TechSpot

Is this a virus or am I just being paranoid?

By okedokeloke
Jun 4, 2015
  1. So I am browsing the internet on Chrome, and heard a windows signature click sound, the kind of click that you hear when you open a file. It was out of nowhere, and I believe Google Chrome does not use such sounds. Do I have a virus? Or am I just being paranoid of the clicks?
     
  2. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Welcome aboard [​IMG]

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
     
  3. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    FRST:

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:03-06-2015
    Ran by Loke (administrator) on LOKE-PC on 05-06-2015 14:47:22
    Running from C:\Users\Loke\Desktop
    Loaded Profiles: UpdatusUser & Loke (Available Profiles: UpdatusUser & Loke)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
    (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    (McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
    (Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McUICnt.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    (CyberLink) C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (McAfee, Inc.) C:\Program Files\mcafee\msm\McSmtFwk.exe
    (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
    (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcupdate.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13353064 2011-11-14] (Realtek Semiconductor)
    HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
    HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-05] (Intel Corporation)
    HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
    HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-06-22] (Egis Technology Inc.)
    HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-07] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [636520 2012-02-07] ()
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
    HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
    Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
    HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2892992 2015-06-05] (Valve Corporation)
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3095840 2015-04-30] (Nota Inc.)
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [456224 2010-07-29] ()
    HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
    URLSearchHook: HKU\S-1-5-21-79519641-1766234843-2241692891-1001 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    URLSearchHook: HKU\S-1-5-21-79519641-1766234843-2241692891-1001 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
    SearchScopes: HKU\S-1-5-21-79519641-1766234843-2241692891-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
    BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-07] (Adobe Systems Incorporated)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
    BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-08] (Microsoft Corporation.)
    Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-08] (Microsoft Corporation.)
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-05-25] (McAfee, Inc.)
    Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-05-25] (McAfee, Inc.)
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-05-25] (McAfee, Inc.)
    Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-05-25] (McAfee, Inc.)
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2014-04-25] (McAfee, Inc.)
    Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

    FireFox:
    ========
    FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-05-09] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-05-09] (NVIDIA Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-03] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-03] (Google Inc.)
    FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-08] ()
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-07] (Adobe Systems Inc.)
    FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
    FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-03-07]
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2012-03-07]

    Chrome:
    =======
    CHR Profile: C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2
    CHR Extension: (Google Slides) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-03]
    CHR Extension: (Google Docs) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-03]
    CHR Extension: (Google Drive) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-03]
    CHR Extension: (YouTube) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-03]
    CHR Extension: (Google Search) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-03]
    CHR Extension: (Google Sheets) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-03]
    CHR Extension: (SiteAdvisor) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-06-03]
    CHR Extension: (Bookmark Manager) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-06-03]
    CHR Extension: (ThemeBeta.com) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\kjpmndbpafificoploalfendmlmgfpjo [2015-06-03]
    CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-03]
    CHR Extension: (Google Wallet) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-03]
    CHR Extension: (Gmail) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-03]
    CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-06-03]
    CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-06-03]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] ()
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
    R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [155368 2015-05-25] (McAfee, Inc.)
    R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
    S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [225216 2011-01-29] (McAfee, Inc.)
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-10-08] (McAfee, Inc.)
    S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
    R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
    R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
    R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
    R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
    R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
    R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
    R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
    R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
    R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
     
  4. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    FRST (continued):


    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-06-05 14:47 - 2015-06-05 14:48 - 00020992 _____ C:\Users\Loke\Desktop\FRST.txt
    2015-06-05 14:46 - 2015-06-05 14:47 - 00000000 ____D C:\FRST
    2015-06-05 14:46 - 2015-06-05 14:46 - 02108928 _____ (Farbar) C:\Users\Loke\Desktop\FRST64.exe
    2015-06-05 14:12 - 2015-06-05 14:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
    2015-06-05 01:53 - 2014-06-27 10:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
    2015-06-05 01:53 - 2014-06-27 09:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
    2015-06-04 18:23 - 2015-06-04 18:23 - 00000000 ____D C:\Users\Loke\Documents\My Games
    2015-06-04 18:23 - 2015-06-04 18:23 - 00000000 ____D C:\Users\Loke\AppData\Local\My Games
    2015-06-04 17:44 - 2015-06-04 17:44 - 00000220 _____ C:\Users\Loke\Desktop\Sid Meier's Civilization V.url
    2015-06-04 17:34 - 2015-06-04 17:34 - 00002160 _____ C:\Users\Loke\Desktop\Google Earth.lnk
    2015-06-04 17:32 - 2015-06-04 17:32 - 00002160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
    2015-06-04 16:55 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
    2015-06-04 14:45 - 2015-04-22 00:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-06-04 14:36 - 2015-06-04 15:11 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2015-06-04 14:36 - 2015-06-04 14:39 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2015-06-04 14:36 - 2015-06-04 14:36 - 00001395 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    2015-06-04 14:36 - 2015-06-04 14:36 - 00001383 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2015-06-04 14:36 - 2015-06-04 14:36 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
    2015-06-04 14:36 - 2015-06-04 14:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    2015-06-04 14:36 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
    2015-06-04 11:53 - 2015-06-04 11:53 - 00000000 ____D C:\Users\Loke\Documents\Fax
    2015-06-04 11:42 - 2014-07-09 10:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
    2015-06-04 11:42 - 2014-07-09 10:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
    2015-06-04 11:42 - 2014-07-09 10:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
    2015-06-04 11:42 - 2014-07-09 10:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
    2015-06-04 11:42 - 2014-07-09 10:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
    2015-06-04 11:42 - 2014-06-24 11:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
    2015-06-04 11:42 - 2014-06-24 10:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
    2015-06-04 11:42 - 2013-11-26 16:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
    2015-06-04 11:42 - 2013-11-23 06:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
    2015-06-04 11:41 - 2012-02-11 14:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
    2015-06-04 11:41 - 2012-02-11 14:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
    2015-06-04 08:23 - 2015-05-05 09:29 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-06-04 08:23 - 2015-05-05 09:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-06-04 08:23 - 2015-04-20 11:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2015-06-04 08:23 - 2015-04-20 11:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2015-06-04 08:23 - 2015-04-20 10:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2015-06-04 08:23 - 2015-04-18 11:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
    2015-06-04 08:23 - 2015-04-18 10:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
    2015-06-04 08:23 - 2015-04-04 11:29 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-06-04 08:23 - 2015-04-04 11:29 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-06-04 08:23 - 2015-04-04 11:22 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-06-04 08:23 - 2015-04-04 11:22 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-06-04 08:23 - 2015-04-04 11:20 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-06-04 08:23 - 2015-04-04 11:20 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-06-04 08:23 - 2015-04-04 11:17 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-06-04 08:23 - 2015-04-04 11:17 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-06-04 08:23 - 2015-04-04 11:15 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-06-04 08:23 - 2015-04-04 11:05 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-06-04 08:23 - 2015-04-04 11:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-06-04 08:23 - 2015-04-04 11:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-06-04 08:23 - 2015-04-04 11:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-06-04 08:23 - 2015-04-04 11:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-06-04 08:23 - 2015-04-04 11:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-06-04 08:23 - 2015-04-04 11:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-06-04 08:23 - 2015-04-04 11:04 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-06-04 08:23 - 2015-04-04 11:04 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-06-04 08:23 - 2015-04-04 11:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-06-04 08:23 - 2015-04-04 11:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-06-04 08:23 - 2015-04-04 10:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-06-04 08:19 - 2015-02-04 11:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
    2015-06-04 08:19 - 2015-02-04 10:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
    2015-06-04 08:19 - 2015-02-03 11:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2015-06-04 08:19 - 2015-02-03 11:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2015-06-04 02:30 - 2015-01-09 07:44 - 00419936 _____ C:\Windows\SysWOW64\locale.nls
    2015-06-04 02:30 - 2015-01-09 07:43 - 00419936 _____ C:\Windows\system32\locale.nls
    2015-06-04 02:22 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
    2015-06-04 02:14 - 2015-06-04 02:14 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-06-04 02:13 - 2015-06-04 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-06-04 02:13 - 2015-06-04 02:13 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-06-04 02:13 - 2015-06-04 02:13 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-06-04 02:13 - 2015-06-04 02:13 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
    2015-06-04 02:13 - 2015-06-04 02:13 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
    2015-06-04 02:13 - 2015-06-04 02:13 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-06-04 02:13 - 2015-06-04 02:13 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-06-04 02:13 - 2015-06-04 02:13 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
    2015-06-04 02:13 - 2015-06-04 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
    2015-06-04 02:13 - 2015-06-04 02:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
    2015-06-04 02:04 - 2015-06-04 02:23 - 00009859 _____ C:\Windows\IE11_main.log
    2015-06-04 01:41 - 2015-06-04 01:46 - 00000000 ____D C:\Windows\system32\MRT
    2015-06-04 01:41 - 2015-04-30 10:07 - 140425016 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-06-04 01:40 - 2015-06-04 01:40 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
    2015-06-04 01:23 - 2015-01-09 11:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
    2015-06-04 01:23 - 2015-01-09 11:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
    2015-06-04 01:23 - 2015-01-09 11:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
    2015-06-04 01:23 - 2015-01-09 10:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
    2015-06-04 01:09 - 2015-06-04 01:09 - 00000000 ___SD C:\Windows\system32\CompatTel
    2015-06-04 01:09 - 2015-06-04 01:09 - 00000000 ____D C:\Windows\system32\appraiser
    2015-06-04 00:39 - 2015-06-04 01:40 - 00284224 _____ C:\Windows\msxml4-KB973688-enu.LOG
    2015-06-04 00:14 - 2015-06-04 01:40 - 00288320 _____ C:\Windows\msxml4-KB954430-enu.LOG
    2015-06-04 00:13 - 2015-06-04 00:13 - 00000419 _____ C:\Windows\BRWMARK.INI
    2015-06-03 23:58 - 2012-07-26 11:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
    2015-06-03 23:58 - 2012-07-26 11:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
    2015-06-03 23:58 - 2012-07-26 11:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
    2015-06-03 23:58 - 2012-07-26 11:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
    2015-06-03 23:58 - 2012-07-26 11:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
    2015-06-03 23:58 - 2012-07-26 10:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
    2015-06-03 23:58 - 2012-07-26 10:26 - 00087040 _____ (Microsoft Corporation)
     
  5. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    FRST (continued):


    2015-06-03 23:58 - 2012-06-02 22:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
    2015-06-03 23:55 - 2015-05-01 21:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-06-03 23:55 - 2015-05-01 21:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-06-03 23:53 - 2015-06-03 23:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2015-06-03 23:52 - 2015-06-03 23:52 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2015-06-03 23:52 - 2015-06-03 23:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2015-06-03 23:52 - 2012-03-01 14:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
    2015-06-03 23:52 - 2012-03-01 14:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
    2015-06-03 23:52 - 2012-03-01 13:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
    2015-06-03 23:46 - 2014-07-01 06:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
    2015-06-03 23:46 - 2014-07-01 06:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
    2015-06-03 23:46 - 2014-06-06 14:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
    2015-06-03 23:46 - 2014-06-06 14:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
    2015-06-03 23:46 - 2014-03-10 05:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
    2015-06-03 23:46 - 2014-03-10 05:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
    2015-06-03 23:46 - 2014-03-10 05:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
    2015-06-03 23:46 - 2014-03-10 05:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
    2015-06-03 23:45 - 2014-07-17 10:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
    2015-06-03 23:45 - 2014-07-17 10:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
    2015-06-03 23:45 - 2014-07-17 10:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
    2015-06-03 23:45 - 2014-07-17 10:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
    2015-06-03 23:45 - 2014-07-17 09:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
    2015-06-03 23:45 - 2014-07-17 09:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
    2015-06-03 23:45 - 2014-07-17 09:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
    2015-06-03 23:45 - 2014-07-17 09:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
    2015-06-03 23:45 - 2012-04-26 13:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
    2015-06-03 23:45 - 2012-04-26 13:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
    2015-06-03 23:44 - 2014-03-04 17:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
    2015-06-03 23:44 - 2014-03-04 17:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
    2015-06-03 23:44 - 2013-10-04 10:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
    2015-06-03 23:44 - 2013-10-04 10:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
    2015-06-03 23:44 - 2013-10-04 09:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
    2015-06-03 23:44 - 2013-10-04 09:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
    2015-06-03 23:44 - 2013-02-15 14:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
    2015-06-03 23:44 - 2013-02-15 14:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
    2015-06-03 23:44 - 2013-02-15 11:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
    2015-06-03 23:43 - 2015-02-03 11:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
    2015-06-03 23:43 - 2015-02-03 11:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
    2015-06-03 23:43 - 2015-02-03 11:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
    2015-06-03 23:43 - 2015-02-03 11:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
    2015-06-03 23:43 - 2015-02-03 11:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
    2015-06-03 23:43 - 2015-02-03 11:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
    2015-06-03 23:43 - 2015-02-03 11:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
    2015-06-03 23:43 - 2015-02-03 11:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
    2015-06-03 23:43 - 2015-02-03 11:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
    2015-06-03 23:43 - 2015-02-03 11:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
    2015-06-03 23:43 - 2015-02-03 11:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
    2015-06-03 23:43 - 2015-02-03 11:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
    2015-06-03 23:43 - 2015-02-03 11:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
    2015-06-03 23:43 - 2015-02-03 11:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
    2015-06-03 23:43 - 2015-02-03 11:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
    2015-06-03 23:43 - 2015-02-03 10:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
    2015-06-03 23:43 - 2014-11-01 06:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
    2015-06-03 23:43 - 2014-06-28 08:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
    2015-06-03 23:43 - 2014-06-28 08:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
    2015-06-03 23:43 - 2014-03-04 17:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
    2015-06-03 23:42 - 2015-03-17 13:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-06-03 23:42 - 2015-03-17 13:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-06-03 23:42 - 2015-03-17 13:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2015-06-03 23:42 - 2015-03-17 13:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2015-06-03 23:42 - 2015-03-17 13:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2015-06-03 23:42 - 2015-03-17 13:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2015-06-03 23:42 - 2015-03-17 13:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-06-03 23:42 - 2015-03-17 13:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2015-06-03 23:42 - 2015-03-17 13:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-06-03 23:42 - 2015-03-17 13:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2015-06-03 23:42 - 2015-03-17 13:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-06-03 23:42 - 2015-03-17 13:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-06-03 23:42 - 2015-03-17 13:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-06-03 23:42 - 2015-03-17 13:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2015-06-03 23:42 - 2015-03-17 13:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2015-06-03 23:42 - 2015-03-17 13:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 13:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-06-03 23:42 - 2015-03-17 13:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-06-03 23:42 - 2015-03-17 12:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2015-06-03 23:42 - 2015-03-17 12:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-06-03 23:42 - 2015-03-17 12:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2015-06-03 23:42 - 2015-03-17 12:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2015-06-03 23:42 - 2015-03-17 12:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2015-06-03 23:42 - 2015-03-17 12:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2015-06-03 23:42 - 2015-03-17 12:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 12:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 11:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2015-06-03 23:42 - 2015-03-17 11:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2015-06-03 23:42 - 2015-03-17 11:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 11:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 11:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2015-06-03 23:42 - 2015-03-17 11:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2015-06-03 23:42 - 2015-01-31 07:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
    2015-06-03 23:42 - 2014-10-14 10:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
    2015-06-03 23:42 - 2014-10-14 10:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
    2015-06-03 23:42 - 2014-10-14 09:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2015-06-03 23:42 - 2014-06-03 18:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
    2015-06-03 23:42 - 2014-06-03 18:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
    2015-06-03 23:42 - 2014-06-03 18:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
    2015-06-03 23:42 - 2014-06-03 17:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2015-06-03 23:42 - 2014-06-03 17:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
    2015-06-03 23:42 - 2013-02-27 13:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
    2015-06-03 23:41 - 2012-12-07 21:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
    2015-06-03 23:41 - 2012-12-07 21:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
    2015-06-03 23:41 - 2012-12-07 20:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
    2015-06-03 23:41 - 2012-12-07 20:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
    2015-06-03 23:41 - 2012-12-07 19:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
    2015-06-03 23:40 - 2015-06-03 23:40 - 00000690 _____ C:\Users\Loke\Desktop\profile.txt
    2015-06-03 23:40 - 2014-11-11 11:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
    2015-06-03 23:40 - 2014-11-11 10:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
    2015-06-03 23:39 - 2014-11-08 11:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2015-06-03 23:39 - 2014-11-08 10:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2015-06-03 23:38 - 2015-02-13 13:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2015-06-03 23:38 - 2015-02-13 13:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2015-06-03 23:38 - 2013-07-26 10:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
    2015-06-03 23:38 - 2013-07-26 09:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
    2015-06-03 23:38 - 2013-05-13 13:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
    2015-06-03 23:38 - 2013-05-13 11:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
    2015-06-03 23:38 - 2013-05-13 11:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
    2015-06-03 23:38 - 2013-05-13 11:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
    2015-06-03 23:38 - 2012-10-04 01:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
    2015-06-03 23:38 - 2012-10-04 01:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
    2015-06-03 23:38 - 2012-10-04 01:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
    2015-06-03 23:38 - 2012-10-04 01:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
    2015-06-03 23:38 - 2012-10-04 01:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
    2015-06-03 23:38 - 2012-10-04 00:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
    2015-06-03 23:38 - 2012-10-04 00:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
    2015-06-03 23:38 - 2012-10-04 00:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
    2015-06-03 23:38 - 2012-06-06 14:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
    2015-06-03 23:38 - 2012-06-06 13:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
    2015-06-03 23:37 - 2015-04-20 10:11 - 03204608 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-06-03 23:37 - 2015-04-13 11:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
    2015-06-03 23:37 - 2013-12-04 10:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
    2015-06-03 23:37 - 2013-12-04 10:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
    2015-06-03 23:37 - 2013-12-04 10:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
    2015-06-03 23:37 - 2013-12-04 10:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
    2015-06-03 23:37 - 2013-12-04 10:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
    2015-06-03 23:37 - 2013-12-04 10:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
    2015-06-03 23:37 - 2013-12-04 10:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
    2015-06-03 23:37 - 2013-12-04 10:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
    2015-06-03 23:37 - 2013-12-04 10:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
    2015-06-03 23:37 - 2013-12-04 10:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
    2015-06-03 23:37 - 2013-12-04 10:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
    2015-06-03 23:37 - 2013-12-04 10:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
    2015-06-03 23:37 - 2013-12-04 10:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
    2015-06-03 23:37 - 2013-12-04 10:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
    2015-06-03 23:37 - 2013-12-04 09:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
    2015-06-03 23:37 - 2013-12-04 09:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
    2015-06-03 23:37 - 2013-12-04 09:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
    2015-06-03 23:37 - 2013-12-04 09:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
    2015-06-03 23:37 - 2013-05-10 13:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
    2015-06-03 23:37 - 2013-05-10 11:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
    2015-06-03 23:36 - 2015-03-23 11:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2015-06-03 23:36 - 2015-03-23 11:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2015-06-03 23:36 - 2015-03-23 11:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2015-06-03 23:36 - 2015-03-23 11:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2015-06-03 23:36 - 2015-03-23 11:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2015-06-03 23:36 - 2015-03-23 11:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
    2015-06-03 23:36 - 2015-03-23 11:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2015-06-03 23:36 - 2015-03-23 11:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2015-06-03 23:36 - 2015-03-04 12:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-06-03 23:36 - 2015-03-04 12:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-06-03 23:36 - 2015-03-04 12:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-06-03 23:36 - 2015-03-04 12:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-06-03 23:36 - 2015-03-04 12:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
    2015-06-03 23:36 - 2015-03-04 12:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
    2015-06-03 23:36 - 2015-03-04 12:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
    2015-06-03 23:36 - 2015-01-28 07:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
    2015-06-03 23:36 - 2014-11-26 11:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
    2015-06-03 23:36 - 2014-11-26 11:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2015-06-03 23:36 - 2014-10-30 10:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
    2015-06-03 23:36 - 2014-10-30 09:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
    2015-06-03 23:36 - 2014-10-04 10:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2015-06-03 23:36 - 2014-10-04 09:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2015-06-03 23:36 - 2014-10-04 09:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
    2015-06-03 23:36 - 2014-08-12 10:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
    2015-06-03 23:36 - 2014-08-12 09:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
    2015-06-03 23:36 - 2014-06-19 06:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
    2015-06-03 23:36 - 2014-06-16 10:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
    2015-06-03 23:36 - 2013-08-05 10:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
    2015-06-03 23:36 - 2013-04-10 14:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
    2015-06-03 23:36 - 2012-10-10 02:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
    2015-06-03 23:36 - 2012-10-10 02:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
    2015-06-03 23:36 - 2012-10-10 01:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
    2015-06-03 23:36 - 2012-10-10 01:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
    2015-06-03 23:36 - 2012-08-22 05:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
    2015-06-03 23:36 - 2011-02-03 19:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
    2015-06-03 23:35 - 2015-04-08 11:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-06-03 23:35 - 2015-04-08 11:29 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-06-03 23:35 - 2015-04-08 11:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-06-03 23:35 - 2015-03-25 11:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-06-03 23:35 - 2015-03-25 11:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-06-03 23:35 - 2015-03-25 11:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-06-03 23:35 - 2015-03-25 11:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-06-03 23:35 - 2015-03-25 11:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-06-03 23:35 - 2015-03-25 11:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-06-03 23:35 - 2015-03-25 11:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-06-03 23:35 - 2015-03-25 11:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-06-03 23:35 - 2015-02-18 15:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
    2015-06-03 23:35 - 2015-02-18 15:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
    2015-06-03 23:35 - 2014-08-01 19:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
    2015-06-03 23:35 - 2014-08-01 19:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
    2015-06-03 23:35 - 2014-06-18 10:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
    2015-06-03 23:35 - 2014-06-18 09:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
    2015-06-03 23:35 - 2014-04-05 10:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
    2015-06-03 23:35 - 2014-04-05 10:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
    2015-06-03 23:35 - 2014-01-24 10:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
    2015-06-03 23:35 - 2013-11-26 19:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
    2015-06-03 23:35 - 2013-09-08 10:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
    2015-06-03 23:35 - 2013-09-08 10:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
    2015-06-03 23:35 - 2013-08-29 10:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
    2015-06-03 23:35 - 2013-08-29 10:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
    2015-06-03 23:35 - 2013-08-29 09:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
    2015-06-03 23:35 - 2013-08-29 09:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
    2015-06-03 23:35 - 2013-06-26 06:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
    2015-06-03 23:35 - 2013-04-26 07:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
    2015-06-03 23:35 - 2013-04-01 06:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
    2015-06-03 23:35 - 2012-11-29 06:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
    2015-06-03 23:35 - 2012-11-29 06:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
    2015-06-03 23:35 - 2012-11-29 06:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
    2015-06-03 23:34 - 2015-03-10 11:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
    2015-06-03 23:34 - 2015-03-10 11:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
    2015-06-03 23:34 - 2015-03-10 11:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2015-06-03 23:34 - 2015-03-10 11:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
    2015-06-03 23:34 - 2015-03-04 12:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
    2015-06-03 23:34 - 2015-03-04 12:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
    2015-06-03 23:34 - 2015-03-04 12:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
    2015-06-03 23:34 - 2015-02-20 12:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
    2015-06-03 23:34 - 2015-02-20 12:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
    2015-06-03 23:34 - 2015-02-20 12:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
    2015-06-03 23:34 - 2015-02-20 12:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
    2015-06-03 23:34 - 2015-02-20 12:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
    2015-06-03 23:34 - 2015-02-20 12:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2015-06-03 23:34 - 2015-02-20 12:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
    2015-06-03 23:34 - 2015-02-20 12:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
    2015-06-03 23:34 - 2015-02-20 11:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
    2015-06-03 23:34 - 2015-02-20 11:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2015-06-03 23:34 - 2015-02-03 11:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
    2015-06-03 23:34 - 2015-02-03 11:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
    2015-06-03 23:34 - 2015-01-29 11:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
    2015-06-03 23:34 - 2015-01-29 11:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
    2015-06-03 23:34 - 2014-12-19 09:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
    2015-06-03 23:34 - 2014-12-12 01:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
    2015-06-03 23:34 - 2014-12-06 12:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
    2015-06-03 23:34 - 2014-12-06 11:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
    2015-06-03 23:34 - 2014-12-06 11:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
    2015-06-03 23:34 - 2014-10-03 10:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
    2015-06-03 23:34 - 2014-10-03 10:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
    2015-06-03 23:34 - 2014-10-03 10:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
    2015-06-03 23:34 - 2014-10-03 10:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
    2015-06-03 23:34 - 2014-10-03 10:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
    2015-06-03 23:34 - 2014-10-03 09:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
    2015-06-03 23:34 - 2014-10-03 09:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
    2015-06-03 23:34 - 2014-10-03 09:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
    2015-06-03 23:34 - 2014-10-03 09:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
    2015-06-03 23:34 - 2014-10-03 09:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
    2015-06-03 23:34 - 2014-09-04 13:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
    2015-06-03 23:34 - 2014-09-04 13:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
    2015-06-03 23:34 - 2014-06-06 18:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
    2015-06-03 23:34 - 2014-06-06 17:44 - 00509440 _____ (Microsoft Corporation)
     
  6. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    FRST (continued):


    2015-06-03 23:34 - 2014-05-30 14:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
    2015-06-03 23:34 - 2014-03-26 22:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
    2015-06-03 23:34 - 2014-03-26 22:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
    2015-06-03 23:34 - 2014-03-26 22:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2015-06-03 23:34 - 2014-03-26 22:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
    2015-06-03 23:34 - 2014-02-04 10:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
    2015-06-03 23:34 - 2014-02-04 10:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
    2015-06-03 23:34 - 2014-02-04 10:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
    2015-06-03 23:34 - 2014-02-04 10:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
    2015-06-03 23:34 - 2014-02-04 10:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
    2015-06-03 23:34 - 2014-01-29 10:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
    2015-06-03 23:34 - 2014-01-29 10:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
    2015-06-03 23:34 - 2013-10-30 10:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
    2015-06-03 23:34 - 2013-10-30 10:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
    2015-06-03 23:34 - 2013-10-19 10:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
    2015-06-03 23:34 - 2013-10-19 09:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
    2015-06-03 23:34 - 2013-10-12 10:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
    2015-06-03 23:34 - 2013-10-12 10:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
    2015-06-03 23:34 - 2013-10-12 10:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
    2015-06-03 23:34 - 2013-10-12 10:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
    2015-06-03 23:34 - 2013-10-12 10:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
    2015-06-03 23:34 - 2013-10-12 10:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
    2015-06-03 23:34 - 2013-10-12 10:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
    2015-06-03 23:34 - 2013-10-12 10:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
    2015-06-03 23:34 - 2013-10-12 10:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
    2015-06-03 23:34 - 2013-10-12 09:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
    2015-06-03 23:34 - 2013-10-12 09:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
    2015-06-03 23:34 - 2013-10-12 09:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
    2015-06-03 23:34 - 2013-10-12 09:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
    2015-06-03 23:34 - 2013-10-04 10:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
    2015-06-03 23:34 - 2013-10-04 09:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
    2015-06-03 23:34 - 2013-07-25 17:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
    2015-06-03 23:34 - 2013-07-25 16:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
    2015-06-03 23:34 - 2013-07-04 20:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
    2015-06-03 23:34 - 2013-07-04 20:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
    2015-06-03 23:34 - 2013-07-04 20:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
    2015-06-03 23:34 - 2013-07-04 19:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
    2015-06-03 23:34 - 2013-07-04 19:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
    2015-06-03 23:34 - 2013-07-04 19:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
    2015-06-03 23:34 - 2013-07-03 12:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
    2015-06-03 23:34 - 2013-07-03 12:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
    2015-06-03 23:34 - 2013-07-03 12:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
    2015-06-03 23:34 - 2013-02-12 12:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
    2015-06-03 23:34 - 2012-09-26 06:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
    2015-06-03 23:34 - 2012-09-26 06:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
    2015-06-03 23:34 - 2012-05-14 13:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
    2015-06-03 23:34 - 2011-11-17 14:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
    2015-06-03 23:34 - 2011-11-17 13:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
    2015-06-03 23:33 - 2015-03-05 13:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2015-06-03 23:33 - 2015-03-05 12:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2015-06-03 23:33 - 2015-02-25 11:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
    2015-06-03 23:33 - 2015-01-17 10:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2015-06-03 23:33 - 2015-01-17 10:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
    2015-06-03 23:33 - 2014-12-19 11:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
    2015-06-03 23:33 - 2014-12-08 11:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
    2015-06-03 23:33 - 2014-12-08 10:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
    2015-06-03 23:33 - 2014-11-11 09:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
    2015-06-03 23:33 - 2014-10-25 09:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
    2015-06-03 23:33 - 2014-10-25 09:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
    2015-06-03 23:33 - 2014-04-25 10:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
    2015-06-03 23:33 - 2014-04-25 10:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
    2015-06-03 23:33 - 2014-01-28 10:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
    2015-06-03 23:33 - 2013-11-27 09:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
    2015-06-03 23:33 - 2013-11-27 09:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
    2015-06-03 23:33 - 2013-11-27 09:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
    2015-06-03 23:33 - 2013-11-27 09:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
    2015-06-03 23:33 - 2013-11-27 09:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
    2015-06-03 23:33 - 2013-07-12 18:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
    2015-06-03 23:33 - 2013-04-26 13:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
    2015-06-03 23:33 - 2013-04-26 12:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
    2015-06-03 23:33 - 2013-03-19 13:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
    2015-06-03 23:33 - 2013-01-24 14:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
    2015-06-03 23:33 - 2012-11-23 11:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
    2015-06-03 23:33 - 2012-11-02 13:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
    2015-06-03 23:33 - 2012-11-02 13:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
    2015-06-03 23:33 - 2012-08-23 02:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
    2015-06-03 23:33 - 2012-07-05 06:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
    2015-06-03 23:33 - 2012-07-05 06:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
    2015-06-03 23:33 - 2012-07-05 06:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
    2015-06-03 23:33 - 2012-07-05 05:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
    2015-06-03 23:33 - 2012-07-05 05:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
    2015-06-03 23:33 - 2012-07-05 04:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
    2015-06-03 23:33 - 2012-03-17 15:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
    2015-06-03 23:25 - 2013-08-28 09:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
    2015-06-03 23:22 - 2014-07-14 10:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2015-06-03 23:22 - 2014-07-14 09:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2015-06-03 22:55 - 2015-06-03 22:55 - 00000000 ____D C:\Windows\NAPP_Dism_Log
    2015-06-03 22:40 - 2015-06-03 22:40 - 00000000 ____D C:\ProgramData\Nexon
    2015-06-03 22:22 - 2015-06-03 22:22 - 00001162 _____ C:\Users\Public\Desktop\MapleStorySEA.lnk
    2015-06-03 22:22 - 2015-06-03 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wizet
    2015-06-03 22:17 - 2015-06-03 22:17 - 00002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
    2015-06-03 22:17 - 2015-06-03 22:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
    2015-06-03 22:16 - 2015-06-03 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    2015-06-03 22:16 - 2015-06-03 22:16 - 00000000 ____D C:\Program Files\PlayReady
    2015-06-03 22:16 - 2015-06-03 22:16 - 00000000 ____D C:\Program Files (x86)\PlayReady
    2015-06-03 22:13 - 2015-06-05 14:08 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
    2015-06-03 22:13 - 2015-06-04 17:17 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
    2015-06-03 22:13 - 2015-06-03 22:13 - 00003492 _____ C:\Windows\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d
    2015-06-03 22:13 - 2015-06-03 22:13 - 00003188 _____ C:\Windows\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon
    2015-06-03 22:13 - 2015-06-03 22:13 - 00000000 ____D C:\ProgramData\Intel
    2015-06-03 22:13 - 2015-06-03 22:13 - 00000000 ____D C:\Program Files\Intel
    2015-06-03 22:13 - 2012-02-07 17:40 - 00015128 _____ C:\Windows\system32\Drivers\IntelMEFWVer.dll
    2015-06-03 22:12 - 2015-06-05 14:08 - 00000000 ____D C:\ProgramData\NVIDIA
    2015-06-03 22:12 - 2015-06-03 22:12 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
    2015-06-03 22:12 - 2012-03-07 15:02 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Macromedia
    2015-06-03 22:12 - 2009-07-14 12:54 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-06-03 22:12 - 2009-07-14 12:49 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2015-06-03 22:11 - 2015-06-03 22:13 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
    2015-06-03 22:11 - 2015-06-03 22:12 - 00000000 ____D C:\Program Files\NVIDIA Corporation
    2015-06-03 22:11 - 2015-06-03 22:12 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
    2015-06-03 22:11 - 2015-06-03 22:11 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
    2015-06-03 22:11 - 2015-06-03 22:11 - 00000000 ____D C:\Program Files (x86)\Wizet
    2015-06-03 22:11 - 2012-05-09 20:27 - 25743168 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 25248064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 19607872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 18044224 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 17551680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 15322432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 14299456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
    2015-06-03 22:11 - 2012-05-09 20:27 - 10194752 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 08139072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 08105792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 05982528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02881856 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02741568 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02681664 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02524992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02445120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02368832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 01738048 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco64.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 01468224 _____ (NVIDIA Corporation) C:\Windows\system32\nvgenco64.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00949056 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00818496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00364352 _____ (NVIDIA Corporation) C:\Windows\system32\nvdecodemft.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00301376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00246592 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00202048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00068928 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00061248 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00028992 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
    2015-06-03 22:11 - 2012-05-09 20:27 - 00014324 _____ C:\Windows\system32\nvinfo.pb
    2015-06-03 22:11 - 2012-05-09 11:54 - 03149632 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 02619385 _____ C:\Windows\system32\nvcoproc.bin
    2015-06-03 22:11 - 2012-05-09 11:54 - 02561856 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 00889664 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
    2015-06-03 22:11 - 2012-05-09 11:54 - 00858944 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 00118080 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 00063296 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 00055616 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
    2015-06-03 22:11 - 2012-05-09 11:41 - 06151488 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
    2015-06-03 22:11 - 2012-04-19 01:08 - 01451840 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
    2015-06-03 22:11 - 2012-04-19 01:08 - 00188736 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
    2015-06-03 22:11 - 2012-04-19 01:08 - 00031040 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
    2015-06-03 22:10 - 2011-11-30 10:40 - 00568600 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStor.sys
    2015-06-03 22:05 - 2015-06-03 22:07 - 00001874 _____ C:\Windows\WinRE_Settings.log
    2015-06-03 22:05 - 2015-06-03 22:05 - 00000000 ___HD C:\book
    2015-06-03 22:05 - 2015-06-03 22:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem
    2015-06-03 22:04 - 2015-06-03 22:04 - 00000025 _____ C:\Windows\mSataSettings.log
    2015-06-03 22:01 - 2015-06-05 14:42 - 02086676 _____ C:\Windows\WindowsUpdate.log
    2015-06-03 22:01 - 2015-06-03 22:01 - 00000000 ___HD C:\Program Files (x86)\Temp
    2015-06-03 22:01 - 2015-06-03 22:01 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
    2015-06-03 22:01 - 2015-06-03 22:01 - 00000000 ____D C:\Program Files\Realtek
    2015-06-03 22:01 - 2015-06-03 22:01 - 00000000 ____D C:\Program Files (x86)\Realtek
    2015-06-03 22:01 - 2011-11-16 12:11 - 00099944 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
    2015-06-03 22:01 - 2011-11-16 11:58 - 02950632 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
    2015-06-03 22:01 - 2011-11-15 13:57 - 02612840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
    2015-06-03 22:01 - 2011-11-15 13:04 - 00015464 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
    2015-06-03 22:01 - 2011-11-14 17:11 - 02007040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
    2015-06-03 22:01 - 2011-11-14 17:08 - 00181324 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
    2015-06-03 22:01 - 2011-11-14 14:38 - 02361448 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
    2015-06-03 22:01 - 2011-11-14 14:38 - 01966184 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
    2015-06-03 22:01 - 2011-11-10 13:47 - 00219752 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
    2015-06-03 22:01 - 2011-10-18 13:55 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
    2015-06-03 22:01 - 2011-09-02 14:21 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
    2015-06-03 22:01 - 2011-09-02 14:21 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
    2015-06-03 22:01 - 2011-09-02 14:21 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
    2015-06-03 22:01 - 2011-08-31 19:12 - 01698408 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
    2015-06-03 22:01 - 2011-08-23 17:00 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
    2015-06-03 22:01 - 2011-08-06 01:29 - 00527872 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
    2015-06-03 22:01 - 2011-08-06 01:29 - 00515584 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
    2015-06-03 22:01 - 2011-08-06 01:29 - 00439808 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
    2015-06-03 22:01 - 2011-07-28 00:55 - 02604376 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
    2015-06-03 22:01 - 2011-07-28 00:55 - 02132824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
    2015-06-03 22:01 - 2011-07-22 19:35 - 01247848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
    2015-06-03 22:01 - 2011-07-08 14:34 - 00065432 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
    2015-06-03 22:01 - 2011-06-30 16:14 - 01560168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
    2015-06-03 22:01 - 2011-06-27 14:45 - 03768152 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll
    2015-06-03 22:01 - 2011-06-14 11:13 - 00177088 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
    2015-06-03 22:01 - 2011-05-05 15:24 - 02085440 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 03308376 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 00426328 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 00136024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 00118104 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 00074072 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
    2015-06-03 22:01 - 2011-03-17 12:17 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
    2015-06-03 22:01 - 2011-03-07 17:11 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
    2015-06-03 22:01 - 2010-11-29 14:36 - 00702808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek2.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
    2015-06-03 22:01 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
    2015-06-03 22:01 - 2010-10-03 13:46 - 00341336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
    2015-06-03 22:01 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
    2015-06-03 22:01 - 2010-07-22 16:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
    2015-06-03 22:01 - 2010-07-22 16:37 - 00200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
    2015-06-03 22:01 - 2010-05-06 17:34 - 00334680 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
    2015-06-03 22:01 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
    2015-06-03 22:01 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
    2015-06-03 22:01 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
    2015-06-03 22:01 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
    2015-06-03 22:01 - 2009-11-17 18:12 - 00108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
    2015-06-03 21:59 - 2015-06-03 21:59 - 00038499 _____ C:\Windows\ATIDetect.txt
    2015-06-03 21:58 - 2015-06-03 21:58 - 00001285 _____ C:\Windows\system32\RaCoInst.log
    2015-06-03 20:20 - 2015-06-03 20:20 - 00000000 ____D C:\Users\Loke\Tracing
    2015-06-03 20:17 - 2015-06-03 20:17 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
    2015-06-03 20:17 - 2015-06-03 20:17 - 00000000 ___RD C:\Program Files (x86)\Skype
    2015-06-03 20:17 - 2015-06-03 20:17 - 00000000 ____D C:\Users\Loke\AppData\Local\Skype
    2015-06-03 20:17 - 2015-06-03 20:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2015-06-03 20:07 - 2015-06-04 01:55 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Skype
    2015-06-03 20:06 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
    2015-06-03 20:06 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
    2015-06-03 20:06 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
    2015-06-03 20:06 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
    2015-06-03 20:06 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
    2015-06-03 20:06 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
    2015-06-03 20:06 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
    2015-06-03 20:06 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
    2015-06-03 20:06 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
    2015-06-03 20:06 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
    2015-06-03 20:06 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
    2015-06-03 20:06 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
    2015-06-03 20:06 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
    2015-06-03 20:06 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
    2015-06-03 20:06 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
    2015-06-03 20:06 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
    2015-06-03 20:06 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
    2015-06-03 20:06 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
    2015-06-03 20:06 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
    2015-06-03 20:06 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
    2015-06-03 20:06 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
    2015-06-03 20:06 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
    2015-06-03 20:06 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
    2015-06-03 20:06 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
    2015-06-03 20:06 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
    2015-06-03 20:06 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
    2015-06-03 20:06 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
    2015-06-03 20:06 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
    2015-06-03 20:06 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
    2015-06-03 20:06 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
    2015-06-03 20:06 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
    2015-06-03 20:06 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
    2015-06-03 20:06 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
    2015-06-03 20:06 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
    2015-06-03 20:06 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
    2015-06-03 20:06 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
    2015-06-03 20:06 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
    2015-06-03 20:06 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
    2015-06-03 20:06 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
    2015-06-03 20:06 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
    2015-06-03 20:06 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
    2015-06-03 20:06 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
    2015-06-03 20:06 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
    2015-06-03 20:06 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
    2015-06-03 20:06 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
    2015-06-03 20:06 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
    2015-06-03 20:06 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
    2015-06-03 20:06 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
    2015-06-03 20:06 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
    2015-06-03 20:06 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
    2015-06-03 20:06 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
    2015-06-03 20:06 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
    2015-06-03 20:06 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
    2015-06-03 20:06 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
    2015-06-03 20:06 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
    2015-06-03 20:06 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
    2015-06-03 20:06 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
    2015-06-03 20:06 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
    2015-06-03 20:06 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
    2015-06-03 20:06 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
    2015-06-03 20:06 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
    2015-06-03 20:06 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
    2015-06-03 20:06 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
    2015-06-03 20:06 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
    2015-06-03 20:06 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
    2015-06-03 20:06 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
    2015-06-03 20:06 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
    2015-06-03 20:06 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
    2015-06-03 20:06 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
    2015-06-03 20:06 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
    2015-06-03 20:06 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
    2015-06-03 20:06 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
    2015-06-03 20:06 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
    2015-06-03 20:06 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
    2015-06-03 20:06 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
    2015-06-03 20:06 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
    2015-06-03 20:06 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
    2015-06-03 20:06 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
    2015-06-03 20:06 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
    2015-06-03 20:06 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
    2015-06-03 20:06 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
    2015-06-03 20:06 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
    2015-06-03 20:06 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
    2015-06-03 20:06 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
    2015-06-03 20:06 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
    2015-06-03 20:06 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
    2015-06-03 20:06 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
    2015-06-03 20:06 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
    2015-06-03 20:06 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
    2015-06-03 20:06 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
    2015-06-03 20:06 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
    2015-06-03 20:06 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
    2015-06-03 20:06 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
    2015-06-03 20:06 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
    2015-06-03 20:06 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
    2015-06-03 20:06 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
    2015-06-03 20:06 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
     
  7. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    FRST (continued):


    2015-06-03 20:06 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
    2015-06-03 20:06 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
    2015-06-03 19:40 - 2015-06-03 19:40 - 00002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
    2015-06-03 19:40 - 2015-06-03 19:40 - 00001945 _____ C:\Windows\epplauncher.mif
    2015-06-03 19:40 - 2015-06-03 19:40 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2015-06-03 19:40 - 2015-06-03 19:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2015-06-03 14:09 - 2015-06-03 14:09 - 00262144 _____ C:\Windows\system32\config\ELAM
    2015-06-03 13:44 - 2015-06-03 13:44 - 00000219 _____ C:\Users\Loke\Desktop\Counter-Strike Global Offensive.url
    2015-06-03 13:35 - 2015-06-03 13:35 - 00000000 ___RD C:\Users\Loke\Desktop\poniponiponi
    2015-06-03 13:20 - 2015-06-03 13:20 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Gyazo
    2015-06-03 13:19 - 2015-06-03 14:19 - 00000000 ____D C:\Program Files (x86)\Gyazo
    2015-06-03 13:19 - 2015-06-03 13:19 - 00003740 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine
    2015-06-03 13:19 - 2015-06-03 13:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo
    2015-06-03 12:49 - 2015-06-04 17:44 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
    2015-06-03 12:49 - 2015-06-03 12:49 - 00000219 _____ C:\Users\Loke\Desktop\Dota 2.url
    2015-06-03 11:43 - 2015-06-03 11:43 - 00000000 ____D C:\Users\Loke\AppData\Local\Steam
    2015-06-03 11:42 - 2015-06-05 14:09 - 00000000 ____D C:\Program Files (x86)\Steam
    2015-06-03 11:42 - 2015-06-03 11:42 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk
    2015-06-03 11:42 - 2015-06-03 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    2015-06-03 07:45 - 2012-02-17 14:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
    2015-06-03 07:45 - 2012-02-17 13:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
    2015-06-03 07:45 - 2012-02-17 12:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
    2015-06-03 07:44 - 2015-06-03 07:44 - 00000000 ____D C:\Users\Loke\AppData\Local\EgisTec IPS
    2015-06-03 07:39 - 2015-06-03 07:39 - 00002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2015-06-03 07:39 - 2015-06-03 07:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-06-03 07:38 - 2015-06-05 14:08 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-06-03 07:38 - 2015-06-05 01:50 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-06-03 07:38 - 2015-06-04 17:32 - 00000000 ____D C:\Program Files (x86)\Google
    2015-06-03 07:38 - 2015-06-03 07:45 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-06-03 07:38 - 2015-06-03 07:45 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-06-03 07:38 - 2015-06-03 07:39 - 00000000 ____D C:\Users\Loke\AppData\Local\Google
    2015-06-03 07:37 - 2015-06-03 07:38 - 00000000 ____D C:\Users\Loke\AppData\Local\Deployment
    2015-06-03 07:37 - 2015-06-03 07:37 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Adobe
    2015-06-03 07:37 - 2015-06-03 07:37 - 00000000 ____D C:\Users\Loke\AppData\Local\Apps\2.0
    2015-06-03 07:36 - 2015-06-04 08:14 - 00001417 _____ C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-06-03 07:36 - 2015-06-03 07:36 - 00000000 ____D C:\Users\Loke\AppData\Roaming\OEM
    2015-06-03 07:35 - 2015-06-03 13:35 - 00000000 ____D C:\Users\Loke\AppData\Local\VirtualStore
    2015-06-03 07:35 - 2015-06-03 07:35 - 00000000 ____D C:\Program Files (x86)\OEM
    2015-06-03 07:35 - 2015-06-03 07:35 - 00000000 _____ C:\Users\Loke\agent.log
    2015-06-03 07:34 - 2015-06-04 01:17 - 00058016 _____ C:\Users\Loke\AppData\Local\GDIPFONTCACHEV1.DAT
    2015-06-03 07:34 - 2015-06-03 20:20 - 00000000 ____D C:\Users\Loke
    2015-06-03 07:34 - 2015-06-03 07:34 - 00000020 ___SH C:\Users\Loke\ntuser.ini
    2015-06-03 07:34 - 2015-06-03 07:34 - 00000000 ____D C:\ProgramData\OEM_E471269A730D
    2015-06-03 07:34 - 2015-06-03 07:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Family Protection
    2015-06-03 07:34 - 2012-03-07 15:02 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Macromedia
    2015-06-03 07:34 - 2009-07-14 12:54 - 00000000 ___RD C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-06-03 07:34 - 2009-07-14 12:49 - 00000000 ___RD C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2015-06-03 07:33 - 2015-06-03 07:33 - 00000000 __SHD C:\Recovery

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-06-05 14:17 - 2012-03-07 14:59 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-06-05 14:17 - 2012-03-07 14:59 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-06-05 14:17 - 2009-07-14 12:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-06-05 14:17 - 2009-07-14 12:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-06-05 14:14 - 2009-07-14 13:13 - 00726316 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-06-05 14:12 - 2012-03-07 14:28 - 00001848 _____ C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk
    2015-06-05 14:08 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-06-05 14:08 - 2009-07-14 12:51 - 00038526 _____ C:\Windows\setupact.log
    2015-06-04 22:59 - 2012-03-07 14:26 - 00000000 ____D C:\ProgramData\McAfee
    2015-06-04 22:59 - 2012-03-07 14:26 - 00000000 ____D C:\Program Files\Common Files\mcafee
    2015-06-04 22:59 - 2010-11-21 11:47 - 00012066 _____ C:\Windows\PFRO.log
    2015-06-04 18:22 - 2012-03-07 14:30 - 00045344 _____ C:\Windows\DirectX.log
    2015-06-04 14:32 - 2012-03-07 14:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
    2015-06-04 08:12 - 2009-07-14 12:45 - 00267672 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\zh-HK
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\tr-TR
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\Dism
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\PolicyDefinitions
    2015-06-04 08:08 - 2010-11-21 15:17 - 00000000 ____D C:\Program Files\Windows Journal
    2015-06-04 08:08 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
    2015-06-04 08:08 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\AppCompat
    2015-06-04 01:31 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\tracing
    2015-06-04 01:09 - 2009-07-14 13:32 - 00000000 ____D C:\Program Files\Windows Defender
    2015-06-04 01:09 - 2009-07-14 13:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2015-06-03 22:56 - 2009-07-14 13:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG
    2015-06-03 22:56 - 2009-07-14 13:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
    2015-06-03 22:31 - 2009-07-14 12:46 - 00004059 _____ C:\Windows\DtcInstall.log
    2015-06-03 22:31 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\sysprep
    2015-06-03 22:31 - 2007-07-12 09:49 - 00000000 ____D C:\Windows\Panther
    2015-06-03 22:23 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\Help
    2015-06-03 22:22 - 2012-03-07 14:28 - 00000000 ____D C:\Program Files (x86)\Acer
    2015-06-03 22:20 - 2012-03-07 14:28 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
    2015-06-03 22:19 - 2012-03-07 15:01 - 00000032 _____ C:\ProgramData\PS.log
    2015-06-03 22:19 - 2012-03-07 15:01 - 00000000 ____D C:\Program Files (x86)\Cyberlink
    2015-06-03 22:19 - 2012-03-07 14:59 - 00002472 _____ C:\ProgramData\clear.fiSDK20.log
    2015-06-03 22:19 - 2012-03-07 14:59 - 00000000 ____D C:\ProgramData\CyberLink
    2015-06-03 22:19 - 2012-03-07 14:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2015-06-03 22:17 - 2009-07-14 13:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
    2015-06-03 22:13 - 2012-03-07 14:16 - 00000000 ____D C:\Program Files (x86)\Intel
    2015-06-03 22:13 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2015-06-03 22:09 - 2011-02-12 11:12 - 00000000 ____D C:\Windows\DeployWinRE2
    2015-06-03 22:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\Recovery
    2015-06-03 22:05 - 2012-03-07 14:24 - 00000000 ____D C:\Program Files (x86)\Acer Games
    2015-06-03 21:58 - 2012-03-07 14:01 - 00003652 _____ C:\Windows\TSSysprep.log
    2015-06-03 20:17 - 2012-03-07 14:26 - 00000000 ____D C:\ProgramData\Skype
    2015-06-03 14:09 - 2012-03-07 14:26 - 00000000 ____D C:\Program Files\mcafee
    2015-06-03 14:09 - 2012-03-07 14:26 - 00000000 ____D C:\Program Files (x86)\McAfee
    2015-06-03 07:36 - 2012-03-07 15:06 - 00018571 _____ C:\Windows\Patch.log
    2015-06-03 07:36 - 2012-03-07 14:57 - 00000000 ____D C:\ProgramData\oem
    2015-06-03 07:36 - 2012-03-07 13:53 - 00000000 ___HD C:\OEM
    2015-06-03 07:34 - 2012-03-07 15:05 - 00000000 ____D C:\Program Files\Preload
    2015-06-03 07:34 - 2009-07-14 13:32 - 00000000 ____D C:\Windows\system32\restore
    2015-06-03 07:33 - 2009-07-14 11:20 - 00000000 __RHD C:\Users\Public\Libraries
    2015-06-03 07:33 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\rescache

    ==================== Files in the root of some directories =======

    2012-03-07 14:59 - 2015-06-03 22:19 - 0002472 _____ () C:\ProgramData\clear.fiSDK20.log
    2012-03-07 15:01 - 2015-06-03 22:19 - 0000032 _____ () C:\ProgramData\PS.log

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2012-03-07 13:59

    ==================== End of log ============================
     
  8. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    Addition:


    Additional scan result of Farbar Recovery Scan Tool (x64) Version:03-06-2015
    Ran by Loke at 2015-06-05 14:49:16
    Running from C:\Users\Loke\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-79519641-1766234843-2241692891-500 - Administrator - Disabled)
    Guest (S-1-5-21-79519641-1766234843-2241692891-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-79519641-1766234843-2241692891-1003 - Limited - Enabled)
    Loke (S-1-5-21-79519641-1766234843-2241692891-1001 - Administrator - Enabled) => C:\Users\Loke
    UpdatusUser (S-1-5-21-79519641-1766234843-2241692891-1000 - Limited - Enabled) => C:\Users\UpdatusUser

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
    AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
    AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
    AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
    FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3507 - Acer Incorporated)
    Acer Games (HKLM-x32\...\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
    Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.04.3506 - Acer Incorporated)
    Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0609.2011 - Acer Incorporated)
    Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3501 - Acer Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated)
    Adobe Flash Player 11 ActiveX 64-bit (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.2.202.222 - Adobe Systems Incorporated)
    Adobe Reader X (10.1.0) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
    Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Bing Bar (HKLM-x32\...\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}) (Version: 7.0.765.0 - Microsoft Corporation)
    clear.fi Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.00.3004 - Acer Incorporated)
    clear.fi Photo (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.00.3004 - Acer Incorporated)
    clear.fi SDK - MVP 2 (x32 Version: 2.0.1505 - CyberLink Corp.) Hidden
    clear.fi SDK- Movie 2 (x32 Version: 2.0.1502 - CyberLink Corp.) Hidden
    Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
    CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)
    eBay Worldwide (HKLM-x32\...\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
    Evernote v. 4.5.2 (HKLM-x32\...\{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
    FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Fooz Kids (HKLM-x32\...\FoozKids) (Version: 3.1.2 - FUHU, Inc.)
    Fooz Kids (x32 Version: 3.1.2 - FUHU, Inc.) Hidden
    Fooz Kids Platform (HKLM-x32\...\{8D68CE08-9A14-4B7B-9857-3C646A2F34C7}) (Version: 2.1 - FUHU, Inc.)
    Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
    Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
    Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
    Gyazo 2.4 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)
    Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3510 - Acer Incorporated)
    Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
    Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
    Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.1.209 - Intel Corporation)
    Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
    Jewel Quest Mysteries: The Seventh Gate Collector's Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
    John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    MapleStorySEA version 1.49 (HKLM-x32\...\{A01FAD0F-93EC-486D-933E-E44A78538E64}_is1) (Version: 1.49 - Asiasoft Online Pte.Ltd.)
    McAfee Internet Security Suite (HKLM-x32\...\MSC) (Version: 12.8.992 - McAfee, Inc.)
    McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.314 - McAfee, Inc.)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
    MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
    MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.18 - Egis Technology Inc.)
    MyWinLocker Suite (x32 Version: 4.0.14.18 - Egis Technology Inc.) Hidden
    Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.4.10500.1.100 - Nero AG)
    Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10700.5.100 - Nero AG)
    Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.6.10300 - Nero AG)
    Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.6.10600.4.100 - Nero AG)
    Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
    NVIDIA 3D Vision Controller Driver 301.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 301.40 - NVIDIA Corporation)
    NVIDIA 3D Vision Driver 301.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 301.40 - NVIDIA Corporation)
    NVIDIA Graphics Driver 301.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 301.40 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.16.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.16.0 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.12.0213 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation)
    Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
    PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6505 - Realtek Semiconductor Corp.)
    Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
    Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
    Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
    Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.)
    Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.102 - Skype Technologies S.A.)
    Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    Torchlight (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
    Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated)
    WildTangent Games App (Acer Games) (x32 Version: 4.0.5.32 - WildTangent) Hidden
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
    Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
    Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Restore Points =========================

    03-06-2015 07:34:17 Windows Update
    03-06-2015 07:45:02 Windows Update
    03-06-2015 20:05:43 Installed DirectX
    03-06-2015 20:15:58 Removed Skype™ 5.5
    03-06-2015 22:44:52 Installed DirectX
    03-06-2015 23:45:54 Windows Update
    04-06-2015 01:28:06 Windows Update
    04-06-2015 01:40:18 Windows Update
    04-06-2015 03:00:24 Windows Update
    04-06-2015 08:23:34 Windows Update
    04-06-2015 18:21:17 Installed DirectX
    05-06-2015 01:52:55 Windows Update

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 10:34 - 2009-06-11 05:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {1E89F138-80BD-42AC-AE53-539214310D4F} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-21] (CyberLink)
    Task: {2642B25E-8228-46A3-A92C-18E97AC478AE} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-29] (Egis Technology Inc.)
    Task: {285967C5-2635-4A7F-841D-FBEC29BE021B} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-26] (Intel Corporation)
    Task: {2B89A434-4315-4936-A187-9EDB1085F51F} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-26] (Intel Corporation)
    Task: {3E1D40B2-B0A8-4100-BDE6-97BBC508A7BF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
    Task: {592D74B2-EDE7-4E22-B48C-72C74BC1E4F5} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29] (Egis Technology Inc.)
    Task: {5A80024F-EF1C-4484-8A41-0A54DB745CAD} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
    Task: {6CA9FDEF-5A47-4A7D-95B3-ACB71027D1D2} - System32\Tasks\Recovery Management\Burn Notification => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe [2012-01-19] (Acer)
    Task: {9800393D-CAE9-4568-B977-582150D8DED8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-03] (Google Inc.)
    Task: {9CC7FC4A-588D-4622-B92A-45FC4BD5F922} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2015-06-04] (Microsoft Corporation)
    Task: {ADF00ECC-D939-4947-9227-915EA93EA96A} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-02-07] (Acer Incorporated)
    Task: {C202B2C2-0F36-4362-86AC-A8A2C27D6A3D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
    Task: {C4251F8A-F291-4AF6-9B86-A57F3BA40E8B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-07] (Adobe Systems Incorporated)
    Task: {CD5097F1-F66F-4398-A7F4-1A0D5D1BF142} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-03] (Google Inc.)
    Task: {E0D44D9B-3F19-41FA-BE52-3CE87F32874F} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2015-04-30] ()
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe

    ==================== Loaded Modules (Whitelisted) ==============

    2015-06-03 22:13 - 2012-02-07 18:04 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    2015-06-03 22:11 - 2012-05-09 11:32 - 00085824 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2012-02-07 10:17 - 2012-02-07 10:17 - 00636520 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    2015-06-04 14:36 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    2015-06-04 14:36 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
    2015-06-04 14:36 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    2015-06-04 14:36 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
    2015-06-04 14:36 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
    2012-02-07 10:18 - 2012-02-07 10:18 - 00151656 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
    2015-06-03 11:42 - 2015-04-17 01:40 - 00776192 _____ () C:\Program Files (x86)\Steam\SDL2.dll
    2015-06-03 11:42 - 2015-04-23 10:16 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
    2015-06-03 11:42 - 2015-04-23 10:16 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
    2015-06-03 11:42 - 2015-04-23 10:16 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
    2015-06-03 11:42 - 2015-06-05 02:56 - 02407104 _____ () C:\Program Files (x86)\Steam\video.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
    2015-06-03 11:42 - 2015-06-05 02:56 - 00703168 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
    2015-06-03 11:42 - 2015-05-12 03:01 - 36302728 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
    2015-06-03 11:42 - 2015-05-12 03:01 - 08958344 _____ () C:\Program Files (x86)\Steam\bin\pdf.dll
    2015-06-03 07:39 - 2015-05-23 04:22 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libglesv2.dll
    2015-06-03 07:39 - 2015-05-23 04:22 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\libegl.dll
    2015-06-03 07:39 - 2015-05-23 04:22 - 14982472 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.81\PepperFlash\pepflashplayer.dll
    2015-06-03 22:10 - 2011-11-30 11:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
    2015-06-03 22:13 - 2012-02-07 17:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.1.254

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{C47CF69D-DD93-4EDF-92A3-ADE1768D7266}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{DB311AF4-EA49-43EC-A406-226F7AADD719}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{CE95AC89-E69D-4F1F-90C5-D4B90E3CBB9F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    FirewallRules: [{0A1D5830-6CFF-4003-BFA1-44650AD74B0F}] => (Allow) LPort=2869
    FirewallRules: [{8D214E05-5040-47E2-99B9-2B16D96AE222}] => (Allow) LPort=1900
    FirewallRules: [{AE48D3B2-3BE9-4CCF-92BF-A3A7E3FABF2A}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{133B2542-B23A-4FFA-8340-FA3E9072E637}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
    FirewallRules: [{4EE3391D-405A-47A0-AE6F-D437CB1C9AD9}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
    FirewallRules: [{676AC7B0-51B3-41ED-A570-0E175901F3DC}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
    FirewallRules: [{0255F560-585C-4E43-BFD2-67A49486975E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
    FirewallRules: [{150ADDCE-76B4-4574-90AF-403F03E98153}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
    FirewallRules: [{FBAF6240-41A6-46C8-9E41-58A9BB131789}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
    FirewallRules: [{AEDFE71E-47A4-4C93-8374-803F8B7AF38D}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
    FirewallRules: [{B14AED8F-82EB-4887-9CD9-3898E41BB383}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
    FirewallRules: [{6BDF6A68-CBFF-4706-80B0-D33E2F983C96}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
    FirewallRules: [{C5771E94-BBD9-4208-A49C-8825CD847087}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    FirewallRules: [{F5B0649A-3F8C-4AAF-A46A-5B768451F827}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    FirewallRules: [{0582E097-61E0-4D0D-80E5-7831B80C3FAD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\Movie\PlayMovie.exe
    FirewallRules: [{3320929E-3256-41AB-8763-0125CD075912}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\MVP\VideoPlayer.exe
    FirewallRules: [{9AF6F87B-39AF-44A0-9093-2838F82541AD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\MVP\MusicPlayer.exe
    FirewallRules: [{47DFE579-7294-44C7-BE71-C0FC22DCD9D4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{0839EF22-5EAD-4AB0-B39C-B2143AAFF9CC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{41D22160-3ADB-45C8-8833-27F90B1F3D8B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{6F181D4E-D3A6-4F57-8EFE-85EBF2212657}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{04B24C4D-6EC3-4BD9-A1D6-830D0B7D0306}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{5B90661C-98BF-414A-AE9D-ECD6E45B9D43}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\dota.exe
    FirewallRules: [{E20F360D-51B7-471D-A916-3C9F8B84883D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\dota.exe
    FirewallRules: [{14F90016-3389-4E2E-921B-062D2BAE6D8C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
    FirewallRules: [{1B9DC53C-AB54-4851-A3E0-3CC9F815C36C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
    FirewallRules: [{0A3ABF9E-9077-47F0-81A5-DD4B6C43D461}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{B2696E85-F3CF-42EF-A9A2-B8FB3CF7757E}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{29C14D07-9DE0-4D85-ACF1-18BB401748E7}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{4D27E759-7E42-4E56-B3FC-94CEC592E293}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
    FirewallRules: [{2368413A-7D39-41D6-A08D-0B551AE936E8}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
    FirewallRules: [{4300E327-9A6B-4A28-A8BA-2BA4BB2424B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
    FirewallRules: [{A1AA3062-04EF-43B0-ACCB-DAAB44292114}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
    StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (06/05/2015 02:08:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 11:00:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 07:00:29 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: CivilizationV_DX11.exe, version: 1.0.3.279, time stamp: 0x546cd0a8
    Faulting module name: CvGameCore_Expansion2.dll, version: 3.0.3.0, time stamp: 0x52c769bf
    Exception code: 0xc0000005
    Fault offset: 0x00116430
    Faulting process id: 0x1f90
    Faulting application start time: 0xCivilizationV_DX11.exe0
    Faulting application path: CivilizationV_DX11.exe1
    Faulting module path: CivilizationV_DX11.exe2
    Report Id: CivilizationV_DX11.exe3

    Error: (06/04/2015 06:21:21 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.


    Details:
    AddWin32ServiceFiles: Unable to back up image of service McAfee Network Agent since QueryServiceConfig API failed

    System Error:
    The system cannot find the file specified.
    .

    Error: (06/04/2015 04:54:00 PM) (Source: McLogEvent) (EventID: 5022) (User: NT AUTHORITY)
    Description: 1

    Error: (06/04/2015 04:53:57 PM) (Source: McLogEvent) (EventID: 5022) (User: NT AUTHORITY)
    Description: 1

    Error: (06/04/2015 11:49:24 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 09:25:29 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 08:56:31 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 08:28:58 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


    System errors:
    =============
    Error: (06/05/2015 02:20:46 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
    Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.199.1825.0).

    Error: (06/05/2015 02:20:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
    Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.199.1810.0

    Update Source: %NT AUTHORITY59

    Update Stage: 4.8.0204.00

    Source Path: 4.8.0204.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

    Error: (06/05/2015 02:09:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Steam Client Service service failed to start due to the following error:
    %%1053

    Error: (06/05/2015 02:09:34 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
    Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.

    Error: (06/04/2015 08:55:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
    %%1068

    Error: (06/04/2015 08:55:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
    %%1068

    Error: (06/04/2015 08:55:48 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
    %%1068

    Error: (06/04/2015 08:55:48 AM) (Source: DCOM) (EventID: 10005) (User: )
    Description: 1084McNaiAnn{DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

    Error: (06/04/2015 08:55:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
    %%1068

    Error: (06/04/2015 08:55:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
    %%1068


    Microsoft Office:
    =========================
    Error: (06/05/2015 02:08:31 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 11:00:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 07:00:29 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: CivilizationV_DX11.exe1.0.3.279546cd0a8CvGameCore_Expansion2.dll3.0.3.052c769bfc0000005001164301f9001d09eb21bae34b4C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\CivilizationV_DX11.exeC:\Users\Loke\Documents\My Games\Sid Meier's Civilization 5\MODS\Civ IV Diplomatic Features (v 10)\CvGameCore_Expansion2.dlle950580b-0aa8-11e5-82b6-f80f4153efec

    Error: (06/04/2015 06:21:21 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description:
    Details:
    AddWin32ServiceFiles: Unable to back up image of service McAfee Network Agent since QueryServiceConfig API failed

    System Error:
    The system cannot find the file specified.

    Error: (06/04/2015 04:54:00 PM) (Source: McLogEvent) (EventID: 5022) (User: NT AUTHORITY)
    Description: 1

    Error: (06/04/2015 04:53:57 PM) (Source: McLogEvent) (EventID: 5022) (User: NT AUTHORITY)
    Description: 1

    Error: (06/04/2015 11:49:24 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 09:25:29 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 08:56:31 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/04/2015 08:28:58 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz
    Percentage of memory in use: 29%
    Total physical RAM: 8139.2 MB
    Available physical RAM: 5754.01 MB
    Total Pagefile: 16276.6 MB
    Available Pagefile: 12676.57 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.84 MB

    ==================== Drives ================================

    Drive c: (Acer) (Fixed) (Total:222.95 GB) (Free:117.97 GB) NTFS
    Drive d: (DATA) (Fixed) (Total:223.71 GB) (Free:222.56 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 127D116D)
    Partition 1: (Not Active) - (Size=19 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=223 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=223.7 GB) - (Type=07 NTFS)

    ==================== End of log ============================
     
  9. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    [​IMG] You're running two AV programs, MSE and McAfee.
    You must uninstall one of them.
    If McAfee use this tool: http://www.majorgeeks.com/files/details/mcafee_consumer_product_removal_tool.html

    [​IMG] Download RogueKiller from one of the following links and save it to your Desktop:

    Link 1
    Link 2

    • Close all the running programs
    • Windows Vista/7/8 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    [​IMG] Please download Malwarebytes Anti-Malware (MBAM) to your desktop.
    NOTE. If you already have MBAM 2.0 installed scroll down.

    • Double-click mbam-setup-2.0.0.1000.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
      • Launch Malwarebytes Anti-Malware
      • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
    • Click Finish.
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.


    If you already have MBAM 2.0 installed:

    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.

    How to get logs:
    (Export log to save as txt)


    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • Attach that saved log to your next reply.


    (Copy to clipboard for pasting into forum replies or tickets)

    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Copy to Clipboard'
    • Paste the contents of the clipboard into your reply.

    [​IMG] Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Scan button.
    • When the scan has finished click on Clean button.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
  10. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    RogueKiller log:


    RogueKiller V10.8.1.0 [Jun 3 2015] by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/softwares/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : Loke [Administrator]
    Started from : C:\Users\Loke\Desktop\RogueKiller.exe
    Mode : Scan -- Date : 06/07/2015 10:26:27

    ¤¤¤ Processes : 1 ¤¤¤
    [VT.Unknown] nvtray.exe(3492) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[7] -> Killed [TermProc]

    ¤¤¤ Registry : 4 ¤¤¤
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-79519641-1766234843-2241692891-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://acer.msn.com -> Found
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-79519641-1766234843-2241692891-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://acer.msn.com -> Found
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-79519641-1766234843-2241692891-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://acer.msn.com -> Found
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-79519641-1766234843-2241692891-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://acer.msn.com -> Found

    ¤¤¤ Tasks : 1 ¤¤¤
    [Suspicious.Path] \Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan -- C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Scan -ScheduleJob -RestrictPrivileges) -> Found

    ¤¤¤ Files : 0 ¤¤¤

    ¤¤¤ Hosts File : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ MBR Check : ¤¤¤
    +++++ PhysicalDrive0: ST500DM002-1BD142 +++++
    --- User ---
    [MBR] e9ae5b58bc434d14cd857a410488bff4
    [BSP] 478bfccd07ba7d51e8f8b9174dff6621 : Windows Vista/7/8|VT.Unknown MBR Code
    Partition table:
    0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 19456 MB
    1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 39847936 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 40052736 | Size: 228302 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 507615232 | Size: 229080 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    User = LL1 ... OK
    User = LL2 ... OK

    +++++ PhysicalDrive1: Generic- Compact Flash USB Device +++++
    Error reading User MBR! ([15] The device is not ready. )
    Error reading LL1 MBR! NOT VALID!
    Error reading LL2 MBR! ([32] The request is not supported. )

    +++++ PhysicalDrive2: Multiple Flash Reader USB Device +++++
    Error reading User MBR! ([15] The device is not ready. )
    Error reading LL1 MBR! NOT VALID!
    Error reading LL2 MBR! ([32] The request is not supported. )
     
  11. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    MBAM log:


    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 6/7/2015
    Scan Time: 10:29:49 AM
    Logfile: mbam log.txt
    Administrator: Yes

    Version: 2.01.6.1022
    Malware Database: v2015.06.07.01
    Rootkit Database: v2015.06.02.01
    License: Trial
    Malware Protection: Enabled
    Malicious Website Protection: Enabled
    Self-protection: Disabled

    OS: Windows 7 Service Pack 1
    CPU: x64
    File System: NTFS
    User: Loke

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 392280
    Time Elapsed: 20 min, 34 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 0
    (No malicious items detected)

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 0
    (No malicious items detected)

    Physical Sectors: 0
    (No malicious items detected)


    (end)
     
  12. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    ADW log:


    # AdwCleaner v4.206 - Logfile created 07/06/2015 at 10:55:55
    # Updated 01/06/2015 by Xplode
    # Database : 2015-06-05.1 [Server]
    # Operating system : Windows 7 Home Premium Service Pack 1 (x64)
    # Username : Loke - LOKE-PC
    # Running from : C:\Users\Loke\Desktop\adwcleaner_4.206.exe
    # Option : Cleaning

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****


    ***** [ Scheduled tasks ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A01FAD0F-93EC-486D-933E-E44A78538E64}_is1

    ***** [ Web browsers ] *****

    -\\ Internet Explorer v11.0.9600.17801


    -\\ Google Chrome v43.0.2357.81


    *************************

    AdwCleaner[R0].txt - [970 bytes] - [07/06/2015 10:54:42]
    AdwCleaner[S0].txt - [900 bytes] - [07/06/2015 10:55:55]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [958 bytes] ##########
     
  13. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    JRT log:


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.8.9 (06.06.2015:1)
    OS: Windows 7 Home Premium x64
    Ran by Loke on Sun 06/07/2015 at 11:01:52.04
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Tasks



    ~~~ Registry Values



    ~~~ Registry Keys



    ~~~ Files



    ~~~ Folders



    ~~~ Chrome


    [C:\Users\Loke\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

    [C:\Users\Loke\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

    [C:\Users\Loke\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

    [C:\Users\Loke\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
     
  14. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Very Important! Temporarily disable your anti-virus and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      If the connection is not there use restore point you created prior to running Combofix.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error Illegal operation attempted on a registery key that has been marked for deletion, restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Windows Vista, 7 or 8 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
     
  15. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    Combofix log:


    ComboFix 15-05-31.01 - Loke 06/08/2015 19:31:22.1.4 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8139.6531 [GMT 8:00]
    Running from: c:\users\Loke\Desktop\ComboFix.exe
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
    FW: McAfee Firewall *Disabled* {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\wininit.ini
    .
    .
    ((((((((((((((((((((((((( Files Created from 2015-05-08 to 2015-06-08 )))))))))))))))))))))))))))))))
    .
    .
    2015-06-08 11:38 . 2015-06-08 11:38 -------- d-----w- c:\users\Default\AppData\Local\temp
    2015-06-08 11:36 . 2015-06-08 11:36 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE5E8899-65E4-4EF3-9067-79BEDD6F086D}\offreg.2672.dll
    2015-06-07 23:57 . 2015-06-07 23:57 -------- d-s---w- c:\windows\system32\GWX
    2015-06-07 23:57 . 2015-06-07 23:57 -------- d-s---w- c:\windows\SysWow64\GWX
    2015-06-07 23:57 . 2015-06-07 23:57 -------- d-----w- c:\windows\Migration
    2015-06-07 03:49 . 2015-05-17 20:57 12214312 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FE5E8899-65E4-4EF3-9067-79BEDD6F086D}\mpengine.dll
    2015-06-07 03:01 . 2015-06-07 03:01 -------- d-----w- C:\RegBackup
    2015-06-07 02:54 . 2015-06-07 02:55 -------- d-----w- C:\AdwCleaner
    2015-06-07 02:19 . 2015-06-07 02:20 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
    2015-06-07 02:19 . 2015-06-07 02:20 -------- d-----w- c:\programdata\RogueKiller
    2015-06-05 19:00 . 2015-06-06 06:31 -------- d-----w- c:\programdata\Malwarebytes Anti-Exploit
    2015-06-05 18:59 . 2015-06-05 18:59 -------- d-----w- c:\programdata\Malwarebytes
    2015-06-05 10:57 . 2013-09-23 05:49 197704 ----a-w- c:\windows\system32\drivers\HipShieldK.sys
    2015-06-05 06:46 . 2015-06-05 06:49 -------- d-----w- C:\FRST
    2015-06-04 17:53 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll
    2015-06-04 17:53 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
    2015-06-04 06:45 . 2015-04-21 16:26 968704 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
    2015-06-04 06:36 . 2015-06-08 11:25 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2015-06-04 06:36 . 2015-06-08 11:25 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
    2015-06-04 03:41 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
    2015-06-04 03:41 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
    2015-06-04 00:19 . 2015-02-03 03:31 1424896 ----a-w- c:\windows\system32\WindowsCodecs.dll
    2015-06-04 00:19 . 2015-02-03 03:12 1230848 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
    2015-06-04 00:19 . 2015-02-04 03:16 465920 ----a-w- c:\windows\system32\WMPhoto.dll
    2015-06-04 00:19 . 2015-02-04 02:54 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
    2015-06-03 18:22 . 2013-10-14 10:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
    2015-06-03 18:14 . 2015-06-03 18:14 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
    2015-06-03 18:08 . 2015-06-03 18:08 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
    2015-06-03 17:41 . 2015-06-03 17:46 -------- d-----w- c:\windows\system32\MRT
    2015-06-03 17:40 . 2015-06-03 17:40 -------- d-----w- c:\program files (x86)\MSXML 4.0
    2015-06-03 17:28 . 2015-06-03 17:28 -------- d-----w- c:\windows\SysWow64\Wat
    2015-06-03 17:28 . 2015-06-03 17:28 -------- d-----w- c:\windows\system32\Wat
    2015-06-03 17:23 . 2015-01-09 03:14 91136 ----a-w- c:\windows\system32\wdi.dll
    2015-06-03 17:23 . 2015-01-09 03:14 950272 ----a-w- c:\windows\system32\perftrack.dll
    2015-06-03 17:23 . 2015-01-09 03:14 29696 ----a-w- c:\windows\system32\powertracker.dll
    2015-06-03 17:23 . 2015-01-09 02:48 76800 ----a-w- c:\windows\SysWow64\wdi.dll
    2015-06-03 17:09 . 2015-06-03 17:09 -------- d-s---w- c:\windows\system32\CompatTel
    2015-06-03 17:09 . 2015-06-03 17:09 -------- d-----w- c:\windows\system32\appraiser
    2015-06-03 16:35 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
    2015-06-03 15:58 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
    2015-06-03 15:58 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
    2015-06-03 15:58 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
    2015-06-03 15:58 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
    2015-06-03 15:58 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
    2015-06-03 15:58 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
    2015-06-03 15:58 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
    2015-06-03 15:55 . 2015-05-01 13:17 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-06-03 15:55 . 2015-05-01 13:16 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
    2015-06-03 15:52 . 2015-06-03 15:52 -------- d-----w- c:\program files\Microsoft Silverlight
    2015-06-03 15:52 . 2015-06-03 15:52 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
    2015-06-03 15:52 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
    2015-06-03 15:52 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
    2015-06-03 15:52 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
    2015-06-03 15:46 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll
    2015-06-03 15:46 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe
    2015-06-03 15:46 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll
    2015-06-03 15:46 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe
    2015-06-03 15:46 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll
    2015-06-03 15:46 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll
    2015-06-03 15:46 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe
    2015-06-03 15:46 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe
    2015-06-03 15:45 . 2014-07-17 02:07 455168 ----a-w- c:\windows\system32\winlogon.exe
    2015-06-03 15:45 . 2014-07-17 02:07 235520 ----a-w- c:\windows\system32\winsta.dll
    2015-06-03 15:45 . 2014-07-17 02:07 1118720 ----a-w- c:\windows\system32\mstsc.exe
    2015-06-03 15:45 . 2014-07-17 01:40 157696 ----a-w- c:\windows\SysWow64\winsta.dll
    2015-06-03 15:45 . 2014-07-17 01:39 1051136 ----a-w- c:\windows\SysWow64\mstsc.exe
    2015-06-03 15:45 . 2014-07-17 01:21 212480 ----a-w- c:\windows\system32\drivers\rdpwd.sys
    2015-06-03 15:45 . 2014-07-17 02:07 150528 ----a-w- c:\windows\system32\rdpcorekmts.dll
    2015-06-03 15:45 . 2014-07-17 01:21 39936 ----a-w- c:\windows\system32\drivers\tssecsrv.sys
    2015-06-03 15:45 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
    2015-06-03 15:45 . 2012-04-26 05:34 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
    2015-06-03 15:44 . 2013-02-15 06:08 44032 ----a-w- c:\windows\system32\tsgqec.dll
    2015-06-03 15:44 . 2013-02-15 06:02 158720 ----a-w- c:\windows\system32\aaclient.dll
    2015-06-03 15:44 . 2013-02-15 03:25 36864 ----a-w- c:\windows\SysWow64\tsgqec.dll
    2015-06-03 15:44 . 2013-10-04 02:28 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll
    2015-06-03 15:44 . 2013-10-04 02:25 197120 ----a-w- c:\windows\system32\credui.dll
    2015-06-03 15:44 . 2013-10-04 01:58 152576 ----a-w- c:\windows\SysWow64\SmartcardCredentialProvider.dll
    2015-06-03 15:44 . 2013-10-04 01:56 168960 ----a-w- c:\windows\SysWow64\credui.dll
    2015-06-03 15:44 . 2014-03-04 09:44 722944 ----a-w- c:\windows\system32\objsel.dll
    2015-06-03 15:44 . 2014-03-04 09:17 538112 ----a-w- c:\windows\SysWow64\objsel.dll
    2015-06-03 15:42 . 2014-10-14 02:13 3241984 ----a-w- c:\windows\system32\msi.dll
    2015-06-03 15:41 . 2012-12-07 11:20 30720 ----a-w- c:\windows\system32\usk.rs
    2015-06-03 15:40 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
    2015-06-03 15:40 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
    2015-06-03 15:39 . 2014-11-08 03:16 2048 ----a-w- c:\windows\system32\tzres.dll
    2015-06-03 15:39 . 2014-11-08 02:45 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2015-06-03 15:37 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll
    2015-06-03 15:36 . 2012-10-09 18:17 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
    2015-06-03 15:35 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
    2015-06-03 15:34 . 2014-12-06 04:17 303616 ----a-w- c:\windows\system32\nlasvc.dll
    2015-06-03 15:33 . 2014-12-08 03:09 406528 ----a-w- c:\windows\system32\scesrv.dll
    2015-06-03 15:25 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
    2015-06-03 15:22 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
    2015-06-03 15:22 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
    2015-06-03 14:55 . 2015-06-03 14:55 -------- d-----w- c:\windows\NAPP_Dism_Log
    2015-06-03 14:40 . 2015-06-03 14:40 -------- d-----w- c:\programdata\Nexon
    2015-06-03 14:17 . 2015-06-03 14:17 -------- d-----w- c:\program files (x86)\Common Files\Intel Corporation
    2015-06-03 14:17 . 2011-08-04 12:51 16972800 ----a-w- c:\programdata\Microsoft\OEMOffice14\Office14\Updates\proofsp1-fr-fr.msp
    2015-06-03 14:17 . 2011-08-04 12:51 11056128 ----a-w- c:\programdata\Microsoft\OEMOffice14\Office14\Updates\proofsp1-es-es.msp
    2015-06-03 14:17 . 2010-11-22 01:29 1819648 ----a-w- c:\programdata\Microsoft\OEMOffice14\Office14\Word.en-us\WordMUI.msi
    2015-06-03 14:17 . 2011-08-04 12:51 11155456 ----a-w- c:\programdata\Microsoft\OEMOffice14\Office14\Updates\proofsp1-en-us.msp
    2015-06-03 14:17 . 2011-08-04 12:51 608768 ----a-w- c:\programdata\Microsoft\OEMOffice14\Office14\Updates\proofingsp1-en-us.msp
    2015-06-03 14:17 . 2011-08-04 12:51 3459584 ----a-w- c:\programdata\Microsoft\OEMOffice14\Office14\Updates\outlfltr.msp
    2015-06-03 14:17 . 2010-12-30 09:10 5790056 ----a-w- c:\programdata\Microsoft\OEMOffice14\Office14\Updates\osetup.dll
    2015-06-03 14:17 . 2011-08-04 12:51 425345024 ----a-w- c:\programdata\Microsoft\OEMOffice14\Office14\Updates\officesuitewwsp1-x-none.msp
    2015-06-03 14:13 . 2012-02-07 09:40 15128 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
    2015-06-03 14:13 . 2015-06-03 14:13 -------- d-----w- c:\programdata\Intel
    2015-06-03 14:13 . 2015-06-03 14:13 -------- d-----w- c:\program files\Intel
    2015-06-03 14:13 . 2015-06-03 14:13 -------- d-----w- c:\program files (x86)\Common Files\postureAgent
    2015-06-03 14:12 . 2015-06-03 14:12 -------- d-----w- c:\users\UpdatusUser
    2015-06-03 14:12 . 2015-06-08 11:26 -------- d-----w- c:\programdata\NVIDIA
    2015-06-03 14:10 . 2011-11-30 02:40 568600 ----a-w- c:\windows\system32\drivers\iaStor.sys
    2015-06-03 14:05 . 2015-06-03 14:05 -------- d---a-w- C:\book
    2015-06-03 12:17 . 2015-06-03 12:17 -------- d-----w- c:\program files (x86)\Common Files\Skype
    2015-06-03 12:17 . 2015-06-03 12:17 -------- d-----r- c:\program files (x86)\Skype
    2015-06-03 05:19 . 2015-06-03 06:19 -------- d-----w- c:\program files (x86)\Gyazo
    2015-06-03 03:42 . 2015-06-08 11:27 -------- d-----w- c:\program files (x86)\Steam
    2015-06-03 03:42 . 2015-06-05 12:30 -------- d-----w- c:\program files (x86)\Common Files\Steam
    2015-06-02 23:45 . 2012-02-17 06:38 1031680 ----a-w- c:\windows\system32\rdpcore.dll
    2015-06-02 23:45 . 2012-02-17 05:34 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
    2015-06-02 23:45 . 2012-02-17 04:57 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
    2015-06-02 23:38 . 2015-06-04 09:32 -------- d-----w- c:\program files (x86)\Google
    2015-06-02 23:35 . 2015-06-02 23:35 -------- d-----w- c:\program files (x86)\OEM
    2015-06-02 23:34 . 2015-06-02 23:34 -------- d-----w- c:\programdata\OEM_E471269A730D
    2015-06-02 23:34 . 2015-06-03 12:20 -------- d-----w- c:\users\Loke
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2015-06-02 23:37 . 2011-03-29 02:36 23776 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2015-03-17 04:56 . 2015-06-03 15:42 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files (x86)\Steam\steam.exe" [2015-06-04 2892992]
    "Gyazo"="c:\program files (x86)\Gyazo\GyStation.exe" [2015-04-30 3095840]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-04 291608]
    "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2011-06-21 341360]
    "Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2012-02-07 636520]
    "mcpltui_exe"="c:\program files\Common Files\McAfee\Platform\mcuicnt.exe" [2015-02-09 643064]
    "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2015-02-27 533872]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
    @=""
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
    R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
    R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
    R3 EgisTec Ticket Service;EgisTec Ticket Service;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;c:\program files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x]
    R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
    R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys;c:\windows\SYSNATIVE\drivers\HipShieldK.sys [x]
    R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
    R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe;c:\progra~1\mcafee\msc\mcawfwk.exe [x]
    R3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\DRIVERS\mfencrk.sys;c:\windows\SYSNATIVE\DRIVERS\mfencrk.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
    R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [x]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
    S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\drivers\iusb3hcs.sys;c:\windows\SYSNATIVE\drivers\iusb3hcs.sys [x]
    S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys [x]
    S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
    S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x]
    S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x]
    S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x]
    S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x]
    S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
    S2 HomeNetSvc;McAfee Home Network;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
    S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
    S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
    S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
    S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
    S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
    S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files (x86)\McAfee\SiteAdvisor\McSACore.exe;c:\program files (x86)\McAfee\SiteAdvisor\McSACore.exe [x]
    S2 McAPExe;McAfee AP Service;c:\program files\McAfee\MSC\McAPExe.exe;c:\program files\McAfee\MSC\McAPExe.exe [x]
    S2 mcbootdelaystartsvc;McAfee Boot Delay Start Service;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [x]
    S2 mccspsvc;McAfee CSP Service;c:\program files\Common Files\McAfee\CSP\1.3.374.0\McCSPServiceHost.exe;c:\program files\Common Files\McAfee\CSP\1.3.374.0\McCSPServiceHost.exe [x]
    S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [x]
    S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [x]
    S2 mcpltsvc;McAfee Platform Services;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [x]
    S2 mfecore;McAfee Anti-Malware Core;c:\program files\Common Files\McAfee\AMCore\mcshield.exe;c:\program files\Common Files\McAfee\AMCore\mcshield.exe [x]
    S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
    S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe [x]
    S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
    S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
    S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
    S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys [x]
    S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys;c:\windows\SYSNATIVE\drivers\iusb3hub.sys [x]
    S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys;c:\windows\SYSNATIVE\drivers\iusb3xhc.sys [x]
    S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys [x]
    S3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\DRIVERS\mfencbdc.sys;c:\windows\SYSNATIVE\DRIVERS\mfencbdc.sys [x]
    S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - WS2IFSL
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2015-06-02 23:39 986440 ----a-w- c:\program files (x86)\Google\Chrome\Application\43.0.2357.81\Installer\chrmstp.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2015-06-08 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-07 06:59]
    .
    2015-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-06-02 23:38]
    .
    2015-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-06-02 23:38]
    .
    2015-06-08 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
    - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
    .
    2015-06-07 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
    - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-11-14 13353064]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    TCP: DhcpNameServer = 192.168.1.254
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    Wow6432Node-HKLM-Run-Malwarebytes Anti-Exploit - c:\program files (x86)\Malwarebytes Anti-Exploit\mbae.exe
    HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
    Toolbar-Locked - (no file)
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_222_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_222_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_222.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_222.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_222.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_222.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
    "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2015-06-08 19:40:22
    ComboFix-quarantined-files.txt 2015-06-08 11:40
    .
    Pre-Run: 117,577,056,256 bytes free
    Post-Run: 117,729,181,696 bytes free
    .
    - - End Of File - - 99F6759312ADB651E3068ECFA0692E9D
     
  16. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.

    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Make sure you checkmark Addition.txt box.
    • Press Scan button.
    • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
     
  17. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-06-2015
    Ran by Loke (administrator) on LOKE-PC on 13-06-2015 20:59:36
    Running from C:\Users\Loke\Desktop
    Loaded Profiles: UpdatusUser & Loke (Available Profiles: UpdatusUser & Loke)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
    (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
    (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
    (McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
    (Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
    () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\CSP\1.3.374.0\McCSPServiceHost.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (CyberLink) C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
    (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
    (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
    () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McUICnt.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13353064 2011-11-14] (Realtek Semiconductor)
    HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-05] (Intel Corporation)
    HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-06-22] (Egis Technology Inc.)
    HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-07] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [636520 2012-02-07] ()
    HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [643064 2015-02-09] (McAfee, Inc.)
    HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [533872 2015-02-27] (McAfee, Inc.)
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2892992 2015-06-05] (Valve Corporation)
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3095840 2015-04-30] (Nota Inc.)
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\System32\Acer.scr [456224 2010-07-29] ()
    HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
    BootExecute: autocheck autochk * sdnclean64.exe

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    URLSearchHook: HKU\S-1-5-21-79519641-1766234843-2241692891-1001 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
    URLSearchHook: HKU\S-1-5-21-79519641-1766234843-2241692891-1001 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
    BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-07] (Adobe Systems Incorporated)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
    BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-08] (Microsoft Corporation.)
    Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-08] (Microsoft Corporation.)
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-06-04] (McAfee, Inc.)
    Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-06-04] (McAfee, Inc.)
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-06-04] (McAfee, Inc.)
    Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-06-04] (McAfee, Inc.)
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2015-02-27] (McAfee, Inc.)
    Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2015-02-27] (McAfee, Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

    FireFox:
    ========
    FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-02-27] ()
    FF Plugin: @microsoft.com/GENUINE -> disabled No File
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
    FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-02-27] ()
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-05-09] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-05-09] (NVIDIA Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-03] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-03] (Google Inc.)
    FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-08] ()
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-07] (Adobe Systems Inc.)
    FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
    FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-03-07]
    FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2012-03-07]

    Chrome:
    =======
    CHR Profile: C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2
    CHR Extension: (Google Slides) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-03]
    CHR Extension: (Google Docs) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-03]
    CHR Extension: (Google Drive) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-03]
    CHR Extension: (YouTube) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-03]
    CHR Extension: (Google Search) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-03]
    CHR Extension: (Google Sheets) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-03]
    CHR Extension: (SiteAdvisor) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-06-03]
    CHR Extension: (Bookmark Manager) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-06-03]
    CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-03]
    CHR Extension: (Google Wallet) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-03]
    CHR Extension: (Gmail) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-03]
    CHR Profile: C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4
    CHR Extension: (Google Slides) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-05]
    CHR Extension: (Google Docs) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-05]
    CHR Extension: (Google Drive) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-05]
    CHR Extension: (YouTube) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-05]
    CHR Extension: (Google Search) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-05]
    CHR Extension: (Google Sheets) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-05]
    CHR Extension: (SiteAdvisor) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-06-05]
    CHR Extension: (Desktop Wallpaper Tool) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\hcfhbpblckhcihdkoogjmgfpkpnfndel [2015-06-13]
    CHR Extension: (ThemeBeta.com) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\kffjafdfoihmdmeaocoknaioifekepfi [2015-06-05]
    CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-05]
    CHR Extension: (Google Wallet) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-05]
    CHR Extension: (Gmail) - C:\Users\Loke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-05]
    CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-06-09]
    CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-06-09]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [335064 2014-10-31] (McAfee, Inc.)
    R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] ()
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
    R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [155368 2015-06-04] (McAfee, Inc.)
    R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [562200 2015-02-27] (McAfee, Inc.)
    S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [225216 2011-01-29] (McAfee, Inc.)
    R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.3.374.0\McCSPServiceHost.exe [422632 2015-01-22] (McAfee, Inc.)
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [335064 2014-10-31] (McAfee, Inc.)
    R2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [335064 2014-10-31] (McAfee, Inc.)
    S2 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [601864 2015-02-27] (McAfee, Inc.)
    S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
    R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [335064 2014-10-31] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [335064 2014-10-31] (McAfee, Inc.)
    R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1050952 2014-11-06] (McAfee, Inc.)
    R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [221832 2014-10-01] (McAfee, Inc.)
    R2 mfevtp; C:\Windows\system32\mfevtps.exe [189920 2014-10-01] (McAfee, Inc.)
    R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [335064 2014-10-31] (McAfee, Inc.)
    R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
    R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72136 2014-10-01] (McAfee, Inc.)
    S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
    R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181584 2014-10-01] (McAfee, Inc.)
    R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313680 2014-10-01] (McAfee, Inc.)
    R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [526360 2014-10-01] (McAfee, Inc.)
    R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786304 2014-10-01] (McAfee, Inc.)
    R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [447440 2014-09-19] (McAfee, Inc.)
    S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96600 2014-09-19] (McAfee, Inc.)
    R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348560 2014-10-01] (McAfee, Inc.)
    U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-06-07] ()
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
  18. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-06-13 20:59 - 2015-06-13 20:59 - 00022142 _____ C:\Users\Loke\Desktop\FRST.txt
    2015-06-13 20:58 - 2015-06-13 20:58 - 02108928 _____ (Farbar) C:\Users\Loke\Desktop\FRST64.exe
    2015-06-11 18:31 - 2015-06-11 18:31 - 00000000 ____D C:\Users\Loke\AppData\Local\GWX
    2015-06-10 07:40 - 2015-06-02 03:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-06-10 07:40 - 2015-06-02 02:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-06-10 07:40 - 2015-05-27 22:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-06-10 07:40 - 2015-05-27 22:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-06-10 07:40 - 2015-05-26 02:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-06-10 07:40 - 2015-05-26 02:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-06-10 07:40 - 2015-05-26 02:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-06-10 07:40 - 2015-05-26 02:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2015-06-10 07:40 - 2015-05-26 02:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2015-06-10 07:40 - 2015-05-26 02:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
    2015-06-10 07:40 - 2015-05-26 02:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-06-10 07:40 - 2015-05-26 02:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-06-10 07:40 - 2015-05-26 02:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-06-10 07:40 - 2015-05-26 02:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
    2015-06-10 07:40 - 2015-05-26 02:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-06-10 07:40 - 2015-05-26 02:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 02:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-06-10 07:40 - 2015-05-26 02:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-06-10 07:40 - 2015-05-26 02:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-06-10 07:40 - 2015-05-26 02:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2015-06-10 07:40 - 2015-05-26 02:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
    2015-06-10 07:40 - 2015-05-26 02:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
    2015-06-10 07:40 - 2015-05-26 02:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-06-10 07:40 - 2015-05-26 02:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
    2015-06-10 07:40 - 2015-05-26 02:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
    2015-06-10 07:40 - 2015-05-26 02:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2015-06-10 07:40 - 2015-05-26 02:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
    2015-06-10 07:40 - 2015-05-26 01:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2015-06-10 07:40 - 2015-05-26 01:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2015-06-10 07:40 - 2015-05-26 01:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-06-10 07:40 - 2015-05-26 01:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2015-06-10 07:40 - 2015-05-26 01:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-06-10 07:40 - 2015-05-26 01:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 01:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-06-10 07:40 - 2015-05-26 01:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
    2015-06-10 07:40 - 2015-05-26 00:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2015-06-10 07:40 - 2015-05-26 00:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2015-06-10 07:40 - 2015-05-26 00:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 00:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 00:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-26 00:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2015-06-10 07:40 - 2015-05-23 11:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-06-10 07:40 - 2015-05-23 11:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-06-10 07:40 - 2015-05-23 11:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-06-10 07:40 - 2015-05-23 11:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-06-10 07:40 - 2015-05-23 11:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-06-10 07:40 - 2015-05-23 11:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-06-10 07:40 - 2015-05-23 11:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-06-10 07:40 - 2015-05-23 11:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-06-10 07:40 - 2015-05-23 11:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-06-10 07:40 - 2015-05-23 11:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-06-10 07:40 - 2015-05-23 11:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-06-10 07:40 - 2015-05-23 11:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-06-10 07:40 - 2015-05-23 11:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-06-10 07:40 - 2015-05-23 10:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-06-10 07:40 - 2015-05-23 10:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-06-10 07:40 - 2015-05-23 10:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-06-10 07:40 - 2015-05-23 10:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-06-10 07:40 - 2015-05-23 10:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-06-10 07:40 - 2015-05-23 10:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-06-10 07:40 - 2015-05-23 10:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-06-10 07:40 - 2015-05-23 10:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-06-10 07:40 - 2015-05-23 10:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-06-10 07:40 - 2015-05-23 10:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-06-10 07:40 - 2015-05-23 10:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-06-10 07:40 - 2015-05-23 10:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-06-10 07:40 - 2015-05-23 10:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-06-10 07:40 - 2015-05-23 03:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-06-10 07:40 - 2015-05-23 03:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-06-10 07:40 - 2015-05-23 03:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-06-10 07:40 - 2015-05-23 03:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-06-10 07:40 - 2015-05-23 03:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-06-10 07:40 - 2015-05-23 03:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-06-10 07:40 - 2015-05-23 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-06-10 07:40 - 2015-05-23 02:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-06-10 07:40 - 2015-05-23 02:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-06-10 07:40 - 2015-05-23 02:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-06-10 07:40 - 2015-05-23 02:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-06-10 07:40 - 2015-05-23 02:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-06-10 07:40 - 2015-05-23 02:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-06-10 07:40 - 2015-05-23 02:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-06-10 07:40 - 2015-05-23 02:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-06-10 07:40 - 2015-05-23 02:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-06-10 07:40 - 2015-05-23 02:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-06-10 07:40 - 2015-05-23 02:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-06-10 07:40 - 2015-05-23 02:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-06-10 07:40 - 2015-05-23 02:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-06-10 07:40 - 2015-05-23 02:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-06-10 07:40 - 2015-05-23 02:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-06-10 07:40 - 2015-05-23 02:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2015-06-10 07:40 - 2015-05-23 02:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2015-06-10 07:40 - 2015-05-23 02:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2015-06-10 07:40 - 2015-05-23 02:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2015-06-10 07:40 - 2015-05-23 02:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2015-06-10 07:40 - 2015-05-23 02:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2015-06-10 07:40 - 2015-05-23 02:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2015-06-10 07:40 - 2015-05-23 02:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-06-10 07:40 - 2015-05-23 02:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-06-10 07:40 - 2015-05-23 02:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-06-10 07:40 - 2015-05-23 02:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-06-10 07:40 - 2015-05-23 01:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-06-10 07:40 - 2015-05-23 01:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-06-10 07:40 - 2015-05-23 01:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-06-10 07:40 - 2015-05-23 01:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-06-10 07:40 - 2015-05-21 21:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
    2015-06-10 07:40 - 2015-04-30 02:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
    2015-06-10 07:40 - 2015-04-30 02:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
    2015-06-10 07:40 - 2015-04-30 02:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
    2015-06-10 07:40 - 2015-04-30 02:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
    2015-06-10 07:40 - 2015-04-30 02:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
    2015-06-10 07:40 - 2015-04-30 02:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
    2015-06-10 07:40 - 2015-04-30 02:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
    2015-06-10 07:40 - 2015-04-30 02:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
    2015-06-10 07:40 - 2015-04-30 02:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
    2015-06-10 07:40 - 2015-04-30 02:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
    2015-06-10 07:40 - 2015-04-25 02:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
    2015-06-10 07:40 - 2015-04-25 01:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
    2015-06-10 07:40 - 2015-04-11 11:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
    2015-06-08 19:40 - 2015-06-08 19:40 - 00027928 _____ C:\ComboFix.txt
    2015-06-08 19:29 - 2011-06-26 14:45 - 00256000 _____ C:\Windows\PEV.exe
    2015-06-08 19:29 - 2010-11-08 01:20 - 00208896 _____ C:\Windows\MBR.exe
    2015-06-08 19:29 - 2009-04-20 12:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
    2015-06-08 19:29 - 2000-08-31 08:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
    2015-06-08 19:29 - 2000-08-31 08:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
    2015-06-08 19:29 - 2000-08-31 08:00 - 00098816 _____ C:\Windows\sed.exe
    2015-06-08 19:29 - 2000-08-31 08:00 - 00080412 _____ C:\Windows\grep.exe
    2015-06-08 19:29 - 2000-08-31 08:00 - 00068096 _____ C:\Windows\zip.exe
    2015-06-08 19:22 - 2015-06-08 19:40 - 00000000 ____D C:\Qoobox
    2015-06-08 19:21 - 2015-06-08 19:39 - 00000000 ____D C:\Windows\erdnt
    2015-06-08 07:57 - 2015-06-08 07:57 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2015-06-08 07:57 - 2015-06-08 07:57 - 00000000 ___SD C:\Windows\system32\GWX
    2015-06-07 11:01 - 2015-06-07 11:01 - 00000207 _____ C:\Windows\tweaking.com-regbackup-LOKE-PC-Windows-7-Home-Premium-(64-bit).dat
    2015-06-07 11:01 - 2015-06-07 11:01 - 00000000 ____D C:\RegBackup
    2015-06-07 10:54 - 2015-06-07 10:55 - 00000000 ____D C:\AdwCleaner
    2015-06-07 10:19 - 2015-06-07 10:20 - 00035064 _____ C:\Windows\system32\Drivers\TrueSight.sys
    2015-06-07 10:19 - 2015-06-07 10:20 - 00000000 ____D C:\ProgramData\RogueKiller
    2015-06-07 01:14 - 2015-06-07 01:14 - 00000000 ____D C:\Users\Loke\AppData\Local\openvr
    2015-06-06 23:47 - 2015-06-06 23:47 - 00000219 _____ C:\Users\Loke\Desktop\Team Fortress 2.url
    2015-06-06 03:00 - 2015-06-06 14:31 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
    2015-06-06 02:59 - 2015-06-06 02:59 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-06-05 18:57 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
    2015-06-05 16:20 - 2015-06-05 16:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
    2015-06-05 14:46 - 2015-06-13 20:59 - 00000000 ____D C:\FRST
    2015-06-05 01:53 - 2014-06-27 10:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
    2015-06-05 01:53 - 2014-06-27 09:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
    2015-06-04 18:23 - 2015-06-04 18:23 - 00000000 ____D C:\Users\Loke\Documents\My Games
    2015-06-04 18:23 - 2015-06-04 18:23 - 00000000 ____D C:\Users\Loke\AppData\Local\My Games
    2015-06-04 17:44 - 2015-06-04 17:44 - 00000220 _____ C:\Users\Loke\Desktop\Sid Meier's Civilization V.url
    2015-06-04 17:34 - 2015-06-04 17:34 - 00002160 _____ C:\Users\Loke\Desktop\Google Earth.lnk
    2015-06-04 17:32 - 2015-06-04 17:32 - 00002160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
    2015-06-04 14:36 - 2015-06-08 19:25 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2015-06-04 14:36 - 2015-06-08 19:25 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
    2015-06-04 14:36 - 2015-06-04 14:36 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
    2015-06-04 11:53 - 2015-06-04 11:53 - 00000000 ____D C:\Users\Loke\Documents\Fax
    2015-06-04 11:42 - 2014-07-09 10:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
    2015-06-04 11:42 - 2014-07-09 10:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
    2015-06-04 11:42 - 2014-07-09 10:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
    2015-06-04 11:42 - 2014-07-09 10:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
    2015-06-04 11:42 - 2014-07-09 10:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
    2015-06-04 11:42 - 2014-07-09 09:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
    2015-06-04 11:42 - 2014-06-24 11:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
    2015-06-04 11:42 - 2014-06-24 10:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
    2015-06-04 11:42 - 2013-11-26 16:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
    2015-06-04 11:42 - 2013-11-23 06:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
    2015-06-04 11:41 - 2012-02-11 14:36 - 00559104 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
    2015-06-04 11:41 - 2012-02-11 14:36 - 00067072 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
    2015-06-04 08:23 - 2015-04-20 11:17 - 01647104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2015-06-04 08:23 - 2015-04-20 11:17 - 01179136 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
    2015-06-04 08:23 - 2015-04-20 10:56 - 01250816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2015-06-04 08:23 - 2015-04-18 11:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
    2015-06-04 08:23 - 2015-04-18 10:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
    2015-06-04 08:19 - 2015-02-04 11:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
    2015-06-04 08:19 - 2015-02-04 10:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
    2015-06-04 08:19 - 2015-02-03 11:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2015-06-04 08:19 - 2015-02-03 11:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2015-06-04 02:30 - 2015-01-09 07:44 - 00419936 _____ C:\Windows\SysWOW64\locale.nls
    2015-06-04 02:30 - 2015-01-09 07:43 - 00419936 _____ C:\Windows\system32\locale.nls
    2015-06-04 02:22 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
    2015-06-04 02:14 - 2015-06-04 02:14 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
    2015-06-04 02:13 - 2015-06-04 02:13 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
    2015-06-04 02:13 - 2015-06-04 02:13 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
    2015-06-04 02:13 - 2015-06-04 02:13 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
    2015-06-04 02:13 - 2015-06-04 02:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
    2015-06-04 02:13 - 2015-06-04 02:13 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
    2015-06-04 02:13 - 2015-06-04 02:13 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
    2015-06-04 02:08 - 2015-06-04 02:08 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
    2015-06-04 02:08 - 2015-06-04 02:08 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
     
  19. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    2015-06-04 02:04 - 2015-06-04 02:23 - 00009859 _____ C:\Windows\IE11_main.log
    2015-06-04 01:41 - 2015-06-10 07:59 - 00000000 ____D C:\Windows\system32\MRT
    2015-06-04 01:41 - 2015-06-10 07:55 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-06-04 01:40 - 2015-06-04 01:40 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0
    2015-06-04 01:23 - 2015-01-09 11:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
    2015-06-04 01:23 - 2015-01-09 11:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
    2015-06-04 01:23 - 2015-01-09 11:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
    2015-06-04 01:23 - 2015-01-09 10:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
    2015-06-04 01:09 - 2015-06-10 18:17 - 00000000 ___SD C:\Windows\system32\CompatTel
    2015-06-04 01:09 - 2015-06-10 18:17 - 00000000 ____D C:\Windows\system32\appraiser
    2015-06-04 00:39 - 2015-06-04 01:40 - 00284224 _____ C:\Windows\msxml4-KB973688-enu.LOG
    2015-06-04 00:14 - 2015-06-04 01:40 - 00288320 _____ C:\Windows\msxml4-KB954430-enu.LOG
    2015-06-04 00:13 - 2015-06-04 00:13 - 00000419 _____ C:\Windows\BRWMARK.INI
    2015-06-03 23:58 - 2012-07-26 11:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
    2015-06-03 23:58 - 2012-07-26 11:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
    2015-06-03 23:58 - 2012-07-26 11:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
    2015-06-03 23:58 - 2012-07-26 11:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
    2015-06-03 23:58 - 2012-07-26 11:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
    2015-06-03 23:58 - 2012-07-26 10:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
    2015-06-03 23:58 - 2012-07-26 10:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
    2015-06-03 23:58 - 2012-06-02 22:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
    2015-06-03 23:55 - 2015-05-01 21:17 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-06-03 23:55 - 2015-05-01 21:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-06-03 23:53 - 2015-06-03 23:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2015-06-03 23:52 - 2015-06-03 23:52 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2015-06-03 23:52 - 2015-06-03 23:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2015-06-03 23:52 - 2012-03-01 14:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
    2015-06-03 23:52 - 2012-03-01 14:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
    2015-06-03 23:52 - 2012-03-01 13:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
    2015-06-03 23:46 - 2014-07-01 06:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
    2015-06-03 23:46 - 2014-07-01 06:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
    2015-06-03 23:46 - 2014-06-06 14:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
    2015-06-03 23:46 - 2014-06-06 14:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
    2015-06-03 23:46 - 2014-03-10 05:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
    2015-06-03 23:46 - 2014-03-10 05:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
    2015-06-03 23:46 - 2014-03-10 05:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
    2015-06-03 23:46 - 2014-03-10 05:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
    2015-06-03 23:45 - 2014-07-17 10:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
    2015-06-03 23:45 - 2014-07-17 10:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
    2015-06-03 23:45 - 2014-07-17 10:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
    2015-06-03 23:45 - 2014-07-17 10:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
    2015-06-03 23:45 - 2014-07-17 09:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
    2015-06-03 23:45 - 2014-07-17 09:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
    2015-06-03 23:45 - 2014-07-17 09:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
    2015-06-03 23:45 - 2014-07-17 09:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
    2015-06-03 23:45 - 2012-04-26 13:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
    2015-06-03 23:45 - 2012-04-26 13:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
    2015-06-03 23:44 - 2014-03-04 17:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
    2015-06-03 23:44 - 2014-03-04 17:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
    2015-06-03 23:44 - 2013-10-04 10:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
    2015-06-03 23:44 - 2013-10-04 10:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
    2015-06-03 23:44 - 2013-10-04 09:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
    2015-06-03 23:44 - 2013-10-04 09:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
    2015-06-03 23:44 - 2013-02-15 14:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
    2015-06-03 23:44 - 2013-02-15 14:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
    2015-06-03 23:44 - 2013-02-15 11:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
    2015-06-03 23:43 - 2015-02-03 11:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
    2015-06-03 23:43 - 2015-02-03 11:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
    2015-06-03 23:43 - 2015-02-03 11:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
    2015-06-03 23:43 - 2015-02-03 11:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
    2015-06-03 23:43 - 2015-02-03 11:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
    2015-06-03 23:43 - 2015-02-03 11:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
    2015-06-03 23:43 - 2015-02-03 11:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
    2015-06-03 23:43 - 2015-02-03 11:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
    2015-06-03 23:43 - 2015-02-03 11:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
    2015-06-03 23:43 - 2015-02-03 11:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
    2015-06-03 23:43 - 2015-02-03 11:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
    2015-06-03 23:43 - 2015-02-03 11:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
    2015-06-03 23:43 - 2015-02-03 11:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
    2015-06-03 23:43 - 2015-02-03 11:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
    2015-06-03 23:43 - 2015-02-03 11:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
    2015-06-03 23:43 - 2015-02-03 10:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
    2015-06-03 23:43 - 2014-11-01 06:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
    2015-06-03 23:43 - 2014-06-28 08:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
    2015-06-03 23:43 - 2014-06-28 08:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
    2015-06-03 23:43 - 2014-03-04 17:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
    2015-06-03 23:43 - 2014-03-04 17:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
    2015-06-03 23:42 - 2015-01-31 07:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
    2015-06-03 23:42 - 2014-10-14 10:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
    2015-06-03 23:42 - 2014-10-14 10:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
    2015-06-03 23:42 - 2014-10-14 09:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2015-06-03 23:42 - 2014-06-03 18:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
    2015-06-03 23:42 - 2014-06-03 18:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
    2015-06-03 23:42 - 2014-06-03 18:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
    2015-06-03 23:42 - 2014-06-03 17:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
    2015-06-03 23:42 - 2014-06-03 17:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
    2015-06-03 23:42 - 2013-02-27 13:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
    2015-06-03 23:41 - 2012-12-07 21:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
    2015-06-03 23:41 - 2012-12-07 21:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
    2015-06-03 23:41 - 2012-12-07 20:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
    2015-06-03 23:41 - 2012-12-07 20:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
    2015-06-03 23:41 - 2012-12-07 19:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
    2015-06-03 23:41 - 2012-12-07 19:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
    2015-06-03 23:41 - 2012-12-07 19:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs
    2015-06-03 23:41 - 2012-12-07 18:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs
    2015-06-03 23:40 - 2015-06-03 23:40 - 00000690 _____ C:\Users\Loke\Desktop\profile.txt
    2015-06-03 23:40 - 2014-11-11 11:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
    2015-06-03 23:40 - 2014-11-11 10:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
    2015-06-03 23:39 - 2014-11-08 11:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
    2015-06-03 23:39 - 2014-11-08 10:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
    2015-06-03 23:38 - 2015-02-13 13:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
    2015-06-03 23:38 - 2015-02-13 13:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
    2015-06-03 23:38 - 2013-07-26 10:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
    2015-06-03 23:38 - 2013-07-26 09:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
    2015-06-03 23:38 - 2013-05-13 13:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
    2015-06-03 23:38 - 2013-05-13 11:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
    2015-06-03 23:38 - 2013-05-13 11:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
    2015-06-03 23:38 - 2013-05-13 11:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
    2015-06-03 23:38 - 2012-10-04 01:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
    2015-06-03 23:38 - 2012-10-04 01:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
    2015-06-03 23:38 - 2012-10-04 01:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
    2015-06-03 23:38 - 2012-10-04 01:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
    2015-06-03 23:38 - 2012-10-04 01:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
    2015-06-03 23:38 - 2012-10-04 00:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
    2015-06-03 23:38 - 2012-10-04 00:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
    2015-06-03 23:38 - 2012-10-04 00:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
    2015-06-03 23:38 - 2012-06-06 14:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
    2015-06-03 23:38 - 2012-06-06 13:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
    2015-06-03 23:37 - 2015-04-13 11:28 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
    2015-06-03 23:37 - 2013-12-04 10:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
    2015-06-03 23:37 - 2013-12-04 10:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
    2015-06-03 23:37 - 2013-12-04 10:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
    2015-06-03 23:37 - 2013-12-04 10:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
    2015-06-03 23:37 - 2013-12-04 10:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
    2015-06-03 23:37 - 2013-12-04 10:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
    2015-06-03 23:37 - 2013-12-04 10:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
    2015-06-03 23:37 - 2013-12-04 10:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
    2015-06-03 23:37 - 2013-12-04 10:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
    2015-06-03 23:37 - 2013-12-04 10:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
    2015-06-03 23:37 - 2013-12-04 10:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
    2015-06-03 23:37 - 2013-12-04 10:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
    2015-06-03 23:37 - 2013-12-04 10:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
    2015-06-03 23:37 - 2013-12-04 10:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
    2015-06-03 23:37 - 2013-12-04 09:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
    2015-06-03 23:37 - 2013-12-04 09:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
    2015-06-03 23:37 - 2013-12-04 09:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
    2015-06-03 23:37 - 2013-12-04 09:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
    2015-06-03 23:37 - 2013-05-10 13:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
    2015-06-03 23:37 - 2013-05-10 11:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
    2015-06-03 23:36 - 2015-03-04 12:41 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-06-03 23:36 - 2015-03-04 12:41 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-06-03 23:36 - 2015-03-04 12:41 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-06-03 23:36 - 2015-03-04 12:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-06-03 23:36 - 2015-03-04 12:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
    2015-06-03 23:36 - 2015-03-04 12:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
    2015-06-03 23:36 - 2015-03-04 12:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
    2015-06-03 23:36 - 2015-01-28 07:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
    2015-06-03 23:36 - 2014-11-26 11:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
    2015-06-03 23:36 - 2014-11-26 11:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2015-06-03 23:36 - 2014-10-30 10:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
    2015-06-03 23:36 - 2014-10-30 09:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
    2015-06-03 23:36 - 2014-10-04 10:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2015-06-03 23:36 - 2014-10-04 09:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2015-06-03 23:36 - 2014-10-04 09:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
    2015-06-03 23:36 - 2014-08-12 10:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
    2015-06-03 23:36 - 2014-08-12 09:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
    2015-06-03 23:36 - 2014-06-19 06:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
    2015-06-03 23:36 - 2014-06-19 06:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
    2015-06-03 23:36 - 2014-06-16 10:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
    2015-06-03 23:36 - 2013-08-05 10:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
    2015-06-03 23:36 - 2013-04-10 14:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
    2015-06-03 23:36 - 2012-10-10 02:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
    2015-06-03 23:36 - 2012-10-10 02:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
    2015-06-03 23:36 - 2012-10-10 01:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
    2015-06-03 23:36 - 2012-10-10 01:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
    2015-06-03 23:36 - 2012-08-22 05:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
    2015-06-03 23:36 - 2011-02-03 19:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
    2015-06-03 23:35 - 2015-04-08 11:29 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-06-03 23:35 - 2015-04-08 11:29 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-06-03 23:35 - 2015-04-08 11:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-06-03 23:35 - 2015-03-25 11:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-06-03 23:35 - 2015-03-25 11:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-06-03 23:35 - 2015-03-25 11:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-06-03 23:35 - 2015-03-25 11:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-06-03 23:35 - 2015-03-25 11:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-06-03 23:35 - 2015-03-25 11:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-06-03 23:35 - 2015-03-25 11:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-06-03 23:35 - 2015-03-25 11:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-06-03 23:35 - 2015-03-25 11:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-06-03 23:35 - 2015-02-18 15:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
    2015-06-03 23:35 - 2015-02-18 15:04 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
    2015-06-03 23:35 - 2014-08-01 19:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
    2015-06-03 23:35 - 2014-08-01 19:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
    2015-06-03 23:35 - 2014-06-18 10:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
    2015-06-03 23:35 - 2014-06-18 09:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
    2015-06-03 23:35 - 2014-04-05 10:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
    2015-06-03 23:35 - 2014-04-05 10:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
    2015-06-03 23:35 - 2014-01-24 10:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
    2015-06-03 23:35 - 2013-11-26 19:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
    2015-06-03 23:35 - 2013-09-08 10:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
    2015-06-03 23:35 - 2013-09-08 10:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
    2015-06-03 23:35 - 2013-06-26 06:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
    2015-06-03 23:35 - 2013-04-26 07:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
    2015-06-03 23:35 - 2013-04-01 06:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
    2015-06-03 23:35 - 2012-11-29 06:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
    2015-06-03 23:35 - 2012-11-29 06:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
    2015-06-03 23:35 - 2012-11-29 06:56 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
    2015-06-03 23:34 - 2015-03-10 11:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
    2015-06-03 23:34 - 2015-03-10 11:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
    2015-06-03 23:34 - 2015-03-10 11:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2015-06-03 23:34 - 2015-03-10 11:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
    2015-06-03 23:34 - 2015-03-04 12:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
    2015-06-03 23:34 - 2015-03-04 12:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
    2015-06-03 23:34 - 2015-03-04 12:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
    2015-06-03 23:34 - 2015-02-20 12:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
    2015-06-03 23:34 - 2015-02-20 12:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
    2015-06-03 23:34 - 2015-02-20 12:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
    2015-06-03 23:34 - 2015-02-20 12:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
    2015-06-03 23:34 - 2015-02-20 12:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
    2015-06-03 23:34 - 2015-02-20 12:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2015-06-03 23:34 - 2015-02-20 12:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
    2015-06-03 23:34 - 2015-02-20 12:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
    2015-06-03 23:34 - 2015-02-20 11:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
    2015-06-03 23:34 - 2015-02-20 11:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2015-06-03 23:34 - 2015-02-03 11:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
    2015-06-03 23:34 - 2015-02-03 11:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
    2015-06-03 23:34 - 2015-01-29 11:19 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
    2015-06-03 23:34 - 2015-01-29 11:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
    2015-06-03 23:34 - 2014-12-19 09:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
    2015-06-03 23:34 - 2014-12-12 01:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
    2015-06-03 23:34 - 2014-12-06 12:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
    2015-06-03 23:34 - 2014-12-06 11:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
    2015-06-03 23:34 - 2014-12-06 11:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
    2015-06-03 23:34 - 2014-10-03 10:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
    2015-06-03 23:34 - 2014-10-03 10:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
    2015-06-03 23:34 - 2014-10-03 10:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
    2015-06-03 23:34 - 2014-10-03 10:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
    2015-06-03 23:34 - 2014-10-03 10:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
    2015-06-03 23:34 - 2014-10-03 09:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
    2015-06-03 23:34 - 2014-10-03 09:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
    2015-06-03 23:34 - 2014-10-03 09:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
    2015-06-03 23:34 - 2014-10-03 09:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
    2015-06-03 23:34 - 2014-10-03 09:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
    2015-06-03 23:34 - 2014-09-04 13:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
    2015-06-03 23:34 - 2014-09-04 13:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
    2015-06-03 23:34 - 2014-06-06 18:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
    2015-06-03 23:34 - 2014-06-06 17:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
    2015-06-03 23:34 - 2014-05-30 14:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
    2015-06-03 23:34 - 2014-03-26 22:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
    2015-06-03 23:34 - 2014-03-26 22:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
    2015-06-03 23:34 - 2014-03-26 22:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
    2015-06-03 23:34 - 2014-03-26 22:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
    2015-06-03 23:34 - 2014-02-04 10:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
    2015-06-03 23:34 - 2014-02-04 10:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
    2015-06-03 23:34 - 2014-02-04 10:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
    2015-06-03 23:34 - 2014-02-04 10:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
    2015-06-03 23:34 - 2014-02-04 10:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
    2015-06-03 23:34 - 2014-01-29 10:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
    2015-06-03 23:34 - 2014-01-29 10:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
    2015-06-03 23:34 - 2013-10-30 10:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
    2015-06-03 23:34 - 2013-10-30 10:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
    2015-06-03 23:34 - 2013-10-19 10:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
    2015-06-03 23:34 - 2013-10-19 09:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
    2015-06-03 23:34 - 2013-10-12 10:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
    2015-06-03 23:34 - 2013-10-12 10:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
    2015-06-03 23:34 - 2013-10-12 10:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
    2015-06-03 23:34 - 2013-10-12 10:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
    2015-06-03 23:34 - 2013-10-12 10:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
    2015-06-03 23:34 - 2013-10-12 10:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
    2015-06-03 23:34 - 2013-10-12 10:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
    2015-06-03 23:34 - 2013-10-12 10:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
    2015-06-03 23:34 - 2013-10-12 10:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
    2015-06-03 23:34 - 2013-10-12 09:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
    2015-06-03 23:34 - 2013-10-12 09:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
    2015-06-03 23:34 - 2013-10-12 09:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
    2015-06-03 23:34 - 2013-10-12 09:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
    2015-06-03 23:34 - 2013-10-04 10:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
    2015-06-03 23:34 - 2013-10-04 09:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
    2015-06-03 23:34 - 2013-07-25 17:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
    2015-06-03 23:34 - 2013-07-25 16:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
    2015-06-03 23:34 - 2013-07-04 20:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
    2015-06-03 23:34 - 2013-07-04 20:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
    2015-06-03 23:34 - 2013-07-04 19:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
    2015-06-03 23:34 - 2013-07-04 19:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
    2015-06-03 23:34 - 2013-07-03 12:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
    2015-06-03 23:34 - 2013-07-03 12:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
    2015-06-03 23:34 - 2013-07-03 12:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
    2015-06-03 23:34 - 2013-02-12 12:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
     
  20. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    2015-06-03 23:34 - 2012-09-26 06:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
    2015-06-03 23:34 - 2012-09-26 06:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
    2015-06-03 23:34 - 2012-05-14 13:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
    2015-06-03 23:34 - 2011-11-17 14:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
    2015-06-03 23:34 - 2011-11-17 13:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
    2015-06-03 23:33 - 2015-03-05 13:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2015-06-03 23:33 - 2015-03-05 12:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2015-06-03 23:33 - 2015-02-25 11:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
    2015-06-03 23:33 - 2015-01-17 10:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2015-06-03 23:33 - 2015-01-17 10:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
    2015-06-03 23:33 - 2014-12-19 11:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
    2015-06-03 23:33 - 2014-12-08 11:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
    2015-06-03 23:33 - 2014-12-08 10:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
    2015-06-03 23:33 - 2014-11-11 09:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
    2015-06-03 23:33 - 2014-10-25 09:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
    2015-06-03 23:33 - 2014-10-25 09:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
    2015-06-03 23:33 - 2014-04-25 10:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
    2015-06-03 23:33 - 2014-04-25 10:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
    2015-06-03 23:33 - 2014-01-28 10:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
    2015-06-03 23:33 - 2013-11-27 09:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
    2015-06-03 23:33 - 2013-11-27 09:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
    2015-06-03 23:33 - 2013-11-27 09:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
    2015-06-03 23:33 - 2013-11-27 09:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
    2015-06-03 23:33 - 2013-11-27 09:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
    2015-06-03 23:33 - 2013-07-12 18:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
    2015-06-03 23:33 - 2013-04-26 13:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
    2015-06-03 23:33 - 2013-04-26 12:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
    2015-06-03 23:33 - 2013-03-19 13:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
    2015-06-03 23:33 - 2013-01-24 14:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
    2015-06-03 23:33 - 2012-11-23 11:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
    2015-06-03 23:33 - 2012-11-02 13:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
    2015-06-03 23:33 - 2012-11-02 13:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
    2015-06-03 23:33 - 2012-08-23 02:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
    2015-06-03 23:33 - 2012-07-05 06:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
    2015-06-03 23:33 - 2012-07-05 06:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
    2015-06-03 23:33 - 2012-07-05 06:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
    2015-06-03 23:33 - 2012-07-05 05:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
    2015-06-03 23:33 - 2012-07-05 05:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
    2015-06-03 23:33 - 2012-07-05 04:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
    2015-06-03 23:33 - 2012-03-17 15:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
    2015-06-03 23:25 - 2013-08-28 09:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
    2015-06-03 23:22 - 2014-07-14 10:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2015-06-03 23:22 - 2014-07-14 09:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2015-06-03 22:55 - 2015-06-03 22:55 - 00000000 ____D C:\Windows\NAPP_Dism_Log
    2015-06-03 22:40 - 2015-06-03 22:40 - 00000000 ____D C:\ProgramData\Nexon
    2015-06-03 22:22 - 2015-06-03 22:22 - 00001162 _____ C:\Users\Public\Desktop\MapleStorySEA.lnk
    2015-06-03 22:22 - 2015-06-03 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wizet
    2015-06-03 22:17 - 2015-06-03 22:17 - 00002435 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
    2015-06-03 22:17 - 2015-06-03 22:17 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
    2015-06-03 22:16 - 2015-06-03 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    2015-06-03 22:16 - 2015-06-03 22:16 - 00000000 ____D C:\Program Files\PlayReady
    2015-06-03 22:16 - 2015-06-03 22:16 - 00000000 ____D C:\Program Files (x86)\PlayReady
    2015-06-03 22:13 - 2015-06-13 17:18 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
    2015-06-03 22:13 - 2015-06-13 14:09 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
    2015-06-03 22:13 - 2015-06-03 22:13 - 00003492 _____ C:\Windows\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d
    2015-06-03 22:13 - 2015-06-03 22:13 - 00003188 _____ C:\Windows\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon
    2015-06-03 22:13 - 2015-06-03 22:13 - 00000000 ____D C:\ProgramData\Intel
    2015-06-03 22:13 - 2015-06-03 22:13 - 00000000 ____D C:\Program Files\Intel
    2015-06-03 22:13 - 2012-02-07 17:40 - 00015128 _____ C:\Windows\system32\Drivers\IntelMEFWVer.dll
    2015-06-03 22:12 - 2015-06-13 14:09 - 00000000 ____D C:\ProgramData\NVIDIA
    2015-06-03 22:12 - 2015-06-03 22:12 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
    2015-06-03 22:12 - 2012-03-07 15:02 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Macromedia
    2015-06-03 22:12 - 2009-07-14 12:54 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-06-03 22:12 - 2009-07-14 12:49 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2015-06-03 22:11 - 2015-06-03 22:13 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
    2015-06-03 22:11 - 2015-06-03 22:12 - 00000000 ____D C:\Program Files\NVIDIA Corporation
    2015-06-03 22:11 - 2015-06-03 22:12 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
    2015-06-03 22:11 - 2015-06-03 22:11 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
    2015-06-03 22:11 - 2015-06-03 22:11 - 00000000 ____D C:\Program Files (x86)\Wizet
    2015-06-03 22:11 - 2012-05-09 20:27 - 25743168 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 25248064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 19607872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 18044224 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 17551680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 15322432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 14299456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
    2015-06-03 22:11 - 2012-05-09 20:27 - 10194752 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 08139072 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 08105792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 05982528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02881856 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02741568 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02681664 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02524992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02445120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 02368832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 01738048 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco64.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 01468224 _____ (NVIDIA Corporation) C:\Windows\system32\nvgenco64.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00949056 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00818496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00364352 _____ (NVIDIA Corporation) C:\Windows\system32\nvdecodemft.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00301376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00246592 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00202048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00068928 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00061248 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2015-06-03 22:11 - 2012-05-09 20:27 - 00028992 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
    2015-06-03 22:11 - 2012-05-09 20:27 - 00014324 _____ C:\Windows\system32\nvinfo.pb
    2015-06-03 22:11 - 2012-05-09 11:54 - 03149632 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 02619385 _____ C:\Windows\system32\nvcoproc.bin
    2015-06-03 22:11 - 2012-05-09 11:54 - 02561856 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 00889664 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
    2015-06-03 22:11 - 2012-05-09 11:54 - 00858944 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 00118080 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 00063296 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
    2015-06-03 22:11 - 2012-05-09 11:54 - 00055616 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
    2015-06-03 22:11 - 2012-05-09 11:41 - 06151488 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
    2015-06-03 22:11 - 2012-04-19 01:08 - 01451840 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
    2015-06-03 22:11 - 2012-04-19 01:08 - 00188736 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
    2015-06-03 22:11 - 2012-04-19 01:08 - 00031040 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
    2015-06-03 22:10 - 2011-11-30 10:40 - 00568600 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStor.sys
    2015-06-03 22:05 - 2015-06-03 22:07 - 00001874 _____ C:\Windows\WinRE_Settings.log
    2015-06-03 22:05 - 2015-06-03 22:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AcerSystem
    2015-06-03 22:05 - 2015-06-03 22:05 - 00000000 ____D C:\book
    2015-06-03 22:04 - 2015-06-03 22:04 - 00000025 _____ C:\Windows\mSataSettings.log
    2015-06-03 22:01 - 2015-06-13 20:29 - 01775074 _____ C:\Windows\WindowsUpdate.log
    2015-06-03 22:01 - 2015-06-03 22:01 - 00000000 ___HD C:\Program Files (x86)\Temp
    2015-06-03 22:01 - 2015-06-03 22:01 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
    2015-06-03 22:01 - 2015-06-03 22:01 - 00000000 ____D C:\Program Files\Realtek
    2015-06-03 22:01 - 2015-06-03 22:01 - 00000000 ____D C:\Program Files (x86)\Realtek
    2015-06-03 22:01 - 2011-11-16 12:11 - 00099944 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
    2015-06-03 22:01 - 2011-11-16 11:58 - 02950632 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
    2015-06-03 22:01 - 2011-11-15 13:57 - 02612840 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
    2015-06-03 22:01 - 2011-11-15 13:04 - 00015464 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
    2015-06-03 22:01 - 2011-11-14 17:11 - 02007040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
    2015-06-03 22:01 - 2011-11-14 17:08 - 00181324 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
    2015-06-03 22:01 - 2011-11-14 14:38 - 02361448 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
    2015-06-03 22:01 - 2011-11-14 14:38 - 01966184 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
    2015-06-03 22:01 - 2011-11-10 13:47 - 00219752 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
    2015-06-03 22:01 - 2011-10-18 13:55 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
    2015-06-03 22:01 - 2011-09-02 14:21 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
    2015-06-03 22:01 - 2011-09-02 14:21 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
    2015-06-03 22:01 - 2011-09-02 14:21 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
    2015-06-03 22:01 - 2011-08-31 19:12 - 01698408 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
    2015-06-03 22:01 - 2011-08-23 17:00 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
    2015-06-03 22:01 - 2011-08-06 01:29 - 00527872 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
    2015-06-03 22:01 - 2011-08-06 01:29 - 00515584 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
    2015-06-03 22:01 - 2011-08-06 01:29 - 00439808 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
    2015-06-03 22:01 - 2011-07-28 00:55 - 02604376 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
    2015-06-03 22:01 - 2011-07-28 00:55 - 02132824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
    2015-06-03 22:01 - 2011-07-22 19:35 - 01247848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
    2015-06-03 22:01 - 2011-07-08 14:34 - 00065432 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
    2015-06-03 22:01 - 2011-06-30 16:14 - 01560168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
    2015-06-03 22:01 - 2011-06-27 14:45 - 03768152 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll
    2015-06-03 22:01 - 2011-06-14 11:13 - 00177088 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
    2015-06-03 22:01 - 2011-05-31 09:42 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
    2015-06-03 22:01 - 2011-05-05 15:24 - 02085440 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 03308376 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 00426328 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 00136024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 00118104 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
    2015-06-03 22:01 - 2011-05-02 14:27 - 00074072 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
    2015-06-03 22:01 - 2011-03-17 12:17 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
    2015-06-03 22:01 - 2011-03-07 17:11 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
    2015-06-03 22:01 - 2010-11-29 14:36 - 00702808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek2.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
    2015-06-03 22:01 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
    2015-06-03 22:01 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
    2015-06-03 22:01 - 2010-10-03 13:46 - 00341336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
    2015-06-03 22:01 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
    2015-06-03 22:01 - 2010-07-22 16:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
    2015-06-03 22:01 - 2010-07-22 16:37 - 00200800 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
    2015-06-03 22:01 - 2010-05-06 17:34 - 00334680 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
    2015-06-03 22:01 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
    2015-06-03 22:01 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
    2015-06-03 22:01 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
    2015-06-03 22:01 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
    2015-06-03 22:01 - 2009-11-17 18:12 - 00108960 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
    2015-06-03 21:59 - 2015-06-03 21:59 - 00038499 _____ C:\Windows\ATIDetect.txt
    2015-06-03 21:58 - 2015-06-03 21:58 - 00001285 _____ C:\Windows\system32\RaCoInst.log
    2015-06-03 20:20 - 2015-06-03 20:20 - 00000000 ____D C:\Users\Loke\Tracing
    2015-06-03 20:17 - 2015-06-03 20:17 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk
    2015-06-03 20:17 - 2015-06-03 20:17 - 00000000 ___RD C:\Program Files (x86)\Skype
    2015-06-03 20:17 - 2015-06-03 20:17 - 00000000 ____D C:\Users\Loke\AppData\Local\Skype
    2015-06-03 20:17 - 2015-06-03 20:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2015-06-03 20:07 - 2015-06-12 02:38 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Skype
    2015-06-03 20:06 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
    2015-06-03 20:06 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
    2015-06-03 20:06 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
    2015-06-03 20:06 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
    2015-06-03 20:06 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
    2015-06-03 20:06 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
    2015-06-03 20:06 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
    2015-06-03 20:06 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
    2015-06-03 20:06 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
    2015-06-03 20:06 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
    2015-06-03 20:06 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
    2015-06-03 20:06 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
    2015-06-03 20:06 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
    2015-06-03 20:06 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
    2015-06-03 20:06 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
    2015-06-03 20:06 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
    2015-06-03 20:06 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
    2015-06-03 20:06 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
    2015-06-03 20:06 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
    2015-06-03 20:06 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
    2015-06-03 20:06 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
    2015-06-03 20:06 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
    2015-06-03 20:06 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
    2015-06-03 20:06 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
    2015-06-03 20:06 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
    2015-06-03 20:06 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
    2015-06-03 20:06 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
    2015-06-03 20:06 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
    2015-06-03 20:06 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
    2015-06-03 20:06 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
    2015-06-03 20:06 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
    2015-06-03 20:06 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
    2015-06-03 20:06 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
    2015-06-03 20:06 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
    2015-06-03 20:06 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
    2015-06-03 20:06 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
    2015-06-03 20:06 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
    2015-06-03 20:06 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
    2015-06-03 20:06 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
    2015-06-03 20:06 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
    2015-06-03 20:06 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
    2015-06-03 20:06 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
    2015-06-03 20:06 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
    2015-06-03 20:06 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
    2015-06-03 20:06 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
    2015-06-03 20:06 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
    2015-06-03 20:06 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
    2015-06-03 20:06 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
    2015-06-03 20:06 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
    2015-06-03 20:06 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
    2015-06-03 20:06 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
    2015-06-03 20:06 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
    2015-06-03 20:06 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
    2015-06-03 20:06 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
    2015-06-03 20:06 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
    2015-06-03 20:06 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
    2015-06-03 20:06 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
    2015-06-03 20:06 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
    2015-06-03 20:06 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
    2015-06-03 20:06 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
    2015-06-03 20:06 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
    2015-06-03 20:06 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
    2015-06-03 20:06 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
    2015-06-03 20:06 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
    2015-06-03 20:06 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
    2015-06-03 20:06 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
    2015-06-03 20:06 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
    2015-06-03 20:06 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
    2015-06-03 20:06 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
    2015-06-03 20:06 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
    2015-06-03 20:06 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
    2015-06-03 20:06 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
    2015-06-03 20:06 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
    2015-06-03 20:06 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
    2015-06-03 20:06 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
    2015-06-03 20:06 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
    2015-06-03 20:06 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
    2015-06-03 20:06 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
    2015-06-03 20:06 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
    2015-06-03 20:06 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
    2015-06-03 20:06 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
    2015-06-03 20:06 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
    2015-06-03 20:06 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
    2015-06-03 20:06 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
    2015-06-03 20:06 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
    2015-06-03 20:06 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
    2015-06-03 20:06 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
    2015-06-03 20:06 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
    2015-06-03 20:06 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
    2015-06-03 20:06 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
    2015-06-03 20:06 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
    2015-06-03 20:06 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
    2015-06-03 20:06 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
    2015-06-03 20:06 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
    2015-06-03 20:06 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
     
  21. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    2015-06-03 20:06 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
    2015-06-03 20:06 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
    2015-06-03 20:06 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
    2015-06-03 20:06 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
    2015-06-03 20:06 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
    2015-06-03 20:06 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
    2015-06-03 20:06 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
    2015-06-03 20:06 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
    2015-06-03 20:06 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
    2015-06-03 20:06 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
    2015-06-03 20:06 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
    2015-06-03 20:06 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
    2015-06-03 20:06 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
    2015-06-03 20:06 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
    2015-06-03 20:06 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
    2015-06-03 19:40 - 2015-06-06 14:33 - 00001945 _____ C:\Windows\epplauncher.mif
    2015-06-03 14:09 - 2015-06-03 14:09 - 00262144 _____ C:\Windows\system32\config\ELAM
    2015-06-03 13:44 - 2015-06-03 13:44 - 00000219 _____ C:\Users\Loke\Desktop\Counter-Strike Global Offensive.url
    2015-06-03 13:35 - 2015-06-03 13:35 - 00000000 ___RD C:\Users\Loke\Desktop\poniponiponi
    2015-06-03 13:20 - 2015-06-03 13:20 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Gyazo
    2015-06-03 13:19 - 2015-06-03 14:19 - 00000000 ____D C:\Program Files (x86)\Gyazo
    2015-06-03 13:19 - 2015-06-03 13:19 - 00003740 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine
    2015-06-03 13:19 - 2015-06-03 13:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo
    2015-06-03 12:49 - 2015-06-06 23:47 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
    2015-06-03 12:49 - 2015-06-03 12:49 - 00000219 _____ C:\Users\Loke\Desktop\Dota 2.url
    2015-06-03 11:43 - 2015-06-03 11:43 - 00000000 ____D C:\Users\Loke\AppData\Local\Steam
    2015-06-03 11:42 - 2015-06-13 14:09 - 00000000 ____D C:\Program Files (x86)\Steam
    2015-06-03 11:42 - 2015-06-03 11:42 - 00000967 _____ C:\Users\Public\Desktop\Steam.lnk
    2015-06-03 11:42 - 2015-06-03 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    2015-06-03 07:45 - 2012-02-17 14:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
    2015-06-03 07:45 - 2012-02-17 13:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
    2015-06-03 07:45 - 2012-02-17 12:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
    2015-06-03 07:44 - 2015-06-03 07:44 - 00000000 ____D C:\Users\Loke\AppData\Local\EgisTec IPS
    2015-06-03 07:39 - 2015-06-10 07:51 - 00002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2015-06-03 07:39 - 2015-06-03 07:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-06-03 07:38 - 2015-06-13 20:50 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-06-03 07:38 - 2015-06-13 14:09 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-06-03 07:38 - 2015-06-04 17:32 - 00000000 ____D C:\Program Files (x86)\Google
    2015-06-03 07:38 - 2015-06-03 07:45 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-06-03 07:38 - 2015-06-03 07:45 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-06-03 07:38 - 2015-06-03 07:39 - 00000000 ____D C:\Users\Loke\AppData\Local\Google
    2015-06-03 07:37 - 2015-06-03 07:38 - 00000000 ____D C:\Users\Loke\AppData\Local\Deployment
    2015-06-03 07:37 - 2015-06-03 07:37 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Adobe
    2015-06-03 07:37 - 2015-06-03 07:37 - 00000000 ____D C:\Users\Loke\AppData\Local\Apps\2.0
    2015-06-03 07:36 - 2015-06-04 08:14 - 00001417 _____ C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-06-03 07:36 - 2015-06-03 07:36 - 00000000 ____D C:\Users\Loke\AppData\Roaming\OEM
    2015-06-03 07:35 - 2015-06-03 13:35 - 00000000 ____D C:\Users\Loke\AppData\Local\VirtualStore
    2015-06-03 07:35 - 2015-06-03 07:35 - 00000000 ____D C:\Program Files (x86)\OEM
    2015-06-03 07:35 - 2015-06-03 07:35 - 00000000 _____ C:\Users\Loke\agent.log
    2015-06-03 07:34 - 2015-06-04 01:17 - 00058016 _____ C:\Users\Loke\AppData\Local\GDIPFONTCACHEV1.DAT
    2015-06-03 07:34 - 2015-06-03 20:20 - 00000000 ____D C:\Users\Loke
    2015-06-03 07:34 - 2015-06-03 07:34 - 00000020 ___SH C:\Users\Loke\ntuser.ini
    2015-06-03 07:34 - 2015-06-03 07:34 - 00000000 ____D C:\ProgramData\OEM_E471269A730D
    2015-06-03 07:34 - 2015-06-03 07:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Family Protection
    2015-06-03 07:34 - 2012-03-07 15:02 - 00000000 ____D C:\Users\Loke\AppData\Roaming\Macromedia
    2015-06-03 07:34 - 2009-07-14 12:54 - 00000000 ___RD C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-06-03 07:34 - 2009-07-14 12:49 - 00000000 ___RD C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2015-06-03 07:33 - 2015-06-03 07:33 - 00000000 ____D C:\Recovery

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-06-13 20:17 - 2012-03-07 14:59 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-06-13 20:17 - 2012-03-07 14:59 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-06-13 14:58 - 2009-07-14 12:51 - 00040150 _____ C:\Windows\setupact.log
    2015-06-13 14:17 - 2009-07-14 12:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-06-13 14:17 - 2009-07-14 12:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-06-13 14:15 - 2009-07-14 13:13 - 00726316 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-06-13 14:09 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-06-10 18:18 - 2009-07-14 12:45 - 00267672 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-06-10 18:17 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\PolicyDefinitions
    2015-06-09 17:23 - 2010-11-21 11:47 - 00017462 _____ C:\Windows\PFRO.log
    2015-06-08 19:40 - 2009-07-14 11:20 - 00000000 __RHD C:\Users\Default
    2015-06-08 19:38 - 2009-07-14 10:34 - 00000215 _____ C:\Windows\system.ini
    2015-06-05 18:58 - 2012-03-07 14:26 - 00000000 ____D C:\ProgramData\McAfee
    2015-06-05 18:56 - 2012-03-07 14:26 - 00000000 ____D C:\Program Files\Common Files\mcafee
    2015-06-05 16:20 - 2012-03-07 14:28 - 00001848 _____ C:\Users\Public\Desktop\McAfee Internet Security Suite.lnk
    2015-06-04 18:22 - 2012-03-07 14:30 - 00045344 _____ C:\Windows\DirectX.log
    2015-06-04 14:32 - 2012-03-07 14:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\zh-HK
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\tr-TR
    2015-06-04 08:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\Dism
    2015-06-04 08:08 - 2010-11-21 15:17 - 00000000 ____D C:\Program Files\Windows Journal
    2015-06-04 08:08 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
    2015-06-04 08:08 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\AppCompat
    2015-06-04 01:31 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\tracing
    2015-06-04 01:09 - 2009-07-14 13:32 - 00000000 ____D C:\Program Files\Windows Defender
    2015-06-04 01:09 - 2009-07-14 13:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2015-06-03 22:56 - 2009-07-14 13:38 - 00025600 ___SH C:\Windows\system32\config\BCD-Template.LOG
    2015-06-03 22:56 - 2009-07-14 13:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
    2015-06-03 22:31 - 2009-07-14 12:46 - 00004059 _____ C:\Windows\DtcInstall.log
    2015-06-03 22:31 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\sysprep
    2015-06-03 22:31 - 2007-07-12 09:49 - 00000000 ____D C:\Windows\Panther
    2015-06-03 22:23 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\Help
    2015-06-03 22:22 - 2012-03-07 14:28 - 00000000 ____D C:\Program Files (x86)\Acer
    2015-06-03 22:20 - 2012-03-07 14:28 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
    2015-06-03 22:19 - 2012-03-07 15:01 - 00000032 _____ C:\ProgramData\PS.log
    2015-06-03 22:19 - 2012-03-07 15:01 - 00000000 ____D C:\Program Files (x86)\Cyberlink
    2015-06-03 22:19 - 2012-03-07 14:59 - 00002472 _____ C:\ProgramData\clear.fiSDK20.log
    2015-06-03 22:19 - 2012-03-07 14:59 - 00000000 ____D C:\ProgramData\CyberLink
    2015-06-03 22:19 - 2012-03-07 14:29 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2015-06-03 22:17 - 2009-07-14 13:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
    2015-06-03 22:13 - 2012-03-07 14:16 - 00000000 ____D C:\Program Files (x86)\Intel
    2015-06-03 22:13 - 2009-07-14 11:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
    2015-06-03 22:09 - 2011-02-12 11:12 - 00000000 ____D C:\Windows\DeployWinRE2
    2015-06-03 22:09 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\system32\Recovery
    2015-06-03 22:05 - 2012-03-07 14:24 - 00000000 ____D C:\Program Files (x86)\Acer Games
    2015-06-03 21:58 - 2012-03-07 14:01 - 00003652 _____ C:\Windows\TSSysprep.log
    2015-06-03 20:17 - 2012-03-07 14:26 - 00000000 ____D C:\ProgramData\Skype
    2015-06-03 14:09 - 2012-03-07 14:26 - 00000000 ____D C:\Program Files\mcafee
    2015-06-03 14:09 - 2012-03-07 14:26 - 00000000 ____D C:\Program Files (x86)\McAfee
    2015-06-03 07:36 - 2012-03-07 15:06 - 00018571 _____ C:\Windows\Patch.log
    2015-06-03 07:36 - 2012-03-07 14:57 - 00000000 ____D C:\ProgramData\oem
    2015-06-03 07:36 - 2012-03-07 13:53 - 00000000 ____D C:\OEM
    2015-06-03 07:34 - 2012-03-07 15:05 - 00000000 ____D C:\Program Files\Preload
    2015-06-03 07:34 - 2009-07-14 13:32 - 00000000 ____D C:\Windows\system32\restore
    2015-06-03 07:33 - 2009-07-14 11:20 - 00000000 __RHD C:\Users\Public\Libraries
    2015-06-03 07:33 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\rescache

    ==================== Files in the root of some directories =======

    2012-03-07 14:59 - 2015-06-03 22:19 - 0002472 _____ () C:\ProgramData\clear.fiSDK20.log
    2012-03-07 15:01 - 2015-06-03 22:19 - 0000032 _____ () C:\ProgramData\PS.log

    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2012-03-07 13:59

    ==================== End of log ============================
     
  22. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:08-06-2015
    Ran by Loke at 2015-06-13 21:00:23
    Running from C:\Users\Loke\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-79519641-1766234843-2241692891-500 - Administrator - Disabled)
    Guest (S-1-5-21-79519641-1766234843-2241692891-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-79519641-1766234843-2241692891-1003 - Limited - Enabled)
    Loke (S-1-5-21-79519641-1766234843-2241692891-1001 - Administrator - Enabled) => C:\Users\Loke
    UpdatusUser (S-1-5-21-79519641-1766234843-2241692891-1000 - Limited - Enabled) => C:\Users\UpdatusUser

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
    FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3507 - Acer Incorporated)
    Acer Games (HKLM-x32\...\WildTangent acer Master Uninstall) (Version: 1.0.2.5 - WildTangent)
    Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.04.3506 - Acer Incorporated)
    Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0609.2011 - Acer Incorporated)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated)
    Adobe Flash Player 11 ActiveX 64-bit (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.2.202.222 - Adobe Systems Incorporated)
    Adobe Reader X (10.1.0) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
    Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Bing Bar (HKLM-x32\...\{C28D96C0-6A90-459E-A077-A6706F4EC0FC}) (Version: 7.0.765.0 - Microsoft Corporation)
    clear.fi Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.00.3004 - Acer Incorporated)
    clear.fi Photo (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.00.3004 - Acer Incorporated)
    clear.fi SDK - MVP 2 (x32 Version: 2.0.1505 - CyberLink Corp.) Hidden
    clear.fi SDK- Movie 2 (x32 Version: 2.0.1502 - CyberLink Corp.) Hidden
    Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
    CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)
    eBay Worldwide (HKLM-x32\...\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
    Evernote v. 4.5.2 (HKLM-x32\...\{F77EF646-19EB-11E1-9A9E-984BE15F174E}) (Version: 4.5.2.5866 - Evernote Corp.)
    FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Fooz Kids (HKLM-x32\...\FoozKids) (Version: 3.1.2 - FUHU, Inc.)
    Fooz Kids (x32 Version: 3.1.2 - FUHU, Inc.) Hidden
    Fooz Kids Platform (HKLM-x32\...\{8D68CE08-9A14-4B7B-9857-3C646A2F34C7}) (Version: 2.1 - FUHU, Inc.)
    Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.124 - Google Inc.)
    Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
    Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
    Gyazo 2.4 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)
    Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3510 - Acer Incorporated)
    Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
    Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
    Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.1.209 - Intel Corporation)
    Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
    Jewel Quest Mysteries: The Seventh Gate Collector's Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
    John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    McAfee Internet Security Suite (HKLM-x32\...\MSC) (Version: 13.6.1599 - McAfee, Inc.)
    McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.316 - McAfee, Inc.)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
    MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden
    MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.18 - Egis Technology Inc.)
    MyWinLocker Suite (x32 Version: 4.0.14.18 - Egis Technology Inc.) Hidden
    Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.4.10500.1.100 - Nero AG)
    Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10700.5.100 - Nero AG)
    Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.6.10300 - Nero AG)
    Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.6.10600.4.100 - Nero AG)
    Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
    NVIDIA 3D Vision Controller Driver 301.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 301.40 - NVIDIA Corporation)
    NVIDIA 3D Vision Driver 301.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 301.40 - NVIDIA Corporation)
    NVIDIA Graphics Driver 301.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 301.40 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.16.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.16.0 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.12.0213 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation)
    Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
    PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6505 - Realtek Semiconductor Corp.)
    Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
    Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
    Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
    Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.)
    Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.102 - Skype Technologies S.A.)
    Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
    Torchlight (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
    Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated)
    WildTangent Games App (Acer Games) (x32 Version: 4.0.5.32 - WildTangent) Hidden
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
    Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
    Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
    Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Restore Points =========================

    05-06-2015 20:26:58 Windows Update
    07-06-2015 11:13:23 Windows Update
    08-06-2015 07:57:39 Windows Update
    10-06-2015 07:54:10 Windows Update
    13-06-2015 14:14:46 Windows Update

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-14 10:34 - 2015-06-08 19:38 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
    127.0.0.1 localhost

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {1658F8BE-FAD5-477F-80CD-C419AF43F871} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
    Task: {1E89F138-80BD-42AC-AE53-539214310D4F} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-21] (CyberLink)
    Task: {2642B25E-8228-46A3-A92C-18E97AC478AE} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-29] (Egis Technology Inc.)
    Task: {285967C5-2635-4A7F-841D-FBEC29BE021B} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-26] (Intel Corporation)
    Task: {2B89A434-4315-4936-A187-9EDB1085F51F} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-26] (Intel Corporation)
    Task: {37F12871-86B8-4B28-A132-CB5567665680} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation)
    Task: {413884C7-2AD9-4883-B52B-C3932381E00A} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-08] (Microsoft Corporation)
    Task: {53E13917-2543-4E48-B288-4785D1CCDE30} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-08] (Microsoft Corporation)
    Task: {592D74B2-EDE7-4E22-B48C-72C74BC1E4F5} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29] (Egis Technology Inc.)
    Task: {6CA9FDEF-5A47-4A7D-95B3-ACB71027D1D2} - System32\Tasks\Recovery Management\Burn Notification => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe [2012-01-19] (Acer)
    Task: {8A72FF95-E4D0-4465-82FC-CFF9EDCEB12C} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-08] (Microsoft Corporation)
    Task: {9800393D-CAE9-4568-B977-582150D8DED8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-03] (Google Inc.)
    Task: {9CC7FC4A-588D-4622-B92A-45FC4BD5F922} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [2015-06-04] (Microsoft Corporation)
    Task: {ADF00ECC-D939-4947-9227-915EA93EA96A} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-02-07] (Acer Incorporated)
    Task: {C4251F8A-F291-4AF6-9B86-A57F3BA40E8B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-07] (Adobe Systems Incorporated)
    Task: {CD5097F1-F66F-4398-A7F4-1A0D5D1BF142} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-03] (Google Inc.)
    Task: {E0D44D9B-3F19-41FA-BE52-3CE87F32874F} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2015-04-30] ()
    Task: {E33B1B72-CABD-4400-B129-F202328E03E8} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-08] (Microsoft Corporation)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
    Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe

    ==================== Loaded Modules (Whitelisted) ==============

    2015-06-03 22:11 - 2012-05-09 11:32 - 00085824 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2015-06-03 22:13 - 2012-02-07 18:04 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    2012-02-07 10:17 - 2012-02-07 10:17 - 00636520 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
    2011-12-24 01:24 - 2011-12-24 01:24 - 00119808 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
    2015-06-03 11:42 - 2015-04-17 01:40 - 00776192 _____ () C:\Program Files (x86)\Steam\SDL2.dll
    2015-06-03 11:42 - 2015-04-23 10:16 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
    2015-06-03 11:42 - 2015-04-23 10:16 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
    2015-06-03 11:42 - 2015-04-23 10:16 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
    2015-06-03 11:42 - 2015-06-05 02:56 - 02407104 _____ () C:\Program Files (x86)\Steam\video.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
    2015-06-03 11:42 - 2014-12-02 05:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
    2015-06-03 11:42 - 2015-06-05 02:56 - 00703168 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
    2012-02-07 10:18 - 2012-02-07 10:18 - 00151656 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
    2015-06-03 11:42 - 2015-05-12 03:01 - 36302728 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
    2015-06-05 14:24 - 2015-06-05 14:24 - 00172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\92a1650dbe9fad5f46633b835420e1a8\IsdiInterop.ni.dll
    2015-06-03 22:10 - 2011-11-30 11:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
    2015-06-03 22:13 - 2012-02-07 17:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
    2015-06-03 11:42 - 2015-05-12 03:01 - 08958344 _____ () C:\Program Files (x86)\Steam\bin\pdf.dll
    2015-06-10 07:50 - 2015-06-06 02:22 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.124\libglesv2.dll
    2015-06-10 07:50 - 2015-06-06 02:22 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.124\libegl.dll
    2015-06-10 07:50 - 2015-06-06 02:22 - 15003464 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.124\PepperFlash\pepflashplayer.dll
    2011-08-16 11:12 - 2011-08-16 11:12 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll
    2011-08-16 11:15 - 2011-08-16 11:15 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll
    2011-08-18 07:41 - 2011-08-18 07:41 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll
    2011-08-18 07:48 - 2011-08-18 07:48 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll
    2011-11-26 04:29 - 2011-11-26 04:29 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll
    2011-08-16 11:12 - 2011-08-16 11:12 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll
    2011-08-18 07:48 - 2011-08-18 07:48 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll
    2011-08-16 10:23 - 2011-08-16 10:23 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll
    2011-11-26 04:28 - 2011-11-26 04:28 - 00484352 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll
    2011-11-26 04:42 - 2011-11-26 04:42 - 00499976 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll
    2011-11-26 04:26 - 2011-11-26 04:26 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll
    2011-07-20 07:05 - 2011-07-20 07:05 - 14978048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll
    2011-07-20 07:04 - 2011-07-20 07:04 - 00317952 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll
    2011-08-16 11:17 - 2011-08-16 11:17 - 09224704 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Loke\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.1.254

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{C47CF69D-DD93-4EDF-92A3-ADE1768D7266}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{DB311AF4-EA49-43EC-A406-226F7AADD719}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{CE95AC89-E69D-4F1F-90C5-D4B90E3CBB9F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    FirewallRules: [{0A1D5830-6CFF-4003-BFA1-44650AD74B0F}] => (Allow) LPort=2869
    FirewallRules: [{8D214E05-5040-47E2-99B9-2B16D96AE222}] => (Allow) LPort=1900
    FirewallRules: [{AE48D3B2-3BE9-4CCF-92BF-A3A7E3FABF2A}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{133B2542-B23A-4FFA-8340-FA3E9072E637}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
    FirewallRules: [{4EE3391D-405A-47A0-AE6F-D437CB1C9AD9}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
    FirewallRules: [{676AC7B0-51B3-41ED-A570-0E175901F3DC}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
    FirewallRules: [{0255F560-585C-4E43-BFD2-67A49486975E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
    FirewallRules: [{150ADDCE-76B4-4574-90AF-403F03E98153}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
    FirewallRules: [{FBAF6240-41A6-46C8-9E41-58A9BB131789}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
    FirewallRules: [{AEDFE71E-47A4-4C93-8374-803F8B7AF38D}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
    FirewallRules: [{B14AED8F-82EB-4887-9CD9-3898E41BB383}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
    FirewallRules: [{6BDF6A68-CBFF-4706-80B0-D33E2F983C96}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
    FirewallRules: [{C5771E94-BBD9-4208-A49C-8825CD847087}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    FirewallRules: [{F5B0649A-3F8C-4AAF-A46A-5B768451F827}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    FirewallRules: [{0582E097-61E0-4D0D-80E5-7831B80C3FAD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\Movie\PlayMovie.exe
    FirewallRules: [{3320929E-3256-41AB-8763-0125CD075912}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\MVP\VideoPlayer.exe
    FirewallRules: [{9AF6F87B-39AF-44A0-9093-2838F82541AD}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK20\MVP\MusicPlayer.exe
    FirewallRules: [{0839EF22-5EAD-4AB0-B39C-B2143AAFF9CC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{41D22160-3ADB-45C8-8833-27F90B1F3D8B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{6F181D4E-D3A6-4F57-8EFE-85EBF2212657}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{04B24C4D-6EC3-4BD9-A1D6-830D0B7D0306}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{5B90661C-98BF-414A-AE9D-ECD6E45B9D43}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\dota.exe
    FirewallRules: [{E20F360D-51B7-471D-A916-3C9F8B84883D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\dota.exe
    FirewallRules: [{14F90016-3389-4E2E-921B-062D2BAE6D8C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
    FirewallRules: [{1B9DC53C-AB54-4851-A3E0-3CC9F815C36C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
    FirewallRules: [{0A3ABF9E-9077-47F0-81A5-DD4B6C43D461}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{B2696E85-F3CF-42EF-A9A2-B8FB3CF7757E}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{29C14D07-9DE0-4D85-ACF1-18BB401748E7}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{4D27E759-7E42-4E56-B3FC-94CEC592E293}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
    FirewallRules: [{2368413A-7D39-41D6-A08D-0B551AE936E8}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
    FirewallRules: [{4300E327-9A6B-4A28-A8BA-2BA4BB2424B0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
    FirewallRules: [{A1AA3062-04EF-43B0-ACCB-DAAB44292114}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
    FirewallRules: [{BC36C62B-E798-454B-8B64-5DE651851F8B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe
    FirewallRules: [{6782EB76-C7C8-4E3B-ABB7-D71A26D6A2BC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Team Fortress 2\hl2.exe
    FirewallRules: [{0978847A-F139-4A8C-A57E-E958B992E936}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (06/13/2015 02:11:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/12/2015 06:20:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/12/2015 07:13:59 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/11/2015 05:58:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/11/2015 07:14:18 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/10/2015 06:20:05 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/10/2015 07:32:03 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/10/2015 07:12:26 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/09/2015 05:24:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/09/2015 07:14:29 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


    System errors:
    =============
    Error: (06/10/2015 07:30:18 AM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 7:15:31 AM on ‎6/‎10/‎2015 was unexpected.

    Error: (06/08/2015 09:25:34 PM) (Source: DCOM) (EventID: 10010) (User: )
    Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}

    Error: (06/08/2015 07:38:13 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (06/08/2015 07:37:38 PM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

    Error: (06/08/2015 07:35:02 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (06/08/2015 01:14:28 AM) (Source: DCOM) (EventID: 10010) (User: )
    Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

    Error: (06/07/2015 11:02:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

    Error: (06/07/2015 11:02:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Software Protection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.

    Error: (06/07/2015 11:02:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Intel(R) Management and Security Application User Notification Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (06/07/2015 11:02:21 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The NVIDIA Update Service Daemon service terminated unexpectedly. It has done this 1 time(s).


    Microsoft Office:
    =========================
    Error: (06/13/2015 02:11:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/12/2015 06:20:34 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/12/2015 07:13:59 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/11/2015 05:58:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/11/2015 07:14:18 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/10/2015 06:20:05 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/10/2015 07:32:03 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/10/2015 07:12:26 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/09/2015 05:24:59 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (06/09/2015 07:14:29 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


    CodeIntegrity Errors:
    ===================================
    Date: 2015-06-08 19:37:38.205
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2015-06-08 19:37:38.190
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-3470 CPU @ 3.20GHz
    Percentage of memory in use: 43%
    Total physical RAM: 8139.2 MB
    Available physical RAM: 4572.95 MB
    Total Pagefile: 16276.61 MB
    Available Pagefile: 10342.89 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.86 MB

    ==================== Drives ================================

    Drive c: (Acer) (Fixed) (Total:222.95 GB) (Free:110 GB) NTFS
    Drive d: (DATA) (Fixed) (Total:223.71 GB) (Free:222.56 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 127D116D)
    Partition 1: (Not Active) - (Size=19 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=223 GB) - (Type=07 NTFS)
    Partition 4: (Not Active) - (Size=223.7 GB) - (Type=07 NTFS)

    ==================== End of log ============================
     
  23. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
     

    Attached Files:

  24. okedokeloke

    okedokeloke TS Rookie Topic Starter Posts: 23

    Fix result of Farbar Recovery Scan Tool (x64) Version:13-06-2015
    Ran by Loke at 2015-06-14 02:41:38 Run:1
    Running from C:\Users\Loke\Desktop
    Loaded Profiles: UpdatusUser & Loke (Available Profiles: UpdatusUser & Loke)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-79519641-1766234843-2241692891-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
    2012-03-07 14:59 - 2015-06-03 22:19 - 0002472 _____ () C:\ProgramData\clear.fiSDK20.log
    2012-03-07 15:01 - 2015-06-03 22:19 - 0000032 _____ () C:\ProgramData\PS.log

    *****************

    "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
    "HKU\S-1-5-21-79519641-1766234843-2241692891-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
    catchme => Service removed successfully
    EagleX64 => Service removed successfully
    C:\ProgramData\clear.fiSDK20.log => moved successfully.
    C:\ProgramData\PS.log => moved successfully.

    ==== End of Fixlog 02:41:38 ====
     
  25. Broni

    Broni Malware Annihilator Posts: 52,915   +344

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
    NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
      • Other Services
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    [​IMG] Download Sophos Free Virus Removal Tool and save it to your desktop.
    • Double click the icon and select Run
    • Click Next
    • Select I accept the terms in this license agreement, then click Next twice
    • Click Install
    • Click Finish to launch the program
    • Once the virus database has been updated click Start Scanning
    • If any threats are found click Details, then View log file... (bottom left hand corner)
    • Copy and paste the results in your reply
    • Close the Notepad document, close the Threat Details screen, then click Start cleanup
    • Click Exit to close the program
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...