This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Deal Spy [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have picked up a Google Chrome extension which cannot be removed through normal means. The extension seems to be adding advertising to all webpages and may be tracking me, stealing data etc. I have no idea how to remove it. Please help? Thank you.
Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any antivirus programs during the scan (If you have difficulty properly disabling your protective programs, refer to this link here )
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

[external image: Posted Image] AdwCleaner

Please download AdwCleaner by Xplode onto your desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.
———-
Yes, thank you. This website is amazing, it's so great to see people learning and increasing their own knowledge by helping others. Sorry, I've been very busy the past few days. I'd love to get this thing off my computer. I am under the impression that some malicious software is installing more and more software onto my computer. aswMBR freezes at service scan on "Service WinDefend C:\Program Files sys" Please note: I have a "C" drive (SSD with OS and a few other items) and an "E" (phsycial) drive… Which you can probably see in the report. :s DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 10.0.9200.16537 Run by [removed] at 9:52:09 on 2013-05-04 #Option Extended Search is enabled. Microsoft Windows 8 6.2.9200.0.1252.61.2057.18.16346.13838 [GMT 10:00] . AV: Kaspersky Internet Security *Disabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5} AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Kaspersky Internet Security *Disabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security *Disabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E} . ============== Running Processes =============== . C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\dwm.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bluetooth Suite\adminservice.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\dashost.exe C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe C:\Windows\System32\alg.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhostex.exe C:\Windows\Explorer.EXE C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\rundll32.exe C:\Program Files (x86)\Bluetooth Suite\BtTray.exe C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe E:\Program Files (x86)\Steam\Steam.exe C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe E:\Program Files (x86)\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\lg_fwupdate\fwupdate.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe E:\Program Files (x86)\MediaMonkey\MediaMonkey.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank mStart Page = about:blank mWinlogon: Userinit = userinit.exe BHO: Deal Spy: {11111111-1111-1111-1111-110211621176} - BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll uRun: [Steam] "E:\Program Files (x86)\Steam\steam.exe" -silent uRun: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" mRun: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" mRun: [LGODDFU] "C:\Program Files (x86)\lg_fwupdate\lgfw.exe" blrun mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe" mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60 mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [iTunesHelper] "E:\Program Files (x86)\iTunesHelper.exe" dRun: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\GIGABY~1.LNK - C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe mPolicies-Explorer: NoDriveTypeAutoRun = dword:60 mPolicies-System: DisableCAD = dword:1 IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - TCP: NameServer = 192.168.1.1 TCP: Interfaces\{4EFC8E57-66CC-4817-ABBA-C5803E3E7846} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{CA73159C-0151-4364-8BD4-E04CA6951ED4} : DHCPNameServer = 192.168.1.1 SSODL: WebCheck - mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome x64-mStart Page = about:blank x64-BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll x64-BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll x64-BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll x64-BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll x64-BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll x64-Run: [RunDLLEntry] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\AmbRunE.dll,RunDLLEntry x64-Run: [BtTray] "C:\Program Files (x86)\Bluetooth Suite\BtTray.exe" x64-Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" x64-mPolicies-Explorer: NoDriveTypeAutoRun = dword:60 x64-mPolicies-System: DisableCAD = dword:1 x64-IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll x64-IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll x64-SSODL: WebCheck - . ============= SERVICES / DRIVERS =============== . R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2013-4-28 647736] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\Drivers\klim6.sys [2012-8-2 28504] R1 klwfp;klwfp;C:\Windows\System32\Drivers\klwfp.sys [2013-3-22 50448] R1 kneps;kneps;C:\Windows\System32\Drivers\kneps.sys [2012-8-13 178448] R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2012-7-31 207488] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-4-28 14904] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-1-18 383264] R2 ZAtheros Bt&Wlan Coex Agent;ZAtheros Bt&Wlan Coex Agent;C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2012-7-31 323584] R3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;C:\Windows\System32\Drivers\btath_flt.sys [2013-4-28 88728] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\Drivers\btath_a2dp.sys [2013-4-28 344216] R3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;C:\Windows\System32\Drivers\btath_avdt.sys [2013-4-28 114840] R3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;C:\Windows\System32\Drivers\btath_bus.sys [2013-4-28 33944] R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\Drivers\btath_hcrp.sys [2013-4-28 178840] R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\Drivers\btath_lwflt.sys [2013-4-28 76952] R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\Drivers\btath_rcp.sys [2013-4-28 135832] R3 BtFilter;BtFilter;C:\Windows\System32\Drivers\btfilter.sys [2013-4-28 574616] R3 BthLEEnum;Bluetooth Low Energy Driver;C:\Windows\System32\Drivers\BthLEEnum.sys [2012-7-26 202752] R3 DAdderFltr;DeathAdder Mouse;C:\Windows\System32\Drivers\dadder.sys [2007-8-2 12672] R3 klkbdflt;Kaspersky Lab KLKBDFLT;C:\Windows\System32\Drivers\klkbdflt.sys [2013-3-22 29016] R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\Drivers\klmouflt.sys [2013-3-22 29528] R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;C:\Windows\System32\Drivers\L1C63x64.sys [2013-4-28 110744] S0 klelam;klelam;C:\Windows\System32\Drivers\klelam.sys [2012-7-27 29616] S2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [2013-3-22 356376] S2 MBAMScheduler;MBAMScheduler;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-4-30 418376] S2 MBAMService;MBAMService;E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-4-30 701512] S3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-4-30 25928] . =============== Created Last 60 ================ . 2013-05-02 08:16:16 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Roaming\NVIDIA 2013-05-01 20:23:57 3245568 —-a-w- C:\Windows\System32\rdpcorets.dll 2013-05-01 08:41:13 ——– d—–w- C:\ProgramData\Creative Labs 2013-05-01 08:38:33 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2013-05-01 08:38:30 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-05-01 08:38:30 ——– d—–w- C:\Program Files\iTunes 2013-05-01 08:38:30 ——– d—–w- C:\Program Files\iPod 2013-05-01 08:37:58 ——– d—–w- C:\Program Files\Bonjour 2013-05-01 08:37:58 ——– d—–w- C:\Program Files (x86)\Bonjour 2013-05-01 08:33:44 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Apple Computer 2013-05-01 08:33:15 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Apple 2013-05-01 08:20:30 16114176 —-a-w- C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll 2013-05-01 08:20:30 15541248 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll 2013-04-30 08:39:00 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Roaming\Malwarebytes 2013-04-30 08:38:47 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys 2013-04-30 08:38:47 ——– d—–w- C:\ProgramData\Malwarebytes 2013-04-30 08:32:26 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Programs 2013-04-30 07:14:53 94208 —-a-w- C:\Windows\System32\synceng.dll 2013-04-30 07:13:55 2893824 —-a-w- C:\Windows\System32\msmpeg2vdec.dll 2013-04-30 07:12:59 55272 —-a-w- C:\Program Files\Windows Defender\MpUXSrv.exe 2013-04-30 07:07:55 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\ElevatedDiagnostics 2013-04-30 06:39:24 ——– d—–w- C:\Windows\System32\catroot2 2013-04-29 21:08:47 ——– d-sh–w- C:\found.000 2013-04-29 11:40:14 ——– d—–w- C:\GvTemp 2013-04-29 11:16:56 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Diagnostics 2013-04-29 10:11:17 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\MediaMonkey 2013-04-29 10:11:09 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Roaming\MediaMonkey 2013-04-29 10:11:08 ——– d—–w- C:\ProgramData\MediaMonkey 2013-04-28 11:57:10 ——– d—–w- C:\Remote Programs 2013-04-28 11:57:09 57824 ——w- C:\Windows\ExentInfo.exe 2013-04-28 11:57:09 ——– d—–w- C:\ProgramData\Free Ride Games 2013-04-28 11:54:58 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Updater26276 2013-04-28 11:54:56 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Deal Spy 2013-04-28 10:16:59 68104 —-a-w- C:\Windows\System32\XAPOFX1_0.dll 2013-04-28 09:47:16 ——– d—–w- C:\Program Files (x86)\Unvanquished 2013-04-28 09:18:58 82944 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPP9N.DLL 2013-04-28 09:18:58 28160 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPD9N.DLL 2013-04-28 09:18:54 290816 —-a-w- C:\Windows\System32\CNMLM9N.DLL 2013-04-28 01:35:22 ——– d—–w- C:\Program Files (x86)\Qualcomm Atheros 2013-04-28 01:35:08 3618304 —-a-w- C:\Windows\System32\drivers\athw8x.sys 2013-04-28 01:35:08 3618304 ——w- C:\Windows\System32\athw8x.sys 2013-04-28 01:35:08 ——– d—–w- C:\Windows\Options 2013-04-28 01:34:55 ——– d—–w- C:\ProgramData\Qualcomm Atheros 2013-04-28 01:29:36 ——– d—–w- C:\Windows\SysWow64\Atheros_L1e 2013-04-28 01:28:58 110744 —-a-w- C:\Windows\System32\drivers\L1C63x64.sys 2013-04-28 01:22:56 ——– d—–w- C:\Program Files (x86)\Common Files\Intel Corporation 2013-04-28 01:22:16 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Roaming\Intel Corporation 2013-04-28 01:19:41 647736 —-a-w- C:\Windows\System32\drivers\iaStorA.sys 2013-04-28 01:17:37 53248 —-a-w- C:\Windows\SysWow64\CSVer.dll 2013-04-28 01:17:23 ——– d—–w- C:\Intel 2013-04-28 01:16:57 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\BMExplorer 2013-04-28 01:16:56 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Roaming\Atheros 2013-04-28 00:42:04 93184 ——w- C:\Windows\System32\ctpxst64.exe 2013-04-28 00:42:04 8704 ——w- C:\Windows\System32\ResDefE.exe 2013-04-28 00:42:04 260608 ——w- C:\Windows\System32\AMBSpiE.exe 2013-04-28 00:42:04 17920 ——w- C:\Windows\System32\AmbRunE.dll 2013-04-28 00:42:04 141312 ——w- C:\Windows\System32\cfgChain.exe 2013-04-28 00:41:59 89600 —-a-w- C:\Windows\System32\CmdRtr64.DLL 2013-04-28 00:41:59 74240 —-a-w- C:\Windows\SysWow64\CmdRtr.DLL 2013-04-28 00:41:59 325120 —-a-w- C:\Windows\System32\APOMgr64.DLL 2013-04-28 00:41:59 25600 ——w- C:\Windows\System32\THXCfg64.dll 2013-04-28 00:41:59 246272 —-a-w- C:\Windows\SysWow64\APOMngr.DLL 2013-04-28 00:41:59 141312 ——w- C:\Windows\System32\THXCfg64.exe 2013-04-28 00:41:37 ——– d—–w- C:\Program Files (x86)\Common Files\Macrovision Shared 2013-04-28 00:41:36 ——– d—–w- C:\Program Files (x86)\Creative 2013-04-28 00:00:00 729088 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll 2013-04-28 00:00:00 69715 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll 2013-04-28 00:00:00 5632 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe 2013-04-28 00:00:00 32768 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll 2013-04-28 00:00:00 266240 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll 2013-04-28 00:00:00 192512 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll 2013-04-27 23:59:59 311428 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll 2013-04-27 23:59:59 188548 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll 2013-04-27 23:16:04 17536 —-a-w- C:\ProgramData\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin 2013-04-27 14:15:56 ——– d—–w- C:\Program Files (x86)\Common Files\Steam 2013-04-27 14:10:03 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Roaming\NVIDIA 3D Vision Video Player 2013-04-27 13:51:11 ——– d—–w- C:\Windows\Panther 2013-04-27 13:48:04 31040 —-a-w- C:\Windows\System32\nvhdap64.dll 2013-04-27 13:48:04 188736 —-a-w- C:\Windows\System32\drivers\nvhda64v.sys 2013-04-27 13:48:04 1451840 —-a-w- C:\Windows\System32\nvhdagenco6420103.dll 2013-04-27 13:47:58 884512 —-a-w- C:\Windows\System32\nvvsvc.exe 2013-04-27 13:47:58 6390048 —-a-w- C:\Windows\System32\nvcpl.dll 2013-04-27 13:47:58 63776 —-a-w- C:\Windows\System32\nvshext.dll 2013-04-27 13:47:58 3460896 —-a-w- C:\Windows\System32\nvsvc64.dll 2013-04-27 13:47:58 2953448 —-a-w- C:\Windows\System32\nvcoproc.bin 2013-04-27 13:47:58 2558240 —-a-w- C:\Windows\System32\nvsvcr.dll 2013-04-27 13:47:58 118560 —-a-w- C:\Windows\System32\nvmctray.dll 2013-04-27 13:47:37 ——– d—–w- C:\ProgramData\NVIDIA Corporation 2013-04-27 13:47:34 1468224 —-a-w- C:\Windows\System32\nvgenco64.dll 2013-04-27 13:47:14 364352 —-a-w- C:\Windows\System32\nvdecodemft.dll 2013-04-27 13:47:14 301376 —-a-w- C:\Windows\SysWow64\nvdecodemft.dll 2013-04-27 13:42:17 ——– d—–w- C:\NVIDIA 2013-04-27 13:38:01 ——– d—–w- C:\Program Files (x86)\GIGABYTE 2013-04-27 13:25:30 ——– d—–w- C:\ProgramData\Atheros 2013-04-27 12:38:12 ——– d—–w- C:\Program Files (x86)\Samsung 2013-04-27 12:28:39 778856 —-a-w- C:\Windows\SysWow64\PresentationNative_v0300.dll 2013-04-27 12:28:39 35400 —-a-w- C:\Windows\SysWow64\TsWpfWrp.exe 2013-04-27 12:28:39 35400 —-a-w- C:\Windows\System32\TsWpfWrp.exe 2013-04-27 12:28:39 102528 —-a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll 2013-04-27 12:28:38 124040 —-a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll 2013-04-27 12:28:38 1166440 —-a-w- C:\Windows\System32\PresentationNative_v0300.dll 2013-04-27 11:54:49 64856 —-a-w- C:\Windows\System32\klfphc.dll 2013-04-27 11:54:29 ——– d—–w- C:\ProgramData\Kaspersky Lab 2013-04-27 11:54:29 ——– d—–w- C:\Program Files (x86)\Kaspersky Lab 2013-04-27 11:54:23 90208 —-a-w- C:\Windows\System32\drivers\klflt.sys 2013-04-27 05:18:08 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Google 2013-04-27 05:05:41 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Power2Go 2013-04-27 04:55:40 68928 —-a-w- C:\Windows\System32\OpenCL.dll 2013-04-27 04:55:40 61248 —-a-w- C:\Windows\SysWow64\OpenCL.dll 2013-04-27 04:55:34 ——– d—–w- C:\Program Files\NVIDIA Corporation 2013-04-27 04:55:34 ——– d—–w- C:\Program Files (x86)\NVIDIA Corporation 2013-04-27 04:42:14 ——– d—–w- C:\Users\Dustin Arbuthnot\Cyberlink 2013-04-27 04:37:26 ——– d—–w- C:\Temp 2013-04-27 04:36:51 59904 —-a-w- C:\Windows\SysWow64\wbemdisp.tlb 2013-04-27 04:36:51 16384 —-a-w- C:\Windows\SysWow64\lgfwunis.exe 2013-04-27 04:36:51 115016 —-a-w- C:\Windows\SysWow64\MSINET.OCX 2013-04-27 04:36:51 102912 —-a-w- C:\Windows\SysWow64\Vb6stkit.dll 2013-04-27 04:36:51 102160 —-a-w- C:\Windows\SysWow64\VB6KO.DLL 2013-04-27 04:36:49 ——– d—–w- C:\Program Files (x86)\lg_fwupdate 2013-04-27 04:36:05 77824 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll 2013-04-27 04:36:05 32768 ——w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll 2013-04-27 04:36:05 225280 ——w- C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll 2013-04-27 04:36:05 176128 ——w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll 2013-04-27 04:36:04 614532 —-a-w- C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe 2013-04-27 04:34:05 ——– d—–w- C:\Users\Dustin Arbuthnot\AppData\Local\Cyberlink 2013-04-27 04:25:37 25640 —-a-w- C:\Windows\gdrv.sys 2013-04-27 04:05:07 ——– d—–r- C:\Users\Dustin Arbuthnot\Searches 2013-04-27 04:05:07 ——– d—–r- C:\Users\Dustin Arbuthnot\Contacts 2013-03-27 02:32:06 69760 —-a-w- C:\Windows\System32\RadioSupport.dll 2013-03-27 02:32:06 246804 —-a-w- C:\Windows\System32\drivers\AtherosBT.bin 2013-03-27 02:32:06 208384 —-a-w- C:\Windows\System32\AdminService.exe 2013-03-22 01:14:34 50448 —-a-w- C:\Windows\System32\drivers\klwfp.sys 2013-03-22 01:14:34 29528 —-a-w- C:\Windows\System32\drivers\klmouflt.sys 2013-03-22 01:14:34 29016 —-a-w- C:\Windows\System32\drivers\klkbdflt.sys . ==================== Find6M ==================== . 2013-04-27 12:23:13 178448 —-a-w- C:\Windows\System32\drivers\kneps.sys 2013-04-02 22:08:01 78176 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-02 22:08:01 692576 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-03-19 22:19:24 4041728 —-a-w- C:\Windows\System32\win32k.sys 2013-03-07 06:50:56 6991592 —-a-w- C:\Windows\System32\ntoskrnl.exe 2013-03-02 10:57:48 337128 —-a-w- C:\Windows\System32\drivers\USBXHCI.SYS 2013-03-02 10:57:46 77544 —-a-w- C:\Windows\System32\drivers\storahci.sys 2013-03-02 10:57:46 332520 —-a-w- C:\Windows\System32\drivers\storport.sys 2013-03-02 10:57:46 283880 —-a-w- C:\Windows\System32\drivers\spaceport.sys 2013-03-02 10:45:20 148712 —-a-w- C:\Windows\System32\drivers\tpm.sys 2013-03-02 10:45:19 194792 —-a-w- C:\Windows\System32\drivers\sdbus.sys 2013-03-02 10:45:10 125160 —-a-w- C:\Windows\System32\drivers\dumpsd.sys 2013-03-02 10:39:39 495336 —-a-w- C:\Windows\System32\drivers\vhdmp.sys 2013-03-02 10:39:38 69864 —-a-w- C:\Windows\System32\drivers\pdc.sys 2013-03-02 10:39:32 327912 —-a-w- C:\Windows\System32\drivers\Classpnp.sys 2013-03-02 09:59:37 2231528 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2013-03-02 09:59:36 411880 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2013-03-02 08:24:08 34304 —-a-w- C:\Windows\SysWow64\wuapp.exe 2013-03-02 08:23:43 83968 —-a-w- C:\Windows\SysWow64\wudriver.dll 2013-03-02 08:23:43 125952 —-a-w- C:\Windows\SysWow64\wuwebv.dll 2013-03-02 08:23:30 893952 —-a-w- C:\Windows\SysWow64\winmde.dll 2013-03-02 08:23:30 1338880 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll 2013-03-02 08:23:28 601088 —-a-w- C:\Windows\SysWow64\Windows.Globalization.dll 2013-03-02 08:23:28 504320 —-a-w- C:\Windows\SysWow64\Windows.Security.Authentication.OnlineId.dll 2013-03-02 08:23:19 8857088 —-a-w- C:\Windows\SysWow64\twinui.dll 2013-03-02 08:23:19 246784 —-a-w- C:\Windows\SysWow64\ubpm.dll 2013-03-02 08:23:04 356352 —-a-w- C:\Windows\SysWow64\SettingSync.dll 2013-03-02 08:23:04 100864 —-a-w- C:\Windows\SysWow64\SettingSyncInfo.dll 2013-03-02 08:23:00 375808 —-a-w- C:\Windows\SysWow64\ReAgent.dll 2013-03-02 08:22:36 357888 —-a-w- C:\Windows\SysWow64\netcfgx.dll 2013-03-02 08:22:32 5091840 —-a-w- C:\Windows\SysWow64\mstscax.dll 2013-03-02 08:22:18 361984 —-a-w- C:\Windows\SysWow64\MFMediaEngine.dll 2013-03-02 08:22:17 850944 —-a-w- C:\Windows\SysWow64\mfasfsrcsnk.dll 2013-03-02 08:21:56 550912 —-a-w- C:\Windows\SysWow64\drvstore.dll 2013-03-02 08:21:52 36352 —-a-w- C:\Windows\SysWow64\DevDispItemProvider.dll 2013-03-02 08:21:40 309760 —-a-w- C:\Windows\SysWow64\BCP47Langs.dll 2013-03-02 08:21:39 2033664 —-a-w- C:\Windows\SysWow64\authui.dll 2013-03-02 08:21:32 145408 —-a-w- C:\Windows\SysWow64\powercfg.cpl 2013-03-02 02:44:59 448512 —-a-w- C:\Windows\System32\SettingSync.dll 2013-03-02 02:44:59 128512 —-a-w- C:\Windows\System32\SettingSyncInfo.dll 2013-03-02 02:44:56 1011200 —-a-w- C:\Windows\System32\reseteng.dll 2013-03-02 02:44:41 455168 —-a-w- C:\Windows\System32\netcfgx.dll 2013-03-02 02:44:41 117248 —-a-w- C:\Windows\System32\NdisImPlatform.dll 2013-03-02 02:44:38 5978624 —-a-w- C:\Windows\System32\mstscax.dll 2013-03-02 02:44:30 468992 —-a-w- C:\Windows\System32\MFMediaEngine.dll 2013-03-02 02:44:29 1048576 —-a-w- C:\Windows\System32\mfasfsrcsnk.dll 2013-03-02 02:44:08 703488 —-a-w- C:\Windows\System32\drvstore.dll 2013-03-02 02:44:07 150016 —-a-w- C:\Windows\System32\discan.dll 2013-03-02 02:44:05 49152 —-a-w- C:\Windows\System32\DevDispItemProvider.dll 2013-03-02 02:43:59 1933312 —-a-w- C:\Windows\System32\wbem\cimwin32.dll 2013-03-02 02:43:56 389120 —-a-w- C:\Windows\System32\BCP47Langs.dll 2013-03-02 02:43:55 2302464 —-a-w- C:\Windows\System32\authui.dll 2013-03-02 02:43:51 2146304 —-a-w- C:\Windows\System32\actxprxy.dll 2013-03-02 02:43:50 156160 —-a-w- C:\Windows\System32\powercfg.cpl 2013-03-02 02:15:53 26112 —-a-w- C:\Windows\System32\drivers\mouhid.sys 2013-03-01 04:56:33 156672 —-a-w- C:\Windows\System32\drivers\rfcomm.sys 2013-03-01 04:56:18 30720 —-a-w- C:\Windows\System32\drivers\monitor.sys 2013-03-01 04:55:37 1175040 —-a-w- C:\Windows\System32\drivers\bthport.sys 2013-02-21 10:30:16 1766912 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-02-21 10:29:39 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll 2013-02-21 10:29:37 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll 2013-02-21 10:29:37 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll 2013-02-21 10:15:07 2240512 —-a-w- C:\Windows\System32\wininet.dll 2013-02-21 10:15:00 915968 —-a-w- C:\Windows\System32\uxtheme.dll 2013-02-21 10:14:09 3958784 —-a-w- C:\Windows\System32\jscript9.dll 2013-02-21 10:14:05 136704 —-a-w- C:\Windows\System32\iesysprep.dll 2013-02-19 09:53:00 534528 —-a-w- C:\Windows\SysWow64\uxtheme.dll 2013-02-15 07:58:59 39936 —-a-w- C:\Windows\apppatch\apppatch64\acspecfc.dll 2013-02-15 06:35:40 444416 —-a-w- C:\Windows\apppatch\AcSpecfc.dll 2013-02-12 00:17:50 20992 —-a-w- C:\Windows\System32\drivers\usb8023.sys 2013-02-07 01:33:01 754176 —-a-w- C:\Windows\SysWow64\actxprxy.dll 2013-02-05 22:31:11 622080 —-a-w- C:\Windows\System32\drivers\srv2.sys 2013-02-05 22:29:09 370688 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys 2013-02-05 22:28:48 247808 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2013-02-05 22:28:36 215552 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2013-02-02 11:19:44 496872 —-a-w- C:\Windows\System32\drivers\usbhub.sys 2013-02-02 11:19:44 446184 —-a-w- C:\Windows\System32\drivers\USBHUB3.SYS 2013-02-02 11:19:33 61672 —-a-w- C:\Windows\System32\drivers\crashdmp.sys 2013-02-02 10:54:54 1933544 —-a-w- C:\Windows\System32\drivers\ntfs.sys 2013-02-02 10:28:54 993512 —-a-w- C:\Windows\System32\drivers\ndis.sys 2013-02-02 08:40:58 375808 —-a-w- C:\Windows\SysWow64\wbem\WmiPrvSE.exe 2013-02-02 08:40:55 80896 —-a-w- C:\Windows\SysWow64\tasklist.exe 2013-02-02 08:40:55 79360 —-a-w- C:\Windows\SysWow64\taskkill.exe 2013-02-02 08:40:36 155136 —-a-w- C:\Windows\SysWow64\XpsRasterService.dll 2013-02-02 08:40:35 370688 —-a-w- C:\Windows\SysWow64\WWanAPI.dll 2013-02-02 08:40:27 131072 —-a-w- C:\Windows\SysWow64\wbem\WmiDcPrv.dll 2013-02-02 08:40:26 410624 —-a-w- C:\Windows\SysWow64\wlroamextension.dll 2013-02-02 08:40:22 197632 —-a-w- C:\Windows\SysWow64\Windows.Networking.Connectivity.dll 2013-02-02 08:40:22 10792448 —-a-w- C:\Windows\SysWow64\Windows.UI.Xaml.dll 2013-02-02 08:39:59 325632 —-a-w- C:\Windows\SysWow64\schannel.dll 2013-02-02 08:39:47 18432 —-a-w- C:\Windows\SysWow64\npmproxy.dll 2013-02-02 08:39:34 55296 —-a-w- C:\Windows\SysWow64\nlaapi.dll 2013-02-02 08:39:34 15872 —-a-w- C:\Windows\SysWow64\nlmproxy.dll 2013-02-02 08:39:34 12288 —-a-w- C:\Windows\SysWow64\nlmsprep.dll 2013-02-02 08:39:33 115712 —-a-w- C:\Windows\SysWow64\netprofm.dll 2013-02-02 08:39:15 157696 —-a-w- C:\Windows\SysWow64\mbsmsapi.dll 2013-02-02 08:38:54 567808 —-a-w- C:\Windows\SysWow64\duser.dll 2013-02-02 08:24:19 107520 —-a-w- C:\Windows\System32\taskkill.exe 2013-02-02 08:24:19 102400 —-a-w- C:\Windows\System32\tasklist.exe 2013-02-02 08:23:44 228352 —-a-w- C:\Windows\System32\XpsRasterService.dll . ============= FINISH: 9:52:13.50 ===============
Since aswMBR seems to be freezing try the following (don't forget about AdwCleaner as well):

[external image: Posted Image] Please download TDSSKiller
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-

[external image: Posted Image]
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-
# AdwCleaner v2.300 - Logfile created 05/06/2013 at 17:46:44
# Updated 28/04/2013 by Xplode
# Operating system : Windows 8 (64 bits)
# User : Dustin Arbuthnot - DUSTINS-RIG
# Boot Mode : Normal
# Running from : E:\Program Files (x86)\WhatTheTech\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110211621176}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110211621176}
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0026276.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0026276.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0026276.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0026276.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440244624476}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211621176}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{11111111-1111-1111-1111-110211621176}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{22222222-2222-2222-2222-220222622276}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{55555555-5555-5555-5555-550255625576}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66666666-6666-6666-6666-660266626676}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211621176}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211621176}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211621176}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550255625576}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660266626676}

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16537

[OK] Registry is clean.

-\\ Google Chrome v26.0.1410.64

File : C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [2566 octets] - [04/05/2013 17:43:00]
AdwCleaner[R2].txt - [2626 octets] - [04/05/2013 17:50:45]
AdwCleaner[S1].txt - [2601 octets] - [06/05/2013 17:46:44]

########## EOF - C:\AdwCleaner[S1].txt - [2661 octets] ##########





OTL logfile created on: 6/05/2013 17:53:28 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\Program Files (x86)\WhatTheTech
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

15.96 Gb Total Physical Memory | 13.66 Gb Available Physical Memory | 85.60% Memory free
18.21 Gb Paging File | 15.85 Gb Available in Paging File | 87.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 118.90 Gb Total Space | 77.76 Gb Free Space | 65.40% Space Free | Partition Type: NTFS
Drive E: | 1863.01 Gb Total Space | 1801.33 Gb Free Space | 96.69% Space Free | Partition Type: NTFS

Computer Name: DUSTINS-RIG | User Name: Dustin Arbuthnot | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - E:\Program Files (x86)\WhatTheTech\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - E:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Corsair\CorsairLINK2\CorsairLINK_HardwareMonitor.exe (Corsair Components, Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - E:\Program Files (x86)\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\500a5dd33bb40326f8ca43e385513ec2\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorDataMcfeeca6f#\1d3541ab8cf202fb41bc2096ae745aa3\IAStorDataMgrSvcInterfaces.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorCommon\70055c8d4365c5b72194e19d03d3bec9\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorUtil\1a2488b08400b3527fc0153fecbacf49\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\89cc9825811c2121acd4e2e12c0ef044\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\9a4fc56833542881e7e451a099562655\System.ServiceModel.Internals.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servf73e6522#\07e482b2b9035605233f2cb72408d6b1\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\e1ec8b9a6d4f9af9d6065c4187fb1b5f\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\9c95779cc3d65cda80695cabc367476b\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f641b786d36d1cc5a5531a746c96ce1b\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\115fb9d1fa2cbda89742b1c2a0631396\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\cf7db4fae047127374f220b4f59bea45\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\38638a559066bf7f2325a53ed53629bc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\cb1bedf1f9e8972aa76ad73f725b964b\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\05cc6faa6704d01e78700561b22937e3\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\0247de206c1c48ac4f8b55df16468405\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\a7811936e59aaee26b1d9d467174d6d4\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\374a0cc6603f58864831897ef723bd4a\mscorlib.ni.dll ()
MOD - E:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - E:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - E:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Program Files (x86)\Corsair\CorsairLINK2\SynchronousIO.Native.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - E:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - E:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - E:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (TimeBroker) – C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) – C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) – C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (wlidsvc) – C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (LSM) – C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) – C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (WSService) – C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) – C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) – C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (PrintNotify) – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (WiaRpc) – C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) – C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) – C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) – C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) – C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) – C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) – C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) – C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (EFS) – C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) – C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) – C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (AllUserInstallAgent) – C:\Windows\SysNative\AUInstallAgent.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) – E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Qualcomm Atheros Commnucations)
SRV - (ZAtheros Bt&Wlan; Coex Agent) – C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (PrintNotify) – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (StorSvc) – C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (KLIF) – C:\Windows\SysNative\Drivers\klif.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kneps) – C:\Windows\SysNative\Drivers\kneps.sys (Kaspersky Lab ZAO)
DRV:64bit: - (klwfp) – C:\Windows\SysNative\Drivers\klwfp.sys (Kaspersky Lab ZAO)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\Drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\Drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (klkbdflt) – C:\Windows\SysNative\Drivers\klkbdflt.sys (Kaspersky Lab)
DRV:64bit: - (USBXHCI) – C:\Windows\SysNative\Drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (spaceport) – C:\Windows\SysNative\Drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (storahci) – C:\Windows\SysNative\Drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (TPM) – C:\Windows\SysNative\Drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\Drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (pdc) – C:\Windows\SysNative\Drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) – C:\Windows\SysNative\Drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) – C:\Windows\SysNative\Drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) – C:\Windows\SysNative\Drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\Drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (msgpiowin32) – C:\Windows\SysNative\Drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (bthhfhid) – C:\Windows\SysNative\Drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) – C:\Windows\SysNative\Drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) – C:\Windows\SysNative\Drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\Drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) – C:\Windows\SysNative\Drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (dam) – C:\Windows\SysNative\Drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (UCX01000) – C:\Windows\SysNative\Drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (GPIOClx0101) – C:\Windows\SysNative\Drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\Drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\Drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (iaStorA) – C:\Windows\SysNative\Drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\Drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (BtFilter) – C:\Windows\SysNative\Drivers\btfilter.sys (Qualcomm Atheros)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\Drivers\btath_rcp.sys (Qualcomm Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\Drivers\btath_lwflt.sys (Qualcomm Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\Drivers\btath_hcrp.sys (Qualcomm Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\Drivers\btath_flt.sys (Qualcomm Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\Drivers\btath_a2dp.sys (Qualcomm Atheros)
DRV:64bit: - (btath_avdt) – C:\Windows\SysNative\Drivers\btath_avdt.sys (Qualcomm Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\Drivers\btath_bus.sys (Qualcomm Atheros)
DRV:64bit: - (klelam) – C:\Windows\SysNative\Drivers\klelam.sys (Kaspersky Lab)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (condrv) – C:\Windows\SysNative\Drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (VSTXRAID) – C:\Windows\SysNative\Drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (VerifierExt) – C:\Windows\SysNative\Drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (UASPStor) – C:\Windows\SysNative\Drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) – C:\Windows\SysNative\Drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) – C:\Windows\SysNative\Drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\Drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\Drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) – C:\Windows\SysNative\Drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\Drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (EhStorTcgDrv) – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) – C:\Windows\SysNative\Drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\Drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) – C:\Windows\SysNative\Drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\Drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\Drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CLFS) – C:\Windows\SysNative\Drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) – C:\Windows\SysNative\Drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (vpci) – C:\Windows\SysNative\Drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) – C:\Windows\SysNative\Drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\Drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) – C:\Windows\SysNative\Drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) – C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) – C:\Windows\SysNative\Drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) – C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) – C:\Windows\SysNative\Drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) – C:\Windows\SysNative\Drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) – C:\Windows\SysNative\Drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) – C:\Windows\SysNative\Drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) – C:\Windows\SysNative\Drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) – C:\Windows\SysNative\Drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) – C:\Windows\SysNative\Drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) – C:\Windows\SysNative\Drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) – C:\Windows\SysNative\Drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\Drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) – C:\Windows\SysNative\Drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) – C:\Windows\SysNative\Drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\Drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) – C:\Windows\SysNative\Drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (BthLEEnum) – C:\Windows\SysNative\Drivers\BthLEEnum.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) – C:\Windows\SysNative\Drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) – C:\Windows\SysNative\Drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) – C:\Windows\SysNative\Drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\Drivers\athw8x.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (L1C) – C:\Windows\SysNative\Drivers\L1C63x64.sys (Qualcomm Atheros Co., Ltd.)
DRV:64bit: - (kl1) – C:\Windows\SysNative\Drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (e1iexpress) – C:\Windows\SysNative\Drivers\e1i63x64.sys (Intel Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\Drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (DAdderFltr) – C:\Windows\SysNative\Drivers\dadder.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (gdrv) – C:\Windows\gdrv.sys (Windows ® Server 2003 DDK provider)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-AU
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D5 82 9F 69 01 43 CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: E:\Program Files (x86)\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0: C:\Program Files (x86)\Free Ride Games\npExentCtl.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\www.exent.com/GameTreatWidget: C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013/04/27 22:23:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013/04/27 22:23:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013/04/27 22:23:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013/04/27 22:23:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[removed] [2013/04/27 22:23:14 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - Extension: Google Docs = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0\
CHR - Extension: Deal Spy = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\crossrider
CHR - Extension: Deal Spy = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\
CHR - Extension: Photo Zoom for Facebook = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi\1.1208.30.1_0\
CHR - Extension: AdBlock = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.63_0\
CHR - Extension: Safe Money = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0\
CHR - Extension: Content Blocker = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\13.0.1.4190_0\
CHR - Extension: Virtual Keyboard = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4292_0\
CHR - Extension: Gmail = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Anti-Banner = C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0\

O1 HOSTS File: ([2012/07/26 15:26:49 | 000,000,824 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O2:64bit: - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O4:64bit: - HKLM..\Run: [BtTray] C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Qualcomm Atheros)
O4:64bit: - HKLM..\Run: [BtvStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Qualcomm Atheros Commnucations)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] E:\Program Files (x86)\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LGODDFU] C:\Program Files (x86)\lg_fwupdate\lgfw.exe (Bitleader)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\Run: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup File not found
O4 - HKCU..\Run: [Steam] E:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4EFC8E57-66CC-4817-ABBA-C5803E3E7846}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA73159C-0151-4364-8BD4-E04CA6951ED4}: DhcpNameServer = 192.168.1.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 0
O33 - MountPoints2\{c11f07c8-aeed-11e2-be65-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{c11f07c8-aeed-11e2-be65-806e6f6e6963}\Shell\AutoRun\command - "" = "D:\setup.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/04 11:02:06 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Corsair
[2013/05/04 11:01:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Silabs
[2013/05/04 11:01:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corsair
[2013/05/04 11:01:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Corsair
[2013/05/04 09:57:09 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\CrashDumps
[2013/05/04 09:53:35 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Dustin Arbuthnot\Desktop\aswMBR.exe
[2013/05/02 18:36:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey
[2013/05/02 18:16:16 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\NVIDIA
[2013/05/02 06:24:50 | 000,301,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\newdev.dll
[2013/05/02 06:24:50 | 000,275,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\newdev.dll
[2013/05/02 06:24:50 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\newdev.exe
[2013/05/02 06:24:50 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ndadmin.exe
[2013/05/02 06:24:50 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\newdev.exe
[2013/05/02 06:24:50 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ndadmin.exe
[2013/05/02 06:24:50 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/05/02 06:24:43 | 001,184,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Display.dll
[2013/05/02 06:24:43 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Display.dll
[2013/05/02 06:24:43 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KBDKURD.DLL
[2013/05/02 06:24:43 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\KBDKURD.DLL
[2013/05/02 06:24:41 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WSShared.dll
[2013/05/02 06:24:41 | 000,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WSShared.dll
[2013/05/02 06:24:41 | 000,198,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.ApplicationModel.Store.dll
[2013/05/02 06:24:41 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.ApplicationModel.Store.TestingFramework.dll
[2013/05/02 06:24:41 | 000,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll
[2013/05/02 06:24:41 | 000,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
[2013/05/02 06:24:33 | 011,459,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\glcndFilter.dll
[2013/05/02 06:24:30 | 008,552,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\glcndFilter.dll
[2013/05/02 06:24:30 | 001,566,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ole32.dll
[2013/05/02 06:24:30 | 001,526,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfcore.dll
[2013/05/02 06:24:30 | 001,451,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfcore.dll
[2013/05/02 06:24:30 | 001,037,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\localspl.dll
[2013/05/02 06:24:30 | 000,976,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/05/02 06:24:29 | 000,883,712 | —- | C] (Microsoft Corporation) – C:\Windows\HelpPane.exe
[2013/05/02 06:24:29 | 000,522,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AUDIOKSE.dll
[2013/05/02 06:24:29 | 000,501,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevicePairing.dll
[2013/05/02 06:24:29 | 000,490,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AudioEng.dll
[2013/05/02 06:24:29 | 000,470,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wlanmsm.dll
[2013/05/02 06:24:29 | 000,463,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\AUDIOKSE.dll
[2013/05/02 06:24:29 | 000,447,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AudioSes.dll
[2013/05/02 06:24:29 | 000,273,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wlanapi.dll
[2013/05/02 06:24:29 | 000,253,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\audiodg.exe
[2013/05/02 06:24:29 | 000,110,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dafWCN.dll
[2013/05/02 06:24:28 | 000,449,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DevicePairing.dll
[2013/05/02 06:24:28 | 000,446,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wlansec.dll
[2013/05/02 06:24:28 | 000,386,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wlanmsm.dll
[2013/05/02 06:24:28 | 000,375,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wlansec.dll
[2013/05/02 06:24:28 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpclip.exe
[2013/05/02 06:24:28 | 000,281,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2013/05/02 06:24:28 | 000,267,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDump.dll
[2013/05/02 06:24:28 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2013/05/02 06:24:28 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bthprops.cpl
[2013/05/02 06:24:28 | 000,202,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wlanapi.dll
[2013/05/02 06:24:28 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\bthprops.cpl
[2013/05/02 06:24:28 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFCaptureEngine.dll
[2013/05/02 06:24:28 | 000,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AudioEndpointBuilder.dll
[2013/05/02 06:24:28 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WcnApi.dll
[2013/05/02 06:24:28 | 000,126,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFCaptureEngine.dll
[2013/05/02 06:24:28 | 000,102,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fdWCN.dll
[2013/05/02 06:24:28 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WcnApi.dll
[2013/05/02 06:24:28 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wfdprov.dll
[2013/05/02 06:24:28 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WcnEapPeerProxy.dll
[2013/05/02 06:24:28 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WcnEapAuthProxy.dll
[2013/05/02 06:24:28 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wfdprov.dll
[2013/05/02 06:24:28 | 000,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fxppm.sys
[2013/05/02 06:24:28 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iscsilog.dll
[2013/05/02 06:24:28 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wlanhlp.dll
[2013/05/02 06:24:28 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wlanhlp.dll
[2013/05/02 06:24:22 | 000,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dskquota.dll
[2013/05/02 06:24:22 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dskquota.dll
[2013/05/02 06:24:18 | 001,172,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfnetsrc.dll
[2013/05/02 06:24:18 | 000,929,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfnetsrc.dll
[2013/05/02 06:24:18 | 000,396,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\hal.dll
[2013/05/02 06:24:17 | 000,677,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfnetcore.dll
[2013/05/02 06:24:17 | 000,673,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmpeg2srcsnk.dll
[2013/05/02 06:24:17 | 000,568,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfnetcore.dll
[2013/05/02 06:24:17 | 000,513,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmpeg2srcsnk.dll
[2013/05/02 06:24:08 | 003,554,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2013/05/02 06:24:07 | 002,116,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2013/05/02 06:24:06 | 002,764,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2013/05/02 06:24:06 | 002,380,944 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/05/02 06:24:06 | 002,206,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dwmcore.dll
[2013/05/02 06:24:06 | 002,115,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2013/05/02 06:24:06 | 001,841,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dwmcore.dll
[2013/05/02 06:24:06 | 001,610,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2013/05/02 06:24:06 | 001,395,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.UI.Immersive.dll
[2013/05/02 06:24:06 | 001,265,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/05/02 06:24:06 | 000,579,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\StructuredQuery.dll
[2013/05/02 06:24:05 | 001,403,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2013/05/02 06:24:05 | 001,267,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2013/05/02 06:24:05 | 001,226,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.UI.Immersive.dll
[2013/05/02 06:24:05 | 001,217,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2013/05/02 06:24:05 | 001,093,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2013/05/02 06:24:05 | 001,045,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usercpl.dll
[2013/05/02 06:24:05 | 000,793,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfplat.dll
[2013/05/02 06:24:05 | 000,612,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfplat.dll
[2013/05/02 06:24:05 | 000,590,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SHCore.dll
[2013/05/02 06:24:05 | 000,561,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4srcsnk.dll
[2013/05/02 06:24:05 | 000,517,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2013/05/02 06:24:05 | 000,460,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SHCore.dll
[2013/05/02 06:24:05 | 000,441,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2013/05/02 06:24:05 | 000,435,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2013/05/02 06:24:05 | 000,411,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4srcsnk.dll
[2013/05/02 06:24:05 | 000,373,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2013/05/02 06:24:05 | 000,286,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\portcls.sys
[2013/05/02 06:24:04 | 000,962,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\usercpl.dll
[2013/05/02 06:24:04 | 000,745,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2013/05/02 06:24:04 | 000,658,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2013/05/02 06:24:04 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SpaceControl.dll
[2013/05/02 06:24:04 | 000,503,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ci.dll
[2013/05/02 06:24:04 | 000,408,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2013/05/02 06:24:04 | 000,259,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\input.dll
[2013/05/02 06:24:04 | 000,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcore6.dll
[2013/05/02 06:24:04 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\input.dll
[2013/05/02 06:24:04 | 000,204,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dhcpcore6.dll
[2013/05/02 06:24:04 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2013/05/02 06:24:04 | 000,154,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Storage.Compression.dll
[2013/05/02 06:24:04 | 000,116,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Storage.Compression.dll
[2013/05/02 06:24:04 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2013/05/02 06:24:04 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dhcpcsvc6.dll
[2013/05/02 06:24:04 | 000,058,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dam.sys
[2013/05/02 06:24:04 | 000,056,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sdstor.sys
[2013/05/02 06:24:04 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\microsoft-windows-pdc.dll
[2013/05/02 06:24:04 | 000,033,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\battc.sys
[2013/05/02 06:24:03 | 001,836,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/05/02 06:24:03 | 001,294,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/05/02 06:24:03 | 000,757,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FirewallAPI.dll
[2013/05/02 06:24:03 | 000,370,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SysFxUI.dll
[2013/05/02 06:24:03 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2013/05/02 06:24:03 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppxSip.dll
[2013/05/02 06:24:03 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icfupgd.dll
[2013/05/02 06:24:03 | 000,102,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssitlb.dll
[2013/05/02 06:24:03 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\AppxSip.dll
[2013/05/02 06:24:03 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssprxy.dll
[2013/05/02 06:24:03 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssitlb.dll
[2013/05/02 06:24:03 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PCPKsp.dll
[2013/05/02 06:24:03 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BdeUISrv.exe
[2013/05/02 06:24:03 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2013/05/02 06:24:03 | 000,047,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PCPKsp.dll
[2013/05/02 06:24:03 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wfapigp.dll
[2013/05/02 06:24:03 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wfapigp.dll
[2013/05/02 06:24:02 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\drmk.sys
[2013/05/02 06:24:02 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msshooks.dll
[2013/05/02 06:24:02 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msshooks.dll
[2013/05/02 06:24:02 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kbdhebl3.dll
[2013/05/02 06:24:02 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\kbdhebl3.dll
[2013/05/02 06:24:00 | 001,131,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentServer.dll
[2013/05/02 06:24:00 | 000,707,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2013/05/02 06:23:57 | 003,245,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2013/05/02 06:23:56 | 001,536,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\storagewmi.dll
[2013/05/02 06:23:56 | 001,217,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\storagewmi.dll
[2013/05/02 06:23:56 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2013/05/02 06:23:56 | 001,122,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Taskmgr.exe
[2013/05/02 06:23:56 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2013/05/02 06:23:56 | 001,027,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Taskmgr.exe
[2013/05/02 06:23:56 | 000,955,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WebcamUi.dll
[2013/05/02 06:23:56 | 000,798,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WebcamUi.dll
[2013/05/02 06:23:56 | 000,631,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UserLanguagesCpl.dll
[2013/05/02 06:23:56 | 000,560,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UserLanguagesCpl.dll
[2013/05/02 06:23:56 | 000,244,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpnapps.dll
[2013/05/02 06:23:56 | 000,190,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vdsutil.dll
[2013/05/02 06:23:56 | 000,179,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wpnapps.dll
[2013/05/02 06:23:56 | 000,027,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013/05/02 06:23:55 | 000,888,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\nshwfp.dll
[2013/05/02 06:23:55 | 000,702,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\nshwfp.dll
[2013/05/02 06:23:55 | 000,378,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FWPUCLNT.DLL
[2013/05/02 06:23:55 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\FWPUCLNT.DLL
[2013/05/02 06:23:55 | 000,235,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2013/05/02 06:23:55 | 000,120,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vds_ps.dll
[2013/05/02 06:23:55 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\vds_ps.dll
[2013/05/02 06:23:55 | 000,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rfxvmt.dll
[2013/05/02 06:23:55 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vdsldr.exe
[2013/05/02 06:23:54 | 000,368,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sppwinob.dll
[2013/05/02 06:23:41 | 002,367,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WSService.dll
[2013/05/02 06:23:38 | 003,265,256 | —- | C] (Broadcom Corporation) – C:\Windows\SysNative\drivers\evbda.sys
[2013/05/02 06:23:36 | 014,259,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2013/05/02 06:23:34 | 002,397,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpcMon.exe
[2013/05/02 06:23:33 | 003,847,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/05/02 06:23:32 | 011,875,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2013/05/02 06:23:32 | 003,964,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WinSAT.exe
[2013/05/02 06:23:32 | 000,533,224 | —- | C] (Broadcom Corporation) – C:\Windows\SysNative\drivers\bxvbda.sys
[2013/05/02 06:23:31 | 001,825,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/05/02 06:23:31 | 001,513,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vssapi.dll
[2013/05/02 06:23:30 | 002,219,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/05/02 06:23:30 | 001,739,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RacEngn.dll
[2013/05/02 06:23:30 | 001,304,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Media.Streaming.dll
[2013/05/02 06:23:30 | 001,019,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.dll
[2013/05/02 06:23:29 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\provcore.dll
[2013/05/02 06:23:29 | 000,757,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\uDWM.dll
[2013/05/02 06:23:29 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WinSATAPI.dll
[2013/05/02 06:23:29 | 000,389,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MMDevAPI.dll
[2013/05/02 06:23:28 | 001,743,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\combase.dll
[2013/05/02 06:23:28 | 000,995,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Media.Streaming.dll
[2013/05/02 06:23:28 | 000,709,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsSpellCheckingFacility.dll
[2013/05/02 06:23:28 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apphelp.dll
[2013/05/02 06:23:28 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IPHLPAPI.DLL
[2013/05/02 06:23:27 | 001,400,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\propsys.dll
[2013/05/02 06:23:27 | 000,866,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WinTypes.dll
[2013/05/02 06:23:27 | 000,755,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fveapi.dll
[2013/05/02 06:23:27 | 000,617,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfsrcsnk.dll
[2013/05/02 06:23:27 | 000,604,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnsapi.dll
[2013/05/02 06:23:27 | 000,545,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskeng.exe
[2013/05/02 06:23:27 | 000,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WWAHost.exe
[2013/05/02 06:23:27 | 000,355,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfsvr.dll
[2013/05/02 06:23:27 | 000,344,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wlidcredprov.dll
[2013/05/02 06:23:27 | 000,332,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/05/02 06:23:27 | 000,249,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpnprv.dll
[2013/05/02 06:23:27 | 000,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFPlay.dll
[2013/05/02 06:23:27 | 000,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bcdsrv.dll
[2013/05/02 06:23:27 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rascfg.dll
[2013/05/02 06:23:27 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rascfg.dll
[2013/05/02 06:23:26 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\appwiz.cpl
[2013/05/02 06:23:26 | 000,541,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\VAN.dll
[2013/05/02 06:23:26 | 000,410,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\services.exe
[2013/05/02 06:23:26 | 000,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WinSATAPI.dll
[2013/05/02 06:23:26 | 000,240,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fveapibase.dll
[2013/05/02 06:23:26 | 000,203,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WSClient.dll
[2013/05/02 06:23:26 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bisrv.dll
[2013/05/02 06:23:26 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psmsrv.dll
[2013/05/02 06:23:25 | 001,369,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RacEngn.dll
[2013/05/02 06:23:25 | 000,670,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\appwiz.cpl
[2013/05/02 06:23:25 | 000,457,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpncore.dll
[2013/05/02 06:23:25 | 000,390,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Networking.BackgroundTransfer.dll
[2013/05/02 06:23:25 | 000,333,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WWAHost.exe
[2013/05/02 06:23:25 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhengine.dll
[2013/05/02 06:23:25 | 000,228,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ProximityService.dll
[2013/05/02 06:23:25 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFPlay.dll
[2013/05/02 06:23:25 | 000,177,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WSSync.dll
[2013/05/02 06:23:25 | 000,172,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dwmredir.dll
[2013/05/02 06:23:25 | 000,166,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WSClient.dll
[2013/05/02 06:23:25 | 000,154,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WSSync.dll
[2013/05/02 06:23:25 | 000,120,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\msgpioclx.sys
[2013/05/02 06:23:25 | 000,112,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PackageStateRoaming.dll
[2013/05/02 06:23:25 | 000,090,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TpmTasks.dll
[2013/05/02 06:23:24 | 002,016,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\batmeter.dll
[2013/05/02 06:23:24 | 002,007,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\batmeter.dll
[2013/05/02 06:23:24 | 001,247,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\combase.dll
[2013/05/02 06:23:24 | 000,533,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\provcore.dll
[2013/05/02 06:23:24 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\twinapi.dll
[2013/05/02 06:23:24 | 000,480,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\VAN.dll
[2013/05/02 06:23:24 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WinTypes.dll
[2013/05/02 06:23:24 | 000,449,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfsrcsnk.dll
[2013/05/02 06:23:24 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfsvr.dll
[2013/05/02 06:23:24 | 000,263,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wlidcredprov.dll
[2013/05/02 06:23:24 | 000,256,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvproc.dll
[2013/05/02 06:23:24 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\microsoft-windows-kernel-power-events.dll
[2013/05/02 06:23:24 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SettingSyncHost.exe
[2013/05/02 06:23:24 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PackageStateRoaming.dll
[2013/05/02 06:23:24 | 000,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\setbcdlocale.dll
[2013/05/02 06:23:24 | 000,062,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dumpfve.sys
[2013/05/02 06:23:24 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\perfdisk.dll
[2013/05/02 06:23:24 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\perfdisk.dll
[2013/05/02 06:23:24 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\svchost.exe
[2013/05/02 06:23:24 | 000,027,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\avrt.dll
[2013/05/02 06:23:23 | 001,342,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\user32.dll
[2013/05/02 06:23:23 | 000,699,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\twinapi.dll
[2013/05/02 06:23:23 | 000,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lpksetup.exe
[2013/05/02 06:23:23 | 000,459,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/05/02 06:23:23 | 000,437,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfh264enc.dll
[2013/05/02 06:23:23 | 000,413,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfh264enc.dll
[2013/05/02 06:23:23 | 000,315,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhcfg.dll
[2013/05/02 06:23:23 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Networking.BackgroundTransfer.dll
[2013/05/02 06:23:23 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvproc.dll
[2013/05/02 06:23:23 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/05/02 06:23:23 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DAFWSD.dll
[2013/05/02 06:23:23 | 000,118,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevPropMgr.dll
[2013/05/02 06:23:23 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dwm.exe
[2013/05/02 06:23:23 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drvinst.exe
[2013/05/02 06:23:23 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SettingSyncHost.exe
[2013/05/02 06:23:23 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drvinst.exe
[2013/05/02 06:23:23 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhevents.dll
[2013/05/02 06:23:23 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\perfnet.dll
[2013/05/02 06:23:22 | 002,066,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/05/02 06:23:22 | 001,701,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/05/02 06:23:22 | 000,588,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2013/05/02 06:23:22 | 000,417,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2013/05/02 06:23:22 | 000,280,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhcat.dll
[2013/05/02 06:23:22 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\perfos.dll
[2013/05/02 06:23:22 | 000,163,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspicli.dll
[2013/05/02 06:23:22 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhmanagew.exe
[2013/05/02 06:23:22 | 000,137,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhshl.dll
[2013/05/02 06:23:22 | 000,116,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhsvc.dll
[2013/05/02 06:23:22 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lpremove.exe
[2013/05/02 06:23:22 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhsrchapi.dll
[2013/05/02 06:23:22 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rasdiag.dll
[2013/05/02 06:23:22 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vsstrace.dll
[2013/05/02 06:23:22 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhsrchph.dll
[2013/05/02 06:23:22 | 000,064,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhlisten.dll
[2013/05/02 06:23:22 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rasdiag.dll
[2013/05/02 06:23:22 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhcleanup.dll
[2013/05/02 06:23:22 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhtask.dll
[2013/05/02 06:23:22 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/05/02 06:23:22 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sdbinst.exe
[2013/05/02 06:23:22 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/05/02 06:23:22 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sdbinst.exe
[2013/05/02 06:23:22 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\perfnet.dll
[2013/05/02 06:23:21 | 000,064,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhautoplay.dll
[2013/05/02 06:23:21 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ndptsp.tsp
[2013/05/02 06:23:21 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ndptsp.tsp
[2013/05/02 06:23:21 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kmddsp.tsp
[2013/05/02 06:23:21 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\perfctrs.dll
[2013/05/02 06:23:21 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rasmxs.dll
[2013/05/02 06:23:21 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\perfctrs.dll
[2013/05/02 06:23:21 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\kmddsp.tsp
[2013/05/02 06:23:21 | 000,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\perfproc.dll
[2013/05/02 06:23:21 | 000,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\LangCleanupSysprepAction.dll
[2013/05/02 06:23:21 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\perfproc.dll
[2013/05/02 06:23:21 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\perfos.dll
[2013/05/02 06:23:21 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rasmxs.dll
[2013/05/02 06:23:21 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rasser.dll
[2013/05/02 06:23:21 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sspisrv.dll
[2013/05/02 06:23:21 | 000,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rasser.dll
[2013/05/02 06:23:21 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhsvcctl.dll
[2013/05/02 06:23:21 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\eventcls.dll
[2013/05/02 06:23:21 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\eventcls.dll
[2013/05/02 06:23:21 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MUILanguageCleanup.dll
[2013/05/02 06:23:21 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\spwmp.dll
[2013/05/02 06:23:21 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lpksetupproxyserv.dll
[2013/05/02 06:23:20 | 009,374,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2013/05/02 06:23:20 | 009,374,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2013/05/02 06:23:20 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\spwmp.dll
[2013/05/02 06:23:20 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shimeng.dll
[2013/05/02 06:23:20 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdxm.ocx
[2013/05/02 06:23:20 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxmasf.dll
[2013/05/02 06:23:20 | 000,004,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msdxm.ocx
[2013/05/02 06:23:20 | 000,004,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxmasf.dll
[2013/05/01 18:41:23 | 000,000,000 | —D | C] – C:\ProgramData\Creative
[2013/05/01 18:41:13 | 000,000,000 | —D | C] – C:\ProgramData\Creative Labs
[2013/05/01 18:38:33 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2013/05/01 18:38:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/05/01 18:38:30 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/05/01 18:38:30 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/05/01 18:38:30 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/05/01 18:38:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2013/05/01 18:38:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2013/05/01 18:37:58 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2013/05/01 18:37:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2013/05/01 18:37:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2013/05/01 18:35:48 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/05/01 18:33:44 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Apple Computer
[2013/05/01 18:33:44 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Apple Computer
[2013/05/01 18:33:41 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2013/05/01 18:33:35 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2013/05/01 18:33:15 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Apple
[2013/05/01 18:32:02 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2013/04/30 18:39:00 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Malwarebytes
[2013/04/30 18:38:47 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/04/30 18:38:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/04/30 18:38:47 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/04/30 18:32:26 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Programs
[2013/04/30 17:16:26 | 002,094,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mmc.exe
[2013/04/30 17:16:25 | 001,964,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wlidsvc.dll
[2013/04/30 17:16:25 | 001,886,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\setupapi.dll
[2013/04/30 17:16:25 | 001,611,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mmc.exe
[2013/04/30 17:16:25 | 001,120,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msctf.dll
[2013/04/30 17:16:25 | 000,594,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Networking.dll
[2013/04/30 17:16:25 | 000,438,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsm.dll
[2013/04/30 17:16:25 | 000,410,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Networking.dll
[2013/04/30 17:16:25 | 000,406,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Media.dll
[2013/04/30 17:16:25 | 000,028,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\msgpiowin32.sys
[2013/04/30 17:16:24 | 000,728,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\samsrv.dll
[2013/04/30 17:16:24 | 000,666,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MP4SDECD.DLL
[2013/04/30 17:16:24 | 000,436,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MP4SDECD.DLL
[2013/04/30 17:16:24 | 000,303,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/04/30 17:16:24 | 000,261,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Media.dll
[2013/04/30 17:16:24 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WSDMon.dll
[2013/04/30 17:16:24 | 000,171,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncbservice.dll
[2013/04/30 17:16:24 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetpp.dll
[2013/04/30 17:16:24 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\httpprxm.dll
[2013/04/30 17:16:24 | 000,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wiaacmgr.exe
[2013/04/30 17:16:24 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wiaacmgr.exe
[2013/04/30 17:16:24 | 000,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\adhsvc.dll
[2013/04/30 17:16:24 | 000,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\adhapi.dll
[2013/04/30 17:16:24 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\httpprxp.dll
[2013/04/30 17:16:24 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\keepaliveprovider.dll
[2013/04/30 17:16:16 | 000,017,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcr100_clr0400.dll
[2013/04/30 17:16:15 | 000,017,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr100_clr0400.dll
[2013/04/30 17:15:49 | 010,116,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\twinui.dll
[2013/04/30 17:15:49 | 001,161,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sppobjs.dll
[2013/04/30 17:15:48 | 008,857,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\twinui.dll
[2013/04/30 17:15:47 | 001,627,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/04/30 17:15:46 | 005,978,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/04/30 17:15:46 | 001,048,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfasfsrcsnk.dll
[2013/04/30 17:15:46 | 000,850,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfasfsrcsnk.dll
[2013/04/30 17:15:46 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ubpm.dll
[2013/04/30 17:15:45 | 005,091,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/04/30 17:15:45 | 002,302,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/04/30 17:15:45 | 002,033,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/04/30 17:15:45 | 001,619,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/04/30 17:15:45 | 001,149,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winmde.dll
[2013/04/30 17:15:45 | 001,101,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmpmde.dll
[2013/04/30 17:15:45 | 000,951,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Globalization.dll
[2013/04/30 17:15:45 | 000,760,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/04/30 17:15:45 | 000,645,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Security.Authentication.OnlineId.dll
[2013/04/30 17:15:45 | 000,411,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/04/30 17:15:45 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BCP47Langs.dll
[2013/04/30 17:15:45 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netcfgx.dll
[2013/04/30 17:15:45 | 000,332,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2013/04/30 17:15:45 | 000,327,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Classpnp.sys
[2013/04/30 17:15:45 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\BCP47Langs.dll
[2013/04/30 17:15:45 | 000,246,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ubpm.dll
[2013/04/30 17:15:45 | 000,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SystemEventsBrokerServer.dll
[2013/04/30 17:15:45 | 000,171,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TimeBrokerServer.dll
[2013/04/30 17:15:44 | 002,146,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\actxprxy.dll
[2013/04/30 17:15:44 | 000,893,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\winmde.dll
[2013/04/30 17:15:44 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drvstore.dll
[2013/04/30 17:15:44 | 000,621,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2013/04/30 17:15:44 | 000,601,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Globalization.dll
[2013/04/30 17:15:44 | 000,550,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drvstore.dll
[2013/04/30 17:15:44 | 000,504,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Security.Authentication.OnlineId.dll
[2013/04/30 17:15:44 | 000,455,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netcfgx.dll
[2013/04/30 17:15:44 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SettingSync.dll
[2013/04/30 17:15:44 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SettingSync.dll
[2013/04/30 17:15:44 | 000,337,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBXHCI.SYS
[2013/04/30 17:15:44 | 000,283,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\spaceport.sys
[2013/04/30 17:15:44 | 000,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUSettingsProvider.dll
[2013/04/30 17:15:44 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usbmon.dll
[2013/04/30 17:15:44 | 000,212,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\UCX01000.SYS
[2013/04/30 17:15:44 | 000,194,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sdbus.sys
[2013/04/30 17:15:44 | 000,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\powercfg.cpl
[2013/04/30 17:15:44 | 000,150,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\discan.dll
[2013/04/30 17:15:44 | 000,148,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\tpm.sys
[2013/04/30 17:15:44 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\powercfg.cpl
[2013/04/30 17:15:44 | 000,125,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dumpsd.sys
[2013/04/30 17:15:44 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\NdisImPlatform.dll
[2013/04/30 17:15:44 | 000,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/04/30 17:15:44 | 000,077,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storahci.sys
[2013/04/30 17:15:44 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhostex.exe
[2013/04/30 17:15:44 | 000,069,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\pdc.sys
[2013/04/30 17:15:44 | 000,058,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/04/30 17:15:44 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevDispItemProvider.dll
[2013/04/30 17:15:44 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2013/04/30 17:15:44 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2013/04/30 17:15:44 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuaext.dll
[2013/04/30 17:15:43 | 000,240,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsquirt.exe
[2013/04/30 17:15:43 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\storewuauth.dll
[2013/04/30 17:15:43 | 000,141,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/04/30 17:15:43 | 000,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SettingSyncInfo.dll
[2013/04/30 17:15:43 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2013/04/30 17:15:43 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SettingSyncInfo.dll
[2013/04/30 17:15:43 | 000,099,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wushareduxresources.dll
[2013/04/30 17:15:43 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/04/30 17:15:43 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2013/04/30 17:15:43 | 000,071,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WSDPrintProxy.DLL
[2013/04/30 17:15:43 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/04/30 17:15:43 | 000,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DevDispItemProvider.dll
[2013/04/30 17:15:43 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2013/04/30 17:15:43 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wups.dll
[2013/04/30 17:14:53 | 000,094,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\synceng.dll
[2013/04/30 17:14:53 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\synceng.dll
[2013/04/30 17:14:41 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/04/30 17:14:38 | 000,915,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\uxtheme.dll
[2013/04/30 17:14:38 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/04/30 17:14:38 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/04/30 17:14:38 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/04/30 17:14:38 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/04/30 17:14:38 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/04/30 17:14:38 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/04/30 17:14:38 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/04/30 17:14:38 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UXInit.dll
[2013/04/30 17:14:38 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/04/30 17:14:38 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UXInit.dll
[2013/04/30 17:14:38 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/04/30 17:14:38 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/04/30 17:14:14 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncryptsslp.dll
[2013/04/30 17:14:14 | 000,071,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ncryptsslp.dll
[2013/04/30 17:14:13 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tssdisai.dll
[2013/04/30 17:14:13 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\appserverai.dll
[2013/04/30 17:14:13 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RDWebAI.dll
[2013/04/30 17:14:13 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\VmHostAI.dll
[2013/04/30 17:14:12 | 000,148,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2013/04/30 17:14:12 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2013/04/30 17:14:00 | 006,991,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/04/30 17:13:55 | 002,893,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/04/30 17:13:55 | 002,400,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/04/30 17:13:50 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ReAgentc.exe
[2013/04/30 17:13:50 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ReAgentc.exe
[2013/04/30 17:13:49 | 001,011,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\reseteng.dll
[2013/04/30 17:13:49 | 000,945,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\resetengmig.dll
[2013/04/30 17:13:49 | 000,443,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ReAgent.dll
[2013/04/30 17:13:49 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ReAgent.dll
[2013/04/30 17:13:49 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sysreset.exe
[2013/04/30 17:13:46 | 013,643,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.UI.Xaml.dll
[2013/04/30 17:13:46 | 000,468,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFMediaEngine.dll
[2013/04/30 17:13:46 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFMediaEngine.dll
[2013/04/30 17:13:45 | 010,792,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013/04/30 17:13:44 | 000,731,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/04/30 17:13:44 | 000,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\duser.dll
[2013/04/30 17:13:44 | 000,543,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wlroamextension.dll
[2013/04/30 17:13:44 | 000,488,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2013/04/30 17:13:44 | 000,475,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WWanAPI.dll
[2013/04/30 17:13:44 | 000,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netprofmsvc.dll
[2013/04/30 17:13:44 | 000,446,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBHUB3.SYS
[2013/04/30 17:13:44 | 000,410,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wlroamextension.dll
[2013/04/30 17:13:44 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncsi.dll
[2013/04/30 17:13:44 | 000,370,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WWanAPI.dll
[2013/04/30 17:13:44 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Networking.Connectivity.dll
[2013/04/30 17:13:44 | 000,260,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\hotspotauth.dll
[2013/04/30 17:13:44 | 000,228,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2013/04/30 17:13:44 | 000,225,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mbsmsapi.dll
[2013/04/30 17:13:44 | 000,197,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Networking.Connectivity.dll
[2013/04/30 17:13:44 | 000,157,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mbsmsapi.dll
[2013/04/30 17:13:44 | 000,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2013/04/30 17:13:44 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskkill.exe
[2013/04/30 17:13:44 | 000,102,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tasklist.exe
[2013/04/30 17:13:44 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hidclass.sys
[2013/04/30 17:13:44 | 000,079,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskkill.exe
[2013/04/30 17:13:44 | 000,061,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\crashdmp.sys
[2013/04/30 17:13:44 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hidi2c.sys
[2013/04/30 17:13:44 | 000,037,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\BthAvrcpTg.sys
[2013/04/30 17:13:44 | 000,021,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2013/04/30 17:13:43 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpd_ci.dll
[2013/04/30 17:13:43 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tasklist.exe
[2013/04/30 17:13:43 | 000,029,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\BthhfHid.sys
[2013/04/30 17:13:43 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\BtaMPM.sys
[2013/04/30 17:13:43 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\nlmproxy.dll
[2013/04/30 17:13:43 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\nlmsprep.dll
[2013/04/30 17:13:33 | 001,690,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\GdiPlus.dll
[2013/04/30 17:13:33 | 001,437,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\GdiPlus.dll
[2013/04/30 17:13:26 | 000,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/04/30 17:13:23 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pcadm.dll
[2013/04/30 17:13:23 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pcalua.exe
[2013/04/30 17:13:23 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pcaevts.dll
[2013/04/30 17:13:22 | 000,463,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2013/04/30 17:13:22 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2013/04/30 17:13:22 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnathlp.dll
[2013/04/30 17:13:22 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnathlp.dll
[2013/04/30 17:13:22 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnsvr.exe
[2013/04/30 17:13:22 | 000,032,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnsvr.exe
[2013/04/30 17:13:22 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnhupnp.dll
[2013/04/30 17:13:22 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnhpast.dll
[2013/04/30 17:13:22 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnhupnp.dll
[2013/04/30 17:13:22 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnhpast.dll
[2013/04/30 17:13:22 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnlobby.dll
[2013/04/30 17:13:22 | 000,003,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnaddr.dll
[2013/04/30 17:13:22 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnlobby.dll
[2013/04/30 17:13:22 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnaddr.dll
[2013/04/30 17:13:17 | 000,362,496 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2013/04/30 17:13:17 | 000,300,032 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2013/04/30 17:13:17 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2013/04/30 17:13:17 | 000,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2013/04/30 17:13:17 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2013/04/30 17:13:17 | 000,035,328 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2013/04/30 17:13:17 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dciman32.dll
[2013/04/30 17:13:17 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lpk.dll
[2013/04/30 17:12:58 | 000,230,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdFilter.sys
[2013/04/30 17:12:58 | 000,035,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdBoot.sys
[2013/04/30 17:12:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml6r.dll
[2013/04/30 17:12:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml6r.dll
[2013/04/30 17:12:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2013/04/30 17:12:47 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2013/04/30 17:07:55 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\ElevatedDiagnostics
[2013/04/30 16:39:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\catroot2
[2013/04/30 07:08:47 | 000,000,000 | -HSD | C] – C:\found.000
[2013/04/29 21:40:15 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\Documents\temp
[2013/04/29 21:40:14 | 000,000,000 | —D | C] – C:\GvTemp
[2013/04/29 21:16:56 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Diagnostics
[2013/04/29 20:11:17 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\MediaMonkey
[2013/04/29 20:11:09 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\MediaMonkey
[2013/04/29 20:11:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MediaMonkey
[2013/04/29 20:11:08 | 000,000,000 | —D | C] – C:\ProgramData\MediaMonkey
[2013/04/28 21:57:10 | 000,000,000 | —D | C] – C:\Remote Programs
[2013/04/28 21:57:09 | 000,057,824 | —- | C] (Exent Technologies Ltd.) – C:\Windows\ExentInfo.exe
[2013/04/28 21:57:09 | 000,000,000 | —D | C] – C:\ProgramData\Free Ride Games
[2013/04/28 21:54:58 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Updater26276
[2013/04/28 21:54:56 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Deal Spy
[2013/04/28 20:17:06 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Natural Selection 2
[2013/04/28 20:17:05 | 000,530,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_6.dll
[2013/04/28 20:17:05 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_6.dll
[2013/04/28 20:17:05 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_6.dll
[2013/04/28 20:17:05 | 000,176,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_6.dll
[2013/04/28 20:17:05 | 000,078,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_4.dll
[2013/04/28 20:17:05 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_4.dll
[2013/04/28 20:17:04 | 005,554,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dcsx_42.dll
[2013/04/28 20:17:04 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dcsx_42.dll
[2013/04/28 20:17:04 | 002,582,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_42.dll
[2013/04/28 20:17:04 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_42.dll
[2013/04/28 20:17:04 | 000,517,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_5.dll
[2013/04/28 20:17:04 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_5.dll
[2013/04/28 20:17:04 | 000,285,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx11_42.dll
[2013/04/28 20:17:04 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_5.dll
[2013/04/28 20:17:04 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx11_42.dll
[2013/04/28 20:17:04 | 000,176,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_5.dll
[2013/04/28 20:17:04 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_7.dll
[2013/04/28 20:17:04 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_7.dll
[2013/04/28 20:17:03 | 005,425,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_41.dll
[2013/04/28 20:17:03 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_41.dll
[2013/04/28 20:17:03 | 002,475,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_42.dll
[2013/04/28 20:17:03 | 002,430,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_41.dll
[2013/04/28 20:17:03 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_42.dll
[2013/04/28 20:17:03 | 001,846,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_41.dll
[2013/04/28 20:17:03 | 000,523,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_42.dll
[2013/04/28 20:17:03 | 000,521,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_4.dll
[2013/04/28 20:17:03 | 000,520,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_41.dll
[2013/04/28 20:17:03 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_4.dll
[2013/04/28 20:17:03 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_42.dll
[2013/04/28 20:17:03 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_41.dll
[2013/04/28 20:17:03 | 000,073,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_3.dll
[2013/04/28 20:17:03 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_3.dll
[2013/04/28 20:17:02 | 002,605,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_40.dll
[2013/04/28 20:17:02 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_40.dll
[2013/04/28 20:17:02 | 000,519,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_40.dll
[2013/04/28 20:17:02 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_40.dll
[2013/04/28 20:17:02 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_4.dll
[2013/04/28 20:17:02 | 000,174,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_4.dll
[2013/04/28 20:17:02 | 000,024,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_6.dll
[2013/04/28 20:17:02 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_6.dll
[2013/04/28 20:17:01 | 005,631,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_40.dll
[2013/04/28 20:17:01 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_40.dll
[2013/04/28 20:17:01 | 000,518,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_3.dll
[2013/04/28 20:17:01 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_3.dll
[2013/04/28 20:17:01 | 000,513,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_2.dll
[2013/04/28 20:17:01 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2013/04/28 20:17:01 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_3.dll
[2013/04/28 20:17:01 | 000,175,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_3.dll
[2013/04/28 20:17:01 | 000,074,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_2.dll
[2013/04/28 20:17:01 | 000,072,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_1.dll
[2013/04/28 20:17:01 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_2.dll
[2013/04/28 20:17:01 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2013/04/28 20:17:01 | 000,025,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_5.dll
[2013/04/28 20:17:01 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_5.dll
[2013/04/28 20:17:00 | 004,992,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_39.dll
[2013/04/28 20:17:00 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2013/04/28 20:17:00 | 001,942,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_39.dll
[2013/04/28 20:17:00 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2013/04/28 20:17:00 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_39.dll
[2013/04/28 20:17:00 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2013/04/28 20:17:00 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_2.dll
[2013/04/28 20:17:00 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_2.dll
[2013/04/28 20:16:59 | 004,991,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_38.dll
[2013/04/28 20:16:59 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_38.dll
[2013/04/28 20:16:59 | 001,941,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_38.dll
[2013/04/28 20:16:59 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_38.dll
[2013/04/28 20:16:59 | 000,540,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_38.dll
[2013/04/28 20:16:59 | 000,511,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_1.dll
[2013/04/28 20:16:59 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_1.dll
[2013/04/28 20:16:59 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_38.dll
[2013/04/28 20:16:59 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_1.dll
[2013/04/28 20:16:59 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_1.dll
[2013/04/28 20:16:59 | 000,068,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAPOFX1_0.dll
[2013/04/28 20:16:59 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_0.dll
[2013/04/28 20:16:59 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_4.dll
[2013/04/28 20:16:59 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_4.dll
[2013/04/28 20:16:58 | 004,910,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DX9_37.dll
[2013/04/28 20:16:58 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_37.dll
[2013/04/28 20:16:58 | 001,860,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_37.dll
[2013/04/28 20:16:58 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_37.dll
[2013/04/28 20:16:58 | 000,529,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_37.dll
[2013/04/28 20:16:58 | 000,489,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XAudio2_0.dll
[2013/04/28 20:16:58 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_0.dll
[2013/04/28 20:16:58 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_37.dll
[2013/04/28 20:16:58 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine3_0.dll
[2013/04/28 20:16:58 | 000,177,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine3_0.dll
[2013/04/28 20:16:58 | 000,028,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_3.dll
[2013/04/28 20:16:58 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_3.dll
[2013/04/28 20:16:57 | 005,081,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_36.dll
[2013/04/28 20:16:57 | 005,073,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_35.dll
[2013/04/28 20:16:57 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_36.dll
[2013/04/28 20:16:57 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_35.dll
[2013/04/28 20:16:57 | 002,006,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_36.dll
[2013/04/28 20:16:57 | 001,985,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_35.dll
[2013/04/28 20:16:57 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_36.dll
[2013/04/28 20:16:57 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_35.dll
[2013/04/28 20:16:57 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_36.dll
[2013/04/28 20:16:57 | 000,508,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_35.dll
[2013/04/28 20:16:57 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_36.dll
[2013/04/28 20:16:57 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_35.dll
[2013/04/28 20:16:57 | 000,411,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_10.dll
[2013/04/28 20:16:57 | 000,411,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_9.dll
[2013/04/28 20:16:57 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_10.dll
[2013/04/28 20:16:57 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_9.dll
[2013/04/28 20:16:56 | 004,496,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_34.dll
[2013/04/28 20:16:56 | 004,494,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_33.dll
[2013/04/28 20:16:56 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_34.dll
[2013/04/28 20:16:56 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_33.dll
[2013/04/28 20:16:56 | 001,401,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_34.dll
[2013/04/28 20:16:56 | 001,400,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\D3DCompiler_33.dll
[2013/04/28 20:16:56 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_34.dll
[2013/04/28 20:16:56 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_33.dll
[2013/04/28 20:16:56 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_34.dll
[2013/04/28 20:16:56 | 000,506,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10_33.dll
[2013/04/28 20:16:56 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_34.dll
[2013/04/28 20:16:56 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_33.dll
[2013/04/28 20:16:56 | 000,409,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_8.dll
[2013/04/28 20:16:56 | 000,403,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_7.dll
[2013/04/28 20:16:56 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_8.dll
[2013/04/28 20:16:56 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_7.dll
[2013/04/28 20:16:56 | 000,107,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_3.dll
[2013/04/28 20:16:56 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_3.dll
[2013/04/28 20:16:56 | 000,021,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\X3DAudio1_2.dll
[2013/04/28 20:16:56 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\X3DAudio1_2.dll
[2013/04/28 20:16:55 | 004,398,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_32.dll
[2013/04/28 20:16:55 | 003,977,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_31.dll
[2013/04/28 20:16:55 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_31.dll
[2013/04/28 20:16:55 | 001,132,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_32.dll
[2013/04/28 20:16:55 | 000,469,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx10.dll
[2013/04/28 20:16:55 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10.dll
[2013/04/28 20:16:55 | 000,393,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_6.dll
[2013/04/28 20:16:55 | 000,390,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_5.dll
[2013/04/28 20:16:55 | 000,364,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_4.dll
[2013/04/28 20:16:55 | 000,363,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_3.dll
[2013/04/28 20:16:55 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_6.dll
[2013/04/28 20:16:55 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_5.dll
[2013/04/28 20:16:55 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_4.dll
[2013/04/28 20:16:55 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_3.dll
[2013/04/28 20:16:55 | 000,017,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_1.dll
[2013/04/28 20:16:55 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_1.dll
[2013/04/28 20:16:54 | 000,354,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_2.dll
[2013/04/28 20:16:54 | 000,352,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_1.dll
[2013/04/28 20:16:54 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_2.dll
[2013/04/28 20:16:54 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_1.dll
[2013/04/28 20:16:54 | 000,083,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_2.dll
[2013/04/28 20:16:54 | 000,083,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xinput1_1.dll
[2013/04/28 20:16:54 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_2.dll
[2013/04/28 20:16:54 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xinput1_1.dll
[2013/04/28 20:16:53 | 003,927,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_30.dll
[2013/04/28 20:16:53 | 003,830,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_29.dll
[2013/04/28 20:16:53 | 003,815,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_28.dll
[2013/04/28 20:16:53 | 003,807,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_27.dll
[2013/04/28 20:16:53 | 003,767,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_26.dll
[2013/04/28 20:16:53 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_30.dll
[2013/04/28 20:16:53 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_29.dll
[2013/04/28 20:16:53 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_28.dll
[2013/04/28 20:16:53 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_27.dll
[2013/04/28 20:16:53 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_26.dll
[2013/04/28 20:16:53 | 000,355,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xactengine2_0.dll
[2013/04/28 20:16:53 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xactengine2_0.dll
[2013/04/28 20:16:53 | 000,016,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\x3daudio1_0.dll
[2013/04/28 20:16:53 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\x3daudio1_0.dll
[2013/04/28 20:16:52 | 003,823,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_25.dll
[2013/04/28 20:16:52 | 003,544,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3dx9_24.dll
[2013/04/28 20:16:52 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_25.dll
[2013/04/28 20:16:52 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx9_24.dll
[2013/04/28 19:47:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unvanquished
[2013/04/28 19:47:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Unvanquished
[2013/04/28 19:19:02 | 000,000,000 | -H-D | C] – C:\Windows\SysNative\CanonIJ Uninstaller Information
[2013/04/28 19:19:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX860 series
[2013/04/28 19:18:58 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonBJ
[2013/04/28 19:18:54 | 000,290,816 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMLM9N.DLL
[2013/04/28 12:26:45 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\vlc
[2013/04/28 12:26:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/04/28 12:06:28 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2013/04/28 11:35:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\Qualcomm Atheros
[2013/04/28 11:35:08 | 003,618,304 | —- | C] (Qualcomm Atheros Communications, Inc.) – C:\Windows\SysNative\drivers\athw8x.sys
[2013/04/28 11:35:08 | 003,618,304 | —- | C] (Qualcomm Atheros Communications, Inc.) – C:\Windows\SysNative\athw8x.sys
[2013/04/28 11:35:08 | 000,000,000 | —D | C] – C:\Windows\Options
[2013/04/28 11:34:55 | 000,000,000 | —D | C] – C:\ProgramData\Qualcomm Atheros
[2013/04/28 11:29:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Atheros_L1e
[2013/04/28 11:28:58 | 000,110,744 | —- | C] (Qualcomm Atheros Co., Ltd.) – C:\Windows\SysNative\drivers\L1C63x64.sys
[2013/04/28 11:22:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel Corporation
[2013/04/28 11:22:16 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Intel Corporation
[2013/04/28 11:20:22 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2013/04/28 11:19:41 | 000,647,736 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\iaStorA.sys
[2013/04/28 11:19:39 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\InstallShield
[2013/04/28 11:17:37 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\SysWow64\CSVer.dll
[2013/04/28 11:17:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Intel
[2013/04/28 11:17:23 | 000,000,000 | —D | C] – C:\Intel
[2013/04/28 11:16:57 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\BMExplorer
[2013/04/28 11:16:56 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Atheros
[2013/04/28 11:13:39 | 001,122,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wdfcoinstaller01009.dll
[2013/04/28 11:13:39 | 000,344,216 | —- | C] (Qualcomm Atheros) – C:\Windows\SysNative\drivers\btath_a2dp.sys
[2013/04/28 11:13:39 | 000,178,840 | —- | C] (Qualcomm Atheros) – C:\Windows\SysNative\drivers\btath_hcrp.sys
[2013/04/28 11:13:39 | 000,135,832 | —- | C] (Qualcomm Atheros) – C:\Windows\SysNative\drivers\btath_rcp.sys
[2013/04/28 11:13:39 | 000,114,840 | —- | C] (Qualcomm Atheros) – C:\Windows\SysNative\drivers\btath_avdt.sys
[2013/04/28 11:13:39 | 000,088,728 | —- | C] (Qualcomm Atheros) – C:\Windows\SysNative\drivers\btath_flt.sys
[2013/04/28 11:13:39 | 000,076,952 | —- | C] (Qualcomm Atheros) – C:\Windows\SysNative\drivers\btath_lwflt.sys
[2013/04/28 11:13:38 | 000,574,616 | —- | C] (Qualcomm Atheros) – C:\Windows\SysNative\drivers\btfilter.sys
[2013/04/28 11:13:38 | 000,033,944 | —- | C] (Qualcomm Atheros) – C:\Windows\SysNative\drivers\btath_bus.sys
[2013/04/28 11:13:20 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\FirewallTool
[2013/04/28 11:13:18 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\Documents\Bluetooth Folder
[2013/04/28 11:13:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Atheros
[2013/04/28 11:13:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\QCA_Bluetooth
[2013/04/28 11:13:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bluetooth Suite
[2013/04/28 10:42:04 | 000,260,608 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\AMBSpiE.exe
[2013/04/28 10:42:04 | 000,141,312 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\cfgChain.exe
[2013/04/28 10:42:04 | 000,093,184 | —- | C] (Creative Technology Ltd) – C:\Windows\SysNative\ctpxst64.exe
[2013/04/28 10:42:04 | 000,017,920 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\AmbRunE.dll
[2013/04/28 10:42:04 | 000,008,704 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\ResDefE.exe
[2013/04/28 10:41:59 | 000,141,312 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\THXCfg64.exe
[2013/04/28 10:41:59 | 000,025,600 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\THXCfg64.dll
[2013/04/28 10:41:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Macrovision Shared
[2013/04/28 10:41:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Creative
[2013/04/28 00:32:16 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2013/04/28 00:15:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013/04/28 00:15:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2013/04/28 00:10:03 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\NVIDIA 3D Vision Video Player
[2013/04/27 23:51:11 | 000,000,000 | —D | C] – C:\Windows\Panther
[2013/04/27 23:48:04 | 001,451,840 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420103.dll
[2013/04/27 23:48:04 | 000,188,736 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2013/04/27 23:48:04 | 000,031,040 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2013/04/27 23:48:00 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2013/04/27 23:47:58 | 006,390,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2013/04/27 23:47:58 | 003,460,896 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2013/04/27 23:47:58 | 002,558,240 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2013/04/27 23:47:58 | 000,118,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2013/04/27 23:47:58 | 000,063,776 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2013/04/27 23:47:37 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2013/04/27 23:47:34 | 001,468,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2013/04/27 23:47:14 | 000,364,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdecodemft.dll
[2013/04/27 23:47:14 | 000,301,376 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvdecodemft.dll
[2013/04/27 23:42:17 | 000,000,000 | —D | C] – C:\NVIDIA
[2013/04/27 23:38:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE
[2013/04/27 23:38:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\GIGABYTE
[2013/04/27 23:25:30 | 000,000,000 | —D | C] – C:\ProgramData\Atheros
[2013/04/27 22:38:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2013/04/27 22:38:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung
[2013/04/27 22:31:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Reference Assemblies
[2013/04/27 22:31:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSBuild
[2013/04/27 22:30:59 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2013/04/27 22:30:59 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2013/04/27 22:28:39 | 000,778,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationNative_v0300.dll
[2013/04/27 22:28:39 | 000,102,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
[2013/04/27 22:28:39 | 000,035,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\TsWpfWrp.exe
[2013/04/27 22:28:39 | 000,035,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsWpfWrp.exe
[2013/04/27 22:28:38 | 001,166,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationNative_v0300.dll
[2013/04/27 22:28:38 | 000,124,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationCFFRasterizerNative_v0300.dll
[2013/04/27 21:54:49 | 000,064,856 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\klfphc.dll
[2013/04/27 21:54:29 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2013/04/27 21:54:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2013/04/27 21:54:23 | 000,090,208 | —- | C] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\klflt.sys
[2013/04/27 21:54:22 | 000,619,616 | —- | C] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\klif.sys
[2013/04/27 15:19:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/04/27 15:18:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2013/04/27 15:18:08 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Google
[2013/04/27 15:05:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2013/04/27 15:05:41 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Power2Go
[2013/04/27 14:55:40 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2013/04/27 14:55:40 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2013/04/27 14:55:34 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2013/04/27 14:55:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2013/04/27 14:42:14 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\Documents\CyberLink
[2013/04/27 14:42:14 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\Cyberlink
[2013/04/27 14:42:14 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\CyberLink
[2013/04/27 14:41:03 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Macromedia
[2013/04/27 14:37:26 | 000,000,000 | —D | C] – C:\Temp
[2013/04/27 14:36:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG Tool Kit
[2013/04/27 14:36:51 | 000,115,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSINET.OCX
[2013/04/27 14:36:51 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Vb6stkit.dll
[2013/04/27 14:36:51 | 000,102,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\VB6KO.DLL
[2013/04/27 14:36:51 | 000,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wbemdisp.tlb
[2013/04/27 14:36:51 | 000,016,384 | —- | C] (BitLeader) – C:\Windows\SysWow64\lgfwunis.exe
[2013/04/27 14:36:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\lg_fwupdate
[2013/04/27 14:36:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InstallShield
[2013/04/27 14:35:00 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
[2013/04/27 14:34:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
[2013/04/27 14:34:05 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Cyberlink
[2013/04/27 14:34:02 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\InstallShield Installation Information
[2013/04/27 14:31:02 | 000,000,000 | —D | C] – C:\ProgramData\CyberLink
[2013/04/27 14:30:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2013/04/27 14:29:56 | 000,000,000 | —D | C] – C:\ProgramData\Temp
[2013/04/27 14:25:37 | 000,025,640 | —- | C] (Windows ® Server 2003 DDK provider) – C:\Windows\gdrv.sys
[2013/04/27 14:05:07 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/04/27 14:05:07 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Searches
[2013/04/27 14:05:07 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Contacts
[2013/04/27 14:05:07 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/04/27 14:05:06 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Adobe
[2013/04/27 14:04:52 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\VirtualStore
[2013/04/27 14:04:51 | 000,000,000 | —D | C] – C:\ProgramData\PRICache
[2013/04/27 14:04:51 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Packages
[2013/04/27 14:04:50 | 000,000,000 | –SD | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Videos
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Saved Games
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Pictures
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Music
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Links
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Favorites
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Downloads
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Documents
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\Desktop
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/04/27 14:04:50 | 000,000,000 | R–D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
[2013/04/27 14:04:50 | 000,000,000 | -H-D | C] – C:\Users\Dustin Arbuthnot\AppData
[2013/04/27 14:04:50 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Temp
[2013/04/27 14:04:50 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2013/04/27 14:04:50 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Microsoft
[2013/04/27 14:04:50 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/04/27 13:51:57 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2013/04/27 13:51:48 | 000,000,000 | -HSD | C] – C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2013/05/06 17:54:54 | 000,000,021 | —- | M] () – C:\Users\Dustin Arbuthnot\AppData\Roaming\config_data.dat
[2013/05/06 17:54:08 | 000,850,046 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/06 17:54:08 | 000,723,298 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/05/06 17:54:08 | 000,136,970 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/05/06 17:51:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/06 17:49:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/06 17:48:53 | 000,000,343 | —- | M] () – C:\Windows\lgfwup.ini
[2013/05/06 17:48:38 | 000,000,938 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/06 17:48:07 | 000,000,441 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.ics
[2013/05/06 17:47:57 | 826,994,685 | -HS- | M] () – C:\hiberfil.sys
[2013/05/06 17:47:57 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/05/05 20:23:00 | 000,000,942 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/04 17:38:38 | 000,291,288 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/05/04 11:01:13 | 000,000,956 | —- | M] () – C:\Users\Public\Desktop\CorsairLINK2.lnk
[2013/05/04 09:55:04 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Dustin Arbuthnot\Desktop\aswMBR.exe
[2013/05/04 09:44:49 | 000,007,607 | —- | M] () – C:\Users\Dustin Arbuthnot\AppData\Local\Resmon.ResmonCfg
[2013/05/02 18:39:34 | 000,000,324 | —- | M] () – C:\Users\Dustin Arbuthnot\Desktop\Master HotKeys.ahk.ahk
[2013/05/01 18:38:33 | 000,001,502 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/04/28 21:57:10 | 000,000,064 | —- | M] () – C:\Windows\GPlrLanc.dat
[2013/04/28 20:31:16 | 000,001,351 | —- | M] () – C:\Users\Dustin Arbuthnot\Documents\AutoHotkey.ahk
[2013/04/28 19:33:23 | 000,000,000 | -H– | M] () – C:\Users\Dustin Arbuthnot\Documents\Default.rdp
[2013/04/28 11:22:56 | 000,856,724 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/04/28 10:41:59 | 000,000,159 | RH– | M] () – C:\Windows\ctfile.rfc
[2013/04/28 00:15:56 | 000,000,727 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2013/04/27 23:51:29 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2013/04/27 23:38:02 | 000,002,751 | —- | M] () – C:\Users\Public\Desktop\GIGABYTE OC_GURU.lnk
[2013/04/27 23:38:02 | 000,002,164 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk
[2013/04/27 23:25:20 | 000,025,640 | —- | M] (Windows ® Server 2003 DDK provider) – C:\Windows\gdrv.sys
[2013/04/27 22:23:13 | 000,619,616 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\klif.sys
[2013/04/27 22:23:13 | 000,178,448 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\kneps.sys
[2013/04/27 22:23:13 | 000,050,448 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\klwfp.sys
[2013/04/27 22:23:11 | 000,090,208 | —- | M] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\klflt.sys
[2013/04/27 21:56:14 | 000,002,344 | —- | M] () – C:\Users\Dustin Arbuthnot\Desktop\Safe Money.lnk
[2013/04/27 15:19:48 | 000,002,259 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/04/27 14:38:08 | 000,016,384 | —- | M] (BitLeader) – C:\Windows\SysWow64\lgfwunis.exe
[2013/04/27 13:52:13 | 000,044,876 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2013/04/27 13:52:13 | 000,044,876 | —- | M] () – C:\Windows\SysNative\license.rtf

========== Files Created - No Company Name ==========

[2013/05/04 17:38:36 | 000,291,288 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/05/04 11:02:08 | 000,000,021 | —- | C] () – C:\Users\Dustin Arbuthnot\AppData\Roaming\config_data.dat
[2013/05/04 11:01:13 | 000,000,956 | —- | C] () – C:\Users\Public\Desktop\CorsairLINK2.lnk
[2013/05/04 09:44:49 | 000,007,607 | —- | C] () – C:\Users\Dustin Arbuthnot\AppData\Local\Resmon.ResmonCfg
[2013/05/02 18:39:34 | 000,000,324 | —- | C] () – C:\Users\Dustin Arbuthnot\Desktop\Master HotKeys.ahk.ahk
[2013/05/02 06:23:22 | 000,110,592 | —- | C] () – C:\Windows\SysNative\OEMLicense.dll
[2013/05/02 06:23:22 | 000,083,968 | —- | C] () – C:\Windows\SysWow64\OEMLicense.dll
[2013/05/01 18:38:33 | 000,001,502 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/01 18:38:25 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2013/04/30 17:15:44 | 000,387,867 | —- | C] () – C:\Windows\SysNative\ApnDatabase.xml
[2013/04/28 21:57:10 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2013/04/28 20:31:16 | 000,001,351 | —- | C] () – C:\Users\Dustin Arbuthnot\Documents\AutoHotkey.ahk
[2013/04/28 19:33:23 | 000,000,000 | -H– | C] () – C:\Users\Dustin Arbuthnot\Documents\Default.rdp
[2013/04/28 11:35:08 | 000,326,379 | —- | C] () – C:\Windows\SysNative\athw8x.inf
[2013/04/28 11:35:08 | 000,079,352 | —- | C] () – C:\Windows\SysNative\athw8x.cat
[2013/04/28 11:22:56 | 000,856,724 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/04/28 10:42:04 | 000,007,594 | —- | C] () – C:\Windows\SysNative\xFiMB2CfgUninstall64.ini
[2013/04/28 10:42:04 | 000,005,135 | —- | C] () – C:\Windows\SysNative\cfgfx.ini
[2013/04/28 10:41:59 | 000,325,120 | —- | C] () – C:\Windows\SysNative\APOMgr64.DLL
[2013/04/28 10:41:59 | 000,246,272 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2013/04/28 10:41:59 | 000,089,600 | —- | C] () – C:\Windows\SysNative\CmdRtr64.DLL
[2013/04/28 10:41:59 | 000,074,240 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2013/04/28 10:41:59 | 000,006,985 | —- | C] () – C:\Windows\SysNative\THXCfgUninstall64.ini
[2013/04/28 10:41:59 | 000,006,772 | —- | C] () – C:\Windows\SysNative\THXCfg64.ini
[2013/04/28 10:41:59 | 000,000,159 | RH– | C] () – C:\Windows\ctfile.rfc
[2013/04/28 00:33:32 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/28 00:15:56 | 000,000,727 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2013/04/27 23:51:29 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
[2013/04/27 23:47:58 | 002,953,448 | —- | C] () – C:\Windows\SysNative\nvcoproc.bin
[2013/04/27 23:38:02 | 000,002,751 | —- | C] () – C:\Users\Public\Desktop\GIGABYTE OC_GURU.lnk
[2013/04/27 23:38:02 | 000,002,164 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk
[2013/04/27 21:56:14 | 000,002,344 | —- | C] () – C:\Users\Dustin Arbuthnot\Desktop\Safe Money.lnk
[2013/04/27 21:56:14 | 000,001,327 | —- | C] () – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013.lnk
[2013/04/27 15:19:48 | 000,002,259 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/04/27 15:18:14 | 000,000,942 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/27 15:18:14 | 000,000,938 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/27 14:36:56 | 000,000,343 | —- | C] () – C:\Windows\lgfwup.ini
[2013/04/27 14:05:06 | 000,001,434 | —- | C] () – C:\Users\Dustin Arbuthnot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/04/27 13:52:37 | 826,994,685 | -HS- | C] () – C:\hiberfil.sys
[2013/04/27 13:51:48 | 268,435,456 | -HS- | C] () – C:\swapfile.sys
[2012/07/26 18:13:10 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2012/07/26 18:13:09 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 17:21:26 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2012/07/26 11:17:42 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/26 06:37:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2012/07/26 06:28:31 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2012/06/03 00:31:19 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== ZeroAccess Check ==========

[2013/04/28 20:16:50 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/03/02 12:45:01 | 019,748,864 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/03/02 18:23:07 | 017,560,576 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/26 13:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/26 13:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/26 13:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/05/06 17:48:37 | 000,000,000 | —D | M] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Corsair
[2013/05/05 20:44:31 | 000,000,000 | —D | M] – C:\Users\Dustin Arbuthnot\AppData\Roaming\MediaMonkey
[2013/05/02 19:07:56 | 000,000,000 | —D | M] – C:\Users\Dustin Arbuthnot\AppData\Roaming\Natural Selection 2

========== Purity Check ==========



< End of report >






OTL Extras logfile created on: 6/05/2013 17:53:29 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\Program Files (x86)\WhatTheTech
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

15.96 Gb Total Physical Memory | 13.66 Gb Available Physical Memory | 85.60% Memory free
18.21 Gb Paging File | 15.85 Gb Available in Paging File | 87.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 118.90 Gb Total Space | 77.76 Gb Free Space | 65.40% Space Free | Partition Type: NTFS
Drive E: | 1863.01 Gb Total Space | 1801.33 Gb Free Space | 96.69% Space Free | Partition Type: NTFS

Computer Name: DUSTINS-RIG | User Name: Dustin Arbuthnot | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] – "E:\Program Files (x86)\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "E:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "E:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "E:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] – "E:\Program Files (x86)\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] – "E:\Program Files (x86)\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "E:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "E:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "E:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] – "E:\Program Files (x86)\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02BB99C1-7CF7-4ECA-9B0D-D725F2F7D410}" = rport=445 | protocol=6 | dir=out | app=system |
"{03CB1860-91F6-4203-90E2-4A164D6E4FDB}" = rport=138 | protocol=17 | dir=out | app=system |
"{0729E572-8EDA-486D-8177-D5C298323F20}" = lport=445 | protocol=6 | dir=in | app=system |
"{0AF5F9B3-2601-4C10-9406-AA2AF792AB5D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{0C114900-E2FB-4AB3-8F72-1F867E45A1AA}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{150810DF-0F6D-45F0-B7FC-2081316B5978}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{191120B1-AEAF-4F5B-A383-BFE896742EC7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{195AB649-3A4B-43D4-90D1-440A59DC4A1B}" = rport=137 | protocol=17 | dir=out | app=system |
"{1C1F315C-6592-4C32-8AEE-774E4BF7F058}" = lport=2869 | protocol=6 | dir=in | app=system |
"{22E8D1F8-0E91-4CDB-9E66-8126A5F85EE6}" = lport=10243 | protocol=6 | dir=in | app=system |
"{24EF77B0-63AF-4702-952F-D2859EC906E7}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2C72B1C1-0CD5-4774-B2B3-2AA2B6475033}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2FE49B56-EFB5-479B-B533-464B4487D7A5}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{35024BF8-B03C-449A-9ECC-9D8E46714D61}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3A875F6D-FB55-4B76-986B-FA2338C2B894}" = rport=2869 | protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{6EB41F02-8E06-4401-89DB-9A2A1D73CD4B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{71E0A9D4-19A0-446F-A57A-03896466F8D4}" = lport=137 | protocol=17 | dir=in | app=system |
"{84CE13CB-22F1-4C56-94C4-99630277B887}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{891ECEDF-5555-41A5-ADA4-5B8F4580CE7D}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{89610D08-4C68-455F-84D5-615ED8660B28}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9C38FF45-6E9B-4E42-883E-D359CAA5939A}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{9DDD13C5-AA81-43C7-A14E-57B28A5B0FD8}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{A17EDE0D-2AD9-463B-B75F-3122C1F825CE}" = lport=138 | protocol=17 | dir=in | app=system |
"{A7190BDD-44BA-46ED-967B-77D52E706C41}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{A98610A8-F121-4FD7-AE3B-C5B68C277A05}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{AA3E837F-BAA8-4CA5-AC9E-AE9CBF88FC84}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AAB4A896-E127-4963-B756-C4479096EA75}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AECBD484-1F82-4715-A281-90571E440D43}" = lport=139 | protocol=6 | dir=in | app=system |
"{B23209E4-B10D-4B94-A9EB-D9CA045865F1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B457EEC7-7F6D-4FEF-B02A-ACC647B57A94}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B4E520BD-77B9-4C5E-A706-CAC934558C25}" = rport=2869 | protocol=6 | dir=out | app=system |
"{C00F0B7C-1E46-4077-AB45-99909E9A1D47}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C5839FB7-1346-41B6-8A81-569A8C800658}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D136E98F-6715-47F5-826A-9A2E50CE0EF6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D83C93E7-5445-4C47-AAC9-C52E9E9E9DAD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E708F237-625C-49DD-939D-7B4B0E03DE68}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{E9B930BA-403B-4DEB-A862-006312D7AB29}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F43880F5-C3B1-482E-A789-5FFF2423D74D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F5C676E1-7AAF-4C8D-9C85-ACF5BFDE1F92}" = rport=139 | protocol=6 | dir=out | app=system |
"{F61BA56E-FE5F-419E-802A-68AAF38EA126}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FA30727A-C5C5-4E7A-A6F9-7BBD74FC7F60}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\dashost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{048F593F-D7B2-46B6-A302-100289BDF62B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{0A7093BD-D444-4F5F-9119-79DE8D92813D}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{19572B1A-FFF6-493B-904A-42A037920698}" = protocol=17 | dir=in | app=e:\program files (x86)\steam\steamapps\common\forge\binaries\win32\forgegame.exe |
"{201E41E7-6F86-4CB7-BDB1-0EEF4EA89910}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{207A31D7-ED20-4A6D-94EC-677B460550D9}" = protocol=6 | dir=in | app=e:\program files (x86)\steam\steam.exe |
"{2360DE51-E022-4EA5-826F-DED0381F0A6D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2592D760-FC40-4FBF-A912-9428813327FA}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{2A8F16DF-025F-4917-8A07-F953EA94CEEA}" = protocol=6 | dir=in | app=e:\program files (x86)\steam\steamapps\common\natural selection 2\ns2.exe |
"{3027F211-06EE-44B6-BAE5-39F3F29D7602}" = protocol=6 | dir=out | app=c:\program files (x86)\bluetooth suite\win7ui.exe |
"{31084AD3-70CD-4B2A-A738-44E2147B4897}" = protocol=6 | dir=in | app=e:\program files (x86)\steam\steamapps\common\natural selection 2\ns2.exe |
"{358C4159-2C89-4903-960B-E9712553676B}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{3B1589CE-5BDC-4AC4-902D-D0C5EFC5DE2A}" = protocol=17 | dir=in | app=e:\program files (x86)\steam\steamapps\common\natural selection 2\ns2.exe |
"{3B4EAE2A-C307-4994-B316-5D1122DBC421}" = protocol=6 | dir=out | app=system |
"{3C07B44C-ABD4-4354-8D98-38BCFE089674}" = protocol=6 | dir=in | app=c:\program files (x86)\bluetooth suite\bttray.exe |
"{437DBB4A-1837-4F8C-8D94-E0C5B71610A0}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{4E605E59-728D-4A88-AD4C-2247AC18A581}" = protocol=6 | dir=in | app=c:\program files (x86)\bluetooth suite\btvstack.exe |
"{5473F915-F171-4D16-A2DD-3774FCB17379}" = protocol=6 | dir=in | app=e:\program files (x86)\steam\steamapps\common\forge\binaries\win32\forgegame.exe |
"{55CD710B-E59C-4EC8-97E8-375D92834216}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{59E857F7-6F4A-4AED-910C-101743D416F6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5BB1ECBF-949E-4008-97EE-74EBF1809720}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{5D0870A2-9F3F-4BBD-A22C-F4AA72A6B260}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{5E590AFF-E760-4745-AF83-0FC35CFB257D}" = protocol=17 | dir=in | app=e:\program files (x86)\steam\steam.exe |
"{5FFB5FE5-A4FF-42B9-88F1-C7210A8F3ECA}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{61563474-F248-4EE4-8476-A31A6E704DA4}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{719360F1-820C-4023-AAA8-E1A29C7A7EF0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{78F6BEDB-B77A-4C2C-98A8-498BD898BA37}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{79988F91-9C45-458C-90AC-54BBFB066BE7}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{7ACF4FCE-5BAE-4C08-8489-2ECCD199FE8D}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{7D0A64FD-8B1C-4FFB-9E41-4D998D5D0C56}" = dir=in | app=e:\program files (x86)\itunes.exe |
"{7FD61D12-334B-4009-A6ED-A3781D66C9BE}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{833701B2-B370-414A-8001-192A3F50681D}" = protocol=6 | dir=out | app=c:\program files (x86)\bluetooth suite\bttray.exe |
"{8891209C-CD6B-410D-AFB5-798A2F8E4BA0}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{8D4850C5-4676-474B-9C23-96E95CD6BA5A}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{909CFB4F-66B0-4749-8893-A1838EECB76F}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{910CA1CF-51B9-46AB-A8F9-D91302A2FDF0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{93EC2DE5-0CFC-4809-A643-9859E1E83440}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{96EE05A6-8ABE-41B5-8EA6-9EADC3C82BE7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9C2DA823-5134-40BA-93FC-AEE0D9E5B2F9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{9DC7F8BF-0994-4157-BEFA-4435F7A5749E}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{A18865D2-863A-4DFB-9698-F78639A42C00}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{A61F8215-D4A2-4889-A163-936407A78D0C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A8E6A723-1F39-40F2-9252-384EA3C103FD}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B2635425-64F8-42E4-B622-BD8B0E53D86D}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{B5EDC78F-34FE-478F-9BB7-A2887DDC365E}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{BC4AC70C-ACA4-45AE-A147-3E1430AB6FEF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BD6BDD4B-E94C-4094-9D87-5134E0AFD014}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{C7165F0B-63E4-4C48-868F-683AFF367022}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{CC553406-3BA6-47D0-8818-7C0B3719822A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D0E0847A-0E10-405A-BDB5-F9B293D15C1E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D2265BA2-B5A3-4C54-AC07-FFBE9AD70138}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{D5046FE0-FA4A-41F9-BCF3-F5AEB2FEDC1B}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{D8DFDE8C-8233-4A20-A12A-520DD11E6D0C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E473588E-5FF5-4D59-81D2-560B0656A245}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{F10570D3-00BE-4841-A37E-83BB352BEE67}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{F6BAF7D2-69AC-42BF-8234-98BCBB572990}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FD72BA68-3677-40AE-B4F6-5DF82E8F3FEA}" = protocol=17 | dir=in | app=e:\program files (x86)\steam\steamapps\common\natural selection 2\ns2.exe |
"{FEEDB4B0-39ED-4FEB-9DA6-A59A613AACDB}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{FF3BB055-C538-4013-9596-06B152AAF209}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"TCP Query User{7D1D4E61-229F-4C8E-B13C-2F6576E54D8F}C:\program files (x86)\bluetooth suite\bttray.exe" = protocol=6 | dir=in | app=c:\program files (x86)\bluetooth suite\bttray.exe |
"TCP Query User{EACB33C7-0E5A-4121-B80C-31E509239F9B}C:\program files (x86)\bluetooth suite\btvstack.exe" = protocol=6 | dir=in | app=c:\program files (x86)\bluetooth suite\btvstack.exe |
"UDP Query User{77591215-255E-4E13-9CBD-8FD03B1DAC3F}C:\program files (x86)\bluetooth suite\bttray.exe" = protocol=17 | dir=in | app=c:\program files (x86)\bluetooth suite\bttray.exe |
"UDP Query User{A1DB0BB8-2E6C-4D24-919E-FFAA8474AC17}C:\program files (x86)\bluetooth suite\btvstack.exe" = protocol=17 | dir=in | app=c:\program files (x86)\bluetooth suite\btvstack.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX860_series" = Canon MX860 series MP Drivers
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{A84A4FB1-D703-48DB-89E0-68B6499D2801}" = Qualcomm Atheros Bluetooth Suite (64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 301.42
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.0213
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"AutoHotkey" = AutoHotkey 1.1.09.04

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros Client Installation Program
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = LG Burning Tool
"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple Application Support
"{5588D686-D23B-4C9D-BDFA-2A7875CD3722}" = GIGABYTE OC_GURU II
"{560985FB-4B76-4121-9189-7A2CDC7886D6}" = Kaspersky Internet Security 2013
"{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}" = Suite
"{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG Tool Kit
"{658EFB3F-8606-4576-8FEC-B0CED48F1E68}" = CorsairLINK2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = LG CyberLink PowerProducer
"{D4DE3DB4-7734-47E5-8D92-B80146311406}" = Samsung Data Migration
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = LG CyberLink MediaEspresso
"{FE3B9518-9FF3-4D89-8A8D-E540C9CCAF3B}" = NVIDIA 3D Vision Video Player
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"CMIUSB&1B1C&1C00" = Corsair Linkâ„¢ USB Dongle (Driver Removal)
"Google Chrome" = Google Chrome
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = LG Burning Tool
"InstallShield_{5588D686-D23B-4C9D-BDFA-2A7875CD3722}" = GIGABYTE OC_GURU II
"InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = LG CyberLink PowerProducer
"InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = LG CyberLink MediaEspresso
"InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}" = Kaspersky Internet Security 2013
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"MediaMonkey_is1" = MediaMonkey 4.0
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Steam App 223390" = Forge
"Steam App 4920" = Natural Selection 2
"Unvanquished 0.14" = Unvanquished
"VLC media player" = VLC media player 2.0.6

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 30/04/2013 04:32:03 | Computer Name = Dustins-Rig | Source = MsiInstaller | ID = 11706
Description =

Error - 30/04/2013 04:32:06 | Computer Name = Dustins-Rig | Source = MsiInstaller | ID = 11706
Description =

Error - 1/05/2013 04:41:32 | Computer Name = Dustins-Rig | Source = SideBySide | ID = 16842827
Description = Activation context generation failed for "C:\Program Files (x86)\Creative\Audio
Device Selection Unicode\CTAudSeu.exe".Error in manifest or policy file "C:\Program
Files (x86)\Creative\Audio Device Selection Unicode\CTAudSeu.exe" on line 2. Multiple
requestedPrivileges elements are not allowed in manifest.

Error - 1/05/2013 12:12:04 | Computer Name = Dustins-Rig | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 1/05/2013 12:12:04 | Computer Name = Dustins-Rig | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1093

Error - 3/05/2013 19:57:04 | Computer Name = Dustins-Rig | Source = Application Error | ID = 1000
Description = Faulting application name: aswMBR.exe, version: 0.9.9.1771, time stamp:
0x5147644e Faulting module name: ntdll.dll, version: 6.2.9200.16420, time stamp:
0x505aaa82 Exception code: 0xc0000005 Fault offset: 0x0004f44d Faulting process ID:
0x710 Faulting application start time: 0x01ce4859a43d864c Faulting application path:
C:\Users\Dustin Arbuthnot\Downloads\aswMBR.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
ID: 271f2e4c-b44d-11e2-be7b-9cb70dc824df Faulting package full name: Faulting package-relative
application ID:

Error - 3/05/2013 20:00:21 | Computer Name = Dustins-Rig | Source = Application Error | ID = 1000
Description = Faulting application name: aswMBR.exe, version: 0.9.9.1771, time stamp:
0x5147644e Faulting module name: ntdll.dll, version: 6.2.9200.16420, time stamp:
0x505aaa82 Exception code: 0xc0000005 Fault offset: 0x0004f44d Faulting process ID:
0x1a3c Faulting application start time: 0x01ce4859f1b4f05d Faulting application path:
C:\Users\Dustin Arbuthnot\Downloads\aswMBR.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
ID: 9ca5bb13-b44d-11e2-be7b-9cb70dc824df Faulting package full name: Faulting package-relative
application ID:

Error - 3/05/2013 20:00:54 | Computer Name = Dustins-Rig | Source = Application Error | ID = 1000
Description = Faulting application name: aswMBR.exe, version: 0.9.9.1771, time stamp:
0x5147644e Faulting module name: ntdll.dll, version: 6.2.9200.16420, time stamp:
0x505aaa82 Exception code: 0xc0000005 Fault offset: 0x0004f44d Faulting process ID:
0x193c Faulting application start time: 0x01ce485a6847dae9 Faulting application path:
C:\Users\Dustin Arbuthnot\Downloads\aswMBR.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
ID: afed5df3-b44d-11e2-be7b-9cb70dc824df Faulting package full name: Faulting package-relative
application ID:

Error - 3/05/2013 20:07:00 | Computer Name = Dustins-Rig | Source = Application Error | ID = 1000
Description = Faulting application name: aswMBR.exe, version: 0.9.9.1771, time stamp:
0x5147644e Faulting module name: ntdll.dll, version: 6.2.9200.16420, time stamp:
0x505aaa82 Exception code: 0xc0000005 Fault offset: 0x0004f44d Faulting process ID:
0x1830 Faulting application start time: 0x01ce485b42a65937 Faulting application path:
C:\Users\Dustin Arbuthnot\Downloads\aswMBR.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
ID: 8a6cbb95-b44e-11e2-be7b-9cb70dc824df Faulting package full name: Faulting package-relative
application ID:

Error - 3/05/2013 20:12:18 | Computer Name = Dustins-Rig | Source = Application Error | ID = 1000
Description = Faulting application name: aswMBR.exe, version: 0.9.9.1771, time stamp:
0x5147644e Faulting module name: ntdll.dll, version: 6.2.9200.16420, time stamp:
0x505aaa82 Exception code: 0xc0000005 Fault offset: 0x0004f44d Faulting process ID:
0x17a4 Faulting application start time: 0x01ce485c013dec8e Faulting application path:
C:\Users\Dustin Arbuthnot\Downloads\aswMBR.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
ID: 47a1373a-b44f-11e2-be7b-9cb70dc824df Faulting package full name: Faulting package-relative
application ID:

[ System Events ]
Error - 4/05/2013 01:04:38 | Computer Name = Dustins-Rig | Source = ipnathlp | ID = 30013
Description =

Error - 4/05/2013 03:38:42 | Computer Name = Dustins-Rig | Source = Service Control Manager | ID = 7000
Description = The X5XSEx_Pr143 service failed to start due to the following error:
%%3

Error - 4/05/2013 03:38:46 | Computer Name = Dustins-Rig | Source = ipnathlp | ID = 34001
Description =

Error - 4/05/2013 03:38:46 | Computer Name = Dustins-Rig | Source = ipnathlp | ID = 30013
Description =

Error - 4/05/2013 04:11:46 | Computer Name = Dustins-Rig | Source = ipnathlp | ID = 30013
Description =

Error - 4/05/2013 07:37:31 | Computer Name = Dustins-Rig | Source = ipnathlp | ID = 30013
Description =

Error - 6/05/2013 03:43:54 | Computer Name = Dustins-Rig | Source = ipnathlp | ID = 30013
Description =

Error - 6/05/2013 03:48:03 | Computer Name = Dustins-Rig | Source = Service Control Manager | ID = 7000
Description = The X5XSEx_Pr143 service failed to start due to the following error:
%%3

Error - 6/05/2013 03:48:07 | Computer Name = Dustins-Rig | Source = ipnathlp | ID = 34001
Description =

Error - 6/05/2013 03:48:07 | Computer Name = Dustins-Rig | Source = ipnathlp | ID = 30013
Description =


< End of report >
Hi,

[external image: Posted Image] Tweaking.com Registry Backup
  • Download the tool found here to your Desktop so it is easy to find.
  • Double click on the file you just downloaded to install it to your system.
  • Once the tool is installed, double-click on the Tweaking.com Registry Backup icon
    **Note** The tool should automatically open to the Backup Registry tab.

    [external image: Posted Image]
  • Press Backup Now
  • When the back up is complete, the tool will tell you that Successful */* Files Backed Up
  • You have now successfully backed up your Registry.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0: C:\Program Files (x86)\Free Ride Games\npExentCtl.dll File not found
    FF - HKLM\Software\MozillaPlugins\www.exent.com/GameTreatWidget: C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll File not found
    O4 - HKCU..\Run: [Exetender] "C:\Program Files (x86)\Free Ride Games\GPlayer.exe" /runonstartup File not found
    O33 - MountPoints2\{c11f07c8-aeed-11e2-be65-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{c11f07c8-aeed-11e2-be65-806e6f6e6963}\Shell\AutoRun\command - "" = "D:\setup.exe"
    [2013/04/28 21:57:09 | 000,000,000 | —D | C] – C:\ProgramData\Free Ride Games
    [2013/04/28 21:54:58 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Updater26276
    [2013/04/28 21:54:56 | 000,000,000 | —D | C] – C:\Users\Dustin Arbuthnot\AppData\Local\Deal Spy
    
    :Files
    C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\crossrider
    C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\
    ipconfig /flushdns /c
    
    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Post the new OTL log and let me know how your system is behaving. :)
Done exactly as you said, everything went smoothly. My computer is behaving normally after the Custom Fix.
Note: Deal Spy is still appearing in the Google Chrome extensions interface, however it is now missing its thumbnail image.

OTL Log:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\www.exent.com/GameTreatWidget\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Exetender deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c11f07c8-aeed-11e2-be65-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c11f07c8-aeed-11e2-be65-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c11f07c8-aeed-11e2-be65-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c11f07c8-aeed-11e2-be65-806e6f6e6963}\ not found.
File "D:\setup.exe" not found.
C:\ProgramData\Free Ride Games folder moved successfully.
C:\Users\Dustin Arbuthnot\AppData\Local\Updater26276 folder moved successfully.
C:\Users\Dustin Arbuthnot\AppData\Local\Deal Spy\Chrome folder moved successfully.
C:\Users\Dustin Arbuthnot\AppData\Local\Deal Spy folder moved successfully.
========== FILES ==========
File\Folder C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\crossrider not found.
C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\js\lib folder moved successfully.
C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\js\api folder moved successfully.
C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\js folder moved successfully.
C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\icons\actions folder moved successfully.
C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0\icons folder moved successfully.
C:\Users\Dustin Arbuthnot\AppData\Local\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd\1.23.8_0 folder moved successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
E:\Program Files (x86)\WhatTheTech\cmd.bat deleted successfully.
E:\Program Files (x86)\WhatTheTech\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Dustin Arbuthnot
->Temp folder emptied: 496594797 bytes
->Temporary Internet Files folder emptied: 96543069 bytes
->Google Chrome cache emptied: 389087195 bytes
->Flash cache emptied: 1695 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1798610 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 344865687 bytes

Total Files Cleaned = 1,267.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 05082013_190907

Files\Folders moved on Reboot…
C:\Users\Dustin Arbuthnot\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Hi,

Good to hear! :)

I was afraid that Deal Spy might have some residual bits in Google Chrome. Google Chrome is very hard to work with and you might be better off (for Chrome) to save your Bookmarks and uninstall Google Chrome completely and then reinstall a fresh copy. That process is by far the easiest and fastest.

[external image: Posted Image] Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
I deleted Chrome and switched to Firefox. Malwarebytes Anti-Malware (Trial) 1.75.0.1300 www.malwarebytes.org Database version: v2013.05.09.02 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16540 Dustin Arbuthnot :: DUSTINS-RIG [limited] Protection: Enabled 9/05/2013 17:46:12 mbam-log-2013-05-09 (17-46-12).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 237082 Time elapsed: 1 minute(s), 14 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESET LOG: Threat Found. E:\_OTL\MovedFiles\05082013_190907\C_Users\Dustin Arbuthnot\AppData\Local\Updater26276\Updater26276.exe a variant of Win32/Toolbar.CrossRider.C application
Very normally. Thank you so much! You've inspired me to learn more about the inner workings of computers. I love this website.
Good to hear! :)

Providing there are no other malware related problems…

[external image: Posted Image]IT APPEARS THAT YOUR LOGS ARE NOW CLEAN

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

[external image: Posted Image] Clean up with OTL:
  • Right-click and Run as Administrator OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop. If you did not have Malwarebytes Antimalware before, I would keep it and run it weekly.
———-

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. FireFox If you use Firefox, I recommend installing the following add-ons to help make your Firefox browser more secure:
NoScript
AdBlock Plus

3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. **There are firewalls that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

7. Finally, I strongly recommend that you read Miekiemoes' great advice How to prevent malware.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI