Results 1 to 4 of 4

Thread: New Laptop- malware and adchoice problems persiting

  1. #1
    Junior Member
    Join Date
    Dec 2014
    Posts
    1

    Default New Laptop- malware and adchoice problems persiting

    I have produced logs requested. My laptop is very slow and there are ads showing up on nearly all pages. My internet frequently wont load due to internet problems which is probably part of the infections. I have a paid Bitfender antivirus but is not helping.


    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-12-2014 02
    Ran by Yvette (administrator) on EVE on 06-12-2014 19:47:14
    Running from C:\Users\Yvette\Downloads
    Loaded Profile: Yvette (Available profiles: Yvette)
    Platform: Windows 8.1 (X64) OS Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe
    (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
    (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\Dragon Assistant\Core\DACore.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Microsoft Corporation) C:\Windows\System32\dasHost.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    (LENOVO INCORPORATED.) C:\Program Files\lenovo\iMController\SystemAgentService.exe
    (Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
    (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
    (Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
    (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
    (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
    (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
    (Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
    (PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe
    () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
    (Superfish, Inc.) C:\Program Files (x86)\Lenovo\VisualDiscovery\VisualDiscovery.exe
    (Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
    () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    (ClientConnect LTD) C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\CltMngSvc.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    () C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    () C:\Program Files (x86)\SoftwareUpdater\Upd4terSrv.exe_old
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Intel Corporation) C:\Windows\System32\igfxHK.exe
    (Intel Corporation) C:\Windows\System32\igfxTray.exe
    (Intel Corporation) C:\Windows\System32\igfxEM.exe
    (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Realtek semiconductor) C:\Windows\RTFTrack.exe
    (Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe
    () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
    (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
    (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
    () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe
    (BitTorrent Inc.) C:\Users\Yvette\AppData\Roaming\uTorrent\uTorrent.exe
    (S p i g o t, I n c.) C:\Users\Yvette\AppData\Roaming\Search Protection\SP.exe
    (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
    () C:\Program Files (x86)\Desktop Dock\DesktopDockApp.exe
    () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    (Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
    (Microsoft Corporation) C:\Windows\System32\WWAHost.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFiles.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\seccenter.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\odscanui.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\odslv.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxcr.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-03-26] (Intel Corporation)
    HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-01-22] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
    HKLM\...\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2013-10-17] (Realtek semiconductor)
    HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-09-15] (Lenovo)
    HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-09-15] ()
    HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2014-09-15] (Lenovo(beijing) Limited)
    HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-09-15] (Lenovo(beijing) Limited)
    HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe [1626752 2014-11-14] (Bitdefender)
    HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-06] (Lenovo)
    HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
    HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe [790344 2014-11-14] (Bitdefender)
    HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30528608 2014-11-27] (Skype Technologies S.A.)
    HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\Run: [uTorrent] => C:\Users\Yvette\AppData\Roaming\uTorrent\uTorrent.exe [1680464 2014-12-03] (BitTorrent Inc.)
    HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\Run: [Search Protection] => C:\Users\Yvette\AppData\Roaming\Search Protection\SP.EXE [1112936 2014-11-12] (S p i g o t, I n c.)
    AppInit_DLLs: C:\PROGRA~2\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64Loader.dll => C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64Loader.dll [206152 2014-08-25] (ClientConnect LTD)
    AppInit_DLLs-x32: C:\PROGRA~2\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll => C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll [173896 2014-08-25] (ClientConnect LTD)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DesktopDock.lnk
    ShortcutTarget: DesktopDock.lnk -> C:\Program Files (x86)\Desktop Dock\DesktopDock.exe (Desktop Dock)
    Startup: C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopDockApp.lnk
    ShortcutTarget: DesktopDockApp.lnk -> C:\Program Files (x86)\Desktop Dock\DesktopDockApp.exe ()
    ShellIconOverlayIdentifiers: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll (Hightail Inc.)
    ShellIconOverlayIdentifiers: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll (Hightail Inc.)
    ShellIconOverlayIdentifiers: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll (Hightail Inc.)
    ShellIconOverlayIdentifiers: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files\Hightail\Hightail for Lenovo\YSINSE64.dll (Hightail Inc.)
    ShellIconOverlayIdentifiers: [__SafeBox1] -> {152C96EB-288E-4EDC-B7C6-D21F8250ADF3} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
    ShellIconOverlayIdentifiers: [__SafeBox2] -> {342DAA0B-D796-460D-8566-901E08A1CCAD} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
    ShellIconOverlayIdentifiers: [__SafeBox3] -> {57595DAE-1AE1-4D97-A49E-67CBB53B52DF} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
    ShellIconOverlayIdentifiers: [__SafeBox4] -> {33816773-98AE-4723-ADE0-EBE54C8B5A67} => C:\Program Files\Bitdefender\Bitdefender SafeBox\SafeBoxShell.dll (Bitdefender)
    ShellIconOverlayIdentifiers-x32: [00001LenovoSyncComplete] -> {1E9CED2C-E7B4-4C47-B07A-25416393B67B} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll (Hightail Inc.)
    ShellIconOverlayIdentifiers-x32: [00002LenovoSyncActive] -> {C1285F4D-918F-4EF2-BC94-CAD5B118C835} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll (Hightail Inc.)
    ShellIconOverlayIdentifiers-x32: [00003LenovoSyncError] -> {CE5633DA-1488-4D1D-9A9B-B500297D4A8C} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll (Hightail Inc.)
    ShellIconOverlayIdentifiers-x32: [00004LenovoLocalOnly] -> {C7362DA9-D3AC-4C17-B2F5-2F1823FA04C3} => C:\Program Files (x86)\Hightail\Hightail for Lenovo\YSINSE.dll (Hightail Inc.)
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-3721279961-3922334345-2485629260-1001 -> DefaultScope {2A7F94B7-4D43-4BFE-82FC-5E7D4BFC0996} URL = https://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=903578&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-3721279961-3922334345-2485629260-1001 -> {2A7F94B7-4D43-4BFE-82FC-5E7D4BFC0996} URL = https://uk.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=903578&p={searchTerms}
    BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll (Bitdefender)
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
    BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll (Bitdefender)
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
    Toolbar: HKLM - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\pmbxie.dll (Bitdefender)
    Toolbar: HKLM-x32 - Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender 2015\Antispam32\pmbxie.dll (Bitdefender)
    Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

    FireFox:
    ========
    FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
    FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
    FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
    FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext
    FF Extension: Bitdefender Antispam Toolbar - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext [2014-12-03]
    FF HKLM-x32\...\Firefox\Extensions: [bdwteff@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff
    FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender 2015\antispam32\bdwteff [2014-12-03]
    FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2015\bdtbext

    Chrome:
    =======
    CHR Profile: C:\Users\Yvette\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Yvette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-05]
    CHR Extension: (Bitdefender Wallet) - C:\Users\Yvette\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabcmochhfpldjekobfaaggijgohadih [2014-12-05]
    CHR Extension: (Google Wallet) - C:\Users\Yvette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-05]
    CHR HKLM-x32\...\Chrome\Extension: [fabcmochhfpldjekobfaaggijgohadih] - No Path

