First, DDs.txt
DDSMalwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org
Database version: v2013.07.29.06
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16635
Troy :: TROY-PC [administrator]
Protection: Enabled
7/29/2013 10:11:57 PM
mbam-log-2013-07-29 (22-11-57).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 219966
Time elapsed: 22 minute(s), 10 second(s)
Memory Processes Detected: 1
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (PUP.Optional.Wajam) -> 1712 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 10
HKCR\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKCR\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKCR\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKCR\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKCR\wajam.WajamBHO.1 (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKCR\wajam.WajamBHO (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
HKLM\SYSTEM\CurrentControlSet\Services\WajamUpdater (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 3
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
Files Detected: 19
C:\Program Files (x86)\Wajam\IE\priam_bho.dll (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
C:\Users\Troy\AppData\Local\Temp\pjpbdrxbrih.exe (PUP.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Troy\AppData\Local\Temp\vtpmkjvipch.exe (PUP.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Troy\AppData\Local\Temp\wajam_install.exe (PUP.Optional.Wajam) -> Quarantined and deleted successfully.
C:\Users\Troy\AppData\Local\Temp\wjtuktxzetr.exe (PUP.BitCoinMiner) -> Quarantined and deleted successfully.
C:\Users\Troy\AppData\Local\Temp\Phx1407\setup__423.exe (PUP.Optional.Amonetize) -> Quarantined and deleted successfully.
C:\Users\Troy\Downloads\Adobe Premier CS6-AMTLIB-64-bit.rar (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Users\Troy\Downloads\SoftonicDownloader_for_ulead-gif-animator.exe (PUP.Optional.Softonic) -> Quarantined and deleted successfully.
C:\Users\Troy\Local Settings\Temporary Internet Files\Content.IE5\26BT823R\852694676[1].jpg (Extension.Mismatch) -> Quarantined and deleted successfully.
C:\Users\Troy\Local Settings\Temporary Internet Files\Content.IE5\AIDUGX0B\702853716[1].jpg (Extension.Mismatch) -> Quarantined and deleted successfully.
C:\Users\Troy\Local Settings\Temporary Internet Files\Content.IE5\AIDUGX0B\906013741[1].jpg (Extension.Mismatch) -> Quarantined and deleted successfully.
C:\Users\Troy\Local Settings\Temporary Internet Files\Content.IE5\AIDUGX0B\setup__423[1].exe (PUP.Optional.Amonetize) -> Quarantined and deleted successfully.
C:\Users\Troy\Local Settings\Temporary Internet Files\Content.IE5\MV1JQTD5\350141492[1].jpg (Extension.Mismatch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (PUP.Optional.Wajam) -> Delete on reboot.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
(end)
S3 storflt;Hyper-V Storage Accelerator;C:\Windows\System32\Drivers\vmstorfl.sys [2012-7-25 45160]
S3 storvsc;storvsc;C:\Windows\System32\Drivers\storvsc.sys [2012-7-25 37992]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 swprv;Microsoft Software Shadow Copy Provider;C:\Windows\System32\svchost.exe -k swprv [2013-1-9 29696]
S3 TCPIP6;Microsoft IPv6 Protocol Driver;C:\Windows\System32\Drivers\tcpip.sys [2013-7-16 2233600]
S3 uagp35;Microsoft AGPv3.5 Filter;C:\Windows\System32\Drivers\UAGP35.SYS [2012-7-25 65776]
S3 uliagpkx;Uli AGP Bus Filter;C:\Windows\System32\Drivers\ULIAGPKX.SYS [2012-7-25 66800]
S3 usbcir;eHome Infrared Receiver (USBCIR);C:\Windows\System32\Drivers\usbcir.sys [2012-7-25 99328]
S3 usbprint;Microsoft USB PRINTER Class;C:\Windows\System32\Drivers\usbprint.sys [2012-7-25 25600]
S3 usbscan;USB Scanner Driver;C:\Windows\System32\Drivers\usbscan.sys [2013-1-1 43008]
S3 USBSTOR;USB Mass Storage Driver;C:\Windows\System32\Drivers\USBSTOR.SYS [2012-7-25 119024]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver;C:\Windows\System32\Drivers\usbuhci.sys [2013-1-1 32256]
S3 vhdmp;vhdmp;C:\Windows\System32\Drivers\vhdmp.sys [2013-4-12 495336]
S3 viaide;viaide;C:\Windows\System32\Drivers\viaide.sys [2012-7-25 19184]
S3 vmbus;Virtual Machine Bus;C:\Windows\System32\Drivers\vmbus.sys [2012-7-25 137832]
S3 VMBusHID;VMBusHID;C:\Windows\System32\Drivers\VMBusHID.sys [2012-7-25 22144]
S3 vsmraid;vsmraid;C:\Windows\System32\Drivers\vsmraid.sys [2012-6-2 164080]
S3 WacomPen;Wacom Serial Pen HID Driver;C:\Windows\System32\Drivers\wacompen.sys [2012-7-25 27008]
S3 Wanarp;Remote Access IP ARP Driver;C:\Windows\System32\Drivers\wanarp.sys [2013-5-18 83456]
S3 WIMMount;WIMMount;C:\Windows\System32\Drivers\wimmount.sys [2012-7-25 33520]
S3 WinRing0_1_2_0;WinRing0_1_2_0;C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [2013-7-2 14544]
S3 WinUsb;WinUsb;C:\Windows\System32\Drivers\winusb.sys [2012-7-25 57344]
S3 WSDPrintDevice;WSD Print Support;C:\Windows\System32\Drivers\WSDPrint.sys [2012-7-25 21504]
S3 WSDScan;WSD Scan Support;C:\Windows\System32\Drivers\WSDScan.sys [2013-1-1 23552]
S3 WudfPf;User Mode Driver Frameworks Platform Driver;C:\Windows\System32\Drivers\WUDFPf.sys [2012-7-25 87040]
S3 WUDFRd;Windows Driver Foundation - User-mode Driver Framework Reflector;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
S3 WUDFWpdFs;WUDFWpdFs;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
S3 WUDFWpdMtp;WUDFWpdMtp;C:\Windows\System32\Drivers\WUDFRd.sys [2012-7-25 198656]
S4 cdfs;CD/DVD File System Reader;C:\Windows\System32\Drivers\cdfs.sys [2012-7-25 108544]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-7-25 139696]
S4 RemoteAccess;Routing and Remote Access;C:\Windows\System32\svchost.exe -k netsvcs [2013-1-9 29696]
S4 RemoteRegistry;Remote Registry;C:\Windows\System32\svchost.exe -k localService [2013-1-9 29696]
S4 SCardSvr;Smart Card;C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation [2013-1-9 29696]
S4 SharedAccess;Internet Connection Sharing (ICS);C:\Windows\System32\svchost.exe -k netsvcs [2013-1-9 29696]
S4 udfs;udfs;C:\Windows\System32\Drivers\udfs.sys [2012-7-25 321024]
S4 ws2ifsl;Winsock IFS Driver;C:\Windows\System32\Drivers\ws2ifsl.sys [2013-1-9 22528]
.
=============== File Associations ===============
.
FileExt: .bat: batfile="%1" %*
FileExt: .cmd: cmdfile="%1" %*
FileExt: .com: comfile="%1" %*
FileExt: .exe: exefile="%1" %*
FileExt: .pif: piffile="%1" %*
FileExt: .scr: scrfile="%1" /S
FileExt: .reg: regfile=regedit.exe "%1"
FileExt: .txt: txtfile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .chm: chm.file="C:\Windows\hh.exe" %1
FileExt: .ini: inifile=C:\Windows\System32\NOTEPAD.EXE %1
FileExt: .inf: inffile=C:\Windows\System32\NOTEPAD.EXE %1
ShellExec: 7z.exe: open="C:\Program Files (x86)\7-Zip\7z.exe" "%1"
ShellExec: chrome.exe: open="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1"
ShellExec: hl2.exe: open="c:\program files (x86)\strogino cs portal\left 4 dead 2\hl2.exe" "%1"
ShellExec: iexplore.exe: open="C:\Program Files\Internet Explorer\iexplore.exe" %1
ShellExec: LOLRecorder.exe: open="C:\Program Files (x86)\LOLReplay\LOLRecorder.exe" "%1"
ShellExec: MSOXMLED.EXE: open="C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE15\MSOXMLED.EXE" "%1"
ShellExec: mspaint.exe: edit="C:\Windows\System32\mspaint.exe" "%1"
ShellExec: notepad.exe: edit=C:\Windows\System32\NOTEPAD.EXE %1
ShellExec: notepad.exe: open=C:\Windows\System32\NOTEPAD.EXE %1
ShellExec: photoviewer.dll: open=C:\Windows\System32\rundll32.exe "C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1
ShellExec: photoviewer.dll: print=C:\Windows\System32\rundll32.exe "C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen %1
ShellExec: Recorder.exe: open="C:\Program Files (x86)\CamStudio 2.7\Recorder.exe" "%1"
ShellExec: vlc.exe: Open="C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file "%1"
ShellExec: WINWORD.EXE: edit="C:\Program Files\Microsoft Office 15\root\Office15\Winword.exe" /n "%1"
ShellExec: wmplayer.exe: open="C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /Open "%L"
ShellExec: wmplayer.exe: play="C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /Play "%L"
ShellExec: wordpad.exe: open="C:\Program Files (x86)\Windows NT\Accessories\WORDPAD.EXE" "%1"
.
=============== Created Last 60 ================
.
2013-08-02 00:10:09378944----a-w-C:\Windows\System32\drivers\aswSP.sys
2013-08-02 00:10:0933400----a-w-C:\Windows\System32\drivers\aswFsBlk.sys
2013-08-02 00:10:0772016----a-w-C:\Windows\System32\drivers\aswRdr2.sys
2013-08-02 00:10:0764288----a-w-C:\Windows\System32\drivers\aswTdi.sys
2013-08-02 00:09:5365336----a-w-C:\Windows\System32\drivers\aswRvrt.sys
2013-08-02 00:09:53189936----a-w-C:\Windows\System32\drivers\aswVmm.sys
2013-08-02 00:09:531030952----a-w-C:\Windows\System32\drivers\aswSnx.sys
2013-08-02 00:09:5280816----a-w-C:\Windows\System32\drivers\aswMonFlt.sys
2013-08-02 00:09:52287840----a-w-C:\Windows\System32\aswBoot.exe
2013-08-02 00:09:0141664----a-w-C:\Windows\avastSS.scr
2013-08-02 00:08:10--------d-----w-C:\Program Files\AVAST Software
2013-08-02 00:06:43--------d-----w-C:\ProgramData\AVAST Software
2013-08-01 14:22:34262832----a-w-C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10212.bin
2013-08-01 14:14:1176232----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D0DB5FAA-DDDD-46F0-A8AB-2A199BEEA447}\offreg.dll
2013-08-01 13:58:379460976----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{D0DB5FAA-DDDD-46F0-A8AB-2A199BEEA447}\mpengine.dll
2013-07-30 16:00:29--------d-sh--w-C:\Windows\SysWow64\AI_RecycleBin
2013-07-30 16:00:25--------d-----w-C:\Riot Games
2013-07-30 15:56:11--------d-----w-C:\Users\Troy\AppData\Local\PMB Files
2013-07-30 15:56:09--------d-----w-C:\ProgramData\PMB Files
2013-07-30 15:54:55--------d-----w-C:\Users\Troy\AppData\Roaming\Riot Games
2013-07-29 22:29:54--------d-----w-C:\Users\Troy\AppData\Roaming\Malwarebytes
2013-07-29 22:29:13--------d-----w-C:\ProgramData\Malwarebytes
2013-07-29 22:29:0525928----a-w-C:\Windows\System32\drivers\mbam.sys
2013-07-29 22:29:05--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-29 00:42:58--------d-sh--w-C:\ProgramData\Javaa0
2013-07-27 08:00:459460976----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-07-26 01:49:49--------d-----w-C:\Users\Troy\AppData\Local\Darksiders2
2013-07-25 20:35:02--------d--h--w-C:\My Pictures
2013-07-20 04:15:28--------d-----w-C:\Users\Troy\AppData\Local\Robot Entertainment
2013-07-19 02:49:56--------d-----w-C:\Program Files\Defraggler
2013-07-17 23:16:44--------d-----w-C:\ProgramData\Ulead Systems
2013-07-17 23:16:33--------d-----w-C:\Program Files (x86)\Ulead Systems
2013-07-17 23:15:28--------d-----w-C:\Windows\Noslip
2013-07-17 23:15:2677824----a-w-C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2013-07-17 23:15:2632768----a-w-C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2013-07-17 23:15:26225280----a-w-C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll
2013-07-17 23:15:26176128----a-w-C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2013-07-17 23:15:24614532----a-w-C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2013-07-17 23:15:24--------d-----w-C:\Program Files (x86)\Common Files\InstallShield
2013-07-17 00:45:56997632----a-w-C:\Windows\System32\drivers\ndis.sys
2013-07-17 00:45:512233600----a-w-C:\Windows\System32\drivers\tcpip.sys
2013-07-17 00:45:442219520----a-w-C:\Windows\System32\dwmcore.dll
2013-07-17 00:45:402391280----a-w-C:\Windows\explorer.exe
2013-07-17 00:45:402106176----a-w-C:\Windows\SysWow64\explorer.exe
2013-07-17 00:45:401842176----a-w-C:\Windows\SysWow64\dwmcore.dll
2013-07-17 00:45:396987008----a-w-C:\Windows\System32\ntoskrnl.exe
2013-07-17 00:45:38729600----a-w-C:\Windows\System32\samsrv.dll
2013-07-17 00:45:381527808----a-w-C:\Windows\System32\mfcore.dll
2013-07-17 00:45:36327936----a-w-C:\Windows\System32\drivers\volsnap.sys
2013-07-17 00:45:361453568----a-w-C:\Windows\SysWow64\mfcore.dll
2013-07-17 00:45:351403296----a-w-C:\Windows\System32\winload.efi
2013-07-17 00:45:341271584----a-w-C:\Windows\System32\winload.exe
2013-07-17 00:45:32523264----a-w-C:\Windows\System32\XpsGdiConverter.dll
2013-07-17 00:45:321217352----a-w-C:\Windows\System32\winresume.efi
2013-07-17 00:45:31680960----a-w-C:\Windows\System32\vds.exe
2013-07-17 00:45:311093904----a-w-C:\Windows\System32\winresume.exe
2013-07-17 00:45:30785408----a-w-C:\Windows\System32\audiosrv.dll
2013-07-17 00:45:30583168----a-w-C:\Windows\System32\mscms.dll
2013-07-17 00:45:301048576----a-w-C:\Windows\System32\mfasfsrcsnk.dll
2013-07-17 00:45:29493056----a-w-C:\Windows\SysWow64\mscms.dll
2013-07-17 00:45:29446976----a-w-C:\Windows\System32\wwansvc.dll
2013-07-17 00:45:29364544----a-w-C:\Windows\SysWow64\XpsGdiConverter.dll
2013-07-17 00:45:29213248----a-w-C:\Windows\System32\drivers\UCX01000.SYS
2013-07-17 00:45:29106496----a-w-C:\Windows\System32\samlib.dll
2013-07-17 00:45:28850944----a-w-C:\Windows\SysWow64\mfasfsrcsnk.dll
2013-07-17 00:45:28207872----a-w-C:\Windows\System32\DeviceSetupManager.dll
2013-07-17 00:45:2780896----a-w-C:\Windows\System32\MbaeParserTask.exe
2013-07-17 00:45:27337152----a-w-C:\Windows\System32\drivers\USBXHCI.SYS
2013-07-17 00:45:27194816----a-w-C:\Windows\System32\drivers\sdbus.sys
2013-07-17 00:45:26125184----a-w-C:\Windows\System32\drivers\dumpsd.sys
2013-07-17 00:45:25190976----a-w-C:\Windows\System32\vdsutil.dll
2013-07-17 00:45:2467584----a-w-C:\Windows\SysWow64\samlib.dll
2013-07-17 00:45:2337632----a-w-C:\Windows\System32\drivers\BthAvrcpTg.sys
2013-07-16 01:44:44--------d-----w-C:\Program Files (x86)\1-click run
2013-07-15 15:04:31--------d-----w-C:\Program Files (x86)\Microsoft XNA
2013-07-11 14:36:002035200----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\InkObj.dll
2013-07-11 14:35:591272320----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 14:35:581617920----a-w-C:\Program Files\Windows Journal\NBDoc.DLL
2013-07-11 14:35:581306112----a-w-C:\Program Files\Windows Journal\JNTFiltr.dll
2013-07-11 14:35:571318912----a-w-C:\Program Files\Windows Journal\JNWDRV.dll
2013-07-11 14:35:521413632----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll
2013-07-11 14:35:441029632----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\journal.dll
2013-07-11 14:15:114036096----a-w-C:\Windows\System32\win32k.sys
2013-07-11 14:00:251838080----a-w-C:\Windows\System32\DWrite.dll
2013-07-11 14:00:241421312----a-w-C:\Windows\SysWow64\DWrite.dll
2013-07-11 14:00:16595968----a-w-C:\Windows\System32\qedit.dll
2013-07-11 14:00:16496640----a-w-C:\Windows\SysWow64\qedit.dll
2013-07-11 13:58:3415404032----a-w-C:\Windows\System32\ieframe.dll
2013-07-11 13:58:2813760512----a-w-C:\Windows\SysWow64\ieframe.dll
2013-07-11 13:58:2519238912----a-w-C:\Windows\System32\mshtml.dll
2013-07-11 13:58:173958784----a-w-C:\Windows\System32\jscript9.dll
2013-07-11 13:58:1614329856----a-w-C:\Windows\SysWow64\mshtml.dll
2013-07-11 13:58:082648576----a-w-C:\Windows\System32\iertutil.dll
2013-07-11 13:58:062046976----a-w-C:\Windows\SysWow64\iertutil.dll
2013-07-11 13:58:041084928----a-w-C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-07-11 13:58:02855552----a-w-C:\Windows\System32\jscript.dll
2013-07-11 13:58:02817664----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-07-11 13:58:011365504----a-w-C:\Windows\System32\urlmon.dll
2013-07-11 13:57:592241024----a-w-C:\Windows\System32\wininet.dll
2013-07-11 13:57:58356864----a-w-C:\Program Files\Internet Explorer\IEShims.dll
2013-07-11 13:57:58235520----a-w-C:\Program Files (x86)\Internet Explorer\IEShims.dll
2013-07-11 13:57:572877440----a-w-C:\Windows\SysWow64\jscript9.dll
2013-07-11 13:57:571767936----a-w-C:\Windows\SysWow64\wininet.dll
2013-07-11 13:57:571141248----a-w-C:\Windows\SysWow64\urlmon.dll
2013-07-11 13:57:56603136----a-w-C:\Windows\System32\msfeeds.dll
2013-07-11 13:57:55493056----a-w-C:\Windows\SysWow64\msfeeds.dll
2013-07-11 13:57:53690688----a-w-C:\Windows\SysWow64\jscript.dll
2013-07-11 13:57:5351712----a-w-C:\Windows\System32\ie4uinit.exe
2013-07-11 13:55:082842112----a-w-C:\Windows\System32\WMVDECOD.DLL
2013-07-11 13:55:072620928----a-w-C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-06 21:00:14--------d-----w-C:\Program Files (x86)\LogMeIn Hamachi
2013-07-04 18:51:31--------d-----w-C:\ProgramData\Picroma
2013-07-03 15:18:55--------d-----w-C:\Users\Troy\AppData\Roaming\vlc
2013-07-03 15:11:242162416----a-w-C:\Users\Troy\AppData\Local\BcsKtYcHW.dll
2013-07-03 15:11:2045056----a-r-C:\Users\Troy\AppData\Roaming\Microsoft\Installer\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}\UNINST_Uninstall_C_EBD1846850A64C858760A659B987DCFF.exe
2013-07-03 15:11:2045056----a-r-C:\Users\Troy\AppData\Roaming\Microsoft\Installer\{37331C16-3E97-4A20-80D8-BFB43AB0E2FB}\ARPPRODUCTICON.exe
2013-07-03 15:11:18--------d-----w-C:\Users\Troy\AppData\Roaming\Catalina – Print Savings
2013-07-03 06:00:56--------d-----w-C:\Program Files (x86)\VideoLAN
2013-07-02 21:35:38--------d-----w-C:\Users\Troy\AppData\Local\Razer
2013-07-02 21:24:50--------d-----w-C:\ProgramData\Razer
2013-07-02 21:24:48--------d-----w-C:\Program Files (x86)\Razer
2013-06-29 05:42:06--------d--h--w-C:\Fraps
2013-06-25 18:06:34--------d-----w-C:\Program Files (x86)\Valve
2013-06-25 17:46:28--------d-----w-C:\Users\Troy\AppData\Roaming\GameRanger
2013-06-24 17:24:41144384----a-w-C:\Windows\System32\tssdisai.dll
2013-06-24 14:30:52--------d-----w-C:\Users\Troy\AppData\Roaming\OpenOffice.org
2013-06-24 14:24:23--------d-----w-C:\Program Files (x86)\OpenOffice.org 3
2013-06-23 01:39:06--------d-----w-C:\Users\Troy\AppData\Roaming\Nero
2013-06-20 02:54:35--------d-----w-C:\Program Files (x86)\VTFEdit
2013-06-16 09:44:191257472----a-w-C:\Windows\System32\kernel32.dll
2013-06-16 09:44:18974848----a-w-C:\Windows\SysWow64\kernel32.dll
2013-06-16 09:44:151300992----a-w-C:\Windows\System32\gdi32.dll
2013-06-16 09:44:141022464----a-w-C:\Windows\SysWow64\gdi32.dll
2013-06-16 09:44:13888320----a-w-C:\Windows\System32\autochk.exe
2013-06-16 09:44:12542208----a-w-C:\Windows\System32\untfs.dll
2013-06-16 09:44:11482816----a-w-C:\Windows\SysWow64\untfs.dll
2013-06-16 09:44:08793088----a-w-C:\Windows\SysWow64\autochk.exe
2013-06-15 18:19:3013644288----a-w-C:\Windows\System32\Windows.UI.Xaml.dll
2013-06-15 18:19:2510788864----a-w-C:\Windows\SysWow64\Windows.UI.Xaml.dll
2013-06-15 18:19:221131520----a-w-C:\Windows\System32\AppXDeploymentServer.dll
2013-06-15 18:19:211332736----a-w-C:\Windows\System32\sysmain.dll
2013-06-15 18:19:2010116096----a-w-C:\Windows\System32\twinui.dll
2013-06-15 18:19:193241472----a-w-C:\Windows\System32\wuaueng.dll
2013-06-15 18:19:18427520----a-w-C:\Windows\System32\drivers\rdbss.sys
2013-06-15 18:19:171483776----a-w-C:\Windows\System32\VSSVC.exe
2013-06-15 18:19:14470528----a-w-C:\Windows\System32\netprofmsvc.dll
2013-06-15 18:19:141820672----a-w-C:\Program Files\Windows Photo Viewer\PhotoViewer.dll
2013-06-15 18:19:128857088----a-w-C:\Windows\SysWow64\twinui.dll
2013-06-15 18:19:122305024----a-w-C:\Windows\System32\authui.dll
2013-06-15 18:19:11760320----a-w-C:\Windows\System32\wuapi.dll
2013-06-15 18:19:102035712----a-w-C:\Windows\SysWow64\authui.dll
2013-06-15 18:19:091637376----a-w-C:\Program Files (x86)\Windows Photo Viewer\PhotoViewer.dll
2013-06-15 18:19:0914848----a-w-C:\Windows\SysWow64\rars.rs
2013-06-15 18:19:0914848----a-w-C:\Windows\System32\rars.rs
2013-06-15 18:19:08446720----a-w-C:\Windows\System32\drivers\USBHUB3.SYS
2013-06-15 18:19:08389120----a-w-C:\Windows\System32\BCP47Langs.dll
2013-06-15 18:19:08330240----a-w-C:\Windows\System32\stobject.dll
2013-06-15 18:19:08328192----a-w-C:\Windows\System32\ubpm.dll
2013-06-15 18:19:08247296----a-w-C:\Windows\SysWow64\ubpm.dll
2013-06-15 18:19:08151552----a-w-C:\Windows\System32\netprofm.dll
2013-06-15 18:19:07708096----a-w-C:\Windows\System32\AppXDeploymentExtensions.dll
2013-06-15 18:19:07621056----a-w-C:\Windows\SysWow64\wuapi.dll
2013-06-15 18:19:0693696----a-w-C:\Windows\System32\psmsrv.dll
2013-06-15 18:19:06812544----a-w-C:\Windows\System32\Magnify.exe
2013-06-15 18:19:06560640----a-w-C:\Windows\System32\mfmp4srcsnk.dll
2013-06-15 18:19:06169984----a-w-C:\Windows\System32\netplwiz.dll
2013-06-15 18:19:05151040----a-w-C:\Windows\SysWow64\netplwiz.dll
2013-06-15 18:19:04501760----a-w-C:\Windows\System32\DevicePairing.dll
2013-06-15 18:19:04303616----a-w-C:\Windows\SysWow64\stobject.dll
2013-06-15 18:19:04284416----a-w-C:\Windows\System32\drivers\spaceport.sys
2013-06-15 18:19:0358312----a-w-C:\Windows\System32\wuauclt.exe
2013-06-15 18:19:03419840----a-w-C:\Windows\System32\intl.cpl
2013-06-15 18:19:02758784----a-w-C:\Windows\SysWow64\Magnify.exe
2013-06-15 18:19:021619968----a-w-C:\Windows\System32\wucltux.dll
2013-06-15 18:19:02120736----a-w-C:\Windows\System32\AuthHost.exe
2013-06-15 18:19:01449536----a-w-C:\Windows\SysWow64\DevicePairing.dll
2013-06-15 18:19:01122368----a-w-C:\Windows\System32\biwinrt.dll
2013-06-15 18:19:01115712----a-w-C:\Windows\SysWow64\netprofm.dll
2013-06-15 18:18:5892160----a-w-C:\Windows\SysWow64\biwinrt.dll
2013-06-15 18:18:58251904----a-w-C:\Windows\System32\WUSettingsProvider.dll
2013-06-15 18:18:57389632----a-w-C:\Windows\SysWow64\intl.cpl
2013-06-15 18:18:57179712----a-w-C:\Windows\System32\bisrv.dll
2013-06-15 18:18:56411136----a-w-C:\Windows\SysWow64\mfmp4srcsnk.dll
2013-06-15 18:18:56173568----a-w-C:\Windows\System32\storewuauth.dll
2013-06-15 18:18:5598304----a-w-C:\Windows\System32\wudriver.dll
2013-06-15 18:18:5583968----a-w-C:\Windows\SysWow64\wudriver.dll
2013-06-15 18:18:5539424----a-w-C:\Windows\System32\wuapp.exe
2013-06-15 18:18:55309760----a-w-C:\Windows\SysWow64\BCP47Langs.dll
2013-06-15 18:18:55141824----a-w-C:\Windows\System32\wuwebv.dll
2013-06-15 18:18:55125952----a-w-C:\Windows\SysWow64\wuwebv.dll
2013-06-15 18:18:5434304----a-w-C:\Windows\SysWow64\wuapp.exe
2013-06-15 18:18:5417408----a-w-C:\Windows\System32\muifontsetup.dll
2013-06-15 18:18:5318432----a-w-C:\Windows\SysWow64\npmproxy.dll
2013-06-15 18:18:5314336----a-w-C:\Windows\SysWow64\muifontsetup.dll
2013-06-12 10:44:321889280----a-w-C:\Windows\System32\crypt32.dll
2013-06-12 10:44:321569792----a-w-C:\Windows\SysWow64\crypt32.dll
2013-06-12 10:44:311255936----a-w-C:\Windows\System32\certutil.exe
2013-06-12 10:44:3068096----a-w-C:\Windows\System32\cryptsvc.dll
2013-06-12 10:44:30141312----a-w-C:\Windows\System32\cryptnet.dll
2013-06-12 10:44:30109056----a-w-C:\Windows\SysWow64\cryptnet.dll
2013-06-12 10:44:301013248----a-w-C:\Windows\SysWow64\certutil.exe
2013-06-12 10:44:27733184----a-w-C:\Windows\System32\win32spl.dll
2013-06-12 10:44:2330720----a-w-C:\Windows\System32\cryptdlg.dll
2013-06-12 10:44:2325088----a-w-C:\Windows\SysWow64\cryptdlg.dll
2013-06-12 10:44:2117271808----a-w-C:\Program Files\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-06-12 10:44:1916642560----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\Microsoft Camera Codec Pack\MicrosoftRawCodec.dll
2013-06-12 10:43:45915968----a-w-C:\Windows\System32\uxtheme.dll
2013-06-12 10:43:45148992----a-w-C:\Program Files\Internet Explorer\jsdebuggeride.dll
2013-06-12 10:43:45108032----a-w-C:\Program Files (x86)\Internet Explorer\jsdebuggeride.dll
2013-06-12 10:43:4244032----a-w-C:\Windows\SysWow64\UXInit.dll
2013-06-12 10:43:4153760----a-w-C:\Windows\System32\UXInit.dll
2013-06-12 10:43:412706432----a-w-C:\Windows\SysWow64\mshtml.tlb
2013-06-12 10:43:412706432----a-w-C:\Windows\System32\mshtml.tlb
.
==================== Find6M ====================
.
2013-07-11 14:17:0978185248----a-w-C:\Windows\System32\MRT.exe
2013-06-27 22:04:5178200----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 22:04:51693112----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-02 15:29:56278800------w-C:\Windows\System32\MpSigStub.exe
2013-04-16 02:34:441455368----a-w-C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-13 05:56:35444416----a-w-C:\Windows\apppatch\AcSpecfc.dll
2013-04-09 05:33:02489576----a-w-C:\Windows\System32\AudioEng.dll
2013-04-09 05:33:02446792----a-w-C:\Windows\System32\AudioSes.dll
2013-04-09 05:33:02253544----a-w-C:\Windows\System32\audiodg.exe
2013-04-09 05:20:0286280----a-w-C:\Windows\System32\kdnet.dll
2013-04-09 05:20:02306952----a-w-C:\Windows\System32\kd_02_10ec.dll
2013-04-09 05:18:0577960----a-w-C:\Windows\System32\kdvm.dll
2013-04-09 05:17:571829408----a-w-C:\Windows\System32\ntdll.dll
2013-04-09 04:52:07816128----a-w-C:\Windows\System32\SearchIndexer.exe
2013-04-09 04:52:07373760----a-w-C:\Windows\System32\SearchProtocolHost.exe
2013-04-09 04:52:07197120----a-w-C:\Windows\System32\SearchFilterHost.exe
2013-04-09 04:52:07126464----a-w-C:\Windows\System32\Robocopy.exe
2013-04-09 04:52:06804352----a-w-C:\Windows\System32\RecoveryDrive.exe
2013-04-09 04:51:51367616----a-w-C:\Windows\System32\conhost.exe
2013-04-09 04:51:4199840----a-w-C:\Windows\System32\wscsvc.dll
2013-04-09 04:51:41456704----a-w-C:\Windows\System32\wpncore.dll
2013-04-09 04:51:3114267904----a-w-C:\Windows\System32\wmp.dll
2013-04-09 04:51:17595456----a-w-C:\Windows\System32\Windows.Networking.dll
2013-04-09 04:51:17391168----a-w-C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-04-09 04:51:033552768----a-w-C:\Windows\System32\tquery.dll
2013-04-09 04:50:53414720----a-w-C:\Windows\System32\GenuineCenter.dll
2013-04-09 04:50:39422400----a-w-C:\Windows\System32\schannel.dll
2013-04-09 04:50:391285632----a-w-C:\Windows\System32\schedsvc.dll
2013-04-09 04:50:0396256----a-w-C:\Windows\System32\mssprxy.dll
2013-04-09 04:50:03745984----a-w-C:\Windows\System32\mssvp.dll
2013-04-09 04:50:032107904----a-w-C:\Windows\System32\mssrch.dll
2013-04-09 04:50:0265024----a-w-C:\Windows\System32\msscntrs.dll
2013-04-09 04:50:02435200----a-w-C:\Windows\System32\mssph.dll
2013-04-09 04:50:0213824----a-w-C:\Windows\System32\msshooks.dll
2013-04-09 04:49:541444864----a-w-C:\Windows\System32\MSAudDecMFT.dll
2013-04-09 04:49:45468992----a-w-C:\Windows\System32\MFMediaEngine.dll
2013-04-09 04:49:45281088----a-w-C:\Windows\System32\mfreadwrite.dll
2013-04-09 04:49:36817152----a-w-C:\Windows\System32\kerberos.dll
2013-04-09 04:49:33210432----a-w-C:\Windows\System32\iuilp.dll
2013-04-09 04:49:1650176----a-w-C:\Windows\System32\fmifs.dll
2013-04-09 04:49:16231936----a-w-C:\Windows\System32\fhengine.dll
2013-04-09 04:49:09172544----a-w-C:\Windows\System32\dwmredir.dll
2013-04-09 04:49:06196096----a-w-C:\Windows\System32\dmvdsitf.dll
2013-04-09 04:48:42169472----a-w-C:\Windows\System32\AudioEndpointBuilder.dll
2013-04-09 02:34:4983968----a-w-C:\Windows\System32\drivers\hidclass.sys
2013-04-09 02:34:4227648----a-w-C:\Windows\System32\drivers\hidusb.sys
2013-04-09 02:34:3095744----a-w-C:\Windows\System32\drivers\hidbth.sys
2013-04-09 02:33:4160416----a-w-C:\Windows\System32\drivers\ndproxy.sys
2013-04-09 02:33:05623104----a-w-C:\Windows\System32\drivers\srv2.sys
2013-04-09 02:32:02805376----a-w-C:\Windows\System32\drivers\PEAuth.sys
2013-04-09 02:31:14247808----a-w-C:\Windows\System32\drivers\srvnet.sys
2013-04-09 02:31:0183456----a-w-C:\Windows\System32\drivers\wanarp.sys
2013-04-08 23:44:25123880----a-w-C:\Windows\SysWow64\wscapi.dll
2013-04-08 23:39:141408896----a-w-C:\Windows\SysWow64\ntdll.dll
2013-04-08 23:37:29426024----a-w-C:\Windows\SysWow64\AudioEng.dll
2013-04-08 23:37:29324368----a-w-C:\Windows\SysWow64\AudioSes.dll
2013-04-08 21:52:16670208----a-w-C:\Windows\SysWow64\SearchIndexer.exe
2013-04-08 21:52:16302592----a-w-C:\Windows\SysWow64\SearchProtocolHost.exe
2013-04-08 21:52:16171008----a-w-C:\Windows\SysWow64\SearchFilterHost.exe
2013-04-08 21:52:16106496----a-w-C:\Windows\SysWow64\Robocopy.exe
2013-04-08 21:52:0111878912----a-w-C:\Windows\SysWow64\wmp.dll
2013-04-04 23:30:17503080----a-w-C:\Windows\System32\ci.dll
2013-03-29 05:03:4295648----a-w-C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-29 05:03:37262560----a-w-C:\Windows\SysWow64\javaws.exe
2013-03-29 05:03:37174496----a-w-C:\Windows\SysWow64\javaw.exe
2013-03-29 05:03:36174496----a-w-C:\Windows\SysWow64\java.exe
2013-03-29 05:03:35861088----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2013-03-29 05:03:35782240----a-w-C:\Windows\SysWow64\deployJava1.dll
2013-03-22 03:49:552382336----a-w-C:\Windows\SysWow64\esent.dll
2013-03-21 22:47:132851840----a-w-C:\Windows\System32\esent.dll
2013-03-15 22:05:34298456----a-w-C:\Windows\System32\rsaenh.dll
2013-03-15 22:05:16252928----a-w-C:\Windows\SysWow64\rsaenh.dll
2013-03-15 00:17:18861184----a-w-C:\Windows\System32\drivers\http.sys
2013-03-06 07:10:10112872----a-w-C:\Windows\System32\consent.exe
2013-03-06 06:31:2819758592----a-w-C:\Windows\System32\shell32.dll
2013-03-06 06:31:26222208----a-w-C:\Windows\System32\shdocvw.dll
2013-03-06 06:29:1570144----a-w-C:\Windows\System32\appinfo.dll
2013-03-06 05:03:3717561600----a-w-C:\Windows\SysWow64\shell32.dll
2013-03-06 05:03:34199168----a-w-C:\Windows\SysWow64\shdocvw.dll
2013-03-02 10:57:4677544----a-w-C:\Windows\System32\drivers\storahci.sys
2013-03-02 10:57:46332520----a-w-C:\Windows\System32\drivers\storport.sys
2013-03-02 10:45:20148712----a-w-C:\Windows\System32\drivers\tpm.sys
2013-03-02 10:39:39495336----a-w-C:\Windows\System32\drivers\vhdmp.sys
2013-03-02 10:39:3869864----a-w-C:\Windows\System32\drivers\pdc.sys
2013-03-02 10:39:32327912----a-w-C:\Windows\System32\drivers\Classpnp.sys
2013-03-02 09:59:36411880----a-w-C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-03-02 08:23:30893952----a-w-C:\Windows\SysWow64\winmde.dll
2013-03-02 08:23:301338880----a-w-C:\Windows\SysWow64\WindowsCodecs.dll
2013-03-02 08:23:28601088----a-w-C:\Windows\SysWow64\Windows.Globalization.dll
2013-03-02 08:23:28504320----a-w-C:\Windows\SysWow64\Windows.Security.Authentication.OnlineId.dll
2013-03-02 08:23:04356352----a-w-C:\Windows\SysWow64\SettingSync.dll
2013-03-02 08:23:04100864----a-w-C:\Windows\SysWow64\SettingSyncInfo.dll
2013-03-02 08:23:00375808----a-w-C:\Windows\SysWow64\ReAgent.dll
2013-03-02 08:22:36357888----a-w-C:\Windows\SysWow64\netcfgx.dll
2013-03-02 08:22:325091840----a-w-C:\Windows\SysWow64\mstscax.dll
2013-03-02 08:21:56550912----a-w-C:\Windows\SysWow64\drvstore.dll
2013-03-02 08:21:5236352----a-w-C:\Windows\SysWow64\DevDispItemProvider.dll
2013-03-02 08:21:32145408----a-w-C:\Windows\SysWow64\powercfg.cpl
2013-03-02 02:44:59448512----a-w-C:\Windows\System32\SettingSync.dll
2013-03-02 02:44:59128512----a-w-C:\Windows\System32\SettingSyncInfo.dll
2013-03-02 02:44:561011200----a-w-C:\Windows\System32\reseteng.dll
2013-03-02 02:44:41455168----a-w-C:\Windows\System32\netcfgx.dll
2013-03-02 02:44:41117248----a-w-C:\Windows\System32\NdisImPlatform.dll
2013-03-02 02:44:385978624----a-w-C:\Windows\System32\mstscax.dll
2013-03-02 02:44:08703488----a-w-C:\Windows\System32\drvstore.dll
2013-03-02 02:44:07150016----a-w-C:\Windows\System32\discan.dll
2013-03-02 02:44:0549152----a-w-C:\Windows\System32\DevDispItemProvider.dll
2013-03-02 02:43:591933312----a-w-C:\Windows\System32\wbem\cimwin32.dll
2013-03-02 02:43:512146304----a-w-C:\Windows\System32\actxprxy.dll
2013-03-02 02:43:50156160----a-w-C:\Windows\System32\powercfg.cpl
2013-03-02 02:15:5326112----a-w-C:\Windows\System32\drivers\mouhid.sys
2013-03-01 04:56:1830720----a-w-C:\Windows\System32\drivers\monitor.sys
2013-02-21 10:29:3939424----a-w-C:\Windows\SysWow64\jsproxy.dll
2013-02-21 10:29:3761440----a-w-C:\Windows\SysWow64\iesetup.dll
2013-02-21 10:29:3733280----a-w-C:\Windows\SysWow64\iernonce.dll
2013-02-21 10:29:37109056----a-w-C:\Windows\SysWow64\iesysprep.dll
2013-02-21 10:14:0953248----a-w-C:\Windows\System32\jsproxy.dll
2013-02-21 10:14:05136704----a-w-C:\Windows\System32\iesysprep.dll
2013-02-19 15:07:2883688----a-w-C:\Windows\System32\mcupdate_AuthenticAMD.dll
2013-02-19 09:53:00534528----a-w-C:\Windows\SysWow64\uxtheme.dll
2013-02-15 07:58:5939936----a-w-C:\Windows\apppatch\apppatch64\acspecfc.dll
2013-02-12 00:17:5020992----a-w-C:\Windows\System32\drivers\usb8023.sys
2013-02-07 01:33:01754176----a-w-C:\Windows\SysWow64\actxprxy.dll
2013-02-05 22:29:09370688----a-w-C:\Windows\System32\drivers\mrxsmb.sys
2013-02-05 22:28:36215552----a-w-C:\Windows\System32\drivers\mrxsmb20.sys
.
============= FINISH: 19:48:09.65 ===============