Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93098 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Trojan Horse Collected_c.BEIS (Have logs) [Solved]

Maleware Trojan Infection Virus Dangerious Lethal AVG

  • This topic is locked This topic is locked
15 replies to this topic

#1 jeff matthews

jeff matthews

    Advanced Member

  • Authentic Member
  • PipPipPipPip
  • 781 posts

Posted 21 June 2015 - 08:41 PM

Hi i have a real dangerious and lethal infection on the computer. I have have no idea how i acquired such a thread. All i know is that its being located in. c:Program Files(x86)Dell Data Safe Local Backup/Components/DSUpdate/Updates/DataSafe_9_4_57_9_4_60_x64_Update.exe

 

After doing some research, i found out this Trojan virus is quite a pretty nasty infection that compromises the computer, steals information and opens up back doors for hackers. The file is collectively known as "Collected_c.BEIS" The machine has gone through various stages of rebooting and at some points, it fails to reboot. It also has lots of lock-ups, freezes and down times that redicilously slow at times, among other things like adds and spyware appearing during simple web browsing. I have also restored my laptop to "factory default" and the virus resufraced again. So knowing this, i am almost inclined to believe that the infection is something that i am installing repeadely back onto the laptop with out knowledge of where the malicious files are coming from.

 

So with that being said, i would like to not only remove this infection entirely but also pinpoint the exact location of where its coming from on my computer so i can prevent my self from installing it again. Thanks, i'll be awaiting reply.

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17840
Run by Kendra at 18:58:59 on 2015-06-22
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.6038.3498 [GMT -4:00]
.
AV: AVG Internet Security 2015 *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2015 *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security 2015 *Disabled* {757AB44A-78C2-7D1A-E37F-CA42A037B368}
.
============== Running Processes ===============
.
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Intel\TurboBoost\TurboBoost.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Users\Kendra\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Users\Kendra\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\GWX\GWX.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Akamai NetSession Interface] "C:\Users\Kendra\AppData\Local\Akamai\netsession_win.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
StartupFolder: C:\Users\Kendra\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\INTEL(~1.LNK - C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{3259E237-D858-48EF-9F67-B8A5B9192137} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{3259E237-D858-48EF-9F67-B8A5B9192137}\2454C4C4535353 : DHCPNameServer = 192.168.2.1
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
AppInit_DLLs= C:\Windows\SysWOW64\nvinit.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
x64-Run: [NVHotkey] rundll32.exe C:\Windows\System32\nvHotkey.dll,Start
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
x64-Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
x64-Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
x64-Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
x64-Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
x64-Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - <orphaned>
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - <orphaned>
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2015-5-12 253408]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2015-5-7 378336]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2015-5-12 224224]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2015-3-20 40928]
R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2011-9-10 25960]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-9-10 55856]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2011-9-10 21616]
R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2015-3-11 162784]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2015-3-20 67552]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2015-5-19 287200]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2015-4-15 256992]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2015-5-12 281568]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-9-10 98208]
R2 Apple Mobile Device Service;Apple Mobile Device Service;C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2015-1-19 77128]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-6-5 312816]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 RosettaStoneDaemon;RosettaStoneDaemon;C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2012-6-19 1646608]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-9-10 1692480]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-4-21 378472]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2010-11-29 16120]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-9-10 2656280]
R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2011-9-10 27760]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2011-9-10 176096]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-9-10 317440]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\System32\drivers\iwdbus.sys [2011-5-17 25496]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2015-5-26 25816]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2011-9-10 82432]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2011-9-10 181760]
R3 qicflt;upper Device Filter Driver;C:\Windows\System32\drivers\qicflt.sys [2011-9-10 29288]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-9-10 412264]
R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504]
R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2014-8-15 54784]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2015-4-30 23200]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2011-5-17 42392]
S2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [2015-6-5 1526936]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-6-5 3461072]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2015-5-26 1080120]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-6-9 114688]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-9-10 158976]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\System32\drivers\intelaud.sys [2011-5-17 34200]
S3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2015-5-26 63704]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\Windows\System32\drivers\nvstusb.sys [2011-9-10 121960]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2015-5-27 1255736]
.
=============== Created Last 30 ================
.
2015-06-22 20:04:51    --------    d-----w-    C:\Fraps
2015-06-22 19:51:35    --------    d-----w-    C:\Program Files (x86)\MediaFire Desktop
2015-06-22 19:51:24    20696    ----a-w-    C:\Windows\System32\drivers\mfmonitor_x64.sys
2015-06-22 19:38:04    --------    d-----w-    C:\Windows\System32\MRT
2015-06-17 16:07:27    --------    d-----w-    C:\Program Files (x86)\SquareEnix
2015-06-14 13:31:48    --------    d-----w-    C:\Program Files\Common Files\AV
2015-06-14 13:30:33    --------    d-----w-    C:\Users\Kendra\AppData\Local\Avg
2015-06-14 04:57:04    --------    d-----w-    C:\Program Files (x86)\Common Files\Macrovision Shared
2015-06-14 04:57:02    --------    d-----w-    C:\Users\Kendra\AppData\Roaming\com.rosettastone.languagetraining
2015-06-14 04:56:44    --------    d-----w-    C:\ProgramData\Rosetta Stone Backups
2015-06-14 04:56:44    --------    d-----w-    C:\ProgramData\Rosetta Stone
2015-06-14 04:56:44    --------    d-----w-    C:\Program Files (x86)\Rosetta Stone
2015-06-14 04:56:12    --------    d-----w-    C:\ProgramData\RosettaStoneLtdServices
2015-06-14 04:56:12    --------    d-----w-    C:\Program Files (x86)\RosettaStoneLtdServices
2015-06-14 04:12:23    --------    d-----w-    C:\Users\Kendra\AppData\Local\Akamai
2015-06-06 15:52:53    --------    d-----w-    C:\Users\Kendra\AppData\Local\GWX
2015-06-05 16:01:27    12214312    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{22BD805A-E304-4E46-ABBF-10AE8667A81F}\mpengine.dll
2015-05-31 22:23:57    --------    d-----w-    C:\Program Files (x86)\FreeCodecPack
2015-05-31 22:23:54    --------    d-----w-    C:\Program Files (x86)\DVDVideoSoft
2015-05-31 22:23:54    --------    d-----w-    C:\Program Files (x86)\Common Files\DVDVideoSoft
2015-05-31 22:23:27    --------    d-----w-    C:\Users\Kendra\AppData\Roaming\DVDVideoSoft
2015-05-30 16:59:44    --------    d-----w-    C:\Users\Kendra\AppData\Local\Apple Computer
2015-05-30 16:59:40    33240    ----a-w-    C:\Windows\System32\drivers\GEARAspiWDM.sys
2015-05-30 16:58:33    --------    d-----w-    C:\Program Files\iPod
2015-05-30 16:58:33    --------    d-----w-    C:\Program Files (x86)\iTunes
2015-05-30 16:58:31    --------    d-----w-    C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-05-30 16:58:31    --------    d-----w-    C:\Program Files\iTunes
2015-05-30 16:58:00    --------    d-----w-    C:\Users\Kendra\AppData\Local\Apple
2015-05-30 16:57:20    --------    d-----w-    C:\Program Files\Bonjour
2015-05-30 16:57:20    --------    d-----w-    C:\Program Files (x86)\Bonjour
2015-05-28 18:58:42    --------    d-----w-    C:\Users\Kendra\AppData\Roaming\PCDr
2015-05-28 18:58:16    --------    d-----w-    C:\ProgramData\PCDr
2015-05-28 07:01:33    --------    d-----w-    C:\Program Files (x86)\MSXML 4.0
2015-05-28 01:20:22    --------    d-s---w-    C:\Windows\SysWow64\GWX
2015-05-28 01:20:22    --------    d-s---w-    C:\Windows\System32\GWX
2015-05-28 01:20:22    --------    d-----w-    C:\Windows\Migration
2015-05-28 01:16:00    2777088    ----a-w-    C:\Windows\System32\msmpeg2vdec.dll
2015-05-28 01:16:00    2285056    ----a-w-    C:\Windows\SysWow64\msmpeg2vdec.dll
2015-05-27 23:58:31    --------    d-----w-    C:\Users\Kendra\AppData\Local\gtk-2.0
2015-05-27 23:58:24    --------    d-----w-    C:\Users\Kendra\.thumbnails
2015-05-27 23:57:12    --------    d-----w-    C:\Users\Kendra\AppData\Local\fontconfig
2015-05-27 23:57:11    --------    d-----w-    C:\Users\Kendra\AppData\Local\gegl-0.2
2015-05-27 23:57:11    --------    d-----w-    C:\Users\Kendra\.gimp-2.8
2015-05-27 23:52:05    --------    d-----w-    C:\Program Files\GIMP 2
2015-05-27 16:15:11    67072    ----a-w-    C:\Windows\splwow64.exe
2015-05-27 16:15:11    559104    ----a-w-    C:\Windows\System32\spoolsv.exe
2015-05-27 16:12:19    1647104    ----a-w-    C:\Windows\System32\DWrite.dll
2015-05-27 16:12:19    1250816    ----a-w-    C:\Windows\SysWow64\DWrite.dll
2015-05-27 16:12:19    1179136    ----a-w-    C:\Windows\System32\FntCache.dll
2015-05-27 16:12:18    1424896    ----a-w-    C:\Windows\System32\WindowsCodecs.dll
2015-05-27 16:12:18    1230848    ----a-w-    C:\Windows\SysWow64\WindowsCodecs.dll
2015-05-27 16:12:01    465920    ----a-w-    C:\Windows\System32\WMPhoto.dll
2015-05-27 16:12:01    417792    ----a-w-    C:\Windows\SysWow64\WMPhoto.dll
2015-05-27 15:57:30    --------    d-s---w-    C:\Windows\System32\CompatTel
2015-05-27 15:57:30    --------    d-----w-    C:\Windows\System32\appraiser
2015-05-27 15:57:27    --------    d-----w-    C:\Windows\SysWow64\Wat
2015-05-27 15:57:27    --------    d-----w-    C:\Windows\System32\Wat
2015-05-27 05:30:20    9728    ---ha-w-    C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-05-27 04:24:07    2560    ----a-w-    C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2015-05-27 03:23:52    87040    ----a-w-    C:\Windows\System32\drivers\WUDFPf.sys
2015-05-27 03:23:52    84992    ----a-w-    C:\Windows\System32\WUDFSvc.dll
2015-05-27 03:23:52    744448    ----a-w-    C:\Windows\System32\WUDFx.dll
2015-05-27 03:23:52    45056    ----a-w-    C:\Windows\System32\WUDFCoinstaller.dll
2015-05-27 03:23:52    229888    ----a-w-    C:\Windows\System32\WUDFHost.exe
2015-05-27 03:23:52    198656    ----a-w-    C:\Windows\System32\drivers\WUDFRd.sys
2015-05-27 03:23:52    194048    ----a-w-    C:\Windows\System32\WUDFPlatform.dll
2015-05-27 03:17:46    124112    ----a-w-    C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2015-05-27 03:17:46    102608    ----a-w-    C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-05-27 03:07:56    23408    ----a-w-    C:\Windows\System32\drivers\fs_rec.sys
2015-05-27 03:07:55    5120    ----a-w-    C:\Windows\SysWow64\wmi.dll
2015-05-27 03:07:55    5120    ----a-w-    C:\Windows\System32\wmi.dll
2015-05-27 02:58:56    99480    ----a-w-    C:\Windows\SysWow64\infocardapi.dll
2015-05-27 02:58:56    171160    ----a-w-    C:\Windows\System32\infocardapi.dll
2015-05-27 02:58:55    619672    ----a-w-    C:\Windows\SysWow64\icardagt.exe
2015-05-27 02:58:55    1389208    ----a-w-    C:\Windows\System32\icardagt.exe
2015-05-27 02:58:53    8856    ----a-w-    C:\Windows\SysWow64\icardres.dll
2015-05-27 02:58:53    8856    ----a-w-    C:\Windows\System32\icardres.dll
2015-05-27 02:58:35    35480    ----a-w-    C:\Windows\SysWow64\TsWpfWrp.exe
2015-05-27 02:58:35    35480    ----a-w-    C:\Windows\System32\TsWpfWrp.exe
2015-05-26 21:41:07    --------    d-----w-    C:\Program Files (x86)\VideoLAN
2015-05-26 21:39:20    63704    ----a-w-    C:\Windows\System32\drivers\mwac.sys
2015-05-26 21:39:20    25816    ----a-w-    C:\Windows\System32\drivers\mbam.sys
2015-05-26 21:39:20    107736    ----a-w-    C:\Windows\System32\drivers\mbamchameleon.sys
2015-05-26 21:39:20    --------    d-----w-    C:\ProgramData\Malwarebytes
2015-05-26 21:39:20    --------    d-----w-    C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-26 21:39:07    --------    d-----w-    C:\Users\Kendra\AppData\Local\Programs
2015-05-26 21:17:51    950272    ----a-w-    C:\Windows\System32\perftrack.dll
2015-05-26 21:17:51    91136    ----a-w-    C:\Windows\System32\wdi.dll
2015-05-26 21:17:51    76800    ----a-w-    C:\Windows\SysWow64\wdi.dll
2015-05-26 21:17:51    29696    ----a-w-    C:\Windows\System32\powertracker.dll
2015-05-26 21:10:15    460800    ----a-w-    C:\Windows\System32\certcli.dll
2015-05-26 21:10:15    342016    ----a-w-    C:\Windows\SysWow64\certcli.dll
2015-05-26 21:10:05    52736    ----a-w-    C:\Windows\System32\TSWbPrxy.exe
2015-05-26 21:10:05    328704    ----a-w-    C:\Windows\System32\services.exe
2015-05-26 21:08:37    86528    ----a-w-    C:\Windows\SysWow64\SearchFilterHost.exe
2015-05-26 21:07:34    210432    ----a-w-    C:\Windows\System32\profsvc.dll
2015-05-26 21:06:49    52224    ----a-w-    C:\Windows\SysWow64\nlaapi.dll
2015-05-26 21:05:59    1888768    ----a-w-    C:\Windows\System32\WMVDECOD.DLL
2015-05-26 21:04:50    245760    ----a-w-    C:\Windows\System32\OxpsConverter.exe
2015-05-26 21:03:56    861696    ----a-w-    C:\Windows\System32\oleaut32.dll
2015-05-26 21:02:58    77824    ----a-w-    C:\Windows\System32\packager.dll
2015-05-26 21:01:52    461312    ----a-w-    C:\Windows\System32\scavengeui.dll
2015-05-26 21:01:51    1216000    ----a-w-    C:\Windows\System32\rpcrt4.dll
2015-05-26 21:01:50    664064    ----a-w-    C:\Windows\SysWow64\rpcrt4.dll
2015-05-26 20:41:36    --------    d-----w-    C:\Windows\SMINST
2015-05-26 20:30:24    1031680    ----a-w-    C:\Windows\System32\rdpcore.dll
2015-05-26 20:30:23    826880    ----a-w-    C:\Windows\SysWow64\rdpcore.dll
2015-05-26 20:30:23    23552    ----a-w-    C:\Windows\System32\drivers\tdtcp.sys
2015-05-26 20:30:22    --------    d-----w-    C:\Users\Kendra\AppData\Roaming\AVG2015
2015-05-26 20:29:40    --------    d-----w-    C:\Users\Kendra\AppData\Roaming\TuneUp Software
2015-05-26 20:29:00    --------    d--h--w-    C:\$AVG
2015-05-26 20:28:59    --------    d-----w-    C:\ProgramData\AVG2015
2015-05-26 20:28:37    --------    d-----w-    C:\Program Files (x86)\AVG
2015-05-26 20:26:11    --------    d--h--w-    C:\ProgramData\Common Files
2015-05-26 20:26:11    --------    d-----w-    C:\Users\Kendra\AppData\Local\MFAData
2015-05-26 20:26:11    --------    d-----w-    C:\Users\Kendra\AppData\Local\Avg2015
2015-05-26 20:26:11    --------    d-----w-    C:\ProgramData\MFAData
2015-05-26 20:25:33    12214312    ----a-w-    C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2015-05-26 20:22:16    --------    d-----w-    C:\Users\Kendra\AppData\Local\Google
2015-05-26 20:22:00    --------    d-----w-    C:\Users\Kendra\AppData\Local\Apps
2015-05-26 20:21:59    --------    d-----w-    C:\Users\Kendra\AppData\Local\Deployment
2015-05-26 20:08:20    --------    d-sh--w-    C:\$RECYCLE.BIN
2015-05-26 20:08:18    --------    d-----w-    C:\Users\Kendra\AppData\Local\VirtualStore
2015-05-26 20:08:02    --------    d-----w-    C:\Users\Kendra\AppData\Local\Dell
2015-05-26 20:07:18    --------    d-----w-    C:\Users\Kendra\AppData\Roaming\Fingertapps
2015-05-26 20:07:11    --------    d-----w-    C:\Users\Kendra\AppData\Roaming\Dell Touch Zone
2015-05-26 20:07:04    --------    d-----w-    C:\Users\Kendra\AppData\Roaming\Dell
2015-05-26 20:06:03    --------    d-----w-    C:\Users\Kendra\AppData\Local\Dell Edoc Viewer
.
==================== Find3M  ====================
.
2015-05-27 05:30:20    9728    ---ha-w-    C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2015-05-25 18:24:00    5569984    ----a-w-    C:\Windows\System32\ntoskrnl.exe
2015-05-25 18:23:59    95680    ----a-w-    C:\Windows\System32\drivers\ksecdd.sys
2015-05-25 18:23:59    155584    ----a-w-    C:\Windows\System32\drivers\ksecpkg.sys
2015-05-25 18:21:21    1728960    ----a-w-    C:\Windows\System32\ntdll.dll
2015-05-25 18:18:56    43520    ----a-w-    C:\Windows\System32\csrsrv.dll
2015-05-25 18:18:56    22016    ----a-w-    C:\Windows\System32\credssp.dll
2015-05-25 18:18:54    879104    ----a-w-    C:\Windows\System32\advapi32.dll
2015-05-25 18:18:45    47104    ----a-w-    C:\Windows\System32\typeperf.exe
2015-05-25 18:18:45    404992    ----a-w-    C:\Windows\System32\tracerpt.exe
2015-05-25 18:18:39    112640    ----a-w-    C:\Windows\System32\smss.exe
2015-05-25 18:18:32    296960    ----a-w-    C:\Windows\System32\rstrui.exe
2015-05-25 18:18:30    43008    ----a-w-    C:\Windows\System32\relog.exe
2015-05-25 18:18:19    31232    ----a-w-    C:\Windows\System32\lsass.exe
2015-05-25 18:18:19    104448    ----a-w-    C:\Windows\System32\logman.exe
2015-05-25 18:18:11    19456    ----a-w-    C:\Windows\System32\diskperf.exe
2015-05-25 18:18:08    338432    ----a-w-    C:\Windows\System32\conhost.exe
2015-05-25 18:18:04    64000    ----a-w-    C:\Windows\System32\auditpol.exe
2015-05-25 18:14:26    60416    ----a-w-    C:\Windows\System32\msobjs.dll
2015-05-25 18:14:04    146432    ----a-w-    C:\Windows\System32\msaudite.dll
2015-05-25 18:07:34    3989440    ----a-w-    C:\Windows\SysWow64\ntkrnlpa.exe
2015-05-25 18:07:34    3934144    ----a-w-    C:\Windows\SysWow64\ntoskrnl.exe
2015-05-25 18:04:08    1310744    ----a-w-    C:\Windows\SysWow64\ntdll.dll
2015-05-25 18:00:44    40448    ----a-w-    C:\Windows\SysWow64\typeperf.exe
2015-05-25 18:00:40    364544    ----a-w-    C:\Windows\SysWow64\tracerpt.exe
2015-05-25 18:00:28    25600    ----a-w-    C:\Windows\SysWow64\setup16.exe
2015-05-25 18:00:25    37888    ----a-w-    C:\Windows\SysWow64\relog.exe
2015-05-25 18:00:17    82944    ----a-w-    C:\Windows\SysWow64\logman.exe
2015-05-25 18:00:09    17408    ----a-w-    C:\Windows\SysWow64\diskperf.exe
2015-05-25 18:00:04    50176    ----a-w-    C:\Windows\SysWow64\auditpol.exe
2015-05-25 17:59:52    96768    ----a-w-    C:\Windows\SysWow64\sspicli.dll
2015-05-25 17:59:52    5120    ----a-w-    C:\Windows\SysWow64\wow32.dll
2015-05-25 17:59:51    274944    ----a-w-    C:\Windows\SysWow64\KernelBase.dll
2015-05-25 17:57:31    60416    ----a-w-    C:\Windows\SysWow64\msobjs.dll
2015-05-25 17:57:15    146432    ----a-w-    C:\Windows\SysWow64\msaudite.dll
2015-05-25 17:08:39    3206144    ----a-w-    C:\Windows\System32\win32k.sys
2015-05-25 17:00:56    36864    ----a-w-    C:\Windows\System32\UtcResources.dll
2015-05-25 16:50:38    7680    ----a-w-    C:\Windows\SysWow64\instnm.exe
2015-05-25 16:50:36    2048    ----a-w-    C:\Windows\SysWow64\user.exe
2015-05-25 16:48:25    6144    ---ha-w-    C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2015-05-25 16:48:25    4608    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-25 16:48:25    3584    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-25 16:48:25    3072    ---ha-w-    C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2015-05-23 03:28:17    2724864    ----a-w-    C:\Windows\SysWow64\mshtml.tlb
2015-05-23 03:15:54    503808    ----a-w-    C:\Windows\SysWow64\vbscript.dll
2015-05-23 03:15:40    62464    ----a-w-    C:\Windows\SysWow64\iesetup.dll
2015-05-23 03:15:02    47616    ----a-w-    C:\Windows\SysWow64\ieetwproxystub.dll
2015-05-23 03:14:51    341504    ----a-w-    C:\Windows\SysWow64\html.iec
2015-05-23 03:13:48    64000    ----a-w-    C:\Windows\SysWow64\MshtmlDac.dll
2015-05-23 03:05:21    115712    ----a-w-    C:\Windows\SysWow64\ieUnatt.exe
2015-05-23 03:04:50    620032    ----a-w-    C:\Windows\SysWow64\jscript9diag.dll
2015-05-23 02:52:43    60416    ----a-w-    C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2015-05-23 02:47:31    4305920    ----a-w-    C:\Windows\SysWow64\jscript9.dll
2015-05-23 02:37:45    2052608    ----a-w-    C:\Windows\SysWow64\inetcpl.cpl
2015-05-23 02:37:25    1155072    ----a-w-    C:\Windows\SysWow64\mshtmlmedia.dll
2015-05-23 02:20:35    1950720    ----a-w-    C:\Windows\SysWow64\wininet.dll
2015-05-22 19:16:55    2724864    ----a-w-    C:\Windows\System32\mshtml.tlb
2015-05-22 19:16:44    4096    ----a-w-    C:\Windows\System32\ieetwcollectorres.dll
2015-05-22 19:01:42    66560    ----a-w-    C:\Windows\System32\iesetup.dll
2015-05-22 19:00:54    48640    ----a-w-    C:\Windows\System32\ieetwproxystub.dll
2015-05-22 19:00:47    417792    ----a-w-    C:\Windows\System32\html.iec
2015-05-22 19:00:25    584192    ----a-w-    C:\Windows\System32\vbscript.dll
2015-05-22 18:59:27    88064    ----a-w-    C:\Windows\System32\MshtmlDac.dll
2015-05-22 18:52:21    6026240    ----a-w-    C:\Windows\System32\jscript9.dll
2015-05-22 18:47:49    144384    ----a-w-    C:\Windows\System32\ieUnatt.exe
2015-05-22 18:47:34    114688    ----a-w-    C:\Windows\System32\ieetwcollector.exe
2015-05-22 18:47:03    814080    ----a-w-    C:\Windows\System32\jscript9diag.dll
2015-05-22 18:40:17    968704    ----a-w-    C:\Windows\System32\MsSpellCheckingFacility.exe
2015-05-22 18:29:31    77824    ----a-w-    C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-05-22 18:18:41    700416    ----a-w-    C:\Windows\System32\generaltel.dll
2015-05-22 18:18:29    757248    ----a-w-    C:\Windows\System32\invagent.dll
2015-05-22 18:18:24    423424    ----a-w-    C:\Windows\System32\devinv.dll
2015-05-22 18:18:22    1021440    ----a-w-    C:\Windows\System32\appraiser.dll
2015-05-22 18:18:21    45568    ----a-w-    C:\Windows\System32\acmigration.dll
2015-05-22 18:18:21    227328    ----a-w-    C:\Windows\System32\aepdu.dll
2015-05-22 18:13:03    1119232    ----a-w-    C:\Windows\System32\aeinv.dll
2015-05-22 18:05:28    1359360    ----a-w-    C:\Windows\System32\mshtmlmedia.dll
2015-05-22 18:05:06    2125824    ----a-w-    C:\Windows\System32\inetcpl.cpl
2015-05-22 17:50:20    2426880    ----a-w-    C:\Windows\System32\wininet.dll
2015-05-21 13:19:52    193536    ----a-w-    C:\Windows\System32\aepic.dll
2015-05-19 13:52:58    287200    ----a-w-    C:\Windows\System32\drivers\avgidsdrivera.sys
2015-05-12 18:39:14    281568    ----a-w-    C:\Windows\System32\drivers\avgtdia.sys
2015-05-12 18:36:54    253408    ----a-w-    C:\Windows\System32\drivers\avgidsha.sys
2015-05-12 18:36:52    224224    ----a-w-    C:\Windows\System32\drivers\avgmfx64.sys
2015-05-07 17:50:22    378336    ----a-w-    C:\Windows\System32\drivers\avgloga.sys
2015-04-30 04:01:06    23200    ----a-w-    C:\Windows\System32\drivers\wdcsam64.sys
2015-04-29 18:21:50    5120    ----a-w-    C:\Windows\System32\msdxm.ocx
2015-04-29 18:21:50    5120    ----a-w-    C:\Windows\System32\dxmasf.dll
2015-04-29 18:21:46    9728    ----a-w-    C:\Windows\System32\spwmp.dll
2015-04-29 18:19:43    12625920    ----a-w-    C:\Windows\System32\wmploc.DLL
2015-04-29 18:07:12    4096    ----a-w-    C:\Windows\SysWow64\msdxm.ocx
2015-04-29 18:07:12    4096    ----a-w-    C:\Windows\SysWow64\dxmasf.dll
2015-04-29 18:07:07    8192    ----a-w-    C:\Windows\SysWow64\spwmp.dll
2015-04-29 18:05:19    12625408    ----a-w-    C:\Windows\SysWow64\wmploc.DLL
2015-04-24 18:17:26    633856    ----a-w-    C:\Windows\System32\comctl32.dll
2015-04-24 17:56:58    530432    ----a-w-    C:\Windows\SysWow64\comctl32.dll
2015-04-15 17:06:02    256992    ----a-w-    C:\Windows\System32\drivers\avgldx64.sys
2015-04-14 20:51:26    67552    ----a-w-    C:\Windows\System32\drivers\avgfwd6a.sys
2015-04-11 03:19:59    69888    ----a-w-    C:\Windows\System32\drivers\stream.sys
2015-04-08 03:29:07    275456    ----a-w-    C:\Windows\System32\InkEd.dll
.
============= FINISH: 18:59:09.98 ===============
 

Attached Files


Edited by jeff matthews, 22 June 2015 - 05:09 PM.

    Advertisements

Register to Remove


#2 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 23 June 2015 - 03:54 PM

:welcome:

 

Jeff, DDS is a bit outdated, where using FRST now that will show us so much more

 

 

1QYkxTZ.jpg Please download aswMBR to your desktop.
 
  • Right click the aswMBR icon and select Run as Administrator
  • XP users just Double Click it to run
  • If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
  • Click the Scan button to start scan.
  • Select Quickscan on the dropdown list
  • If you are asked to update the Avast Virus database please allow it to do so.
  • The scan could take 20 minutes or more , please be patient and let it finish
  • It will say Scan Finished when its done.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
  •  
    I just want to see the report....Please Do Not Fix Anything
     
    ============================================================================
     
     

    Please download Farbar Recovery Scan Tool and save it to your DESKTOP
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
     
    How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
    A simple way to check your system: Start --> Computer (right click) --> Properties
     
    FRST_zps5d956a1a.jpg
     
     
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Please make sure All Users is checked
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.


     
     
    The forum is staffed by volunteers who donate their time and expertise.
    If you feel you have been helped, please consider a donation.
    donate.gif
     
    Find us on Facebook
    Please LIKE and SHARE
     
     
    Just a reminder that threads will be closed if no reply in 3 days.

    #3 jeff matthews

    jeff matthews

      Advanced Member

    • Authentic Member
    • PipPipPipPip
    • 781 posts

    Posted 24 June 2015 - 01:36 PM

    aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
    Run date: 2015-06-24 14:36:32

    -----------------------------
    14:36:32.510    OS Version: Windows x64 6.1.7601 Service Pack 1
    14:36:32.510    Number of processors: 8 586 0x2A07
    14:36:32.510    ComputerName: MAYURI  UserName: Kendra
    14:36:33.293    Initialize success
    14:36:33.299    VM: initialized successfully
    14:36:33.301    VM: Intel CPU supported
    14:36:34.535    VM: supported disk I/O iaStor.sys
    14:41:20.720    AVAST engine defs: 15062401
    14:41:54.083    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    14:41:54.089    Disk 0 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
    14:41:54.096    Disk 1  \Device\Harddisk1\DR1 -> \Device\Ide\IAAStorageDevice-2
    14:41:54.102    Disk 1 Vendor: WDC_WD50 01.0 Size: 476940MB BusType: 3
    14:41:54.232    VM: Disk 0 MBR read successfully
    14:41:54.240    Disk 0 MBR scan
    14:41:54.252    Disk 0 Windows 7 default MBR code
    14:41:54.260    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0      101 MB offset 63
    14:41:54.273    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS        20000 MB offset 212992
    14:41:54.277    Disk 0 Boot: NTFS     code=1
    14:41:54.291    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       456835 MB offset 41172992
    14:41:54.308    Disk 0 scanning C:\Windows\system32\drivers
    14:42:02.811    Service scanning
    14:42:20.857    Modules scanning
    14:42:20.871    Disk 0 trace - called modules:
    14:42:20.895    ntoskrnl.exe CLASSPNP.SYS disk.sys stdcfltn.sys ACPI.sys iaStor.sys hal.dll
    14:42:20.907    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006255790]
    14:42:20.918    3 CLASSPNP.SYS[fffff880013c043f] -> nt!IofCallDriver -> [0xfffffa800616bb30]
    14:42:20.927    5 stdcfltn.sys[fffff880016d6c52] -> nt!IofCallDriver -> [0xfffffa800600d950]
    14:42:20.931    7 ACPI.sys[fffff88000f547a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8006011050]
    14:42:22.077    AVAST engine scan C:\Windows
    14:42:24.245    AVAST engine scan C:\Windows\system32
    14:45:28.875    AVAST engine scan C:\Windows\system32\drivers
    14:45:37.108    AVAST engine scan C:\Users\Kendra
    14:48:02.999    AVAST engine scan C:\ProgramData
    15:07:52.035    Disk 0 statistics 5033983/0/22 @ 2.54 MB/s
    15:07:52.042    Scan finished successfully
    15:09:54.182    Disk 0 MBR has been saved successfully to "C:\Users\Kendra\Desktop\MBR.dat"
    15:09:54.186    The log file has been saved successfully to "C:\Users\Kendra\Desktop\aswMBR.txt"

     

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:21-06-2015 01

     

    Ran by Kendra (administrator) on MAYURI on 24-06-2015 14:12:46
    Running from C:\Users\Kendra\Desktop
    Loaded Profiles: UpdatusUser & Kendra (Available Profiles: UpdatusUser & Kendra & Rolland)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
    (Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    (NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
    (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (Rosetta Stone Ltd.) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
    (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
    () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
    (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Intel Corporation) C:\WINDOWS\System32\igfxtray.exe
    (Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
    (Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
    () C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
    (Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (Akamai Technologies, Inc.) C:\Users\Kendra\AppData\Local\Akamai\netsession_win.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
    () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
    (Akamai Technologies, Inc.) C:\Users\Kendra\AppData\Local\Akamai\netsession_win.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Microsoft Corporation) C:\WINDOWS\System32\GWX\GWX.exe
    (Intel® Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
    (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
    (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil10u_ActiveX.exe
    (Microsoft Corporation) C:\WINDOWS\System32\MsSpellCheckingFacility.exe
    (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
    (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
    (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2370856 2010-09-23] (Synaptics Incorporated)
    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6611048 2011-02-18] (Realtek Semiconductor)
    HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2188904 2011-01-18] (Realtek Semiconductor)
    HKLM\...\Run: [NVHotkey] => rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
    HKLM\...\Run: [FreeFallProtection] => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-17] ()
    HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel® Corporation)
    HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [4479648 2011-01-25] (Dell Inc.)
    HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-13] (Creative Technology Ltd)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
    HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
    HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3727824 2015-06-16] (AVG Technologies CZ, s.r.o.)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKU\S-1-5-21-1613421670-3433999689-4052708816-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Kendra\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
    HKU\S-1-5-21-1613421670-3433999689-4052708816-1001\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10u_ActiveX.exe [243360 2011-09-10] (Adobe Systems, Inc.)
    AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [226920 2011-04-22] (NVIDIA Corporation)
    AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [193128 2011-04-22] (NVIDIA Corporation)
    Startup: C:\Users\Kendra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel® Turbo Boost Technology Monitor 2.0.lnk [2015-05-26]
    ShortcutTarget: Intel® Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)
    Startup: C:\Users\Rolland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel® Turbo Boost Technology Monitor 2.0.lnk [2015-05-26]
    ShortcutTarget: Intel® Turbo Boost Technology Monitor 2.0.lnk -> C:\Program Files\Intel\TurboBoost\SignalIslandUi.exe (Intel® Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKU\S-1-5-21-1613421670-3433999689-4052708816-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/23
    HKU\S-1-5-21-1613421670-3433999689-4052708816-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/23
    SearchScopes: HKLM -> DefaultScope {2EE50857-0AF0-4F40-8DD1-4FAFBD199F46} URL = http://www.bing.com/...rc=IE-SearchBox
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> {2EE50857-0AF0-4F40-8DD1-4FAFBD199F46} URL = http://www.bing.com/...rc=IE-SearchBox
    SearchScopes: HKLM-x32 -> DefaultScope {2EE50857-0AF0-4F40-8DD1-4FAFBD199F46} URL = http://www.bing.com/...rc=IE-SearchBox
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {2EE50857-0AF0-4F40-8DD1-4FAFBD199F46} URL = http://www.bing.com/...rc=IE-SearchBox
    SearchScopes: HKU\S-1-5-21-1613421670-3433999689-4052708816-1001 -> DefaultScope {2EE50857-0AF0-4F40-8DD1-4FAFBD199F46} URL =
    SearchScopes: HKU\S-1-5-21-1613421670-3433999689-4052708816-1001 -> {2EE50857-0AF0-4F40-8DD1-4FAFBD199F46} URL =
    BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-09-10] (Sun Microsystems, Inc.)
    BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15] (Adobe Systems Incorporated)
    BHO-x32: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08] (Skype Technologies S.A.)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-09-10] (Sun Microsystems, Inc.)
    Handler-x32: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll [2011-05-05] (Cozi Group, Inc.)
    Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08] (Skype Technologies S.A.)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2010-05-13] (Skype Technologies)
    Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

    FireFox:
    ========
    FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2011-09-10] (Sun Microsystems, Inc.)
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
    FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2011-09-10] (Sun Microsystems, Inc.)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2011-04-21] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2011-04-21] (NVIDIA Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-26] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-26] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

    Chrome:
    =======
    CHR Profile: C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Slides) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-26]
    CHR Extension: (Google Docs) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-26]
    CHR Extension: (Google Drive) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-26]
    CHR Extension: (YouTube) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-26]
    CHR Extension: (Google Search) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-26]
    CHR Extension: (Google Sheets) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-26]
    CHR Extension: (AdBlock) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-05-26]
    CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-26]
    CHR Extension: (Google Wallet) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-26]
    CHR Extension: (Gmail) - C:\Users\Kendra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-26]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
    R2 avgfws; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [1526936 2015-06-16] (AVG Technologies CZ, s.r.o.)
    R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3461072 2015-06-16] (AVG Technologies CZ, s.r.o.)
    R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [312816 2015-06-16] (AVG Technologies CZ, s.r.o.)
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.)
    R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [67552 2015-04-14] (AVG Technologies CZ, s.r.o.)
    R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [287200 2015-05-19] (AVG Technologies CZ, s.r.o.)
    R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.)
    R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [256992 2015-04-15] (AVG Technologies CZ, s.r.o.)
    R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
    R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [224224 2015-05-12] (AVG Technologies CZ, s.r.o.)
    R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
    R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [281568 2015-05-12] (AVG Technologies CZ, s.r.o.)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
    S3 NvStUSB; C:\Windows\system32\drivers\nvstusb.sys [121960 2011-01-31] ()

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-06-24 14:12 - 2015-06-24 14:12 - 00017172 _____ C:\Users\Kendra\Desktop\FRST.txt
    2015-06-24 14:09 - 2015-06-24 14:09 - 02109952 _____ (Farbar) C:\Users\Kendra\Desktop\FRST64.exe
    2015-06-24 13:57 - 2015-06-24 14:12 - 00000000 ____D C:\FRST
    2015-06-23 16:41 - 2015-06-23 16:41 - 00026710 _____ C:\Users\Kendra\AppData\Local\recently-used.xbel
    2015-06-22 23:27 - 2015-06-22 23:27 - 00001442 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
    2015-06-22 17:38 - 2015-06-22 17:38 - 00010653 _____ C:\Users\Kendra\Downloads\download.htm
    2015-06-22 16:04 - 2015-06-22 16:11 - 00000000 ____D C:\Fraps
    2015-06-22 16:04 - 2015-06-22 16:04 - 00000564 _____ C:\Users\Public\Desktop\Fraps.lnk
    2015-06-22 16:04 - 2015-06-22 16:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
    2015-06-22 15:51 - 2015-04-23 09:10 - 00020696 _____ (Windows ® Win 7 DDK provider) C:\Windows\system32\Drivers\mfmonitor_x64.sys
    2015-06-22 15:38 - 2015-06-22 15:42 - 00000000 ____D C:\Windows\system32\MRT
    2015-06-22 15:37 - 2015-05-27 00:04 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-06-17 12:07 - 2015-06-17 12:07 - 00002408 _____ C:\Users\Public\Desktop\FINAL FANTASY XIV - A Realm Reborn.lnk
    2015-06-17 12:07 - 2015-06-17 12:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQUARE ENIX
    2015-06-17 12:07 - 2015-06-17 12:07 - 00000000 ____D C:\Program Files (x86)\SquareEnix
    2015-06-16 23:06 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
    2015-06-16 23:06 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
    2015-06-16 23:06 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
    2015-06-16 23:06 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
    2015-06-16 23:06 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
    2015-06-16 23:06 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
    2015-06-16 23:06 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
    2015-06-16 23:06 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
    2015-06-16 23:06 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
    2015-06-16 23:06 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
    2015-06-16 23:06 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
    2015-06-16 23:06 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
    2015-06-16 23:06 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
    2015-06-16 23:06 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
    2015-06-16 23:06 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
    2015-06-16 23:06 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
    2015-06-16 23:06 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
    2015-06-16 23:06 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
    2015-06-16 23:06 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
    2015-06-16 23:06 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
    2015-06-16 23:06 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
    2015-06-16 23:06 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
    2015-06-16 23:06 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
    2015-06-16 23:06 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
    2015-06-16 23:06 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
    2015-06-16 23:06 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
    2015-06-16 23:06 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
    2015-06-16 23:06 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
    2015-06-16 23:06 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
    2015-06-16 23:06 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
    2015-06-16 23:06 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
    2015-06-16 23:06 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
    2015-06-16 23:06 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
    2015-06-16 23:06 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
    2015-06-16 23:06 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
    2015-06-16 23:06 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
    2015-06-16 23:06 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
    2015-06-16 23:06 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
    2015-06-16 23:06 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
    2015-06-16 23:06 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
    2015-06-16 23:06 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
    2015-06-16 23:06 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
    2015-06-16 23:06 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
    2015-06-16 23:06 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
    2015-06-16 23:06 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
    2015-06-16 23:06 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
    2015-06-16 23:06 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
    2015-06-16 23:06 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
    2015-06-16 23:06 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
    2015-06-16 23:06 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
    2015-06-16 23:06 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
    2015-06-16 23:06 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
    2015-06-16 23:06 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
    2015-06-16 23:06 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
    2015-06-16 23:06 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
    2015-06-16 23:06 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
    2015-06-16 23:06 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
    2015-06-16 23:06 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
    2015-06-16 23:06 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
    2015-06-16 23:06 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
    2015-06-16 23:06 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
    2015-06-16 23:06 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
    2015-06-16 23:06 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
    2015-06-16 23:06 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
    2015-06-16 23:06 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
    2015-06-16 23:06 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
    2015-06-16 23:06 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
    2015-06-16 23:06 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
    2015-06-16 23:06 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
    2015-06-16 23:06 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
    2015-06-16 23:06 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
    2015-06-16 23:06 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
    2015-06-16 23:06 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
    2015-06-16 23:06 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
    2015-06-16 23:06 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
    2015-06-16 23:06 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
    2015-06-16 23:06 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
    2015-06-16 23:06 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
    2015-06-16 23:06 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
    2015-06-16 23:06 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
    2015-06-16 23:06 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
    2015-06-16 23:06 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
    2015-06-16 23:06 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
    2015-06-16 23:06 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
    2015-06-16 23:06 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
    2015-06-16 23:06 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
    2015-06-16 23:06 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
    2015-06-16 23:06 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
    2015-06-16 23:06 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
    2015-06-16 23:04 - 2015-06-16 23:04 - 00000000 ____D C:\Users\Kendra\Documents\My Games
    2015-06-14 09:31 - 2015-06-14 09:31 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
    2015-06-14 09:31 - 2015-06-14 09:31 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
    2015-06-14 09:31 - 2015-06-14 09:31 - 00000000 ____D C:\Program Files\Common Files\AV
    2015-06-14 09:30 - 2015-06-14 09:30 - 00000000 ____D C:\Users\Rolland\AppData\Local\Avg
    2015-06-14 09:30 - 2015-06-14 09:30 - 00000000 ____D C:\Users\Kendra\AppData\Local\Avg
    2015-06-14 00:57 - 2015-06-14 00:57 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\com.rosettastone.languagetraining
    2015-06-14 00:56 - 2015-06-14 00:56 - 00001151 _____ C:\Users\Public\Desktop\Rosetta Stone.lnk
    2015-06-14 00:56 - 2015-06-14 00:56 - 00000000 ____D C:\ProgramData\RosettaStoneLtdServices
    2015-06-14 00:56 - 2015-06-14 00:56 - 00000000 ____D C:\ProgramData\Rosetta Stone Backups
    2015-06-14 00:56 - 2015-06-14 00:56 - 00000000 ____D C:\ProgramData\Rosetta Stone
    2015-06-14 00:56 - 2015-06-14 00:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rosetta Stone
    2015-06-14 00:56 - 2015-06-14 00:56 - 00000000 ____D C:\Program Files (x86)\RosettaStoneLtdServices
    2015-06-14 00:56 - 2015-06-14 00:56 - 00000000 ____D C:\Program Files (x86)\Rosetta Stone
    2015-06-14 00:54 - 2015-06-14 01:09 - 00000000 ____D C:\ProgramData\FLEXnet
    2015-06-14 00:12 - 2015-06-14 00:12 - 00000000 ____D C:\Users\Kendra\AppData\Local\Akamai
    2015-06-09 14:24 - 2015-04-29 14:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
    2015-06-09 14:23 - 2015-06-01 15:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-06-09 14:23 - 2015-06-01 14:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-06-09 14:23 - 2015-05-27 10:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-06-09 14:23 - 2015-05-27 10:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-06-09 14:23 - 2015-05-25 14:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-06-09 14:23 - 2015-05-25 14:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-06-09 14:23 - 2015-05-25 14:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-06-09 14:23 - 2015-05-25 14:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2015-06-09 14:23 - 2015-05-25 14:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2015-06-09 14:23 - 2015-05-25 14:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
    2015-06-09 14:23 - 2015-05-25 14:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-06-09 14:23 - 2015-05-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-06-09 14:23 - 2015-05-25 14:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-06-09 14:23 - 2015-05-25 14:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
    2015-06-09 14:23 - 2015-05-25 14:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-06-09 14:23 - 2015-05-25 14:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 14:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-06-09 14:23 - 2015-05-25 14:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-06-09 14:23 - 2015-05-25 14:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-06-09 14:23 - 2015-05-25 14:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2015-06-09 14:23 - 2015-05-25 14:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
    2015-06-09 14:23 - 2015-05-25 14:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
    2015-06-09 14:23 - 2015-05-25 14:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-06-09 14:23 - 2015-05-25 14:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
    2015-06-09 14:23 - 2015-05-25 14:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
    2015-06-09 14:23 - 2015-05-25 14:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2015-06-09 14:23 - 2015-05-25 14:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
    2015-06-09 14:23 - 2015-05-25 13:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2015-06-09 14:23 - 2015-05-25 13:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2015-06-09 14:23 - 2015-05-25 13:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-06-09 14:23 - 2015-05-25 13:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2015-06-09 14:23 - 2015-05-25 13:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-06-09 14:23 - 2015-05-25 13:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 13:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-06-09 14:23 - 2015-05-25 13:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
    2015-06-09 14:23 - 2015-05-25 12:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2015-06-09 14:23 - 2015-05-25 12:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2015-06-09 14:23 - 2015-05-25 12:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 12:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 12:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-25 12:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2015-06-09 14:23 - 2015-05-22 23:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-06-09 14:23 - 2015-05-22 23:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-06-09 14:23 - 2015-05-22 23:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-06-09 14:23 - 2015-05-22 23:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-06-09 14:23 - 2015-05-22 23:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-06-09 14:23 - 2015-05-22 23:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-06-09 14:23 - 2015-05-22 23:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-06-09 14:23 - 2015-05-22 23:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-06-09 14:23 - 2015-05-22 23:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-06-09 14:23 - 2015-05-22 23:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-06-09 14:23 - 2015-05-22 23:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-06-09 14:23 - 2015-05-22 23:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-06-09 14:23 - 2015-05-22 23:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-06-09 14:23 - 2015-05-22 22:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-06-09 14:23 - 2015-05-22 22:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-06-09 14:23 - 2015-05-22 22:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-06-09 14:23 - 2015-05-22 22:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-06-09 14:23 - 2015-05-22 22:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-06-09 14:23 - 2015-05-22 22:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-06-09 14:23 - 2015-05-22 22:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-06-09 14:23 - 2015-05-22 22:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-06-09 14:23 - 2015-05-22 22:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-06-09 14:23 - 2015-05-22 22:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-06-09 14:23 - 2015-05-22 22:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-06-09 14:23 - 2015-05-22 22:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-06-09 14:23 - 2015-05-22 22:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-06-09 14:23 - 2015-05-22 15:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-06-09 14:23 - 2015-05-22 15:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-06-09 14:23 - 2015-05-22 15:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-06-09 14:23 - 2015-05-22 15:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-06-09 14:23 - 2015-05-22 15:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-06-09 14:23 - 2015-05-22 15:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-06-09 14:23 - 2015-05-22 15:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-06-09 14:23 - 2015-05-22 14:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-06-09 14:23 - 2015-05-22 14:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-06-09 14:23 - 2015-05-22 14:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-06-09 14:23 - 2015-05-22 14:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-06-09 14:23 - 2015-05-22 14:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-06-09 14:23 - 2015-05-22 14:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-06-09 14:23 - 2015-05-22 14:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-06-09 14:23 - 2015-05-22 14:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-06-09 14:23 - 2015-05-22 14:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-06-09 14:23 - 2015-05-22 14:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-06-09 14:23 - 2015-05-22 14:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-06-09 14:23 - 2015-05-22 14:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-06-09 14:23 - 2015-05-22 14:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-06-09 14:23 - 2015-05-22 14:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-06-09 14:23 - 2015-05-22 14:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-06-09 14:23 - 2015-05-22 14:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2015-06-09 14:23 - 2015-05-22 14:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2015-06-09 14:23 - 2015-05-22 14:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2015-06-09 14:23 - 2015-05-22 14:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2015-06-09 14:23 - 2015-05-22 14:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2015-06-09 14:23 - 2015-05-22 14:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2015-06-09 14:23 - 2015-05-22 14:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2015-06-09 14:23 - 2015-05-22 14:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-06-09 14:23 - 2015-05-22 14:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-06-09 14:23 - 2015-05-22 14:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-06-09 14:23 - 2015-05-22 14:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-06-09 14:23 - 2015-05-22 13:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-06-09 14:23 - 2015-05-22 13:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-06-09 14:23 - 2015-05-22 13:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-06-09 14:23 - 2015-05-22 13:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-06-09 14:23 - 2015-05-21 09:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
    2015-06-09 14:23 - 2015-04-29 14:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
    2015-06-09 14:23 - 2015-04-29 14:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
    2015-06-09 14:23 - 2015-04-29 14:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
    2015-06-09 14:23 - 2015-04-29 14:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
    2015-06-09 14:23 - 2015-04-29 14:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
    2015-06-09 14:23 - 2015-04-29 14:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
    2015-06-09 14:23 - 2015-04-29 14:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
    2015-06-09 14:23 - 2015-04-29 14:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
    2015-06-09 14:23 - 2015-04-29 14:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
    2015-06-09 14:23 - 2015-04-24 14:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
    2015-06-09 14:23 - 2015-04-24 13:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
    2015-06-09 14:23 - 2015-04-10 23:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
    2015-06-06 11:52 - 2015-06-06 11:52 - 00000000 ____D C:\Users\Kendra\AppData\Local\GWX
    2015-06-03 22:08 - 2015-06-04 18:17 - 00000000 ____D C:\Users\Kendra\Downloads\Mirai Nikki
    2015-06-02 22:46 - 2015-06-02 22:56 - 00000000 ____D C:\Users\Kendra\Downloads\[Vivid] Amagi Brilliant Park [TV 720p]
    2015-06-02 22:41 - 2015-06-02 23:17 - 00000000 ____D C:\Users\Kendra\Downloads\[Coalgirls]_Soul_Eater_(1280x720_Blu-ray_FLAC)
    2015-06-02 22:39 - 2015-06-04 05:21 - 4055068292 _____ C:\Users\Kendra\Downloads\Madoka_Magica Movie 3 1080p.mkv
    2015-05-31 18:24 - 2015-06-22 23:27 - 00001247 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
    2015-05-31 18:24 - 2015-06-22 23:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
    2015-05-31 18:24 - 2015-05-31 18:24 - 00001538 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
    2015-05-31 18:23 - 2015-06-22 23:27 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\DVDVideoSoft
    2015-05-31 18:23 - 2015-06-22 23:27 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
    2015-05-31 18:23 - 2015-05-31 18:23 - 00000000 ____D C:\Program Files (x86)\FreeCodecPack
    2015-05-30 12:59 - 2015-05-31 18:18 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Apple Computer
    2015-05-30 12:59 - 2015-05-30 12:59 - 00001755 _____ C:\Users\Public\Desktop\iTunes.lnk
    2015-05-30 12:59 - 2015-05-30 12:59 - 00000000 ____D C:\Users\Kendra\AppData\Local\Apple Computer
    2015-05-30 12:59 - 2015-05-30 12:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2015-05-30 12:59 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
    2015-05-30 12:58 - 2015-05-30 12:59 - 00000000 ____D C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
    2015-05-30 12:58 - 2015-05-30 12:59 - 00000000 ____D C:\Program Files\iTunes
    2015-05-30 12:58 - 2015-05-30 12:58 - 00000000 ____D C:\Windows\System32\Tasks\Apple
    2015-05-30 12:58 - 2015-05-30 12:58 - 00000000 ____D C:\Users\Kendra\AppData\Local\Apple
    2015-05-30 12:58 - 2015-05-30 12:58 - 00000000 ____D C:\ProgramData\Apple Computer
    2015-05-30 12:58 - 2015-05-30 12:58 - 00000000 ____D C:\Program Files\iPod
    2015-05-30 12:58 - 2015-05-30 12:58 - 00000000 ____D C:\Program Files (x86)\iTunes
    2015-05-30 12:57 - 2015-05-30 12:58 - 00000000 ____D C:\Program Files\Common Files\Apple
    2015-05-30 12:57 - 2015-05-30 12:57 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
    2015-05-30 12:57 - 2015-05-30 12:57 - 00000000 ____D C:\Program Files\Bonjour
    2015-05-30 12:57 - 2015-05-30 12:57 - 00000000 ____D C:\Program Files (x86)\Bonjour
    2015-05-30 12:57 - 2015-05-30 12:57 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
    2015-05-30 12:56 - 2015-05-30 12:57 - 00000000 ____D C:\ProgramData\Apple
    2015-05-28 14:58 - 2015-06-24 13:54 - 00003488 _____ C:\Windows\System32\Tasks\PCDEventLauncher
    2015-05-28 14:58 - 2015-05-28 14:58 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\PCDr
    2015-05-28 14:58 - 2015-05-28 14:58 - 00000000 ____D C:\ProgramData\PCDr
    2015-05-28 03:01 - 2015-05-28 03:01 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
    2015-05-27 21:20 - 2015-05-27 21:23 - 00000000 ___SD C:\Windows\system32\GWX
    2015-05-27 21:20 - 2015-05-27 21:20 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2015-05-27 21:16 - 2014-06-26 22:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
    2015-05-27 21:16 - 2014-06-26 21:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
    2015-05-27 19:58 - 2015-06-23 16:41 - 00000000 ____D C:\Users\Kendra\AppData\Local\gtk-2.0
    2015-05-27 19:58 - 2015-05-27 19:58 - 00000000 ____D C:\Users\Kendra\.thumbnails
    2015-05-27 19:57 - 2015-06-23 16:41 - 00000000 ____D C:\Users\Kendra\.gimp-2.8
    2015-05-27 19:57 - 2015-05-27 19:57 - 00000000 ____D C:\Users\Kendra\AppData\Local\gegl-0.2
    2015-05-27 19:52 - 2015-05-27 19:52 - 00000896 _____ C:\Users\Kendra\Desktop\GIMP 2.lnk
    2015-05-27 19:52 - 2015-05-27 19:52 - 00000896 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
    2015-05-27 19:52 - 2015-05-27 19:52 - 00000000 ____D C:\Program Files\GIMP 2
    2015-05-27 12:16 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
    2015-05-27 12:16 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
    2015-05-27 12:16 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
    2015-05-27 12:16 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
    2015-05-27 12:16 - 2014-07-08 22:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
    2015-05-27 12:16 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
    2015-05-27 12:16 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
    2015-05-27 12:16 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
    2015-05-27 12:16 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
    2015-05-27 12:16 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
    2015-05-27 12:16 - 2014-06-23 23:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
    2015-05-27 12:16 - 2014-06-23 22:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
    2015-05-27 12:16 - 2013-11-26 04:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
    2015-05-27 12:16 - 2013-11-22 18:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
    2015-05-27 12:15 - 2012-02-11 02:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
    2015-05-27 12:15 - 2012-02-11 02:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
    2015-05-27 12:12 - 2015-04-19 23:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2015-05-27 12:12 - 2015-04-19 23:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2015-05-27 12:12 - 2015-04-19 22:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2015-05-27 12:12 - 2015-02-03 23:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
    2015-05-27 12:12 - 2015-02-03 22:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
    2015-05-27 12:12 - 2015-02-02 23:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2015-05-27 12:12 - 2015-02-02 23:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2015-05-27 11:57 - 2015-06-10 03:19 - 00000000 ___SD C:\Windows\system32\CompatTel
    2015-05-27 11:57 - 2015-06-10 03:19 - 00000000 ____D C:\Windows\system32\appraiser
    2015-05-27 02:03 - 2015-01-08 19:44 - 00419936 _____ C:\Windows\SysWOW64\locale.nls
    2015-05-27 02:03 - 2015-01-08 19:43 - 00419936 _____ C:\Windows\system32\locale.nls
    2015-05-27 01:42 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
    2015-05-27 01:37 - 2015-05-27 01:37 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
    2015-05-27 01:37 - 2015-05-27 01:37 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
    2015-05-27 01:37 - 2015-05-27 01:37 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
    2015-05-27 01:37 - 2015-05-27 01:37 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
    2015-05-27 01:37 - 2015-05-27 01:37 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
    2015-05-27 01:37 - 2015-05-27 01:37 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
    2015-05-27 01:37 - 2015-05-27 01:37 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
    2015-05-27 01:30 - 2015-05-27 01:30 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
    2015-05-27 01:30 - 2015-05-27 01:30 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
    2015-05-27 01:28 - 2015-05-27 01:42 - 00013169 _____ C:\Windows\IE11_main.log
    2015-05-27 00:32 - 2015-05-28 03:02 - 00284588 _____ C:\Windows\msxml4-KB973688-enu.LOG
    2015-05-27 00:03 - 2015-05-28 03:01 - 00288380 _____ C:\Windows\msxml4-KB954430-enu.LOG
    2015-05-26 23:23 - 2012-07-25 23:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
    2015-05-26 23:23 - 2012-07-25 23:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
    2015-05-26 23:23 - 2012-07-25 23:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
    2015-05-26 23:23 - 2012-07-25 23:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
    2015-05-26 23:23 - 2012-07-25 23:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
    2015-05-26 23:23 - 2012-07-25 22:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
    2015-05-26 23:23 - 2012-07-25 22:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
    2015-05-26 23:23 - 2012-06-02 10:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
    2015-05-26 23:17 - 2015-05-01 09:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-05-26 23:17 - 2015-05-01 09:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-05-26 23:07 - 2012-03-01 02:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
    2015-05-26 23:07 - 2012-03-01 02:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
    2015-05-26 23:07 - 2012-03-01 01:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
    2015-05-26 22:58 - 2014-06-30 18:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
    2015-05-26 22:58 - 2014-06-30 18:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
    2015-05-26 22:58 - 2014-06-06 02:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
    2015-05-26 22:58 - 2014-06-06 02:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
    2015-05-26 22:58 - 2014-03-09 17:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
    2015-05-26 22:58 - 2014-03-09 17:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
    2015-05-26 22:58 - 2014-03-09 17:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
    2015-05-26 22:58 - 2014-03-09 17:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
    2015-05-26 20:29 - 2015-06-23 14:27 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\vlc
    2015-05-26 18:03 - 2015-05-26 18:03 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
    2015-05-26 17:59 - 2015-05-26 17:59 - 00001449 _____ C:\Users\Rolland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-05-26 17:59 - 2015-05-26 17:59 - 00001415 _____ C:\Users\Rolland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
    2015-05-26 17:59 - 2015-05-26 17:59 - 00000000 ____D C:\Users\Rolland\AppData\Roaming\Roxio
    2015-05-26 17:59 - 2015-05-26 17:59 - 00000000 ____D C:\Users\Rolland\AppData\Roaming\Creative
    2015-05-26 17:59 - 2015-05-26 17:59 - 00000000 ____D C:\Users\Rolland\AppData\Roaming\AVG2015
    2015-05-26 17:59 - 2015-05-26 17:59 - 00000000 ____D C:\Users\Rolland\AppData\Local\Google
    2015-05-26 17:59 - 2015-05-26 17:59 - 00000000 ____D C:\Users\Rolland\AppData\Local\Avg2015
    2015-05-26 17:58 - 2015-05-26 17:59 - 00000000 ____D C:\Users\Rolland
    2015-05-26 17:58 - 2015-05-26 17:58 - 00000020 ___SH C:\Users\Rolland\ntuser.ini
    2015-05-26 17:58 - 2015-05-26 17:58 - 00000000 ____D C:\Users\Rolland\AppData\Roaming\Intel
    2015-05-26 17:58 - 2015-05-26 17:58 - 00000000 ____D C:\Users\Rolland\AppData\Local\VirtualStore
    2015-05-26 17:58 - 2011-09-10 20:54 - 00000000 ____D C:\Users\Rolland\AppData\Local\SoftThinks
    2015-05-26 17:58 - 2009-07-14 00:54 - 00000000 ___RD C:\Users\Rolland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-05-26 17:58 - 2009-07-14 00:49 - 00000000 ___RD C:\Users\Rolland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2015-05-26 17:41 - 2015-05-26 17:41 - 00001072 _____ C:\Users\Public\Desktop\VLC media player.lnk
    2015-05-26 17:41 - 2015-05-26 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    2015-05-26 17:41 - 2015-05-26 17:41 - 00000000 ____D C:\Program Files (x86)\VideoLAN
    2015-05-26 17:40 - 2015-05-26 17:40 - 28849904 _____ C:\Users\Kendra\Downloads\vlc-2.2.1-win32.exe
    2015-05-26 17:39 - 2015-05-26 17:39 - 00001108 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-05-26 17:39 - 2015-05-26 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-05-26 17:39 - 2015-05-26 17:39 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-05-26 17:39 - 2015-05-26 17:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-05-26 17:39 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-05-26 17:39 - 2015-04-14 09:37 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2015-05-26 17:39 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2015-05-26 17:38 - 2015-05-26 17:39 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Kendra\Downloads\mbam-setup-2.1.6.1022.exe
    2015-05-26 17:27 - 2015-06-23 14:03 - 00000967 _____ C:\Users\Public\Desktop\AVG 2015.lnk
    2015-05-26 17:27 - 2015-06-23 14:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    2015-05-26 17:19 - 2015-05-26 17:19 - 04928976 _____ (AVG Technologies) C:\Users\Kendra\Downloads\avg_isc_stb_all_2015_ltst_205.exe
    2015-05-26 17:17 - 2015-01-08 23:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
    2015-05-26 17:17 - 2015-01-08 23:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
    2015-05-26 17:17 - 2015-01-08 23:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
    2015-05-26 17:17 - 2015-01-08 22:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
    2015-05-26 17:10 - 2015-04-17 23:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
    2015-05-26 17:10 - 2015-04-17 22:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
    2015-05-26 17:10 - 2015-04-12 23:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
    2015-05-26 17:10 - 2014-12-11 13:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
    2015-05-26 17:10 - 2011-06-16 01:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
    2015-05-26 17:10 - 2011-06-16 00:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xmllite.dll
    2015-05-26 17:09 - 2015-02-20 00:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
    2015-05-26 17:09 - 2015-02-20 00:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
    2015-05-26 17:09 - 2015-02-20 00:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
    2015-05-26 17:09 - 2015-02-20 00:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
    2015-05-26 17:09 - 2015-02-20 00:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
    2015-05-26 17:09 - 2015-02-20 00:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2015-05-26 17:09 - 2015-02-20 00:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
    2015-05-26 17:09 - 2015-02-20 00:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
    2015-05-26 17:09 - 2015-02-19 23:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
    2015-05-26 17:09 - 2015-02-19 23:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2015-05-26 17:09 - 2014-01-27 22:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
    2015-05-26 17:09 - 2013-10-29 22:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
    2015-05-26 17:09 - 2013-10-29 22:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
    2015-05-26 17:09 - 2013-03-19 01:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
    2015-05-26 17:09 - 2012-10-09 14:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
    2015-05-26 17:09 - 2012-10-09 14:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
    2015-05-26 17:09 - 2012-10-09 13:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
    2015-05-26 17:09 - 2012-10-09 13:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
    2015-05-26 17:09 - 2012-01-04 06:44 - 00509952 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
    2015-05-26 17:09 - 2012-01-04 04:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
    2015-05-26 17:09 - 2011-06-15 06:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
    2015-05-26 17:09 - 2011-06-15 06:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
    2015-05-26 17:09 - 2011-06-15 06:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
    2015-05-26 17:09 - 2011-06-15 06:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
    2015-05-26 17:09 - 2011-06-15 04:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
    2015-05-26 17:09 - 2011-06-15 04:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
    2015-05-26 17:09 - 2011-06-15 04:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
    2015-05-26 17:09 - 2011-06-15 04:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
    2015-05-26 17:09 - 2011-06-15 04:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
    2015-05-26 17:08 - 2015-02-02 23:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
    2015-05-26 17:08 - 2015-02-02 23:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
    2015-05-26 17:08 - 2015-02-02 23:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
    2015-05-26 17:08 - 2015-02-02 23:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
    2015-05-26 17:08 - 2015-02-02 23:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
    2015-05-26 17:08 - 2015-02-02 23:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
    2015-05-26 17:08 - 2015-02-02 23:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
    2015-05-26 17:08 - 2015-02-02 23:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
    2015-05-26 17:08 - 2015-02-02 23:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
    2015-05-26 17:08 - 2015-02-02 23:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
    2015-05-26 17:08 - 2015-02-02 23:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
    2015-05-26 17:08 - 2015-02-02 23:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
    2015-05-26 17:08 - 2015-02-02 23:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
    2015-05-26 17:08 - 2015-02-02 23:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
    2015-05-26 17:08 - 2015-02-02 23:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
    2015-05-26 17:08 - 2015-02-02 23:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
    2015-05-26 17:08 - 2015-02-02 23:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
    2015-05-26 17:08 - 2015-02-02 23:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
    2015-05-26 17:08 - 2015-02-02 23:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
    2015-05-26 17:08 - 2015-02-02 23:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
    2015-05-26 17:08 - 2015-02-02 22:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
    2015-05-26 17:08 - 2014-10-31 18:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
    2015-05-26 17:08 - 2014-08-01 07:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
    2015-05-26 17:08 - 2014-08-01 07:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
    2015-05-26 17:08 - 2014-06-27 20:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
    2015-05-26 17:08 - 2014-06-27 20:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
    2015-05-26 17:08 - 2014-04-24 22:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
    2015-05-26 17:08 - 2014-04-24 22:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
    2015-05-26 17:08 - 2011-11-17 02:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
    2015-05-26 17:08 - 2011-11-17 01:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
    2015-05-26 17:08 - 2011-07-08 22:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
    2015-05-26 17:08 - 2011-05-04 01:25 - 02315776 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
    2015-05-26 17:08 - 2011-05-04 01:22 - 02223616 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
    2015-05-26 17:08 - 2011-05-04 01:22 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
    2015-05-26 17:08 - 2011-05-04 01:22 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
    2015-05-26 17:08 - 2011-05-04 01:22 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
    2015-05-26 17:08 - 2011-05-04 01:22 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
    2015-05-26 17:08 - 2011-05-04 01:19 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
    2015-05-26 17:08 - 2011-05-04 01:19 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
    2015-05-26 17:08 - 2011-05-04 01:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
    2015-05-26 17:08 - 2011-05-04 00:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
    2015-05-26 17:08 - 2011-05-04 00:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
    2015-05-26 17:08 - 2011-05-04 00:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
    2015-05-26 17:08 - 2011-05-04 00:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
    2015-05-26 17:08 - 2011-05-04 00:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
    2015-05-26 17:08 - 2011-05-04 00:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
    2015-05-26 17:08 - 2011-05-04 00:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
    2015-05-26 17:08 - 2011-05-04 00:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
    2015-05-26 17:08 - 2011-05-04 00:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
    2015-05-26 17:07 - 2015-04-07 23:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-05-26 17:07 - 2015-04-07 23:29 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-05-26 17:07 - 2015-04-07 23:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
    2015-05-26 17:07 - 2014-12-18 23:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
    2015-05-26 17:07 - 2014-10-13 22:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
    2015-05-26 17:07 - 2014-06-18 18:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
    2015-05-26 17:07 - 2014-06-18 18:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
    2015-05-26 17:07 - 2014-06-18 18:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
    2015-05-26 17:07 - 2014-06-18 18:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
    2015-05-26 17:07 - 2014-06-18 18:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
    2015-05-26 17:07 - 2014-06-18 18:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
    2015-05-26 17:07 - 2014-04-04 22:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
    2015-05-26 17:07 - 2014-04-04 22:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
    2015-05-26 17:07 - 2014-01-28 22:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
    2015-05-26 17:07 - 2014-01-28 22:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
    2015-05-26 17:07 - 2013-11-26 07:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
    2015-05-26 17:07 - 2013-10-18 22:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
    2015-05-26 17:07 - 2013-10-18 21:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
    2015-05-26 17:06 - 2015-05-26 17:52 - 00000000 ____D C:\Users\Kendra\AppData\Local\LogMeIn Rescue Applet
    2015-05-26 17:06 - 2015-05-26 17:06 - 01489216 _____ (LogMeIn, Inc.) C:\Users\Kendra\Downloads\Support-LogMeInRescue.exe
    2015-05-26 17:06 - 2015-03-24 23:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-05-26 17:06 - 2015-03-24 23:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-05-26 17:06 - 2015-03-24 23:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-05-26 17:06 - 2015-03-24 23:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-05-26 17:06 - 2015-03-24 23:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-05-26 17:06 - 2015-03-24 23:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-05-26 17:06 - 2015-03-24 23:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-05-26 17:06 - 2015-03-24 23:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-05-26 17:06 - 2015-03-24 23:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-05-26 17:06 - 2015-03-24 23:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-05-26 17:06 - 2015-03-24 23:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-05-26 17:06 - 2015-03-24 23:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-05-26 17:06 - 2015-03-24 23:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-05-26 17:06 - 2015-03-24 23:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-05-26 17:06 - 2015-03-24 23:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-05-26 17:06 - 2015-03-24 23:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-05-26 17:06 - 2015-02-02 23:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
    2015-05-26 17:06 - 2015-02-02 23:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
    2015-05-26 17:06 - 2015-01-28 23:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
    2015-05-26 17:06 - 2015-01-28 23:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
    2015-05-26 17:06 - 2014-12-18 21:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
    2015-05-26 17:06 - 2014-12-06 00:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
    2015-05-26 17:06 - 2014-12-05 23:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
    2015-05-26 17:06 - 2014-12-05 23:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
    2015-05-26 17:06 - 2014-06-17 22:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
    2015-05-26 17:06 - 2014-06-17 21:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
    2015-05-26 17:06 - 2014-06-06 06:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
    2015-05-26 17:06 - 2014-06-06 05:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
    2015-05-26 17:06 - 2014-03-26 10:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
    2015-05-26 17:06 - 2014-03-26 10:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
    2015-05-26 17:06 - 2014-03-26 10:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2015-05-26 17:06 - 2014-03-26 10:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
    2015-05-26 17:06 - 2013-12-03 22:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
    2015-05-26 17:06 - 2013-12-03 22:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
    2015-05-26 17:06 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
    2015-05-26 17:06 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
    2015-05-26 17:06 - 2013-12-03 22:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
    2015-05-26 17:06 - 2013-12-03 22:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
    2015-05-26 17:06 - 2013-12-03 22:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
    2015-05-26 17:06 - 2013-12-03 22:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
    2015-05-26 17:06 - 2013-12-03 22:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
    2015-05-26 17:06 - 2013-12-03 22:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
    2015-05-26 17:06 - 2013-12-03 22:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
    2015-05-26 17:06 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
    2015-05-26 17:06 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
    2015-05-26 17:06 - 2013-12-03 22:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
    2015-05-26 17:06 - 2013-12-03 21:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
    2015-05-26 17:06 - 2013-12-03 21:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
    2015-05-26 17:06 - 2013-12-03 21:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
    2015-05-26 17:06 - 2013-12-03 21:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
    2015-05-26 17:06 - 2013-11-26 21:42 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
    2015-05-26 17:06 - 2013-11-26 21:42 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
    2015-05-26 17:06 - 2013-11-26 21:42 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
    2015-05-26 17:06 - 2013-11-26 21:42 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
    2015-05-26 17:06 - 2013-11-26 21:42 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
    2015-05-26 17:06 - 2013-11-26 21:42 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
    2015-05-26 17:06 - 2013-11-26 21:42 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
    2015-05-26 17:06 - 2013-10-03 22:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
    2015-05-26 17:06 - 2013-10-03 22:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
    2015-05-26 17:06 - 2013-10-03 22:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
    2015-05-26 17:06 - 2013-10-03 21:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
    2015-05-26 17:06 - 2013-10-03 21:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
    2015-05-26 17:06 - 2013-10-03 21:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
    2015-05-26 17:06 - 2013-08-04 22:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
    2015-05-26 17:06 - 2013-04-25 19:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
    2015-05-26 17:06 - 2013-03-31 18:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
    2015-05-26 17:06 - 2013-02-12 00:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
    2015-05-26 17:06 - 2012-08-22 14:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
    2015-05-26 17:06 - 2012-07-04 16:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
    2015-05-26 17:06 - 2011-12-30 02:26 - 00515584 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
    2015-05-26 17:06 - 2011-12-30 01:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\timedate.cpl
    2015-05-26 17:05 - 2015-03-05 01:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2015-05-26 17:05 - 2015-03-05 00:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2015-05-26 17:05 - 2015-02-13 01:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2015-05-26 17:05 - 2015-02-13 01:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2015-05-26 17:05 - 2015-01-27 19:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
    2015-05-26 17:05 - 2014-11-10 21:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
    2015-05-26 17:05 - 2014-05-30 02:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
    2015-05-26 17:05 - 2014-03-04 05:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
    2015-05-26 17:05 - 2014-03-04 05:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
    2015-05-26 17:05 - 2014-03-04 05:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
    2015-05-26 17:05 - 2014-03-04 05:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
    2015-05-26 17:05 - 2014-03-04 05:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
    2015-05-26 17:05 - 2014-03-04 05:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
    2015-05-26 17:05 - 2013-07-25 05:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
    2015-05-26 17:05 - 2013-07-25 04:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
    2015-05-26 17:05 - 2013-07-12 06:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
    2015-05-26 17:05 - 2013-07-12 06:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
    2015-05-26 17:05 - 2013-07-04 08:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
    2015-05-26 17:05 - 2013-07-04 08:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
    2015-05-26 17:05 - 2013-07-04 07:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
    2015-05-26 17:05 - 2013-07-04 07:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
    2015-05-26 17:05 - 2013-07-03 00:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
    2015-05-26 17:05 - 2013-07-03 00:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
    2015-05-26 17:05 - 2013-06-25 18:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
    2015-05-26 17:05 - 2012-11-28 18:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
    2015-05-26 17:05 - 2012-11-28 18:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
    2015-05-26 17:05 - 2012-11-28 18:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
    2015-05-26 17:05 - 2012-11-02 01:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
    2015-05-26 17:05 - 2012-11-02 01:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
    2015-05-26 17:05 - 2012-10-03 13:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
    2015-05-26 17:05 - 2012-10-03 13:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
    2015-05-26 17:05 - 2012-10-03 13:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
    2015-05-26 17:05 - 2012-10-03 13:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
    2015-05-26 17:05 - 2012-10-03 13:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
    2015-05-26 17:05 - 2012-10-03 12:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
    2015-05-26 17:05 - 2012-10-03 12:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
    2015-05-26 17:05 - 2012-10-03 12:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
    2015-05-26 17:04 - 2015-03-09 23:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
    2015-05-26 17:04 - 2015-03-09 23:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
    2015-05-26 17:04 - 2015-03-09 23:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2015-05-26 17:04 - 2015-03-09 23:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
    2015-05-26 17:04 - 2015-01-30 19:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
    2015-05-26 17:04 - 2014-08-11 22:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
    2015-05-26 17:04 - 2014-08-11 21:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
    2015-05-26 17:04 - 2014-06-15 22:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
    2015-05-26 17:04 - 2013-09-07 22:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
    2015-05-26 17:04 - 2013-09-07 22:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
    2015-05-26 17:04 - 2013-04-10 02:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
    2015-05-26 17:04 - 2012-12-07 09:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
    2015-05-26 17:04 - 2012-12-07 09:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
    2015-05-26 17:04 - 2012-12-07 08:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
    2015-05-26 17:04 - 2012-12-07 08:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
    2015-05-26 17:04 - 2012-12-07 07:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
    2015-05-26 17:04 - 2012-12-07 07:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
    2015-05-26 17:04 - 2012-12-07 07:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
    2015-05-26 17:04 - 2012-12-07 07:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
    2015-05-26 17:04 - 2012-12-07 07:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
    2015-05-26 17:04 - 2012-12-07 07:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
    2015-05-26 17:04 - 2012-12-07 07:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
    2015-05-26 17:04 - 2012-12-07 07:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
    2015-05-26 17:04 - 2012-12-07 07:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
    2015-05-26 17:04 - 2012-12-07 07:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
    2015-05-26 17:04 - 2012-12-07 07:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
    2015-05-26 17:04 - 2012-12-07 07:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
    2015-05-26 17:04 - 2012-12-07 07:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
    2015-05-26 17:04 - 2012-12-07 07:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
    2015-05-26 17:04 - 2012-12-07 06:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
    2015-05-26 17:04 - 2012-08-21 17:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
    2015-05-26 17:04 - 2011-08-17 01:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
    2015-05-26 17:04 - 2011-08-17 01:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
    2015-05-26 17:04 - 2011-08-17 00:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
    2015-05-26 17:04 - 2011-08-17 00:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
    2015-05-26 17:04 - 2011-02-03 07:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
    2015-05-26 17:03 - 2015-03-04 00:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-05-26 17:03 - 2015-03-04 00:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-05-26 17:03 - 2015-03-04 00:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-05-26 17:03 - 2015-03-04 00:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-05-26 17:03 - 2015-03-04 00:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
    2015-05-26 17:03 - 2015-03-04 00:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
    2015-05-26 17:03 - 2015-03-04 00:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
    2015-05-26 17:03 - 2015-02-24 23:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
    2015-05-26 17:03 - 2015-02-18 03:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
    2015-05-26 17:03 - 2015-02-18 03:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
    2015-05-26 17:03 - 2015-01-16 22:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2015-05-26 17:03 - 2015-01-16 22:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
    2015-05-26 17:03 - 2014-11-25 23:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
    2015-05-26 17:03 - 2014-11-25 23:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2015-05-26 17:03 - 2014-11-10 23:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
    2015-05-26 17:03 - 2014-11-10 22:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
    2015-05-26 17:03 - 2014-11-07 23:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2015-05-26 17:03 - 2014-11-07 22:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2015-05-26 17:03 - 2014-10-29 22:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
    2015-05-26 17:03 - 2014-10-29 21:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
    2015-05-26 17:03 - 2014-10-03 22:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2015-05-26 17:03 - 2014-10-03 21:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2015-05-26 17:03 - 2014-10-03 21:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
    2015-05-26 17:03 - 2014-10-02 22:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
    2015-05-26 17:03 - 2014-10-02 22:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
    2015-05-26 17:03 - 2014-10-02 22:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
    2015-05-26 17:03 - 2014-10-02 22:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
    2015-05-26 17:03 - 2014-10-02 22:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
    2015-05-26 17:03 - 2014-10-02 21:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
    2015-05-26 17:03 - 2014-10-02 21:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
    2015-05-26 17:03 - 2014-10-02 21:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
    2015-05-26 17:03 - 2014-10-02 21:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
    2015-05-26 17:03 - 2014-10-02 21:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
    2015-05-26 17:03 - 2014-09-04 01:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
    2015-05-26 17:03 - 2014-09-04 01:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
    2015-05-26 17:03 - 2014-02-03 22:37 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
    2015-05-26 17:03 - 2014-02-03 22:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
    2015-05-26 17:03 - 2014-02-03 22:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
    2015-05-26 17:03 - 2014-02-03 22:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
    2015-05-26 17:03 - 2014-02-03 22:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
    2015-05-26 17:03 - 2013-07-25 22:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
    2015-05-26 17:03 - 2013-07-25 21:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
    2015-05-26 17:03 - 2013-05-10 01:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
    2015-05-26 17:03 - 2013-05-09 23:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
    2015-05-26 17:03 - 2013-04-26 01:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
    2015-05-26 17:03 - 2013-04-26 00:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
    2015-05-26 17:03 - 2012-11-22 23:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
    2015-05-26 17:03 - 2012-09-25 18:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
    2015-05-26 17:03 - 2012-09-25 18:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
    2015-05-26 17:03 - 2012-03-17 03:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
    2015-05-26 17:03 - 2011-05-24 07:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
    2015-05-26 17:03 - 2011-05-24 06:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
    2015-05-26 17:03 - 2011-05-24 06:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
    2015-05-26 17:03 - 2011-05-24 06:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
    2015-05-26 17:03 - 2011-05-24 06:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
    2015-05-26 17:02 - 2015-03-04 00:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
    2015-05-26 17:02 - 2015-03-04 00:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
    2015-05-26 17:02 - 2015-03-04 00:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
    2015-05-26 17:02 - 2014-12-07 23:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
    2015-05-26 17:02 - 2014-12-07 22:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
    2015-05-26 17:02 - 2014-10-24 21:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
    2015-05-26 17:02 - 2014-10-24 21:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
    2015-05-26 17:02 - 2014-10-13 22:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
    2015-05-26 17:02 - 2014-10-13 21:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2015-05-26 17:02 - 2014-07-16 22:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
    2015-05-26 17:02 - 2014-07-16 22:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
    2015-05-26 17:02 - 2014-07-16 22:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
    2015-05-26 17:02 - 2014-07-16 22:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
    2015-05-26 17:02 - 2014-07-16 21:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
    2015-05-26 17:02 - 2014-07-16 21:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
    2015-05-26 17:02 - 2014-07-16 21:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
    2015-05-26 17:02 - 2014-07-16 21:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
    2015-05-26 17:02 - 2014-06-03 06:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
    2015-05-26 17:02 - 2014-06-03 06:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
    2015-05-26 17:02 - 2014-06-03 06:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
    2015-05-26 17:02 - 2014-06-03 05:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2015-05-26 17:02 - 2014-06-03 05:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
    2015-05-26 17:02 - 2014-01-23 22:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
    2015-05-26 17:02 - 2013-10-11 22:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
    2015-05-26 17:02 - 2013-10-11 22:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
    2015-05-26 17:02 - 2013-10-11 22:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
    2015-05-26 17:02 - 2013-10-11 22:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
    2015-05-26 17:02 - 2013-10-11 22:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
    2015-05-26 17:02 - 2013-10-11 22:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
    2015-05-26 17:02 - 2013-10-11 22:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
    2015-05-26 17:02 - 2013-10-11 22:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
    2015-05-26 17:02 - 2013-10-11 22:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
    2015-05-26 17:02 - 2013-10-11 21:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
    2015-05-26 17:02 - 2013-10-11 21:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
    2015-05-26 17:02 - 2013-10-11 21:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
    2015-05-26 17:02 - 2013-10-11 21:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
    2015-05-26 17:02 - 2013-05-13 01:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
    2015-05-26 17:02 - 2013-05-12 23:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
    2015-05-26 17:02 - 2013-05-12 23:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
    2015-05-26 17:02 - 2013-05-12 23:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
    2015-05-26 17:02 - 2013-02-27 01:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
    2015-05-26 17:02 - 2013-02-15 02:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
    2015-05-26 17:02 - 2013-02-15 02:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
    2015-05-26 17:02 - 2013-02-14 23:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
    2015-05-26 17:02 - 2013-01-24 02:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
    2015-05-26 17:02 - 2012-07-04 18:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
    2015-05-26 17:02 - 2012-07-04 18:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
    2015-05-26 17:02 - 2012-07-04 18:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
    2015-05-26 17:02 - 2012-07-04 17:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
    2015-05-26 17:02 - 2012-07-04 17:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
    2015-05-26 17:02 - 2012-06-06 02:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
    2015-05-26 17:02 - 2012-06-06 01:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
    2015-05-26 17:02 - 2012-05-14 01:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
    2015-05-26 17:02 - 2012-04-26 01:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
    2015-05-26 17:02 - 2012-04-26 01:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
    2015-05-26 17:02 - 2011-12-16 04:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
    2015-05-26 17:02 - 2011-12-16 03:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
    2015-05-26 17:02 - 2011-10-15 02:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
    2015-05-26 17:02 - 2011-10-15 01:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
    2015-05-26 17:02 - 2011-08-27 01:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
    2015-05-26 17:02 - 2011-08-27 00:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
    2015-05-26 17:01 - 2014-07-13 22:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2015-05-26 17:01 - 2014-07-13 21:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2015-05-26 17:01 - 2013-08-27 21:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
    2015-05-26 16:41 - 2015-05-26 16:56 - 00000000 ____D C:\Windows\SMINST
    2015-05-26 16:30 - 2015-05-26 16:30 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\AVG2015
    2015-05-26 16:30 - 2012-02-17 02:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
    2015-05-26 16:30 - 2012-02-17 01:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
    2015-05-26 16:30 - 2012-02-17 00:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
    2015-05-26 16:29 - 2015-05-26 17:26 - 00000000 ___HD C:\$AVG
    2015-05-26 16:29 - 2015-05-26 16:29 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\TuneUp Software
    2015-05-26 16:28 - 2015-05-26 17:28 - 00000000 ____D C:\ProgramData\AVG2015
    2015-05-26 16:28 - 2015-05-26 16:28 - 00000000 ____D C:\Program Files (x86)\AVG
    2015-05-26 16:26 - 2015-06-24 14:08 - 00000000 ____D C:\ProgramData\MFAData
    2015-05-26 16:26 - 2015-05-26 19:04 - 00000000 ____D C:\Users\Kendra\AppData\Local\Avg2015
    2015-05-26 16:26 - 2015-05-26 16:26 - 00000000 ____D C:\Users\Kendra\AppData\Local\MFAData
    2015-05-26 16:25 - 2015-05-26 16:26 - 04928976 _____ (AVG Technologies) C:\Users\Kendra\Downloads\avg_avc_stb_all_2015_ltst_197.exe
    2015-05-26 16:23 - 2015-06-22 17:38 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2015-05-26 16:23 - 2015-05-26 16:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-05-26 16:22 - 2015-06-24 13:54 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-05-26 16:22 - 2015-06-23 21:36 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-05-26 16:22 - 2015-05-26 21:31 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-05-26 16:22 - 2015-05-26 21:31 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-05-26 16:22 - 2015-05-26 16:23 - 00000000 ____D C:\Users\Kendra\AppData\Local\Google
    2015-05-26 16:22 - 2015-05-26 16:23 - 00000000 ____D C:\Program Files (x86)\Google
    2015-05-26 16:22 - 2015-05-26 16:22 - 00000000 ____D C:\Users\Kendra\AppData\Local\Apps\2.0
    2015-05-26 16:21 - 2015-05-26 16:22 - 00000000 ____D C:\Users\Kendra\AppData\Local\Deployment
    2015-05-26 16:21 - 2015-05-26 16:21 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Macromedia
    2015-05-26 16:21 - 2015-05-26 16:21 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Adobe
    2015-05-26 16:13 - 2015-05-26 16:13 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Mozilla
    2015-05-26 16:08 - 2015-06-24 13:55 - 00000422 _____ C:\Windows\Tasks\SystemToolsDailyTest.job
    2015-05-26 16:08 - 2015-06-24 13:54 - 00003446 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
    2015-05-26 16:08 - 2015-06-15 12:12 - 00000564 _____ C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
    2015-05-26 16:08 - 2015-05-26 16:13 - 00000000 ____D C:\Users\Kendra\AppData\Local\Dell
    2015-05-26 16:08 - 2015-05-26 16:08 - 00008096 _____ C:\Windows\system32\TEST.log
    2015-05-26 16:08 - 2015-05-26 16:08 - 00003920 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
    2015-05-26 16:08 - 2015-05-26 16:08 - 00001056 _____ C:\Windows\system32\SENT.log
    2015-05-26 16:08 - 2015-05-26 16:08 - 00000388 _____ C:\Windows\system32\RECV.log
    2015-05-26 16:08 - 2015-05-26 16:08 - 00000000 ____D C:\Users\Kendra\AppData\Local\VirtualStore
    2015-05-26 16:07 - 2015-05-26 16:07 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Roxio
    2015-05-26 16:07 - 2015-05-26 16:07 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Dell Touch Zone
    2015-05-26 16:07 - 2015-05-26 16:07 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Dell
    2015-05-26 16:07 - 2015-05-26 16:07 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Creative
    2015-05-26 16:06 - 2015-06-22 16:16 - 00075736 _____ C:\Users\Kendra\AppData\Local\GDIPFONTCACHEV1.DAT
    2015-05-26 16:06 - 2015-05-27 12:06 - 00001419 _____ C:\Users\Kendra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-05-26 16:06 - 2015-05-26 16:06 - 00001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Help Documentation.lnk
    2015-05-26 16:06 - 2015-05-26 16:06 - 00000000 ____D C:\Users\Kendra\AppData\Local\Dell Edoc Viewer
    2015-05-26 16:05 - 2015-06-22 23:24 - 00000000 ____D C:\Users\Kendra\AppData\Local\SoftThinks
    2015-05-26 16:05 - 2015-05-27 19:58 - 00000000 ____D C:\Users\Kendra
    2015-05-26 16:05 - 2015-05-26 16:05 - 00000020 ___SH C:\Users\Kendra\ntuser.ini
    2015-05-26 16:05 - 2015-05-26 16:05 - 00000000 ____D C:\Users\Kendra\AppData\Roaming\Intel
    2015-05-26 16:05 - 2009-07-14 00:54 - 00000000 ___RD C:\Users\Kendra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-05-26 16:05 - 2009-07-14 00:49 - 00000000 ___RD C:\Users\Kendra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-06-24 14:05 - 2011-09-10 22:12 - 01272823 _____ C:\Windows\WindowsUpdate.log
    2015-06-24 13:59 - 2009-07-14 00:45 - 00021296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-06-24 13:59 - 2009-07-14 00:45 - 00021296 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-06-22 23:29 - 2009-07-14 01:13 - 00778834 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-06-22 23:24 - 2011-09-10 22:10 - 00000000 ____D C:\ProgramData\NVIDIA
    2015-06-22 23:24 - 2011-09-10 20:45 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
    2015-06-22 23:24 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-06-22 23:24 - 2009-07-14 00:45 - 00323488 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-06-22 23:23 - 2009-07-14 00:51 - 00054472 _____ C:\Windows\setupact.log
    2015-06-19 14:08 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\LiveKernelReports
    2015-06-17 12:07 - 2011-09-10 20:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2015-06-16 23:06 - 2011-09-10 20:56 - 00216671 _____ C:\Windows\DirectX.log
    2015-06-10 03:59 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
    2015-06-10 03:19 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\PolicyDefinitions
    2015-06-06 11:52 - 2011-09-10 21:06 - 00000000 ____D C:\ProgramData\Sonic
    2015-06-05 20:42 - 2010-11-20 23:47 - 00026518 _____ C:\Windows\PFRO.log
    2015-05-28 08:42 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\AppCompat
    2015-05-27 11:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
    2015-05-27 11:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
    2015-05-27 11:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
    2015-05-27 11:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\zh-HK
    2015-05-27 11:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\tr-TR
    2015-05-27 11:58 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\Dism
    2015-05-27 11:58 - 2009-07-13 23:20 - 00000000 ____D C:\Program Files\Common Files\System
    2015-05-27 11:57 - 2010-11-21 03:17 - 00000000 ____D C:\Program Files\Windows Journal
    2015-05-27 11:57 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\Windows Defender
    2015-05-27 11:57 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2015-05-27 11:57 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\tracing
    2015-05-27 11:57 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
    2015-05-27 01:49 - 2011-02-10 12:10 - 00764378 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
    2015-05-26 16:58 - 2011-02-10 10:02 - 00000000 ____D C:\Windows\panther
    2015-05-26 16:20 - 2011-09-10 21:00 - 00000000 ____D C:\ProgramData\McAfee
    2015-05-26 16:19 - 2011-02-10 10:01 - 00000000 ____D C:\DELL
    2015-05-26 16:18 - 2011-09-10 20:58 - 00000000 ____D C:\Program Files (x86)\Windows Live
    2015-05-26 16:17 - 2009-07-13 23:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2015-05-26 16:13 - 2011-09-10 20:50 - 00000000 ____D C:\ProgramData\install_clap
    2015-05-26 16:13 - 2011-09-10 20:50 - 00000000 ____D C:\Program Files (x86)\Dell
    2015-05-26 16:12 - 2011-09-10 21:54 - 00000000 ____D C:\ProgramData\dell
    2015-05-26 16:08 - 2011-09-10 20:47 - 00017982 _____ C:\Windows\RPSETUP.EXE.LOG
    2015-05-26 16:03 - 2009-07-13 23:20 - 00000000 __RHD C:\Users\Public\Libraries

    ==================== Files in the root of some directories =======

    2015-06-23 16:41 - 2015-06-23 16:41 - 0026710 _____ () C:\Users\Kendra\AppData\Local\recently-used.xbel

    Some files in TEMP:
    ====================
    C:\Users\Kendra\AppData\Local\Temp\MSN9E72.exe


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-06-23 17:52

    ==================== End of log ============================

     

     

    ADDITION

     

    __________________________________________________________________

     

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:21-06-2015 01
    Ran by Kendra at 2015-06-24 14:13:11
    Running from C:\Users\Kendra\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1613421670-3433999689-4052708816-500 - Administrator - Disabled)
    Guest (S-1-5-21-1613421670-3433999689-4052708816-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-1613421670-3433999689-4052708816-1003 - Limited - Enabled)
    Kendra (S-1-5-21-1613421670-3433999689-4052708816-1001 - Administrator - Enabled) => C:\Users\Kendra
    Rolland (S-1-5-21-1613421670-3433999689-4052708816-1004 - Limited - Enabled) => C:\Users\Rolland
    UpdatusUser (S-1-5-21-1613421670-3433999689-4052708816-1000 - Limited - Enabled) => C:\Users\UpdatusUser

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: AVG Internet Security 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: AVG Internet Security 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
    FW: AVG Internet Security 2015 (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    AccelerometerP11 (HKLM-x32\...\{87434D51-51DB-4109-B68F-A829ECDCF380}) (Version: 2.00.11.22 - STMicroelectronics)
    Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.3.181.34 - Adobe Systems Incorporated)
    Adobe Reader X MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated)
    Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
    Akamai NetSession Interface (HKU\S-1-5-21-1613421670-3433999689-4052708816-1001\...\Akamai) (Version:  - Akamai Technologies, Inc)
    Apple Application Support (32-bit) (HKLM-x32\...\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\...\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6037 - AVG Technologies)
    AVG 2015 (Version: 15.0.4365 - AVG Technologies) Hidden
    AVG 2015 (Version: 15.0.6037 - AVG Technologies) Hidden
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Cozi (HKLM-x32\...\{EA1F3D6C-A6F5-4CDC-B0D3-9C56C06B4D29}) (Version: 1.0.6505.38692 - Cozi Group, Inc.)
    Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.57 - Dell Inc.)
    Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.57 - Dell Inc.)
    Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
    Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
    Dell Support Center (HKLM\...\Dell Support Center) (Version: 3.1.5803.11 - Dell Inc.)
    Dell Support Center (Version: 3.1.5803.11 - PC-Doctor, Inc.) Hidden
    Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
    DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
    eBay (HKLM-x32\...\{A8B88634-7F90-402F-B66A-86429755F6A5}) (Version: 1.4.0 - eBay Inc.)
    FINAL FANTASY XIV - A Realm Reborn (HKLM-x32\...\{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}) (Version: 1.0.0000 - SQUARE ENIX CO., LTD.)
    Fraps (HKLM-x32\...\Fraps) (Version:  - )
    Free YouTube Download version 3.2.59.616 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.59.616 - DVDVideoSoft Ltd.)
    Free YouTube to MP3 Converter version 3.12.59.525 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.59.525 - DVDVideoSoft Ltd.)
    GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
    Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
    Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2321 - Intel Corporation)
    Intel® PROSet/Wireless WiFi Software (HKLM\...\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation)
    Intel® Turbo Boost Technology Monitor 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
    Intel® WiDi (HKLM-x32\...\{0DD706AF-B542-438C-999E-B30C7F625C8D}) (Version: 2.1.39.0 - Intel Corporation)
    Intel® Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
    iTunes (HKLM\...\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)
    Java™ 6 Update 24 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
    Java™ 6 Update 24 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216024FF}) (Version: 6.0.240 - Oracle)
    Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    NVIDIA 3D Vision Driver 268.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 268.30 - NVIDIA Corporation)
    NVIDIA Graphics Driver 268.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.30 - NVIDIA Corporation)
    PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
    Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.0.10 - Dell Inc.)
    RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6312 - Realtek Semiconductor Corp.)
    Rosetta Stone Language Training (HKLM-x32\...\{00384623-4937-4D7D-BDD9-23513D1C50AB}) (Version: 5.0.13.0 - Rosetta Stone, Ltd)
    Rosetta Stone Ltd Services (HKLM-x32\...\{3165E4A6-D5DE-46B0-8597-D55E2B826B84}) (Version: 3.2.21 - Rosetta Stone Ltd.)
    Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
    Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
    Skype Toolbars (HKLM-x32\...\{981029E0-7FC9-4CF3-AB39-6F133621921A}) (Version: 1.0.4051 - Skype Technologies S.A.)
    Skype™ 4.2 (HKLM-x32\...\{D103C4BA-F905-437A-8049-DB24763BBE36}) (Version: 4.2.169 - Skype Technologies S.A.)
    Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.15.0 - Synaptics Incorporated)
    TrustedID (HKLM-x32\...\{C16A92EF-017B-4839-9C75-FBADB5A1FA27}) (Version: 5.0 - TrustedID)
    Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
    Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
    VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Restore Points =========================

    14-06-2015 00:54:59 Installed Rosetta Stone Ltd Services
    14-06-2015 00:56:31 Installed Rosetta Stone Language Training
    16-06-2015 23:05:09 Installed DirectX
    22-06-2015 15:37:22 Windows Update

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {088EE105-C39C-451B-A6E7-0B76090F4E62} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-26] (Google Inc.)
    Task: {10E459BA-D937-45CC-B12A-34DB72F1BE09} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-07] (Microsoft Corporation)
    Task: {1193EEBE-8FBC-4EEE-BA72-AFF0F5E816AE} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell Support Center\uaclauncher.exe [2011-03-22] (PC-Doctor, Inc.)
    Task: {352693A6-079E-489A-A90F-62D68986D396} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation)
    Task: {38B83F76-F7AA-43B7-A4E7-3C8EC8F93D51} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
    Task: {3C5A9329-010F-4DB0-B35C-35FBA8618643} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
    Task: {4F086C79-1559-4AA4-B797-E56AD7D6D855} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-26] (Google Inc.)
    Task: {88E53664-24D3-46B0-9680-B61029751D8E} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
    Task: {A9F48BD3-93F9-4FBC-ABDB-90F3C4F27BAC} - System32\Tasks\SystemToolsDailyTest => C:\Program Files\Dell Support Center\pcdrcui.exe [2011-03-22] (PC-Doctor, Inc.)
    Task: {BC92351B-0726-45D8-B53A-CAEBFEE69447} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
    Task: {EBA38D0C-8351-4B58-B1AF-3F39CA3A35FD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
    Task: {EEF4E370-8203-40C0-99BF-9753A5A0AFCA} - System32\Tasks\PCDEventLauncher => C:\Program Files\Dell Support Center\sessionchecker.exe [2011-03-22] (PC-Doctor, Inc.)
    Task: {F8335B72-C881-465D-ADC0-D0254CC548F3} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-07] (Microsoft Corporation)
    Task: {F88F11BD-50E4-4D3B-B471-35FB0E66FC91} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
    Task: {F9392C54-9B3B-42F4-B7D9-3C70AC5C97C2} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2015-05-26] (Microsoft Corporation)
    Task: {FAE98564-FD3F-4EC8-A0C1-B1E32B30BFF2} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job => C:\Program Files\Dell Support Center\uaclauncher.exeo-backgroundmon scripts\defaultscan.xml
    Task: C:\Windows\Tasks\SystemToolsDailyTest.job => C:\Program Files\Dell Support Center\pcdrcui.exe

    ==================== Loaded Modules (Whitelisted) ==============

    2010-12-17 14:53 - 2010-12-17 14:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
    2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2011-09-10 20:45 - 2011-07-08 11:12 - 02749248 _____ () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
    2011-09-10 21:40 - 2011-03-07 16:07 - 00094208 _____ () C:\WINDOWS\System32\IccLibDll_x64.dll
    2011-09-10 20:31 - 2010-12-17 11:25 - 00686704 _____ () C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
    2010-12-17 14:53 - 2010-12-17 14:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
    2010-11-17 11:35 - 2010-11-17 11:35 - 00514544 _____ () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
    2010-11-24 23:44 - 2010-11-24 23:44 - 00375280 _____ () c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
    2015-06-22 17:38 - 2015-06-20 01:46 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libglesv2.dll
    2015-06-22 17:38 - 2015-06-20 01:46 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libegl.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1613421670-3433999689-4052708816-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kendra\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.2.1

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{12C6616A-E316-4989-BCFA-A1CB4B5E0689}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    FirewallRules: [{DAD91514-4E94-4161-9063-AB46A2B52AD9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    FirewallRules: [{34979C31-0CD9-428E-9B38-BC60A1582091}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    FirewallRules: [{1FB8C1E9-1027-4ED5-9C73-3B8C4A48C4A5}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
    FirewallRules: [{F149D086-2844-4AE5-BF45-A49FD717D897}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{B3B3C638-FBE4-4F1F-A1AA-67308C614887}] => (Allow) c:\Program Files (x86)\Dell\VideoStage\VideoStage.exe
    FirewallRules: [{28134051-99AA-4FE2-8DA7-8FC6CAE0A64A}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{595C6D96-7DC1-427B-8110-620DB68AAD99}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{CD3BF246-1A02-42FC-8851-8D73EA0A855B}] => (Allow) C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe
    FirewallRules: [{E090DCA2-E696-4818-8E7B-02B478BD17B8}] => (Allow) C:\Program Files\dell stage\musicstage\musicstageengine.exe
    FirewallRules: [{0EC6CAE2-769A-45E9-B11D-40D9794F11BB}] => (Allow) C:\Program Files\dell stage\dell stage\stage_primary.exe
    FirewallRules: [{94D23466-9464-4194-AFA8-CACD22E5E068}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
    FirewallRules: [{AD114F8D-F118-4D32-82A1-43E5730FC7B5}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
    FirewallRules: [{083CCC10-71C6-4F93-BC35-308D3EB50C79}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{04986DE6-5B9A-49C2-B089-CDB6D5076ADA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{28C94C12-E0FB-4BDB-BEE8-48FEB989C67B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{AE1BE738-C07E-4F20-B56D-D29BD7B8AE11}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{224EF786-2BB3-4643-B94E-DDA992872B73}] => (Allow) C:\Program Files\iTunes\iTunes.exe
    FirewallRules: [{887DFAA1-68D1-427A-8DAB-CD25073A8FEC}] => (Allow) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneLtdServices.exe
    FirewallRules: [{9F055BD4-308E-4ED6-B7BC-CBEA6B76FF59}] => (Allow) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneLtdServices.exe
    FirewallRules: [{918A073D-C1E7-4560-92A7-54715C33EBA2}] => (Allow) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
    FirewallRules: [{CE26D0FE-CECA-47EF-A496-BD09F238E027}] => (Allow) C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
    FirewallRules: [TCP Query User{0CDC48A0-EC69-473B-BE78-2D3378A91D07}C:\users\kendra\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\kendra\appdata\local\akamai\netsession_win.exe
    FirewallRules: [UDP Query User{CAC0E60F-F614-4B95-8757-38070BB8CAAD}C:\users\kendra\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\kendra\appdata\local\akamai\netsession_win.exe
    FirewallRules: [{A747105C-1502-48F3-B315-C9F2870D763A}] => (Allow) C:\Program Files (x86)\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe
    FirewallRules: [{423A6558-642F-48BF-A9CD-A72D76C21B42}] => (Allow) C:\Program Files (x86)\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe
    FirewallRules: [{12FE46F2-7FDE-490E-AE32-E22D1A92750C}] => (Allow) C:\Program Files (x86)\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivlauncher.exe
    FirewallRules: [{19025089-2636-41BC-B419-806AE5007C48}] => (Allow) C:\Program Files (x86)\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivlauncher.exe
    FirewallRules: [{B19AE9E9-B216-43ED-8377-8BA87F7D9AB2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{F230F873-5810-40A9-BEA9-2022841F06F6}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
    FirewallRules: [{17EED99C-8D64-4DFB-96E5-B930A8B4B759}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
    FirewallRules: [{201DBACB-2C2A-44A8-9E84-6A5795424AD0}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
    FirewallRules: [{782FA73B-FAAF-4770-AF87-E4D838E9EF19}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
    FirewallRules: [{E79716A4-1454-40A9-826F-ADEC051E0FFD}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
    FirewallRules: [{78E6B33E-68B9-4193-8AD8-31C5CC2DCB15}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (06/24/2015 02:10:57 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program FRST64.exe version 21.6.2015.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 98

    Start Time: 01d0aea8f0def36b

    Termination Time: 8

    Application Path: C:\Users\Kendra\Desktop\FRST64.exe

    Report Id:

    Error: (06/22/2015 11:24:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/22/2015 11:07:07 PM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY)
    Description: Chrome has encountered a fatal error.
    ver=43.0.2357.130;lang=;guid=E621758208DE497DAD3899491511DFB6;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\8fa7081c-e11a-4890-ac67-4468556f06a7.dmp

    Error: (06/22/2015 08:48:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 3011

    Error: (06/22/2015 08:48:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 3011

    Error: (06/22/2015 08:48:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (06/22/2015 08:48:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 2012

    Error: (06/22/2015 08:48:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 2012

    Error: (06/22/2015 08:48:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (06/22/2015 08:48:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1014


    System errors:
    =============
    Error: (06/24/2015 01:54:47 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk2\DR2.

    Error: (06/23/2015 01:57:47 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk2\DR2.

    Error: (06/22/2015 11:25:14 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

    Error: (06/22/2015 11:24:44 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

    Error: (06/22/2015 11:23:59 PM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 11:22:42 PM on ‎22/‎06/‎2015 was unexpected.

    Error: (06/22/2015 11:21:21 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WSearch service.

    Error: (06/22/2015 05:02:05 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

    Error: (06/22/2015 03:37:29 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SftService service.

    Error: (06/22/2015 01:38:46 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk2\DR2.

    Error: (06/22/2015 00:03:33 PM) (Source: Disk) (EventID: 11) (User: )
    Description: The driver detected a controller error on \Device\Harddisk2\DR2.


    Microsoft Office:
    =========================
    Error: (06/24/2015 02:10:57 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: FRST64.exe21.6.2015.19801d0aea8f0def36b8C:\Users\Kendra\Desktop\FRST64.exe

    Error: (06/22/2015 11:24:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/22/2015 11:07:07 PM) (Source: Chrome) (EventID: 1) (User: NT AUTHORITY)
    Description: Chrome has encountered a fatal error.
    ver=43.0.2357.130;lang=;guid=E621758208DE497DAD3899491511DFB6;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\8fa7081c-e11a-4890-ac67-4468556f06a7.dmp

    Error: (06/22/2015 08:48:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 3011

    Error: (06/22/2015 08:48:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 3011

    Error: (06/22/2015 08:48:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (06/22/2015 08:48:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 2012

    Error: (06/22/2015 08:48:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 2012

    Error: (06/22/2015 08:48:34 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (06/22/2015 08:48:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 1014


    CodeIntegrity Errors:
    ===================================
      Date: 2015-05-27 11:54:56.080
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2015-05-27 11:54:56.080
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2015-05-26 17:52:05.301
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2015-05-26 17:52:05.301
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2015-05-26 17:50:35.670
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2015-05-26 17:50:35.670
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\WINDOWS\System32\drivers\wdcsam64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


    ==================== Memory info ===========================

    Processor: Intel® Core™ i7-2630QM CPU @ 2.00GHz
    Percentage of memory in use: 43%
    Total physical RAM: 6038.17 MB
    Available physical RAM: 3420.9 MB
    Total Pagefile: 12074.54 MB
    Available Pagefile: 9110.72 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.83 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:446.13 GB) (Free:320.94 GB) NTFS
    Drive d: () (Fixed) (Total:465.76 GB) (Free:443.55 GB) NTFS
    Drive f: (KENDRA'S BA) (Fixed) (Total:930.93 GB) (Free:843.35 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 07F2837E)
    Partition 1: (Not Active) - (Size=102 MB) - (Type=DE)
    Partition 2: (Active) - (Size=19.5 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=446.1 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 43AF5E37)
    Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 2 (Size: 931.5 GB) (Disk ID: 67A9A9CC)

    Partition: GPT Partition Type.
    Partition 2: (Not Active) - (Size=931.2 GB) - (Type=0B)

    ==================== End of log ============================


    Edited by jeff matthews, 24 June 2015 - 01:38 PM.


    #4 ken545

    ken545

      Forum God

    • Retired Classroom Teacher
    • 23,225 posts
    • Interests:Fighting Malware and cooking some great Italian and TexMex food
    • MVP

    Posted 24 June 2015 - 02:33 PM

    Your logs look fine, nothing bad that I can see

     

    http://www.herdprote...2e4c57567f.aspx



     
     
    The forum is staffed by volunteers who donate their time and expertise.
    If you feel you have been helped, please consider a donation.
    donate.gif
     
    Find us on Facebook
    Please LIKE and SHARE
     
     
    Just a reminder that threads will be closed if no reply in 3 days.

    #5 jeff matthews

    jeff matthews

      Advanced Member

    • Authentic Member
    • PipPipPipPip
    • 781 posts

    Posted 24 June 2015 - 03:01 PM

    hmm so your saying its read as a "false positive" cause this has been a file that i have gotten repeatedly and if you google this Collected_c.BEIS. It is a pretty notorious and dangerous infection according to several sources ive read.

     

     

     

    http://blog.doohelp....protect-the-pc/

     

     

    Should i try any other fine tune scans like Kapsersky or something or are you pretty sure there is absolutely nothing in those logs.


    Edited by jeff matthews, 24 June 2015 - 03:08 PM.


    #6 ken545

    ken545

      Forum God

    • Retired Classroom Teacher
    • 23,225 posts
    • Interests:Fighting Malware and cooking some great Italian and TexMex food
    • MVP

    Posted 24 June 2015 - 03:08 PM

    It is bad but it looks like its not related to Dell backup.

     

    You have AVG antivirus, open it, check for updates and run a full system scan and see if it finds it

     

    Then run a free online virus scanner

     

    ESET Online Scanner
    I'd like us to scan your machine with ESET OnlineScan
     
    *Note
    It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
    Please don't go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
     
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
  • Click the esetOnline.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetSmartInstallDesktopIcon.png icon on your desktop.
  • Check esetAcceptTerms.png
  • Click the esetStart.png button.
  • Accept any security warnings from your browser.
  • Check esetScanArchives.png
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
  • scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push esetListThreats.png
  • Push esetExport.png, and save the file to your desktop using a unique name, such as
  • ESETScan. Include the contents of this report in your next reply.
  • Push the esetBack.png button.
  • Push esetFinish.png
  • Please make sure you include the following items in your next post:
    The log that was produced after running ESET Online Scanner.


     
     
    The forum is staffed by volunteers who donate their time and expertise.
    If you feel you have been helped, please consider a donation.
    donate.gif
     
    Find us on Facebook
    Please LIKE and SHARE
     
     
    Just a reminder that threads will be closed if no reply in 3 days.

    #7 jeff matthews

    jeff matthews

      Advanced Member

    • Authentic Member
    • PipPipPipPip
    • 781 posts

    Posted 24 June 2015 - 03:14 PM

    Well yeah i didn't think it was related to DELL Back up, it might just be using DELL back as an invulnerability loop hole or like when a virus uses Java to spread it self. I am surprised Fubar didn't pick up anything though if its bad and still exist on the computer.

     

    But i'll take care of these scans.



    #8 ken545

    ken545

      Forum God

    • Retired Classroom Teacher
    • 23,225 posts
    • Interests:Fighting Malware and cooking some great Italian and TexMex food
    • MVP

    Posted 24 June 2015 - 03:29 PM

    You have Malwarebytes installed also, open it , check for updates and run the Threat scan and see if it finds anything

     

    Another thing you can do is go to Dell backup and delete it all, it will remove all backups, then just do a new backup and see if that problem went away

     

    http://www.dell.com/...8990/EN#Issue14



     
     
    The forum is staffed by volunteers who donate their time and expertise.
    If you feel you have been helped, please consider a donation.
    donate.gif
     
    Find us on Facebook
    Please LIKE and SHARE
     
     
    Just a reminder that threads will be closed if no reply in 3 days.

    #9 jeff matthews

    jeff matthews

      Advanced Member

    • Authentic Member
    • PipPipPipPip
    • 781 posts

    Posted 24 June 2015 - 04:40 PM

    If its bad, how come Fubar didn't find anything? Are you saying it might be like dormant or something, or like the file is in a Antivirus Vault. Or is it active on the computer. The machine still runs quite slow.


    Edited by jeff matthews, 24 June 2015 - 04:41 PM.


    #10 ken545

    ken545

      Forum God

    • Retired Classroom Teacher
    • 23,225 posts
    • Interests:Fighting Malware and cooking some great Italian and TexMex food
    • MVP

    Posted 24 June 2015 - 08:04 PM

    Most likely a false positive. If that threat was present one of our tools would have found it , lets see what the AV scans find



     
     
    The forum is staffed by volunteers who donate their time and expertise.
    If you feel you have been helped, please consider a donation.
    donate.gif
     
    Find us on Facebook
    Please LIKE and SHARE
     
     
    Just a reminder that threads will be closed if no reply in 3 days.

      Advertisements

    Register to Remove


    #11 jeff matthews

    jeff matthews

      Advanced Member

    • Authentic Member
    • PipPipPipPip
    • 781 posts

    Posted 24 June 2015 - 08:25 PM

    Found nothing in ESET, found nothing on AVG and also found Nothing on maleware. I think its safe to say this computer is just not infected i guess. The computer still runs to slow though, what the heck



    #12 jeff matthews

    jeff matthews

      Advanced Member

    • Authentic Member
    • PipPipPipPip
    • 781 posts

    Posted 24 June 2015 - 08:47 PM

    Ok, so provide me some instructions on how to set up a restore point or a registry back-up to prevent my self from being re-infected if in the future i manage to copy the virus over to my machine by some unknown application or program that i have backed up.

     

    Also i am not a fan of Erunt. I don't like how the program stays locked into your system and even removing it from the programs list does not completely get rid of it and you end up with a failed box during start-up every time that you have to close.


    Edited by jeff matthews, 24 June 2015 - 08:48 PM.


    #13 ken545

    ken545

      Forum God

    • Retired Classroom Teacher
    • 23,225 posts
    • Interests:Fighting Malware and cooking some great Italian and TexMex food
    • MVP

    Posted 25 June 2015 - 05:22 AM

    You have some controller errors  that have to do with your hard drive

     

    FreeCodecPack  

    https://safeweb.nort...eecodecpack.com

     

     System Restore

    http://windows.micro.../system-restore

     

     

    Backup the Registry:
     
    Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.
     
    •  
    • Please download the installer for Registry Backup from here or here and save to your desktop.
    • Right-click on tweaking.com_registry_backup_setup.exe and select Run as Administrator >> Follow the prompts for a default installation
    • Ensure the option Open "Tweaking.com - Registry Backup"  When Install Completes is selected >> Next >  >> Finish
    • Once the GUI(graphical user interface) has appeared/loaded:-
     
    TCRB-1.jpg
     
    •  
    • Click on Backup Now >> once the process is complete the below will be displayed in the GUI:-
     
    TBRB-2.jpg
     
    •  
    • Close Tweaking.com - Registry Backup
     
    Note: There will now be a folder at the root of the Hard-Drive named C:\RegBackup, do not delete this as it is the actual backup just created.
     
    A tutorial for Registry Backup explaining the various features be viewed HERE
     
     
     
    I think what you should do is post in our windows forum for help, you can link them to this thread if you wish so that they can look at the logs and see that its not malware, a lot of people post with slow computers thinking that they must be infected and that's not always the case. Slow computers can be a mixture or lots of things, outdated drivers, two programs bumping heads. A few months back I installed ZoneAlarm firewall on my system it it really slowed it down, uninstalling it brought my system back to normal, but we just do malware removal in this forum so post in our windows forum and let the techs take a look
     
     
     

    Double click on AdwCleaner.exe to run the tool again.
    •  
    • Click on the Uninstall button.
    • Click Yes when asked are you sure you want to uninstall.
    • Both AdwCleaner.exe, its folder and all logs will be removed.
     
     
     
    ==========================================================
     
     
    Please download DelFix and save the file to your Desktop.
     
    DelFix_zps139e2ea1.jpg
     
    •  
    • Windows XP Double Click DelFix.exe to run the program. 
    • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
    • Checkmark " Remove Disinfection Tools"
    • Click the Run button
     
     
    This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
     
     
     
    ==========================================================
     
     
     
    •  
    How did I get infected in the first place ?
     
     
     
     
    Safe Surfn
    Ken
     


     
     
    The forum is staffed by volunteers who donate their time and expertise.
    If you feel you have been helped, please consider a donation.
    donate.gif
     
    Find us on Facebook
    Please LIKE and SHARE
     
     
    Just a reminder that threads will be closed if no reply in 3 days.

    #14 jeff matthews

    jeff matthews

      Advanced Member

    • Authentic Member
    • PipPipPipPip
    • 781 posts

    Posted 25 June 2015 - 05:31 PM

    Wait a min, are you saying i have this Freecodecpack? I should remove that then? How would i fix the Controller errors?



    #15 ken545

    ken545

      Forum God

    • Retired Classroom Teacher
    • 23,225 posts
    • Interests:Fighting Malware and cooking some great Italian and TexMex food
    • MVP

    Posted 25 June 2015 - 06:15 PM

    Freecodecpack could be responsible for some of the problems your having, I would uninstall it

     

     

    As far as controller errors

     

     

    I think what you should do is post in our windows forum for help, you can link them to this thread if you wish so that they can look at the logs and see that its not malware, a lot of people post with slow computers thinking that they must be infected and that's not always the case. Slow computers can be a mixture or lots of things, outdated drivers, two programs bumping heads. A few months back I installed ZoneAlarm firewall on my system it it really slowed it down, uninstalling it brought my system back to normal, but we just do malware removal in this forum so post in our windows forum and let the techs take a look
     

     

     



     
     
    The forum is staffed by volunteers who donate their time and expertise.
    If you feel you have been helped, please consider a donation.
    donate.gif
     
    Find us on Facebook
    Please LIKE and SHARE
     
     
    Just a reminder that threads will be closed if no reply in 3 days.

    Related Topics




    Also tagged with one or more of these keywords: Maleware, Trojan, Infection, Virus, Dangerious, Lethal, AVG

    2 user(s) are reading this topic

    0 members, 2 guests, 0 anonymous users