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S3 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2015\bdparentalservice.exe [78144 2014-10-07] (Bitdefender)
    R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2169016 2014-01-02] (Microsoft Corporation)
    R2 CltMngSvc; C:\Program Files (x86)\LenovoBrowserGuard\Main\bin\CltMngSvc.exe [2538824 2014-08-25] (ClientConnect LTD)
    R2 DACoreService; C:\Program Files (x86)\Nuance\Dragon Assistant\Core\DACore.exe [432528 2013-05-02] (Nuance Communications, Inc.)
    R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-03-26] (Intel Corporation)
    R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282072 2014-03-10] (Intel Corporation)
    R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
    R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-16] (Intel Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
    S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [533760 2014-06-03] (Lenovo)
    R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
    R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-09-15] (Lenovo(beijing) Limited)
    R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-09-15] (Lenovo)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-18] ()
    R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-13] (Nitro PDF Software)
    R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [167176 2014-02-24] (PointGrab LTD)
    R2 PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [512776 2014-02-24] (PointGrab LTD)
    R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [285712 2014-09-15] (Lenovo)
    S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [304144 2014-09-15] (Lenovo)
    R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
    S4 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender)
    R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
    R2 SrvUpdater; C:\Program Files (x86)\SoftwareUpdater\Upd4terSrv.exe [196096 2014-12-05] () [File not signed]
    R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe [67320 2014-10-27] (Bitdefender)
    R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-09-15] ()
    R2 VisualDiscovery; C:\Program Files (x86)\Lenovo\VisualDiscovery\VisualDiscovery.exe [1354296 2014-06-21] (Superfish, Inc.)
    R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [1527360 2014-11-14] (Bitdefender)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
    R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-09-15] (Lenovo)
    R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2014-01-06] ()
    R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-01-18] (Intel® Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1288472 2014-09-25] (BitDefender)
    R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [263032 2014-10-03] (BitDefender)
    R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-05-16] (BitDefender)
    S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
    S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23568 2013-09-08] (Bitdefender)
    R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-11-19] (BitDefender LLC)
    R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-07-29] (BitDefender LLC)
    S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
    S3 BDSandBox; C:\windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
    R1 BDVEDISK; C:\Windows\system32\DRIVERS\bdvedisk.sys [79192 2013-07-30] (BitDefender)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
    R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
    R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [142280 2013-10-18] (Intel Corporation)
    R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
    R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3433952 2014-02-18] (Intel Corporation)
    S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
    R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8876248 2013-10-17] (Realtek Semiconductor Corp.)
    R3 SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
    R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
    R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-12-19] (Synaptics Incorporated)
    R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [452040 2014-10-15] (BitDefender S.R.L.)
    R2 VDWFP; C:\windows\system32\Drivers\VDWFP64.sys [39800 2014-05-12] (Superfish, Inc.)
    S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
    S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-12-06 19:47 - 2014-12-06 19:47 - 00025205 _____ () C:\Users\Yvette\Downloads\FRST.txt
    2014-12-06 19:45 - 2014-12-06 19:47 - 00000000 ____D () C:\FRST
    2014-12-06 19:43 - 2014-12-06 19:43 - 02119168 _____ (Farbar) C:\Users\Yvette\Downloads\FRST64 (1).exe
    2014-12-06 19:38 - 2014-12-06 19:38 - 02119168 _____ (Farbar) C:\Users\Yvette\Downloads\FRST64.exe
    2014-12-06 19:35 - 2014-12-06 19:35 - 00000207 _____ () C:\windows\tweaking.com-regbackup-EVE-Microsoft-Windows-8.1-(64-bit).dat
    2014-12-06 19:34 - 2014-12-06 19:34 - 00000000 ____D () C:\RegBackup
    2014-12-06 19:33 - 2014-12-06 19:33 - 00002266 _____ () C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
    2014-12-06 19:33 - 2014-12-06 19:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
    2014-12-06 19:33 - 2014-12-06 19:33 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
    2014-12-06 19:31 - 2014-12-06 19:31 - 04215584 _____ () C:\Users\Yvette\Downloads\tweaking.com_registry_backup_setup.exe
    2014-12-06 12:40 - 2014-12-06 12:40 - 00000000 __SHD () C:\Users\Yvette\AppData\Local\EmieBrowserModeList
    2014-12-05 23:52 - 2014-12-05 23:52 - 04184008 _____ (Kaspersky Lab ZAO) C:\Users\Yvette\Downloads\tdsskiller.exe
    2014-12-05 23:40 - 2014-12-06 19:17 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Dock
    2014-12-05 23:40 - 2014-12-06 12:39 - 00000000 ____D () C:\Users\Yvette\AppData\Local\DesktopDock
    2014-12-05 23:40 - 2014-12-05 23:40 - 08399438 _____ () C:\Users\Yvette\Downloads\35062-6045-ewido-anti-spyware.exe
    2014-12-05 23:40 - 2014-12-05 23:40 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Desktop Dock
    2014-12-05 23:40 - 2014-12-05 23:40 - 00000000 ____D () C:\Program Files (x86)\Desktop Dock
    2014-12-05 23:38 - 2014-12-05 23:44 - 00000000 ____D () C:\Program Files (x86)\SoftwareUpdater
    2014-12-05 23:32 - 2014-12-05 23:32 - 00840416 _____ () C:\Users\Yvette\Downloads\installer_ewido_anti-spyware_4_0_English.exe
    2014-12-05 23:16 - 2014-12-05 23:16 - 00001418 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2014-12-05 23:16 - 2014-12-05 23:16 - 00001406 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2014-12-05 23:16 - 2014-12-05 23:16 - 00000000 ____D () C:\windows\System32\Tasks\Safer-Networking
    2014-12-05 23:16 - 2014-12-05 23:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2014-12-05 23:15 - 2014-12-05 23:57 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
    2014-12-05 23:15 - 2014-12-05 23:19 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
    2014-12-05 23:15 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe
    2014-12-05 23:12 - 2014-12-05 23:14 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Yvette\Downloads\spybot-2.4.exe
    2014-12-05 21:43 - 2014-12-05 22:59 - 785613345 _____ () C:\Users\Yvette\Downloads\Girl.Most.Likely.2012.720p.BluRay.750MB.ShAaNiG.com.mkv
    2014-12-05 21:42 - 2014-12-05 21:42 - 00000000 ____D () C:\Users\Yvette\Downloads\Girl.Most.Likely.2012.Blu-Ray.1080p.NovaLan
    2014-12-05 20:51 - 2014-12-05 23:34 - 00000000 ____D () C:\Users\Yvette\Downloads\Frank Ocean - Channel Orange [2012] [256 kbps]
    2014-12-05 20:47 - 2014-12-05 20:48 - 00000000 ____D () C:\Users\Yvette\Downloads\Frank Ocean - Lost
    2014-12-05 18:47 - 2014-12-05 18:47 - 00000000 __SHD () C:\found.002
    2014-12-05 18:01 - 2014-12-05 18:01 - 00000000 ___SD () C:\windows\system32\CompatTel
    2014-12-05 17:57 - 2014-04-14 03:29 - 01018880 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
    2014-12-05 17:56 - 2014-12-05 17:56 - 00000000 __SHD () C:\found.001
    2014-12-05 17:56 - 2014-12-05 17:56 - 00000000 __SHD () C:\found.000
    2014-12-05 17:53 - 2014-12-05 17:57 - 00000000 ____D () C:\windows\system32\MRT
    2014-12-05 17:53 - 2014-10-31 23:26 - 103374192 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
    2014-12-05 01:22 - 2014-07-24 15:03 - 02141920 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
    2014-12-05 01:22 - 2014-07-24 13:36 - 02145472 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
    2014-12-05 01:22 - 2014-07-24 11:43 - 00412160 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
    2014-12-05 01:22 - 2014-07-24 09:44 - 16874496 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll
    2014-12-05 01:22 - 2014-07-24 09:16 - 12730880 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll
    2014-12-05 01:22 - 2014-07-24 08:53 - 01261056 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll
    2014-12-05 01:22 - 2014-07-24 08:32 - 01532416 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll
    2014-12-05 01:22 - 2014-07-24 08:21 - 01231872 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll
    2014-12-05 01:22 - 2014-07-24 08:10 - 00889344 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll
    2014-12-05 01:22 - 2014-07-24 07:28 - 01600000 _____ (Microsoft Corporation) C:\windows\system32\workfolderssvc.dll
    2014-12-05 01:22 - 2014-06-14 06:03 - 02389504 _____ (Microsoft Corporation) C:\windows\system32\d3d10warp.dll
    2014-12-05 01:22 - 2014-06-14 05:46 - 02071552 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d10warp.dll
    2014-12-05 01:21 - 2014-07-24 15:28 - 00419648 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
    2014-12-05 01:21 - 2014-07-24 15:28 - 00412992 _____ (Microsoft Corporation) C:\windows\system32\Drivers\spaceport.sys
    2014-12-05 01:21 - 2014-07-24 15:28 - 00280384 _____ (Microsoft Corporation) C:\windows\system32\Drivers\pci.sys
    2014-12-05 01:21 - 2014-07-24 15:28 - 00143680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
    2014-12-05 01:21 - 2014-07-24 15:23 - 00125472 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll
    2014-12-05 01:21 - 2014-07-24 15:20 - 00645592 _____ (Microsoft Corporation) C:\windows\system32\SHCore.dll
    2014-12-05 01:21 - 2014-07-24 15:20 - 00263400 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlows.exe
    2014-12-05 01:21 - 2014-07-24 15:16 - 02574208 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
    2014-12-05 01:21 - 2014-07-24 15:16 - 00211216 _____ (Microsoft Corporation) C:\windows\system32\SndVol.exe
    2014-12-05 01:21 - 2014-07-24 15:07 - 02009920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
    2014-12-05 01:21 - 2014-07-24 15:05 - 01660048 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
    2014-12-05 01:21 - 2014-07-24 15:05 - 01519560 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
    2014-12-05 01:21 - 2014-07-24 15:05 - 01488008 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
    2014-12-05 01:21 - 2014-07-24 15:05 - 01356840 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
    2014-12-05 01:21 - 2014-07-24 15:03 - 00882136 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
    2014-12-05 01:21 - 2014-07-24 15:03 - 00360480 _____ (Microsoft Corporation) C:\windows\system32\mfreadwrite.dll
    2014-12-05 01:21 - 2014-07-24 15:03 - 00233888 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
    2014-12-05 01:21 - 2014-07-24 15:03 - 00205512 _____ (Microsoft Corporation) C:\windows\system32\mftranscode.dll
    2014-12-05 01:21 - 2014-07-24 13:50 - 00098048 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll
    2014-12-05 01:21 - 2014-07-24 13:48 - 02410976 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
    2014-12-05 01:21 - 2014-07-24 13:48 - 00180208 _____ (Microsoft Corporation) C:\windows\SysWOW64\SndVol.exe
    2014-12-05 01:21 - 2014-07-24 13:46 - 00477200 _____ (Microsoft Corporation) C:\windows\SysWOW64\SHCore.dll
    2014-12-05 01:21 - 2014-07-24 13:36 - 00707536 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
    2014-12-05 01:21 - 2014-07-24 13:36 - 00355800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfreadwrite.dll
    2014-12-05 01:21 - 2014-07-24 13:36 - 00180720 _____ (Microsoft Corporation) C:\windows\SysWOW64\mftranscode.dll
    2014-12-05 01:21 - 2014-07-24 11:51 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\KBDRUM.DLL
    2014-12-05 01:21 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDYAK.DLL
    2014-12-05 01:21 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDTT102.DLL
    2014-12-05 01:21 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDTAT.DLL
    2014-12-05 01:21 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDRU1.DLL
    2014-12-05 01:21 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\windows\system32\KBDBASH.DLL
    2014-12-05 01:21 - 2014-07-24 11:51 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\KBDRU.DLL
    2014-12-05 01:21 - 2014-07-24 11:46 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\Drivers\IPMIDrv.sys
    2014-12-05 01:21 - 2014-07-24 11:45 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hdaudbus.sys
    2014-12-05 01:21 - 2014-07-24 11:44 - 00674816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
    2014-12-05 01:21 - 2014-07-24 11:42 - 00446976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\nwifi.sys
    2014-12-05 01:21 - 2014-07-24 11:42 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\NdisImPlatform.sys
    2014-12-05 01:21 - 2014-07-24 11:41 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthpan.sys
    2014-12-05 01:21 - 2014-07-24 11:06 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\iasnap.dll
    2014-12-05 01:21 - 2014-07-24 11:05 - 00287232 _____ (Microsoft Corporation) C:\windows\system32\usbmon.dll
    2014-12-05 01:21 - 2014-07-24 11:05 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
    2014-12-05 01:21 - 2014-07-24 10:52 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDYAK.DLL
    2014-12-05 01:21 - 2014-07-24 10:52 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDTT102.DLL
    2014-12-05 01:21 - 2014-07-24 10:52 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDTAT.DLL
    2014-12-05 01:21 - 2014-07-24 10:51 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRUM.DLL
    2014-12-05 01:21 - 2014-07-24 10:51 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU1.DLL
    2014-12-05 01:21 - 2014-07-24 10:51 - 00007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDBASH.DLL
    2014-12-05 01:21 - 2014-07-24 10:51 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\KBDRU.DLL
    2014-12-05 01:21 - 2014-07-24 10:49 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\WorkFoldersGPExt.dll
    2014-12-05 01:21 - 2014-07-24 10:32 - 00207360 _____ (Microsoft Corporation) C:\windows\system32\powercfg.cpl
    2014-12-05 01:21 - 2014-07-24 10:20 - 02050560 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
    2014-12-05 01:21 - 2014-07-24 10:18 - 01089024 _____ (Microsoft Corporation) C:\windows\system32\gpedit.dll
    2014-12-05 01:21 - 2014-07-24 10:12 - 00878592 _____ (Microsoft Corporation) C:\windows\system32\ActionCenter.dll
    2014-12-05 01:21 - 2014-07-24 10:10 - 01844224 _____ (Microsoft Corporation) C:\windows\system32\Display.dll
    2014-12-05 01:21 - 2014-07-24 10:10 - 00834560 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
    2014-12-05 01:21 - 2014-07-24 10:10 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
    2014-12-05 01:21 - 2014-07-24 10:10 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\iasnap.dll
    2014-12-05 01:21 - 2014-07-24 10:05 - 00187392 _____ (Microsoft Corporation) C:\windows\system32\WorkFoldersShell.dll
    2014-12-05 01:21 - 2014-07-24 09:52 - 00621056 _____ (Microsoft Corporation) C:\windows\system32\comdlg32.dll
    2014-12-05 01:21 - 2014-07-24 09:42 - 00206336 _____ (Microsoft Corporation) C:\windows\SysWOW64\powercfg.cpl
    2014-12-05 01:21 - 2014-07-24 09:40 - 00557056 _____ (Microsoft Corporation) C:\windows\system32\PrintDialogs.dll
    2014-12-05 01:21 - 2014-07-24 09:39 - 00770048 _____ (Microsoft Corporation) C:\windows\system32\WorkfoldersControl.dll
