View Full Version : Infected with something!

2014-08-04, 12:54
System is sluggish and often unresponsive. Hope I'm doing this right since internet isn't really helping/working all that much. Wrong display of folders etc...crap
Spybot S&D says it can't remove the found items...

aswMBR version Copyright(c) 2014 AVAST Software
Run date: 2014-08-04 10:41:58
10:41:58.246 OS Version: Windows x64 6.1.7600
10:41:58.246 Number of processors: 4 586 0x2502
10:41:58.247 ComputerName: AKV-I5 UserName: Akron
10:41:59.500 Initialize success
10:42:16.958 VM: initialized successfully
10:42:17.046 VM: Intel CPU supported
10:42:24.699 VM: supported disk I/O ataport.SYS
10:42:30.492 AVAST engine defs: 14080301
10:44:31.183 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
10:44:31.187 Disk 0 Vendor: Hitachi_HTS545025B9A300 PB2OC64G Size: 238475MB BusType: 11
10:44:31.393 VM: Disk 0 MBR read successfully
10:44:31.397 Disk 0 MBR scan
10:44:31.403 Disk 0 Windows 7 default MBR code
10:44:31.407 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 178472 MB offset 63
10:44:31.411 Disk 0 Boot: NTFS code=2
10:44:31.442 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 60000 MB offset 365512704
10:44:31.621 Disk 0 scanning C:\Windows\system32\drivers
10:44:39.238 Service scanning
10:45:29.259 Modules scanning
10:45:29.260 Disk 0 trace - called modules:
10:45:29.272 ntoskrnl.exe CLASSPNP.SYS disk.sys thpdrv.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
10:45:29.272 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800267e060]
10:45:29.272 3 CLASSPNP.SYS[fffff880019cf43f] -> nt!IofCallDriver -> \Device\THPDRV[0xfffffa800267d060]
10:45:29.272 5 thpdrv.sys[fffff88001918a4d] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800244a680]
10:45:32.725 AVAST engine scan C:\Windows
10:45:38.408 AVAST engine scan C:\Windows\system32
10:48:43.076 AVAST engine scan C:\Windows\system32\drivers
10:48:58.550 AVAST engine scan C:\Users\Akron
10:54:48.337 AVAST engine scan C:\ProgramData
10:55:17.417 Scan finished successfully
11:43:38.658 Disk 0 MBR has been saved successfully to "C:\Users\Akron\Desktop\MBR.dat"
11:43:38.832 The log file has been saved successfully to "C:\Users\Akron\Desktop\aswMBR.txt"


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-08-2014
Ran by Akron (administrator) on AKV-I5 on 04-08-2014 10:41:04
Running from C:\Users\Akron\Desktop
Platform: Windows 7 Ultimate (X64) OS Language: Nederlands (Nederland)
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(COMODO) C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Anvisoft) C:\Program Files (x86)\Anvisoft\StartupBooster\StartupTimeSrv.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(COMODO) C:\Program Files\COMODO\COMODO GeekBuddy\CLPS.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
(VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
(Moonchild Productions) C:\Program Files (x86)\Pale Moon\palemoon.exe
(Microsoft Corporation) C:\Windows\System32\Magnify.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ThpSrv] => C:\Windows\system32\thpsrv /logon
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [9454920 2011-12-21] (COMODO)
HKLM-x32\...\Run: [COMODO] => C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe [213304 2011-11-23] (COMODO)
HKLM-x32\...\Run: [CPA] => C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe [184120 2011-11-23] (COMODO)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-02] (AVAST Software)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3876806816-3870314601-911572463-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3876806816-3870314601-911572463-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6581488 2013-08-15] (SUPERAntiSpyware)
HKU\S-1-5-21-3876806816-3870314601-911572463-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
HKU\S-1-5-21-3876806816-3870314601-911572463-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
AppInit_DLLs: C:\Windows\System32\guard64.dll => C:\Windows\System32\guard64.dll [389840 2011-12-19] (COMODO)
AppInit_DLLs-x32: C:\Windows\SysWOW64\guard32.dll => C:\Windows\SysWOW64\guard32.dll [301224 2011-12-19] (COMODO)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE47F6FBC96AECF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl-be
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll (Google Inc.)
BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Tcpip\Parameters: [DhcpNameServer]

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-02]

CHR StartupUrls: "hxxp://www.google.com/"
CHR Extension: (Docs) - C:\Users\Akron\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-02]
CHR Extension: (Google Drive) - C:\Users\Akron\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-02]
CHR Extension: (YouTube) - C:\Users\Akron\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-02]
CHR Extension: (Google Zoeken) - C:\Users\Akron\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-02]
CHR Extension: (avast! Online Security) - C:\Users\Akron\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-08-02]
CHR Extension: (Google Wallet) - C:\Users\Akron\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-02]
CHR Extension: (Gmail) - C:\Users\Akron\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-02]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-02]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com)
R2 AnviStartupTime; C:\Program Files (x86)\Anvisoft\StartupBooster\StartupTimeSrv.exe [193256 2013-04-24] (Anvisoft)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-02] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [106488 2014-08-02] (AVAST Software)
R2 CLPSLS; C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [1267000 2011-11-23] (COMODO)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2779416 2011-12-19] (COMODO)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 A2DDA; C:\EEK\RUN\a2ddax64.sys [26176 2014-07-21] (Emsisoft GmbH)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-02] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-08-02] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-02] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [448400 2014-08-02] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-02] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-02] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-02] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-02] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-02] (AVAST Software)
S3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57024 2014-07-21] (Emsisoft GmbH)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [577824 2012-01-17] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [43248 2011-12-19] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-08-03] (Disc Soft Ltd)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
S3 gfiutil; C:\Windows\System32\drivers\gfiutil.sys [31264 2013-09-04] (ThreatTrack Security)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [93200 2011-12-19] (COMODO)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-03] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 aswVmm; \??\C:\Users\Akron\AppData\Local\Temp\aswVmm.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U3 aswMBR; \??\C:\Users\Akron\AppData\Local\Temp\aswMBR.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-04 10:41 - 2014-08-04 10:41 - 00012672 _____ () C:\Users\Akron\Desktop\FRST.txt
2014-08-04 10:39 - 2014-08-04 10:41 - 00000000 ____D () C:\FRST
2014-08-04 05:40 - 2014-08-04 06:35 - 00000112 _____ () C:\Windows\setupact.log
2014-08-04 00:01 - 2014-08-04 00:01 - 02094080 _____ (Farbar) C:\Users\Akron\Desktop\FRST64.exe
2014-08-04 00:00 - 2014-08-04 00:00 - 05185536 _____ (AVAST Software) C:\Users\Akron\Desktop\aswMBR.exe
2014-08-03 23:59 - 2014-08-03 23:59 - 04057608 _____ () C:\Users\Akron\Desktop\tweaking.com_registry_backup_setup.exe
2014-08-03 21:56 - 2014-08-03 21:56 - 00021422 _____ () C:\ComboFix.txt
2014-08-03 21:14 - 2014-08-03 21:14 - 09522240 _____ () C:\Users\Akron\Downloads\tweaking.com_windows_repair_aio_setup.exe
2014-08-03 21:12 - 2014-08-03 21:12 - 00002170 _____ () C:\Users\Akron\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2014-08-03 21:11 - 2014-08-03 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-08-03 21:11 - 2014-08-03 21:11 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-03 21:10 - 2014-08-03 21:15 - 00003062 _____ () C:\Users\Akron\Desktop\Rkill.txt
2014-08-03 21:06 - 2014-08-03 21:07 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-03 21:06 - 2014-08-03 21:06 - 00001440 _____ () C:\Users\Akron\Desktop\MBAM.lnk
2014-08-03 21:06 - 2014-08-03 21:06 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-03 21:06 - 2014-05-12 13:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-03 21:04 - 2014-08-03 21:04 - 00279896 _____ () C:\Windows\Minidump\080314-36473-01.dmp
2014-08-03 19:38 - 2014-08-03 19:38 - 00002243 _____ () C:\Windows\epplauncher.mif
2014-08-03 19:12 - 2014-08-03 19:12 - 00279896 _____ () C:\Windows\Minidump\080314-26785-01.dmp
2014-08-03 17:48 - 2014-08-04 09:48 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ebbecc67-3cc7-4b75-8b91-b3b886c0e521.job
2014-08-03 17:48 - 2014-08-03 19:06 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9349cd4c-b26b-41ed-9000-fa8da98a969c.job
2014-08-03 17:48 - 2014-08-03 17:48 - 00003580 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 9349cd4c-b26b-41ed-9000-fa8da98a969c
2014-08-03 17:48 - 2014-08-03 17:48 - 00003506 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task ebbecc67-3cc7-4b75-8b91-b3b886c0e521
2014-08-03 17:48 - 2014-08-03 17:48 - 00001779 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2014-08-03 17:48 - 2014-08-03 17:48 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\SUPERAntiSpyware.com
2014-08-03 17:48 - 2014-08-03 17:48 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-08-03 17:48 - 2014-08-03 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-08-03 17:48 - 2014-08-03 17:48 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-08-03 17:45 - 2014-08-03 21:04 - 391647295 _____ () C:\Windows\MEMORY.DMP
2014-08-03 17:45 - 2014-08-03 21:04 - 00000000 ____D () C:\Windows\Minidump
2014-08-03 17:45 - 2014-08-03 17:45 - 00279896 _____ () C:\Windows\Minidump\080314-42853-01.dmp
2014-08-03 17:07 - 2014-08-03 17:07 - 00000022 _____ () C:\Windows\cmm.dat
2014-08-03 16:40 - 2014-08-03 16:40 - 00001221 _____ () C:\Users\Public\Desktop\StartupBooster.lnk
2014-08-03 16:40 - 2014-08-03 16:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
2014-08-03 16:40 - 2014-08-03 16:40 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-08-03 16:39 - 2014-08-03 16:39 - 00003512 _____ () C:\Windows\System32\Tasks\Clean System Memory
2014-08-03 16:39 - 2014-08-03 16:39 - 00000000 ____D () C:\Windows\CleanMem
2014-08-03 16:39 - 2014-08-03 16:39 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CleanMem
2014-08-03 16:39 - 2014-08-03 16:39 - 00000000 ____D () C:\Program Files (x86)\CleanMem
2014-08-03 16:39 - 2012-09-21 00:27 - 00061440 _____ (PcWinTech.com) C:\Windows\SysWOW64\CleanMem.exe
2014-08-03 16:39 - 2012-06-26 20:40 - 00000187 _____ () C:\Windows\SysWOW64\CleanMem.ini
2014-08-03 16:39 - 2009-02-22 07:53 - 00000565 _____ () C:\Windows\SysWOW64\CleanMem.exe.manifest
2014-08-03 16:25 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-03 16:25 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-03 16:25 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-03 16:25 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-03 16:25 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-03 16:25 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-03 16:25 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-03 16:25 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-03 16:15 - 2014-08-03 16:52 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 16:03 - 2014-08-03 16:03 - 00000000 ____D () C:\Program Files (x86)\VST
2014-08-03 15:46 - 2014-08-03 15:46 - 00000000 _____ () C:\Windows\SysWOW64\SBRC.dat
2014-08-03 15:46 - 2013-09-04 14:57 - 00031264 _____ (ThreatTrack Security) C:\Windows\system32\Drivers\gfiutil.sys
2014-08-03 15:45 - 2013-05-23 08:39 - 00041032 _____ (ThreatTrack Security) C:\Windows\system32\Drivers\gfiark.sys
2014-08-03 15:39 - 2014-08-03 15:39 - 00001094 _____ () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 9 Suite.lnk
2014-08-03 15:31 - 2014-08-04 05:40 - 00002818 _____ () C:\Windows\PFRO.log
2014-08-03 15:26 - 2014-08-03 15:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-03 14:08 - 2014-08-03 14:08 - 00000000 ____D () C:\Program Files (x86)\MBAM Portable
2014-08-03 13:59 - 2014-08-03 13:58 - 03784904 _____ (WiseCleaner.com ) C:\Users\Akron\Downloads\WPCASetup.exe
2014-08-03 13:30 - 2014-08-03 15:31 - 00000402 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
2014-08-03 13:30 - 2014-08-03 13:30 - 00003212 _____ () C:\Windows\System32\Tasks\Wise Turbo Checker
2014-08-03 13:22 - 2014-08-03 13:22 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Macromedia
2014-08-03 13:22 - 2014-08-03 13:22 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Adobe
2014-08-03 13:22 - 2014-08-03 13:22 - 00000000 ____D () C:\Users\Akron\AppData\Local\Macromedia
2014-08-03 13:17 - 2014-08-03 13:17 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-03 13:16 - 2014-08-03 13:17 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-03 13:16 - 2014-08-03 13:16 - 00000793 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-03 13:16 - 2014-08-03 13:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-03 12:48 - 2014-08-03 12:48 - 00000000 ____D () C:\ProgramData\Ableton
2014-08-03 12:37 - 2014-08-03 12:37 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton
2014-08-03 12:37 - 2014-08-03 12:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton
2014-08-03 12:37 - 2010-10-08 17:57 - 00368640 _____ (Propellerhead Software AB) C:\Windows\SysWOW64\ReWire.dll
2014-08-03 12:37 - 2010-10-08 17:57 - 00233472 _____ (Propellerhead Software AB) C:\Windows\SysWOW64\REX Shared Library.dll
2014-08-03 11:29 - 2014-08-03 12:53 - 00000000 ____D () C:\Users\Akron\Documents\Ableton
2014-08-03 11:29 - 2014-08-03 12:48 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Ableton
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debugging Tools for Windows (x64)
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Application Verifier (x64)
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Application Verifier
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\Program Files\Debugging Tools for Windows (x64)
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\Program Files\Application Verifier (x64)
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\Program Files (x86)\Application Verifier
2014-08-03 11:18 - 2014-08-03 11:19 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 9.0
2014-08-03 11:18 - 2014-08-03 11:18 - 00000000 ____D () C:\Windows\symbols
2014-08-03 10:19 - 2014-08-03 10:19 - 00000000 ____D () C:\Users\Akron\AppData\Local\Microsoft Help
2014-08-03 10:17 - 2014-08-03 11:18 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-03 10:17 - 2014-08-03 11:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0
2014-08-03 10:17 - 2014-08-03 10:17 - 00000000 ____D () C:\Program Files\Microsoft SDKs
2014-08-03 10:12 - 2014-08-03 10:12 - 00504144 _____ (Microsoft Corporation) C:\Users\Akron\Downloads\winsdk_web.exe
2014-08-03 10:08 - 2011-02-19 08:37 - 01135104 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-08-03 09:57 - 2014-08-03 15:39 - 00000000 ____D () C:\Program Files (x86)\Ableton
2014-08-03 09:56 - 2014-08-03 09:56 - 00001275 _____ () C:\Users\Akron\Desktop\Revo Uninstaller.lnk
2014-08-03 09:56 - 2014-08-03 09:56 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-03 09:43 - 2014-08-03 09:43 - 00001961 _____ () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2014-08-03 09:42 - 2014-08-03 09:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2014-08-03 09:41 - 2014-08-03 14:52 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\DAEMON Tools Lite
2014-08-03 09:41 - 2014-08-03 09:41 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2014-08-03 09:41 - 2014-08-03 09:41 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\WinRAR
2014-08-03 09:41 - 2014-08-03 09:41 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2014-08-03 09:40 - 2014-08-03 09:47 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2014-08-03 09:31 - 2014-08-04 10:02 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-03 09:31 - 2014-08-03 09:31 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-03 09:31 - 2014-08-03 09:31 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-03 09:31 - 2014-08-03 09:31 - 00003878 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-03 09:31 - 2014-08-03 09:31 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-08-03 09:31 - 2014-08-03 09:31 - 00000000 ____D () C:\Windows\system32\Macromed
2014-08-03 09:21 - 2014-08-03 09:21 - 00001466 _____ () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-03 09:13 - 2014-08-03 09:13 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-03 06:10 - 2010-09-14 08:45 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2014-08-03 06:10 - 2010-09-14 08:07 - 00276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2014-08-03 04:58 - 2009-09-10 08:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-08-03 04:58 - 2009-09-10 07:52 - 00257024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-08-03 04:41 - 2012-07-26 06:55 - 00785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-08-03 04:41 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-08-03 04:41 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-08-03 04:41 - 2012-06-02 16:35 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-08-03 04:17 - 2014-08-03 04:23 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-03 04:16 - 2014-06-26 17:40 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-03 04:00 - 2009-11-25 12:47 - 01942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-08-03 04:00 - 2009-11-25 12:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-08-03 04:00 - 2009-11-25 12:47 - 00444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2014-08-03 04:00 - 2009-11-25 12:47 - 00320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2014-08-03 04:00 - 2009-11-25 12:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll
2014-08-03 04:00 - 2009-11-25 12:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe
2014-08-03 04:00 - 2009-11-25 12:47 - 00109912 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2014-08-03 04:00 - 2009-11-25 12:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll
2014-08-03 04:00 - 2009-11-25 12:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll
2014-08-03 04:00 - 2009-11-25 12:47 - 00048960 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2014-08-03 03:59 - 2010-02-23 10:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-08-03 03:51 - 2014-08-03 03:51 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-08-03 03:51 - 2014-08-03 03:51 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-03 03:51 - 2014-08-03 03:51 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-03 03:51 - 2014-08-03 03:51 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-03 03:51 - 2014-08-03 03:51 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-03 03:51 - 2014-08-03 03:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-08-03 03:51 - 2014-08-03 03:51 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-08-03 03:51 - 2014-08-03 03:51 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-08-03 03:51 - 2014-08-03 03:51 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-08-03 03:51 - 2014-08-03 03:51 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-08-03 03:18 - 2012-12-16 18:52 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-08-03 03:18 - 2012-12-16 16:40 - 00367616 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-08-03 03:18 - 2012-12-16 16:25 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-08-03 03:18 - 2012-12-16 16:25 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-08-03 03:18 - 2009-10-19 16:46 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-08-03 03:18 - 2009-10-19 16:10 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-08-03 03:15 - 2012-07-26 05:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-08-03 03:15 - 2012-07-26 05:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-08-03 03:15 - 2012-07-26 05:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-08-03 03:15 - 2012-07-26 05:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-08-03 03:15 - 2012-07-26 05:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-08-03 03:15 - 2012-07-26 04:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-08-03 03:15 - 2012-07-26 04:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-08-03 03:15 - 2012-06-02 16:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-08-03 03:00 - 2012-03-01 08:54 - 00022896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-08-03 03:00 - 2012-03-01 08:40 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-08-03 03:00 - 2012-03-01 08:35 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-08-03 03:00 - 2012-03-01 07:45 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-08-03 03:00 - 2012-03-01 07:40 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-08-03 02:35 - 2010-03-04 06:40 - 00184832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-08-03 02:35 - 2010-03-04 06:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-08-03 02:14 - 2013-02-12 17:42 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-08-03 02:14 - 2013-02-12 17:37 - 03138048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-08-03 02:14 - 2013-02-12 17:31 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-08-03 02:14 - 2013-02-12 17:13 - 02691072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-08-03 02:14 - 2013-02-12 17:07 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-08-03 02:14 - 2013-02-12 15:59 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-08-03 02:14 - 2011-11-17 09:12 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-08-03 02:14 - 2011-11-17 07:39 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-08-03 02:14 - 2010-03-05 09:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2014-08-03 02:14 - 2010-03-05 09:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2014-08-03 02:12 - 2011-01-26 08:53 - 00982912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-03 02:12 - 2011-01-26 08:53 - 00265088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-03 02:12 - 2011-01-26 08:31 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-03 02:12 - 2010-11-02 07:18 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll
2014-08-03 02:12 - 2010-11-02 06:41 - 00135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll
2014-08-03 02:12 - 2010-06-26 07:31 - 01863680 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2014-08-03 02:12 - 2010-06-26 07:14 - 01495040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2014-08-03 02:12 - 2010-05-23 12:15 - 01619456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-08-03 02:12 - 2010-05-23 12:11 - 03181568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-08-03 02:12 - 2010-05-23 12:11 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2014-08-03 02:12 - 2010-05-23 10:37 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-08-03 02:12 - 2010-05-23 10:35 - 04068864 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-08-03 02:12 - 2010-05-23 10:35 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2014-08-03 02:12 - 2010-05-23 10:35 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-08-03 02:11 - 2011-05-04 07:30 - 02326016 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-08-03 02:11 - 2011-05-04 07:28 - 02228224 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-08-03 02:11 - 2011-05-04 07:28 - 00779264 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-08-03 02:11 - 2011-05-04 07:28 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-08-03 02:11 - 2011-05-04 07:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2014-08-03 02:11 - 2011-05-04 07:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2014-08-03 02:11 - 2011-05-04 07:24 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-08-03 02:11 - 2011-05-04 07:24 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-08-03 02:11 - 2011-05-04 07:24 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-08-03 02:11 - 2011-05-04 06:53 - 01553920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2014-08-03 02:11 - 2011-05-04 06:52 - 01401856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2014-08-03 02:11 - 2011-05-04 06:52 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2014-08-03 02:11 - 2011-05-04 06:52 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2014-08-03 02:11 - 2011-05-04 06:52 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2014-08-03 02:11 - 2011-05-04 06:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2014-08-03 02:11 - 2011-05-04 06:52 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2014-08-03 02:11 - 2011-05-04 06:52 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2014-08-03 02:11 - 2011-05-04 06:52 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2014-08-03 02:10 - 2014-07-01 03:56 - 00516096 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-03 02:10 - 2014-07-01 03:50 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-03 02:10 - 2009-09-03 09:36 - 01975296 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2014-08-03 02:10 - 2009-09-03 09:04 - 01320960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2014-08-03 02:08 - 2012-06-09 07:30 - 14165504 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-03 02:08 - 2012-06-09 06:46 - 12868608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-03 02:08 - 2012-03-03 08:29 - 01837568 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-08-03 02:08 - 2012-03-03 08:29 - 01541120 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-08-03 02:08 - 2012-03-03 08:29 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-08-03 02:08 - 2012-03-03 08:29 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-08-03 02:08 - 2012-03-03 08:29 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-08-03 02:08 - 2012-03-03 07:40 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-08-03 02:08 - 2012-03-03 07:40 - 01074176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-08-03 02:08 - 2012-03-03 07:40 - 00739840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-08-03 02:08 - 2012-03-03 07:40 - 00218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-08-03 02:08 - 2012-03-03 07:40 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-08-03 02:07 - 2012-01-04 11:58 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-08-03 02:07 - 2012-01-04 11:03 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2014-08-03 02:06 - 2012-11-09 07:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-03 02:06 - 2012-11-09 06:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-03 01:59 - 2012-12-07 07:41 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-08-03 01:59 - 2012-12-07 07:35 - 02745856 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-08-03 01:59 - 2012-12-07 07:04 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-08-03 01:59 - 2012-12-07 06:57 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
2014-08-03 01:59 - 2012-12-07 05:45 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-08-03 01:59 - 2012-12-07 05:45 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
2014-08-03 01:59 - 2012-12-07 05:21 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
2014-08-03 01:56 - 2013-01-04 07:37 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-08-03 01:56 - 2013-01-04 07:37 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-08-03 01:56 - 2013-01-04 07:37 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-08-03 01:56 - 2013-01-04 07:36 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-08-03 01:56 - 2013-01-04 07:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-08-03 01:56 - 2013-01-04 07:30 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-08-03 01:56 - 2013-01-04 07:30 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:51 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-08-03 01:56 - 2013-01-04 06:51 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-08-03 01:56 - 2013-01-04 06:51 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 05:19 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-08-03 01:56 - 2013-01-04 04:48 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-08-03 01:56 - 2013-01-04 04:48 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-08-03 01:56 - 2013-01-04 04:48 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-08-03 01:56 - 2013-01-04 04:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 04:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-08-03 01:56 - 2013-01-04 04:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-08-03 01:56 - 2010-12-23 08:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-08-03 01:56 - 2010-12-23 08:07 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-08-03 01:56 - 2010-12-23 08:02 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-08-03 01:56 - 2010-12-23 07:28 - 00850432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-08-03 01:56 - 2010-12-23 07:28 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-08-03 01:56 - 2010-12-23 07:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-08-03 01:56 - 2010-06-19 08:53 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2014-08-03 01:56 - 2010-06-19 08:23 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtutils.dll
2014-08-03 01:55 - 2013-01-04 07:26 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-08-03 01:55 - 2013-01-04 07:26 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-08-03 01:55 - 2013-01-04 06:43 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-08-03 01:55 - 2013-01-04 06:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-08-03 01:55 - 2013-01-04 04:48 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-08-03 01:55 - 2013-01-04 04:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-08-03 01:55 - 2011-04-09 08:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-08-03 01:55 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-08-03 01:54 - 2012-11-09 07:34 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-08-03 01:54 - 2012-11-09 06:49 - 00492032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-08-03 01:54 - 2011-06-15 11:58 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-08-03 01:54 - 2011-06-15 11:58 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-08-03 01:54 - 2011-06-15 11:58 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-08-03 01:54 - 2011-06-15 11:58 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-08-03 01:54 - 2011-06-15 11:04 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-08-03 01:54 - 2011-06-15 11:04 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-08-03 01:54 - 2011-06-15 11:04 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-08-03 01:54 - 2011-06-15 11:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-08-03 01:54 - 2011-06-15 11:04 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-08-03 01:53 - 2013-01-04 07:41 - 01893224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-08-03 01:53 - 2013-01-04 07:40 - 00287576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-08-03 01:53 - 2010-12-21 08:16 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2014-08-03 01:53 - 2010-12-21 08:16 - 00258048 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-08-03 01:53 - 2010-12-21 08:16 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2014-08-03 01:53 - 2010-12-21 08:16 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2014-08-03 01:53 - 2010-12-21 08:15 - 00264192 _____ (Microsoft Corporation) C:\Windows\system32\upnp.dll
2014-08-03 01:53 - 2010-12-21 08:15 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2014-08-03 01:53 - 2010-12-21 08:10 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-08-03 01:53 - 2010-12-21 07:38 - 00350720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2014-08-03 01:53 - 2010-12-21 07:38 - 00204800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-08-03 01:53 - 2010-12-21 07:38 - 00204288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnp.dll
2014-08-03 01:53 - 2010-12-21 07:38 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2014-08-03 01:53 - 2010-12-21 07:38 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2014-08-03 01:53 - 2010-12-21 07:34 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-08-03 01:53 - 2010-11-02 07:18 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2014-08-03 01:53 - 2010-11-02 07:17 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2014-08-03 01:53 - 2010-11-02 07:17 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2014-08-03 01:53 - 2010-11-02 07:16 - 01114624 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-08-03 01:53 - 2010-11-02 07:10 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2014-08-03 01:53 - 2010-11-02 07:10 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2014-08-03 01:53 - 2010-11-02 06:40 - 00496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll
2014-08-03 01:53 - 2010-11-02 06:40 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2014-08-03 01:53 - 2010-11-02 06:34 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2014-08-03 01:53 - 2010-11-02 06:34 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2014-08-03 01:53 - 2010-05-05 09:37 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2014-08-03 01:53 - 2010-05-05 08:46 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2014-08-03 01:52 - 2011-10-26 07:22 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-08-03 01:52 - 2011-10-26 07:22 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-08-03 01:52 - 2011-10-26 06:28 - 01328640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-08-03 01:52 - 2011-10-26 06:28 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-08-03 01:51 - 2012-11-30 01:21 - 00420032 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-03 01:51 - 2012-11-30 01:19 - 00420032 _____ () C:\Windows\system32\locale.nls
2014-08-03 01:45 - 2013-04-12 16:36 - 01653096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-08-03 01:45 - 2013-03-01 05:32 - 03150848 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-03 01:45 - 2011-07-09 04:44 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-08-03 01:45 - 2011-05-04 04:51 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-08-03 01:45 - 2011-05-04 04:51 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-08-03 01:44 - 2011-06-16 07:31 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2014-08-03 01:44 - 2011-06-16 06:35 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
2014-08-03 01:44 - 2010-06-29 07:39 - 02085376 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-08-03 01:43 - 2010-06-29 07:02 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2014-08-03 01:42 - 2012-06-02 07:38 - 00152432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-08-03 01:42 - 2012-06-02 07:38 - 00095088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-08-03 01:42 - 2012-06-02 07:37 - 00459216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-08-03 01:42 - 2012-06-02 07:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-08-03 01:42 - 2012-06-02 06:48 - 00225280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-08-03 01:42 - 2012-06-02 06:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-08-03 01:42 - 2012-06-02 06:42 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-08-03 01:42 - 2011-11-17 09:11 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-08-03 01:42 - 2011-11-17 09:11 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-08-03 01:42 - 2011-11-17 09:11 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-08-03 01:42 - 2011-11-17 09:08 - 01446912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-08-03 01:42 - 2011-11-17 09:05 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-08-03 01:42 - 2011-04-27 04:57 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-08-03 01:42 - 2011-03-12 14:03 - 00662528 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-08-03 01:42 - 2011-03-12 13:31 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-08-03 01:42 - 2011-03-11 08:19 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-08-03 01:42 - 2011-03-11 08:19 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-08-03 01:42 - 2011-03-11 07:40 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-08-03 01:42 - 2011-03-11 07:40 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-08-03 01:41 - 2013-02-12 16:02 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-08-03 01:41 - 2012-11-02 07:30 - 02001408 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-08-03 01:41 - 2012-11-02 07:30 - 01880064 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-08-03 01:41 - 2012-11-02 06:50 - 01388544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-08-03 01:41 - 2012-11-02 06:50 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-08-03 01:41 - 2010-08-26 07:27 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2014-08-03 01:41 - 2010-08-26 06:39 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2014-08-03 01:40 - 2012-08-02 19:55 - 00574464 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-08-03 01:40 - 2012-08-02 19:05 - 00490496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-08-03 01:40 - 2010-01-19 11:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-08-03 01:40 - 2010-01-19 11:05 - 00422912 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-08-03 01:40 - 2010-01-19 11:00 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-08-03 01:40 - 2010-01-19 01:29 - 00369152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-08-03 01:40 - 2010-01-19 01:29 - 00365568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-08-03 01:39 - 2011-04-29 05:13 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-08-03 01:39 - 2011-04-29 05:12 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-08-03 01:39 - 2011-04-29 05:12 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-08-03 01:39 - 2010-01-19 11:05 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-08-03 01:39 - 2010-01-19 11:05 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-08-03 01:39 - 2010-01-19 11:00 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-08-03 01:39 - 2010-01-19 11:00 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-08-03 01:39 - 2010-01-19 11:00 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-08-03 01:39 - 2010-01-19 01:29 - 00085504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-08-03 01:39 - 2010-01-19 01:29 - 00085504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-08-03 01:39 - 2010-01-19 01:28 - 00324608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-08-03 01:39 - 2010-01-19 01:28 - 00320512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-08-03 01:39 - 2010-01-19 01:28 - 00280064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-08-03 01:39 - 2010-01-19 01:28 - 00277504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-08-03 01:39 - 2009-10-31 08:34 - 02870272 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-08-03 01:39 - 2009-10-31 07:45 - 02614272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2014-08-03 01:39 - 2009-10-28 08:24 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-08-03 01:38 - 2011-02-24 08:30 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-08-03 01:38 - 2011-02-24 07:32 - 00288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-08-03 01:37 - 2012-04-28 05:50 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-08-03 01:34 - 2014-08-03 01:34 - 00002646 _____ () C:\Windows\System32\Tasks\Wise Care 365
2014-08-03 01:34 - 2014-08-03 01:34 - 00000374 _____ () C:\Windows\Tasks\Wise Care 365.job
2014-08-03 01:32 - 2011-03-03 08:17 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-08-03 01:32 - 2011-03-03 08:17 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-08-03 01:32 - 2011-03-03 08:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-08-03 01:32 - 2011-03-03 07:29 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-08-03 01:32 - 2011-03-03 07:27 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-08-03 01:32 - 2010-08-21 08:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-08-03 01:32 - 2010-08-21 07:33 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-08-03 01:31 - 2012-01-03 08:24 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-08-03 01:31 - 2012-01-03 07:44 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
2014-08-03 01:30 - 2012-05-02 07:32 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-08-03 01:30 - 2011-08-17 07:32 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-08-03 01:30 - 2011-08-17 07:27 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2014-08-03 01:30 - 2011-08-17 07:27 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-08-03 01:30 - 2011-08-17 07:27 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2014-08-03 01:30 - 2011-08-17 07:27 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2014-08-03 01:30 - 2011-08-17 06:26 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-08-03 01:30 - 2011-08-17 06:22 - 00204288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSNP.ax
2014-08-03 01:30 - 2011-08-17 06:22 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-08-03 01:30 - 2011-08-17 06:22 - 00072704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mpeg2Data.ax
2014-08-03 01:30 - 2011-08-17 06:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDvbNP.ax
2014-08-03 01:29 - 2012-04-07 14:18 - 03213824 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-03 01:29 - 2012-04-07 13:34 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-03 01:29 - 2010-08-21 08:29 - 00558592 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-08-03 01:28 - 2012-04-26 07:34 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-08-03 01:28 - 2012-04-26 07:34 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-08-03 01:28 - 2012-04-26 07:28 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-08-03 01:27 - 2012-11-22 12:32 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-08-03 01:27 - 2012-11-22 11:33 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-08-03 01:27 - 2009-12-19 11:50 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2014-08-03 01:27 - 2009-12-19 11:47 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2014-08-03 01:27 - 2009-12-19 11:47 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2014-08-03 01:27 - 2009-12-19 11:47 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2014-08-03 01:27 - 2009-12-19 11:46 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2014-08-03 01:27 - 2009-12-19 11:02 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\avifil32.dll
2014-08-03 01:27 - 2009-12-19 11:02 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mciavi32.dll
2014-08-03 01:27 - 2009-12-19 11:02 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iyuv_32.dll
2014-08-03 01:27 - 2009-12-19 11:02 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvidc32.dll
2014-08-03 01:27 - 2009-12-19 11:02 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msyuv.dll
2014-08-03 01:27 - 2009-12-19 11:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrle32.dll
2014-08-03 01:27 - 2009-12-19 11:02 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsbyuv.dll
2014-08-03 01:26 - 2010-08-21 08:38 - 01024512 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-08-03 01:26 - 2010-08-21 07:36 - 00738816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2014-08-03 01:23 - 2012-09-06 19:38 - 00295792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-08-03 01:23 - 2010-08-31 06:32 - 00954752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40.dll
2014-08-03 01:23 - 2010-08-31 06:32 - 00954288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc40u.dll
2014-08-03 01:22 - 2011-04-22 22:18 - 00027008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-08-03 01:22 - 2010-12-18 08:08 - 01097216 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-08-03 01:22 - 2010-12-18 07:26 - 01034240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-08-03 01:22 - 2010-07-29 08:30 - 00082944 _____ (Radius Inc.) C:\Windows\SysWOW64\iccvid.dll
2014-08-03 01:19 - 2012-08-11 02:53 - 00714752 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-08-03 01:19 - 2012-08-11 01:54 - 00541184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-08-03 01:18 - 2011-02-05 14:41 - 00640896 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-08-03 01:18 - 2011-02-05 14:41 - 00556928 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-08-03 01:18 - 2011-02-05 14:41 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-08-03 01:18 - 2011-02-05 14:41 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-08-03 01:18 - 2011-02-05 14:41 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-08-03 01:18 - 2011-02-05 14:39 - 00603976 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-08-03 01:18 - 2011-02-05 14:39 - 00518160 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-08-03 01:17 - 2012-11-20 07:55 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-08-03 01:17 - 2012-11-20 07:10 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-08-03 01:17 - 2012-11-02 07:27 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-08-03 01:17 - 2012-11-02 06:48 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-08-03 01:17 - 2010-09-01 07:21 - 14627840 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-08-03 01:16 - 2012-08-24 20:05 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-08-03 01:16 - 2012-08-24 19:10 - 00172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-08-03 01:16 - 2010-09-01 07:12 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-08-03 01:16 - 2010-09-01 06:29 - 11406848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-08-03 01:16 - 2010-09-01 06:23 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-08-03 01:14 - 2011-12-28 05:59 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-08-03 01:13 - 2014-08-03 15:32 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Wise Care 365
2014-08-03 01:13 - 2012-09-26 00:39 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-08-03 01:13 - 2012-09-25 23:55 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-08-03 01:13 - 2011-05-24 13:21 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-08-03 01:13 - 2011-05-24 12:34 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-08-03 01:13 - 2011-05-24 12:34 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-08-03 01:13 - 2011-05-24 12:34 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-08-03 01:13 - 2011-05-24 12:32 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-08-03 01:12 - 2012-03-17 09:55 - 00075632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-08-03 01:11 - 2009-08-29 09:50 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2014-08-03 01:11 - 2009-08-29 08:57 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msasn1.dll
2014-08-03 01:10 - 2012-05-05 10:30 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-08-03 01:10 - 2011-12-16 10:42 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-08-03 01:10 - 2011-12-16 09:59 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-08-03 01:09 - 2014-08-03 14:00 - 00001164 _____ () C:\Users\Public\Desktop\Wise PC 1stAid.lnk
2014-08-03 01:09 - 2014-08-03 14:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise PC 1stAid
2014-08-03 01:09 - 2014-08-03 01:37 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Wise PC 1stAid
2014-08-03 01:09 - 2012-05-05 09:44 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-08-03 01:09 - 2011-08-27 07:40 - 00861184 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-08-03 01:09 - 2011-08-27 07:40 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-08-03 01:09 - 2011-08-27 06:43 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-08-03 01:09 - 2011-08-27 06:43 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-08-03 01:08 - 2012-07-05 00:04 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-08-03 01:08 - 2012-07-05 00:01 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-08-03 01:08 - 2012-07-05 00:01 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-08-03 01:08 - 2012-07-04 23:26 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-08-03 01:08 - 2012-07-04 23:23 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-08-03 01:07 - 2014-08-03 01:09 - 00000000 ____D () C:\Program Files (x86)\Wise
2014-08-03 01:07 - 2014-08-03 01:07 - 00001167 _____ () C:\Users\Public\Desktop\Wise Care 365.lnk
2014-08-03 01:07 - 2014-08-03 01:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Care 365
2014-08-03 01:05 - 2014-08-03 01:05 - 00000952 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk
2014-08-03 01:05 - 2014-08-03 01:05 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-03 01:05 - 2014-08-03 01:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-03 01:03 - 2014-08-03 01:05 - 00000000 ____D () C:\Program Files\WinRAR
2014-08-03 01:03 - 2011-02-18 08:33 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2014-08-03 01:03 - 2011-02-18 07:33 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
2014-08-03 01:02 - 2013-01-24 07:41 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-08-03 01:02 - 2011-05-03 07:21 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-08-03 01:01 - 2011-05-03 06:50 - 00740864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-08-03 00:59 - 2014-08-03 11:57 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\vlc
2014-08-03 00:52 - 2014-08-03 11:59 - 00001077 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-08-03 00:52 - 2014-08-03 00:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-08-03 00:46 - 2014-08-03 00:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-08-03 00:46 - 2012-06-09 19:21 - 00178688 _____ () C:\Windows\SysWOW64\unrar.dll
2014-08-03 00:43 - 2014-08-03 00:43 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-08-03 00:36 - 2014-08-03 00:52 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
2014-08-03 00:28 - 2014-08-03 20:41 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-08-03 00:28 - 2014-08-03 00:28 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-08-03 00:27 - 2014-08-03 17:19 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-03 00:27 - 2014-08-03 00:27 - 00002196 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-08-03 00:27 - 2014-08-03 00:27 - 00002184 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-08-03 00:27 - 2014-08-03 00:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-08-03 00:27 - 2009-01-25 12:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-08-03 00:26 - 2014-08-03 14:37 - 00000000 ___RD () C:\Users\Akron\Desktop\MBAMPortable
2014-08-03 00:25 - 2014-07-21 22:47 - 17508309 _____ (Malwarebytes Corporation) C:\Users\Akron\Desktop\MBAMPortable_2.0.2.1012.paf (1).exe
2014-08-03 00:03 - 2014-08-03 00:03 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Mozilla
2014-08-03 00:03 - 2014-08-03 00:03 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Moonchild Productions
2014-08-03 00:03 - 2014-08-03 00:03 - 00000000 ____D () C:\Users\Akron\AppData\Local\Moonchild Productions
2014-08-03 00:01 - 2014-08-03 00:01 - 00001135 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pale Moon.lnk
2014-08-03 00:01 - 2014-08-03 00:01 - 00001123 _____ () C:\Users\Public\Desktop\Pale Moon.lnk
2014-08-03 00:01 - 2014-08-03 00:01 - 00000000 ____D () C:\Program Files (x86)\Pale Moon
2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Google
2014-08-02 23:54 - 2011-02-12 08:14 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-08-02 23:53 - 2013-03-19 08:19 - 05497688 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-08-02 23:53 - 2013-03-19 07:54 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-08-02 23:53 - 2013-03-19 07:06 - 03958120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-08-02 23:53 - 2013-03-19 07:06 - 03902312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-08-02 23:53 - 2013-03-19 06:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-08-02 23:53 - 2013-03-19 05:19 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-08-02 23:53 - 2012-05-14 07:20 - 00956416 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-08-02 23:53 - 2011-10-15 08:25 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-08-02 23:53 - 2011-10-15 07:48 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-08-02 23:53 - 2011-02-23 07:15 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-08-02 23:53 - 2010-10-16 07:23 - 00112000 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-02 23:53 - 2010-10-16 07:17 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2014-08-02 23:53 - 2010-10-16 06:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbc32.dll
2014-08-02 23:52 - 2011-11-17 09:14 - 01739160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-08-02 23:52 - 2011-11-17 07:41 - 01292592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-08-02 23:49 - 2014-08-03 09:23 - 00000000 ____D () C:\ProgramData\CPA_VA
2014-08-02 23:48 - 2014-08-03 09:44 - 00000000 ____D () C:\Users\Public\Documents\COMODO
2014-08-02 23:48 - 2014-08-02 23:48 - 00016962 _____ () C:\Windows\system32\results.xml
2014-08-02 23:41 - 2014-08-03 20:52 - 00002233 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-08-02 23:39 - 2014-08-02 23:38 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-08-02 23:39 - 2012-06-02 07:25 - 01462784 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-08-02 23:39 - 2012-06-02 07:25 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-08-02 23:39 - 2012-06-02 07:25 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-08-02 23:39 - 2012-06-02 06:45 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-08-02 23:39 - 2012-06-02 06:45 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-08-02 23:39 - 2012-06-02 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-08-02 23:38 - 2014-08-02 23:38 - 00448400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-08-02 23:38 - 2010-08-27 08:14 - 00236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-08-02 23:38 - 2010-08-27 07:46 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2014-08-02 23:34 - 2011-11-19 17:07 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-08-02 23:34 - 2011-11-19 16:06 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-08-02 23:31 - 2014-08-02 23:31 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\AVAST Software
2014-08-02 23:29 - 2014-08-04 06:39 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-02 23:29 - 2014-08-02 23:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-08-02 23:29 - 2014-08-02 23:29 - 06010880 _____ () C:\Program Files (x86)\GUT696.tmp
2014-08-02 23:29 - 2014-08-02 23:29 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-08-02 23:29 - 2014-08-02 23:29 - 00000000 ____D () C:\Program Files (x86)\GUM695.tmp
2014-08-02 23:28 - 2014-08-02 23:28 - 00000000 ____D () C:\Program Files\Google
2014-08-02 23:27 - 2014-08-02 23:29 - 00000000 ____D () C:\ProgramData\Google
2014-08-02 23:27 - 2014-07-23 10:52 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-02 23:25 - 2014-08-02 23:25 - 00002286 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-02 23:25 - 2014-08-02 23:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-02 23:24 - 2010-01-09 09:19 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2014-08-02 23:24 - 2010-01-09 08:52 - 00132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cabview.dll
2014-08-02 23:23 - 2014-08-02 23:23 - 00000000 ____D () C:\Intel
2014-08-02 23:22 - 2014-08-04 10:36 - 00001054 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-02 23:22 - 2014-08-04 06:37 - 00001050 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-02 23:22 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Akron\AppData\Local\Google
2014-08-02 23:22 - 2014-08-02 23:31 - 00004050 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-02 23:22 - 2014-08-02 23:31 - 00003798 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-02 23:22 - 2014-08-02 23:28 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-02 23:21 - 2012-02-15 08:27 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-08-02 23:21 - 2012-02-15 07:44 - 00826368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-08-02 23:21 - 2012-02-15 06:46 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-08-02 23:20 - 2014-08-02 23:29 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-08-02 23:20 - 2014-08-02 23:27 - 00000000 ____D () C:\ProgramData\Comodo
2014-08-02 23:20 - 2014-08-02 23:20 - 00001846 _____ () C:\Users\Public\Desktop\COMODO Firewall.lnk
2014-08-02 23:20 - 2014-08-02 23:20 - 00001056 _____ () C:\Users\Public\Desktop\COMODO GeekBuddy.lnk
2014-08-02 23:20 - 2014-08-02 23:19 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-08-02 23:20 - 2014-08-02 23:19 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-08-02 23:20 - 2014-08-02 23:19 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-08-02 23:20 - 2014-08-02 23:19 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-08-02 23:20 - 2014-08-02 23:19 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-08-02 23:20 - 2014-08-02 23:19 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-08-02 23:20 - 2014-08-02 23:19 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-02 23:19 - 2014-08-02 23:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2014-08-02 23:19 - 2014-08-02 23:20 - 00000000 ____D () C:\Program Files\COMODO
2014-08-02 23:19 - 2014-08-02 23:19 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-08-02 23:19 - 2014-08-02 23:19 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2014-08-02 23:19 - 2014-08-02 23:19 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-08-02 23:19 - 2014-08-02 23:19 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-08-02 23:19 - 2014-08-02 23:19 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-02 23:19 - 2014-08-02 23:19 - 00001121 _____ () C:\Users\Public\Desktop\Comodo Dragon.lnk
2014-08-02 23:19 - 2014-08-02 23:19 - 00000000 ____D () C:\Program Files (x86)\Comodo
2014-08-02 23:16 - 2014-08-02 23:16 - 00000000 ____D () C:\Program Files\AVAST Software
2014-08-02 23:15 - 2014-08-03 10:13 - 00058016 _____ () C:\Users\Akron\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-02 23:15 - 2014-08-02 23:16 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-08-02 23:14 - 2014-08-03 13:19 - 00000000 ____D () C:\Windows\Panther
2014-08-02 23:13 - 2012-06-03 00:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-02 23:13 - 2012-06-03 00:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-02 23:13 - 2012-06-03 00:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-02 23:13 - 2012-06-03 00:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-02 23:12 - 2012-06-03 00:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-02 23:12 - 2012-06-03 00:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-02 23:12 - 2012-06-03 00:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-02 23:12 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-02 23:12 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-02 23:12 - 2009-07-14 13:13 - 00171136 __RSH () C:\grldr
2014-08-02 23:11 - 2009-09-23 17:11 - 00283824 _____ (Intel Corporation) C:\Windows\system32\Drivers\e1k62x64.sys
2014-08-02 23:11 - 2009-09-16 18:06 - 00003148 _____ () C:\Windows\system32\e1k62x64.din
2014-08-02 23:11 - 2009-08-04 12:39 - 00078528 _____ (Intel Corporation) C:\Windows\system32\NicInstK.dll
2014-08-02 23:11 - 2009-08-04 09:35 - 00345800 _____ (Intel Corporation) C:\Windows\system32\PROUnstl.exe
2014-08-02 23:11 - 2009-05-26 10:05 - 00036472 _____ (Intel Corporation) C:\Windows\system32\NicCo36.dll
2014-08-02 23:11 - 2009-04-21 17:39 - 00072288 _____ (Intel Corporation) C:\Windows\system32\e1kmsg.dll
2014-08-02 23:09 - 2014-08-02 23:10 - 00000000 ____D () C:\Program Files\TOSHIBA
2014-08-02 23:09 - 2014-08-02 23:09 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\WinBatch
2014-08-02 23:09 - 2014-08-02 23:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA
2014-08-02 23:04 - 2014-08-03 09:21 - 00001392 _____ () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-08-02 23:03 - 2014-08-04 06:37 - 00000000 ____D () C:\Users\Akron
2014-08-02 23:03 - 2014-08-02 23:03 - 00000020 ___SH () C:\Users\Akron\ntuser.ini
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Sjablonen
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Netwerkprinteromgeving
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Mijn documenten
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Menu Start
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Documents\Mijn video's
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Documents\Mijn muziek
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Documents\Mijn afbeeldingen
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\AppData\Local\Geschiedenis
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 ____D () C:\Users\Akron\AppData\Local\VirtualStore
2014-08-02 23:03 - 2009-07-14 06:54 - 00000000 ___RD () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-02 23:03 - 2009-07-14 06:49 - 00000000 ___RD () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-08-02 22:55 - 2014-08-02 22:55 - 00000000 ____D () C:\Windows.old
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Public\Documents\Mijn video's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Public\Documents\Mijn muziek
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Public\Documents\Mijn afbeeldingen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Sjablonen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Netwerkprinteromgeving
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Mijn documenten
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Menu Start
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Documents\Mijn video's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Documents\Mijn muziek
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Documents\Mijn afbeeldingen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Geschiedenis
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\Documents\Mijn video's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\Documents\Mijn muziek
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\Documents\Mijn afbeeldingen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Geschiedenis
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Sjablonen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programma's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Menu Start
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Favorieten
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Documenten
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Bureaublad
2014-08-02 22:31 - 2014-08-02 22:31 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2014-08-02 22:29 - 2014-08-02 22:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf
2014-08-02 22:27 - 2014-08-02 22:27 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-08-02 22:26 - 2014-08-04 10:30 - 01478754 _____ () C:\Windows\WindowsUpdate.log
2014-08-02 16:37 - 2014-08-03 19:15 - 00000000 ____D () C:\VIPRERESCUE
2014-08-01 20:16 - 2014-08-03 21:57 - 00000000 ____D () C:\Qoobox
2014-08-01 19:32 - 2014-08-01 19:33 - 00000000 ____D () C:\EEK
2014-07-30 17:49 - 2014-08-02 23:14 - 00008192 __RSH () C:\BOOTSECT.BAK
2014-07-30 17:49 - 2010-11-20 14:40 - 00383786 __RSH () C:\bootmgr
2014-07-30 16:57 - 2014-08-02 22:53 - 00000000 ____D () C:\Recovery

