2009-07-13 22:32 - 00000000 ____D () C:\Windows\addins
2015-05-04 21:27 - 2015-03-01 08:58 - 00000000 ____D () C:\Users\Owner\AppData\Local\ab8fbb56-07e0-4e81-a11d-45c5bdf2cc9a
2015-05-04 21:27 - 2009-07-13 20:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-05-04 17:40 - 2015-03-03 18:44 - 00000000 ___HD () C:\Users\Public\Temp
2015-05-03 20:01 - 2015-03-07 13:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-03 20:01 - 2014-07-09 09:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-03 16:22 - 2009-07-13 19:34 - 00000505 _____ () C:\Windows\win.ini
2015-05-03 13:55 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\rescache
2015-05-03 11:35 - 2014-07-03 11:27 - 00000000 ____D () C:\Users\Owner
2015-05-03 11:28 - 2014-09-11 17:52 - 00000000 ____D () C:\Program Files (x86)\AutoEnginuity
2015-05-03 11:27 - 2015-03-04 14:44 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-03 11:05 - 2009-07-13 20:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-05-03 11:05 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-05-02 23:20 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\AppCompat
2015-05-02 17:29 - 2014-12-10 03:25 - 00000000 ____D () C:\Windows\system32\appraiser
2015-05-02 17:29 - 2014-07-09 17:44 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-05-02 17:29 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-05-02 16:59 - 2014-07-09 17:21 - 00774028 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-05-02 16:59 - 2009-07-13 22:13 - 00774028 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-02 16:55 - 2014-07-09 12:24 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-02 16:19 - 2014-07-09 12:24 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-02 11:23 - 2014-07-23 19:03 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-05-02 11:23 - 2014-07-23 19:03 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-05-02 11:23 - 2014-07-23 19:03 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater

==================== Files in the root of some directories =======

2015-04-14 09:28 - 2015-04-14 09:28 - 0004387 _____ () C:\Users\Owner\AppData\Roaming\GTADpvow8oqf2kN80ud
2015-04-14 09:28 - 2015-04-14 09:28 - 0004387 _____ () C:\Users\Owner\AppData\Roaming\QSx4mPCRXgVp3vx17I8SPjzMlB
2015-04-19 05:20 - 2015-04-19 05:20 - 0005872 _____ () C:\Users\Owner\AppData\Roaming\TdJ7xwKd
2015-04-19 05:20 - 2015-04-19 05:20 - 0005872 _____ () C:\Users\Owner\AppData\Roaming\xkLc3uuMHcyRR6cmoFug
2015-03-09 14:30 - 2015-03-09 14:30 - 0005487 _____ () C:\Users\Owner\AppData\Roaming\YOXALEU
2015-02-07 17:51 - 2015-02-07 17:51 - 0000064 _____ () C:\Users\Owner\AppData\Local\0df296065d8b7004eef1fd7c1e1c4f9c
2015-05-03 08:39 - 2015-05-03 08:39 - 0613255 _____ (CMI Limited) C:\Users\Owner\AppData\Local\nscE964.tmp
2015-05-02 23:32 - 2015-05-02 23:31 - 0613255 _____ (CMI Limited) C:\Users\Owner\AppData\Local\nsr8C65.tmp
2015-05-02 23:05 - 2015-05-02 23:04 - 0613255 _____ (CMI Limited) C:\Users\Owner\AppData\Local\nszFB57.tmp
2014-12-14 20:24 - 2014-12-14 20:24 - 0000080 _____ () C:\Users\Owner\AppData\Local\X-Plane Installer.prf
2014-12-14 20:24 - 2014-12-14 20:46 - 0000015 _____ () C:\Users\Owner\AppData\Local\X-Plane_drm.prf
2014-12-14 18:52 - 2014-12-14 18:52 - 0000041 _____ () C:\Users\Owner\AppData\Local\x-plane_install_10.txt

Some content of TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\117E33AA-A836-729F-A61B-C83629B4D037.exe
C:\Users\Owner\AppData\Local\Temp\1764.exe
C:\Users\Owner\AppData\Local\Temp\4360.exe
C:\Users\Owner\AppData\Local\Temp\57A9BEBD-780D-FEAF-ECCB-E80B32EE8CF3.dll
C:\Users\Owner\AppData\Local\Temp\6C56A3B9-E153-8CB2-E301-064433884E37.dll
C:\Users\Owner\AppData\Local\Temp\6C56A3B9-E153-8CB2-E301-064433884E37.exe
C:\Users\Owner\AppData\Local\Temp\7710.exe
C:\Users\Owner\AppData\Local\Temp\7FE20657-986D-8DB1-A42F-614498676B9A.dll
C:\Users\Owner\AppData\Local\Temp\7FE20657-986D-8DB1-A42F-614498676B9A.exe
C:\Users\Owner\AppData\Local\Temp\amisetup0690__11083.exe
C:\Users\Owner\AppData\Local\Temp\amisetup6464__11904.exe
C:\Users\Owner\AppData\Local\Temp\B7A8CC63-2332-DAD1-1096-C6F5AB5B74C3.exe
C:\Users\Owner\AppData\Local\Temp\BackupSetup.exe
C:\Users\Owner\AppData\Local\Temp\CloudBackup2742.exe
C:\Users\Owner\AppData\Local\Temp\compete.exe
C:\Users\Owner\AppData\Local\Temp\ConsumerInputSetup.exe
C:\Users\Owner\AppData\Local\Temp\cw.exe
C:\Users\Owner\AppData\Local\Temp\EC6DC9F6-4A5C-EBF9-3A3E-ADF370770EB1.exe
C:\Users\Owner\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Owner\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Owner\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Owner\AppData\Local\Temp\Launcher__10979.exe
C:\Users\Owner\AppData\Local\Temp\Launcher__11273.exe
C:\Users\Owner\AppData\Local\Temp\nsi62FB.exe
C:\Users\Owner\AppData\Local\Temp\nsuD9CF.exe
C:\Users\Owner\AppData\Local\Temp\optprosetup.exe
C:\Users\Owner\AppData\Local\Temp\Quarantine.exe
C:\Users\Owner\AppData\Local\Temp\SpOrder.dll
C:\Users\Owner\AppData\Local\Temp\sqlite3.dll
C:\Users\Owner\AppData\Local\Temp\supoptsetup.exe
C:\Users\Owner\AppData\Local\Temp\SymCCIS.dll
C:\Users\Owner\AppData\Local\Temp\tu17p84.exe
C:\Users\Owner\AppData\Local\Temp\UninstallModule.exe
C:\Users\Owner\AppData\Local\Temp\vcredist_x64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-06 20:19

==================== End Of Log ============================



BC AdBot (Login to Remove)

 


#2 duffster

duffster
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Arizona
  • Local time:03:04 PM

Posted 09 May 2015 - 12:21 AM

Nevermind, got it all repaired by reading and downloading a bunch of different tools fromthe downloads section. Thx.



#3 nasdaq

nasdaq

  • Malware Response Team
  • 38,942 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:04 PM

Posted 12 May 2015 - 09:34 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users