I was able to run them in normal boot mode. Here are the logs:
Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 02/18/2014 07:22:30 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 02/18/2014 07:22:44 PM
Execution time: 0 hours(s), 0 minute(s), and 14 seconds(s)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2014
Ran by Andy Besing (administrator) on ANDYBESING-PC on 18-02-2014 19:16:27
Running from C:\Users\Andy Besing\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Affinegy, Inc.) C:\Program Files (x86)\TWC\DigiDo\AffinegyService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Check Point Software Technologies) C:\Program Files (x86)\CheckPoint\SSL Network Extender\slimsvc.exe
() C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
() C:\Program Files (x86)\Flip Video\FlipShareServer\FlipShareServer.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
() C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\McciCMService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Affinegy, Inc.) C:\Program Files (x86)\TWC\DigiDo\TrayApp.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Affinegy, Inc.) C:\Program Files (x86)\TWC\DigiDo\DigiDo.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2012-01-17] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6489704 2011-07-16] (Realtek Semiconductor)
HKLM\...\Run: [RtkOSD] - C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe [995840 2010-01-12] (Realtek Semiconductor Corp.)
HKLM\...\Run: [HP Quick Launch] - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [451072 2010-01-18] (Hewlett-Packard Company)
HKLM\...\Run: [IntelliType Pro] - c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1464944 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] - c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2076272 2012-11-02] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] - C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe [600936 2009-06-29] (Symantec Corporation)
HKLM-x32\...\Run: [WirelessAssistant] - C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [500792 2010-05-20] (Hewlett-Packard Company)
HKLM-x32\...\Run: [AppleSyncNotifier] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [47904 2010-10-08] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM-x32\...\Run: [DigiDo] - C:\Program Files (x86)\TWC\DigiDo\TrayApp.exe [1458544 2011-10-17] (Affinegy, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-12-21] (Adobe Systems Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.)
HKLM-x32\...\Run: [] - [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1125724057-2074268439-1374579803-1000\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-06-16] (Hewlett-Packard Company)
HKU\S-1-5-21-1125724057-2074268439-1374579803-1000\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-09-14] (Apple Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {CE4487AD-3505-4DAF-9F03-7FA53F88005A} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
Toolbar: HKLM-x32 - PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll No File
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
Toolbar: HKCU - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
DPF: HKLM-x32 {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
DPF: HKLM-x32 {414FB93D-DEDD-4FEF-AD7F-167992EBDB52}
https://sc1.checkpoint.com/sc/update/CSHELL/extender.cab
DPF: HKLM-x32 {B4CB50E4-0309-4906-86EA-10B6641C8392}
https://vpn.grubb-ellis.com/extender.cab
DPF: HKLM-x32 {BEA7310D-06C4-4339-A784-DC3804819809}
http://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com//activex/ractrl.cab?lmi=1058
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Windows\SysWOW64\npdeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @mozilla.zeniko.ch/PDFlite_Browser_Plugin - C:\Program Files (x86)\PDFlite\npPdfViewer.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32:
yaxmpb@yahoo.com/YahooActiveXPluginBridge;version=1.0.0.1 - C:\Program Files (x86)\Yahoo!\Common\npyaxmpb.dll No File
FF Extension: No Name - C:\Users\Andy Besing\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2014-02-12]
FF Extension: No Name - C:\Users\Andy Besing\AppData\Roaming\Mozilla\Firefox\profiles\extensions\searchplugins [2014-02-12]
FF Extension: Magnet Downloader - C:\Users\Andy Besing\AppData\Roaming\Mozilla\Firefox\profiles\extensions\b026053c-c151-481a-a83e-4fb8d5b1b1a4@cb8a450e-83dd-422a-b921-028b1cbf9831.com.xpi [2013-11-05]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-08-30]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2013-09-09]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-08-30]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\pdf.dll ()
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (PDFlite Browser Plugin) - C:\Program Files (x86)\PDFlite\npPdfViewer.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Users\Andy Besing\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-03]
CHR Extension: (Google Drive) - C:\Users\Andy Besing\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-03]
CHR Extension: (YouTube) - C:\Users\Andy Besing\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-03]
CHR Extension: (Google Search) - C:\Users\Andy Besing\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-03]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Andy Besing\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2014-01-03]
CHR Extension: (Google Wallet) - C:\Users\Andy Besing\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-03]
CHR Extension: (Gmail) - C:\Users\Andy Besing\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-03]
CHR HKLM-x32\...\Chrome\Extension: [dfcfkhnlpcoafpoepljegijlkinbhjgb] - C:\Program Files (x86)\Magnet.TV\magnet-downloader10.crx [2013-11-05]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-12-21]
==================== Services (Whitelisted) =================
R2 AffinegyService; C:\Program Files (x86)\TWC\DigiDo\AffinegyService.exe [580464 2011-10-17] (Affinegy, Inc.)
R2 cpextender; C:\Program Files (x86)\CheckPoint\SSL Network Extender\slimsvc.exe [353672 2009-04-02] (Check Point Software Technologies)
R2 FlipShare Service; C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe [460144 2010-12-15] ()
R2 FlipShareServer; C:\Program Files (x86)\Flip Video\FlipShareServer\FlipShareServer.exe [1085440 2010-12-15] ()
R2 HPWMISVC; C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [20480 2010-01-18] ()
R2 McciCMService64; C:\Program Files\Common Files\Motive\McciCMService.exe [517632 2009-10-22] (Alcatel-Lucent)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-07-06] ()
S3 gusvc; "C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe" [X]
S2 vToolbarUpdater17.1.2; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.2\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
R0 70817744; C:\Windows\System32\DRIVERS\70817744.sys [460888 2013-11-20] (Kaspersky Lab ZAO)
R1 7999121drv; C:\Windows\System32\DRIVERS\7999121drv.sys [556632 2013-11-20] (Kaspersky Lab)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-11-12] (AVG Technologies)
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [47632 2013-04-29] (Panda Security, S.L.)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-22] (Realtek Semiconductor Corp.)
R3 VNA; C:\Windows\System32\DRIVERS\vna.sys [161256 2009-04-02] (Check Point Software Technologies)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-18 19:16 - 2014-02-18 19:16 - 00022362 _____ () C:\Users\Andy Besing\Desktop\FRST.txt
2014-02-18 19:16 - 2014-02-18 19:16 - 00000000 ____D () C:\FRST
2014-02-18 19:07 - 2014-02-18 19:15 - 00002122 _____ () C:\Users\Andy Besing\Desktop\Rkill.txt
2014-02-18 19:06 - 2014-02-18 19:06 - 02153472 _____ (Farbar) C:\Users\Andy Besing\Desktop\FRST64.exe
2014-02-18 19:05 - 2014-02-18 19:05 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Andy Besing\Desktop\rkill.scr
2014-02-18 10:24 - 2014-02-18 10:12 - 00025856 _____ () C:\Users\Andy Besing\Desktop\attach - Copy.txt
2014-02-18 10:20 - 2014-02-18 10:20 - 00001925 _____ () C:\Users\Andy Besing\Desktop\aswMBR.txt
2014-02-18 10:20 - 2014-02-18 10:20 - 00000512 _____ () C:\Users\Andy Besing\Desktop\MBR.dat
2014-02-18 10:14 - 2014-02-18 10:14 - 04745728 _____ (AVAST Software) C:\Users\Andy Besing\Downloads\aswMBR.exe
2014-02-18 10:12 - 2014-02-18 10:12 - 00025856 _____ () C:\Users\Andy Besing\Desktop\attach.txt
2014-02-18 10:12 - 2014-02-18 10:12 - 00018354 _____ () C:\Users\Andy Besing\Desktop\dds.txt
2014-02-18 10:10 - 2014-02-18 10:10 - 00688992 ____R (Swearware) C:\Users\Andy Besing\Downloads\dds (1).scr
2014-02-18 10:10 - 2014-02-18 10:10 - 00688992 _____ (Swearware) C:\Users\Andy Besing\Downloads\dds.scr
2014-02-18 09:20 - 2013-12-21 03:39 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-18 09:20 - 2013-12-21 01:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-18 08:58 - 2014-02-18 08:58 - 00000085 _____ () C:\Windows\wininit.ini
2014-02-18 08:58 - 2014-02-18 08:58 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-02-18 08:54 - 2014-02-18 08:54 - 00023889 _____ () C:\ComboFix.txt
2014-02-17 18:23 - 2014-02-17 18:23 - 00024164 _____ () C:\Users\Andy Besing\Desktop\combofix report.txt
2014-02-17 18:08 - 2014-02-18 08:44 - 00000000 ____D () C:\Windows\erdnt
2014-02-17 18:08 - 2011-06-26 00:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-02-17 18:08 - 2010-11-07 11:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-02-17 18:08 - 2009-04-19 22:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-02-17 18:08 - 2000-08-30 18:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-02-17 18:08 - 2000-08-30 18:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-02-17 18:08 - 2000-08-30 18:00 - 00098816 _____ () C:\Windows\sed.exe
2014-02-17 18:08 - 2000-08-30 18:00 - 00080412 _____ () C:\Windows\grep.exe
2014-02-17 18:08 - 2000-08-30 18:00 - 00068096 _____ () C:\Windows\zip.exe
2014-02-17 18:07 - 2014-02-17 18:07 - 05183112 ____R (Swearware) C:\Users\Andy Besing\Downloads\ComboFix.exe
2014-02-17 18:06 - 2014-02-17 18:06 - 00543016 _____ (Fusion Install ) C:\Users\Andy Besing\Downloads\Setup.exe
2014-02-17 18:05 - 2014-02-17 18:06 - 00000000 ____D () C:\Users\Andy Besing\AppData\Roaming\GetRightToGo
2014-02-17 18:05 - 2014-02-17 18:05 - 00610798 _____ (Max Secure Software) C:\Users\Andy Besing\Desktop\MaxSDDMnew.exe
2014-02-17 18:05 - 2014-02-17 18:05 - 00368256 _____ (RegNow.com) C:\Users\Andy Besing\Downloads\Download_MaxSDDMnew.exe
2014-02-17 18:02 - 2014-02-17 18:02 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Andy Besing\Downloads\tdsskiller (1).exe
2014-02-17 18:02 - 2014-02-17 18:02 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Andy Besing\Desktop\tdsskiller.exe
2014-02-17 16:08 - 2014-02-17 16:08 - 00000000 ____D () C:\42069860f03033add3eeae
2014-02-17 15:54 - 2014-02-17 15:52 - 00002117 _____ () C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
2014-02-17 15:49 - 2014-02-17 15:49 - 00265752 _____ (Secure By Design Inc.) C:\Users\Andy Besing\Downloads\Ninite Essentials Installer.exe
2014-02-17 15:40 - 2014-02-17 15:41 - 155264904 _____ (AVG Technologies) C:\Users\Andy Besing\Downloads\avg_free_x64_all_2014_4335a7045.exe
2014-02-17 15:38 - 2014-02-17 15:38 - 04462384 _____ (AVG Technologies) C:\Users\Andy Besing\Downloads\avg_free_stb_all_2014_4335_cnet.exe
2014-02-17 15:36 - 2014-02-17 15:48 - 00000000 ____D () C:\ProgramData\MFAData
2014-02-17 15:36 - 2014-02-17 15:36 - 00000000 ____D () C:\Users\Andy Besing\AppData\Local\MFAData
2014-02-17 15:36 - 2014-02-17 15:36 - 00000000 ____D () C:\Users\Andy Besing\AppData\Local\Avg2014
2014-02-17 15:35 - 2014-02-17 15:35 - 00265752 _____ (Secure By Design Inc.) C:\Users\Andy Besing\Downloads\Ninite AVG Installer.exe
2014-02-17 15:33 - 2013-12-18 21:10 - 00877480 _____ (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2014-02-17 15:33 - 2013-12-18 21:10 - 00800168 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2014-02-17 15:30 - 2014-02-17 15:30 - 00003214 _____ () C:\Windows\System32\Tasks\IHUninstallTrackingTASK
2014-02-17 15:29 - 2014-02-17 15:29 - 00003214 _____ () C:\Windows\System32\Tasks\IHSelfDeleteTASK
2014-02-17 15:29 - 2014-02-17 15:29 - 00000000 ____D () C:\ProgramData\Motive
2014-02-17 13:19 - 2014-02-17 13:22 - 00001468 _____ () C:\Windows\KB937882.log
2014-02-17 13:13 - 2014-02-17 20:41 - 00007600 _____ () C:\Users\Andy Besing\AppData\Local\Resmon.ResmonCfg
2014-02-17 10:05 - 2014-02-17 10:06 - 00000000 ____D () C:\640ce3d826caedf57a1b497ade
2014-02-16 08:46 - 2014-02-01 03:20 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-16 08:46 - 2014-02-01 03:19 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-16 08:46 - 2014-02-01 03:19 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 19274240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 15403520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-16 08:46 - 2014-02-01 03:18 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-16 08:46 - 2014-02-01 01:58 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-16 08:46 - 2014-02-01 01:58 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 14359040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-16 08:46 - 2014-02-01 01:57 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-16 08:46 - 2014-02-01 01:40 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-16 08:46 - 2014-02-01 01:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-16 08:46 - 2014-02-01 00:45 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-02-16 08:46 - 2014-02-01 00:38 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-02-15 18:19 - 2014-02-18 09:05 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-02-15 18:19 - 2014-02-18 08:58 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-15 18:19 - 2014-02-15 18:19 - 00000656 _____ () C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2014-02-15 18:19 - 2014-02-15 18:19 - 00000628 _____ () C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2014-02-15 18:19 - 2014-02-15 18:19 - 00000458 _____ () C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
2014-02-15 18:17 - 2014-02-15 18:18 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\Andy Besing\Downloads\spybot-2.2.exe
2014-02-15 18:14 - 2014-02-15 18:14 - 00000010 _____ () C:\Users\Andy Besing\AppData\Local\sponge.last.runtime.cache
2014-02-15 18:13 - 2014-02-15 18:13 - 00185800 _____ (Лаборатория Касперского) C:\Users\Andy Besing\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5203.exe
2014-02-15 18:10 - 2014-02-15 18:10 - 02049128 _____ (Trend Micro Inc.) C:\Users\Andy Besing\Downloads\HousecallLauncher.exe
2014-02-15 18:10 - 2014-02-15 18:10 - 00000036 _____ () C:\Users\Andy Besing\AppData\Local\housecall.guid.cache
2014-02-15 18:01 - 2014-02-15 18:01 - 01166132 _____ () C:\Users\Andy Besing\Downloads\AdwCleaner.exe
2014-02-15 17:59 - 2014-02-15 17:59 - 00001436 _____ () C:\Users\Andy Besing\Desktop\JRT.txt
2014-02-15 17:55 - 2014-02-15 17:55 - 01037530 _____ (Thisisu) C:\Users\Andy Besing\Downloads\JRT (1).exe
2014-02-15 17:36 - 2014-02-15 17:54 - 00000000 ____D () C:\Users\Andy Besing\Desktop\mbar
2014-02-15 17:36 - 2014-02-15 17:54 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-02-15 17:36 - 2014-02-15 17:36 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-02-15 17:36 - 2014-02-15 17:36 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-02-15 17:35 - 2014-02-15 17:35 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Andy Besing\Downloads\mbar-1.07.0.1009.exe
2014-02-15 16:44 - 2014-02-15 16:44 - 01402880 _____ () C:\Users\Andy Besing\Downloads\HijackThis.msi
2014-02-15 16:06 - 2014-02-18 09:04 - 00001945 _____ () C:\Windows\epplauncher.mif
2014-02-15 16:03 - 2014-02-15 16:03 - 13670584 _____ (Microsoft Corporation) C:\Users\Andy Besing\Downloads\mseinstall.exe
2014-02-15 15:57 - 2014-02-15 15:58 - 102354712 _____ (Microsoft Corporation) C:\Users\Andy Besing\Downloads\msert.exe
2014-02-13 07:49 - 2014-02-15 19:07 - 00000000 ____D () C:\665be9cda96a2768561cbcac0ba2bf
2014-02-13 07:32 - 2014-02-13 07:32 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (4).exe
2014-02-12 23:35 - 2014-02-12 23:35 - 00000000 ____D () C:\Users\Public\Desktop\TrendMicro_TAV_17.10_en-US_32-bit
2014-02-12 23:24 - 2014-02-12 23:24 - 01293496 _____ () C:\Users\Andy Besing\Downloads\PDFCreatorSetup.exe
2014-02-12 23:21 - 2014-02-12 23:21 - 00664864 _____ () C:\Users\Andy Besing\Downloads\UltimateCodec.exe
2014-02-12 23:21 - 2014-02-12 23:21 - 00001095 _____ () C:\Users\Andy Besing\Desktop\Continue Codec Pack Installation.lnk
2014-02-12 23:01 - 2014-02-12 23:01 - 00388608 _____ (Trend Micro Inc.) C:\Users\Andy Besing\Downloads\HijackThis (1).exe
2014-02-12 22:50 - 2014-02-12 22:50 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (3).exe
2014-02-12 22:46 - 2014-02-12 22:46 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-CleanUp-SEO-10727454.exe
2014-02-12 22:38 - 2014-02-12 22:38 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (2).exe
2014-02-12 21:59 - 2014-02-12 21:59 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (1).exe
2014-02-12 21:18 - 2014-02-12 21:18 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221.exe
2014-02-12 20:21 - 2014-02-12 20:26 - 00000000 ____D () C:\Users\Andy Besing\AppData\Roaming\.minecraft
2014-02-12 20:21 - 2014-02-12 20:21 - 00675988 _____ () C:\Users\Andy Besing\Downloads\Minecraft.exe
2014-02-12 20:11 - 2014-02-12 20:11 - 00675988 _____ () C:\Users\Andy Besing\Downloads\Minecraft-Installer.exe
2014-02-12 20:11 - 2014-02-12 20:11 - 00000392 _____ () C:\Users\Andy Besing\Desktop\FREE Games.url
2014-02-12 20:11 - 2014-02-12 20:11 - 00000047 _____ () C:\Users\Andy Besing\AppData\Roaming\WB.CFG
2014-02-12 20:10 - 2014-02-12 20:10 - 00619024 _____ ( ) C:\Users\Andy Besing\Downloads\Minecraft Download Manager.exe
2014-02-12 20:00 - 2013-12-31 17:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-12 20:00 - 2013-12-31 17:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-12 20:00 - 2013-12-24 17:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-12 20:00 - 2013-12-24 16:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-12 20:00 - 2013-12-05 20:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-12 20:00 - 2013-12-05 20:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-12 20:00 - 2013-12-05 20:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-12 20:00 - 2013-12-05 20:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-12 20:00 - 2013-12-03 20:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-12 20:00 - 2013-12-03 20:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-12 20:00 - 2013-12-03 20:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-12 20:00 - 2013-12-03 20:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-12 20:00 - 2013-12-03 20:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-12 20:00 - 2013-12-03 20:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-12 20:00 - 2013-12-03 20:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-12 20:00 - 2013-12-03 20:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-12 20:00 - 2013-12-03 20:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-12 20:00 - 2013-12-03 20:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-12 20:00 - 2013-12-03 20:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-12 20:00 - 2013-12-03 20:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-12 20:00 - 2013-12-03 20:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-12 20:00 - 2013-12-03 20:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-12 20:00 - 2013-12-03 19:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-12 20:00 - 2013-12-03 19:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-12 20:00 - 2013-12-03 19:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-12 20:00 - 2013-12-03 19:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-12 20:00 - 2013-11-26 02:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-12 20:00 - 2013-11-22 16:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-08 11:52 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-02-08 11:52 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-02-08 11:52 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-02-08 11:52 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-02-08 11:51 - 2014-02-08 11:52 - 00005175 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-31 17:41 - 2014-02-08 10:27 - 00027136 _____ () C:\Users\Andy Besing\Desktop\Blakely Birthday Invites 2014.xls
2014-01-31 08:36 - 2014-01-31 08:36 - 00606272 _____ () C:\Users\Andy Besing\Downloads\PDFlite-0.11.2.exe
2014-01-31 08:36 - 2014-01-31 08:36 - 00606272 _____ () C:\Users\Andy Besing\Downloads\PDFlite-0.11.2 (1).exe
2014-01-27 16:45 - 2014-01-27 17:03 - 00046592 _____ () C:\Users\Andy Besing\Documents\Barrett's 7th Birthday Invite.pub
2014-01-27 14:26 - 2014-01-28 20:56 - 00000000 ____D () C:\Users\Andy Besing\Documents\Laugh for Lymphoma
2014-01-25 13:01 - 2014-01-25 13:01 - 07141688 _____ () C:\Users\Andy Besing\Downloads\Laugh for Lymphoma Presentation.zip
2014-01-24 12:30 - 2014-02-12 20:40 - 00026112 _____ () C:\Users\Andy Besing\Desktop\Barrett Birthday Invites 2014.xls
==================== One Month Modified Files and Folders =======
2014-02-18 19:16 - 2014-02-18 19:16 - 00022362 _____ () C:\Users\Andy Besing\Desktop\FRST.txt
2014-02-18 19:16 - 2014-02-18 19:16 - 00000000 ____D () C:\FRST
2014-02-18 19:15 - 2014-02-18 19:07 - 00002122 _____ () C:\Users\Andy Besing\Desktop\Rkill.txt
2014-02-18 19:14 - 2010-08-15 17:34 - 00000908 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-18 19:11 - 2009-07-13 22:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-18 19:11 - 2009-07-13 22:45 - 00023248 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-18 19:10 - 2010-05-23 02:27 - 02029990 _____ () C:\Windows\WindowsUpdate.log
2014-02-18 19:06 - 2014-02-18 19:06 - 02153472 _____ (Farbar) C:\Users\Andy Besing\Desktop\FRST64.exe
2014-02-18 19:05 - 2014-02-18 19:05 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Andy Besing\Desktop\rkill.scr
2014-02-18 19:02 - 2010-08-15 17:34 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-18 19:02 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-18 19:02 - 2009-07-13 22:51 - 00070562 _____ () C:\Windows\setupact.log
2014-02-18 10:20 - 2014-02-18 10:20 - 00001925 _____ () C:\Users\Andy Besing\Desktop\aswMBR.txt
2014-02-18 10:20 - 2014-02-18 10:20 - 00000512 _____ () C:\Users\Andy Besing\Desktop\MBR.dat
2014-02-18 10:14 - 2014-02-18 10:14 - 04745728 _____ (AVAST Software) C:\Users\Andy Besing\Downloads\aswMBR.exe
2014-02-18 10:12 - 2014-02-18 10:24 - 00025856 _____ () C:\Users\Andy Besing\Desktop\attach - Copy.txt
2014-02-18 10:12 - 2014-02-18 10:12 - 00025856 _____ () C:\Users\Andy Besing\Desktop\attach.txt
2014-02-18 10:12 - 2014-02-18 10:12 - 00018354 _____ () C:\Users\Andy Besing\Desktop\dds.txt
2014-02-18 10:10 - 2014-02-18 10:10 - 00688992 ____R (Swearware) C:\Users\Andy Besing\Downloads\dds (1).scr
2014-02-18 10:10 - 2014-02-18 10:10 - 00688992 _____ (Swearware) C:\Users\Andy Besing\Downloads\dds.scr
2014-02-18 09:55 - 2012-11-20 20:35 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-18 09:19 - 2009-07-13 23:13 - 00744902 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-18 09:05 - 2014-02-15 18:19 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-02-18 09:05 - 2010-08-13 11:37 - 00328572 _____ () C:\Windows\PFRO.log
2014-02-18 09:04 - 2014-02-15 16:06 - 00001945 _____ () C:\Windows\epplauncher.mif
2014-02-18 08:58 - 2014-02-18 08:58 - 00000085 _____ () C:\Windows\wininit.ini
2014-02-18 08:58 - 2014-02-18 08:58 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-02-18 08:58 - 2014-02-15 18:19 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-02-18 08:54 - 2014-02-18 08:54 - 00023889 _____ () C:\ComboFix.txt
2014-02-18 08:54 - 2009-07-23 00:11 - 00000000 ____D () C:\Qoobox
2014-02-18 08:46 - 2009-07-13 20:34 - 00000215 _____ () C:\Windows\system.ini
2014-02-18 08:44 - 2014-02-17 18:08 - 00000000 ____D () C:\Windows\erdnt
2014-02-17 20:41 - 2014-02-17 13:13 - 00007600 _____ () C:\Users\Andy Besing\AppData\Local\Resmon.ResmonCfg
2014-02-17 18:23 - 2014-02-17 18:23 - 00024164 _____ () C:\Users\Andy Besing\Desktop\combofix report.txt
2014-02-17 18:17 - 2010-08-13 12:40 - 00000000 ____D () C:\Users\Andy Besing
2014-02-17 18:07 - 2014-02-17 18:07 - 05183112 ____R (Swearware) C:\Users\Andy Besing\Downloads\ComboFix.exe
2014-02-17 18:06 - 2014-02-17 18:06 - 00543016 _____ (Fusion Install ) C:\Users\Andy Besing\Downloads\Setup.exe
2014-02-17 18:06 - 2014-02-17 18:05 - 00000000 ____D () C:\Users\Andy Besing\AppData\Roaming\GetRightToGo
2014-02-17 18:05 - 2014-02-17 18:05 - 00610798 _____ (Max Secure Software) C:\Users\Andy Besing\Desktop\MaxSDDMnew.exe
2014-02-17 18:05 - 2014-02-17 18:05 - 00368256 _____ (RegNow.com) C:\Users\Andy Besing\Downloads\Download_MaxSDDMnew.exe
2014-02-17 18:02 - 2014-02-17 18:02 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Andy Besing\Downloads\tdsskiller (1).exe
2014-02-17 18:02 - 2014-02-17 18:02 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Andy Besing\Desktop\tdsskiller.exe
2014-02-17 16:08 - 2014-02-17 16:08 - 00000000 ____D () C:\42069860f03033add3eeae
2014-02-17 15:52 - 2014-02-17 15:54 - 00002117 _____ () C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
2014-02-17 15:49 - 2014-02-17 15:49 - 00265752 _____ (Secure By Design Inc.) C:\Users\Andy Besing\Downloads\Ninite Essentials Installer.exe
2014-02-17 15:48 - 2014-02-17 15:36 - 00000000 ____D () C:\ProgramData\MFAData
2014-02-17 15:47 - 2011-05-18 08:58 - 00000000 ____D () C:\Users\Andy Besing\Tracing
2014-02-17 15:41 - 2014-02-17 15:40 - 155264904 _____ (AVG Technologies) C:\Users\Andy Besing\Downloads\avg_free_x64_all_2014_4335a7045.exe
2014-02-17 15:38 - 2014-02-17 15:38 - 04462384 _____ (AVG Technologies) C:\Users\Andy Besing\Downloads\avg_free_stb_all_2014_4335_cnet.exe
2014-02-17 15:36 - 2014-02-17 15:36 - 00000000 ____D () C:\Users\Andy Besing\AppData\Local\MFAData
2014-02-17 15:36 - 2014-02-17 15:36 - 00000000 ____D () C:\Users\Andy Besing\AppData\Local\Avg2014
2014-02-17 15:35 - 2014-02-17 15:35 - 00265752 _____ (Secure By Design Inc.) C:\Users\Andy Besing\Downloads\Ninite AVG Installer.exe
2014-02-17 15:33 - 2010-05-15 00:13 - 00000000 ____D () C:\Program Files (x86)\Java
2014-02-17 15:31 - 2010-05-14 23:07 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-02-17 15:30 - 2014-02-17 15:30 - 00003214 _____ () C:\Windows\System32\Tasks\IHUninstallTrackingTASK
2014-02-17 15:29 - 2014-02-17 15:29 - 00003214 _____ () C:\Windows\System32\Tasks\IHSelfDeleteTASK
2014-02-17 15:29 - 2014-02-17 15:29 - 00000000 ____D () C:\ProgramData\Motive
2014-02-17 15:12 - 2010-08-15 17:34 - 00000000 ____D () C:\Program Files\Google
2014-02-17 15:12 - 2010-08-15 17:33 - 00000000 ____D () C:\Program Files (x86)\Google
2014-02-17 15:11 - 2010-08-15 17:34 - 00000000 ____D () C:\Users\Andy Besing\AppData\Local\Google
2014-02-17 15:11 - 2010-08-15 17:33 - 00000000 ____D () C:\ProgramData\Google
2014-02-17 13:37 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-02-17 13:37 - 2009-07-13 23:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2014-02-17 13:22 - 2014-02-17 13:19 - 00001468 _____ () C:\Windows\KB937882.log
2014-02-17 10:06 - 2014-02-17 10:05 - 00000000 ____D () C:\640ce3d826caedf57a1b497ade
2014-02-16 10:20 - 2013-07-23 13:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 09:08 - 2011-02-03 21:06 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-15 19:08 - 2010-08-30 18:48 - 00000000 ____D () C:\ProgramData\Recovery
2014-02-15 19:07 - 2014-02-13 07:49 - 00000000 ____D () C:\665be9cda96a2768561cbcac0ba2bf
2014-02-15 19:07 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\AppCompat
2014-02-15 19:06 - 2013-11-20 08:12 - 00000000 ____D () C:\Users\Andy Besing\Downloads\backups
2014-02-15 18:19 - 2014-02-15 18:19 - 00000656 _____ () C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2014-02-15 18:19 - 2014-02-15 18:19 - 00000628 _____ () C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2014-02-15 18:19 - 2014-02-15 18:19 - 00000458 _____ () C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
2014-02-15 18:18 - 2014-02-15 18:17 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\Andy Besing\Downloads\spybot-2.2.exe
2014-02-15 18:14 - 2014-02-15 18:14 - 00000010 _____ () C:\Users\Andy Besing\AppData\Local\sponge.last.runtime.cache
2014-02-15 18:13 - 2014-02-15 18:13 - 00185800 _____ (Лаборатория Касперского) C:\Users\Andy Besing\Downloads\kss12.0.1.117abRU_EN_DE_FR_ES_IT_JA_PT_ZH_5203.exe
2014-02-15 18:10 - 2014-02-15 18:10 - 02049128 _____ (Trend Micro Inc.) C:\Users\Andy Besing\Downloads\HousecallLauncher.exe
2014-02-15 18:10 - 2014-02-15 18:10 - 00000036 _____ () C:\Users\Andy Besing\AppData\Local\housecall.guid.cache
2014-02-15 18:05 - 2013-11-25 07:50 - 00000000 ____D () C:\AdwCleaner
2014-02-15 18:01 - 2014-02-15 18:01 - 01166132 _____ () C:\Users\Andy Besing\Downloads\AdwCleaner.exe
2014-02-15 17:59 - 2014-02-15 17:59 - 00001436 _____ () C:\Users\Andy Besing\Desktop\JRT.txt
2014-02-15 17:55 - 2014-02-15 17:55 - 01037530 _____ (Thisisu) C:\Users\Andy Besing\Downloads\JRT (1).exe
2014-02-15 17:54 - 2014-02-15 17:36 - 00000000 ____D () C:\Users\Andy Besing\Desktop\mbar
2014-02-15 17:54 - 2014-02-15 17:36 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-02-15 17:36 - 2014-02-15 17:36 - 00119000 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-02-15 17:36 - 2014-02-15 17:36 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-02-15 17:35 - 2014-02-15 17:35 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Andy Besing\Downloads\mbar-1.07.0.1009.exe
2014-02-15 16:44 - 2014-02-15 16:44 - 01402880 _____ () C:\Users\Andy Besing\Downloads\HijackThis.msi
2014-02-15 16:31 - 2011-05-15 18:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-15 16:03 - 2014-02-15 16:03 - 13670584 _____ (Microsoft Corporation) C:\Users\Andy Besing\Downloads\mseinstall.exe
2014-02-15 15:58 - 2014-02-15 15:57 - 102354712 _____ (Microsoft Corporation) C:\Users\Andy Besing\Downloads\msert.exe
2014-02-15 10:35 - 2010-08-13 16:59 - 00000000 ____D () C:\Users\Andy Besing\AppData\Roaming\HpUpdate
2014-02-13 07:32 - 2014-02-13 07:32 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (4).exe
2014-02-13 00:08 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2014-02-12 23:35 - 2014-02-12 23:35 - 00000000 ____D () C:\Users\Public\Desktop\TrendMicro_TAV_17.10_en-US_32-bit
2014-02-12 23:24 - 2014-02-12 23:24 - 01293496 _____ () C:\Users\Andy Besing\Downloads\PDFCreatorSetup.exe
2014-02-12 23:21 - 2014-02-12 23:21 - 00664864 _____ () C:\Users\Andy Besing\Downloads\UltimateCodec.exe
2014-02-12 23:21 - 2014-02-12 23:21 - 00001095 _____ () C:\Users\Andy Besing\Desktop\Continue Codec Pack Installation.lnk
2014-02-12 23:02 - 2013-11-20 08:09 - 00014555 _____ () C:\Users\Andy Besing\Downloads\hijackthis.log
2014-02-12 23:01 - 2014-02-12 23:01 - 00388608 _____ (Trend Micro Inc.) C:\Users\Andy Besing\Downloads\HijackThis (1).exe
2014-02-12 22:50 - 2014-02-12 22:50 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (3).exe
2014-02-12 22:46 - 2014-02-12 22:46 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-CleanUp-SEO-10727454.exe
2014-02-12 22:38 - 2014-02-12 22:38 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (2).exe
2014-02-12 21:59 - 2014-02-12 21:59 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (1).exe
2014-02-12 21:51 - 2013-11-25 08:47 - 10820032 _____ (SurfRight B.V.) C:\Users\Andy Besing\Desktop\HitmanPro_x64.exe
2014-02-12 21:18 - 2014-02-12 21:18 - 00930440 _____ (CNET Download.com) C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221.exe
2014-02-12 20:40 - 2014-01-24 12:30 - 00026112 _____ () C:\Users\Andy Besing\Desktop\Barrett Birthday Invites 2014.xls
2014-02-12 20:26 - 2014-02-12 20:21 - 00000000 ____D () C:\Users\Andy Besing\AppData\Roaming\.minecraft
2014-02-12 20:21 - 2014-02-12 20:21 - 00675988 _____ () C:\Users\Andy Besing\Downloads\Minecraft.exe
2014-02-12 20:11 - 2014-02-12 20:11 - 00675988 _____ () C:\Users\Andy Besing\Downloads\Minecraft-Installer.exe
2014-02-12 20:11 - 2014-02-12 20:11 - 00000392 _____ () C:\Users\Andy Besing\Desktop\FREE Games.url
2014-02-12 20:11 - 2014-02-12 20:11 - 00000047 _____ () C:\Users\Andy Besing\AppData\Roaming\WB.CFG
2014-02-12 20:10 - 2014-02-12 20:10 - 00619024 _____ ( ) C:\Users\Andy Besing\Downloads\Minecraft Download Manager.exe
2014-02-12 19:45 - 2011-10-26 08:24 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-02-12 19:45 - 2010-08-24 08:45 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-02-11 07:09 - 2010-08-15 17:34 - 00003904 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-11 07:09 - 2010-08-15 17:34 - 00003652 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-09 14:19 - 2013-11-12 10:06 - 00000000 ____D () C:\ProgramData\Oracle
2014-02-08 11:52 - 2014-02-08 11:51 - 00005175 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-02-08 10:27 - 2014-01-31 17:41 - 00027136 _____ () C:\Users\Andy Besing\Desktop\Blakely Birthday Invites 2014.xls
2014-02-08 07:37 - 2012-11-20 20:35 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-08 07:37 - 2012-11-20 20:35 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-08 07:37 - 2012-11-20 20:35 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-03 20:19 - 2014-01-03 09:55 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-01 03:20 - 2014-02-16 08:46 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-01 03:19 - 2014-02-16 08:46 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-01 03:19 - 2014-02-16 08:46 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 19274240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 15403520 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 03960320 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-01 03:18 - 2014-02-16 08:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-01 01:58 - 2014-02-16 08:46 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-01 01:58 - 2014-02-16 08:46 - 01140736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 14359040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-01 01:57 - 2014-02-16 08:46 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-01 01:40 - 2014-02-16 08:46 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-01 01:34 - 2014-02-16 08:46 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-01 00:45 - 2014-02-16 08:46 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-02-01 00:38 - 2014-02-16 08:46 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-01-31 08:36 - 2014-01-31 08:36 - 00606272 _____ () C:\Users\Andy Besing\Downloads\PDFlite-0.11.2.exe
2014-01-31 08:36 - 2014-01-31 08:36 - 00606272 _____ () C:\Users\Andy Besing\Downloads\PDFlite-0.11.2 (1).exe
2014-01-28 20:56 - 2014-01-27 14:26 - 00000000 ____D () C:\Users\Andy Besing\Documents\Laugh for Lymphoma
2014-01-27 17:03 - 2014-01-27 16:45 - 00046592 _____ () C:\Users\Andy Besing\Documents\Barrett's 7th Birthday Invite.pub
2014-01-25 13:01 - 2014-01-25 13:01 - 07141688 _____ () C:\Users\Andy Besing\Downloads\Laugh for Lymphoma Presentation.zip
2014-01-19 01:33 - 2010-08-15 16:30 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Files to move or delete:
====================
C:\Users\Andy Besing\gotomypc_437.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-30 17:36
==================== End Of Log ============================