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-04 10:41 - 2014-08-04 10:41 - 00012672 _____ () C:\Users\Akron\Desktop\FRST.txt
2014-08-04 10:41 - 2014-08-04 10:39 - 00000000 ____D () C:\FRST
2014-08-04 10:36 - 2014-08-02 23:22 - 00001054 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-04 10:30 - 2014-08-02 22:26 - 01478754 _____ () C:\Windows\WindowsUpdate.log
2014-08-04 10:02 - 2014-08-03 09:31 - 00000940 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-04 09:48 - 2014-08-03 17:48 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ebbecc67-3cc7-4b75-8b91-b3b886c0e521.job
2014-08-04 06:45 - 2009-07-14 06:45 - 00010016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-04 06:45 - 2009-07-14 06:45 - 00010016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-04 06:39 - 2014-08-02 23:29 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-04 06:37 - 2014-08-02 23:22 - 00001050 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-04 06:37 - 2014-08-02 23:03 - 00000000 ____D () C:\Users\Akron
2014-08-04 06:35 - 2014-08-04 05:40 - 00000112 _____ () C:\Windows\setupact.log
2014-08-04 06:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-04 05:40 - 2014-08-03 15:31 - 00002818 _____ () C:\Windows\PFRO.log
2014-08-04 00:01 - 2014-08-04 00:01 - 02094080 _____ (Farbar) C:\Users\Akron\Desktop\FRST64.exe
2014-08-04 00:00 - 2014-08-04 00:00 - 05185536 _____ (AVAST Software) C:\Users\Akron\Desktop\aswMBR.exe
2014-08-03 23:59 - 2014-08-03 23:59 - 04057608 _____ () C:\Users\Akron\Desktop\tweaking.com_registry_backup_setup.exe
2014-08-03 21:57 - 2014-08-01 20:16 - 00000000 ____D () C:\Qoobox
2014-08-03 21:56 - 2014-08-03 21:56 - 00021422 _____ () C:\ComboFix.txt
2014-08-03 21:48 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-03 21:15 - 2014-08-03 21:10 - 00003062 _____ () C:\Users\Akron\Desktop\Rkill.txt
2014-08-03 21:14 - 2014-08-03 21:14 - 09522240 _____ () C:\Users\Akron\Downloads\tweaking.com_windows_repair_aio_setup.exe
2014-08-03 21:12 - 2014-08-03 21:12 - 00002170 _____ () C:\Users\Akron\Desktop\Tweaking.com - Windows Repair (All in One).lnk
2014-08-03 21:11 - 2014-08-03 21:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-08-03 21:11 - 2014-08-03 21:11 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-08-03 21:07 - 2014-08-03 21:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-03 21:06 - 2014-08-03 21:06 - 00001440 _____ () C:\Users\Akron\Desktop\MBAM.lnk
2014-08-03 21:06 - 2014-08-03 21:06 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-03 21:04 - 2014-08-03 21:04 - 00279896 _____ () C:\Windows\Minidump\080314-36473-01.dmp
2014-08-03 21:04 - 2014-08-03 17:45 - 391647295 _____ () C:\Windows\MEMORY.DMP
2014-08-03 21:04 - 2014-08-03 17:45 - 00000000 ____D () C:\Windows\Minidump
2014-08-03 20:52 - 2014-08-02 23:41 - 00002233 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-08-03 20:41 - 2014-08-03 00:28 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-08-03 19:38 - 2014-08-03 19:38 - 00002243 _____ () C:\Windows\epplauncher.mif
2014-08-03 19:15 - 2014-08-02 16:37 - 00000000 ____D () C:\VIPRERESCUE
2014-08-03 19:12 - 2014-08-03 19:12 - 00279896 _____ () C:\Windows\Minidump\080314-26785-01.dmp
2014-08-03 19:06 - 2014-08-03 17:48 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9349cd4c-b26b-41ed-9000-fa8da98a969c.job
2014-08-03 17:48 - 2014-08-03 17:48 - 00003580 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 9349cd4c-b26b-41ed-9000-fa8da98a969c
2014-08-03 17:48 - 2014-08-03 17:48 - 00003506 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task ebbecc67-3cc7-4b75-8b91-b3b886c0e521
2014-08-03 17:48 - 2014-08-03 17:48 - 00001779 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2014-08-03 17:48 - 2014-08-03 17:48 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\SUPERAntiSpyware.com
2014-08-03 17:48 - 2014-08-03 17:48 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-08-03 17:48 - 2014-08-03 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-08-03 17:48 - 2014-08-03 17:48 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-08-03 17:45 - 2014-08-03 17:45 - 00279896 _____ () C:\Windows\Minidump\080314-42853-01.dmp
2014-08-03 17:19 - 2014-08-03 00:27 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-03 17:07 - 2014-08-03 17:07 - 00000022 _____ () C:\Windows\cmm.dat
2014-08-03 17:04 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-08-03 16:52 - 2014-08-03 16:15 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 16:43 - 2009-07-14 04:34 - 51904512 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-08-03 16:43 - 2009-07-14 04:34 - 15204352 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-08-03 16:43 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-08-03 16:43 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-08-03 16:43 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-08-03 16:40 - 2014-08-03 16:40 - 00001221 _____ () C:\Users\Public\Desktop\StartupBooster.lnk
2014-08-03 16:40 - 2014-08-03 16:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvisoft
2014-08-03 16:40 - 2014-08-03 16:40 - 00000000 ____D () C:\Program Files (x86)\Anvisoft
2014-08-03 16:39 - 2014-08-03 16:39 - 00003512 _____ () C:\Windows\System32\Tasks\Clean System Memory
2014-08-03 16:39 - 2014-08-03 16:39 - 00000000 ____D () C:\Windows\CleanMem
2014-08-03 16:39 - 2014-08-03 16:39 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CleanMem
2014-08-03 16:39 - 2014-08-03 16:39 - 00000000 ____D () C:\Program Files (x86)\CleanMem
2014-08-03 16:30 - 2009-07-14 11:16 - 00691728 _____ () C:\Windows\system32\perfh013.dat
2014-08-03 16:30 - 2009-07-14 11:16 - 00130232 _____ () C:\Windows\system32\perfc013.dat
2014-08-03 16:30 - 2009-07-14 07:13 - 01523502 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-03 16:03 - 2014-08-03 16:03 - 00000000 ____D () C:\Program Files (x86)\VST
2014-08-03 15:46 - 2014-08-03 15:46 - 00000000 _____ () C:\Windows\SysWOW64\SBRC.dat
2014-08-03 15:39 - 2014-08-03 15:39 - 00001094 _____ () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 9 Suite.lnk
2014-08-03 15:39 - 2014-08-03 09:57 - 00000000 ____D () C:\Program Files (x86)\Ableton
2014-08-03 15:32 - 2014-08-03 01:13 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Wise Care 365
2014-08-03 15:31 - 2014-08-03 13:30 - 00000402 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
2014-08-03 15:26 - 2014-08-03 15:26 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-03 14:52 - 2014-08-03 09:41 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\DAEMON Tools Lite
2014-08-03 14:37 - 2014-08-03 00:26 - 00000000 ___RD () C:\Users\Akron\Desktop\MBAMPortable
2014-08-03 14:08 - 2014-08-03 14:08 - 00000000 ____D () C:\Program Files (x86)\MBAM Portable
2014-08-03 14:00 - 2014-08-03 01:09 - 00001164 _____ () C:\Users\Public\Desktop\Wise PC 1stAid.lnk
2014-08-03 14:00 - 2014-08-03 01:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise PC 1stAid
2014-08-03 13:58 - 2014-08-03 13:59 - 03784904 _____ (WiseCleaner.com ) C:\Users\Akron\Downloads\WPCASetup.exe
2014-08-03 13:30 - 2014-08-03 13:30 - 00003212 _____ () C:\Windows\System32\Tasks\Wise Turbo Checker
2014-08-03 13:22 - 2014-08-03 13:22 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Macromedia
2014-08-03 13:22 - 2014-08-03 13:22 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Adobe
2014-08-03 13:22 - 2014-08-03 13:22 - 00000000 ____D () C:\Users\Akron\AppData\Local\Macromedia
2014-08-03 13:19 - 2014-08-02 23:14 - 00000000 ____D () C:\Windows\Panther
2014-08-03 13:17 - 2014-08-03 13:17 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-03 13:17 - 2014-08-03 13:16 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-03 13:16 - 2014-08-03 13:16 - 00000793 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-03 13:16 - 2014-08-03 13:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-03 12:53 - 2014-08-03 11:29 - 00000000 ____D () C:\Users\Akron\Documents\Ableton
2014-08-03 12:48 - 2014-08-03 12:48 - 00000000 ____D () C:\ProgramData\Ableton
2014-08-03 12:48 - 2014-08-03 11:29 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Ableton
2014-08-03 12:37 - 2014-08-03 12:37 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton
2014-08-03 12:37 - 2014-08-03 12:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton
2014-08-03 11:59 - 2014-08-03 00:52 - 00001077 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-08-03 11:57 - 2014-08-03 00:59 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\vlc
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debugging Tools for Windows (x64)
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Application Verifier (x64)
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Application Verifier
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\Program Files\Debugging Tools for Windows (x64)
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\Program Files\Application Verifier (x64)
2014-08-03 11:21 - 2014-08-03 11:21 - 00000000 ____D () C:\Program Files (x86)\Application Verifier
2014-08-03 11:19 - 2014-08-03 11:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 9.0
2014-08-03 11:18 - 2014-08-03 11:18 - 00000000 ____D () C:\Windows\symbols
2014-08-03 11:18 - 2014-08-03 10:17 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-03 11:17 - 2014-08-03 10:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0
2014-08-03 10:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-08-03 10:19 - 2014-08-03 10:19 - 00000000 ____D () C:\Users\Akron\AppData\Local\Microsoft Help
2014-08-03 10:17 - 2014-08-03 10:17 - 00000000 ____D () C:\Program Files\Microsoft SDKs
2014-08-03 10:13 - 2014-08-02 23:15 - 00058016 _____ () C:\Users\Akron\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-03 10:12 - 2014-08-03 10:12 - 00504144 _____ (Microsoft Corporation) C:\Users\Akron\Downloads\winsdk_web.exe
2014-08-03 09:56 - 2014-08-03 09:56 - 00001275 _____ () C:\Users\Akron\Desktop\Revo Uninstaller.lnk
2014-08-03 09:56 - 2014-08-03 09:56 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-03 09:47 - 2014-08-03 09:40 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2014-08-03 09:44 - 2014-08-02 23:48 - 00000000 ____D () C:\Users\Public\Documents\COMODO
2014-08-03 09:43 - 2014-08-03 09:43 - 00001961 _____ () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2014-08-03 09:43 - 2014-08-03 09:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2014-08-03 09:41 - 2014-08-03 09:41 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2014-08-03 09:41 - 2014-08-03 09:41 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\WinRAR
2014-08-03 09:41 - 2014-08-03 09:41 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2014-08-03 09:31 - 2014-08-03 09:31 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-03 09:31 - 2014-08-03 09:31 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-03 09:31 - 2014-08-03 09:31 - 00003878 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-03 09:31 - 2014-08-03 09:31 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-08-03 09:31 - 2014-08-03 09:31 - 00000000 ____D () C:\Windows\system32\Macromed
2014-08-03 09:23 - 2014-08-02 23:49 - 00000000 ____D () C:\ProgramData\CPA_VA
2014-08-03 09:21 - 2014-08-03 09:21 - 00001466 _____ () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-03 09:21 - 2014-08-02 23:04 - 00001392 _____ () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2014-08-03 09:17 - 2009-07-14 06:45 - 00267472 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-03 09:13 - 2014-08-03 09:13 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-03 09:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-08-03 09:12 - 2009-07-14 11:58 - 00000000 ____D () C:\Program Files\Windows Journal
2014-08-03 09:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-03 04:23 - 2014-08-03 04:17 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-03 03:51 - 2014-08-03 03:51 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-08-03 03:51 - 2014-08-03 03:51 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-08-03 03:51 - 2014-08-03 03:51 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-03 03:51 - 2014-08-03 03:51 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-03 03:51 - 2014-08-03 03:51 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-03 03:51 - 2014-08-03 03:51 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-03 03:51 - 2014-08-03 03:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-08-03 03:51 - 2014-08-03 03:51 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-08-03 03:51 - 2014-08-03 03:51 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-08-03 03:51 - 2014-08-03 03:51 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-08-03 03:51 - 2014-08-03 03:51 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-08-03 03:51 - 2014-08-03 03:51 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-03 03:51 - 2014-08-03 03:51 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-08-03 01:37 - 2014-08-03 01:09 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Wise PC 1stAid
2014-08-03 01:34 - 2014-08-03 01:34 - 00002646 _____ () C:\Windows\System32\Tasks\Wise Care 365
2014-08-03 01:34 - 2014-08-03 01:34 - 00000374 _____ () C:\Windows\Tasks\Wise Care 365.job
2014-08-03 01:09 - 2014-08-03 01:07 - 00000000 ____D () C:\Program Files (x86)\Wise
2014-08-03 01:07 - 2014-08-03 01:07 - 00001167 _____ () C:\Users\Public\Desktop\Wise Care 365.lnk
2014-08-03 01:07 - 2014-08-03 01:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wise Care 365
2014-08-03 01:05 - 2014-08-03 01:05 - 00000952 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk
2014-08-03 01:05 - 2014-08-03 01:05 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-03 01:05 - 2014-08-03 01:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-08-03 01:05 - 2014-08-03 01:03 - 00000000 ____D () C:\Program Files\WinRAR
2014-08-03 00:52 - 2014-08-03 00:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-08-03 00:52 - 2014-08-03 00:36 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
2014-08-03 00:46 - 2014-08-03 00:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-08-03 00:43 - 2014-08-03 00:43 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-08-03 00:28 - 2014-08-03 00:28 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-08-03 00:27 - 2014-08-03 00:27 - 00002196 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-08-03 00:27 - 2014-08-03 00:27 - 00002184 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-08-03 00:27 - 2014-08-03 00:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-08-03 00:03 - 2014-08-03 00:03 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Mozilla
2014-08-03 00:03 - 2014-08-03 00:03 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Moonchild Productions
2014-08-03 00:03 - 2014-08-03 00:03 - 00000000 ____D () C:\Users\Akron\AppData\Local\Moonchild Productions
2014-08-03 00:01 - 2014-08-03 00:01 - 00001135 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pale Moon.lnk
2014-08-03 00:01 - 2014-08-03 00:01 - 00001123 _____ () C:\Users\Public\Desktop\Pale Moon.lnk
2014-08-03 00:01 - 2014-08-03 00:01 - 00000000 ____D () C:\Program Files (x86)\Pale Moon
2014-08-02 23:57 - 2014-08-02 23:57 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\Google
2014-08-02 23:57 - 2014-08-02 23:22 - 00000000 ____D () C:\Users\Akron\AppData\Local\Google
2014-08-02 23:48 - 2014-08-02 23:48 - 00016962 _____ () C:\Windows\system32\results.xml
2014-08-02 23:41 - 2014-08-02 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-08-02 23:38 - 2014-08-02 23:39 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-08-02 23:38 - 2014-08-02 23:38 - 00448400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-08-02 23:31 - 2014-08-02 23:31 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\AVAST Software
2014-08-02 23:31 - 2014-08-02 23:22 - 00004050 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-08-02 23:31 - 2014-08-02 23:22 - 00003798 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-08-02 23:29 - 2014-08-02 23:29 - 06010880 _____ () C:\Program Files (x86)\GUT696.tmp
2014-08-02 23:29 - 2014-08-02 23:29 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-08-02 23:29 - 2014-08-02 23:29 - 00000000 ____D () C:\Program Files (x86)\GUM695.tmp
2014-08-02 23:29 - 2014-08-02 23:27 - 00000000 ____D () C:\ProgramData\Google
2014-08-02 23:29 - 2014-08-02 23:20 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-08-02 23:28 - 2014-08-02 23:28 - 00000000 ____D () C:\Program Files\Google
2014-08-02 23:28 - 2014-08-02 23:22 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-02 23:27 - 2014-08-02 23:20 - 00000000 ____D () C:\ProgramData\Comodo
2014-08-02 23:25 - 2014-08-02 23:25 - 00002286 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-02 23:25 - 2014-08-02 23:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-08-02 23:23 - 2014-08-02 23:23 - 00000000 ____D () C:\Intel
2014-08-02 23:20 - 2014-08-02 23:20 - 00001846 _____ () C:\Users\Public\Desktop\COMODO Firewall.lnk
2014-08-02 23:20 - 2014-08-02 23:20 - 00001056 _____ () C:\Users\Public\Desktop\COMODO GeekBuddy.lnk
2014-08-02 23:20 - 2014-08-02 23:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2014-08-02 23:20 - 2014-08-02 23:19 - 00000000 ____D () C:\Program Files\COMODO
2014-08-02 23:19 - 2014-08-02 23:20 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-08-02 23:19 - 2014-08-02 23:20 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-08-02 23:19 - 2014-08-02 23:20 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-08-02 23:19 - 2014-08-02 23:20 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-08-02 23:19 - 2014-08-02 23:20 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-08-02 23:19 - 2014-08-02 23:20 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-08-02 23:19 - 2014-08-02 23:20 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-02 23:19 - 2014-08-02 23:19 - 01700352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll
2014-08-02 23:19 - 2014-08-02 23:19 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2014-08-02 23:19 - 2014-08-02 23:19 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
2014-08-02 23:19 - 2014-08-02 23:19 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-08-02 23:19 - 2014-08-02 23:19 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-02 23:19 - 2014-08-02 23:19 - 00001121 _____ () C:\Users\Public\Desktop\Comodo Dragon.lnk
2014-08-02 23:19 - 2014-08-02 23:19 - 00000000 ____D () C:\Program Files (x86)\Comodo
2014-08-02 23:16 - 2014-08-02 23:16 - 00000000 ____D () C:\Program Files\AVAST Software
2014-08-02 23:16 - 2014-08-02 23:15 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-08-02 23:14 - 2014-07-30 17:49 - 00008192 __RSH () C:\BOOTSECT.BAK
2014-08-02 23:14 - 2009-07-14 07:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-08-02 23:14 - 2009-07-14 07:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-08-02 23:12 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore
2014-08-02 23:12 - 2009-07-14 06:45 - 00000000 ____D () C:\Windows\Setup
2014-08-02 23:12 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-08-02 23:10 - 2014-08-02 23:09 - 00000000 ____D () C:\Program Files\TOSHIBA
2014-08-02 23:09 - 2014-08-02 23:09 - 00000000 ____D () C:\Users\Akron\AppData\Roaming\WinBatch
2014-08-02 23:09 - 2014-08-02 23:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA
2014-08-02 23:03 - 2014-08-02 23:03 - 00000020 ___SH () C:\Users\Akron\ntuser.ini
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Sjablonen
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Netwerkprinteromgeving
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Mijn documenten
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Menu Start
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Documents\Mijn video's
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Documents\Mijn muziek
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\Documents\Mijn afbeeldingen
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 _SHDL () C:\Users\Akron\AppData\Local\Geschiedenis
2014-08-02 23:03 - 2014-08-02 23:03 - 00000000 ____D () C:\Users\Akron\AppData\Local\VirtualStore
2014-08-02 22:55 - 2014-08-02 22:55 - 00000000 ____D () C:\Windows.old
2014-08-02 22:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Public\Documents\Mijn video's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Public\Documents\Mijn muziek
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Public\Documents\Mijn afbeeldingen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Sjablonen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Netwerkprinteromgeving
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Mijn documenten
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Menu Start
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Documents\Mijn video's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Documents\Mijn muziek
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\Documents\Mijn afbeeldingen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Geschiedenis
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\Documents\Mijn video's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\Documents\Mijn muziek
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\Documents\Mijn afbeeldingen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programma's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Geschiedenis
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Sjablonen
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programma's
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Menu Start
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Favorieten
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Documenten
2014-08-02 22:53 - 2014-08-02 22:53 - 00000000 _SHDL () C:\ProgramData\Bureaublad
2014-08-02 22:53 - 2014-07-30 16:57 - 00000000 ____D () C:\Recovery
2014-08-02 22:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Recovery
2014-08-02 22:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Windows NT
2014-08-02 22:32 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-02 22:31 - 2014-08-02 22:31 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2014-08-02 22:31 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-08-02 22:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\sysprep
2014-08-02 22:29 - 2014-08-02 22:29 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf
2014-08-02 22:27 - 2014-08-02 22:27 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-08-02 22:24 - 2009-07-14 11:57 - 00000000 ____D () C:\Windows\CSC
2014-08-01 19:33 - 2014-08-01 19:32 - 00000000 ____D () C:\EEK
2014-07-23 10:52 - 2014-08-02 23:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-07-21 22:47 - 2014-08-03 00:25 - 17508309 _____ (Malwarebytes Corporation) C:\Users\Akron\Desktop\MBAMPortable_2.0.2.1012.paf (1).exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2014-08-02 22:23

==================== End Of Log ============================

Thanks in advance!

2014-08-04, 19:19
Hi Akron,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.


You should of generated another log file when you did the FRST scan called Addition.txt, include that in your next reply.


You appear to have run ComboFix & Rkill on 2014-08-03. Please locate the logs and include them in your next reply.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Security Check

Download Security Check by screen317 from here (http://screen317.spywareinfoforum.org/SecurityCheck.exe) or here (http://screen317.changelog.fr/SecurityCheck.exe).
Save it to your Desktop.

Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
A Notepad document should open automatically called checkup.txt; please post the contents of that document.


In your next post please provide the following:

Have you recently rolled back to an earlier System Restore Point?

2014-08-05, 01:23
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-08-2014
Ran by Akron at 2014-08-04 10:42:52
Running from C:\Users\Akron\Desktop
Boot Mode: Normal

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
AS: COMODO Defense+ (Enabled - Up to date) {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
FW: COMODO Firewall (Enabled) {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Ableton Live 9 Suite (HKLM-x32\...\{A8D189F5-A5BD-4F59-94C3-BD39662B96F7}) (Version: - Ableton)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated)
Application Verifier (x64) (HKLM\...\{361A49FA-59B3-49FB-8C3E-08AF3EA5791A}) (Version: 4.0.917 - Microsoft Corporation)
avast! Internet Security (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
CleanMem (HKLM-x32\...\CleanMem) (Version: v2.4.3 - PcWinTech.com)
Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 15.0 - COMODO)
COMODO GeekBuddy (HKLM-x32\...\COMODO GeekBuddy) (Version: 3.3.217083.59 - COMODO)
COMODO Internet Security (HKLM\...\{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}) (Version: 5.9.25057.2197 - COMODO Security Solutions Inc.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: - Disc Soft Ltd)
Debugging Tools for Windows (x64) (HKLM\...\{7F2E5C3B-DBDF-469D-AD8D-F686D3B71176}) (Version: - Microsoft Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 14.5 - Intel)
K-Lite Codec Pack 9.4.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.4.0 - )
Live 8.2.1 (HKLM-x32\...\Live 8.2.1) (Version: - )
Microsoft Document Explorer 2008 (HKLM-x32\...\Microsoft Document Explorer 2008) (Version: - Microsoft Corporation)
Microsoft Document Explorer 2008 (x32 Version: 9.0.21022 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x64 (HKLM\...\{965DF723-5688-359E-84D2-417CAFE644B5}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ Compilers 2008 Standard Edition - enu - x86 (HKLM-x32\...\{44D9A2CB-0692-3180-B5E2-26F4E807D067}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Windows SDK .NET Framework Tools (40715) (Version: 7.0.40715 - Microsoft) Hidden
Microsoft Windows SDK for Windows 7 (7.0) (HKLM\...\SDKSetup_7.0.7600.16385.40715) (Version: 7.0.7600.16385.40715 - Microsoft Corporation)
Microsoft Windows SDK for Windows 7 (7.0) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 .NET Documentation (40715) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Common Utilities (40715) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Headers and Libraries (40715) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Redistributable Components for Application Verifier and Windows Debugging Tools (40715) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Samples (40715) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (40715) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Microsoft Windows SDK for Windows 7 Win32 Documentation (40715) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Microsoft Windows SDK Net Fx Interop Headers And Libraries (40715) (Version: 7.0.40715 - Microsoft Corporation) Hidden
Pale Moon 24.7.0 (x86 en-US) (HKLM-x32\...\Pale Moon 24.7.0 (x86 en-US)) (Version: 24.7.0 - Moonchild Productions)
Revo Uninstaller 1.94 (HKLM-x32\...\Revo Uninstaller) (Version: 1.94 - VS Revo Group)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.0.12 - Safer-Networking Ltd.)
StartupBooster 1.0 (HKLM-x32\...\StartupBooster) (Version: 1.0 - anvisoft)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1032 - SUPERAntiSpyware.com)
TOSHIBA HDD Protection (HKLM\...\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: - TOSHIBA Corporation)
Tweaking.com - Windows Repair (All in One) (HKLM-x32\...\Tweaking.com - Windows Repair (All in One)) (Version: 2.8.3 - Tweaking.com)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WinRAR 5.10 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
Wise Care 365 2.95 (HKLM-x32\...\Wise Care 365_is1) (Version: 2.95 - WiseCleaner.com, Inc.)
Wise PC 1stAid 1.36 (HKLM-x32\...\Wise PC 1stAid_is1) (Version: 1.36 - WiseCleaner.com, Inc.)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

==================== Restore Points =========================

02-08-2014 21:23:08 Installatie van apparaatstuurprogramma: COMODO Network Service
02-08-2014 21:24:03 Windows Update
02-08-2014 21:35:13 avast! antivirus system restore point
02-08-2014 21:40:26 Installatie van apparaatstuurprogramma: Avast Network Service
02-08-2014 23:17:13 Installatieprogramma voor Windows-modules
03-08-2014 00:24:26 Windows Update
03-08-2014 07:41:25 Installatie van apparaatstuurprogramma: DT Soft Ltd Systeemapparaten
03-08-2014 07:48:42 Installed Ableton Live 9 Suite
03-08-2014 07:56:51 Installed Ableton Live 9 Suite
03-08-2014 08:08:32 Windows Update
03-08-2014 09:32:13 Windows Update
03-08-2014 09:36:13 Windows Update
03-08-2014 10:17:23 Windows Update
03-08-2014 11:26:33 Created by Wise Care 365
03-08-2014 13:05:16 Revo Uninstaller's restore point - Ableton Live 9 Suite
03-08-2014 13:07:26 Removed Ableton Live 9 Suite
03-08-2014 13:25:45 Windows Update
03-08-2014 13:37:52 Installed Ableton Live 9 Suite
03-08-2014 15:08:44 Windows Update
03-08-2014 15:51:11 Windows Update
03-08-2014 18:58:43 C
04-08-2014 03:46:46 C
04-08-2014 03:48:28 C
04-08-2014 03:50:52 C
04-08-2014 03:53:03 Windows Update
04-08-2014 04:42:08 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2014-08-03 21:47 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {247F4DF0-6A99-433B-9584-379FA67DC1CD} - System32\Tasks\Wise Care 365 => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe [2013-12-09] (WiseCleaner.com)
Task: {333C207A-985D-4F53-A356-6533422CA960} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-02] (Google Inc.)
Task: {3825E51C-2582-43A2-A976-F69665C62671} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {5BA49994-2BB2-4153-9252-C05C70D40178} - System32\Tasks\Wise Turbo Checker => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2014-01-21] (WiseCleaner.COM)
Task: {63F1B49D-EB8B-472A-91A7-057B018724D8} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-08-02] (AVAST Software)
Task: {67CA8312-3968-4220-9AFD-8C6D993FC2BD} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {7DAB7A22-17A3-4313-A9DE-6F092DE77F40} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {9040D1FF-E68E-4671-A109-F8CC69A19CF2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {97EDB5DA-1F5D-40D4-8C31-29A2B57A818D} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-03] (Adobe Systems Incorporated)
Task: {A45B3363-0FBA-4069-B3FF-9EB096C2E457} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-08-02] (Google Inc.)
Task: {B97C341C-9675-4343-B084-85CBA6418D28} - System32\Tasks\Clean System Memory => C:\Windows\syswow64\CleanMem.exe [2012-09-21] (PcWinTech.com)
Task: {C5DBC30B-B536-4E56-9D5D-5D9A0AFA23AC} - System32\Tasks\SUPERAntiSpyware Scheduled Task ebbecc67-3cc7-4b75-8b91-b3b886c0e521 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com)
Task: {EF3D92CD-2C3A-42DC-9802-869130EE4D63} - System32\Tasks\SUPERAntiSpyware Scheduled Task 9349cd4c-b26b-41ed-9000-fa8da98a969c => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9349cd4c-b26b-41ed-9000-fa8da98a969c.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ebbecc67-3cc7-4b75-8b91-b3b886c0e521.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
Task: C:\Windows\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe

==================== Loaded Modules (whitelisted) =============

2011-11-23 12:27 - 2011-11-23 12:27 - 00493880 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\CRF\export.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 00358712 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\EventMonitor\export.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 02687800 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\GuiListener\export.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 00020280 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLANG.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 01131320 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\CLPS_RES.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 00500024 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\RemoteDesktop\export.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 02185016 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\Socket\export.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 05714232 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\Socket\Adaptor.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 00048952 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\RemoteDesktop\ShHook.dll
2011-11-23 12:27 - 2011-11-23 12:27 - 00146232 _____ () C:\Program Files\COMODO\COMODO GeekBuddy\Components\Core\EventMonitor\EventMonitor.dll
2014-08-02 23:19 - 2014-08-02 23:19 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-08-03 20:59 - 2014-08-03 20:59 - 02795008 _____ () C:\Program Files\AVAST Software\Avast\defs\14080301\algo.dll
2014-08-03 00:27 - 2012-11-13 14:06 - 00108960 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-08-03 00:27 - 2012-11-13 14:06 - 00416160 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-08-03 00:27 - 2012-11-13 14:06 - 00158624 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-08-03 00:27 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-08-03 00:27 - 2012-11-13 14:06 - 00528288 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl
2014-08-02 23:19 - 2014-08-02 23:19 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-08-03 00:27 - 2012-11-13 14:06 - 00554400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl
2014-07-23 01:29 - 2014-07-23 01:29 - 00113171 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 02396691 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00268307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00027667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00031251 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00066579 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 02043411 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00100371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00244243 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00076307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_vdr_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00045587 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00060947 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00531475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00708627 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00114195 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00040467 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libstream_filter_rar_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00014867 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00133139 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01512467 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00296979 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01248787 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00054291 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00038419 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libglobalhotkeys_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 11148307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00189971 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00036371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00292371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00017939 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01280019 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00018451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00336403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00344595 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00198675 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00027155 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libg711_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015891 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01393171 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00146451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00022035 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00733203 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00026131 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00171027 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libopus_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liba52_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 10447379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00746515 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\text_renderer\libfreetype_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00026643 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi420_yuy2_sse2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi420_yuy2_mmx_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00587283 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libswscale_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00113683 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi420_rgb_sse2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00027667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi422_yuy2_sse2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi422_yuy2_mmx_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00053779 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi420_rgb_mmx_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00016915 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i422_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libgrey_yuv_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00032275 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00020499 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i420_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00017427 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_i420_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libscale_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00013843 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libyuvp_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00068115 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00013843 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01496083 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll
2014-08-03 00:01 - 2014-07-25 13:04 - 03044352 _____ () C:\Program Files (x86)\Pale Moon\mozjs.dll

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CLPSLS => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

==================== Faulty Device Manager Devices =============

Class Guid:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Class Guid:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Base System-apparaat
Description: Base System-apparaat
Class Guid:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Fingerprint Sensor
Description: Fingerprint Sensor
Class Guid:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================

Application errors:
Error: (08/04/2014 10:33:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Naam van toepassing met fout: aswMBR.exe, versie:, tijdstempel: 0x539e8df7
Naam van module met fout: ntdll.dll, versie: 6.1.7600.16915, tijdstempel: 0x4ec49d10
Uitzonderingscode: 0xc0000005
Foutoffset: 0x0002e423
Id van proces met fout: 0x1064
Starttijd van toepassing met fout: 0xaswMBR.exe0
Pad naar toepassing met fout: aswMBR.exe1
Pad naar module met fout: aswMBR.exe2
Rapport-id: aswMBR.exe3

Error: (08/04/2014 07:49:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Het programma vlc.exe, versie reageert niet meer op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum in het Configuratiescherm.

Proces-id: e68

Starttijd: 01cfafa7568a9c12

Eindtijd: 20

Toepassingspad: C:\Program Files (x86)\VideoLAN\VLC\vlc.exe

Rapport-id: f4411f6c-1b9a-11e4-93cb-002318f92a8a

Error: (08/03/2014 09:18:38 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Er kan geen herstelpunt worden gemaakt (proces = C:\Windows\system32\wbem\wmiprvse.exe; beschrijving = ComboFix created restore point; fout = 0x8007043c).

Error: (08/03/2014 09:18:37 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Fout in de Volume Shadow Copy-service: onverwachte fout bij het aanroepen van routine CoCreateInstance. hr = 0x8007043c, Deze service kan niet in veilige modus worden gestart.

Instantie van VSS-server maken

Error: (08/03/2014 09:18:37 PM) (Source: VSS) (EventID: 18) (User: )
Description: Fout in de Volume Shadow Copy-service: de COM-server met CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} en naam IVssCoordinatorEx2 kan niet worden gestart in de veilige modus.
De Volume Shadow Copy-service kan niet worden gestart in de veilige modus. [0x8007043c, Deze service kan niet in veilige modus worden gestart.

Instantie van VSS-server maken

Error: (08/03/2014 07:38:08 PM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: AkV-i5)
Description: HRESULT:0x8004FF11
Description:Can’t install Microsoft Security Essentials on a computer running in safe mode. Your computer is currently running in safe mode. To install Security Essentials, your computer must be running in normal mode. Please restart your computer in normal mode, and then try to run the Security Essentials Setup Wizard again. Error code:0x8004FF11.

Error: (08/03/2014 03:04:12 PM) (Source: MsiInstaller) (EventID: 11730) (User: AkV-i5)
Description: Product: Ableton Live 9 Suite -- Error 1730. You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance.

Error: (08/03/2014 10:33:27 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Kan activeringscontext voor 'Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1' niet maken.
Kan afhankelijke assembly Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" niet vinden.
Gebruik sxstrace.exe voor een gedetailleerde diagnose.

Error: (08/03/2014 10:24:52 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Kan activeringscontext voor 'Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1' niet maken.
Kan afhankelijke assembly Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" niet vinden.
Gebruik sxstrace.exe voor een gedetailleerde diagnose.

Error: (08/03/2014 10:17:19 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Kan activeringscontext voor 'Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1' niet maken.
Kan afhankelijke assembly Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8" niet vinden.
Gebruik sxstrace.exe voor een gedetailleerde diagnose.

System errors:
Error: (08/04/2014 06:35:22 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: De vorige afsluiting van het systeem om 6:31:53 op ‎4/‎08/‎2014 is onverwacht gebeurd.

Error: (08/04/2014 05:47:56 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: De Windows Update-service is bij het starten vastgelopen.

Error: (08/04/2014 03:38:36 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084wuauserv{E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error: (08/03/2014 09:57:23 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: De HomeGroup Provider-service is afhankelijk van de Function Discovery Provider Host-service, die vanwege de volgende fout niet kan worden gestart:

Error: (08/03/2014 09:52:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: De Computer Browser-service is afhankelijk van de Server-service, die vanwege de volgende fout niet kan worden gestart:

Error: (08/03/2014 09:52:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: De Computer Browser-service is afhankelijk van de Server-service, die vanwege de volgende fout niet kan worden gestart:

Error: (08/03/2014 09:52:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: De Computer Browser-service is afhankelijk van de Server-service, die vanwege de volgende fout niet kan worden gestart:

Error: (08/03/2014 09:52:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: De Computer Browser-service is afhankelijk van de Server-service, die vanwege de volgende fout niet kan worden gestart:

Error: (08/03/2014 09:52:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: De Computer Browser-service is afhankelijk van de Server-service, die vanwege de volgende fout niet kan worden gestart:

Error: (08/03/2014 09:52:48 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: De Computer Browser-service is afhankelijk van de Server-service, die vanwege de volgende fout niet kan worden gestart:

Microsoft Office Sessions:
Error: (08/04/2014 10:33:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: aswMBR.exe1.0.1.2041539e8df7ntdll.dll6.1.7600.169154ec49d10c00000050002e423106401cfafa087d0a4cdC:\Users\Akron\Desktop\aswMBR.exeC:\Windows\SysWOW64\ntdll.dll127fc211-1bb2-11e4-93cb-002318f92a8a

Error: (08/04/2014 07:49:57 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: vlc.exe2.1.5.0e6801cfafa7568a9c1220C:\Program Files (x86)\VideoLAN\VLC\vlc.exef4411f6c-1b9a-11e4-93cb-002318f92a8a

Error: (08/03/2014 09:18:38 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Windows\system32\wbem\wmiprvse.exeComboFix created restore point0x8007043c

Error: (08/03/2014 09:18:37 PM) (Source: VSS) (EventID: 8193) (User: )
Description: CoCreateInstance0x8007043c, Deze service kan niet in veilige modus worden gestart.

Instantie van VSS-server maken

Error: (08/03/2014 09:18:37 PM) (Source: VSS) (EventID: 18) (User: )
Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}IVssCoordinatorEx20x8007043c, Deze service kan niet in veilige modus worden gestart.

Instantie van VSS-server maken

Error: (08/03/2014 07:38:08 PM) (Source: Microsoft Security Client Setup) (EventID: 100) (User: AkV-i5)
Description: HRESULT:0x8004FF11
Description:Can’t install Microsoft Security Essentials on a computer running in safe mode. Your computer is currently running in safe mode. To install Security Essentials, your computer must be running in normal mode. Please restart your computer in normal mode, and then try to run the Security Essentials Setup Wizard again. Error code:0x8004FF11.

Error: (08/03/2014 03:04:12 PM) (Source: MsiInstaller) (EventID: 11730) (User: AkV-i5)
Description: Product: Ableton Live 9 Suite -- Error 1730. You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (08/03/2014 10:33:27 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files (x86)\Common Files\Microsoft Shared\Help 9\msenv.dll

Error: (08/03/2014 10:24:52 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.ATL,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files (x86)\Common Files\Microsoft Shared\Help 9\msenv.dll

Error: (08/03/2014 10:17:19 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files (x86)\Ableton\Live 9 Suite\Program\Ableton Live 9 Suite.exe

CodeIntegrity Errors:
Date: 2014-08-03 21:42:49.676
Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume1\ComboFix\catchme.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.

Date: 2014-08-03 21:42:49.645
Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume1\ComboFix\catchme.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.

Date: 2014-08-03 21:42:49.552
Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume1\ComboFix\catchme.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.

Date: 2014-08-03 21:42:49.474
Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume1\ComboFix\catchme.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.

Date: 2014-08-03 16:40:55.079
Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume1\ComboFix\catchme.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.

Date: 2014-08-03 16:40:55.047
Description: De integriteit van de kopie van het bestand \Device\HarddiskVolume1\ComboFix\catchme.sys kan niet worden geverifieerd omdat de bestands-hash niet is gevonden op het systeem. Tijdens een recente hardware- of softwarewijziging is mogelijk een bestand geïnstalleerd dat onjuist ondertekend of beschadigd is, of dat mogelijk kwaadwillende software van een onbekende bron is.

==================== Memory info ===========================

Percentage of memory in use: 69%
Total physical RAM: 1840.43 MB
Available physical RAM: 556.26 MB
Total Pagefile: 3680.85 MB
Available Pagefile: 1294.96 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (Ak V i5 SyS) (Fixed) (Total:174.29 GB) (Free:119.5 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Ak V i5) (Fixed) (Total:58.59 GB) (Free:38.95 GB) NTFS
Drive f: (RB) (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
Drive g: (HDDRIVE2GO) (Fixed) (Total:2794.51 GB) (Free:2621.12 GB) NTFS
Drive h: (X-Terra 4) (Fixed) (Total:621 GB) (Free:208.54 GB) NTFS
Drive i: (X-Terra 5) (Fixed) (Total:621 GB) (Free:385.06 GB) NTFS
Drive j: (X-Terra 6) (Fixed) (Total:621.01 GB) (Free:341.47 GB) NTFS
Drive k: (X-7) (Fixed) (Total:465.76 GB) (Free:188.09 GB) NTFS
Drive l: (SUITE821PC) (CDROM) (Total:1.86 GB) (Free:0 GB) CDFS
Drive m: (Muzik) (Fixed) (Total:149.05 GB) (Free:74.74 GB) NTFS
Drive n: (LIVESUITE90132) (CDROM) (Total:0.93 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 55D9B683)
Partition 1: (Active) - (Size=174 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=59 GB) - (Type=07 NTFS)

Disk: 1 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: 5BD3FE09)
Partition 1: (Active) - (Size=4 GB) - (Type=0B)

Disk: 2 (Size: 149 GB) (Disk ID: 049AD02F)
Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS)

Disk: 3 (Size: 466 GB) (Disk ID: A59F7D00)
Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS)
Attempted reading MBR returned 0 bytes.
Could not read MBR for disk 4.

Disk: 5 (Size: 1863 GB) (Disk ID: 536C51CC)
Partition 1: (Active) - (Size=621 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1242 GB) - (Type=OF Extended)

==================== End Of Log ============================


ComboFix 14-07-25.01 - Akron 03/08/2014 21:19:35.2.4 - x64 NETWORK
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.32.1043.18.1840.584 [GMT 2:00]
Gestart vanuit: j:\exe\64-Bit\Progz\sys\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Nieuw herstelpunt werd aangemaakt
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
(((((((((((((((((((( Bestanden Gemaakt van 2014-07-03 to 2014-08-03 ))))))))))))))))))))))))))))))
2014-08-03 19:47 . 2014-08-03 19:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-08-03 19:11 . 2014-08-03 19:11 -------- d-----w- c:\program files (x86)\Tweaking.com
2014-08-03 19:06 . 2014-08-03 19:07 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-08-03 19:06 . 2014-08-03 19:06 -------- d-----w- c:\programdata\Malwarebytes
2014-08-03 19:06 . 2014-05-12 11:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-08-03 15:48 . 2014-08-03 15:48 -------- d-----w- c:\program files\SUPERAntiSpyware
2014-08-03 15:48 . 2014-08-03 15:48 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2014-08-03 14:40 . 2014-08-03 14:40 -------- d-----w- c:\program files (x86)\Anvisoft
2014-08-03 14:39 . 2012-09-20 22:27 61440 ----a-w- c:\windows\SysWow64\CleanMem.exe
2014-08-03 14:39 . 2014-08-03 14:39 -------- d-----w- c:\windows\CleanMem
2014-08-03 14:39 . 2014-08-03 14:39 -------- d-----w- c:\program files (x86)\CleanMem
2014-08-03 14:03 . 2014-08-03 14:03 -------- d-----w- c:\program files (x86)\VST
2014-08-03 13:46 . 2013-09-04 12:57 31264 ----a-w- c:\windows\system32\drivers\gfiutil.sys
2014-08-03 13:45 . 2013-05-23 06:39 41032 ----a-w- c:\windows\system32\drivers\gfiark.sys
2014-08-03 12:08 . 2014-08-03 12:08 -------- d-----w- c:\program files (x86)\MBAM Portable
2014-08-03 11:16 . 2014-08-03 11:17 -------- d-----w- c:\program files\CCleaner
2014-08-03 10:48 . 2014-08-03 10:48 -------- d-----w- c:\programdata\Ableton
2014-08-03 10:37 . 2010-10-08 15:57 233472 ----a-w- c:\windows\SysWow64\REX Shared Library.dll
2014-08-03 10:37 . 2010-10-08 15:57 368640 ----a-w- c:\windows\SysWow64\ReWire.dll
2014-08-03 09:21 . 2014-08-03 09:21 -------- d-----w- c:\program files\Debugging Tools for Windows (x64)
2014-08-03 09:21 . 2014-08-03 09:21 -------- d-----w- c:\program files (x86)\Application Verifier
2014-08-03 09:21 . 2014-08-03 09:21 -------- d-----w- c:\program files\Application Verifier (x64)
2014-08-03 09:18 . 2014-08-03 09:19 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 9.0
2014-08-03 09:18 . 2014-08-03 09:18 -------- d-----w- c:\windows\symbols
2014-08-03 08:17 . 2014-08-03 08:17 -------- d-----w- c:\program files\Microsoft SDKs
2014-08-03 08:17 . 2014-08-03 09:18 -------- d-----w- c:\programdata\Microsoft Help
2014-08-03 08:11 . 2014-08-03 08:11 -------- d-----w- c:\windows\SysWow64\Wat
2014-08-03 08:11 . 2014-08-03 08:11 -------- d-----w- c:\windows\system32\Wat
2014-08-03 08:08 . 2011-02-19 06:37 1135104 ----a-w- c:\windows\system32\FntCache.dll
2014-08-03 08:02 . 2014-08-03 08:02 -------- d-----w- c:\program files (x86)\Common Files\Propellerhead Software
2014-08-03 07:57 . 2014-08-03 13:39 -------- d-----w- c:\program files (x86)\Ableton
2014-08-03 07:56 . 2014-08-03 07:56 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-08-03 07:41 . 2014-08-03 07:41 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2014-08-03 07:41 . 2014-08-03 07:41 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2014-08-03 07:40 . 2014-08-03 07:47 -------- d-----w- c:\programdata\DAEMON Tools Lite
2014-08-03 07:31 . 2014-08-03 07:31 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-08-03 07:31 . 2014-08-03 07:31 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-08-03 07:31 . 2014-08-03 07:31 -------- d-----w- c:\windows\SysWow64\Macromed
2014-08-03 07:31 . 2014-08-03 07:31 -------- d-----w- c:\windows\system32\Macromed
2014-08-03 07:13 . 2014-08-03 07:13 -------- d-s---w- c:\windows\system32\CompatTel
2014-08-03 07:12 . 2014-08-03 07:12 -------- d-----w- c:\windows\SysWow64\wbem\en-US
2014-08-03 07:12 . 2014-08-03 07:12 -------- d-----w- c:\windows\system32\wbem\en-US
2014-08-03 04:10 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2014-08-03 04:10 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2014-08-03 02:58 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2014-08-03 02:58 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2014-08-03 02:41 . 2012-07-26 07:49 2560 ----a-w- c:\windows\system32\drivers\nl-NL\wdf01000.sys.mui
2014-08-03 02:41 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2014-08-03 02:41 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2014-08-03 02:41 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2014-08-03 02:17 . 2014-08-03 02:23 -------- d-----w- c:\windows\system32\MRT
2014-08-03 02:00 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2014-08-03 02:00 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2014-08-03 02:00 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2014-08-03 02:00 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2014-08-03 02:00 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2014-08-03 02:00 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2014-08-03 02:00 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2014-08-03 02:00 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2014-08-03 02:00 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2014-08-03 02:00 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2014-08-03 01:59 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-08-03 01:18 . 2012-12-16 14:25 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2014-08-03 01:18 . 2012-12-16 16:52 46080 ----a-w- c:\windows\system32\atmlib.dll
2014-08-03 01:18 . 2009-10-19 14:10 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2014-08-03 01:18 . 2009-10-19 14:46 100864 ----a-w- c:\windows\system32\fontsub.dll
2014-08-03 01:18 . 2012-12-16 14:40 367616 ----a-w- c:\windows\system32\atmfd.dll
2014-08-03 01:18 . 2012-12-16 14:25 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2014-08-03 01:15 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2014-08-03 01:15 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2014-08-03 01:15 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2014-08-03 01:15 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2014-08-03 01:15 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2014-08-03 01:15 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2014-08-03 01:15 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2014-08-03 01:00 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-08-03 01:00 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
2014-08-03 01:00 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2014-08-03 01:00 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
2014-08-03 01:00 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-08-03 00:35 . 2010-03-04 04:40 184832 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2014-08-03 00:35 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2014-08-03 00:14 . 2011-11-17 07:12 395776 ----a-w- c:\windows\system32\webio.dll
2014-08-03 00:14 . 2011-11-17 05:39 314368 ----a-w- c:\windows\SysWow64\webio.dll
2014-08-03 00:14 . 2010-03-05 07:52 84992 ----a-w- c:\windows\system32\asycfilt.dll
2014-08-03 00:14 . 2010-03-05 07:42 67584 ----a-w- c:\windows\SysWow64\asycfilt.dll
2014-08-03 00:14 . 2013-02-12 15:37 3138048 ----a-w- c:\windows\system32\mstscax.dll
2014-08-03 00:14 . 2013-02-12 15:13 2691072 ----a-w- c:\windows\SysWow64\mstscax.dll
2014-08-03 00:14 . 2013-02-12 15:07 131072 ----a-w- c:\windows\SysWow64\aaclient.dll
2014-08-03 00:14 . 2013-02-12 15:42 44032 ----a-w- c:\windows\system32\tsgqec.dll
2014-08-03 00:14 . 2013-02-12 15:31 158208 ----a-w- c:\windows\system32\aaclient.dll
2014-08-03 00:14 . 2013-02-12 13:59 36864 ----a-w- c:\windows\SysWow64\tsgqec.dll
2014-08-03 00:11 . 2011-05-04 05:28 2228224 ----a-w- c:\windows\system32\mssrch.dll
2014-08-03 00:10 . 2009-09-03 07:36 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2014-08-03 00:10 . 2009-09-03 07:04 1320960 ----a-w- c:\windows\SysWow64\CertEnroll.dll
2014-08-03 00:10 . 2014-07-01 01:56 516096 ----a-w- c:\windows\system32\aepdu.dll
2014-08-03 00:10 . 2014-07-01 01:50 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-08-03 00:08 . 2012-03-03 06:29 1837568 ----a-w- c:\windows\system32\d3d10warp.dll
2014-08-03 00:08 . 2012-03-03 06:29 902656 ----a-w- c:\windows\system32\d2d1.dll
2014-08-03 00:08 . 2012-03-03 05:40 1170944 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-08-03 00:08 . 2012-03-03 05:40 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-08-03 00:08 . 2012-03-03 06:29 1541120 ----a-w- c:\windows\system32\DWrite.dll
2014-08-03 00:08 . 2012-03-03 06:29 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-08-03 00:08 . 2012-03-03 05:40 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2014-08-03 00:08 . 2012-03-03 05:40 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2014-08-03 00:08 . 2012-03-03 06:29 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2014-08-03 00:08 . 2012-03-03 05:40 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2014-08-03 00:08 . 2012-06-09 05:30 14165504 ----a-w- c:\windows\system32\shell32.dll
2014-08-03 00:07 . 2012-01-04 09:58 509952 ----a-w- c:\windows\system32\ntshrui.dll
2014-08-03 00:07 . 2012-01-04 09:03 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2014-08-03 00:06 . 2012-11-09 05:34 2048 ----a-w- c:\windows\system32\tzres.dll
2014-08-03 00:06 . 2012-11-09 04:49 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-08-02 23:56 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll
2014-08-02 23:55 . 2013-01-04 05:26 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-08-02 23:55 . 2013-01-04 04:43 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2014-08-02 23:55 . 2013-01-04 02:43 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2014-08-02 23:55 . 2013-01-04 05:26 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-08-02 23:55 . 2013-01-04 04:43 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
2014-08-02 23:55 . 2013-01-04 02:48 2048 ----a-w- c:\windows\SysWow64\user.exe
2014-08-02 23:55 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2014-08-02 23:55 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2014-08-02 23:53 . 2010-05-05 07:37 483840 ----a-w- c:\windows\system32\StructuredQuery.dll
2014-08-02 23:52 . 2011-10-26 04:28 1328640 ----a-w- c:\windows\SysWow64\quartz.dll
2014-08-02 23:52 . 2011-10-26 05:22 1572864 ----a-w- c:\windows\system32\quartz.dll
2014-08-02 23:52 . 2011-10-26 05:22 366592 ----a-w- c:\windows\system32\qdvd.dll
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-08-15 6581488]
"Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-11-13 3713032]
"COMODO"="c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 213304]
"CPA"="c:\program files\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 184120]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-08-02 4085896]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
R0 aswRvrt;avast! Revert; [x]
R0 aswVmm;avast! VM Monitor; [x]
R1 A2DDA;A2 Direct Disk Access Support Driver;c:\eek\RUN\a2ddax64.sys;c:\eek\RUN\a2ddax64.sys [x]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys;c:\windows\SYSNATIVE\DRIVERS\cmdguard.sys [x]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
R2 AnviStartupTime;AnviStartupTime;c:\program files (x86)\Anvisoft\StartupBooster\StartupTimeSrv.exe;c:\program files (x86)\Anvisoft\StartupBooster\StartupTimeSrv.exe [x]
R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
R3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys;c:\windows\SYSNATIVE\drivers\gfiark.sys [x]
R3 gfiutil;gfiutil;c:\windows\system32\drivers\gfiutil.sys;c:\windows\SYSNATIVE\drivers\gfiutil.sys [x]
R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswNdisFlt;Avast! Firewall Driver;c:\windows\system32\DRIVERS\aswNdisFlt.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdisFlt.sys [x]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys;c:\windows\SYSNATIVE\DRIVERS\thpdrv.sys [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS;c:\windows\SYSNATIVE\DRIVERS\Thpevm.SYS [x]
S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys;c:\windows\SYSNATIVE\DRIVERS\cmdhlp.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [x]
S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys;c:\windows\SYSNATIVE\DRIVERS\rixdpe64.sys [x]
S3 cleanhlp;cleanhlp;c:\eek\Run\cleanhlp64.sys;c:\eek\Run\cleanhlp64.sys [x]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1k62x64.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 NETw5s64;Intel(R) Wireless WiFi Link adapter stuurprogramma onder Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
--- Andere Services/Drivers In Geheugen ---
*NewlyCreated* - MBAMSWISSARMY
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-08-02 21:24 1104200 ----a-w- c:\program files (x86)\Google\Chrome\Application\36.0.1985.125\Installer\chrmstp.exe
Inhoud van de 'Gedeelde Taken' map
2014-08-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-03 07:31]
2014-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-08-02 21:22]
2014-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-08-02 21:22]
2014-08-03 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 9349cd4c-b26b-41ed-9000-fa8da98a969c.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2013-05-23 20:21]
2014-08-03 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task ebbecc67-3cc7-4b75-8b91-b3b886c0e521.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2013-05-23 20:21]
2014-08-02 c:\windows\Tasks\Wise Care 365.job
- c:\program files (x86)\Wise\Wise Care 365\WiseTray.exe [2014-08-02 12:38]
2014-08-03 c:\windows\Tasks\Wise Turbo Checker.job
- c:\program files (x86)\Wise\Wise Care 365\WiseTurbo.exe [2014-08-02 13:25]
--------- X64 Entries -----------
2014-08-02 21:19 634872 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-12-20 9454920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-10 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-10 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-10 415256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
------- Bijkomende Scan -------
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer =
- - - - ORPHANS VERWIJDERD - - - -
Notify-SDWinLogon - SDWinLogon.dll
--------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
@Denied: (Full) (Everyone)
Voltooingstijd: 2014-08-03 21:56:53
ComboFix-quarantined-files.txt 2014-08-03 19:56
ComboFix2.txt 2014-08-03 15:04
ComboFix3.txt 2014-08-02 19:20
Pre-Run: 131.097.907.200 bytes beschikbaar
Post-Run: 130.902.110.208 bytes beschikbaar
- - End Of File - - B466C8EB2060B769F0E9578C743B4357


Rkill 2.6.6 by Lawrence Abrams (Grinler)
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:

Program started at: 08/03/2014 09:10:53 PM in x64 mode. (Safe Mode)
Windows Version: Windows 7 Ultimate

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\Users\Akron\Desktop\MBAMPortable\MBAMPortable.exe (PID: 1384)

1 proccess terminated!

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* Windows Firewall Disabled

"EnableFirewall" = dword:00000000

Checking Windows Service Integrity:

* COM+ Event System (EventSystem) is not Running.
Startup Type set to: Automatic

* Security Center (wscsvc) is not Running.
Startup Type set to: Automatic (Delayed Start)

* Windows Update (wuauserv) is not Running.
Startup Type set to: Automatic (Delayed Start)

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found: localhost

Program finished at: 08/03/2014 09:15:01 PM
Execution time: 0 hours(s), 4 minute(s), and 7 seconds(s)


Results of screen317's Security Check version 0.99.86
Windows 7 x64 (UAC is enabled)
Out of date service pack!! (http://windows.microsoft.com/en-US/windows7/install-windows-7-service-pack-1)
Internet Explorer 11
[u]``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus
Antivirus out of date!
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Adobe Flash Player
Google Chrome 36.0.1985.125
````````Process Check: objlist.exe by Laurent````````
Spybot Teatimer.exe is disabled!
Comodo Firewall cmdagent.exe
Comodo Firewall cfp.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast afwServ.exe
AVAST Software Avast avastui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 10%
````````````````````End of Log``````````````````````

Thnx for assistance! Greatly appreciated!:bigthumb:

2014-08-05, 03:00
forgot to tell

Yes I did some system restore operations and other stuff like combofix before I ended up here and read I wasn't supposed to :confused:

2014-08-05, 03:55
Hi Akron,

Thanks for all the logs, let's continue.

Multiple Firewall Programs Installed

I notice that you have multiple Firewall programs installed at the same time. Having more than one antivirus program running at the same time can seriously degrade the performance of your system.

avast! Internet Security
COMODO Internet Security

Please uninstall either one (1) (which ever you prefer) using either the provided uninstall feature that is part of the antivirus program or through Add/Remove Programs (for Vista and Win 7 users to go to Programs and Features in the Control Panel). As a rule of thumb one should run one firewall, one antivirus program in memory, and one anti-spyware utility in memory. It's fine to have other security tools available on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.

avast! Internet Security
COMODO Internet Security


You also don't have the latest Service Pack (SP1) for Windows 7.

The easiest way to keep Windows updated is to turn on automatic updates.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Windows Update

Open Windows Update by clicking the Start button http://i1269.photobucket.com/albums/jj590/OCD-WTT/start.jpg (http://s1269.photobucket.com/user/OCD-WTT/media/start.jpg.html). In the search box, type Update, and then, in the list of results, click Windows Update.
In the left pane, click Check for updates, and then wait while Windows looks for the latest updates for your computer.
If you see a message telling you that important updates are available, or telling you to review important updates, click the message to view and select the important updates to install.
In the list, click the important updates for more information. Check the box for Windows 7 Service Pack 1, select the check boxes for any other updates that you want to install, and then click OK.
Click Install updates.
Read and accept the license terms, and then click Finish if the update requires it. http://i1269.photobucket.com/albums/jj590/OCD-WTT/adminshield.jpg (http://s1269.photobucket.com/user/OCD-WTT/media/adminshield.jpg.html) Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.


Or go here >> http://windows.microsoft.com/en-us/windows/service-packs-download#sptabs=win7 and download the file directly and follow the directions to install it.


Your computer is also 10% fragmented, please run the disk defrag tool to improve this condition.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Disk Defragmenter in Windows 7

Click on the Start button, and type in "disk defragmenter" in the search window at the bottom.
"Disk Defragmenter" should appear at the top of the search results, click to open.

(a window similar to the one below will open)


Locate your primary hard drive (usually C:), and select it.


Next select the Defragment Disk button. Monitor the progress if you choose.


Close when the defrag process has been completed.

= = = = = = = = = =

You can also Schedule the Disk Defragmenter to run on a predetermined schedule.

From the main Disk Defragmenter window


Select the Configure / Schedule button


Select a date and time that best suits your needs.
Close when finished.


In your next post please provide the following:

Post update on performance when you have completed the above steps.

2014-08-05, 11:42
Ok OCD,I removed Comodo Internet Security (can I still use comodo firewall??) defragmented disc C: (allthough it wants me to run it as an administrator which isn't an option in the start-menu-search window,the rest of windows layout is F*ed up; no menubar or side panel in explorer). Pc startup is still very slow and the updates I don't understand,100% sure it (SP1) got installed yesterday. Watched it doing so long enough at least. Busy installing updates until the SP1 shows up (again) since it isn't installed...

Awaiting further Instructions on this mess...

2014-08-05, 18:09
Ok sevice pack is installed and all other updates as well. Still same symptoms though. Defrag does seem to have completed succesfully.
Also there are these 'new' folders on all my HDD;$RECYCLE.BIN and System Volume Information for example. Just adding info not pushing or impatient or something:)

2014-08-05, 18:12
Hi Akron,

I removed Comodo Internet Security (can I still use comodo firewall??)
According to the information I have your avast! Internet Security has a firewall in it. You should only run one (1) firewall. Using multiple firewalls actually can degrad your protection. So the answer is no, unles yopu choose to chnage back to the Comodo software.

allthough it wants me to run it as an administrator which isn't an option in the start-menu-search window,the rest of windows layout is F*ed up; no menubar or side panel in explorer
You're going to have to explain this clearer. Include a screenshot if possible.

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye2_zpse2245433.png.html) Security Check

Re-run Security Check by screen317.
Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box. A Notepad document should open automatically called checkup.txt; please post the contents of that document.


In your next post please provide the following:


2014-08-05, 19:24
Screenshot I have no clue about, windows search box didn't return anything ? :confused:
Not sure the defrag worked, analysis is stuck at 16% for over 3 hours. The problem with the windows 'explorer window' is just what I described; no left-side 'explorer' panel and mapoptions don't seem to help or mention anything problem-related. Switched back to comodo btw.
Security scan Check seems stuck on "performing System Health Check", suggestions?

2014-08-05, 19:27
Oh and on the admin front; how do you run disk defrag as an dmin? Option isn't presented...

Appreciate the effort, NOOB here :bigthumb:

2014-08-05, 20:44
Finally screen317 finished here's the log

Results of screen317's Security Check version 0.99.86
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
COMODO Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Adobe Flash Player
Google Chrome 36.0.1985.125
````````Process Check: objlist.exe by Laurent````````
Spybot Teatimer.exe is disabled!
Comodo Firewall cmdagent.exe
Comodo Firewall cfp.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 3%
````````````````````End of Log``````````````````````

2014-08-05, 22:41
Hi Akron,

The problem with the windows 'explorer window' is just what I described; no left-side 'explorer' panel and mapoptions don't seem to help or mention anything problem-related

Open Windows Explorer >> Organize >> Layout >> place a check mark beside Navigation pane, then close Explorer

http://i1269.photobucket.com/albums/jj590/OCD-WTT/ExplorerWindowNavigationPane_zpsca4ce213.gif (http://s1269.photobucket.com/user/OCD-WTT/media/ExplorerWindowNavigationPane_zpsca4ce213.gif.html)

Oh and on the admin front; how do you run disk defrag as an dmin?
Does it to ask you to run as Admin? You may need to be logged into the Admin account in order to run the defrag tool.

Your last Security Check scan shows SP1 is installed, :bigthumb: and your hard drive is down to 3% fragmentation which is good. :)

How does the computer seem to be running?

2014-08-05, 22:46
Awesome! Screen layout is back to normal!
Start up is still slow ; 2 min + .
Any idea what the 'new' folders are? Or why the layout got messed up?

Thnx for the assistance again! More tests I should run?

2014-08-05, 22:54
There is only my account, which Windows says is an admin account...and yes disk defragger told me to run it as an admin.

2014-08-05, 23:07
Hi Akron,

Any idea what the 'new' folders are?
Where are the "new folders" being generated? (location)

Or why the layout got messed up?
Not really. Could be something as simple as clicking at the wrong moment while you were adjusting some setting or navigating within a menu.

Thnx for the assistance again! More tests I should run?
You're welcome. We still have a little more to do.

2014-08-05, 23:17
The 'new' folders are located on every single HDD root tree. $RECYCLE.BIN and a hidden folder 'system volume information'.

2014-08-06, 00:09
Hi Akron,

I will try and help you the best I can, but please keep in mind that my primary focus is on malware. You may have other issues going on that I might be out of my scope of knowledge. You also have an unusual number of hard drives and I'm not 100% sure how having so many drives effects the performance of your machine, along with how they interact with each other and the OS.

The 'new' folders are located on every single HDD root tree. $RECYCLE.BIN and a hidden folder 'system volume information'.
Is anything contained in the folders?

You may also have a setting for Files & Folders to show protected operating system files.

You can give this a try . . .

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye2_zpse2245433.png.html) Hide protected operating system files

To show hidden files, just click on the Organize button in any folder, and then select “Folder and Search Options” from the menu.
Click the View tab, and then locate “Show hidden files and folders” in the list.


Place a check mark in the box next to "Hide protected operating system files"
Click Apply, then OK.


Let me know if that resolved any of your issues. If not we will need to table that issue and move on to finishing the malware removal process.

2014-08-06, 00:25
$RECYCLE.BIN folder contains folders like S-1-5-21-2173814516-2348489751-3330685890-1000 and similar folders that aren't accessible.
The hide hidden folders fix solved the 'system volume information' mystery folder.
Awaiting further instructions oh wise one :confused:!

2014-08-06, 00:49
Concerning the amount of HDD's: never had a problem with them (2 HDD - 6 partitions). Is a RAID setup advisable or what would you suggest?

2014-08-06, 00:56
Gotta go to bed; I'll be back tomorrow. Thanks for the assistance so far! This service is AWESOME!!!


2014-08-06, 03:04
Hi Akron,

$RECYCLE.BIN folder contains folders like S-1-5-21-2173814516-2348489751-3330685890-1000 and similar folders that aren't accessible.
If you would like more information about this, please visit this link: http://www.pcguide.com/vb/showthread.php?71189-What-are-the-Vista-Recycle-bin-subfolders-quot-S-1-5-21-1000-1001-quot

Hopefully it will expalin a little bit of what these are.

Is a RAID setup advisable or what would you suggest?
Sorry, that's out of my scope of knowledge.

Other than the previous questions about the files and folders do you seem to have any other symptoms of malicious activity on your computer?

2014-08-06, 13:28
Seems ok until just now when trying to post my reply, going to assume I did something wrong here.

System is running smoother now so thanks a lot OCD for the help!

One thing though Spybot S&D keeps finding 2 files it can't delete after 18 retries. Suggestions?

In case this thread gets marked solved and symptoms reappear, just add to this thread or start a new one?

Awesome job OCD Thank you very much for the assistance!

2014-08-06, 16:29
Hi Akron,

Seems ok until just now when trying to post my reply, going to assume I did something wrong here.
What happened?

One thing though Spybot S&D keeps finding 2 files it can't delete after 18 retries. Suggestions?
What is the path to the files it can't delete?

2014-08-07, 00:01
Crap, left the system alone for a whole day and it's acting up again. 2 threats of level 5 and 3 of threat level 1 all it has done is a bit of youtube and a bunch of scans by avast and Eset online scanner.... Waiting for S&D to finish to show the locations of the infections.
Should finnish in 1 hour. Thinngs I can do in the meanwhile? Other scan from the tools downloaded yesterday?

Back to square one...:devil:

2014-08-07, 00:17
Search results from Spybot - Search & Destroy

7/08/2014 0:13:09
Scan took 00:24:16.
5 items found.

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

History: [SBI $49804B54] Browser: History (1) (Browser: History, nothing done)

Cookie: [SBI $49804B54] Browser: Cookie (4) (Browser: Cookie, nothing done)

--- Spybot - Search & Destroy version: DLL (build: 20121113) ---

2012-11-13 blindman.exe (
2012-11-13 explorer.exe (
2012-11-13 SDBootCD.exe (
2012-11-13 SDCleaner.exe (
2012-11-13 SDDelFile.exe (
2012-11-13 SDFiles.exe (
2012-11-13 SDFileScanHelper.exe (
2012-11-13 SDFSSvc.exe (
2012-11-13 SDImmunize.exe (
2012-11-13 SDLogReport.exe (
2012-11-13 SDPESetup.exe (
2012-11-13 SDPEStart.exe (
2012-11-13 SDPhoneScan.exe (
2012-11-13 SDPRE.exe (
2012-11-13 SDPrepPos.exe (
2012-11-13 SDQuarantine.exe (
2012-11-13 SDRootAlyzer.exe (
2012-11-13 SDSBIEdit.exe (
2012-11-13 SDScan.exe (
2012-11-13 SDScript.exe (
2012-11-13 SDSettings.exe (
2012-11-13 SDShred.exe (
2012-11-13 SDSysRepair.exe (
2012-11-13 SDTools.exe (
2012-11-13 SDTray.exe (
2012-11-13 SDUpdate.exe (
2012-11-13 SDUpdSvc.exe (
2012-11-13 SDWelcome.exe (
2012-11-13 SDWSCSvc.exe (
2014-05-20 spybotsd2-install-bdcore-update.exe (
2014-07-31 spybotsd2-translation-esx.exe
2014-08-03 unins000.exe (51.1052.0.0)
1999-12-02 xcacls.exe
2012-08-23 borlndmm.dll (10.0.2288.42451)
2012-09-05 DelZip190.dll (
2012-09-10 libeay32.dll (
2012-09-10 libssl32.dll (
2012-11-13 SDAdvancedCheckLibrary.dll (
2012-11-13 SDECon32.dll (
2012-11-13 SDECon64.dll (
2012-11-13 SDEvents.dll (
2012-11-13 SDFileScanLibrary.dll (
2012-11-13 SDHelper.dll (
2012-11-13 SDImmunizeLibrary.dll (
2012-11-13 SDLists.dll (
2012-11-13 SDResources.dll (
2012-11-13 SDScanLibrary.dll (
2012-11-13 SDTasks.dll (
2012-11-13 SDWinLogon.dll (
2012-08-23 sqlite3.dll
2012-09-10 ssleay32.dll (
2012-11-13 Tools.dll (
2012-11-13 UninsSrv.dll (
2014-03-05 Includes\Adware-000.sbi (*)
2014-01-08 Includes\Adware-001.sbi (*)
2014-07-30 Includes\Adware-C.sbi (*)
2014-01-13 Includes\Adware.sbi (*)
2014-01-13 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2014-01-08 Includes\Dialer-000.sbi (*)
2014-01-08 Includes\Dialer-001.sbi (*)
2014-01-08 Includes\Dialer-C.sbi (*)
2014-01-13 Includes\Dialer.sbi (*)
2014-01-13 Includes\DialerC.sbi (*)
2014-01-09 Includes\Fraud-000.sbi (*)
2014-01-09 Includes\Fraud-001.sbi (*)
2014-03-31 Includes\Fraud-002.sbi (*)
2014-01-09 Includes\Fraud-003.sbi (*)
2012-11-14 Includes\HeavyDuty.sbi (*)
2014-01-08 Includes\Hijackers-000.sbi (*)
2014-01-08 Includes\Hijackers-001.sbi (*)
2014-01-08 Includes\Hijackers-C.sbi (*)
2014-01-13 Includes\Hijackers.sbi (*)
2014-01-13 Includes\HijackersC.sbi (*)
2014-01-08 Includes\iPhone-000.sbi (*)
2014-01-08 Includes\iPhone.sbi (*)
2014-01-08 Includes\Keyloggers-000.sbi (*)
2014-03-19 Includes\Keyloggers-C.sbi (*)
2014-01-13 Includes\Keyloggers.sbi (*)
2014-01-13 Includes\KeyloggersC.sbi (*)
2014-01-09 Includes\Malware-001.sbi (*)
2014-01-09 Includes\Malware-002.sbi (*)
2014-02-05 Includes\Malware-003.sbi (*)
2014-01-28 Includes\Malware-004.sbi (*)
2014-04-15 Includes\Malware-005.sbi (*)
2014-02-26 Includes\Malware-006.sbi (*)
2014-01-09 Includes\Malware-007.sbi (*)
2014-07-30 Includes\Malware-C.sbi (*)
2014-01-13 Includes\Malware.sbi (*)
2013-12-23 Includes\MalwareC.sbi (*)
2014-01-15 Includes\PUPS-000.sbi (*)
2014-01-15 Includes\PUPS-001.sbi (*)
2014-01-15 Includes\PUPS-002.sbi (*)
2014-07-30 Includes\PUPS-C.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2014-01-07 Includes\PUPSC.sbi (*)
2014-01-08 Includes\Security-000.sbi (*)
2014-01-08 Includes\Security-C.sbi (*)
2014-01-21 Includes\Security.sbi (*)
2014-01-21 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2014-01-08 Includes\Spyware-000.sbi (*)
2014-01-08 Includes\Spyware-001.sbi (*)
2014-01-08 Includes\Spyware-C.sbi (*)
2014-01-21 Includes\Spyware.sbi (*)
2014-01-21 Includes\SpywareC.sbi (*)
2011-06-07 Includes\Tracks.sbi (*)
2012-11-19 Includes\Tracks.uti (*)
2014-01-15 Includes\Trojans-000.sbi (*)
2014-01-15 Includes\Trojans-001.sbi (*)
2014-01-15 Includes\Trojans-002.sbi (*)
2014-01-15 Includes\Trojans-003.sbi (*)
2014-01-15 Includes\Trojans-004.sbi (*)
2014-03-19 Includes\Trojans-005.sbi (*)
2014-07-09 Includes\Trojans-006.sbi (*)
2014-01-15 Includes\Trojans-007.sbi (*)
2014-07-09 Includes\Trojans-008.sbi (*)
2014-07-09 Includes\Trojans-009.sbi (*)
2014-07-30 Includes\Trojans-C.sbi (*)
2014-01-15 Includes\Trojans-OG-000.sbi (*)
2014-01-15 Includes\Trojans-TD-000.sbi (*)
2014-01-15 Includes\Trojans-VM-000.sbi (*)
2014-01-15 Includes\Trojans-VM-001.sbi (*)
2014-01-15 Includes\Trojans-VM-002.sbi (*)
2014-01-15 Includes\Trojans-VM-003.sbi (*)
2014-01-15 Includes\Trojans-VM-004.sbi (*)
2014-01-15 Includes\Trojans-VM-005.sbi (*)
2014-01-15 Includes\Trojans-VM-006.sbi (*)
2014-01-15 Includes\Trojans-VM-007.sbi (*)
2014-01-15 Includes\Trojans-VM-008.sbi (*)
2014-01-15 Includes\Trojans-VM-009.sbi (*)
2014-01-15 Includes\Trojans-VM-010.sbi (*)
2014-01-15 Includes\Trojans-VM-011.sbi (*)
2014-01-15 Includes\Trojans-VM-012.sbi (*)
2014-01-15 Includes\Trojans-VM-013.sbi (*)
2014-01-15 Includes\Trojans-VM-014.sbi (*)
2014-01-15 Includes\Trojans-VM-015.sbi (*)
2014-01-15 Includes\Trojans-VM-016.sbi (*)
2014-01-15 Includes\Trojans-VM-017.sbi (*)
2014-01-15 Includes\Trojans-VM-018.sbi (*)
2014-01-15 Includes\Trojans-VM-019.sbi (*)
2014-01-15 Includes\Trojans-VM-020.sbi (*)
2014-01-15 Includes\Trojans-VM-021.sbi (*)
2014-01-15 Includes\Trojans-VM-022.sbi (*)
2014-01-15 Includes\Trojans-VM-023.sbi (*)
2014-01-15 Includes\Trojans-VM-024.sbi (*)
2014-01-15 Includes\Trojans-ZB-000.sbi (*)
2014-01-15 Includes\Trojans-ZL-000.sbi (*)
2014-01-09 Includes\Trojans.sbi (*)
2014-01-16 Includes\TrojansC-01.sbi (*)
2014-01-16 Includes\TrojansC-02.sbi (*)
2014-01-16 Includes\TrojansC-03.sbi (*)
2014-01-16 Includes\TrojansC-04.sbi (*)
2014-01-16 Includes\TrojansC-05.sbi (*)
2014-01-09 Includes\TrojansC.sbi (*)

2014-08-07, 01:17
Ok 3 scans further everything seems back in order :confused: ... including the 2 files it couldn't remove...
I hate being a boob at this ....:lip: and hating Windows again....:sick: or that's unfounded?

2014-08-07, 05:02
Hi Akron,

I don't know which files you are talking about you didn't make any distinction between them. Which files can SpyBot not remove?

These show that for all of them nothing was done.

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

History: [SBI $49804B54] Browser: History (1) (Browser: History, nothing done)

Cookie: [SBI $49804B54] Browser: Cookie (4) (Browser: Cookie, nothing done)

2014-08-07, 11:51
Hi Akron,

I don't know which files you are talking about you didn't make any distinction between them. Which files can SpyBot not remove?

These show that for all of them nothing was done.

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

History: [SBI $49804B54] Browser: History (1) (Browser: History, nothing done)

Cookie: [SBI $49804B54] Browser: Cookie (4) (Browser: Cookie, nothing done)

Pfff what a bunch of ....
Ok?? Just going to send logs from now on seeing I don't get what S&D's results mean. Still want to get rid of this though. So what is next OCD?

2014-08-07, 16:23
The log:

Search results from Spybot - Search & Destroy

7/08/2014 15:49:41
Scan took 00:52:43.
3 items found.

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

Cookie: [SBI $49804B54] Browser: Cookie (38) (Browser: Cookie, nothing done)

--- Spybot - Search & Destroy version: DLL (build: 20121113) ---

2012-11-13 blindman.exe (
2012-11-13 explorer.exe (
2012-11-13 SDBootCD.exe (
2012-11-13 SDCleaner.exe (
2012-11-13 SDDelFile.exe (
2012-11-13 SDFiles.exe (
2012-11-13 SDFileScanHelper.exe (
2012-11-13 SDFSSvc.exe (
2012-11-13 SDImmunize.exe (
2012-11-13 SDLogReport.exe (
2012-11-13 SDPESetup.exe (
2012-11-13 SDPEStart.exe (
2012-11-13 SDPhoneScan.exe (
2012-11-13 SDPRE.exe (
2012-11-13 SDPrepPos.exe (
2012-11-13 SDQuarantine.exe (
2012-11-13 SDRootAlyzer.exe (
2012-11-13 SDSBIEdit.exe (
2012-11-13 SDScan.exe (
2012-11-13 SDScript.exe (
2012-11-13 SDSettings.exe (
2012-11-13 SDShred.exe (
2012-11-13 SDSysRepair.exe (
2012-11-13 SDTools.exe (
2012-11-13 SDTray.exe (
2012-11-13 SDUpdate.exe (
2012-11-13 SDUpdSvc.exe (
2012-11-13 SDWelcome.exe (
2012-11-13 SDWSCSvc.exe (
2014-05-20 spybotsd2-install-bdcore-update.exe (
2014-07-31 spybotsd2-translation-esx.exe
2014-08-03 unins000.exe (51.1052.0.0)
1999-12-02 xcacls.exe
2012-08-23 borlndmm.dll (10.0.2288.42451)
2012-09-05 DelZip190.dll (
2012-09-10 libeay32.dll (
2012-09-10 libssl32.dll (
2012-11-13 SDAdvancedCheckLibrary.dll (
2012-11-13 SDECon32.dll (
2012-11-13 SDECon64.dll (
2012-11-13 SDEvents.dll (
2012-11-13 SDFileScanLibrary.dll (
2012-11-13 SDHelper.dll (
2012-11-13 SDImmunizeLibrary.dll (
2012-11-13 SDLists.dll (
2012-11-13 SDResources.dll (
2012-11-13 SDScanLibrary.dll (
2012-11-13 SDTasks.dll (
2012-11-13 SDWinLogon.dll (
2012-08-23 sqlite3.dll
2012-09-10 ssleay32.dll (
2012-11-13 Tools.dll (
2012-11-13 UninsSrv.dll (
2014-03-05 Includes\Adware-000.sbi (*)
2014-01-08 Includes\Adware-001.sbi (*)
2014-07-30 Includes\Adware-C.sbi (*)
2014-01-13 Includes\Adware.sbi (*)
2014-01-13 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2014-01-08 Includes\Dialer-000.sbi (*)
2014-01-08 Includes\Dialer-001.sbi (*)
2014-01-08 Includes\Dialer-C.sbi (*)
2014-01-13 Includes\Dialer.sbi (*)
2014-01-13 Includes\DialerC.sbi (*)
2014-01-09 Includes\Fraud-000.sbi (*)
2014-01-09 Includes\Fraud-001.sbi (*)
2014-03-31 Includes\Fraud-002.sbi (*)
2014-01-09 Includes\Fraud-003.sbi (*)
2012-11-14 Includes\HeavyDuty.sbi (*)
2014-01-08 Includes\Hijackers-000.sbi (*)
2014-01-08 Includes\Hijackers-001.sbi (*)
2014-01-08 Includes\Hijackers-C.sbi (*)
2014-01-13 Includes\Hijackers.sbi (*)
2014-01-13 Includes\HijackersC.sbi (*)
2014-01-08 Includes\iPhone-000.sbi (*)
2014-01-08 Includes\iPhone.sbi (*)
2014-01-08 Includes\Keyloggers-000.sbi (*)
2014-03-19 Includes\Keyloggers-C.sbi (*)
2014-01-13 Includes\Keyloggers.sbi (*)
2014-01-13 Includes\KeyloggersC.sbi (*)
2014-01-09 Includes\Malware-001.sbi (*)
2014-01-09 Includes\Malware-002.sbi (*)
2014-02-05 Includes\Malware-003.sbi (*)
2014-01-28 Includes\Malware-004.sbi (*)
2014-04-15 Includes\Malware-005.sbi (*)
2014-02-26 Includes\Malware-006.sbi (*)
2014-01-09 Includes\Malware-007.sbi (*)
2014-07-30 Includes\Malware-C.sbi (*)
2014-01-13 Includes\Malware.sbi (*)
2013-12-23 Includes\MalwareC.sbi (*)
2014-01-15 Includes\PUPS-000.sbi (*)
2014-01-15 Includes\PUPS-001.sbi (*)
2014-01-15 Includes\PUPS-002.sbi (*)
2014-07-30 Includes\PUPS-C.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2014-01-07 Includes\PUPSC.sbi (*)
2014-01-08 Includes\Security-000.sbi (*)
2014-01-08 Includes\Security-C.sbi (*)
2014-01-21 Includes\Security.sbi (*)
2014-01-21 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2014-01-08 Includes\Spyware-000.sbi (*)
2014-01-08 Includes\Spyware-001.sbi (*)
2014-01-08 Includes\Spyware-C.sbi (*)
2014-01-21 Includes\Spyware.sbi (*)
2014-01-21 Includes\SpywareC.sbi (*)
2011-06-07 Includes\Tracks.sbi (*)
2012-11-19 Includes\Tracks.uti (*)
2014-01-15 Includes\Trojans-000.sbi (*)
2014-01-15 Includes\Trojans-001.sbi (*)
2014-01-15 Includes\Trojans-002.sbi (*)
2014-01-15 Includes\Trojans-003.sbi (*)
2014-01-15 Includes\Trojans-004.sbi (*)
2014-03-19 Includes\Trojans-005.sbi (*)
2014-07-09 Includes\Trojans-006.sbi (*)
2014-01-15 Includes\Trojans-007.sbi (*)
2014-07-09 Includes\Trojans-008.sbi (*)
2014-07-09 Includes\Trojans-009.sbi (*)
2014-07-30 Includes\Trojans-C.sbi (*)
2014-01-15 Includes\Trojans-OG-000.sbi (*)
2014-01-15 Includes\Trojans-TD-000.sbi (*)
2014-01-15 Includes\Trojans-VM-000.sbi (*)
2014-01-15 Includes\Trojans-VM-001.sbi (*)
2014-01-15 Includes\Trojans-VM-002.sbi (*)
2014-01-15 Includes\Trojans-VM-003.sbi (*)
2014-01-15 Includes\Trojans-VM-004.sbi (*)
2014-01-15 Includes\Trojans-VM-005.sbi (*)
2014-01-15 Includes\Trojans-VM-006.sbi (*)
2014-01-15 Includes\Trojans-VM-007.sbi (*)
2014-01-15 Includes\Trojans-VM-008.sbi (*)
2014-01-15 Includes\Trojans-VM-009.sbi (*)
2014-01-15 Includes\Trojans-VM-010.sbi (*)
2014-01-15 Includes\Trojans-VM-011.sbi (*)
2014-01-15 Includes\Trojans-VM-012.sbi (*)
2014-01-15 Includes\Trojans-VM-013.sbi (*)
2014-01-15 Includes\Trojans-VM-014.sbi (*)
2014-01-15 Includes\Trojans-VM-015.sbi (*)
2014-01-15 Includes\Trojans-VM-016.sbi (*)
2014-01-15 Includes\Trojans-VM-017.sbi (*)
2014-01-15 Includes\Trojans-VM-018.sbi (*)
2014-01-15 Includes\Trojans-VM-019.sbi (*)
2014-01-15 Includes\Trojans-VM-020.sbi (*)
2014-01-15 Includes\Trojans-VM-021.sbi (*)
2014-01-15 Includes\Trojans-VM-022.sbi (*)
2014-01-15 Includes\Trojans-VM-023.sbi (*)
2014-01-15 Includes\Trojans-VM-024.sbi (*)
2014-01-15 Includes\Trojans-ZB-000.sbi (*)
2014-01-15 Includes\Trojans-ZL-000.sbi (*)
2014-01-09 Includes\Trojans.sbi (*)
2014-01-16 Includes\TrojansC-01.sbi (*)
2014-01-16 Includes\TrojansC-02.sbi (*)
2014-01-16 Includes\TrojansC-03.sbi (*)
2014-01-16 Includes\TrojansC-04.sbi (*)
2014-01-16 Includes\TrojansC-05.sbi (*)
2014-01-09 Includes\TrojansC.sbi (*)

So we're back to 3 files that won't delete through spybot.:confused:

The system is real slow now, displaying desktop or opening folders/programs is a struggle for the laptop:spider:
What is causing this behavior and how to prevent it?! Can't one manually prevent the register from being changed? (If that has anything to do with it...).
When you ask where are the files located isn't that in the scan log and if not where can i find that info after the scan to post here?

Again massive thanks for all the help and the patience.:rolleyes:

2014-08-07, 16:29
The log:

Search results from Spybot - Search & Destroy

7/08/2014 15:49:41
Scan took 00:52:43.
3 items found.

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

Cookie: [SBI $49804B54] Browser: Cookie (38) (Browser: Cookie, nothing done)

--- Spybot - Search & Destroy version: DLL (build: 20121113) ---

2012-11-13 blindman.exe (
2012-11-13 explorer.exe (
2012-11-13 SDBootCD.exe (
2012-11-13 SDCleaner.exe (
2012-11-13 SDDelFile.exe (
2012-11-13 SDFiles.exe (
2012-11-13 SDFileScanHelper.exe (
2012-11-13 SDFSSvc.exe (
2012-11-13 SDImmunize.exe (
2012-11-13 SDLogReport.exe (
2012-11-13 SDPESetup.exe (
2012-11-13 SDPEStart.exe (
2012-11-13 SDPhoneScan.exe (
2012-11-13 SDPRE.exe (
2012-11-13 SDPrepPos.exe (
2012-11-13 SDQuarantine.exe (
2012-11-13 SDRootAlyzer.exe (
2012-11-13 SDSBIEdit.exe (
2012-11-13 SDScan.exe (
2012-11-13 SDScript.exe (
2012-11-13 SDSettings.exe (
2012-11-13 SDShred.exe (
2012-11-13 SDSysRepair.exe (
2012-11-13 SDTools.exe (
2012-11-13 SDTray.exe (
2012-11-13 SDUpdate.exe (
2012-11-13 SDUpdSvc.exe (
2012-11-13 SDWelcome.exe (
2012-11-13 SDWSCSvc.exe (
2014-05-20 spybotsd2-install-bdcore-update.exe (
2014-07-31 spybotsd2-translation-esx.exe
2014-08-03 unins000.exe (51.1052.0.0)
1999-12-02 xcacls.exe
2012-08-23 borlndmm.dll (10.0.2288.42451)
2012-09-05 DelZip190.dll (
2012-09-10 libeay32.dll (
2012-09-10 libssl32.dll (
2012-11-13 SDAdvancedCheckLibrary.dll (
2012-11-13 SDECon32.dll (
2012-11-13 SDECon64.dll (
2012-11-13 SDEvents.dll (
2012-11-13 SDFileScanLibrary.dll (
2012-11-13 SDHelper.dll (
2012-11-13 SDImmunizeLibrary.dll (
2012-11-13 SDLists.dll (
2012-11-13 SDResources.dll (
2012-11-13 SDScanLibrary.dll (
2012-11-13 SDTasks.dll (
2012-11-13 SDWinLogon.dll (
2012-08-23 sqlite3.dll
2012-09-10 ssleay32.dll (
2012-11-13 Tools.dll (
2012-11-13 UninsSrv.dll (
2014-03-05 Includes\Adware-000.sbi (*)
2014-01-08 Includes\Adware-001.sbi (*)
2014-07-30 Includes\Adware-C.sbi (*)
2014-01-13 Includes\Adware.sbi (*)
2014-01-13 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2014-01-08 Includes\Dialer-000.sbi (*)
2014-01-08 Includes\Dialer-001.sbi (*)
2014-01-08 Includes\Dialer-C.sbi (*)
2014-01-13 Includes\Dialer.sbi (*)
2014-01-13 Includes\DialerC.sbi (*)
2014-01-09 Includes\Fraud-000.sbi (*)
2014-01-09 Includes\Fraud-001.sbi (*)
2014-03-31 Includes\Fraud-002.sbi (*)
2014-01-09 Includes\Fraud-003.sbi (*)
2012-11-14 Includes\HeavyDuty.sbi (*)
2014-01-08 Includes\Hijackers-000.sbi (*)
2014-01-08 Includes\Hijackers-001.sbi (*)
2014-01-08 Includes\Hijackers-C.sbi (*)
2014-01-13 Includes\Hijackers.sbi (*)
2014-01-13 Includes\HijackersC.sbi (*)
2014-01-08 Includes\iPhone-000.sbi (*)
2014-01-08 Includes\iPhone.sbi (*)
2014-01-08 Includes\Keyloggers-000.sbi (*)
2014-03-19 Includes\Keyloggers-C.sbi (*)
2014-01-13 Includes\Keyloggers.sbi (*)
2014-01-13 Includes\KeyloggersC.sbi (*)
2014-01-09 Includes\Malware-001.sbi (*)
2014-01-09 Includes\Malware-002.sbi (*)
2014-02-05 Includes\Malware-003.sbi (*)
2014-01-28 Includes\Malware-004.sbi (*)
2014-04-15 Includes\Malware-005.sbi (*)
2014-02-26 Includes\Malware-006.sbi (*)
2014-01-09 Includes\Malware-007.sbi (*)
2014-07-30 Includes\Malware-C.sbi (*)
2014-01-13 Includes\Malware.sbi (*)
2013-12-23 Includes\MalwareC.sbi (*)
2014-01-15 Includes\PUPS-000.sbi (*)
2014-01-15 Includes\PUPS-001.sbi (*)
2014-01-15 Includes\PUPS-002.sbi (*)
2014-07-30 Includes\PUPS-C.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2014-01-07 Includes\PUPSC.sbi (*)
2014-01-08 Includes\Security-000.sbi (*)
2014-01-08 Includes\Security-C.sbi (*)
2014-01-21 Includes\Security.sbi (*)
2014-01-21 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2014-01-08 Includes\Spyware-000.sbi (*)
2014-01-08 Includes\Spyware-001.sbi (*)
2014-01-08 Includes\Spyware-C.sbi (*)
2014-01-21 Includes\Spyware.sbi (*)
2014-01-21 Includes\SpywareC.sbi (*)
2011-06-07 Includes\Tracks.sbi (*)
2012-11-19 Includes\Tracks.uti (*)
2014-01-15 Includes\Trojans-000.sbi (*)
2014-01-15 Includes\Trojans-001.sbi (*)
2014-01-15 Includes\Trojans-002.sbi (*)
2014-01-15 Includes\Trojans-003.sbi (*)
2014-01-15 Includes\Trojans-004.sbi (*)
2014-03-19 Includes\Trojans-005.sbi (*)
2014-07-09 Includes\Trojans-006.sbi (*)
2014-01-15 Includes\Trojans-007.sbi (*)
2014-07-09 Includes\Trojans-008.sbi (*)
2014-07-09 Includes\Trojans-009.sbi (*)
2014-07-30 Includes\Trojans-C.sbi (*)
2014-01-15 Includes\Trojans-OG-000.sbi (*)
2014-01-15 Includes\Trojans-TD-000.sbi (*)
2014-01-15 Includes\Trojans-VM-000.sbi (*)
2014-01-15 Includes\Trojans-VM-001.sbi (*)
2014-01-15 Includes\Trojans-VM-002.sbi (*)
2014-01-15 Includes\Trojans-VM-003.sbi (*)
2014-01-15 Includes\Trojans-VM-004.sbi (*)
2014-01-15 Includes\Trojans-VM-005.sbi (*)
2014-01-15 Includes\Trojans-VM-006.sbi (*)
2014-01-15 Includes\Trojans-VM-007.sbi (*)
2014-01-15 Includes\Trojans-VM-008.sbi (*)
2014-01-15 Includes\Trojans-VM-009.sbi (*)
2014-01-15 Includes\Trojans-VM-010.sbi (*)
2014-01-15 Includes\Trojans-VM-011.sbi (*)
2014-01-15 Includes\Trojans-VM-012.sbi (*)
2014-01-15 Includes\Trojans-VM-013.sbi (*)
2014-01-15 Includes\Trojans-VM-014.sbi (*)
2014-01-15 Includes\Trojans-VM-015.sbi (*)
2014-01-15 Includes\Trojans-VM-016.sbi (*)
2014-01-15 Includes\Trojans-VM-017.sbi (*)
2014-01-15 Includes\Trojans-VM-018.sbi (*)
2014-01-15 Includes\Trojans-VM-019.sbi (*)
2014-01-15 Includes\Trojans-VM-020.sbi (*)
2014-01-15 Includes\Trojans-VM-021.sbi (*)
2014-01-15 Includes\Trojans-VM-022.sbi (*)
2014-01-15 Includes\Trojans-VM-023.sbi (*)
2014-01-15 Includes\Trojans-VM-024.sbi (*)
2014-01-15 Includes\Trojans-ZB-000.sbi (*)
2014-01-15 Includes\Trojans-ZL-000.sbi (*)
2014-01-09 Includes\Trojans.sbi (*)
2014-01-16 Includes\TrojansC-01.sbi (*)
2014-01-16 Includes\TrojansC-02.sbi (*)
2014-01-16 Includes\TrojansC-03.sbi (*)
2014-01-16 Includes\TrojansC-04.sbi (*)
2014-01-16 Includes\TrojansC-05.sbi (*)
2014-01-09 Includes\TrojansC.sbi (*)

So we're back to 3 files that won't delete through spybot.:confused:

The system is real slow now, displaying desktop or opening folders/programs is a struggle for the laptop:spider:
What is causing this behavior and how to prevent it?! Can't one manually prevent the register from being changed? (If that has anything to do with it...).
When you ask where are the files located isn't that in the scan log and if not where can i find that info after the scan to post here?

Again massive thanks for all the help and the patience.:rolleyes:

.....And waiting for the planet to turn.... ;) (assuming you are in the US seeing the time of response....again not pushing just observing:bigthumb:)

2014-08-07, 16:33
Sorry for the double post.....NOOB:lip:

2014-08-07, 16:39
Hi Akron,

Please wait for a reply before you make a secondary post. When you make multiple replies it requires me to go a read the new post and see if I need to make any updates to my reply, which cause a delay in the process.

Ok?? Just going to send logs from now on seeing I don't get what S&D's results mean. Still want to get rid of this though.
The registry entries you have listed are all simply usage tracks, not malware, so there's really no reason to worry about them unless you're paranoid about your privacy.


"The advanced features in Spybot S&D can remove some of the most important and common tracks on your system."

I would suggest you take some time to learn how the SpyBot program works. What it can and cannot not do, so you will have a greater understanding about the protection software you are using. I do not personally use SpyBot even though I am a volunteer here at their forum.

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done)

Cookie: [SBI $49804B54] Browser: Cookie (38) (Browser: Cookie, nothing done)

As you can see by the entry information that I have highlighted. In the first to 2 entries these are showing that Microsoft's Direct3D was the most recent application used, and it made note of this in the registry so the next time you used that program it could access the data quicker.

The third entry is a browser tracking cookie. This is also normal any time you use your browser.

Can't one manually prevent the register from being changed?
The only way to not have items changed in the registry would be to not use any programs. All programs will make changes to the registry.

Dig a bit into the SpyBot program and see if these entries are even removable in SpyBot. If they are not it would be my assumption that they do not pose any risk to your system.

Post back with your findings, and we'll go from there.

2014-08-07, 17:51
OK? SO my system is clean ?? :spider:

Weird. I'll have to read up on spybot and it's findings cause...well....wtf lol
So the problems (speed,internet) are not spy/malware related then (?). Suggestions on what the next step should be? I'll be doing a lot of internet searching again but since you seem very versed in this matter maybe you know of a decent forum/board/tool that deals with laptop/PC issues/analysis ?

seems the planet skipped a few times :red:

2014-08-07, 18:01
again sorry this should have been with the previous post

Well thing is every time (after reboot) it found these entries and deleted(fixed) them after all (:spider:) they just reappear the next scan, hence my confusion. So I basically wasted everyone's time by not understanding the results and making my own conclusions based on Laptop behavior and scan results unrelated to my problems? AWESOME!
Thanks OCD and sorry, panicking never helps it seems:bigthumb:

2014-08-08, 04:02
Hi Akron,

SO my system is clean
Yes, you system appears to be clean.

So the problems (speed,internet) are not spy/malware related then (?)
No, not likely. Go here (http://www.malwareremoval.com/tutorials/runningslowly.php/) and read up on ways to try and improve the performance of your computer.


http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) TFC

Download TFC (http://oldtimer.geekstogo.com/TFC.exe) to your desktop

Close any open windows.
Double click the TFC icon to run the program

Vista, Windows 7 & 8 Right click and select "Run as Administrator"

TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean

Be advised your computer may run a bit slower after the initial reboot. This is normal.

Post the results

2014-08-08, 14:15
OCD here's what THC generated.

Getting user folders.

Stopping running processes.

Emptying Temp folders.

User: Akron
->Temp folder emptied: 416445 bytes
->Temporary Internet Files folder emptied: 155975 bytes
->Java cache emptied: 66696 bytes
->Google Chrome cache emptied: 819568 bytes
->Flash cache emptied: 2019 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 602488 bytes
%systemroot%\System32 (64bit) .tmp files removed: 821432 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2830400 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 40792 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 56936367 bytes

Emptying RecycleBin. Do not interrupt.

RecycleBin emptied: 75100648 bytes
Process complete!

Total Files Cleaned = 131,00 mb

I'll start using the laptop now as I usually do so I'll know pretty soon how things are running again. Thanks for all the assistance again! You guys are giving humanity an awesome tool and a middle finger to those who try to make everything about money and (bad)'luck'. respect.

2014-08-08, 16:37
Hi Akron,

OK, post back in a few days and let me know how it's running as we still have some cleanup to do.

2014-08-11, 16:48
Hi Akron,

So how is she running? Do you still need help?

2014-08-11, 20:59
Things are running smooth again just my internet (palemoon) consumes loads of memory; error message system has stopped palemoon.exe since it is using too much memory and has shut the program down to avoid system damage or something along those lines.
And wasn't I supposed to finish the previous clean up session as well?
At least it doesn't interfere with my 'normal' programs memory usage anymore. :bigthumb:

2014-08-12, 03:04
Hi Akron,

just my internet (palemoon) consumes loads of memory
You could always choose to switch to a different browser.

Internet Explorer
Google Chrome
Mozilla Firefox

= = = = = = = = = = = = = = = = = = = =

Your log appears to be clean. :bigthumb:
We have a few items to take care of before we get to the All Clean Speech.

= = = = = = = = = = = = = = = = = = = =

http://i1269.photobucket.com/albums/jj590/OCD-WTT/bullseye_zpse9eaf36e.gif (http://s1269.photobucket.com/user/OCD-WTT/media/bullseye_zpse9eaf36e.gif.html) Remove Disinfection Tools

Download Delfix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix)
Tick the following boxes:

Remove disinfection tools
Create registry backup
Purge system restore

http://i1269.photobucket.com/albums/jj590/OCD-WTT/Delfix_zpsbce6c60b.gif (http://s1269.photobucket.com/user/OCD-WTT/media/Delfix_zpsbce6c60b.gif.html)

Click Run
Any other tools and files found can simply be deleted or uninstall via the Control Panel.

= = = = = = = = = = = = = = = = = = = =

With the above items taken care of let's move on to the All Clean part of the process.

The following procedures are recommendations for helping to keep your system running smoothly. If you are currently satisfied with how your system is running some or all of these may not pertain to you. Implement what you need.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:

From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:

NoScript (https://addons.mozilla.org/en-US/firefox/addon/noscript/?src=ss)
AdBlockPlus (https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/)

Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

Free Anti-Virus

Avast Free Antivirus (http://download.cnet.com/Avast-Free-Antivirus/3000-2239_4-10019223.html)
Avira Free Antivirus 2013 (http://download.cnet.com/Avira-Free-Antivirus-2013/3000-2239_4-10322935.html)
PC Tools AntiVirus Free (http://download.cnet.com/PC-Tools-AntiVirus-Free/3000-2239_4-10625067.html)
Ad-Aware Free Antivirus + (http://download.cnet.com/Ad-Aware-Free-Antivirus/3000-8022_4-10045910.html)

Free Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here (http://www.bleepingcomputer.com/tutorials/understanding-and-using-firewalls/).

Online Armor Free (http://download.cnet.com/Online-Armor-Free/3000-10435_4-10426782.html)
Agnitum Outpost Firewall Free (http://download.cnet.com/Agnitum-Outpost-Firewall-Free/3000-10435_4-10913746.html)
Comodo Firewall (http://download.cnet.com/Comodo-Firewall/3000-10435_4-75181464.html)

= = = = = = = = = = = = = = = = = = = =

Be prepared for CryptoLocker:

Cryptolocker Ransomware: What You Need To Know (http://blog.malwarebytes.org/intelligence/2013/10/cryptolocker-ransomware-what-you-need-to-know/#)
CryptoLocker Ransomware Information Guide and FAQ (http://www.bleepingcomputer.com/virus-removal/cryptolocker-ransomware-information)

to help protect your computer in the future I recommend that you get the following free program:

CryptoPrevent (http://www.foolishit.com/vb6-projects/cryptoprevent/) install this program to lock down and prevent crypto-ransomeware

http://i1269.photobucket.com/albums/jj590/OCD-WTT/CryptoPrevent_zps7ddc3ebd.jpg (http://s1269.photobucket.com/user/OCD-WTT/media/CryptoPrevent_zps7ddc3ebd.jpg.html)

= = = = = = = = = = = = = = = = = = = =

COMPUTER SECURITY (http://www.malwareremoval.com/forum/viewtopic.php?p=557960#p557960) - a short guide to staying safer online

= = = = = = = = = = = = = = = = = = = =

WOT (http://www.mywot.com/) Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites - green to go, yellow for caution and red to stop, helping you avoid the dangerous sites. WOT has an addon available for both Firefox and IE.

Green should be good to go
Yellow for caution
Red to stop

= = = = = = = = = = = = = = = = = = = =

P2P may be a great way to get lots of stuffs, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well.

Please read these short reports on the dangers of peer-2-peer programs and file sharing.

FBI Cyber Education Letter (http://www.fbi.gov/cyberinvest/cyberedletter.htm)
USAToday (http://www.usatoday.com/tech/columnist/kimkomando/2006-04-13-file-sharing-woes_x.htm)
infoworld (http://www.infoworld.com/article/07/09/06/Seattle-man-arrested-for-p-to-p-ID-theft_1.html)

= = = = = = = = = = = = = = = = = = = =

Make sure you keep your Windows OS current.

Windows XP:
Microsoft will no longer offer support for Windows XP beginning on April 8, 2014
If you are running Windows XP, please take the time to read the information provided at these links.

Windows XP - The Elephant In The Room (http://www.malwareremoval.com/forum/viewtopic.php?p=630064#p630064)
Windows XP - The end of the road (http://techpageone.dell.com/technology/windows-xp-end-road/?dgc=BA&cid=272099&lid=5049884&acd=12309189674467600#.UxUoP4W9Is3)

Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems.
Window 8 Open Windows Update by swiping in from the right edge of the screen (or, if you're using a mouse, pointing to the lower-right corner of the screen and moving the mouse pointer up), tapping or clicking Settings, tapping or clicking Change PC settings, and then tapping or clicking Update and recovery.

Without these you are leaving the back door open.

= = = = = = = = = = = = = = = = = = = =

Consider a custom hosts file such as MVPS HOSTS (http://www.mvps.org/winhelp2002/hosts.htm). This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002 (http://www.mvps.org/winhelp2002/hosts.htm)
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

= = = = = = = = = = = = = = = = = = = =

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place? (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

2014-08-12, 11:09
O.o.o.o.k??? WTF is this (Delfix just gave a bunch of errors with the ERUNT utility) Second site (Foolish IT) is way too slow for my laptop to navigate (or vice versa)(can't find download link on the page :snorkle:).
I went to palemoon from firefox cause FF was a memory hog. Just like palemoon is now...:fear:


2014-08-12, 15:09
Ok got my system to react again, was totally frozen for quite some time,rebooted and reran the delfix and found the other app on the site, since the internet isn't hogging as much anymore either ..... that's something for very wise people to explain I suppose cause I can't even start to begin to make sense of this whole "crash" scenario.

Oh well ...

So I finished the previous set of instructions. Further steps?
Oh and my second system is still running XP but it's specs won't let me run Win7 on it. Suggestions seeing it runs Microsoft compatible programs I'd love to keep, audio production software. Just get the system offline then?

2014-08-12, 15:22
So I finished the previous set of instructions. Further steps?
Oh and my second system is still running XP but it's specs won't let me run Win7 on it. Suggestions seeing it runs Microsoft compatible programs I'd love to keep, audio production software. Just get the system offline then?

No further steps necessary.

As for your other computer running XP, since MS won't be offering anymore security patches for that OS your best course of action (with the limitations you are working with) is to use it for offline purposes as you surmised

If there are no other questions I think we are done here. I can mark this issue resolved and you can be on your way, just let me know.

2014-08-12, 18:44
I believe you are right then! Weird experience this and none the wiser but I'm helped so I thank you OCD for all the patience and support. I'll keep this thread bookmarked for all the reading material suggested. Case closed indeed my good man. In case symptoms return revive this thread or start a new one?

very much appreciated!

2014-08-12, 19:05
Hi Akron,

Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

If you still require help, please start a new topic and include fresh FRST and aswMBR logs, along with a link to your previous thread.

Please do not add any logs that might have been requested previously, you would be starting fresh.

Applies only to the original poster, anyone else with similar problems please start your own topic.