This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

most of ms services in msconfig stopped [Solved]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

Had occasion to be in misconfig and noticed that most of Microsoft's services are configured as stopped.  Everything is ticked but the enable all button is greyed out.  There are also some of my programme update services stopped and it seems no way to start them.

 

Windows Update is stopped, as is Windows Backup.  WLan AutoConfig, Windows Event Collector, Web Client, Volume Shadow Copy, Virtual Disk, Programme Compatibility Assistant etc.  These are just a sample and I admit I don't know what they all are, but I'm sure some of them should be 'started' and probably some of what is left should be running.  Let's put it this way, there were more MS services stopped, than started and no way it seemed to start them.

 

Maybe some of these non-starting services would account for my external drives not starting up with my computer.  I always have to boot them separately, and would maybe account for why some things just don't work, period.

 

I posted this on the Windows board and was told I probably had a virus.  So I have enclosed the following scans as asked for your use, if someone could take a look, please.

 

Thank you for reading and in advance for any help offered.

hedley

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-05-2015
Ran by [removed] (administrator) on ANDREA-PC on 26-05-2015 10:12:49
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Foxit Software Inc.) C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Contacts\wlcomm.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil32_17_0_0_188_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [747264 2013-11-01] (Advanced Micro Devices, Inc.)
HKLM\…\Run: [NUSB3MON] => C:\Program Files\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [6336216 2013-10-22] (Realtek Semiconductor)
HKLM\…\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\…\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\…\Run: [hpqSRMon] => C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM Group Policy restriction on software: *.rtf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <====== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <====== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <====== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: ** <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <====== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <====== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <====== ATTENTION
HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\Run: [AVG-Secure-Search-Update_0215pit] => C:\Users\Andrea\AppData\Roaming\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe [2794520 2015-02-17] ()
HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6714136 2015-05-15] (SUPERAntiSpyware)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2015-05-05]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://uk.yahoo.com/
HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/en-gb/?ocid=iehp
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-05-19] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-05-19] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
 
FireFox:
========
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @Nero.com/KM -> C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-19] (Google Inc.)
FF Plugin HKU\S-1-5-21-1844252164-2368963752-2148446147-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Andrea\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-05-02] (Citrix Online)
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2015-05-05]
FF HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\Firefox\Extensions: [[removed]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-23] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2013-11-01] (Advanced Micro Devices, Inc.) []
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [851456 2015-04-27] (Microsoft Corporation)
R2 FoxitCloudUpdateService; C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [244392 2015-05-11] (Foxit Software Inc.)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) []
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) []
R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [694784 2009-09-20] (Hewlett-Packard Co.) []
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [786256 2014-07-15] (Nero AG)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) []
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) []
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdhub30; C:\Windows\System32\DRIVERS\amdhub30.sys [85312 2013-05-27] (Advanced Micro Devices, INC.)
R3 amdxhc; C:\Windows\System32\DRIVERS\amdxhc.sys [178496 2013-05-27] (Advanced Micro Devices, INC.)
R0 amd_sata; C:\Windows\System32\DRIVERS\amd_sata.sys [70464 2013-06-27] (Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\DRIVERS\amd_xata.sys [34624 2013-06-27] (Advanced Micro Devices)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [50432 2013-09-19] (Advanced Micro Devices)
R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [92888 2015-04-14] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-26] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
U3 aswMBR; \??\C:\Users\Andrea\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Andrea\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-26 10:12 - 2015-05-26 10:13 - 00038548 _____ () C:\Users\Andrea\Desktop\FRST.txt
2015-05-26 10:10 - 2015-05-26 10:12 - 00000000 ____D () C:\FRST
2015-05-26 10:09 - 2015-05-26 10:10 - 01147392 _____ (Farbar) C:\Users\Andrea\Desktop\FRST.exe
2015-05-26 10:05 - 2015-05-26 10:05 - 00000562 _____ () C:\Users\Andrea\Desktop\aswMBR.txt
2015-05-26 10:01 - 2015-05-26 10:01 - 05198336 _____ (AVAST Software) C:\Users\Andrea\Desktop\aswMBR.exe
2015-05-19 14:34 - 2015-05-26 09:48 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-19 14:34 - 2015-05-26 00:48 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-19 14:34 - 2015-05-19 14:34 - 00000000 ____D () C:\ProgramData\Google
2015-05-19 14:33 - 2015-05-19 14:41 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Google
2015-05-19 14:33 - 2015-05-19 14:41 - 00000000 ____D () C:\Program Files\Google
2015-05-19 14:33 - 2015-05-19 14:35 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Adobe
2015-05-16 14:06 - 2015-05-16 15:41 - 00002245 _____ () C:\Users\Andrea\Desktop\Kindle.lnk
2015-05-16 14:06 - 2015-05-16 14:43 - 00000000 ____D () C:\Users\Andrea\Documents\My Kindle Content
2015-05-16 14:05 - 2015-05-16 15:41 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Amazon
2015-05-16 14:05 - 2015-05-16 14:05 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2015-05-15 16:17 - 2015-05-15 16:17 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Nero_AG
2015-05-15 16:16 - 2015-05-15 16:21 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Nero
2015-05-15 16:11 - 2015-05-15 16:16 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Nero
2015-05-15 16:09 - 2015-05-15 16:09 - 00002889 _____ () C:\Users\Public\Desktop\Nero 2015.lnk
2015-05-15 16:06 - 2015-05-15 16:10 - 00000000 ____D () C:\ProgramData\Nero
2015-05-15 16:06 - 2015-05-15 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
2015-05-15 16:06 - 2015-05-15 16:09 - 00000000 ____D () C:\Program Files\Nero
2015-05-15 16:06 - 2015-05-15 16:09 - 00000000 ____D () C:\Program Files\Common Files\Nero
2015-05-13 20:19 - 2015-05-01 14:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 10:38 - 2015-05-05 02:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 10:38 - 2015-04-27 20:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-05-13 10:38 - 2015-04-27 20:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-13 10:38 - 2015-04-27 20:11 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-13 10:38 - 2015-04-27 20:11 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-13 10:38 - 2015-04-27 20:08 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-13 10:38 - 2015-04-27 20:05 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-13 10:38 - 2015-04-27 20:04 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-13 10:38 - 2015-04-27 20:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-13 10:38 - 2015-04-27 20:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-13 10:38 - 2015-04-27 20:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-13 10:38 - 2015-04-27 20:04 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-13 10:38 - 2015-04-27 20:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-13 10:38 - 2015-04-27 20:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-13 10:38 - 2015-04-27 20:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-13 10:38 - 2015-04-27 20:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-13 10:38 - 2015-04-27 20:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-13 10:38 - 2015-04-27 20:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-13 10:38 - 2015-04-27 20:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-13 10:38 - 2015-04-27 20:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-13 10:38 - 2015-04-27 20:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-13 10:38 - 2015-04-27 20:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-13 10:38 - 2015-04-27 20:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-13 10:38 - 2015-04-27 19:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-13 10:38 - 2015-04-27 19:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-13 10:38 - 2015-04-27 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-13 10:38 - 2015-04-20 03:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 10:38 - 2015-04-20 03:56 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 10:38 - 2015-04-20 03:03 - 02382336 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 10:38 - 2015-04-18 03:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 10:38 - 2015-01-29 04:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-13 10:37 - 2015-04-22 02:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 10:37 - 2015-04-21 17:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-13 10:37 - 2015-04-21 17:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-13 10:37 - 2015-04-21 17:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 10:37 - 2015-04-21 17:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 10:37 - 2015-04-21 17:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-13 10:37 - 2015-04-21 17:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-13 10:37 - 2015-04-21 17:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 10:37 - 2015-04-21 17:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-13 10:37 - 2015-04-21 17:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 10:37 - 2015-04-21 17:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-13 10:37 - 2015-04-21 17:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-13 10:37 - 2015-04-21 17:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 10:37 - 2015-04-21 16:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 10:37 - 2015-04-21 16:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-13 10:37 - 2015-04-21 16:58 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-13 10:37 - 2015-04-21 16:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-13 10:37 - 2015-04-21 16:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-13 10:37 - 2015-04-21 16:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-13 10:37 - 2015-04-21 16:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-13 10:37 - 2015-04-21 16:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-13 10:37 - 2015-04-21 16:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 10:37 - 2015-04-21 16:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 10:37 - 2015-04-21 16:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 10:37 - 2015-04-21 16:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 10:37 - 2015-04-21 16:26 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 10:37 - 2015-04-21 16:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 10:37 - 2015-04-21 16:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-13 10:37 - 2015-04-21 16:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 10:37 - 2015-04-21 16:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 10:37 - 2015-04-21 15:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 10:37 - 2015-04-21 15:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 10:37 - 2015-04-13 04:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 10:37 - 2015-04-08 04:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-13 10:37 - 2015-04-08 04:14 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-13 10:37 - 2015-03-04 05:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-13 10:37 - 2015-03-04 05:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-13 10:37 - 2015-03-04 05:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-13 10:37 - 2015-03-04 05:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-13 10:37 - 2015-02-18 08:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-11 14:19 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2015-05-11 14:18 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2015-05-11 14:16 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2015-05-11 14:15 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2015-05-11 14:14 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2015-05-10 19:37 - 2015-05-10 19:37 - 00000039 _____ () C:\Users\Public\Documents\CryptoPrevent Premium Product Key.txt
2015-05-09 19:38 - 2015-05-09 19:38 - 00002283 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2015-05-09 19:37 - 2015-05-09 19:41 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\DVDVideoSoft
2015-05-09 19:37 - 2015-05-09 19:38 - 00001210 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2015-05-09 19:37 - 2015-05-09 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-05-09 19:37 - 2015-05-09 19:38 - 00000000 ____D () C:\Program Files\Free Codec Pack
2015-05-09 19:37 - 2015-05-09 19:38 - 00000000 ____D () C:\Program Files\DVDVideoSoft
2015-05-09 19:37 - 2015-05-09 19:38 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2015-05-09 19:37 - 2015-05-09 19:37 - 00002187 _____ () C:\Users\Public\Desktop\Free YouTube Download.lnk
2015-05-08 19:42 - 2015-05-08 19:42 - 00520032 _____ () C:\Users\Andrea\Desktop\Amazon_co_uk - Online Return Center.mht
2015-05-07 19:50 - 2015-05-07 19:50 - 00287198 _____ () C:\Windows\msxml4-KB973688-enu.LOG
2015-05-07 12:00 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-06 14:15 - 2015-05-06 14:15 - 00291464 _____ () C:\Windows\msxml4-KB954430-enu.LOG
2015-05-06 14:15 - 2015-05-06 14:15 - 00000000 ____D () C:\Program Files\MSXML 4.0
2015-05-05 16:04 - 2015-05-15 08:06 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\HP
2015-05-05 16:04 - 2015-05-05 16:04 - 00000000 ____D () C:\ProgramData\WEBREG
2015-05-05 16:02 - 2015-05-11 15:04 - 00000000 ____D () C:\Program Files\Yahoo!
2015-05-05 16:02 - 2015-05-05 16:02 - 00002132 _____ () C:\Users\Public\Desktop\HP Photosmart Essential 3.5.lnk
2015-05-05 16:02 - 2015-05-05 16:02 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Yahoo!
2015-05-05 16:01 - 2015-05-05 16:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-05-05 16:01 - 2015-05-05 16:01 - 00001286 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\HP Solution Center.lnk
2015-05-05 16:01 - 2015-05-05 16:01 - 00001280 _____ () C:\Users\Public\Desktop\HP Solution Center.lnk
2015-05-05 16:01 - 2015-05-05 16:01 - 00001126 _____ () C:\Users\Public\Desktop\Shop for HP Supplies.lnk
2015-05-05 16:01 - 2015-05-05 16:01 - 00001028 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
2015-05-05 16:01 - 2015-05-05 16:01 - 00000000 ____D () C:\ProgramData\HP Product Assistant
2015-05-05 16:00 - 2015-05-05 16:00 - 00000000 ____D () C:\Program Files\Common Files\HP
2015-05-05 16:00 - 2015-05-05 16:00 - 00000000 ____D () C:\Program Files\Common Files\Hewlett-Packard
2015-05-05 15:58 - 2015-05-05 16:01 - 00000000 ____D () C:\Program Files\HP
2015-05-05 15:57 - 2015-05-15 08:06 - 00000000 ____D () C:\ProgramData\HP
2015-05-05 15:57 - 2015-05-05 16:03 - 00221501 _____ () C:\Windows\hpoins19.dat
2015-05-05 15:57 - 2015-05-05 16:03 - 00001252 _____ () C:\ProgramData\hpzinstall.log
2015-05-05 15:57 - 2009-10-20 05:30 - 00013898 ____N () C:\Windows\hpomdl19.dat
2015-05-05 15:57 - 2009-07-08 11:51 - 00452408 _____ (Hewlett-Packard) C:\Windows\system32\hpzids01.dll
2015-05-04 18:06 - 2015-05-26 09:48 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-04 16:55 - 2015-05-26 09:46 - 00000000 ____D () C:\Windows\pss
2015-05-03 19:57 - 2015-05-03 19:57 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-05-03 19:54 - 2015-05-03 19:54 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2015-05-03 19:54 - 2015-05-03 19:54 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2015-05-03 17:09 - 2015-05-03 17:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2015-05-03 17:09 - 2015-05-03 17:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-05-03 17:08 - 2015-05-03 17:08 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services
2015-05-03 17:07 - 2015-05-03 17:07 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8
2015-05-03 17:07 - 2015-05-03 17:07 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
2015-05-03 17:07 - 2015-05-03 17:07 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2015-05-03 17:06 - 2015-05-03 17:06 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2015-05-03 17:05 - 2015-05-13 20:19 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-05-03 17:05 - 2015-05-03 17:19 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Microsoft Help
2015-05-03 17:05 - 2015-05-03 17:07 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-05-03 17:05 - 2015-05-03 17:05 - 00000000 __RHD () C:\MSOCache
2015-05-03 16:50 - 2015-05-03 16:50 - 00001241 _____ () C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2015-05-03 16:50 - 2015-05-03 16:50 - 00000000 ____D () C:\Users\Andrea\AppData\Local\VS Revo Group
2015-05-03 16:50 - 2015-05-03 16:50 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-05-03 16:50 - 2015-05-03 16:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-05-03 16:50 - 2015-05-03 16:50 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-05-03 16:50 - 2009-12-30 10:21 - 00027192 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-05-03 16:43 - 2015-05-23 11:15 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-05-03 16:43 - 2015-05-03 16:43 - 00001972 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-05-03 16:43 - 2015-05-03 16:43 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\SUPERAntiSpyware.com
2015-05-03 16:43 - 2015-05-03 16:43 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2015-05-03 16:43 - 2015-05-03 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-05-03 16:41 - 2015-05-03 16:41 - 00001227 _____ () C:\Users\Andrea\Desktop\Spybot - Search & Destroy.lnk
2015-05-03 16:41 - 2015-05-03 16:41 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-05-03 16:41 - 2015-05-03 16:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2015-05-03 16:41 - 2015-05-03 16:41 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy
2015-05-03 16:36 - 2015-05-04 19:22 - 00000000 ____D () C:\ProgramData\TEMP
2015-05-03 16:36 - 2015-05-04 19:22 - 00000000 ____D () C:\Program Files\SpywareBlaster
2015-05-03 16:36 - 2015-05-03 16:36 - 00001048 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk
2015-05-03 16:36 - 2015-05-03 16:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2015-05-03 16:36 - 2015-05-03 16:36 - 00000000 ____D () C:\ProgramData\Licenses
2015-05-03 16:36 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\Windows\system32\MSSTDFMT.DLL
2015-05-03 16:27 - 2015-05-07 12:00 - 00001071 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-03 16:27 - 2015-05-07 12:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-03 16:27 - 2015-05-07 12:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-05-03 16:27 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-03 16:27 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-03 16:26 - 2015-05-03 16:27 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-03 16:26 - 2015-05-03 16:26 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Malwarebytes
2015-05-03 16:23 - 2015-05-26 09:48 - 00000526 _____ () C:\Windows\Tasks\AVG_SYS_TASK_0215pit.job
2015-05-03 16:23 - 2015-05-26 09:48 - 00000392 _____ () C:\Windows\Tasks\AVG_SYS_TASK_0215pit_DELETE.job
2015-05-03 16:23 - 2015-05-03 16:23 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Avg_Update_0215pit
2015-05-03 16:23 - 2015-05-03 16:23 - 00000000 ____D () C:\ProgramData\Avg_Update_0215pit
2015-05-03 16:19 - 2015-05-03 16:19 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\TuneUp Software
2015-05-03 16:05 - 2015-05-04 17:31 - 00000000 ____D () C:\ProgramData\MFAData
2015-05-03 16:05 - 2015-05-03 16:05 - 00000000 ____D () C:\Users\Andrea\AppData\Local\MFAData
2015-05-03 15:06 - 2015-05-10 16:01 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Foxit Software
2015-05-03 15:06 - 2015-05-03 15:06 - 00002102 _____ () C:\Users\Public\Desktop\Foxit Reader.lnk
2015-05-03 15:06 - 2015-05-03 15:06 - 00000000 ____D () C:\Users\Public\Foxit Software
2015-05-03 15:06 - 2015-05-03 15:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2015-05-03 15:06 - 2015-05-03 15:06 - 00000000 ____D () C:\Program Files\Foxit Software
2015-05-02 23:19 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2015-05-02 19:10 - 2015-05-02 19:10 - 00053248 _____ () C:\Windows\system32\zlib.dll
2015-05-02 19:10 - 2015-05-02 19:10 - 00001181 _____ () C:\Users\Public\Desktop\CryptoPrevent.lnk
2015-05-02 19:10 - 2015-05-02 19:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foolish IT
2015-05-02 19:10 - 2015-05-02 19:10 - 00000000 ____D () C:\ProgramData\Foolish IT
2015-05-02 19:10 - 2015-05-02 19:10 - 00000000 ____D () C:\Program Files\Foolish IT
2015-05-02 16:19 - 2015-05-02 16:19 - 00000669 _____ () C:\Users\Public\Desktop\DocX Viewer.lnk
2015-05-02 16:19 - 2015-05-02 16:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epingsoft
2015-05-02 16:19 - 2015-05-02 16:19 - 00000000 ____D () C:\epingsoft
2015-05-02 12:51 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2015-05-02 12:51 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2015-05-02 12:51 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2015-05-02 12:51 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2015-05-02 12:51 - 2014-07-09 02:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2015-05-02 12:51 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-05-02 12:51 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-05-02 12:51 - 2012-02-11 06:37 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2015-05-02 12:51 - 2011-03-11 06:39 - 00143744 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2015-05-02 12:51 - 2011-03-11 06:39 - 00117120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2015-05-02 12:51 - 2011-03-11 06:38 - 00332160 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2015-05-02 12:51 - 2011-03-11 06:38 - 00080256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2015-05-02 12:51 - 2011-03-11 06:38 - 00022400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2015-05-02 12:51 - 2011-03-11 06:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2015-05-02 12:51 - 2011-03-11 06:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2015-05-02 12:51 - 2011-03-11 05:01 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2015-05-02 12:51 - 2011-02-25 06:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-05-02 11:49 - 2015-05-04 17:27 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Citrix
2015-05-02 11:49 - 2015-05-04 17:27 - 00000000 ____D () C:\Program Files\Citrix
2015-05-02 11:22 - 2015-05-02 12:30 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Windows Live Writer
2015-05-02 11:22 - 2015-05-02 11:22 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Windows Live Writer
2015-05-02 11:21 - 2015-05-02 11:21 - 00001411 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-05-02 11:20 - 2015-05-02 11:21 - 00000000 ____D () C:\Program Files\Windows Live
2015-05-02 11:20 - 2015-05-02 11:20 - 00000000 ____D () C:\Windows\PCHEALTH
2015-05-02 11:17 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2015-05-02 11:16 - 2015-05-02 11:16 - 00002190 _____ () C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-05-02 11:16 - 2015-05-02 11:16 - 00002069 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-05-02 11:16 - 2015-05-02 11:16 - 00002069 _____ () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-05-02 11:16 - 2015-05-02 11:16 - 00000000 ___RD () C:\Users\Andrea\OneDrive
2015-05-02 11:16 - 2015-05-02 11:16 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2015-05-02 11:16 - 2015-05-02 11:16 - 00000000 ____D () C:\Program Files\Microsoft OneDrive
2015-05-02 11:15 - 2015-05-05 14:49 - 00000000 ____D () C:\Users\Andrea\AppData\Local\Windows Live
2015-05-02 11:15 - 2015-05-02 11:15 - 00000000 ____D () C:\Program Files\Common Files\Windows Live
2015-05-02 11:00 - 2015-05-02 11:00 - 00000000 __SHD () C:\Users\Andrea\AppData\Local\EmieUserList
2015-05-02 11:00 - 2015-05-02 11:00 - 00000000 __SHD () C:\Users\Andrea\AppData\Local\EmieSiteList
2015-05-02 11:00 - 2015-05-02 11:00 - 00000000 __SHD () C:\Users\Andrea\AppData\Local\EmieBrowserModeList
2015-05-02 08:24 - 2015-05-02 08:24 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-05-02 08:24 - 2015-05-02 08:24 - 00000000 ____D () C:\Windows\system32\appraiser
2015-05-02 08:20 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-05-02 06:14 - 2015-05-02 06:14 - 00008192 __RSH () C:\BOOTSECT.BAK
2015-05-02 06:14 - 2015-05-01 14:19 - 00000000 ____D () C:\Windows\Panther
2015-05-02 06:14 - 2014-06-28 01:21 - 00391640 __RSH () C:\bootmgr
2015-05-02 03:18 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-05-02 03:17 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-05-02 03:09 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2015-05-02 03:09 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2015-05-02 03:09 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2015-05-02 03:09 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2015-05-01 21:16 - 2015-05-01 21:16 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2015-05-01 21:16 - 2015-05-01 21:16 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2015-05-01 21:15 - 2015-05-01 21:16 - 00001355 _____ () C:\Windows\TSSysprep.log
2015-05-01 20:37 - 2015-05-05 16:21 - 00109664 _____ () C:\Users\Andrea\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-01 20:37 - 2015-05-01 20:37 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-05-01 20:37 - 2015-05-01 20:37 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\ATI
2015-05-01 20:37 - 2015-05-01 20:37 - 00000000 ____D () C:\Users\Andrea\AppData\Local\ATI
2015-05-01 20:37 - 2015-05-01 20:37 - 00000000 ____D () C:\Users\Andrea\AppData\Local\AMD
2015-05-01 20:37 - 2015-05-01 20:37 - 00000000 ____D () C:\ProgramData\ATI
2015-05-01 20:11 - 2015-05-01 20:11 - 00000000 _____ () C:\Windows\system32\spu_storage.bin
2015-05-01 20:11 - 2015-05-01 20:11 - 00000000 _____ () C:\Windows\ativpsrm.bin
2015-05-01 20:07 - 2015-05-20 20:00 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-01 19:08 - 2015-05-13 20:18 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-01 19:08 - 2015-05-13 20:14 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-01 18:09 - 2015-05-26 10:12 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-01 18:09 - 2015-05-19 14:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-05-01 18:09 - 2015-05-19 14:33 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-05-01 18:09 - 2015-05-01 18:09 - 00000000 ____D () C:\Windows\system32\Macromed
2015-05-01 18:09 - 2015-05-01 18:09 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Macromedia
2015-05-01 18:09 - 2015-05-01 18:09 - 00000000 ____D () C:\Users\Andrea\AppData\Roaming\Adobe
2015-05-01 18:08 - 2015-05-01 18:09 - 00000000 ___HD () C:\Windows\AxInstSV
2015-05-01 17:47 - 2015-05-01 17:47 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2015-05-01 17:18 - 2012-07-26 04:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2015-05-01 17:18 - 2012-07-26 04:20 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2015-05-01 17:18 - 2012-07-26 04:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2015-05-01 17:18 - 2012-07-26 04:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2015-05-01 17:18 - 2012-07-26 04:20 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2015-05-01 17:18 - 2012-07-26 03:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2015-05-01 17:18 - 2012-07-26 03:32 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2015-05-01 17:18 - 2012-06-02 15:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2015-05-01 17:17 - 2012-03-01 06:46 - 00019824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2015-05-01 17:17 - 2012-03-01 06:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-05-01 17:07 - 2015-05-01 17:07 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-05-01 17:07 - 2015-05-01 17:07 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-05-01 17:07 - 2015-05-01 17:07 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-05-01 17:07 - 2015-05-01 17:07 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-05-01 17:07 - 2015-05-01 17:07 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-05-01 17:07 - 2015-05-01 17:07 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-05-01 17:07 - 2015-05-01 17:07 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-05-01 17:07 - 2015-05-01 17:07 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-05-01 17:06 - 2015-05-01 17:06 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2015-05-01 17:06 - 2015-05-01 17:06 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2015-05-01 17:05 - 2015-05-01 17:05 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2015-05-01 17:05 - 2015-05-01 17:05 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2015-05-01 17:04 - 2015-05-01 17:08 - 00013968 _____ () C:\Windows\IE11_main.log
2015-05-01 17:04 - 2015-05-01 17:04 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2015-05-01 17:03 - 2015-01-09 03:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-05-01 17:03 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-05-01 17:03 - 2015-01-09 03:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-05-01 17:01 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2015-05-01 17:01 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2015-05-01 17:01 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2015-05-01 16:58 - 2015-03-23 04:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-05-01 16:58 - 2015-03-23 04:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-05-01 16:58 - 2015-03-23 04:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-05-01 16:58 - 2015-03-23 04:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-05-01 16:58 - 2015-03-23 04:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-05-01 16:58 - 2015-03-23 04:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-05-01 16:58 - 2015-03-23 04:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-05-01 16:58 - 2015-03-23 03:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-05-01 16:58 - 2015-01-28 00:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-05-01 16:58 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2015-05-01 16:58 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-05-01 16:58 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2015-05-01 16:58 - 2014-06-03 10:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-05-01 16:58 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-05-01 16:58 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-05-01 16:58 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2015-05-01 16:58 - 2014-03-04 10:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-05-01 16:58 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2015-05-01 16:58 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2015-05-01 16:58 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2015-05-01 16:58 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2015-05-01 16:58 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2015-05-01 16:58 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2015-05-01 16:58 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-05-01 16:58 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2015-05-01 16:58 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2015-05-01 16:58 - 2012-11-02 06:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2015-05-01 16:58 - 2012-10-03 17:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2015-05-01 16:58 - 2012-10-03 17:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2015-05-01 16:58 - 2012-10-03 17:40 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2015-05-01 16:58 - 2012-10-03 16:21 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2015-05-01 16:57 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-05-01 16:57 - 2014-11-11 02:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-05-01 16:57 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-05-01 16:57 - 2014-10-04 02:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-05-01 16:57 - 2014-10-04 02:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-05-01 16:57 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2015-05-01 16:57 - 2014-07-14 02:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-05-01 16:57 - 2014-06-16 02:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2015-05-01 16:57 - 2014-06-16 02:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2015-05-01 16:57 - 2014-06-16 02:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2015-05-01 16:57 - 2014-03-26 15:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-05-01 16:57 - 2014-03-26 15:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-05-01 16:57 - 2014-02-04 03:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2015-05-01 16:57 - 2014-02-04 03:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2015-05-01 16:57 - 2014-02-04 03:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2015-05-01 16:57 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2015-05-01 16:57 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2015-05-01 16:57 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2015-05-01 16:57 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2015-05-01 16:57 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2015-05-01 16:57 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2015-05-01 16:57 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2015-05-01 16:57 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2015-05-01 16:57 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2015-05-01 16:57 - 2013-08-28 01:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2015-05-01 16:57 - 2013-07-03 05:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2015-05-01 16:57 - 2013-07-03 04:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2015-05-01 16:57 - 2013-07-03 04:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2015-05-01 16:57 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2015-05-01 16:57 - 2013-02-12 04:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2015-05-01 16:57 - 2013-01-24 05:47 - 00196328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2015-05-01 16:57 - 2012-08-22 18:16 - 00712048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-05-01 16:57 - 2012-08-21 21:12 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2015-05-01 16:57 - 2012-07-04 20:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2015-05-01 16:57 - 2012-06-06 06:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2015-05-01 16:57 - 2011-12-30 06:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2015-05-01 16:57 - 2011-08-17 05:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2015-05-01 16:57 - 2011-08-17 05:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2015-05-01 16:57 - 2011-06-16 05:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2015-05-01 16:57 - 2011-05-03 05:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-05-01 16:57 - 2011-04-29 03:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2015-05-01 16:57 - 2011-04-29 03:46 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2015-05-01 16:57 - 2011-04-29 03:46 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2015-05-01 16:57 - 2011-03-03 06:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-05-01 16:57 - 2011-03-03 06:38 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2015-05-01 16:57 - 2011-03-03 06:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2015-05-01 16:57 - 2011-02-18 06:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2015-05-01 16:56 - 2015-03-05 05:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-05-01 16:56 - 2015-03-04 05:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-05-01 16:56 - 2015-03-04 05:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-05-01 16:56 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-05-01 16:56 - 2015-01-31 04:32 - 00919552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-05-01 16:56 - 2015-01-31 03:52 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-05-01 16:56 - 2015-01-31 03:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-05-01 16:56 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2015-05-01 16:56 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2015-05-01 16:56 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2015-05-01 16:56 - 2014-05-30 07:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-05-01 16:56 - 2014-04-05 03:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2015-05-01 16:56 - 2014-04-05 03:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2015-05-01 16:56 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2015-05-01 16:56 - 2014-01-24 03:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2015-05-01 16:56 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2015-05-01 16:56 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2015-05-01 16:56 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2015-05-01 16:56 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2015-05-01 16:56 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2015-05-01 16:56 - 2013-03-19 04:33 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2015-05-01 16:56 - 2012-07-04 22:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2015-05-01 16:56 - 2012-07-04 22:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2015-05-01 16:56 - 2012-07-04 22:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2015-05-01 16:56 - 2011-10-15 06:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2015-05-01 16:56 - 2011-08-27 05:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2015-05-01 16:56 - 2011-07-09 03:30 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-05-01 16:56 - 2011-05-24 11:44 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2015-05-01 16:56 - 2011-05-04 05:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-05-01 16:56 - 2011-05-04 05:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-05-01 16:56 - 2011-05-04 05:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2015-05-01 16:56 - 2011-05-04 05:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2015-05-01 16:56 - 2011-05-04 05:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2015-05-01 16:56 - 2011-05-04 05:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2015-05-01 16:56 - 2011-05-04 05:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-05-01 16:56 - 2011-05-04 05:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-05-01 16:56 - 2011-05-04 05:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2015-05-01 16:56 - 2011-04-27 03:17 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-05-01 16:56 - 2011-04-27 03:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-05-01 16:56 - 2011-02-12 06:35 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2015-05-01 16:56 - 2010-12-23 06:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2015-05-01 16:56 - 2010-12-23 06:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2015-05-01 16:56 - 2010-12-23 06:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2015-05-01 16:48 - 2015-03-25 04:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-05-01 16:48 - 2015-03-25 04:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-05-01 16:48 - 2015-03-25 04:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-05-01 16:48 - 2015-03-25 04:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-05-01 16:48 - 2015-03-25 04:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-05-01 16:48 - 2015-03-25 04:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-05-01 16:48 - 2015-03-25 04:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-05-01 16:48 - 2015-03-25 04:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-05-01 16:48 - 2015-03-25 04:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-05-01 16:48 - 2015-03-25 04:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-05-01 16:48 - 2015-03-25 04:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-05-01 16:48 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-05-01 16:48 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-05-01 16:48 - 2015-02-20 05:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-05-01 16:48 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-05-01 16:48 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-05-01 16:48 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-05-01 16:48 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-05-01 16:48 - 2014-12-11 18:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-05-01 16:48 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-05-01 16:48 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-05-01 16:48 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2015-05-01 16:48 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2015-05-01 16:48 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2015-05-01 16:48 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-05-01 16:48 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2015-05-01 16:48 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2015-05-01 16:48 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2015-05-01 16:48 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2015-05-01 16:48 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2015-05-01 16:48 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2015-05-01 16:48 - 2013-08-05 02:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2015-05-01 16:48 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2015-05-01 16:48 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-05-01 16:48 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-05-01 16:48 - 2013-02-15 04:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-05-01 16:48 - 2012-12-07 13:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2015-05-01 16:48 - 2012-12-07 13:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2015-05-01 16:48 - 2012-12-07 11:46 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2015-05-01 16:48 - 2012-12-07 11:46 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2015-05-01 16:48 - 2012-10-09 18:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2015-05-01 16:48 - 2012-10-09 18:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2015-05-01 16:48 - 2012-09-25 23:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2015-05-01 16:48 - 2012-05-14 05:33 - 00769024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-05-01 16:48 - 2012-04-26 05:45 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2015-05-01 16:48 - 2012-04-26 05:41 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2015-05-01 16:48 - 2012-03-17 08:27 - 00056176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2015-05-01 16:48 - 2012-01-04 09:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2015-05-01 16:48 - 2011-12-16 08:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2015-05-01 16:48 - 2011-11-17 06:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2015-05-01 16:48 - 2011-06-15 09:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\odbcjt32.dll
2015-05-01 16:48 - 2011-06-15 09:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2015-05-01 16:48 - 2011-06-15 09:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2015-05-01 16:48 - 2011-06-15 09:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2015-05-01 16:48 - 2011-06-15 09:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2015-05-01 16:47 - 2015-02-25 04:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-05-01 16:47 - 2015-02-03 04:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-05-01 16:47 - 2015-02-03 04:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-05-01 16:47 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-05-01 16:47 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-05-01 16:47 - 2015-02-03 04:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-05-01 16:47 - 2015-02-03 04:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-05-01 16:47 - 2015-02-03 04:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-05-01 16:47 - 2015-02-03 04:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-05-01 16:47 - 2015-02-03 04:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-05-01 16:47 - 2015-02-03 04:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-05-01 16:47 - 2015-02-03 04:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-05-01 16:47 - 2015-02-03 04:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-05-01 16:47 - 2015-02-03 04:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-05-01 16:47 - 2015-02-03 04:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-05-01 16:47 - 2015-02-03 04:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-05-01 16:47 - 2015-02-03 03:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-05-01 16:47 - 2015-01-31 00:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-01 16:47 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-05-01 16:47 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-05-01 16:47 - 2014-10-31 23:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-05-01 16:47 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2015-05-01 16:47 - 2014-06-28 01:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-05-01 16:47 - 2014-06-28 01:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-05-01 16:47 - 2014-04-25 03:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-05-01 16:47 - 2014-03-04 10:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-05-01 16:47 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-05-01 16:47 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2015-05-01 16:47 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2015-05-01 16:47 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2015-05-01 16:47 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2015-05-01 16:47 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2015-05-01 16:47 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2015-05-01 16:47 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2015-05-01 16:47 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2015-05-01 16:47 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2015-05-01 16:47 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2015-05-01 16:47 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2015-05-01 16:47 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2015-05-01 16:47 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2015-05-01 16:47 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2015-05-01 16:47 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2015-05-01 16:47 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2015-05-01 16:47 - 2013-08-02 02:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 01:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-05-01 16:47 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-01 16:47 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-01 16:47 - 2013-07-12 11:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2015-05-01 16:47 - 2013-06-25 23:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2015-05-01 16:47 - 2012-11-28 23:57 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2015-05-01 16:47 - 2012-11-28 23:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2015-05-01 16:47 - 2012-11-28 23:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2015-05-01 16:47 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-05-01 16:47 - 2012-10-03 17:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-05-01 16:47 - 2011-03-11 06:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2015-05-01 16:47 - 2011-03-11 06:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2015-05-01 16:47 - 2011-02-23 05:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2015-05-01 16:46 - 2015-03-10 04:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-05-01 16:46 - 2015-03-10 04:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-05-01 16:46 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-05-01 16:46 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-05-01 16:46 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-05-01 16:46 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-05-01 16:46 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-05-01 16:46 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-05-01 16:46 - 2013-02-27 05:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-05-01 16:42 - 2012-02-17 06:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2015-05-01 16:42 - 2012-02-17 05:13 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2015-05-01 16:18 - 2015-05-01 16:18 - 00000000 ____D () C:\Users\Andrea\AppData\Local\WindowsUpdate
2015-05-01 15:41 - 2015-05-01 15:41 - 00000000 ____D () C:\Windows\AsDmiHtm
2015-05-01 15:39 - 2015-02-24 04:23 - 00246920 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-05-01 15:38 - 2015-05-01 15:38 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2015-05-01 15:38 - 2015-05-01 15:38 - 00000000 ____D () C:\Windows\system32\RTCOM
2015-05-01 15:38 - 2013-10-22 13:38 - 02876760 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2015-05-01 15:38 - 2013-10-22 10:40 - 00673037 _____ () C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-05-01 15:38 - 2013-10-22 10:11 - 00123608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2015-05-01 15:38 - 2013-10-22 02:42 - 37850112 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes.dat
2015-05-01 15:38 - 2013-10-21 03:46 - 02328792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO.dll
2015-05-01 15:38 - 2013-10-11 04:31 - 00919600 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2015-05-01 15:38 - 2013-10-07 04:05 - 02547928 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2015-05-01 15:38 - 2013-10-02 02:42 - 00708920 _____ (ASUSTeKcomputer.Inc Inc) C:\Windows\system32\RTKSMSettingsIPC.dll
2015-05-01 15:38 - 2013-10-02 02:39 - 04880152 _____ (ASUSTeKcomputer.Inc Inc) C:\Windows\system32\RTKSMlfx.dll
2015-05-01 15:38 - 2013-09-26 09:11 - 00782040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2015-05-01 15:38 - 2013-09-09 08:32 - 05681192 _____ () C:\Windows\system32\Drivers\rtvienna.dat
2015-05-01 15:38 - 2013-08-23 20:14 - 00938752 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt32.dll
2015-05-01 15:38 - 2013-08-23 20:14 - 00823040 _____ (DTS, Inc.) C:\Windows\system32\sl3apo32.dll
2015-05-01 15:38 - 2013-08-23 20:14 - 00604928 _____ (DTS, Inc.) C:\Windows\system32\sltech32.dll
2015-05-01 15:38 - 2013-08-23 20:14 - 00218368 _____ (TODO: ) C:\Windows\system32\slprp32.dll
2015-05-01 15:38 - 2013-08-20 10:36 - 00502584 _____ () C:\Windows\system32\audioLibVc.dll
2015-05-01 15:38 - 2013-08-14 09:36 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2015-05-01 15:38 - 2013-08-14 09:35 - 00761088 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO20.dll
2015-05-01 15:38 - 2013-08-07 10:34 - 00642304 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO.dll
2015-05-01 15:38 - 2013-07-23 08:40 - 01824000 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
2015-05-01 15:38 - 2013-07-23 08:39 - 03354880 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnN.dll
2015-05-01 15:38 - 2013-04-24 10:16 - 01596488 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2015-05-01 15:38 - 2012-08-31 12:17 - 07162128 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP32A.dll
2015-05-01 15:38 - 2012-08-31 12:17 - 00352016 _____ (Dolby Laboratories) C:\Windows\system32\R4EED32A.dll
2015-05-01 15:38 - 2012-08-31 12:17 - 00106768 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL32A.dll
2015-05-01 15:38 - 2012-08-31 12:17 - 00091920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA32A.dll
2015-05-01 15:38 - 2012-08-31 12:17 - 00062224 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG32A.dll
2015-05-01 15:38 - 2012-01-30 04:42 - 00819648 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo2.dll
2015-05-01 15:38 - 2012-01-10 03:20 - 00058264 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\TepeqAPO.dll
2015-05-01 15:38 - 2011-11-22 09:28 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2015-05-01 15:38 - 2011-09-02 07:21 - 00214368 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK.dll
2015-05-01 15:38 - 2011-09-02 07:21 - 00074080 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM.dll
2015-05-01 15:38 - 2011-09-02 07:21 - 00068960 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO.dll
2015-05-01 15:38 - 2011-03-17 05:16 - 01379760 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2015-05-01 15:38 - 2011-03-07 10:03 - 00134584 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2015-05-01 15:38 - 2010-11-08 00:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll
2015-05-01 15:38 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll
2015-05-01 15:38 - 2010-11-08 00:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll
2015-05-01 15:38 - 2010-11-08 00:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll
2015-05-01 15:38 - 2010-11-08 00:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll
2015-05-01 15:38 - 2010-11-08 00:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll
2015-05-01 15:38 - 2009-11-24 02:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll
2015-05-01 15:38 - 2009-11-24 02:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll
2015-05-01 15:38 - 2009-11-24 02:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll
2015-05-01 15:38 - 2009-11-24 02:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll
2015-05-01 15:38 - 2009-11-18 11:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll
2015-05-01 15:37 - 2015-05-01 15:39 - 00000000 ___HD () C:\Program Files\Temp
2015-05-01 15:37 - 2015-05-01 15:37 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2015-05-01 15:37 - 2013-10-15 20:43 - 00182472 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2015-05-01 15:37 - 2013-10-11 05:47 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-05-01 15:37 - 2013-10-06 17:14 - 00426944 _____ (DTS) C:\Windows\system32\DTSU2PLFX32.dll
2015-05-01 15:37 - 2013-10-06 17:14 - 00403392 _____ (DTS) C:\Windows\system32\DTSU2PGFX32.dll
2015-05-01 15:37 - 2013-10-06 17:14 - 00346048 _____ (DTS) C:\Windows\system32\DTSU2PREC32.dll
2015-05-01 15:37 - 2013-09-13 11:44 - 02080472 ____R (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2015-05-01 15:37 - 2013-09-09 21:02 - 06176944 _____ (Dolby Laboratories) C:\Windows\system32\DDPP32A.dll
2015-05-01 15:37 - 2013-09-09 21:02 - 00272048 _____ (Dolby Laboratories) C:\Windows\system32\DDPO32A.dll
2015-05-01 15:37 - 2013-09-09 21:01 - 01489072 _____ (Dolby Laboratories) C:\Windows\system32\DDPD32A.dll
2015-05-01 15:37 - 2013-09-09 21:01 - 00219312 _____ (Dolby Laboratories) C:\Windows\system32\DDPA32.dll
2015-05-01 15:37 - 2013-08-14 09:36 - 01065216 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO50.dll
2015-05-01 15:37 - 2013-08-14 09:36 - 00873728 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO40.dll
2015-05-01 15:37 - 2013-08-14 09:35 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2015-05-01 15:37 - 2013-08-05 11:10 - 02395680 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2015-05-01 15:37 - 2013-07-28 03:48 - 27258112 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnA.dll
2015-05-01 15:37 - 2013-07-24 03:07 - 01932544 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2015-05-01 15:37 - 2013-07-23 08:40 - 13789440 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll
2015-05-01 15:37 - 2013-07-23 08:39 - 01673472 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek2.dll
2015-05-01 15:37 - 2013-07-23 08:39 - 00790272 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell.dll
2015-05-01 15:37 - 2013-06-17 13:20 - 00188696 _____ () C:\Windows\system32\AcpiServiceVnA.dll
2015-05-01 15:37 - 2013-04-03 07:12 - 00852016 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2015-05-01 15:37 - 2012-03-08 04:47 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2015-05-01 15:37 - 2011-08-23 10:00 - 00357712 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 01509480 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 01292904 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 01220200 _____ (DTS) C:\Windows\system32\DTSBoostDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00654952 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00631400 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00601704 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00458344 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00389736 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00375400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPONS.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPO.dll
2015-05-01 15:37 - 2011-05-31 02:42 - 00218216 _____ (DTS) C:\Windows\system32\DTSLFXAPO.dll
2015-05-01 15:37 - 2010-09-27 02:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-05-01 15:37 - 2009-12-04 08:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll
2015-05-01 15:36 - 2015-05-01 15:37 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-05-01 15:36 - 2015-05-01 15:37 - 00000000 ____D () C:\Program Files\Realtek
2015-05-01 15:36 - 2013-11-26 08:49 - 00683736 _____ (Realtek ) C:\Windows\system32\Drivers\Rt86win7.sys
2015-05-01 15:36 - 2013-11-26 08:49 - 00100896 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst32.dll
2015-05-01 15:36 - 2013-11-26 08:49 - 00076872 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp32.dll
2015-05-01 15:24 - 2015-05-01 15:24 - 00000000 ____D () C:\ProgramData\AMD
2015-05-01 15:24 - 2015-05-01 15:24 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2015-05-01 15:24 - 2015-05-01 15:24 - 00000000 ____D () C:\Program Files\AMD AVT
2015-05-01 15:23 - 2015-05-01 15:23 - 00000000 ____D () C:\AMD
2015-05-01 15:23 - 2013-11-01 18:22 - 00995342 _____ () C:\Windows\system32\amdocl_as32.exe
2015-05-01 15:23 - 2013-11-01 18:22 - 00798734 _____ () C:\Windows\system32\amdocl_ld32.exe
2015-05-01 15:23 - 2013-11-01 18:22 - 00200704 _____ () C:\Windows\system32\clinfo.exe
2015-05-01 15:23 - 2013-11-01 18:22 - 00083968 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OpenVideo.dll
2015-05-01 15:23 - 2013-11-01 18:22 - 00073728 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\OVDecode.dll
2015-05-01 15:23 - 2013-11-01 18:19 - 24859648 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl.dll
2015-05-01 15:23 - 2013-11-01 18:17 - 00057344 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-05-01 15:23 - 2013-11-01 18:12 - 00114688 _____ (AMD) C:\Windows\system32\coinst_13.25.26.dll
2015-05-01 15:23 - 2013-11-01 18:10 - 00068608 _____ () C:\Windows\system32\hsaumd.dll
2015-05-01 15:23 - 2013-11-01 18:03 - 22103040 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdhsacl.dll
2015-05-01 15:23 - 2013-11-01 17:58 - 00547808 _____ () C:\Windows\system32\atiapfxx.blb
2015-05-01 15:23 - 2013-11-01 17:38 - 00442368 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2015-05-01 15:23 - 2013-11-01 17:09 - 00204952 _____ () C:\Windows\system32\ativvsvl.dat
2015-05-01 15:23 - 2013-11-01 17:09 - 00157144 _____ () C:\Windows\system32\ativvsva.dat
2015-05-01 15:23 - 2013-09-30 21:48 - 00047887 _____ () C:\Windows\atiogl.xml
2015-05-01 15:23 - 2013-09-26 22:14 - 00083552 _____ () C:\Windows\system32\ativce02.dat
2015-05-01 15:23 - 2013-09-24 15:52 - 00077312 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdW73.sys
2015-05-01 15:23 - 2013-09-24 15:50 - 00084480 _____ (TODO: ) C:\Windows\system32\DelayAPO.dll
2015-05-01 15:23 - 2013-09-12 17:31 - 00233776 _____ () C:\Windows\system32\ativvaxy_cik_nd.dat
2015-05-01 15:23 - 2013-09-12 17:30 - 00234036 _____ () C:\Windows\system32\ativvaxy_cik.dat
2015-05-01 15:23 - 2013-06-27 16:50 - 00070464 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amd_sata.sys
2015-05-01 15:23 - 2013-06-27 16:50 - 00034624 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amd_xata.sys
2015-05-01 15:23 - 2013-05-27 20:09 - 00178496 _____ (Advanced Micro Devices, INC.) C:\Windows\system32\Drivers\amdxhc.sys
2015-05-01 15:23 - 2013-05-27 20:09 - 00085312 _____ (Advanced Micro Devices, INC.) C:\Windows\system32\Drivers\amdhub30.sys
2015-05-01 15:23 - 2011-09-12 23:06 - 00003917 _____ () C:\Windows\system32\atipblag.dat
2015-05-01 15:21 - 2015-05-11 14:37 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-01 15:21 - 2015-05-03 17:07 - 00000000 ____D () C:\Program Files\Microsoft.NET
2015-05-01 15:20 - 2015-05-01 15:24 - 00000000 ____D () C:\Program Files\ATI Technologies
2015-05-01 15:20 - 2015-05-01 15:20 - 00000000 ____D () C:\Program Files\ATI
2015-05-01 15:19 - 2015-05-01 15:54 - 00030440 _____ () C:\Windows\Ascd_tmp.ini
2015-05-01 15:19 - 2015-05-01 15:54 - 00001769 _____ () C:\Windows\Language_trs.ini
2015-05-01 15:19 - 2015-05-01 15:54 - 00000192 _____ () C:\Windows\As_Utilities.log
2015-05-01 15:19 - 2015-05-01 15:19 - 00016896 _____ (ASUS) C:\Windows\AsTaskSched.dll
2015-05-01 14:19 - 2015-05-26 09:54 - 01288389 _____ () C:\Windows\WindowsUpdate.log
2015-05-01 14:19 - 2015-05-11 15:56 - 00000000 ____D () C:\Users\Andrea
2015-05-01 14:19 - 2015-05-01 15:37 - 00000000 ____D () C:\Windows\SoftwareDistributionOLD
2015-05-01 14:19 - 2015-05-01 14:19 - 00001427 _____ () C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-05-01 14:19 - 2015-05-01 14:19 - 00000020 ___SH () C:\Users\Andrea\ntuser.ini
2015-05-01 14:19 - 2015-05-01 14:19 - 00000000 __SHD () C:\Recovery
2015-05-01 14:19 - 2015-05-01 14:19 - 00000000 ____D () C:\Users\Andrea\AppData\Local\VirtualStore
2015-05-01 14:19 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-01 14:19 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-26 09:56 - 2009-07-14 05:34 - 00020448 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-26 09:56 - 2009-07-14 05:34 - 00020448 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-26 09:48 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-26 09:48 - 2009-07-14 05:39 - 00030657 _____ () C:\Windows\setupact.log
2015-05-25 14:57 - 2010-11-20 22:01 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-20 10:34 - 2010-11-20 22:48 - 00032326 _____ () C:\Windows\PFRO.log
2015-05-15 08:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-05-14 17:50 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-14 13:44 - 2011-04-12 03:24 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-14 13:22 - 2009-07-14 05:33 - 00408752 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-14 13:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-11 15:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\registration
2015-05-11 14:27 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Cursors
2015-05-07 12:22 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-05-05 16:03 - 2009-07-14 03:04 - 00000513 _____ () C:\Windows\win.ini
2015-05-05 16:00 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\twain_32
2015-05-03 19:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-05-03 19:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-05-03 17:08 - 2011-04-12 03:24 - 00000000 ____D () C:\Windows\ShellNew
2015-05-03 17:08 - 2009-07-14 05:52 - 00000000 ____D () C:\Program Files\MSBuild
2015-05-03 15:06 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-05-03 10:36 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\AppCompat
2015-05-02 06:14 - 2009-07-14 05:57 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2015-05-02 06:14 - 2009-07-14 05:52 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2015-05-02 03:29 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing
2015-05-01 21:16 - 2009-07-14 05:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-01 21:16 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-01 21:15 - 2011-04-12 03:24 - 00000000 ____D () C:\Windows\CSC
2015-05-01 21:15 - 2009-07-14 05:34 - 00002790 _____ () C:\Windows\DtcInstall.log
2015-05-01 20:42 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-05-01 20:06 - 2009-07-14 05:52 - 00000000 ____D () C:\Program Files\Windows Defender
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-TW
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-HK
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-CN
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\tr-TR
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\sv-SE
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ru-RU
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pt-PT
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pt-BR
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pl-PL
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\nl-NL
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\nb-NO
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ko-KR
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ja-JP
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\it-IT
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\hu-HU
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\fr-FR
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\fi-FI
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\el-GR
2015-05-01 20:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-05-01 15:50 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries
2015-05-01 15:21 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\restore
 
==================== Files in the root of some directories =======
 
2015-05-01 15:38 - 2015-05-01 15:38 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-05-05 15:57 - 2015-05-05 16:03 - 0001252 _____ () C:\ProgramData\hpzinstall.log
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-05-24 11:14
 
==================== End of log ============================
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 25-05-2015
Ran by [removed] at 2015-05-26 10:13:35
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1844252164-2368963752-2148446147-500 - Administrator - Disabled)
Andrea (S-1-5-21-1844252164-2368963752-2148446147-1000 - Administrator - Enabled) => C:\Users\Andrea
Guest (S-1-5-21-1844252164-2368963752-2148446147-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1844252164-2368963752-2148446147-1003 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 6.1.1 - Hewlett-Packard) Hidden
Adobe Flash Player 17 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 17.0.0.188 - Adobe Systems Incorporated)
AIO_CDB_ProductContext (Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_CDB_Software (Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_Scan (Version: 130.0.421.000 - Hewlett-Packard) Hidden
Amazon Kindle (HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\Amazon Kindle) (Version:  - Amazon)
AMD Catalyst Install Manager (HKLM\…\{09802AD7-805A-8720-582C-BF7B66E6B6E4}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden
Citrix Online Launcher (HKLM\…\{6740FE60-43C1-4D15-8C4A-001624134B14}) (Version: 1.0.312 - Citrix)
Copy (Version: 130.0.428.000 - Hewlett-Packard) Hidden
CryptoPrevent (HKLM\…\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version:  - Foolish IT LLC)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 130.0.465.000 - Hewlett-Packard) Hidden
DocProc (Version: 13.0.0.0 - Hewlett-Packard) Hidden
DocX Viewer version 1.2 (HKLM\…\DocX Viewer_is1) (Version: 1.2 - )
F300 (Version: 130.0.365.000 - Hewlett-Packard) Hidden
F300_Help (Version: 82.0.242.000 - Hewlett-Packard) Hidden
F300Trb (Version: 82.0.242.000 - Hewlett-Packard) Hidden
Fax (Version: 130.0.418.000 - Hewlett-Packard) Hidden
Foxit Cloud (HKLM\…\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 3.4.96.511 - Foxit Software Inc.)
Foxit Reader (HKLM\…\Foxit Reader_is1) (Version: 7.1.0.306 - Foxit Software Inc.)
Free YouTube Download version 3.2.58.505 (HKLM\…\Free YouTube Download_is1) (Version: 3.2.58.505 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.59.505 (HKLM\…\Free YouTube to MP3 Converter_is1) (Version: 3.12.59.505 - DVDVideoSoft Ltd.)
Google Toolbar for Internet Explorer (HKLM\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6227.252 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.24.7 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HP Customer Participation Program 13.0 (HKLM\…\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\…\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photosmart Essential 3.5 (HKLM\…\HP Photosmart Essential) (Version: 3.5 - HP)
HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (HKLM\…\{B61ED343-0B14-4241-999C-490CB1A20DA4}) (Version: 13.0 - HP)
HP Smart Web Printing 4.51 (HKLM\…\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM\…\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard)
HPPhotoGadget (Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotosmartEssential (Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden
Junk Mail filter update (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 4.5 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 2015 (HKLM\…\{763EF8DC-4CC0-47CA-BE1C-BDE731462250}) (Version: 16.0.02900 - Nero AG)
Nero Info (HKLM\…\{B791E0AB-87A9-41A4-8D98-D13C2E37D928}) (Version: 16.0.1003 - Nero AG)
Network (Version: 130.0.572.000 - Hewlett-Packard) Hidden
OCR Software by I.R.I.S. 13.0 (HKLM\…\HPOCR) (Version: 13.0 - HP)
Prerequisite installer (Version: 16.0.0000 - Nero AG) Hidden
Realtek Ethernet Controller Driver (HKLM\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.77.1126.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7071 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.0.8 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.0.8 - VS Revo Group, Ltd.)
Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 13.0 - HP)
SmartWebPrinting (Version: 130.0.457.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Spybot - Search & Destroy (HKLM\…\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
SpywareBlaster 5.0 (HKLM\…\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
Status (Version: 130.0.469.000 - Hewlett-Packard) Hidden
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1158 - SUPERAntiSpyware.com)
Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (Version: 130.0.422.000 - Hewlett-Packard) Hidden
UnloadSupport (Version: 11.0.0 - Hewlett-Packard) Hidden
Visual Studio 2012 x86 Redistributables (HKLM\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> C:\Users\Andrea\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Andrea\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> C:\Users\Andrea\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Andrea\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Andrea\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Andrea\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Andrea\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\FileSyncApi.dll (Microsoft Corporation)
 
==================== Restore Points =========================
 
02-05-2015 10:37:39 new recovered system point
02-05-2015 11:15:51 Windows Live Essentials
02-05-2015 11:17:31 Installed DirectX
02-05-2015 11:19:36 Windows Live Essentials
02-05-2015 11:20:26 WLSetup
02-05-2015 23:17:52 Windows Update
03-05-2015 16:18:01 Installed AVG 2015
03-05-2015 16:18:18 Installed AVG 2015
03-05-2015 17:04:46 Installed Microsoft Office Professional Plus 2010
03-05-2015 19:51:49 Windows Update
04-05-2015 17:19:19 Revo Uninstaller Pro's restore point - AVG 2015
04-05-2015 17:20:15 Removed AVG 2015
04-05-2015 17:22:44 Removed AVG 2015
04-05-2015 17:26:25 Revo Uninstaller Pro's restore point - GoToAssist Corporate
04-05-2015 17:27:41 Revo Uninstaller Pro's restore point - Malwarebytes' Anti-Malware
04-05-2015 17:29:12 Revo Uninstaller Pro's restore point - Citrix Online Launcher
04-05-2015 19:50:01 Windows Update
05-05-2015 22:42:20 Windows Update
06-05-2015 14:14:57 Windows Update
07-05-2015 19:50:21 Windows Update
09-05-2015 19:34:41 Revo Uninstaller Pro's restore point - Free Studio version 6.5.1.415
11-05-2015 14:14:20 Installed DirectX
11-05-2015 14:15:36 Installed DirectX
11-05-2015 14:16:42 Installed DirectX
11-05-2015 14:17:50 Installed DirectX
11-05-2015 14:18:54 Installed DirectX
11-05-2015 14:22:57 Installed Nero 12.
11-05-2015 14:36:02 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
11-05-2015 14:36:23 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
11-05-2015 15:02:16 Revo Uninstaller Pro's restore point - Yahoo! Toolbar
11-05-2015 15:42:08 Installed Nero CoverDesigner.
11-05-2015 15:52:56 Restore Operation
12-05-2015 13:49:29 Windows Update
13-05-2015 20:08:28 Windows Update
14-05-2015 13:44:28 Windows Update
15-05-2015 15:50:27 Revo Uninstaller Pro's restore point - Nero 12
15-05-2015 16:05:44 Installed Nero 2015.
19-05-2015 14:36:25 Revo Uninstaller Pro's restore point - Google Toolbar for Internet Explorer
19-05-2015 14:39:49 Revo Uninstaller Pro's restore point - Google Chrome
19-05-2015 14:41:20 Windows Update
20-05-2015 19:59:35 Windows Update
26-05-2015 09:53:44 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0CDF37E1-84DF-448A-AFE3-828CC8867F2D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-19] (Google Inc.)
Task: {29CB5EB9-53B0-42F2-8233-1A18A677DAD9} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
Task: {4A206E99-DF88-4D74-A759-7A53A8B167B8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-19] (Google Inc.)
Task: {620E4217-D677-4F59-8B33-96F6A35EB455} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation)
Task: {7B676B1D-7E27-4302-BF65-EBA4F3F0D841} - System32\Tasks\AVG_SYS_TASK_0215pit_DELETE => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe [2015-02-17] ()
Task: {8699692F-82C7-4FE9-AD0E-A20CE73AE7ED} - System32\Tasks\Nero\Nero Info => C:\Program Files\Common Files\Nero\Nero Info\NeroInfo.exe [2014-07-21] (Nero AG)
Task: {86D54BC1-68FA-464D-8A5F-D5B7DC197B20} - System32\Tasks\AVG_SYS_TASK_0215pit => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe [2015-02-17] ()
Task: {9E64D04F-9248-4A24-9748-1DC2ED9FD7F5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-19] (Adobe Systems Incorporated)
Task: {F5DD7D18-DFF9-4365-814E-71A5E80FB232} - System32\Tasks\{24F92A4A-D799-46D0-B7AD-D315DC566589} => pcalua.exe -a "C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RevoUninPro.exe" -d "C:\Program Files\VS Revo Group\Revo Uninstaller Pro"
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AVG_SYS_TASK_0215pit.job => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
Task: C:\Windows\Tasks\AVG_SYS_TASK_0215pit_DELETE.job => C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-11-01 11:45 - 2013-11-01 11:45 - 00203776 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2013-07-26 05:18 - 2013-07-26 05:18 - 03854336 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2013-07-26 05:18 - 2013-07-26 05:18 - 00618496 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2015-05-03 16:23 - 2015-02-17 14:31 - 02794520 _____ () C:\ProgramData\Avg_Update_0215pit\AVG-Secure-Search-Update_0215pit.exe
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2014-03-31 21:35 - 2014-03-31 21:35 - 00270016 _____ () C:\Program Files\Windows Live\Writer\en\WindowsLive.Writer.Localization.resources.dll
2014-03-31 21:35 - 2014-03-31 21:35 - 00270016 _____ () C:\Program Files\Windows Live\Writer\en-GB\WindowsLive.Writer.Localization.resources.dll
2013-11-01 11:45 - 2013-11-01 11:45 - 00095744 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\…\1001movie.com -> 1001movie.com
 
There are 6091 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1844252164-2368963752-2148446147-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Andrea\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254
 
==================== MSCONFIG/TASK MANAGER Error getting ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{58C0BF9C-50EA-41A6-8C9F-209E937E1ACC}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{A0BD5E9E-65B1-4BFC-BAFE-7A364C4336A2}] => (Allow) C:\Users\Andrea\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{144002E0-1B49-4C96-A49F-80175941D616}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{CDD3B1C3-3687-4FD0-B188-A52E2A20A41B}] => (Allow) LPort=2869
FirewallRules: [{7DA9788B-423C-444C-BD1A-AC3B7121F252}] => (Allow) LPort=1900
FirewallRules: [{9842E32A-7FF1-4873-A312-BBD4403AA7D8}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{D885AFB1-30D6-41B5-81E9-18D6C8D7F6FC}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{07148E9D-7C4B-4C04-A097-88DDA815A669}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{B355C0B2-551C-4731-9B61-426A861CDE91}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{1AA92699-03EE-4E98-9280-93D657BB661C}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{6FA8E432-D4FE-4B97-8023-61CF85E3EC7A}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{0906D55E-C83E-43C3-AE75-C24FDFEC197F}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{01DD3582-884F-4532-AC1C-FCAD46B6EFC5}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{9B1B6303-2345-4A00-8AD5-CCC3416E70BB}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{3DE114A6-9B89-4456-9774-8AB11A5A7B17}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{2ABA8BBE-28EF-42CC-8E48-11641B3BC5FD}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
FirewallRules: [{6F4F45EA-E37F-4490-A93E-3ACE1720D52A}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{0F3C8DDC-C8A0-484A-B185-9215E556F1AA}] => (Allow) C:\Program Files\common files\hp\digital imaging\bin\hpqphotocrm.exe
FirewallRules: [{E3885342-5596-46BA-A4F5-F7F46C6F2D63}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe
FirewallRules: [{36E089B8-343D-4DDA-BEA3-837F9096C4FC}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe
FirewallRules: [{48942888-2108-4FB0-A150-5A70D47E66D7}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{85F612C9-3FA1-4DC0-9BE7-262504123DD6}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{D0ED6BCD-A467-4B82-99BB-C89896F86BA6}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe
FirewallRules: [{4982F220-A75B-4A02-BBAE-DBCEB0F02A43}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{3835C14B-90BA-4A6A-B277-716FCE2AC486}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{C724EF70-FE09-4A2E-88D8-E6A0FF89B7C4}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{E7782547-307A-4C62-AB24-68B687B12D6E}] => (Allow) C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{40F1573E-923A-4B88-9750-7EDF8102739E}] => (Allow) C:\Program Files\HP\hp software update\hpwucli.exe
FirewallRules: [{087931C8-4DC3-48A8-B3FE-618562E6A8EC}] => (Allow) C:\Program Files\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{D8E0B0EF-55C9-4136-891D-FCABFE6D317C}] => (Allow) C:\Program Files\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{8168F0D2-3F94-4E32-9FDD-2D8FE89C14D7}] => (Allow) C:\Program Files\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{DAAD5F80-755A-4684-A5F2-4F5EE26E863D}] => (Allow) C:\Program Files\Nero\Nero 2015\Nero Burning ROM\StartNBR.exe
FirewallRules: [{840DFF37-DDAB-4476-97B7-2C967EC38BD3}] => (Allow) C:\Program Files\Nero\KM\NMDllHost.exe
FirewallRules: [{5ED65181-4961-4061-9200-9B6B4D609FA8}] => (Allow) C:\Program Files\Nero\Nero 2015\Nero Burning ROM\nero.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/26/2015 09:48:09 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/26/2015 09:43:32 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 02:44:53 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 02:41:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: msconfig.exe, version: 6.1.7601.17514, time stamp: 0x4ce78d12
Faulting module name: msvcrt.dll, version: 7.0.7601.17744, time stamp: 0x4eeaf722
Exception code: 0xc0000005
Fault offset: 0x0000a749
Faulting process id: 0x16c0
Faulting application start time: 0xmsconfig.exe0
Faulting application path: msconfig.exe1
Faulting module path: msconfig.exe2
Report Id: msconfig.exe3
 
Error: (05/25/2015 02:37:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 02:03:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 02:00:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 00:08:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/24/2015 08:03:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.17801, time stamp: 0x5536642c
Faulting module name: atidxx32.dll, version: 8.17.10.525, time stamp: 0x5273d74a
Exception code: 0xc0000005
Fault offset: 0x0041cc1a
Faulting process id: 0x164c
Faulting application start time: 0xiexplore.exe0
Faulting application path: iexplore.exe1
Faulting module path: iexplore.exe2
Report Id: iexplore.exe3
 
Error: (05/24/2015 11:16:03 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
 
System errors:
=============
Error: (05/24/2015 08:02:51 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (05/24/2015 08:02:51 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (05/24/2015 08:02:18 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (05/24/2015 08:02:18 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (05/23/2015 08:10:01 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 20.
 
Error: (05/23/2015 06:08:29 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (05/23/2015 06:08:29 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (05/20/2015 07:39:23 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (05/20/2015 07:39:23 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 43. The internal error state is 252.
 
Error: (05/19/2015 07:40:00 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
 
 
Microsoft Office:
=========================
Error: (05/26/2015 09:48:09 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/26/2015 09:43:32 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 02:44:53 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 02:41:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: msconfig.exe6.1.7601.175144ce78d12msvcrt.dll7.0.7601.177444eeaf722c00000050000a74916c001d096effc771506C:\Windows\system32\msconfig.exeC:\Windows\system32\msvcrt.dllcb9ef9c6-02e3-11e5-85d6-10c37b4e2507
 
Error: (05/25/2015 02:37:13 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 02:03:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 02:00:27 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/25/2015 00:08:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
 
Error: (05/24/2015 08:03:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iexplore.exe11.0.9600.178015536642catidxx32.dll8.17.10.5255273d74ac00000050041cc1a164c01d096522b1e3f43C:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\atidxx32.dll99322c93-0247-11e5-82a5-10c37b4e2507
 
Error: (05/24/2015 11:16:03 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\SLSTaskbar64.exe
 
 
==================== Memory info =========================== 
 
Processor: AMD A10-7850K Radeon R7, 12 Compute Cores 4C+8G
Percentage of memory in use: 54%
Total physical RAM: 2516.05 MB
Available physical RAM: 1134.99 MB
Total Pagefile: 5030.41 MB
Available Pagefile: 3007.54 MB
Total Virtual: 2047.88 MB
Available Virtual: 1890.1 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:465.76 GB) (Free:387.38 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (New Volume) (Fixed) (Total:621 GB) (Free:620.9 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:621 GB) (Free:620.9 GB) NTFS
Drive f: (New Volume) (Fixed) (Total:621 GB) (Free:620.9 GB) NTFS
Drive g: () (Fixed) (Total:116.44 GB) (Free:12.04 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive h: () (Fixed) (Total:116.44 GB) (Free:111.87 GB) NTFS
Drive i: () (Fixed) (Total:116.44 GB) (Free:112.62 GB) NTFS
Drive j: () (Fixed) (Total:116.44 GB) (Free:112.73 GB) NTFS
Drive k: (New Volume) (Fixed) (Total:465.75 GB) (Free:465.65 GB) NTFS
Drive l: (New Volume) (Fixed) (Total:465.75 GB) (Free:465.65 GB) NTFS
Drive m: (New Volume) (Fixed) (Total:465.75 GB) (Free:465.65 GB) NTFS
Drive n: (New Volume) (Fixed) (Total:465.75 GB) (Free:465.65 GB) NTFS
Drive o: (Data11) (Fixed) (Total:232.88 GB) (Free:228.81 GB) NTFS
Drive p: (Data12) (Fixed) (Total:232.88 GB) (Free:227.11 GB) NTFS
Drive q: (Data13) (Fixed) (Total:232.88 GB) (Free:211.02 GB) NTFS
Drive r: (Data14) (Fixed) (Total:232.88 GB) (Free:230.53 GB) NTFS
Drive s: (Data7) (Fixed) (Total:232.88 GB) (Free:96.12 GB) NTFS
Drive t: (Data8) (Fixed) (Total:232.88 GB) (Free:72.75 GB) NTFS
Drive u: (Data9) (Fixed) (Total:232.88 GB) (Free:103.67 GB) NTFS
Drive v: (Data10) (Fixed) (Total:232.88 GB) (Free:106.82 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: F023775F)
Partition 1: (Not Active) - (Size=621 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=621 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=621 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: BB0F1083)
Partition 1: (Active) - (Size=116.4 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=116.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=116.4 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=116.4 GB) - (Type=OF Extended)
 
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 489A5B6E)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)
 
========================================================
Disk: 3 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 770BE943)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=465.8 GB) - (Type=OF Extended)
 
========================================================
Disk: 4 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 82E76CCC)
Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
 
========================================================
Disk: 5 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 307523DC)
Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
 
==================== End of log ============================

:welcome:

 

I am attaching a FIXLIST file, you need to download it to your desktop where you now have FRST or the fix wont work, use your mouse to drag FIXLIST right next to FRST, either above or below it but not right on top of it, after its downloaded open up FRST and click on FIX (Not Scan) it wont take long, after your computer reboots you will find a FIXLOG file on your desktop, post it please and let me know if there has been any improvement with your system.

Attachments:

Hi Ken, thanks for the reply, the fixlist was applied and the fixlog txt is hereby attached:

Fix result of Farbar Recovery Scan Tool (x86) Version: 25-05-2015
Ran by [removed] at 2015-05-26 18:52:50 Run:1
Running from C:\Users\[removed]\Desktop
[removed]

Lets run some programs to see if there is malware underfoot or if this is a windows issue

 

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner To your Desktop
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  to your desktop. <———
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: MBAM2010601022_zpsyvzbaddn.jpg]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished and the log pops up…select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • Hi Ken, thanks for the reply.  Below are the requested logs:

           

          AdwCleaner Log:

           

          # AdwCleaner v4.205 - Logfile created 27/05/2015 at 17:06:51
          # Updated 21/05/2015 by Xplode
          # Database : 2015-05-25.3 [Server]
          # Operating system : Windows 7 Ultimate Service Pack 1 (x86)
          # Username : Andrea - ANDREA-PC
          # Running from : C:\Users\Andrea\Desktop\AdwCleaner.exe
          # Option : Cleaning

          ***** [ Services ] *****

          ***** [ Files / Folders ] *****

          ***** [ Scheduled tasks ] *****

          ***** [ Shortcuts ] *****

          ***** [ Registry ] *****

          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
          Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

          ***** [ Web browsers ] *****

          -\\ Internet Explorer v11.0.9600.17801

          *************************

          AdwCleaner[R0].txt - [937 bytes] - [27/05/2015 17:04:08]
          AdwCleaner[S0].txt - [867 bytes] - [27/05/2015 17:06:51]

          ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [925  bytes] ##########

           

          JRT Log:

           

          Junkware Removal Tool (JRT) by Thisisu
          Version: 6.8.1 (05.27.2015:1)
          OS: Windows 7 Ultimate x86
          Ran by [removed] on 27/05/2015 at 17:15:36.08
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

           

          ~~~ Services

           

          ~~~ Tasks

           

          ~~~ Registry Values

           

          ~~~ Registry Keys

           

          ~~~ Files

          Successfully deleted: [File] C:\Windows\prefetch\GOOGLETOOLBARMANAGER_BA9226F4-62E9BE03.pf
          Successfully deleted: [File] C:\Windows\prefetch\GOOGLETOOLBARNOTIFIER.EXE-3753CFA1.pf

           

          ~~~ Folders

           

           

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on 27/05/2015 at 17:18:54.61
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

           

          Malwarebytes Log:

           

          Malwarebytes Anti-Malware
          www.malwarebytes.org

          Scan Date: 27/05/2015
          Scan Time: 17:23:49
          Logfile: Malwarebytes.txt
          Administrator: Yes

          Version: 2.01.6.1022
          Malware Database: v2015.05.27.03
          Rootkit Database: v2015.05.24.01
          License: Premium
          Malware Protection: Enabled
          Malicious Website Protection: Enabled
          Self-protection: Enabled

          OS: Windows 7 Service Pack 1
          CPU: x86
          File System: NTFS
          User: Andrea

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 305121
          Time Elapsed: 7 min, 34 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Enabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 0
          (No malicious items detected)

          Registry Values: 0
          (No malicious items detected)

          Registry Data: 0
          (No malicious items detected)

          Folders: 0
          (No malicious items detected)

          Files: 0
          (No malicious items detected)

          Physical Sectors: 0
          (No malicious items detected)

          (end)

           

          The Malwarebytes I used was my own as I have the Premium version on my computer.

           

          Thanks again for the help, much appreciated.

          hedley

          Malwarebytes is a great program, keep it updated and run regular scans. Don't lose your ID and Key because if you ever sell or get rid of this computer you can uninstall it and download and install it on a new one and use your keys and you will be back up and running again.

           

          Anything any better ?

          Hi Ken, thanks for your reply.  Yes, malwarebytes is a great programme, I wouldn't be without it.  As for any changes in my pc since before, I have noticed a couple of things in msconfig are now running - Windows update & Nero Update for example.  There could be some more, as I don't know just what they all are for, but there are still an awful lot of MS services stopped, aside a few others.

           

          This is a new computer just at the start of May, came with a 'free' drive.  What I didn't know until I installed my copy of Windows 7 on my own drive was that there must have been a copy of Windows 8 on the 'free' drive and it was removed when I said I didn't what an OS with the computer.  I had to do a repair on the computer after the install and it brought up a recovered windows 7 and windows 8 install.  Possibly now windows 8 is coming back to bite me in the proverbial!!  That drive has now been completely removed from the computer, but maybe best to cut my losses and reinstall my windows 7 again.

           

          Thanks again for the help, much appreciated.

          hedley

          Maybe its best to do a complete format of the hard drive and clean install of windows, it think you would be smart to do that

           

          Take care my friend

           

          Ken :)

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI