FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-03-2016 01
Ran by Daniel M. Burkus (administrator) on PC (27-03-2016 14:17:51)
Running from C:\My Documents\A - Software Shortcuts\Malware Scanning Tools
Loaded Profiles: Daniel M. Burkus (Available Profiles: Daniel M. Burkus)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
() C:\Program Files\Unlocker\UnlockerAssistant.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
() C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [1793736 2015-02-20] (NVIDIA Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-24] (AVAST Software)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM\...\Run: [UnlockerAssistant] => C:\Program Files\Unlocker\UnlockerAssistant.exe [17408 2010-07-05] ()
HKLM\...\Run: [NeroFilterCheck] => C:\Windows\system32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6825888 2016-03-26] (SUPERAntiSpyware)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2016-01-29] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-03-02] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Smart Wizard.lnk [2016-03-26]
ShortcutTarget: NETGEAR WNDA3100v2 Smart Wizard.lnk -> C:\Program Files\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2016-02-21]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{64DEE58B-1BB1-4EC3-A5F5-F207663D912E}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{66B87001-DA33-470B-9512-77BE9AE4D883}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{B3CE4C30-3C2F-4806-AE63-1892B7E644A5}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1259038908-1583320175-680065255-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-1259038908-1583320175-680065255-1005 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-02] (AVAST Software)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
FireFox:
========
FF ProfilePath: C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\aich2zne.default
FF Homepage: hxxps://login.yahoo.com/?.src=ym&.intl=us&.lang=en-US&.done=https%3a//mail.yahoo.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-04] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-04] (NVIDIA Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-19] (Adobe Systems Inc.)
FF Extension: CacheViewer - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\aich2zne.default\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}.xpi [2016-03-24]
FF Extension: Restart Button - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\aich2zne.default\extensions\restartbutton@strk.jp.xpi [2016-03-24]
FF Extension: CacheViewer2 - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\aich2zne.default\extensions\cacheview2@scriptkitz.ml [2016-03-24]
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\aich2zne.default\extensions\artur.dubovoy@gmail.com [2016-03-24]
FF Extension: AdBlock Ultimate - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\aich2zne.default\Extensions\adblockultimate@adblockultimate.net.xpi [2016-03-24]
FF Extension: Click to Play per-element - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\aich2zne.default\Extensions\ClickToPlayPerElement@uaSad.addons.mozilla.org.xpi [2016-03-26]
FF Extension: Webmail Ad Blocker - C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla\Firefox\Profiles\aich2zne.default\Extensions\gmailnoads@mywebber.com.xpi [2016-03-24]
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-20] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-24]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-03-24]
Chrome:
=======
CHR Profile: C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-24]
CHR Extension: (No Name) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-24]
CHR Extension: (Avast SafePrice) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-03-24]
CHR Extension: (Avast Online Security) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-03-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-24]
CHR Extension: (Gmail) - C:\Users\Daniel M. Burkus.PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-24]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-23] (SUPERAntiSpyware.com)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-02] (AVAST Software)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1570520 2016-02-02] (Secunia)
S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [837848 2016-02-02] (Secunia)
S3 SophosVirusRemovalTool; C:\Program Files\Sophos\Sophos Virus Removal Tool\SVRTservice.exe [153352 2015-10-20] (Sophos Limited)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 WSWNDA3100; C:\Program Files\NETGEAR\WNDA3100v2\WifiSvc.exe [272864 2010-08-19] ()
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [32792 2016-03-02] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [35096 2016-03-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [91168 2016-03-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [91232 2016-03-02] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [58776 2016-03-02] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [816304 2016-03-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447848 2016-03-02] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [127432 2016-03-02] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [221240 2016-03-02] (AVAST Software)
R3 BCMH43XX; C:\Windows\System32\DRIVERS\bcmwlhigh6.sys [699896 2009-11-06] (Broadcom Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2016-02-02] (Secunia)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 SCMNdisP; C:\Windows\System32\DRIVERS\scmndisp.sys [21728 2007-01-19] (Windows (R) Codename Longhorn DDK provider)
R1 SCT_SKMScan; C:\Windows\System32\DRIVERS\sct_skmscan.sys [33096 2012-10-12] (Sophos Limited)
S3 SIVDriver; C:\Windows\system32\Drivers\SIVX32.sys [134928 2016-02-14] (Ray Hinchliffe)
R3 vpcbus; C:\Windows\System32\DRIVERS\vpchbus.sys [172416 2010-11-20] (Microsoft Corporation)
R1 vpcnfltr; C:\Windows\System32\DRIVERS\vpcnfltr.sys [48128 2010-11-20] (Microsoft Corporation)
R3 vpcusb; C:\Windows\System32\DRIVERS\vpcusb.sys [78336 2010-11-20] (Microsoft Corporation)
R1 vpcvmm; C:\Windows\System32\drivers\vpcvmm.sys [296064 2010-11-20] (Microsoft Corporation)
S3 catchme; \??\C:\Users\DANIEL~1.PC\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-26 21:31 - 2016-03-26 21:31 - 00033063 _____ C:\ComboFix.txt
2016-03-26 19:27 - 2016-03-26 19:27 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\CrashDumps
2016-03-26 17:13 - 2016-03-26 17:15 - 00000000 ____D C:\My Documents
2016-03-26 17:13 - 2016-03-26 17:13 - 00000723 _____ C:\Users\Daniel M. Burkus.PC\Desktop\My Documents - Shortcut.lnk
2016-03-26 15:13 - 2016-03-26 21:35 - 00007392 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Elmar's letter..txt
2016-03-26 12:54 - 2016-03-26 13:07 - 00000000 ____D C:\AdwCleaner
2016-03-26 11:06 - 2016-03-27 11:44 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\New Scans
2016-03-26 10:10 - 2016-03-26 10:10 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-03-26 10:10 - 2016-03-26 10:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WNDA3100v2 Smart Wizard
2016-03-26 10:10 - 2016-03-26 10:10 - 00000000 ____D C:\Program Files\NETGEAR
2016-03-26 10:10 - 2010-02-03 11:20 - 00050704 _____ (CACE Technologies, Inc.) C:\Windows\system32\Drivers\npf.sys
2016-03-26 10:10 - 2009-11-06 08:37 - 00699896 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\bcmwlhigh6.sys
2016-03-26 10:10 - 2009-11-06 08:31 - 03862528 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv.dll
2016-03-26 10:10 - 2009-11-06 08:31 - 03551232 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui.dll
2016-03-26 10:10 - 2009-11-06 08:31 - 01176312 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2016-03-26 10:10 - 2009-11-06 08:31 - 00091376 _____ (Broadcom Corporation) C:\Windows\system32\bcmwlcoi.dll
2016-03-26 10:10 - 2007-01-19 18:20 - 00021728 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Drivers\SCMNdisP.sys
2016-03-26 07:46 - 2016-03-27 14:17 - 00000000 ____D C:\FRST
2016-03-26 07:46 - 2016-03-26 12:52 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\SCANS
2016-03-26 07:03 - 2016-03-24 09:12 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts.20160326-070351.backup
2016-03-25 18:43 - 2016-03-26 19:16 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2016-03-25 18:43 - 2016-03-25 18:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2016-03-25 16:49 - 2016-03-26 09:33 - 00000000 ____D C:\Restore Removed Folders
2016-03-25 15:39 - 2016-03-25 15:44 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\AVMedia Files
2016-03-25 14:57 - 2016-03-25 14:57 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\SUPERAntiSpyware.com
2016-03-25 07:49 - 2016-03-25 07:54 - 00000000 ____D C:\Program Files\Software by Design
2016-03-25 07:49 - 2016-03-25 07:49 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Software by Design
2016-03-25 07:49 - 2013-04-09 15:00 - 00086016 ____N (Software Design) C:\Windows\SDUnInst.exe
2016-03-25 07:33 - 2016-03-21 21:47 - 00001245 _____ C:\Users\Daniel M. Burkus.PC\Desktop\taskmanager.exe.lnk
2016-03-25 07:33 - 2016-03-14 07:41 - 00001480 _____ C:\Users\Daniel M. Burkus.PC\Desktop\KB LIST.txt.lnk
2016-03-25 07:33 - 2016-03-13 11:42 - 00000561 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Windows Update.lnk
2016-03-24 22:26 - 2016-03-24 22:26 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (7), Notes.txt
2016-03-24 22:26 - 2016-03-24 22:26 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (6), Notes.txt
2016-03-24 22:26 - 2016-03-24 22:26 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (5), Notes.txt
2016-03-24 22:26 - 2016-03-24 22:26 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (4), Notes.txt
2016-03-24 22:26 - 2016-03-24 22:26 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (3), Notes.txt
2016-03-24 22:26 - 2016-03-24 22:26 - 00000272 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (2), Notes.txt
2016-03-24 22:25 - 2016-03-25 10:23 - 00007592 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (1), Notes.txt
2016-03-24 22:24 - 2016-03-25 09:22 - 00000282 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (7).txt
2016-03-24 22:24 - 2016-03-25 09:22 - 00000282 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (6).txt
2016-03-24 22:24 - 2016-03-25 09:22 - 00000282 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (5).txt
2016-03-24 22:24 - 2016-03-25 09:22 - 00000282 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (4).txt
2016-03-24 22:23 - 2016-03-25 10:25 - 00000640 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (1).txt
2016-03-24 22:23 - 2016-03-25 09:22 - 00000282 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (3).txt
2016-03-24 22:23 - 2016-03-25 09:21 - 00000282 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Bon-date no Densho (2).txt
2016-03-24 21:39 - 2016-03-24 21:40 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\14 - Bon-date no Densho
2016-03-24 21:37 - 2016-03-24 21:47 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Desktop\13 - Matsue Sotoku-ate no Densho
2016-03-24 20:56 - 2016-03-24 22:29 - 00000858 _____ C:\Users\Daniel M. Burkus.PC\Desktop\Blog Templates.txt
2016-03-24 20:40 - 2016-03-24 20:41 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\Blog Documents
2016-03-24 20:26 - 2016-03-24 20:26 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\WinRAR
2016-03-24 19:46 - 2016-03-24 19:46 - 00931330 _____ C:\Users\Daniel M. Burkus.PC\Desktop\To Kill a Mockingbird (Harper Lee).pdf
2016-03-24 19:45 - 2016-03-24 19:45 - 00546794 _____ C:\Users\Daniel M. Burkus.PC\Desktop\The Perks of Being a Wallflower (Stephen Chbosky).pdf
2016-03-24 19:18 - 2016-03-24 19:18 - 00000913 _____ C:\ProgramData\ReclaiMe.config
2016-03-24 19:18 - 2016-03-24 19:18 - 00000438 _____ C:\Users\Daniel M. Burkus.PC\AppData\Local\ReclaiMe.config
2016-03-24 19:10 - 2016-03-24 19:12 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Foxit Software
2016-03-24 19:10 - 2016-03-24 19:10 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\LocalLow\Adobe
2016-03-24 19:10 - 2016-03-24 19:10 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\CEF
2016-03-24 19:10 - 2016-03-24 19:10 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\Adobe
2016-03-24 16:22 - 2016-03-24 16:22 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\HWP
2016-03-24 16:17 - 2016-03-24 16:17 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\IrfanView
2016-03-24 16:02 - 2016-03-24 16:02 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\NVIDIA
2016-03-24 16:02 - 2016-03-24 16:02 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\GRETECH
2016-03-24 13:40 - 2016-03-24 13:41 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Hnc
2016-03-24 13:15 - 2016-03-24 18:40 - 00000000 ____D C:\Program Files\Recuva
2016-03-24 13:15 - 2016-03-24 13:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2016-03-24 10:32 - 2016-03-24 10:32 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\ElevatedDiagnostics
2016-03-24 09:58 - 2016-03-24 09:58 - 00000000 ____D C:\Users\Daniel M. Burkus (n)\AppData\Roaming\AVAST Software
2016-03-24 09:58 - 2016-03-24 09:58 - 00000000 ____D C:\Users\Daniel M. Burkus (n)\AppData\Roaming\Adobe
2016-03-24 09:58 - 2016-03-24 09:58 - 00000000 ____D C:\Users\Daniel M. Burkus (n)\AppData\Local\NVIDIA
2016-03-24 09:58 - 2016-03-24 09:58 - 00000000 ____D C:\Users\Daniel M. Burkus (n)\AppData\Local\Google
2016-03-24 09:57 - 2016-03-24 10:08 - 00000000 ____D C:\Users\Daniel M. Burkus (n)
2016-03-24 09:57 - 2016-03-24 09:57 - 00000000 _SHDL C:\Users\Daniel M. Burkus (n)\My Documents
2016-03-24 09:57 - 2016-03-24 09:57 - 00000000 _SHDL C:\Users\Daniel M. Burkus (n)\Documents\My Videos
2016-03-24 09:57 - 2016-03-24 09:57 - 00000000 _SHDL C:\Users\Daniel M. Burkus (n)\Documents\My Pictures
2016-03-24 09:57 - 2016-03-24 09:57 - 00000000 _SHDL C:\Users\Daniel M. Burkus (n)\Documents\My Music
2016-03-24 09:57 - 2016-03-24 09:57 - 00000000 ____D C:\Users\Daniel M. Burkus (n)\AppData\Local\VirtualStore
2016-03-24 09:42 - 2016-03-24 09:42 - 00000000 ____D C:\Users\Daniel Burkus\AppData\Roaming\SUPERAntiSpyware.com
2016-03-24 09:42 - 2016-03-24 09:42 - 00000000 ____D C:\Users\Daniel Burkus\AppData\Roaming\AVAST Software
2016-03-24 08:57 - 2011-06-26 15:45 - 00256000 _____ C:\Windows\PEV.exe
2016-03-24 08:57 - 2010-11-08 02:20 - 00208896 _____ C:\Windows\MBR.exe
2016-03-24 08:57 - 2009-04-20 13:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2016-03-24 08:57 - 2000-08-31 09:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2016-03-24 08:57 - 2000-08-31 09:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2016-03-24 08:57 - 2000-08-31 09:00 - 00098816 _____ C:\Windows\sed.exe
2016-03-24 08:57 - 2000-08-31 09:00 - 00080412 _____ C:\Windows\grep.exe
2016-03-24 08:57 - 2000-08-31 09:00 - 00068096 _____ C:\Windows\zip.exe
2016-03-24 08:52 - 2016-03-24 10:06 - 00000000 ____D C:\Scans to Run
2016-03-24 08:48 - 2016-03-26 21:31 - 00000000 ____D C:\Qoobox
2016-03-24 08:45 - 2016-03-24 08:45 - 01725440 _____ (Farbar) C:\FRST.exe
2016-03-24 08:40 - 2016-03-24 08:40 - 05658151 ____R (Swearware) C:\ComboFix.exe
2016-03-24 08:37 - 2016-03-24 08:37 - 00064568 _____ C:\Users\Daniel M. Burkus.PC\AppData\Local\GDIPFONTCACHEV1.DAT
2016-03-24 08:05 - 2016-03-24 08:05 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Macromedia
2016-03-24 08:05 - 2016-03-24 08:05 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\Macromedia
2016-03-24 08:02 - 2016-03-24 10:06 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Mozilla
2016-03-24 08:02 - 2016-03-24 10:06 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\Mozilla
2016-03-24 08:00 - 2016-03-24 19:10 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Adobe
2016-03-24 08:00 - 2016-03-24 10:06 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\NVIDIA
2016-03-24 08:00 - 2016-03-24 08:00 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Roaming\AVAST Software
2016-03-24 07:59 - 2016-03-26 21:05 - 00000000 ____D C:\Users\Daniel M. Burkus.PC
2016-03-24 07:59 - 2016-03-25 18:48 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\VirtualStore
2016-03-24 07:59 - 2016-03-24 10:06 - 00000000 ____D C:\Users\Daniel M. Burkus.PC\AppData\Local\Google
2016-03-24 07:59 - 2016-03-24 07:59 - 00001413 _____ C:\Users\Daniel M. Burkus.PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-03-24 07:59 - 2016-03-24 07:59 - 00000020 ___SH C:\Users\Daniel M. Burkus.PC\ntuser.ini
2016-03-24 07:59 - 2016-03-24 07:59 - 00000000 _SHDL C:\Users\Daniel M. Burkus.PC\My Documents
2016-03-24 07:50 - 2016-03-24 07:50 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Roaming\Macromedia
2016-03-24 07:50 - 2016-03-24 07:50 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Local\Macromedia
2016-03-24 07:48 - 2016-03-24 10:06 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Roaming\Mozilla
2016-03-24 07:48 - 2016-03-24 10:06 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Local\Mozilla
2016-03-24 07:46 - 2016-03-24 10:06 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Local\NVIDIA
2016-03-24 07:46 - 2016-03-24 07:46 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Roaming\AVAST Software
2016-03-24 07:46 - 2016-03-24 07:46 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Roaming\Adobe
2016-03-24 07:45 - 2016-03-24 10:07 - 00000000 ___RD C:\Users\TEMP.PC.001\Virtual Machines
2016-03-24 07:45 - 2016-03-24 10:06 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Local\Google
2016-03-24 07:45 - 2016-03-24 07:47 - 00002201 _____ C:\Users\TEMP.PC.001\Desktop\Google Chrome.lnk
2016-03-24 07:45 - 2016-03-24 07:45 - 00001413 _____ C:\Users\TEMP.PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-03-24 07:44 - 2016-03-24 10:07 - 00000000 ____D C:\Users\TEMP.PC.001
2016-03-24 07:44 - 2016-03-24 07:44 - 00000020 ___SH C:\Users\TEMP.PC.001\ntuser.ini
2016-03-24 07:44 - 2016-03-24 07:44 - 00000000 _SHDL C:\Users\TEMP.PC.001\My Documents
2016-03-24 07:44 - 2016-03-24 07:44 - 00000000 _SHDL C:\Users\TEMP.PC.001\Documents\My Videos
2016-03-24 07:44 - 2016-03-24 07:44 - 00000000 _SHDL C:\Users\TEMP.PC.001\Documents\My Pictures
2016-03-24 07:44 - 2016-03-24 07:44 - 00000000 _SHDL C:\Users\TEMP.PC.001\Documents\My Music
2016-03-24 07:44 - 2016-03-24 07:44 - 00000000 ____D C:\Users\TEMP.PC.001\AppData\Local\VirtualStore
2016-03-24 07:43 - 2016-03-24 07:43 - 00003528 ____N C:\bootsqm.dat
2016-03-24 06:46 - 2016-03-24 06:46 - 00064568 _____ C:\Users\TEMP.PC.000\AppData\Local\GDIPFONTCACHEV1.DAT
2016-03-24 06:40 - 2016-03-24 10:07 - 00000000 ___RD C:\Users\TEMP.PC.000\Virtual Machines
2016-03-24 06:40 - 2016-03-24 10:06 - 00000000 ____D C:\Users\TEMP.PC.000\AppData\Local\NVIDIA
2016-03-24 06:40 - 2016-03-24 10:06 - 00000000 ____D C:\Users\TEMP.PC.000\AppData\Local\Google
2016-03-24 06:40 - 2016-03-24 06:42 - 00002201 _____ C:\Users\TEMP.PC.000\Desktop\Google Chrome.lnk
2016-03-24 06:40 - 2016-03-24 06:40 - 00001413 _____ C:\Users\TEMP.PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-03-24 06:40 - 2016-03-24 06:40 - 00000000 ____D C:\Users\TEMP.PC.000\AppData\Roaming\AVAST Software
2016-03-24 06:40 - 2016-03-24 06:40 - 00000000 ____D C:\Users\TEMP.PC.000\AppData\Roaming\Adobe
2016-03-24 06:39 - 2016-03-24 10:07 - 00000000 ____D C:\Users\TEMP.PC.000
2016-03-24 06:39 - 2016-03-24 06:39 - 00000020 ___SH C:\Users\TEMP.PC.000\ntuser.ini
2016-03-24 06:39 - 2016-03-24 06:39 - 00000000 _SHDL C:\Users\TEMP.PC.000\My Documents
2016-03-24 06:39 - 2016-03-24 06:39 - 00000000 _SHDL C:\Users\TEMP.PC.000\Documents\My Videos
2016-03-24 06:39 - 2016-03-24 06:39 - 00000000 _SHDL C:\Users\TEMP.PC.000\Documents\My Pictures
2016-03-24 06:39 - 2016-03-24 06:39 - 00000000 _SHDL C:\Users\TEMP.PC.000\Documents\My Music
2016-03-24 06:39 - 2016-03-24 06:39 - 00000000 ____D C:\Users\TEMP.PC.000\AppData\Local\VirtualStore
2016-03-24 06:28 - 2016-03-24 06:28 - 00064568 _____ C:\Users\TEMP.PC\AppData\Local\GDIPFONTCACHEV1.DAT
2016-03-24 06:28 - 2016-03-24 06:28 - 00000000 ____D C:\Users\TEMP.PC\AppData\Roaming\AVAST Software
2016-03-24 06:28 - 2016-03-24 06:28 - 00000000 ____D C:\Users\TEMP.PC\AppData\Roaming\Adobe
2016-03-24 06:27 - 2016-03-24 10:07 - 00000000 ___RD C:\Users\TEMP.PC\Virtual Machines
2016-03-24 06:27 - 2016-03-24 10:07 - 00000000 ____D C:\Users\TEMP.PC
2016-03-24 06:27 - 2016-03-24 10:06 - 00000000 ____D C:\Users\TEMP.PC\AppData\Local\NVIDIA
2016-03-24 06:27 - 2016-03-24 10:06 - 00000000 ____D C:\Users\TEMP.PC\AppData\Local\Google
2016-03-24 06:27 - 2016-03-24 06:29 - 00002201 _____ C:\Users\TEMP.PC\Desktop\Google Chrome.lnk
2016-03-24 06:27 - 2016-03-24 06:27 - 00001413 _____ C:\Users\TEMP.PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-03-24 06:27 - 2016-03-24 06:27 - 00000020 ___SH C:\Users\TEMP.PC\ntuser.ini
2016-03-24 06:27 - 2016-03-24 06:27 - 00000000 _SHDL C:\Users\TEMP.PC\My Documents
2016-03-24 06:27 - 2016-03-24 06:27 - 00000000 _SHDL C:\Users\TEMP.PC\Documents\My Videos
2016-03-24 06:27 - 2016-03-24 06:27 - 00000000 _SHDL C:\Users\TEMP.PC\Documents\My Pictures
2016-03-24 06:27 - 2016-03-24 06:27 - 00000000 _SHDL C:\Users\TEMP.PC\Documents\My Music
2016-03-24 06:27 - 2016-03-24 06:27 - 00000000 ____D C:\Users\TEMP.PC\AppData\Local\VirtualStore
2016-03-23 21:17 - 2016-03-23 21:17 - 00035096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-03-23 21:17 - 2016-03-23 21:17 - 00001118 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-23 16:09 - 2016-03-24 10:06 - 00000000 ____D C:\Users\Public\Foxit Software
2016-03-23 15:47 - 2016-03-23 22:30 - 00000000 ____D C:\Users\TEMP\AppData\Local\Google
2016-03-23 15:46 - 2016-03-23 22:31 - 00000000 ____D C:\Users\TEMP
2016-03-23 15:46 - 2016-03-23 22:30 - 00000000 ____D C:\Users\TEMP\AppData\Local\VirtualStore
2016-03-20 06:01 - 2016-03-24 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2016-03-20 06:01 - 2016-03-20 06:01 - 00000000 ____D C:\ProgramData\Foxit ContentPlatform
2016-03-20 06:00 - 2016-03-20 06:00 - 00000000 ____D C:\Program Files\Foxit Software
2016-03-17 08:50 - 2016-03-24 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeOCR
2016-03-17 08:50 - 2016-03-24 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AbleWord
2016-03-17 08:50 - 2016-03-17 09:06 - 00000000 ____D C:\FreeOCR
2016-03-17 08:50 - 2016-03-17 08:50 - 00000000 ____D C:\Program Files\AbleWord
2016-03-17 08:50 - 2007-03-10 10:11 - 02680320 _____ (HiComponents) C:\Windows\system32\ImageEnXLibrary.ocx
2016-03-13 16:00 - 2016-02-12 03:44 - 03994560 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2016-03-13 16:00 - 2016-02-12 03:44 - 03938240 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-03-13 16:00 - 2016-02-12 03:44 - 00138176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-03-13 16:00 - 2016-02-12 03:44 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-03-13 16:00 - 2016-02-12 03:41 - 01310232 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-03-13 16:00 - 2016-02-12 03:38 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-03-13 16:00 - 2016-02-12 03:38 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-03-13 16:00 - 2016-02-12 03:37 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-03-13 16:00 - 2016-02-12 03:37 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-03-13 16:00 - 2016-02-12 03:37 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-03-13 16:00 - 2016-02-12 03:37 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-03-13 16:00 - 2016-02-12 03:37 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-03-13 16:00 - 2016-02-12 03:37 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-03-13 16:00 - 2016-02-12 03:35 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-03-13 16:00 - 2016-02-12 03:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-03-13 16:00 - 2016-02-12 03:35 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-03-13 16:00 - 2016-02-12 03:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-03-13 16:00 - 2016-02-12 03:33 - 01060864 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-03-13 16:00 - 2016-02-12 03:33 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-03-13 16:00 - 2016-02-12 03:31 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-03-13 16:00 - 2016-02-12 03:31 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-03-13 16:00 - 2016-02-12 03:30 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-03-13 16:00 - 2016-02-12 03:30 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-03-13 16:00 - 2016-02-12 03:30 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-03-13 16:00 - 2016-02-12 02:43 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-03-13 16:00 - 2016-02-12 02:37 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-03-13 16:00 - 2016-02-12 02:32 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-03-13 16:00 - 2016-02-12 02:32 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-03-13 16:00 - 2016-02-12 02:32 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-03-13 16:00 - 2016-02-12 02:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-03-13 16:00 - 2016-02-12 02:30 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-03-13 16:00 - 2016-02-12 02:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-03-13 16:00 - 2016-02-12 02:30 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-03-13 15:59 - 2016-02-05 02:46 - 02387456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-03-13 15:58 - 2016-02-06 03:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-03-13 15:58 - 2016-02-06 03:44 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-03-13 15:58 - 2016-02-06 03:42 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-03-13 15:58 - 2016-02-06 02:43 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-03-13 15:58 - 2016-02-06 02:43 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-03-13 15:58 - 2016-02-05 03:41 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2016-03-13 15:58 - 2016-02-04 03:49 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2016-03-13 15:58 - 2016-02-04 03:49 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll
2016-03-13 15:58 - 2016-02-04 03:43 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-03-13 15:58 - 2016-02-04 02:59 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2016-03-13 12:27 - 2016-03-13 12:27 - 00000000 ____D C:\Windows\CheckSur
2016-03-13 09:48 - 2016-03-11 07:45 - 00006262 _____ C:\Windows\system32\Drivers\etc\hosts.20160313-094841.backup
2016-03-11 08:30 - 2016-03-26 06:30 - 00000000 ____D C:\Program Files\Google
2016-03-11 07:46 - 2016-03-11 07:46 - 00000000 ___HD C:\$windows.~bt
2016-03-11 07:42 - 2016-03-11 07:42 - 00000000 ____D C:\Program Files\AEGIS-Voat
2016-03-11 07:31 - 2016-03-11 07:31 - 00000000 ____D C:\2d3f5ed3ad81cf6d8f1e358b68f9
2016-03-10 21:46 - 2016-03-26 09:02 - 00000000 ____D C:\Program Files\AdwCleaner
2016-03-10 21:10 - 2016-02-09 18:50 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll
2016-03-09 06:03 - 2016-03-17 09:38 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-09 06:03 - 2016-03-09 06:03 - 00000000 ____D C:\Program Files\Common Files\Adobe
2016-03-09 06:03 - 2016-03-09 06:03 - 00000000 ____D C:\Program Files\Adobe
2016-03-02 07:31 - 2016-03-02 07:30 - 00334280 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-03-02 07:30 - 2016-03-02 07:30 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-03-01 22:38 - 2016-03-24 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Direct MIDI to MP3 Converter
2016-03-01 22:38 - 2016-03-01 22:38 - 00000000 ____D C:\Program Files\Direct MIDI to MP3 Converter
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-27 14:13 - 2016-01-29 01:50 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-27 14:13 - 2009-07-14 13:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-03-27 12:00 - 2009-07-14 13:34 - 00013904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-03-27 12:00 - 2009-07-14 13:34 - 00013904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-03-27 11:03 - 2016-02-19 17:18 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-03-26 21:25 - 2009-07-14 11:04 - 00000215 _____ C:\Windows\system.ini
2016-03-26 21:21 - 2016-02-19 14:55 - 00000000 ____D C:\Windows\erdnt
2016-03-26 20:11 - 2016-02-17 17:11 - 00000000 ____D C:\EEK
2016-03-26 11:55 - 2016-01-29 16:21 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-26 11:39 - 2016-02-15 14:58 - 00024688 _____ C:\Windows\system32\Drivers\TrueSight.sys
2016-03-26 11:10 - 2016-02-13 21:56 - 01127632 _____ C:\Windows\ntbtlog.txt
2016-03-26 10:16 - 2016-01-29 02:16 - 00429336 _____ C:\Windows\system32\perfh012.dat
2016-03-26 10:16 - 2016-01-29 02:16 - 00417690 _____ C:\Windows\system32\perfh011.dat
2016-03-26 10:16 - 2016-01-29 02:16 - 00401934 _____ C:\Windows\system32\prfh0404.dat
2016-03-26 10:16 - 2016-01-29 02:16 - 00384862 _____ C:\Windows\system32\prfh0804.dat
2016-03-26 10:16 - 2016-01-29 02:16 - 00122062 _____ C:\Windows\system32\perfc011.dat
2016-03-26 10:16 - 2016-01-29 02:16 - 00120346 _____ C:\Windows\system32\perfc012.dat
2016-03-26 10:16 - 2016-01-29 02:16 - 00119554 _____ C:\Windows\system32\prfc0804.dat
2016-03-26 10:16 - 2016-01-29 02:16 - 00115052 _____ C:\Windows\system32\prfc0404.dat
2016-03-26 10:16 - 2016-01-29 01:16 - 02850866 _____ C:\Windows\system32\PerfStringBackup.INI
2016-03-26 10:16 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\system32\NDF
2016-03-26 10:16 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\inf
2016-03-26 06:29 - 2016-01-29 16:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-26 06:29 - 2016-01-29 16:20 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-03-25 07:56 - 2009-07-14 11:04 - 00000442 _____ C:\Windows\win.ini
2016-03-24 18:03 - 2016-01-29 05:02 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-03-24 18:03 - 2016-01-29 05:02 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-03-24 10:31 - 2016-01-29 01:39 - 141270216 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-03-24 10:08 - 2016-01-29 01:14 - 00000000 ____D C:\Users\Daniel Burkus
2016-03-24 10:07 - 2016-02-20 07:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2016-03-24 10:07 - 2016-02-18 09:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ADS Scanner 2
2016-03-24 10:07 - 2016-02-15 14:57 - 00000000 ____D C:\ProgramData\RogueKiller
2016-03-24 10:07 - 2016-02-15 14:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2016-03-24 10:07 - 2016-02-06 17:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-24 10:07 - 2016-01-30 17:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player
2016-03-24 10:07 - 2016-01-30 09:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2016-03-24 10:07 - 2016-01-30 08:56 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Virtual PC
2016-03-24 10:07 - 2016-01-30 08:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HAANSOFT
2016-03-24 10:07 - 2016-01-30 08:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-03-24 10:07 - 2016-01-30 07:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Free
2016-03-24 10:07 - 2016-01-29 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-03-24 10:07 - 2016-01-29 21:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2016-03-24 10:07 - 2016-01-29 21:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
2016-03-24 10:07 - 2016-01-29 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3 Toolkit
2016-03-24 10:07 - 2016-01-29 20:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft
2016-03-24 10:07 - 2016-01-29 19:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2016-03-24 10:07 - 2016-01-29 19:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView
2016-03-24 10:07 - 2016-01-29 16:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2016-03-24 10:07 - 2016-01-29 16:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-03-24 10:07 - 2016-01-29 05:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KakaoTalk
2016-03-24 10:07 - 2016-01-29 05:02 - 00000000 ____D C:\Windows\system32\Macromed
2016-03-24 10:07 - 2016-01-29 05:02 - 00000000 ____D C:\Users\Daniel Burkus\AppData\Roaming\Adobe
2016-03-24 10:07 - 2016-01-29 02:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-03-24 10:07 - 2009-07-14 13:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-03-24 10:06 - 2016-01-29 16:29 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-24 10:06 - 2016-01-29 16:28 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-24 10:06 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\registration
2016-03-24 09:38 - 2016-01-29 02:52 - 00000000 ____D C:\Users\Daniel Burkus\AppData\Local\NVIDIA
2016-03-24 09:16 - 2016-01-30 09:26 - 00000000 ____D C:\Users\Daniel M. Burkus
2016-03-23 22:31 - 2016-01-29 20:10 - 00000000 ____D C:\Users\TEMP\Desktop\WORK
2016-03-23 22:30 - 2016-01-29 16:01 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\Mozilla
2016-03-23 22:30 - 2016-01-29 04:56 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\TuneUp Software
2016-03-22 14:45 - 2016-02-21 08:57 - 00000979 _____ C:\DelFix.txt
2016-03-21 06:49 - 2016-01-29 16:01 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-03-20 05:56 - 2016-02-12 06:49 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-03-19 13:48 - 2016-01-29 05:05 - 00001089 _____ C:\ProgramData\Microsoft\Windows\Start Menu\KakaoTalk.lnk
2016-03-18 15:40 - 2016-02-15 14:57 - 00000000 ____D C:\Program Files\RogueKiller
2016-03-15 09:38 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\rescache
2016-03-14 16:02 - 2009-07-14 13:52 - 00000000 ____D C:\Program Files\Windows Defender
2016-03-13 22:51 - 2016-01-29 01:39 - 00000000 ____D C:\Windows\system32\MRT
2016-03-13 20:20 - 2009-07-14 13:33 - 00309064 _____ C:\Windows\system32\FNTCACHE.DAT
2016-03-11 08:52 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-03-11 08:11 - 2009-07-14 13:52 - 00000000 ____D C:\Program Files\DVD Maker
2016-03-11 08:11 - 2009-07-14 11:37 - 00000000 ____D C:\Windows\tracing
2016-03-11 07:48 - 2016-01-31 19:55 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-03-11 07:48 - 2016-01-31 19:55 - 00000000 ____D C:\Windows\system32\appraiser
2016-03-10 14:09 - 2016-01-29 16:20 - 00053120 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-03-10 14:08 - 2016-01-29 16:20 - 00126336 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-03-10 14:08 - 2016-01-29 16:20 - 00024448 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-03-10 06:53 - 2016-01-29 16:31 - 00816304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2016-03-10 06:53 - 2016-01-29 16:31 - 00091168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2016-03-09 11:32 - 2009-07-14 13:53 - 00032600 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-03-09 11:32 - 2009-07-14 13:53 - 00032600 _____ C:\Windows\Tasks\SCHEDLGU(32).TXT
2016-03-09 06:38 - 2016-01-29 16:01 - 00001117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-09 06:02 - 2016-01-30 08:05 - 00000000 ____D C:\ProgramData\Adobe
2016-03-02 08:28 - 2016-01-29 21:31 - 00000000 ____D C:\Program Files\WinRAR
2016-03-02 07:32 - 2016-01-29 16:31 - 00447848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-03-02 07:32 - 2016-01-29 16:31 - 00221240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-03-02 07:31 - 2016-01-29 16:31 - 00127432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-03-02 07:30 - 2016-01-29 16:31 - 00091232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-03-02 07:30 - 2016-01-29 16:31 - 00058776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-03-02 07:30 - 2016-01-29 16:31 - 00032792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-03-01 16:56 - 2009-07-14 11:04 - 00450151 ____R C:\Windows\system32\Drivers\etc\hosts.20160306-120250.backup
2016-02-29 18:11 - 2016-01-29 21:02 - 00000000 ____D C:\Program Files\Audacity
2016-02-29 18:08 - 2016-01-29 21:02 - 00000977 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2016-02-29 09:06 - 2009-07-14 11:04 - 00450151 ____R C:\Windows\system32\Drivers\etc\hosts.20160301-165623.backup
==================== Files in the root of some directories =======
2016-03-24 19:18 - 2016-03-24 19:18 - 0000438 _____ () C:\Users\Daniel M. Burkus.PC\AppData\Local\ReclaiMe.config
2016-03-24 19:18 - 2016-03-24 19:18 - 0000913 _____ () C:\ProgramData\ReclaiMe.config
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll
[2016-01-31 08:35] - [2009-07-14 10:16] - 0811520 ____A (Microsoft Corporation) 8626F0C30D4E3564FFDD25C90F4426F1
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-19 12:03
==================== End of FRST.txt ============================