    2014-12-05 01:21 - 2014-07-24 09:33 - 01741824 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
    2014-12-05 01:21 - 2014-07-24 09:32 - 01048064 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpedit.dll
    2014-12-05 01:21 - 2014-07-24 09:27 - 00779264 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
    2014-12-05 01:21 - 2014-07-24 09:25 - 00832512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ActionCenter.dll
    2014-12-05 01:21 - 2014-07-24 09:24 - 01817088 _____ (Microsoft Corporation) C:\windows\SysWOW64\Display.dll
    2014-12-05 01:21 - 2014-07-24 09:21 - 00134144 _____ (Microsoft Corporation) C:\windows\system32\browser.dll
    2014-12-05 01:21 - 2014-07-24 09:18 - 00018432 _____ (Microsoft Corporation) C:\windows\system32\wlansvcpal.dll
    2014-12-05 01:21 - 2014-07-24 09:14 - 00443904 _____ (Microsoft Corporation) C:\windows\system32\wlansec.dll
    2014-12-05 01:21 - 2014-07-24 09:12 - 00127488 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
    2014-12-05 01:21 - 2014-07-24 09:11 - 00356864 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
    2014-12-05 01:21 - 2014-07-24 09:11 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\wshbth.dll
    2014-12-05 01:21 - 2014-07-24 09:10 - 00540672 _____ (Microsoft Corporation) C:\windows\SysWOW64\comdlg32.dll
    2014-12-05 01:21 - 2014-07-24 09:04 - 00492032 _____ (Microsoft Corporation) C:\windows\SysWOW64\PrintDialogs.dll
    2014-12-05 01:21 - 2014-07-24 09:04 - 00183808 _____ (Microsoft Corp.) C:\windows\system32\Defrag.exe
    2014-12-05 01:21 - 2014-07-24 09:03 - 00324096 _____ (Microsoft Corporation) C:\windows\system32\srvsvc.dll
    2014-12-05 01:21 - 2014-07-24 09:02 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
    2014-12-05 01:21 - 2014-07-24 08:58 - 00105472 _____ (Microsoft Corporation) C:\windows\system32\BluetoothApis.dll
    2014-12-05 01:21 - 2014-07-24 08:53 - 00449536 _____ (Microsoft Corporation) C:\windows\system32\defragsvc.dll
    2014-12-05 01:21 - 2014-07-24 08:49 - 01287680 _____ (Microsoft Corporation) C:\windows\system32\mispace.dll
    2014-12-05 01:21 - 2014-07-24 08:49 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\wlanapi.dll
    2014-12-05 01:21 - 2014-07-24 08:48 - 00659968 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Bluetooth.dll
    2014-12-05 01:21 - 2014-07-24 08:47 - 00102912 _____ (Microsoft Corporation) C:\windows\system32\wcmcsp.dll
    2014-12-05 01:21 - 2014-07-24 08:43 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshbth.dll
    2014-12-05 01:21 - 2014-07-24 08:39 - 02397184 _____ (Microsoft Corporation) C:\windows\system32\storagewmi.dll
    2014-12-05 01:21 - 2014-07-24 08:38 - 00371200 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll
    2014-12-05 01:21 - 2014-07-24 08:36 - 00079872 _____ (Microsoft Corporation) C:\windows\SysWOW64\BluetoothApis.dll
    2014-12-05 01:21 - 2014-07-24 08:30 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanapi.dll
    2014-12-05 01:21 - 2014-07-24 08:29 - 00439296 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Bluetooth.dll
    2014-12-05 01:21 - 2014-07-24 08:28 - 00595456 _____ (Microsoft Corporation) C:\windows\system32\Windows.Networking.dll
    2014-12-05 01:21 - 2014-07-24 08:23 - 01404416 _____ (Microsoft Corporation) C:\windows\SysWOW64\storagewmi.dll
    2014-12-05 01:21 - 2014-07-24 08:22 - 00487936 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv
    2014-12-05 01:21 - 2014-07-24 08:21 - 00302080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanmsm.dll
    2014-12-05 01:21 - 2014-07-24 08:18 - 01144320 _____ (Microsoft Corporation) C:\windows\system32\wwanmm.dll
    2014-12-05 01:21 - 2014-07-24 08:18 - 00795136 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
    2014-12-05 01:21 - 2014-07-24 08:16 - 00505344 _____ (Microsoft Corporation) C:\windows\system32\VAN.dll
    2014-12-05 01:21 - 2014-07-24 08:16 - 00084480 _____ (Microsoft Corporation) C:\windows\system32\wpdbusenum.dll
    2014-12-05 01:21 - 2014-07-24 08:15 - 00721408 _____ (Microsoft Corporation) C:\windows\system32\twinapi.dll
    2014-12-05 01:21 - 2014-07-24 08:15 - 00432128 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Networking.dll
    2014-12-05 01:21 - 2014-07-24 08:13 - 00226304 _____ (Microsoft Corporation) C:\windows\system32\SndVolSSO.dll
    2014-12-05 01:21 - 2014-07-24 08:10 - 00371712 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv
    2014-12-05 01:21 - 2014-07-24 08:08 - 00321536 _____ (Microsoft Corporation) C:\windows\system32\stobject.dll
    2014-12-05 01:21 - 2014-07-24 08:05 - 00448000 _____ (Microsoft Corporation) C:\windows\SysWOW64\VAN.dll
    2014-12-05 01:21 - 2014-07-24 08:01 - 01992192 _____ (Microsoft Corporation) C:\windows\system32\XpsPrint.dll
    2014-12-05 01:21 - 2014-07-24 08:00 - 02100736 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlowUI.dll
    2014-12-05 01:21 - 2014-07-24 07:58 - 00432640 _____ (Microsoft Corporation) C:\windows\system32\wwanconn.dll
    2014-12-05 01:21 - 2014-07-24 07:58 - 00288768 _____ (Microsoft Corporation) C:\windows\SysWOW64\stobject.dll
    2014-12-05 01:21 - 2014-07-24 07:54 - 01290752 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsPrint.dll
    2014-12-05 01:21 - 2014-07-24 07:50 - 01182208 _____ (Microsoft Corporation) C:\windows\system32\printui.dll
    2014-12-05 01:21 - 2014-07-24 07:47 - 00576512 _____ (Microsoft Corporation) C:\windows\system32\SettingSync.dll
    2014-12-05 01:21 - 2014-07-24 07:44 - 01057792 _____ (Microsoft Corporation) C:\windows\SysWOW64\printui.dll
    2014-12-05 01:21 - 2014-07-24 07:41 - 00459264 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSync.dll
    2014-12-05 01:21 - 2014-07-24 04:11 - 00513544 _____ () C:\windows\SysWOW64\locale.nls
    2014-12-05 01:21 - 2014-07-24 04:11 - 00513544 _____ () C:\windows\system32\locale.nls
    2014-12-05 01:21 - 2014-07-12 05:55 - 00268288 _____ (Microsoft Corporation) C:\windows\system32\wisp.dll
    2014-12-05 01:21 - 2014-07-12 04:58 - 00210944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wisp.dll
    2014-12-05 01:21 - 2014-07-04 12:59 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ks.sys
    2014-12-05 01:21 - 2014-07-04 10:29 - 00117248 _____ (Microsoft Corporation) C:\windows\system32\AppxSip.dll
    2014-12-05 01:21 - 2014-07-04 10:20 - 01656832 _____ (Microsoft Corporation) C:\windows\system32\GdiPlus.dll
    2014-12-05 01:21 - 2014-07-04 10:06 - 00095232 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxSip.dll
    2014-12-05 01:21 - 2014-07-04 10:00 - 01351168 _____ (Microsoft Corporation) C:\windows\SysWOW64\GdiPlus.dll
    2014-12-05 01:21 - 2014-07-04 09:30 - 00544768 _____ (Microsoft Corporation) C:\windows\system32\AppxPackaging.dll
    2014-12-05 01:21 - 2014-07-04 09:27 - 00474112 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxPackaging.dll
    2014-12-05 01:21 - 2014-06-27 06:22 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
    2014-12-05 01:21 - 2014-06-26 00:32 - 01029632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mispace.dll
    2014-12-05 01:21 - 2014-06-26 00:29 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\dab.dll
    2014-12-05 01:21 - 2014-06-19 23:37 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
    2014-12-05 01:21 - 2014-06-19 02:13 - 00310080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\volsnap.sys
    2014-12-05 01:21 - 2014-06-07 12:46 - 00216368 _____ (Microsoft Corporation) C:\windows\system32\rsaenh.dll
    2014-12-05 01:21 - 2014-06-07 10:20 - 00189016 _____ (Microsoft Corporation) C:\windows\SysWOW64\rsaenh.dll
    2014-12-05 01:21 - 2014-06-05 14:00 - 01118040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
    2014-12-05 01:21 - 2014-06-05 10:18 - 01018368 _____ (Microsoft Corporation) C:\windows\system32\aclui.dll
    2014-12-05 01:21 - 2014-06-05 09:42 - 00889856 _____ (Microsoft Corporation) C:\windows\SysWOW64\aclui.dll
    2014-12-05 01:21 - 2014-05-31 05:00 - 01463808 _____ (Microsoft Corporation) C:\windows\system32\wsecedit.dll
    2014-12-05 01:21 - 2014-05-31 04:18 - 01319936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wsecedit.dll
    2014-12-05 01:21 - 2014-05-29 06:23 - 00427008 _____ (Microsoft Corporation) C:\windows\system32\clusapi.dll
    2014-12-05 01:21 - 2014-05-29 05:25 - 00313856 _____ (Microsoft Corporation) C:\windows\SysWOW64\clusapi.dll
    2014-12-05 01:21 - 2014-05-26 07:26 - 00053248 _____ (Microsoft Corporation) C:\windows\system32\AppxSysprep.dll
    2014-12-05 01:21 - 2014-05-10 10:12 - 00387896 _____ (Microsoft Corporation) C:\windows\system32\bcryptprimitives.dll
    2014-12-05 01:21 - 2014-05-10 08:46 - 00335680 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcryptprimitives.dll
    2014-12-05 01:21 - 2014-05-06 04:41 - 00486744 _____ (Microsoft Corporation) C:\windows\system32\netcfgx.dll
    2014-12-05 01:21 - 2014-05-06 00:55 - 00391000 _____ (Microsoft Corporation) C:\windows\SysWOW64\netcfgx.dll
    2014-12-05 01:21 - 2014-03-25 02:27 - 00160600 _____ (Microsoft Corporation) C:\windows\system32\winmmbase.dll
    2014-12-05 01:21 - 2014-03-25 02:27 - 00123920 _____ (Microsoft Corporation) C:\windows\system32\winmm.dll
    2014-12-05 01:21 - 2014-03-25 01:20 - 00128568 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmm.dll
    2014-12-05 01:21 - 2014-03-25 01:20 - 00127544 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmmbase.dll
    2014-12-05 01:10 - 2014-12-05 01:10 - 00002290 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-12-05 01:10 - 2014-12-05 01:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2014-12-05 01:08 - 2014-12-05 23:13 - 00000906 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-12-05 01:08 - 2014-12-05 20:25 - 00000902 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-12-05 01:08 - 2014-12-05 01:10 - 00000000 ____D () C:\Users\Yvette\AppData\Local\Google
    2014-12-05 01:08 - 2014-12-05 01:10 - 00000000 ____D () C:\Program Files (x86)\Google
    2014-12-05 01:08 - 2014-12-05 01:08 - 00003878 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-12-05 01:08 - 2014-12-05 01:08 - 00003642 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-12-05 01:07 - 2014-12-05 01:08 - 00000000 ____D () C:\Users\Yvette\AppData\Local\Deployment
    2014-12-05 01:07 - 2014-12-05 01:07 - 00000000 ____D () C:\Users\Yvette\AppData\Local\Apps\2.0
    2014-12-05 01:05 - 2014-12-05 01:05 - 00003542 _____ () C:\windows\System32\Tasks\CreateChoiceProcessTask
    2014-12-05 01:05 - 2013-08-22 06:57 - 00002143 ___RS () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser Choice.lnk
    2014-12-04 20:15 - 2014-12-04 20:15 - 00000000 _____ () C:\Recovery.txt
    2014-12-04 18:09 - 2014-12-05 01:05 - 00000000 ___RD () C:\windows\BrowserChoice
    2014-12-04 01:55 - 2014-07-30 01:56 - 00299520 _____ (Microsoft Corporation) C:\windows\system32\WSDMon.dll
    2014-12-04 01:55 - 2014-07-29 05:22 - 00205824 _____ (Microsoft Corporation) C:\windows\system32\tcpmon.dll
    2014-12-04 01:54 - 2014-08-15 00:36 - 00146752 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msgpioclx.sys
    2014-12-04 01:50 - 2014-10-31 05:28 - 25110016 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
    2014-12-04 01:50 - 2014-10-31 05:06 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
    2014-12-04 01:50 - 2014-10-31 05:05 - 02884096 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
    2014-12-04 01:50 - 2014-10-31 04:53 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
    2014-12-04 01:50 - 2014-10-31 04:51 - 00812544 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
    2014-12-04 01:50 - 2014-10-31 04:50 - 06040064 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
    2014-12-04 01:50 - 2014-10-31 04:50 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
    2014-12-04 01:50 - 2014-10-31 04:38 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
    2014-12-04 01:50 - 2014-10-31 04:30 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
    2014-12-04 01:50 - 2014-10-31 04:24 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
    2014-12-04 01:50 - 2014-10-31 04:21 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
    2014-12-04 01:50 - 2014-10-31 04:15 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
    2014-12-04 01:50 - 2014-10-31 04:06 - 00372736 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
    2014-12-04 01:50 - 2014-10-31 04:05 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
    2014-12-04 01:50 - 2014-10-31 04:05 - 00716800 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
    2014-12-04 01:50 - 2014-10-31 04:03 - 02124288 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
    2014-12-04 01:50 - 2014-10-31 03:59 - 14390272 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
    2014-12-04 01:50 - 2014-10-31 03:45 - 02365440 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
    2014-12-04 01:50 - 2014-10-31 03:44 - 02865152 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
    2014-12-04 01:50 - 2014-10-31 03:42 - 19781632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
    2014-12-04 01:50 - 2014-10-31 03:32 - 01550336 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
    2014-12-04 01:50 - 2014-10-31 03:24 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
    2014-12-04 01:50 - 2014-10-31 03:20 - 00799232 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
    2014-12-04 01:50 - 2014-10-31 03:18 - 02277376 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
    2014-12-04 01:50 - 2014-10-31 03:13 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
    2014-12-04 01:50 - 2014-10-31 03:12 - 00661504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
    2014-12-04 01:50 - 2014-10-31 03:11 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
    2014-12-04 01:50 - 2014-10-31 03:02 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
    2014-12-04 01:50 - 2014-10-31 02:57 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
    2014-12-04 01:50 - 2014-10-31 02:52 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
    2014-12-04 01:50 - 2014-10-31 02:50 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
    2014-12-04 01:50 - 2014-10-31 02:46 - 04298240 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
    2014-12-04 01:50 - 2014-10-31 02:46 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
    2014-12-04 01:50 - 2014-10-31 02:40 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
    2014-12-04 01:50 - 2014-10-31 02:40 - 00325632 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
    2014-12-04 01:50 - 2014-10-31 02:39 - 02051072 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
    2014-12-04 01:50 - 2014-10-31 02:30 - 12819456 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
    2014-12-04 01:50 - 2014-10-31 02:26 - 01042944 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
    2014-12-04 01:50 - 2014-10-31 02:17 - 01892864 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
    2014-12-04 01:50 - 2014-10-31 02:13 - 01310208 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
    2014-12-04 01:50 - 2014-10-31 02:11 - 00708096 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
    2014-12-04 01:49 - 2014-10-31 05:12 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
    2014-12-04 01:49 - 2014-10-31 05:12 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
    2014-12-04 01:49 - 2014-10-31 05:10 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
    2014-12-04 01:49 - 2014-10-31 05:09 - 00064512 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
    2014-12-04 01:49 - 2014-10-31 05:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
    2014-12-04 01:49 - 2014-10-31 05:06 - 00237568 _____ (Microsoft Corporation) C:\windows\system32\url.dll
    2014-12-04 01:49 - 2014-10-31 05:06 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
    2014-12-04 01:49 - 2014-10-31 05:06 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
    2014-12-04 01:49 - 2014-10-31 05:05 - 00417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
    2014-12-04 01:49 - 2014-10-31 05:04 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
    2014-12-04 01:49 - 2014-10-31 04:57 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
    2014-12-04 01:49 - 2014-10-31 04:56 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
    2014-12-04 01:49 - 2014-10-31 04:54 - 00132096 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
    2014-12-04 01:49 - 2014-10-31 04:52 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
    2014-12-04 01:49 - 2014-10-31 04:51 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
    2014-12-04 01:49 - 2014-10-31 04:51 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
    2014-12-04 01:49 - 2014-10-31 04:40 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
    2014-12-04 01:49 - 2014-10-31 04:29 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
    2014-12-04 01:49 - 2014-10-31 04:29 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
    2014-12-04 01:49 - 2014-10-31 04:28 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
    2014-12-04 01:49 - 2014-10-31 04:25 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
    2014-12-04 01:49 - 2014-10-31 04:24 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
    2014-12-04 01:49 - 2014-10-31 04:23 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
    2014-12-04 01:49 - 2014-10-31 04:19 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
    2014-12-04 01:49 - 2014-10-31 04:08 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
    2014-12-04 01:49 - 2014-10-31 03:42 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
    2014-12-04 01:49 - 2014-10-31 03:28 - 00137728 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe
    2014-12-04 01:49 - 2014-10-31 03:28 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe
    2014-12-04 01:49 - 2014-10-31 03:27 - 00152064 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe
    2014-12-04 01:49 - 2014-10-31 03:26 - 00057344 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll
    2014-12-04 01:49 - 2014-10-31 03:25 - 00011264 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe
    2014-12-04 01:49 - 2014-10-31 03:24 - 00235520 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
    2014-12-04 01:49 - 2014-10-31 03:24 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
    2014-12-04 01:49 - 2014-10-31 03:23 - 00340992 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
    2014-12-04 01:49 - 2014-10-31 03:23 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
    2014-12-04 01:49 - 2014-10-31 03:22 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
    2014-12-04 01:49 - 2014-10-31 03:16 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
    2014-12-04 01:49 - 2014-10-31 03:15 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
    2014-12-04 01:49 - 2014-10-31 03:14 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll
    2014-12-04 01:49 - 2014-10-31 03:13 - 00099328 _____ (Microsoft Corporation) C:\windows\SysWOW64\hlink.dll
    2014-12-04 01:49 - 2014-10-31 03:12 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
    2014-12-04 01:49 - 2014-10-31 03:03 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll
    2014-12-04 01:49 - 2014-10-31 02:56 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
    2014-12-04 01:49 - 2014-10-31 02:56 - 00090624 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
    2014-12-04 01:49 - 2014-10-31 02:56 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
    2014-12-04 01:49 - 2014-10-31 02:53 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
    2014-12-04 01:49 - 2014-10-31 02:53 - 00052736 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
    2014-12-04 01:49 - 2014-10-31 02:51 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
    2014-12-04 01:49 - 2014-10-31 02:48 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
    2014-12-04 01:49 - 2014-10-31 02:42 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
    2014-12-04 01:49 - 2014-10-31 02:24 - 00040448 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll
    2014-12-04 00:45 - 2014-09-10 06:25 - 00474432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
    2014-12-04 00:45 - 2014-09-08 03:07 - 02497344 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
    2014-12-04 00:45 - 2014-09-08 03:07 - 00428864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
    2014-12-04 00:45 - 2014-09-07 22:08 - 00389176 _____ () C:\windows\system32\ApnDatabase.xml
    2014-12-04 00:45 - 2014-09-04 22:30 - 00822272 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
    2014-12-04 00:45 - 2014-09-04 22:21 - 01053184 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
    2014-12-04 00:45 - 2014-09-04 03:05 - 00836176 _____ (Microsoft Corporation) C:\windows\system32\mfmp4srcsnk.dll
    2014-12-04 00:45 - 2014-09-04 02:22 - 00670384 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmp4srcsnk.dll
    2014-12-04 00:45 - 2014-09-04 01:01 - 00448512 _____ (Microsoft Corporation) C:\windows\system32\puiobj.dll
    2014-12-04 00:45 - 2014-09-04 00:32 - 00334336 _____ (Microsoft Corporation) C:\windows\SysWOW64\puiobj.dll
    2014-12-04 00:45 - 2014-09-04 00:10 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll
    2014-12-04 00:45 - 2014-09-03 23:57 - 00921600 _____ (Microsoft Corporation) C:\windows\system32\MrmCoreR.dll
    2014-12-04 00:45 - 2014-09-03 23:49 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\MrmCoreR.dll
    2014-12-04 00:45 - 2014-08-31 00:17 - 00148800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
    2014-12-04 00:45 - 2014-08-31 00:15 - 21197152 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
    2014-12-04 00:45 - 2014-08-30 22:59 - 18723112 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
    2014-12-04 00:45 - 2014-08-30 22:05 - 00615424 _____ (Microsoft Corporation) C:\windows\system32\FXSCOMEX.dll
    2014-12-04 00:45 - 2014-08-30 21:58 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\FXSAPI.dll
    2014-12-04 00:45 - 2014-08-30 21:04 - 00941568 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll
    2014-12-04 00:45 - 2014-08-30 20:53 - 00239104 _____ (Microsoft Corporation) C:\windows\SysWOW64\FXSAPI.dll
    2014-12-04 00:45 - 2014-08-30 20:17 - 00799744 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll
    2014-12-04 00:45 - 2014-08-28 02:55 - 07484224 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
    2014-12-04 00:45 - 2014-08-28 00:21 - 02480128 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
    2014-12-04 00:45 - 2014-08-28 00:06 - 02030592 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
    2014-12-04 00:45 - 2014-08-23 05:14 - 13424128 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
    2014-12-04 00:45 - 2014-08-23 05:04 - 11820544 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
    2014-12-04 00:45 - 2014-08-23 04:50 - 02714112 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll
    2014-12-04 00:45 - 2014-08-02 00:51 - 00545792 _____ (Microsoft Corporation) C:\windows\system32\untfs.dll
    2014-12-04 00:45 - 2014-08-02 00:35 - 00485376 _____ (Microsoft Corporation) C:\windows\SysWOW64\untfs.dll
    2014-12-04 00:45 - 2014-07-24 11:22 - 00308736 _____ (Microsoft Corporation) C:\windows\system32\compstui.dll
    2014-12-04 00:45 - 2014-07-24 09:53 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\prnntfy.dll
    2014-12-04 00:45 - 2014-07-24 09:13 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\prnntfy.dll
    2014-12-04 00:45 - 2014-07-24 08:20 - 00187392 _____ (Microsoft Corporation) C:\windows\system32\puiapi.dll
    2014-12-04 00:45 - 2014-07-24 08:08 - 00162816 _____ (Microsoft Corporation) C:\windows\SysWOW64\puiapi.dll
    2014-12-04 00:45 - 2014-07-24 07:49 - 00263680 _____ (Microsoft Corporation) C:\windows\system32\DafPrintProvider.dll
    2014-12-04 00:45 - 2014-07-24 07:43 - 00200192 _____ (Microsoft Corporation) C:\windows\SysWOW64\DafPrintProvider.dll
    2014-12-04 00:00 - 2014-08-16 04:08 - 01507648 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll
    2014-12-04 00:00 - 2014-08-16 04:01 - 01710184 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
    2014-12-04 00:00 - 2014-08-16 03:58 - 01112512 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
    2014-12-04 00:00 - 2014-08-16 03:16 - 01205976 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll
    2014-12-04 00:00 - 2014-08-16 03:03 - 01467384 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
    2014-12-04 00:00 - 2014-08-16 01:31 - 00838144 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
    2014-12-04 00:00 - 2014-08-16 01:04 - 00359424 _____ (Microsoft Corporation) C:\windows\system32\Wldap32.dll
    2014-12-04 00:00 - 2014-08-16 00:58 - 00287744 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll
    2014-12-04 00:00 - 2014-08-16 00:53 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\httpprxm.dll
    2014-12-04 00:00 - 2014-08-16 00:46 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\ProximityService.dll
    2014-12-04 00:00 - 2014-08-16 00:45 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll
    2014-12-04 00:00 - 2014-08-16 00:43 - 00321024 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wldap32.dll
    2014-12-04 00:00 - 2014-08-16 00:43 - 00075776 _____ (Microsoft Corporation) C:\windows\system32\adhsvc.dll
    2014-12-04 00:00 - 2014-08-16 00:31 - 00914432 _____ (Microsoft Corporation) C:\windows\system32\iphlpsvc.dll
    2014-12-04 00:00 - 2014-08-16 00:31 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\pcsvDevice.dll
    2014-12-04 00:00 - 2014-08-16 00:29 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
    2014-12-04 00:00 - 2014-08-16 00:23 - 01106432 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll
    2014-12-04 00:00 - 2014-08-16 00:22 - 00717824 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll
    2014-12-04 00:00 - 2014-08-16 00:22 - 00286208 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll
    2014-12-04 00:00 - 2014-08-16 00:19 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
    2014-12-04 00:00 - 2014-08-16 00:18 - 04758528 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll
    2014-12-04 00:00 - 2014-08-16 00:17 - 08757760 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll
    2014-12-04 00:00 - 2014-08-16 00:14 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll
    2014-12-04 00:00 - 2014-08-16 00:13 - 06649344 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
    2014-12-04 00:00 - 2014-08-16 00:13 - 05902848 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll
    2014-12-04 00:00 - 2014-08-16 00:13 - 00840192 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll
    2014-12-04 00:00 - 2014-08-16 00:11 - 00920064 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
    2014-12-04 00:00 - 2014-08-16 00:10 - 01120768 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe
    2014-12-04 00:00 - 2014-08-16 00:08 - 05777408 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
    2014-12-04 00:00 - 2014-08-16 00:07 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
    2014-12-04 00:00 - 2014-07-24 15:28 - 00468288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
    2014-12-04 00:00 - 2014-07-24 11:42 - 01200640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
    2014-12-04 00:00 - 2014-07-24 11:41 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bridge.sys
    2014-12-04 00:00 - 2014-07-24 10:09 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
    2014-12-04 00:00 - 2014-07-24 09:27 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
    2014-12-03 23:24 - 2014-05-31 10:06 - 00555736 _____ (Microsoft Corporation) C:\windows\system32\twinapi.appcore.dll
    2014-12-03 23:24 - 2014-05-31 02:37 - 01054208 _____ (Microsoft Corporation) C:\windows\system32\twinui.appcore.dll
    2014-12-03 23:24 - 2014-05-31 02:35 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.appcore.dll
    2014-12-03 23:24 - 2014-05-30 03:03 - 00563200 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
    2014-12-03 23:17 - 2014-09-22 04:38 - 01519488 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
    2014-12-03 23:17 - 2014-09-22 03:06 - 00258368 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdFilter.sys
    2014-12-03 23:17 - 2014-09-22 03:06 - 00114496 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdNisDrv.sys
    2014-12-03 23:17 - 2014-09-22 02:49 - 00035320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdBoot.sys
    2014-12-03 23:17 - 2014-09-19 00:16 - 01346048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
    2014-12-03 23:17 - 2014-09-02 22:08 - 00014336 _____ (Microsoft Corporation) C:\windows\system32\winshfhc.dll
    2014-12-03 23:17 - 2014-09-02 22:08 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\winshfhc.dll
    2014-12-03 23:15 - 2014-10-13 02:33 - 00116032 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
    2014-12-03 23:15 - 2014-10-11 00:58 - 03320320 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
    2014-12-03 23:15 - 2014-10-11 00:53 - 03607040 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
    2014-12-03 23:15 - 2014-10-08 07:30 - 00110080 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
    2014-12-03 23:15 - 2014-10-08 07:09 - 00428032 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
    2014-12-03 23:15 - 2014-10-08 06:27 - 00325120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
    2014-12-03 23:15 - 2014-10-08 05:32 - 02773504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
    2014-12-03 23:15 - 2014-10-08 05:19 - 02459136 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
    2014-12-03 23:13 - 2014-09-27 07:13 - 00104336 _____ (Microsoft Corporation) C:\windows\system32\ncryptsslp.dll
    2014-12-03 23:13 - 2014-09-27 05:24 - 00088800 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncryptsslp.dll
    2014-12-03 23:13 - 2014-09-27 03:38 - 00426496 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
    2014-12-03 23:13 - 2014-09-27 03:30 - 00185856 _____ (Microsoft Corporation) C:\windows\system32\dpapisrv.dll
    2014-12-03 23:13 - 2014-09-27 03:17 - 00357376 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
    2014-12-03 23:11 - 2014-08-07 02:12 - 01336624 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
    2014-12-03 23:11 - 2014-08-02 03:56 - 01064448 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
    2014-12-03 23:11 - 2014-06-20 01:48 - 01273184 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
    2014-12-03 23:11 - 2014-06-19 23:52 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
    2014-12-03 23:11 - 2014-06-13 01:15 - 00517528 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
    2014-12-03 23:11 - 2014-06-13 01:14 - 01557848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
    2014-12-03 23:11 - 2014-06-13 00:10 - 00406400 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
    2014-12-03 23:11 - 2014-06-06 11:34 - 02133504 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
    2014-12-03 23:06 - 2014-10-10 01:58 - 00177472 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
    2014-12-03 23:06 - 2014-10-10 01:58 - 00027456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
    2014-12-03 23:06 - 2014-10-10 01:44 - 00563976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
    2014-12-03 23:06 - 2014-10-08 07:37 - 00736768 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
    2014-12-03 23:06 - 2014-10-08 07:37 - 00154112 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
    2014-12-03 23:06 - 2014-10-08 07:34 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
    2014-12-03 23:06 - 2014-10-08 07:24 - 00040448 _____ (Microsoft Corporation) C:\windows\system32\rfxvmt.dll
    2014-12-03 23:06 - 2014-10-08 06:56 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
    2014-12-03 23:06 - 2014-10-08 06:51 - 00736768 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
    2014-12-03 23:06 - 2014-10-08 06:51 - 00154112 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
    2014-12-03 23:06 - 2014-10-08 06:18 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
    2014-12-03 23:06 - 2014-10-08 06:17 - 01441792 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
    2014-12-03 23:06 - 2014-10-08 05:23 - 03547648 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
    2014-12-03 23:06 - 2014-07-15 18:16 - 03048880 _____ (Microsoft Corporation) C:\windows\system32\WpcMon.exe
    2014-12-03 23:06 - 2014-07-15 08:29 - 03118080 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll
    2014-12-03 23:06 - 2014-07-15 08:22 - 02861056 _____ (Microsoft Corporation) C:\windows\system32\WpcWebSync.dll
    2014-12-03 23:06 - 2014-07-15 08:03 - 02344448 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wpc.dll
    2014-12-03 23:04 - 2014-08-02 00:18 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
    2014-12-03 23:03 - 2014-10-18 09:55 - 00055776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
    2014-12-03 23:03 - 2014-10-18 08:09 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
    2014-12-03 23:03 - 2014-10-18 08:09 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
    2014-12-03 23:03 - 2014-10-18 07:25 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
    2014-12-03 23:03 - 2014-10-18 06:50 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\wuaext.dll
    2014-12-03 23:03 - 2014-10-18 06:38 - 03557376 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
    2014-12-03 23:03 - 2014-10-18 06:27 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
    2014-12-03 23:03 - 2014-10-18 06:26 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
    2014-12-03 23:03 - 2014-10-18 06:23 - 00407552 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
    2014-12-03 23:03 - 2014-10-18 06:23 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
    2014-12-03 23:03 - 2014-10-18 06:21 - 00894976 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
    2014-12-03 23:03 - 2014-10-18 06:20 - 01714176 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
    2014-12-03 23:03 - 2014-10-18 06:14 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
    2014-12-03 23:03 - 2014-10-18 06:14 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
    2014-12-03 23:03 - 2014-10-18 06:12 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
    2014-12-03 23:03 - 2014-10-18 06:11 - 00723968 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
    2014-12-03 23:03 - 2014-09-04 00:12 - 00590336 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
    2014-12-03 23:03 - 2014-09-04 00:01 - 00514048 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
    2014-12-03 23:01 - 2014-10-17 07:01 - 00789184 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
    2014-12-03 23:01 - 2014-10-17 06:58 - 00602768 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
    2014-12-03 23:01 - 2014-08-23 07:48 - 02374784 _____ (Microsoft Corporation) C:\windows\explorer.exe
    2014-12-03 23:01 - 2014-08-23 07:13 - 02084520 _____ (Microsoft Corporation) C:\windows\SysWOW64\explorer.exe
    2014-12-03 23:01 - 2014-08-23 06:10 - 00068096 _____ (Microsoft Corporation) C:\windows\system32\UXInit.dll
    2014-12-03 23:01 - 2014-08-23 05:32 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
    2014-12-03 23:01 - 2014-08-23 04:33 - 00796672 _____ (Microsoft Corporation) C:\windows\system32\uDWM.dll
    2014-12-03 22:49 - 2014-06-09 22:13 - 00035480 _____ (Microsoft Corporation) C:\windows\SysWOW64\TsWpfWrp.exe
    2014-12-03 22:49 - 2014-06-09 22:13 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe
    2014-12-03 22:44 - 2014-11-04 23:38 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
    2014-12-03 22:44 - 2014-11-04 00:10 - 00304128 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
    2014-12-03 22:44 - 2014-10-31 04:53 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
    2014-12-03 22:44 - 2014-10-31 04:49 - 00537088 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
    2014-12-03 22:44 - 2014-10-31 04:24 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
    2014-12-03 22:42 - 2014-10-23 05:48 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
    2014-12-03 22:42 - 2014-10-23 05:05 - 00072192 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
    2014-12-03 22:42 - 2014-08-23 05:18 - 02149376 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
    2014-12-03 22:42 - 2014-08-23 05:03 - 01346048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
    2014-12-03 22:42 - 2014-05-19 06:31 - 00057856 _____ (Microsoft Corporation) C:\windows\system32\drvcfg.exe
    2014-12-03 22:42 - 2014-05-19 06:21 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\drvinst.exe
    2014-12-03 22:42 - 2014-05-19 05:23 - 00098816 _____ (Microsoft Corporation) C:\windows\SysWOW64\drvinst.exe
    2014-12-03 22:41 - 2014-10-07 06:28 - 00500016 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
    2014-12-03 22:41 - 2014-10-07 06:27 - 00482872 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
    2014-12-03 22:41 - 2014-10-07 06:27 - 00394120 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
    2014-12-03 22:41 - 2014-10-07 06:27 - 00272248 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
    2014-12-03 22:41 - 2014-10-07 06:27 - 00108432 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
    2014-12-03 22:41 - 2014-10-07 03:34 - 00370424 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
    2014-12-03 22:41 - 2014-10-07 03:34 - 00344536 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
    2014-12-03 22:41 - 2014-10-07 03:33 - 00424544 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
    2014-12-03 22:41 - 2014-10-07 03:30 - 04182016 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
    2014-12-03 22:41 - 2014-10-07 01:54 - 00226304 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
    2014-12-03 22:41 - 2014-10-07 01:46 - 00911360 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
    2014-12-03 22:39 - 2014-06-02 02:10 - 00423768 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
    2014-12-03 22:39 - 2014-05-31 10:07 - 00440664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
    2014-12-03 22:39 - 2014-05-31 10:07 - 00089944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
    2014-12-03 22:39 - 2014-05-31 10:07 - 00027480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
    2014-12-03 22:39 - 2014-05-31 06:30 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
    2014-12-03 22:39 - 2014-05-31 06:27 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys
    2014-12-03 22:39 - 2014-05-31 06:26 - 00227840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys
    2014-12-03 22:39 - 2014-05-31 04:01 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe
    2014-12-03 22:39 - 2014-05-31 04:01 - 00209408 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll
    2014-12-03 22:39 - 2014-05-31 04:01 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll
    2014-12-03 22:39 - 2014-05-27 09:56 - 00323584 _____ (Microsoft Corporation) C:\windows\system32\DaOtpCredentialProvider.dll
    2014-12-03 22:39 - 2014-05-27 09:53 - 00270848 _____ (Microsoft Corporation) C:\windows\SysWOW64\DaOtpCredentialProvider.dll
    2014-12-03 22:36 - 2014-07-12 04:17 - 00623616 _____ (Microsoft Corporation) C:\windows\system32\MDMAgent.exe
    2014-12-03 22:36 - 2014-06-06 13:04 - 00586240 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
    2014-12-03 22:36 - 2014-06-06 12:18 - 00488960 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
    2014-12-03 22:31 - 2014-11-09 23:19 - 00991232 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
    2014-12-03 22:31 - 2014-11-09 23:19 - 00806400 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
    2014-12-03 22:31 - 2014-11-09 23:18 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
    2014-12-03 22:31 - 2014-11-09 23:18 - 00208896 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
    2014-12-03 20:59 - 2014-07-24 03:20 - 00875688 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr120_clr0400.dll
    2014-12-03 20:59 - 2014-07-24 03:20 - 00869544 _____ (Microsoft Corporation) C:\windows\system32\msvcr120_clr0400.dll
    2014-12-03 18:38 - 2014-12-03 18:38 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
    2014-12-03 18:20 - 2014-12-03 18:25 - 00000000 ____D () C:\Users\Yvette\Downloads\Gwen Stefani - Greatest Hits (2007) 320 vtwin88cube
    2014-12-03 17:38 - 2014-12-03 18:23 - 00000000 ____D () C:\Removable Disk
    2014-12-03 17:31 - 2014-12-03 17:31 - 00000871 _____ () C:\Users\Yvette\Desktop\µTorrent.lnk
    2014-12-03 17:31 - 2014-12-03 17:31 - 00000851 _____ () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
    2014-12-03 17:31 - 2014-12-03 17:31 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Search Protection
    2014-12-03 17:30 - 2014-12-06 19:46 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\uTorrent
    2014-12-03 13:36 - 2014-12-06 19:12 - 00004956 _____ () C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for EVE-Yvette eve
    2014-12-03 13:36 - 2014-12-03 13:36 - 00003088 _____ () C:\windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-3721279961-3922334345-2485629260-1001
    2014-12-03 13:35 - 2014-12-03 13:35 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
    2014-12-03 13:33 - 2014-12-03 13:33 - 00074512 _____ (BitDefender SRL) C:\windows\system32\bdsandboxuiskin32.dll
    2014-12-03 13:30 - 2014-12-03 13:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
    2014-12-03 13:30 - 2014-12-03 13:30 - 00000000 ____D () C:\Program Files\Microsoft Office 15
    2014-12-03 13:12 - 2014-12-06 00:50 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\DivX
    2014-12-03 13:12 - 2014-12-03 13:12 - 00001609 _____ () C:\Users\Yvette\Desktop\DivX Movies.lnk
    2014-12-03 13:12 - 2014-12-03 13:12 - 00001158 _____ () C:\Users\Public\Desktop\DivX Converter.lnk
    2014-12-03 13:12 - 2014-12-03 13:12 - 00001093 _____ () C:\Users\Public\Desktop\DivX Player.lnk
    2014-12-03 13:12 - 2014-12-03 13:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
    2014-12-03 13:12 - 2014-12-03 13:12 - 00000000 ____D () C:\Program Files\DivX
    2014-12-03 13:11 - 2014-12-05 19:00 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Skype
    2014-12-03 13:11 - 2014-12-03 13:11 - 00002531 _____ () C:\Users\Public\Desktop\Skype.lnk
    2014-12-03 13:11 - 2014-12-03 13:11 - 00000000 ____D () C:\Users\Yvette\AppData\Local\Skype
    2014-12-03 13:11 - 2014-12-03 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2014-12-03 13:10 - 2014-12-04 17:27 - 00000000 ___RD () C:\Program Files (x86)\Skype
    2014-12-03 13:10 - 2014-12-03 13:11 - 00000000 ____D () C:\ProgramData\Skype
    2014-12-03 13:08 - 2014-12-03 13:12 - 00000000 ____D () C:\Program Files (x86)\DivX
    2014-12-03 13:07 - 2014-12-06 00:51 - 00000000 ____D () C:\ProgramData\DivX
    2014-12-03 13:04 - 2014-12-03 13:04 - 01089561 _____ () C:\ProgramData\1417610847.bdinstall.bin
    2014-12-03 13:04 - 2014-12-03 13:04 - 00000385 _____ () C:\Users\Yvette\AppData\Roaminguser_gensett.xml
    2014-12-03 13:03 - 2014-12-03 13:03 - 00002228 _____ () C:\Users\Public\Desktop\Bitdefender Total Security.lnk
    2014-12-03 13:03 - 2014-12-03 13:03 - 00000385 _____ () C:\windows\system32\user_gensett.xml
    2014-12-03 13:03 - 2014-12-03 13:03 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
    2014-12-03 13:03 - 2014-12-03 13:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender 2015
    2014-12-03 13:03 - 2014-12-03 13:03 - 00000000 ____D () C:\ProgramData\BDLogging
    2014-12-03 13:03 - 2013-09-08 20:04 - 00023568 _____ (Bitdefender) C:\windows\system32\Drivers\bdelam.sys
    2014-12-03 13:02 - 2013-11-19 14:44 - 00098768 _____ (BitDefender LLC) C:\windows\system32\Drivers\bdfndisf6.sys
    2014-12-03 13:02 - 2013-11-04 15:47 - 00082824 _____ (BitDefender SRL) C:\windows\system32\Drivers\bdsandbox.sys
    2014-12-03 13:02 - 2013-11-04 15:47 - 00074512 _____ (BitDefender SRL) C:\windows\SysWOW64\bdsandboxuiskin32.dll
    2014-12-03 13:02 - 2013-07-30 18:41 - 00079192 _____ (BitDefender) C:\windows\system32\Drivers\bdvedisk.sys
    2014-12-03 13:02 - 2007-04-11 11:11 - 00511328 _____ (Microsoft Corporation) C:\windows\capicom.dll
    2014-12-03 13:01 - 2014-10-03 20:11 - 00263032 _____ (BitDefender) C:\windows\system32\Drivers\avchv.sys
    2014-12-03 13:01 - 2014-09-25 15:57 - 01288472 _____ (BitDefender) C:\windows\system32\Drivers\avc3.sys
    2014-12-03 13:01 - 2014-05-16 13:04 - 00647752 _____ (BitDefender) C:\windows\system32\Drivers\avckf.sys
    2014-12-03 12:53 - 2014-12-03 13:09 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Bitdefender
    2014-12-03 12:49 - 2014-12-03 13:03 - 00000000 ____D () C:\ProgramData\Bitdefender
    2014-12-03 12:49 - 2014-12-03 12:52 - 00000000 ____D () C:\Program Files\Bitdefender
    2014-12-03 12:49 - 2014-10-15 16:14 - 00452040 _____ (BitDefender S.R.L.) C:\windows\system32\Drivers\trufos.sys
    2014-12-03 12:49 - 2013-11-04 15:47 - 00084848 _____ (BitDefender SRL) C:\windows\system32\BDSandBoxUISkin.dll
    2014-12-03 12:49 - 2013-11-04 15:46 - 00034384 _____ (BitDefender SRL) C:\windows\system32\BDSandBoxUH.dll
    2014-12-03 12:49 - 2013-08-23 12:48 - 00150256 _____ (BitDefender LLC) C:\windows\system32\Drivers\gzflt.sys
    2014-12-03 12:47 - 2014-12-03 12:47 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\QuickScan
    2014-12-03 12:42 - 2014-12-03 12:42 - 07029224 _____ () C:\Users\Yvette\Downloads\bitdefender_tsecurity.exe
    2014-12-03 12:41 - 2014-12-03 12:49 - 00000000 ____D () C:\Program Files\Common Files\Bitdefender
    2014-12-03 12:40 - 2014-12-03 12:40 - 00000000 __SHD () C:\Users\Yvette\AppData\Local\EmieUserList
    2014-12-03 12:40 - 2014-12-03 12:40 - 00000000 __SHD () C:\Users\Yvette\AppData\Local\EmieSiteList
    2014-12-03 12:39 - 2014-12-06 19:38 - 00003598 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3721279961-3922334345-2485629260-1001
    2014-12-03 12:39 - 2014-12-06 19:02 - 00003910 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{7A964A82-345E-43A2-83EF-5C263925312C}
    2014-12-03 12:36 - 2014-12-03 12:36 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
    2014-12-03 12:35 - 2014-12-06 12:37 - 00000000 ____D () C:\Users\Yvette\OneDrive
    2014-12-03 12:31 - 2014-12-03 12:31 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Intel Corporation
    2014-12-03 12:31 - 2014-12-03 12:31 - 00000000 ____D () C:\Users\Yvette\AppData\Local\LenovoBrowserGuard
    2014-12-03 12:31 - 2014-12-03 12:31 - 00000000 ____D () C:\Users\Yvette\AppData\Local\Lenovo
    2014-12-03 12:30 - 2014-12-03 17:34 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Hightail for Lenovo
    2014-12-03 12:30 - 2014-12-03 12:30 - 00000000 ____D () C:\windows\System32\Tasks\WPD
    2014-12-03 12:30 - 2014-12-03 12:30 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Macromedia
    2014-12-03 12:30 - 2014-12-03 12:30 - 00000000 ____D () C:\Users\Yvette\AppData\Local\PackageStaging
    2014-12-03 12:29 - 2014-12-05 01:05 - 00000000 ____D () C:\Users\Yvette\AppData\Local\Packages
    2014-12-03 12:29 - 2014-12-03 13:30 - 00000000 ____D () C:\Users\Yvette\AppData\Local\VirtualStore
    2014-12-03 12:29 - 2014-12-03 12:29 - 00001457 _____ () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2014-12-03 12:29 - 2014-12-03 12:29 - 00000180 _____ () C:\windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
    2014-12-03 12:29 - 2014-12-03 12:29 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Intel
    2014-12-03 12:29 - 2014-12-03 12:29 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Adobe
    2014-12-03 12:27 - 2014-12-03 12:35 - 00000000 ____D () C:\Users\Yvette
    2014-12-03 12:27 - 2014-12-03 12:27 - 00000020 ___SH () C:\Users\Yvette\ntuser.ini
    2014-12-03 12:27 - 2014-09-15 05:57 - 00000000 ____D () C:\Users\Yvette\AppData\Local\Pokki
    2014-12-03 12:27 - 2014-09-15 05:14 - 00000000 ___RD () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2014-12-03 12:27 - 2014-03-18 10:05 - 00000000 ___RD () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    2014-12-03 12:27 - 2014-03-18 09:55 - 00000369 _____ () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
    2014-12-03 12:27 - 2014-03-18 09:55 - 00000369 _____ () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
    2014-12-03 12:27 - 2013-08-22 15:36 - 00000000 ___RD () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2014-12-03 12:27 - 2013-08-22 15:36 - 00000000 ____D () C:\Users\Yvette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2014-11-06 05:42 - 2014-11-06 05:42 - 00341848 _____ (DivX, LLC) C:\windows\SysWOW64\DivXControlPanelApplet.cpl

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-12-06 19:31 - 2014-09-15 05:04 - 01887039 _____ () C:\windows\WindowsUpdate.log
    2014-12-06 19:06 - 2014-03-18 09:53 - 00865408 _____ () C:\windows\system32\PerfStringBackup.INI
    2014-12-06 19:01 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\system32\sru
    2014-12-06 17:18 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\rescache
    2014-12-05 23:35 - 2013-08-22 15:20 - 00000000 ____D () C:\windows\CbsTemp
    2014-12-05 23:32 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\Resources
    2014-12-05 21:20 - 2013-08-22 13:25 - 00262144 ___SH () C:\windows\system32\config\ELAM
    2014-12-05 20:16 - 2013-08-22 14:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
    2014-12-05 20:15 - 2013-08-22 14:44 - 00492000 _____ () C:\windows\system32\FNTCACHE.DAT
    2014-12-05 20:14 - 2014-09-15 06:08 - 00002560 _____ () C:\windows\system32\VfService.trf
    2014-12-05 20:14 - 2013-08-22 13:25 - 00262144 ___SH () C:\windows\system32\config\BBI
    2014-12-05 19:56 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\AppReadiness
    2014-12-05 18:49 - 2014-09-15 06:09 - 00010568 _____ () C:\windows\SysWOW64\VisualDiscovery.ini
    2014-12-05 18:49 - 2014-09-15 06:09 - 00005216 _____ () C:\windows\SysWOW64\VisualDiscoveryOff.ini
    2014-12-05 18:49 - 2014-09-15 06:09 - 00005216 _____ () C:\windows\system32\VisualDiscoveryOff.ini
    2014-12-05 18:48 - 2014-03-18 09:44 - 00010204 _____ () C:\windows\PFRO.log
    2014-12-05 18:01 - 2014-03-18 09:38 - 00000000 ____D () C:\Program Files\Windows Journal
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ___RD () C:\windows\ToastData
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ___RD () C:\windows\ImmersiveControlPanel
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\SysWOW64\setup
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\SysWOW64\InputMethod
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\system32\setup
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ____D () C:\Program Files\Windows Defender
    2014-12-05 18:01 - 2013-08-22 15:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
    2014-12-05 18:01 - 2013-08-22 13:36 - 00000000 ____D () C:\windows\system32\oobe
    2014-12-05 17:57 - 2013-08-22 15:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
    2014-12-04 20:15 - 2014-04-03 18:16 - 00000000 __SHD () C:\Recovery
    2014-12-04 20:15 - 2013-08-22 15:36 - 00262144 _____ () C:\windows\system32\config\BCD-Template
    2014-12-04 18:09 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\WinStore
    2014-12-04 18:09 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\PolicyDefinitions
    2014-12-04 18:09 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\MediaViewer
    2014-12-04 18:09 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\FileManager
    2014-12-04 18:09 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\Camera
    2014-12-03 18:38 - 2013-08-22 14:46 - 00023127 _____ () C:\windows\setupact.log
    2014-12-03 12:45 - 2014-09-15 06:03 - 00000000 ____D () C:\ProgramData\McAfee
    2014-12-03 12:36 - 2014-09-15 06:01 - 00000000 ____D () C:\windows\System32\Tasks\Lenovo
    2014-12-03 12:34 - 2014-09-15 05:58 - 00000000 ____D () C:\ProgramData\Lenovo
    2014-12-03 12:32 - 2014-09-15 06:01 - 00000000 ____D () C:\Program Files (x86)\LenovoBrowserGuard
    2014-12-03 12:29 - 2014-09-15 07:24 - 00123954 _____ () C:\windows\modules.log
    2014-12-03 12:29 - 2014-04-03 19:15 - 00000000 ____D () C:\windows\Panther
    2014-11-20 20:51 - 2013-08-22 15:38 - 00714208 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
    2014-11-20 20:51 - 2013-08-22 15:38 - 00106976 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-11-19 16:28 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\ELAMBKUP

    Some content of TEMP:
    ====================
    C:\Users\Yvette\AppData\Local\Temp\divx115a.exe
    C:\Users\Yvette\AppData\Local\Temp\divxb0a8.exe
    C:\Users\Yvette\AppData\Local\Temp\vcredist.exe


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2014-09-15 04:59

    ==================== End Of Log ============================

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-12-2014 02
    Ran by Yvette at 2014-12-06 19:47:58
    Running from C:\Users\Yvette\Downloads
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Bitdefender Antivirus (Enabled - Up to date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Bitdefender Antispyware (Enabled - Up to date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
    FW: Bitdefender Firewall (Enabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
    Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
    µTorrent (HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\uTorrent) (Version: 3.4.2.36615 - BitTorrent Inc.)
    Bitdefender Total Security 2015 (HKLM\...\Bitdefender) (Version: 18.19.0.1369 - Bitdefender)
    CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
    CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
    CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
    Dependency Package Update (Version: 1.6.25.00 - Lenovo Inc.) Hidden
    Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
    Dependency Package Update (Version: 1.6.32.00 - Lenovo Inc.) Hidden
    DesktopDock (HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\DesktopDock) (Version: 1.0.1.32 - DesktopDock)
    DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC)
    Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
    Dragon Assistant Application en-GB version 1.5.8 (HKLM-x32\...\{1CCBE73F-4948-4711-8D12-22E2FD65D706}_is1) (Version: 1.5.8 - Nuance Communications, Inc.)
    Dragon Assistant Core Recognition Service version 1.1.10 (HKLM-x32\...\{E97BA7A6-46FC-4EBF-B24A-B8362948C696}_is1) (Version: 1.1.10 - Nuance Communications, Inc.)
    Dragon Assistant Installer version 1.5.8 (HKLM-x32\...\{D57A8269-3BE5-4D10-B882-64D0F2D448BF}_is1) (Version: 1.5.8 - Nuance Communications, Inc.)
    Dragon Assistant Language Data en-GB version 1.1.3 (HKLM-x32\...\{CA54E6DD-70F8-4AE5-8427-522A52FC4408}_is1) (Version: 1.1.3 - Nuance Communications, Inc.)
    Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.35 - Lenovo)
    Energy Manager (x32 Version: 1.0.0.35 - Lenovo) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Hightail for Lenovo (HKLM\...\{2F10E937-F6D7-4174-8AB9-B299E8FC5CEC}) (Version: 2.4.97.2857 - Hightail, Inc.)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.2.1000 - Intel Corporation)
    Intel(R) Wireless Bluetooth(R) 4.0 (HKLM-x32\...\{96C730E4-F055-4118-BDF3-6E071763853C}) (Version: 3.0.1342.02 - Intel Corporation)
    Intel® PROSet/Wireless Software (HKLM-x32\...\{7e493493-a430-4b7b-b8a2-48d61599e220}) (Version: 17.0.0 - Intel Corporation)
    Lenovo Browser Guard (HKLM-x32\...\LenovoBrowserGuard) (Version: 2.16.50.5 - ClientConnect LTD)
    Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.25.00 - Lenovo Group Limited)
    Lenovo EasyCamera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10249 - Realtek Semiconductor Corp.)
    Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.0.17.0 - Lenovo)
    Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
    Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
    Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
    Lenovo Motion Control (HKLM-x32\...\InstallShield_{E9325F15-6339-45E8-9DC4-C2D44B623039}) (Version: 2.5.1.0224 - PointGrab)
    Lenovo Motion Control (x32 Version: 2.5.1.0224 - PointGrab) Hidden
    Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
    Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
    Lenovo SHAREit (HKLM-x32\...\Lenovo SHAREit_is1) (Version: 2.0.5.0 - Lenovo Group Limited)
    Lenovo Smart Voice (HKLM\...\Lenovo SmartVoice) (Version: 1.0.2.4 - Lenovo)
    Lenovo Transition (HKLM\...\Lenovo Transition) (Version: 2.0.13.10181 - Lenovo)
    Lenovo VeriFace Pro (HKLM\...\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo)
    Lenovo Yoga 2 Demo (HKLM-x32\...\{03C682A4-05CD-4D22-B50A-B9C3C5F2B137}) (Version: 1.0.7 - Lenovo)
    Lenovo Yoga PhoneCompanion (HKLM-x32\...\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.1.9.5 - Lenovo)
    Lenovo Yoga PhoneCompanion (x32 Version: 1.1.9.5 - Lenovo) Hidden
    Metric Collection SDK 35 (x32 Version: 1.2.0001.00 - Lenovo Group Limited) Hidden
    Microsoft Office 365 Home Premium - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4569.1506 - Microsoft Corporation)
    Microsoft OneDrive (HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Nitro Pro 9 (HKLM\...\{70B831B7-A8EE-4C5F-8F34-F383D24B3A04}) (Version: 9.0.5.9 - Nitro)
    Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Licensing Component (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
    Pokki (HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\Pokki) (Version: 0.269.2.471 - Pokki)
    Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.39053 - Realtek Semiconductor Corp.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7161 - Realtek Semiconductor Corp.)
    Search Protection (HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\Search Protection) (Version: 10.3.0.1 - Spigot, Inc.) <==== ATTENTION
    Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.)
    SoftwareUpdater (HKLM-x32\...\SoftwareUpdater) (Version: - ) <==== ATTENTION
    Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
    Superfish Inc. VisualDiscovery (HKLM-x32\...\Superfish Inc. VisualDiscovery) (Version: 1.0.0.1 - Superfish)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.14.71 - Synaptics Incorporated)
    Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.10.1 - Tweaking.com)
    User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
    User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
    VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
    Windows Driver Package - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
    Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
    Yoga Picks (HKLM-x32\...\{267C8BA0-876B-4589-9F14-EFB84ABCEA7F}) (Version: 1.5.014.0106 - Lenovo)

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    CustomCLSID: HKU\S-1-5-21-3721279961-3922334345-2485629260-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\windows\system32\igfxEM.exe (Intel Corporation)
    CustomCLSID: HKU\S-1-5-21-3721279961-3922334345-2485629260-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Yvette\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation)

    ==================== Restore Points =========================

    03-12-2014 13:22:33 dec314
    05-12-2014 23:38:35 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-08-22 13:25 - 2013-08-22 13:25 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {0C6D3D41-8333-4D73-9A9B-2D316B5B9CE3} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
    Task: {17202C3C-9FAF-4BDF-950E-8FD681994FA6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
    Task: {26519E7B-B844-450B-8DA0-1AA07CE0B044} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-09-15] (Lenovo)
    Task: {341B0110-4AF1-4A49-BDE5-036CD9C6FAC4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-05] (Google Inc.)
    Task: {367F390F-CDC1-4AB3-BB34-844F6F0B13B2} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe
    Task: {3CF6E37A-86DA-4C60-BF27-30E38EB27481} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-10-31] (Microsoft Corporation)
    Task: {4C7F6199-18FC-4000-83CF-126C46750F18} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-05-30] (Lenovo)
    Task: {5A6AE3EF-8B81-478B-B36E-2ED93995965D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
    Task: {6C457029-6327-4AF3-9D44-6384A9653E36} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-3721279961-3922334345-2485629260-1001 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe
    Task: {6D127D4B-CAF9-4D00-B89C-E8C1E4236B32} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-05] (Google Inc.)
    Task: {79363636-92C4-4DCA-98A1-20F64FA3EAAD} - System32\Tasks\Microsoft Office 15 Sync Maintenance for EVE-Yvette eve => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-12-03] (Microsoft Corporation)
    Task: {8C28D70A-F150-4C21-90A7-153C46E418D2} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-12-19] (Synaptics Incorporated)
    Task: {916EA195-A86A-455F-AF48-AEF8A9C9CE71} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2013-12-17] (Microsoft Corporation)
    Task: {B5C4DEF8-E810-4D37-A113-DB4745FB5EC6} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-12-03] (Microsoft Corporation)
    Task: {BB7EFB87-FA3A-4E2F-BFB6-AC5341FBCD02} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2014-05-22] ()
    Task: {D3A3BD5B-EE83-42CB-8D8E-3A0742D499DF} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2014-12-03] (Lenovo)
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => ?

    ==================== Loaded Modules (whitelisted) =============

    2014-12-03 13:02 - 2014-08-27 16:31 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\txmlutil.dll
    2014-12-03 13:01 - 2013-09-03 14:29 - 00101328 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdmetrics.dll
    2014-12-03 13:03 - 2014-11-19 16:24 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\UI\accessl.ui
    2014-12-03 13:02 - 2012-10-29 14:22 - 00152816 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdfwcore.dll
    2014-12-03 13:01 - 2014-07-24 09:44 - 00780592 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_001_001\ashttpbr.mdl
    2014-12-03 13:01 - 2014-07-24 09:44 - 00568400 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_001_001\ashttpdsp.mdl
    2014-12-03 13:01 - 2014-07-24 09:44 - 02602680 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_001_001\ashttpph.mdl
    2014-12-03 13:01 - 2014-07-24 09:44 - 01323408 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\otengines_001_001\ashttprbl.mdl
    2014-12-03 13:30 - 2013-10-31 17:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
    2014-12-03 13:30 - 2014-01-02 18:41 - 00621736 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll
    2014-09-15 06:06 - 2012-04-24 10:43 - 00390632 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
    2014-09-15 06:08 - 2014-09-15 06:08 - 00067856 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
    2014-09-15 06:08 - 2014-09-15 06:08 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll
    2014-09-15 06:08 - 2014-09-15 06:08 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
    2014-09-15 06:02 - 2014-01-06 22:14 - 00019440 _____ () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
    2014-09-15 06:08 - 2014-09-15 06:08 - 00815104 _____ () C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
    2014-12-05 23:38 - 2014-12-05 12:32 - 00196096 _____ () C:\Program Files (x86)\SoftwareUpdater\Upd4terSrv.exe
    2014-12-03 13:31 - 2014-12-03 13:31 - 08878248 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    2014-11-08 21:30 - 2014-11-08 21:30 - 00124248 _____ () C:\Program Files (x86)\DivX\DivX Player\DPXIconHandler.dll
    2014-09-15 06:08 - 2014-09-15 06:08 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
    2014-09-15 06:08 - 2014-09-15 06:08 - 00108304 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
    2014-10-09 14:14 - 2014-10-09 14:14 - 01448472 _____ () C:\Program Files (x86)\Desktop Dock\DesktopDockApp.exe
    2014-01-10 05:26 - 2014-01-10 05:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    2014-12-03 13:01 - 2014-11-13 14:12 - 00467448 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\bdidntconp.dll
    2014-12-03 13:03 - 2014-11-19 16:24 - 00184320 _____ () C:\Program Files\Bitdefender\Bitdefender 2015\ui\bdidntconp.ui
    2014-09-15 06:07 - 2013-05-02 18:26 - 00387984 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\fl_core.dll
    2014-09-15 06:07 - 2013-05-02 18:26 - 01165712 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_asr.dll
    2014-09-15 06:07 - 2013-05-02 18:26 - 00199056 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_base.dll
    2014-09-15 06:07 - 2013-05-02 18:26 - 01132944 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_pron.dll
    2014-09-15 06:07 - 2013-05-02 18:26 - 00035216 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\vocon3200_platform.dll
    2014-09-15 06:07 - 2013-05-02 18:26 - 00229264 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\sdxg.dll
    2014-09-15 06:07 - 2013-05-02 18:25 - 00027648 _____ () C:\Program Files (x86)\Nuance\Dragon Assistant\Core\WASAPIResamplingStreamCOMServer.dll
    2014-02-24 23:39 - 2014-02-24 23:39 - 00013576 _____ () C:\Program Files (x86)\Lenovo\Motion Control\PointGrabDeviceAPI.dll
    2014-09-15 05:18 - 2013-09-16 19:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
    2014-12-05 23:15 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    2014-12-05 23:15 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
    2014-12-05 23:15 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    2014-12-05 23:15 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
    2014-12-05 23:15 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
    2014-12-03 13:30 - 2014-12-03 13:31 - 00316584 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
    2014-09-15 06:08 - 2014-09-15 06:08 - 00102672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll
    2014-09-15 06:08 - 2014-09-15 06:08 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
    2014-09-15 06:08 - 2014-09-15 06:08 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
    2014-01-10 05:28 - 2014-01-10 05:28 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
    2014-02-24 23:39 - 2014-02-24 23:39 - 02690312 _____ () C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterFilter.ax
    2014-12-05 01:10 - 2014-11-25 06:39 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libglesv2.dll
    2014-12-05 01:10 - 2014-11-25 06:39 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libegl.dll
    2014-12-05 01:10 - 2014-11-25 06:39 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\pdf.dll
    2014-12-05 01:10 - 2014-11-25 06:39 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    AlternateDataStreams: C:\Users\Yvette\OneDrive:ms-properties
    AlternateDataStreams: C:\Users\Yvette\Downloads\FRST64 (1).exe:BDU
    AlternateDataStreams: C:\Users\Yvette\Downloads\FRST64.exe:BDU
    AlternateDataStreams: C:\Users\Yvette\Downloads\installer_ewido_anti-spyware_4_0_English.exe:BDU
    AlternateDataStreams: C:\Users\Yvette\Downloads\spybot-2.4.exe:BDU
    AlternateDataStreams: C:\Users\Yvette\Downloads\tdsskiller.exe:BDU
    AlternateDataStreams: C:\Users\Yvette\Downloads\tweaking.com_registry_backup_setup.exe:BDU

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VDWFP => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VisualDiscovery => ""="service"

    ==================== EXE Association (whitelisted) =============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== MSCONFIG/TASK MANAGER disabled items =========

    (Currently there is no automatic fix for this section.)

    HKLM\...\StartupApproved\Run32: => "Yoga Picks"
    HKU\S-1-5-21-3721279961-3922334345-2485629260-1001\...\StartupApproved\Run: => "Skype"

    ========================= Accounts: ==========================

    Administrator (S-1-5-21-3721279961-3922334345-2485629260-500 - Administrator - Disabled)
    Guest (S-1-5-21-3721279961-3922334345-2485629260-501 - Limited - Disabled)
    Yvette (S-1-5-21-3721279961-3922334345-2485629260-1001 - Administrator - Enabled) => C:\Users\Yvette

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/06/2014 07:20:47 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program DesktopDockBrowser.exe version 1.0.0.21 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 2b34

    Start Time: 01d0117fa87dc6a7

    Termination Time: 4294967295

    Application Path: C:\Users\Yvette\AppData\Local\DesktopDock\DesktopDockBrowser.exe

    Report Id: fa744c3b-7d7c-11e4-8260-e8b1fc125cf4

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (12/06/2014 07:20:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program DesktopDockBrowser.exe version 1.0.0.21 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 2548

    Start Time: 01d0117e07425eb9

    Termination Time: 4294967295

    Application Path: C:\Users\Yvette\AppData\Local\DesktopDock\DesktopDockBrowser.exe

    Report Id: f74e6f14-7d7c-11e4-8260-e8b1fc125cf4

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (12/06/2014 02:15:38 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80070005

    Error: (12/05/2014 11:23:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program SDFiles.exe version 2.4.40.135 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 2bcc

    Start Time: 01d010e2785cb43d

    Termination Time: 15

    Application Path: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFiles.exe

    Report Id: bf3e512f-7cd5-11e4-8260-e8b1fc125cf4

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (12/05/2014 08:02:39 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80070005

    Error: (12/05/2014 05:48:03 PM) (Source: Application Error) (EventID: 1005) (User: )
    Description: Windows cannot access the file for one of the following reasons:
    there is a problem with the network connection, the disk that the file is stored on, or the storage
    drivers installed on this computer; or the disk is missing.
    Windows closed the program Spooler SubSystem App because of this error.

    Program: Spooler SubSystem App
    File:

    The error value is listed in the Additional Data section.
    User Action
    1. Open the file again.
    This situation might be a temporary problem that corrects itself when the program runs again.
    2.
    If the file still cannot be accessed and
    - It is on the network,
    your network administrator should verify that there is not a problem with the network and that the server can be contacted.
    - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
    3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
    4. If the problem persists, restore the file from a backup copy.
    5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
    further assistance.

    Additional Data
    Error value: C000003F
    Disk type: 0

    Error: (12/05/2014 05:48:03 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: spoolsv.exe, version: 6.3.9600.16384, time stamp: 0x5215d570
    Faulting module name: ntdll.dll, version: 6.3.9600.17278, time stamp: 0x53eebd22
    Exception code: 0xc0000006
    Fault offset: 0x0000000000093259
    Faulting process id: 0x69c
    Faulting application start time: 0xspoolsv.exe0
    Faulting application path: spoolsv.exe1
    Faulting module path: spoolsv.exe2
    Report Id: spoolsv.exe3
    Faulting package full name: spoolsv.exe4
    Faulting package-relative application ID: spoolsv.exe5

    Error: (12/05/2014 05:42:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program LiveComm.exe version 17.5.9600.20498 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 24cc

    Start Time: 01d01057a11e97cc

    Termination Time: 4294967295

    Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe

    Report Id: 08114025-7ca6-11e4-825e-e8b1fc125cf4

    Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe

    Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1

    Error: (12/05/2014 05:59:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program LiveComm.exe version 17.5.9600.20498 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 660

    Start Time: 01d0104fdf745380

    Termination Time: 4294967295

    Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe

    Report Id: d31b53b1-7c43-11e4-825e-e8b1fc125cf4

    Faulting package full name: microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe

    Faulting package-relative application ID: ppleae38af2e007f4358a809ac99a64a67c1

    Error: (12/05/2014 05:53:56 AM) (Source: ESENT) (EventID: 455) (User: )
    Description: svchost (1720) SRUJet: Error -1811 (0xfffff8ed) occurred while opening logfile C:\windows\system32\SRU\SRU0002F.log.


    System errors:
    =============
    Error: (12/06/2014 02:40:56 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/06/2014 00:36:02 PM) (Source: ACPI) (EventID: 13) (User: )
    Description: : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.

    Error: (12/06/2014 02:53:33 AM) (Source: DCOM) (EventID: 10010) (User: EVE)
    Description: {03E64E17-B220-4052-9B9B-155F9CB8E016}

    Error: (12/06/2014 02:53:33 AM) (Source: DCOM) (EventID: 10010) (User: EVE)
    Description: {03E64E17-B220-4052-9B9B-155F9CB8E016}

    Error: (12/05/2014 11:46:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The MbQoZxIo service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

    Error: (12/05/2014 11:34:46 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 70. The Windows SChannel error state is 105.

    Error: (12/05/2014 08:14:43 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/05/2014 06:49:48 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT AUTHORITY)
    Description: WLAN Extensibility Module has failed to start.

    Module Path: C:\windows\System32\IWMSSvc.dll
    Error Code: 258

    Error: (12/05/2014 06:48:48 PM) (Source: Microsoft-Windows-Eventlog) (EventID: 23) (User: NT AUTHORITY)
    Description: The event logging service encountered an error (res=1500) while initializing logging resources for channel Microsoft-Windows-Diagnostics-Performance/Operational.

    Error: (12/05/2014 06:02:08 PM) (Source: Ntfs) (EventID: 55) (User: )
    Description: A corruption was discovered in the file system structure on volume C:.

    The exact nature of the corruption is unknown. The file system structures need to be scanned online.


    Microsoft Office Sessions:
    =========================
    Error: (12/06/2014 07:20:47 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: DesktopDockBrowser.exe1.0.0.212b3401d0117fa87dc6a74294967295C:\Users\Yvette\AppData\Local\DesktopDock\DesktopDockBrowser.exefa744c3b-7d7c-11e4-8260-e8b1fc125cf4

    Error: (12/06/2014 07:20:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: DesktopDockBrowser.exe1.0.0.21254801d0117e07425eb94294967295C:\Users\Yvette\AppData\Local\DesktopDock\DesktopDockBrowser.exef74e6f14-7d7c-11e4-8260-e8b1fc125cf4

    Error: (12/06/2014 02:15:38 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80070005

    Error: (12/05/2014 11:23:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: SDFiles.exe2.4.40.1352bcc01d010e2785cb43d15C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFiles.exebf3e512f-7cd5-11e4-8260-e8b1fc125cf4

    Error: (12/05/2014 08:02:39 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
    Description: 80070005

    Error: (12/05/2014 05:48:03 PM) (Source: Application Error) (EventID: 1005) (User: )
    Description: Spooler SubSystem AppC000003F0

    Error: (12/05/2014 05:48:03 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: spoolsv.exe6.3.9600.163845215d570ntdll.dll6.3.9600.1727853eebd22c0000006000000000009325969c01d01025ed2bced4C:\windows\System32\spoolsv.exeC:\windows\SYSTEM32\ntdll.dlldbfdba04-7ca6-11e4-825e-e8b1fc125cf4

    Error: (12/05/2014 05:42:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: LiveComm.exe17.5.9600.2049824cc01d01057a11e97cc4294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe08114025-7ca6-11e4-825e-e8b1fc125cf4microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

    Error: (12/05/2014 05:59:14 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: LiveComm.exe17.5.9600.2049866001d0104fdf7453804294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exed31b53b1-7c43-11e4-825e-e8b1fc125cf4microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

    Error: (12/05/2014 05:53:56 AM) (Source: ESENT) (EventID: 455) (User: )
    Description: svchost1720SRUJet: C:\windows\system32\SRU\SRU0002F.log-1811 (0xfffff8ed)


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i3-4010U CPU @ 1.70GHz
    Percentage of memory in use: 50%
    Total physical RAM: 8112.96 MB
    Available physical RAM: 4031.7 MB
    Total Pagefile: 10032.96 MB
    Available Pagefile: 6443.19 MB
    Total Virtual: 131072 MB
    Available Virtual: 131071.83 MB

    ==================== Drives ================================

    Drive c: (Windows8_OS) (Fixed) (Total:423.44 GB) (Free:330.18 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:24.9 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 465.8 GB) (Disk ID: 836F81DE)

    Partition: GPT Partition Type.

    ==================== End Of Log ============================

    aswMBR version 1.0.1.2252 Copyright(c) 2014 AVAST Software
    Run date: 2014-12-06 19:59:52
    -----------------------------
    19:59:52.502 OS Version: Windows x64 6.2.9200
    19:59:52.502 Number of processors: 4 586 0x4501
    19:59:52.502 ComputerName: EVE UserName:
    19:59:53.495 Initialize success
    19:59:53.526 VM: initialized successfully
    19:59:53.526 VM: Intel CPU BiosDisabled
    20:05:35.736 AVAST engine defs: 14120601
    20:07:30.322 The log file has been saved successfully to "C:\Users\Yvette\Desktop\aswMBR.txt"

    Search results from Spybot - Search & Destroy

    09/12/2014 21:09:05
    Scan took 00:40:15.
    22 items found.

    DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)


    DoubleClick: [SBI $4E2AF2AC] Tracking cookie (Google Chrome: Default) (Browser: Cookie, nothing done)


    Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

    Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
    HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

    Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
    HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

    Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

    Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

    MS Management Console: [SBI $ECD50EAD] Recent command list (Registry Key, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Microsoft Management Console\Recent File List

    MS Media Player: [SBI $5C51E349] Client ID (Registry Change, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\MediaPlayer\Player\Settings\Client ID

    MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name

    Windows.OpenWith: [SBI $F1129B32] Open with list - .CPL extension (Registry Key, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CPL\OpenWithList

    Windows Explorer: [SBI $7308A845] Run history (Registry Key, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU

    Windows Explorer: [SBI $AA0766B5] Stream history (Registry Key, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU

    Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry Key, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

    Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry Change, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Windows Media\WMSDK\General\ComputerName

    Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry Change, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Windows Media\WMSDK\General\UniqueID

    Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry Value, nothing done)
    HKEY_USERS\S-1-5-21-3721279961-3922334345-2485629260-1001\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

    Cookie: [SBI $49804B54] Browser: Cookie (7) (Browser: Cookie, nothing done)


    Cache: [SBI $49804B54] Browser: Cache (167) (Browser: Cache, nothing done)


    History: [SBI $49804B54] Browser: History (24) (Browser: History, nothing done)


    Cookie: [SBI $49804B54] Browser: Cookie (88) (Browser: Cookie, nothing done)


    History: [SBI $49804B54] Browser: History (130) (Browser: History, nothing done)



    --- Spybot - Search & Destroy version: 2.4.40.131 DLL (build: 20140425) ---

    Thank you

  2. #2
    Visiting Fellow
    Join Date
    Mar 2011
    Location
    Canada
    Posts
    142

    Default

    Hello, yvette77.

    My name is fbfbfb. I will gladly assist you with your concerns.

    While working to resolve the issues with your machine, please follow these guidelines:
    • Please be patient. Logs are lengthy and can take time to analyze.
    • Read and follow my directions carefully, in the sequence they are posted.
    • If you are unsure about anything, please ask for clarification before continuing.
    • Use only those tools that you have been directed to use.
    • Do not install or uninstall any applications or run any other scans without being directed to do so.
    • Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
    • Stay with me until your machine has been deemed all clear.
    • Please reply within 3 days of each posting to avoid closing this topic. If you need more time to complete tasks, or if you will be away, please let me know in advance.


    Please run the following scans

    1. aswMBR

    Please download aswMBR from [/color][/b] from HERE.
    • Double click aswMBR.exe to run it.
    • When asked if you want to download Avast's virus definitions, please select Yes.
    • Click the Scan button to start the scan.


    • On completion of the scan, click save log, save it to your desktop, and post in your next reply.




    2. AdwCleaner

    We will be running this cleaner in 2 parts. The first time you run it, please scan only and send me the log. We will rerun it again later to clean.

    Please download AdwCleaner from HERE.
    • Double click on adwcleaner.exe. Note: Vista/Windows 7/8 users right-click and select Run As Administrator.
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Copy and paste the contents of that logfile in your next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    3. Junkware Removal Tool (JRT)

    Please download Junkware Removal Tool from HERE and save it to your desktop.
    • Shutdown your antivirus to avoid any potential conflicts.
    • Right-mouse click JRT.exe and select Run as Administrator.
    • JRTwill begin to backup your registry and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, the log JRT.txt is saved on your desktop and will automatically open.
    Post the contents of JRT.txt into your next reply.


    4. Malwarebytes Anti-Malware (MBAM)

    Download MBAM from HERE > Save it to your Desktop.

    Note:
    • Windows XP > Double click on the icon to run it.
    • Windows Vista, Windows 7 and 8 > Right-click and select Run As Administrator.




    • On the Dashboard, click Update Now.
    • Click the Settings tab > Click Detection and Protection.
    • Under Non-Malware Protection, make sure that both PUP and PUM are set to show Treat Detections as Malware .
    • Click Advanced Settings > Check mark Automatically Quarantine Detected Items.
    • On the Dashboard, click Scan.
    • Select Threat Scan > Click Scan Now.
    • When the scan is finished and the log pops up, select Copy to Clipboard .
    • Please paste the log into your next reply.
    • Exit Malwarebytes.


    CHECKLIST : In your next reply, please post the following:

    • aswMBR log
    • AdwCleaner[R0].txt
    • JRT.txt
    • MBAM log

  3. #3
    Visiting Fellow
    Join Date
    Mar 2011
    Location
    Canada
    Posts
    142

    Default

    Hello, yvette77.

    Please ignore my instructions to run aswMBR as I see that you have already submitted this log.

    Thank you.

  4. #4
    Visiting Fellow
    Join Date
    Mar 2011
    Location
    Canada
    Posts
    142

    Default

    Hello, yvette 77.

    I have not heard back from you. Do you still need help?

    Please reply within the next 24 hours to avoid closing this thread.

    Thank you.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •