Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2013 01
Ran by Bill @ Deb (administrator) on GINN-PC on 11-11-2013 12:01:37
Running from C:\Users\Bill @ Deb\Desktop
Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(Andrea Electronics Corporation) C:\Windows\system32\AERTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(WebEx Communications, Inc.) C:\Windows\SysWOW64\atashost.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
(Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
(Realtek Semiconductor) C:\Windows\RAVCpl64.exe
() C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
(Southwest Airlines) C:\Program Files (x86)\Southwest Airlines\Ding\Ding.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(SlySoft, Inc.) C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
(Motorola Mobility Inc.) C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoCast.exe
() C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
() C:\Program Files (x86)\SlySoft\AnyDVD\ADvdDiscHlp64.exe
() C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe
(Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-20] (Microsoft Corporation)
HKLM\...\Run: [Skytel] - Skytel.exe
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RAVCpl64.exe [6431232 2008-07-18] (Realtek Semiconductor)
HKLM\...\Run: [WrtMon.exe] - C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe [20480 2006-09-20] ()
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE [2782096 2010-07-25] (CANON INC.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1356240 2013-08-12] (Microsoft Corporation)
HKCU\...\Run: [AnyDVD] - C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVD.exe [94296 2013-10-25] (SlySoft, Inc.)
HKCU\...\Run: [MotoCast] - C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk [1888 2012-12-13] ()
HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION
HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1213848 2010-09-14] (CANON INC.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2010-09-09] (CANON INC.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - "C:\Program Files (x86)\Java\jre7\bin\jusched.exe"
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [ApnUpdater] - "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-23] (Apple Inc.)
AppInit_DLLs-x32: C:\PROGRA~2\BEARSH~1\MediaBar\Datamngr\datamngr.dll [1453192 2012-06-06] (MusicLab, LLC)
Startup: C:\Users\Bill @ Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Bill @ Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DING!.lnk
ShortcutTarget: DING!.lnk -> C:\Program Files (x86)\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.rr.com/
StartMenuInternet: IEXPLORE.EXE - %ProgramFiles(x86)%\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL =
http://dts.search-results.com/sr?src=ieb&appid=221&systemid=1&sr=0&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL =
http://dts.search-results.com/sr?src=ieb&appid=221&systemid=1&sr=0&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL =
http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL =
http://dts.search-results.com/sr?src=ieb&appid=221&systemid=1&sr=0&q={searchTerms}
SearchScopes: HKLM-x32 - {6BD63EF5-F376-4104-B390-F6E1E3BEDAAC} URL =
http://startsear.ch/?q={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL =
http://dts.search-results.com/sr?src=ieb&appid=221&systemid=1&sr=0&q={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL =
http://dts.search-results.com/sr?src=ieb&appid=20&systemid=2&sr=0&q={searchTerms}
SearchScopes: HKCU - {6BD63EF5-F376-4104-B390-F6E1E3BEDAAC} URL =
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL =
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: DataMngr - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\x64\BrowserConnection.dll (MusicLab, LLC)
BHO-x32: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: DataMngr - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC)
BHO-x32: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - !{57425637-0076-A76A-76A7-7A786E7484D7} - No File
Toolbar: HKLM-x32 - Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files (x86)\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
Toolbar: HKLM-x32 - No Name - !{57425637-0076-A76A-76A7-7A786E7484D7} - No File
Toolbar: HKLM-x32 - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No File
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.100.1
Chrome:
=======
CHR Extension: (AT_Porsche) - C:\Users\BILL@D~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3
==================== Services (Whitelisted) =================
R2 AERTFilters; C:\Windows\system32\AERTSr64.exe [86016 2008-07-18] (Andrea Electronics Corporation)
R2 atashost; C:\Windows\SysWOW64\atashost.exe [20376 2009-03-06] (WebEx Communications, Inc.)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [185688 2013-03-27] (Garmin Ltd or its subsidiaries)
S2 gupdate1ca0d49557030b0; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [133104 2009-07-25] (Google Inc.)
S2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [109352 2013-11-03] (SurfRight B.V.)
R2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [137528 2013-07-31] (Motorola Mobility LLC)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-08-12] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366600 2013-08-12] (Microsoft Corporation)
S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x]
==================== Drivers (Whitelisted) ====================
R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [139352 2013-07-31] (SlySoft, Inc.)
R3 AnyDVD; C:\Windows\SysWow64\Drivers\AnyDVD.sys [139352 2013-07-31] (SlySoft, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [247216 2013-06-18] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [139616 2013-06-18] (Microsoft Corporation)
S3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [60416 2007-08-23] (Dynex)
R2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [26624 2008-07-21] (Windows (R) Codename Longhorn DDK provider)
S3 Rtnic64; C:\Windows\System32\DRIVERS\Rtnic64.sys [60416 2007-08-23] (Dynex)
S3 BTCFilterService; system32\DRIVERS\motfilt.sys [x]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 MFE_RR; \??\C:\Users\BILL@D~1\AppData\Local\Temp\mfe_rr.sys [x]
S3 motandroidusb; System32\Drivers\motoandroid.sys [x]
S3 motccgp; system32\DRIVERS\motccgp.sys [x]
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [x]
S3 MotoSwitchService; system32\DRIVERS\motswch.sys [x]
S3 Motousbnet; system32\DRIVERS\Motousbnet.sys [x]
S3 motusbdevice; system32\DRIVERS\motusbdevice.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-11 12:00 - 2013-11-11 12:00 - 00000000 ____D C:\FRST
2013-11-11 11:59 - 2013-11-11 11:59 - 01957590 _____ (Farbar) C:\Users\Bill @ Deb\Desktop\FRST64.exe
2013-11-11 10:00 - 2013-11-11 10:28 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-11 10:00 - 2013-11-11 10:00 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-11-11 09:59 - 2013-11-11 09:59 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-11-11 09:58 - 2013-11-11 10:28 - 00000000 ____D C:\Users\Bill @ Deb\Desktop\mbar
2013-11-11 09:50 - 2013-11-11 09:50 - 17833984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 12336128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-11 09:50 - 2013-11-11 09:50 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-11 09:50 - 2013-11-11 09:50 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-11 09:50 - 2013-11-11 09:50 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-11 09:50 - 2013-11-11 09:50 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-11 09:50 - 2013-11-11 09:50 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-11 09:50 - 2013-11-11 09:50 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-11 09:50 - 2013-11-11 09:50 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-11 09:50 - 2013-11-11 09:50 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advpack.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-11 09:50 - 2013-11-11 09:50 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-11 09:50 - 2013-11-11 09:50 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-11 09:42 - 2013-11-11 09:51 - 00000000 ____D C:\Users\Bill @ Deb\Desktop\RK_Quarantine
2013-11-08 12:33 - 2013-11-11 11:57 - 00003686 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{B1099519-36B7-4C24-AFAA-22586259D54C}
2013-11-08 11:10 - 2013-11-08 11:10 - 00782640 _____ (McAfee, Inc.) C:\Users\Bill @ Deb\Downloads\rootkitremover.exe
2013-11-07 11:05 - 2013-11-07 11:05 - 00000000 ____D C:\Users\Bill @ Deb\AppData\Roaming\LavasoftStatistics
2013-11-07 09:18 - 2013-11-07 09:18 - 00000085 _____ C:\Windows\wininit.ini
2013-11-06 19:10 - 2013-11-07 09:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-11-06 19:10 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-11-06 15:55 - 2013-11-06 15:55 - 00000000 _____ C:\autoexec.bat
2013-11-06 15:51 - 2013-11-06 15:51 - 00000126 _____ C:\sh4_service.log
2013-11-06 15:49 - 2013-10-18 15:01 - 00285747 _____ C:\shldr
2013-11-06 15:49 - 2013-10-18 15:01 - 00008192 _____ C:\shldr.mbr
2013-11-06 15:48 - 2013-11-06 15:48 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-11-06 15:47 - 2013-11-06 19:49 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-11-06 15:46 - 2013-11-06 15:46 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Bill @ Deb\Downloads\SpyHunter-Installer.exe
2013-11-06 15:24 - 2013-11-06 15:24 - 01071584 _____ (Solid State Networks) C:\Users\Bill @ Deb\Downloads\install_flashplayer11x32ax_chrd_awa_aih.exe
2013-11-06 10:50 - 2013-11-06 10:50 - 00000351 _____ C:\spyhunter.log
2013-11-05 16:47 - 2013-11-05 16:47 - 00000024 _____ C:\Windows\8458CEBF4414B328.log
2013-10-27 12:02 - 2013-10-27 12:04 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-27 12:02 - 2013-10-27 12:04 - 00000000 ____D C:\Program Files\iTunes
2013-10-27 12:02 - 2013-10-27 12:02 - 00000000 ____D C:\Program Files\iPod
==================== One Month Modified Files and Folders =======
2013-11-11 12:02 - 2009-01-12 08:04 - 01763390 _____ C:\Windows\WindowsUpdate.log
2013-11-11 12:00 - 2013-11-11 12:00 - 00000000 ____D C:\FRST
2013-11-11 11:59 - 2013-11-11 11:59 - 01957590 _____ (Farbar) C:\Users\Bill @ Deb\Desktop\FRST64.exe
2013-11-11 11:57 - 2013-11-08 12:33 - 00003686 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{B1099519-36B7-4C24-AFAA-22586259D54C}
2013-11-11 11:56 - 2009-07-25 12:08 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-11 10:48 - 2012-12-13 17:29 - 00000000 ____D C:\Users\Bill @ Deb\AppData\Roaming\MotoCast
2013-11-11 10:48 - 2012-06-23 15:15 - 00000000 ____D C:\Users\Bill @ Deb\.gstreamer-0.10
2013-11-11 10:46 - 2009-07-25 12:08 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-11 10:45 - 2009-01-12 13:18 - 00000288 _____ C:\Windows\Tasks\RtlNICDiagVistaStart.job
2013-11-11 10:43 - 2006-11-02 10:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-11 10:43 - 2006-11-02 10:22 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-11 10:43 - 2006-11-02 10:22 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-11 10:31 - 2006-11-02 10:42 - 00032556 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-11 10:31 - 2006-11-02 08:33 - 00000000 ___RD C:\Windows\Offline Web Pages
2013-11-11 10:31 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-11 10:28 - 2013-11-11 10:00 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-11 10:28 - 2013-11-11 09:58 - 00000000 ____D C:\Users\Bill @ Deb\Desktop\mbar
2013-11-11 10:00 - 2013-11-11 10:00 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-11-11 09:59 - 2013-11-11 09:59 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-11-11 09:51 - 2013-11-11 09:42 - 00000000 ____D C:\Users\Bill @ Deb\Desktop\RK_Quarantine
2013-11-11 09:50 - 2013-11-11 09:50 - 17833984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 12336128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 03695416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-11 09:50 - 2013-11-11 09:50 - 03695416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-11 09:50 - 2013-11-11 09:50 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-11 09:50 - 2013-11-11 09:50 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-11 09:50 - 2013-11-11 09:50 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-11 09:50 - 2013-11-11 09:50 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-11 09:50 - 2013-11-11 09:50 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-11 09:50 - 2013-11-11 09:50 - 00434176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00403248 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-11 09:50 - 2013-11-11 09:50 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00353584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieaksie.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakui.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00150528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00130560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieakeng.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00123392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00118784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advpack.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00110592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admparse.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-11 09:50 - 2013-11-11 09:50 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00063488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-11 09:50 - 2013-11-11 09:50 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00031744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-11 09:50 - 2013-11-11 09:50 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-11 09:50 - 2013-11-11 09:50 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-11 09:50 - 2011-06-01 07:38 - 00005660 _____ C:\Windows\IE9_main.log
2013-11-11 09:50 - 2006-11-02 07:16 - 00008798 _____ C:\Windows\SysWOW64\icrav03.rat
2013-11-11 09:50 - 2006-11-02 07:16 - 00001988 _____ C:\Windows\SysWOW64\ticrf.rat
2013-11-11 09:50 - 2006-11-02 01:36 - 00008798 _____ C:\Windows\system32\icrav03.rat
2013-11-11 09:50 - 2006-11-02 01:36 - 00001988 _____ C:\Windows\system32\ticrf.rat
2013-11-09 11:43 - 2006-11-02 07:46 - 00756338 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-08 14:16 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\rescache
2013-11-08 11:58 - 2012-12-29 11:32 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2013-11-08 11:54 - 2009-01-12 13:29 - 00000000 ____D C:\ProgramData\WildTangent
2013-11-08 11:10 - 2013-11-08 11:10 - 00782640 _____ (McAfee, Inc.) C:\Users\Bill @ Deb\Downloads\rootkitremover.exe
2013-11-08 10:41 - 2009-01-16 14:11 - 00000000 ____D C:\Users\Bill @ Deb
2013-11-08 10:13 - 2012-03-31 17:46 - 00018363 _____ C:\Windows\setupact.log
2013-11-07 12:55 - 2009-01-18 12:24 - 00000000 ____D C:\Users\Bill @ Deb\Documents\Bill
2013-11-07 11:05 - 2013-11-07 11:05 - 00000000 ____D C:\Users\Bill @ Deb\AppData\Roaming\LavasoftStatistics
2013-11-07 11:03 - 2012-02-19 14:17 - 00000000 ____D C:\ProgramData\Lavasoft
2013-11-07 09:34 - 2009-01-17 23:29 - 00221696 _____ C:\Users\Bill @ Deb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-11-07 09:19 - 2013-11-06 19:10 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-11-07 09:19 - 2008-01-20 22:26 - 00178036 _____ C:\Windows\PFRO.log
2013-11-07 09:18 - 2013-11-07 09:18 - 00000085 _____ C:\Windows\wininit.ini
2013-11-07 09:18 - 2012-02-19 14:43 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-07 00:01 - 2012-06-15 10:16 - 00000000 ____D C:\ProgramData\pdf995
2013-11-07 00:01 - 2006-11-02 08:34 - 00000000 ____D C:\Windows\system32\spool
2013-11-07 00:01 - 2006-11-02 08:34 - 00000000 ____D C:\Windows\system32\Msdtc
2013-11-07 00:01 - 2006-11-02 08:33 - 00000000 ____D C:\Windows\registration
2013-11-07 00:01 - 2006-11-02 07:33 - 79429632 _____ C:\Windows\system32\config\software_previous
2013-11-07 00:01 - 2006-11-02 07:33 - 29360128 _____ C:\Windows\system32\config\system_previous
2013-11-06 23:58 - 2006-11-02 07:33 - 54001664 _____ C:\Windows\system32\config\components_previous
2013-11-06 23:58 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\sam_previous
2013-11-06 20:55 - 2006-11-02 07:33 - 00524288 _____ C:\Windows\system32\config\default_previous
2013-11-06 20:55 - 2006-11-02 07:33 - 00262144 _____ C:\Windows\system32\config\security_previous
2013-11-06 20:38 - 2013-06-21 17:22 - 00000000 ____D C:\ProgramData\HitmanPro
2013-11-06 19:49 - 2013-11-06 15:47 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP
2013-11-06 19:16 - 2009-09-25 08:16 - 00000000 ____D C:\Program Files\Google
2013-11-06 19:16 - 2009-01-12 13:21 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-06 19:02 - 2009-01-16 17:37 - 00000000 ____D C:\Users\Bill @ Deb\AppData\Local\Google
2013-11-06 18:51 - 2009-01-12 13:21 - 00000000 ____D C:\ProgramData\Google
2013-11-06 15:55 - 2013-11-06 15:55 - 00000000 _____ C:\autoexec.bat
2013-11-06 15:51 - 2013-11-06 15:51 - 00000126 _____ C:\sh4_service.log
2013-11-06 15:48 - 2013-11-06 15:48 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-11-06 15:46 - 2013-11-06 15:46 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Bill @ Deb\Downloads\SpyHunter-Installer.exe
2013-11-06 15:44 - 2009-01-18 12:32 - 00000000 ____D C:\Users\Bill @ Deb\AppData\Local\Adobe
2013-11-06 15:24 - 2013-11-06 15:24 - 01071584 _____ (Solid State Networks) C:\Users\Bill @ Deb\Downloads\install_flashplayer11x32ax_chrd_awa_aih.exe
2013-11-06 10:50 - 2013-11-06 10:50 - 00000351 _____ C:\spyhunter.log
2013-11-05 16:47 - 2013-11-05 16:47 - 00000024 _____ C:\Windows\8458CEBF4414B328.log
2013-11-05 16:32 - 2012-08-30 18:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-05 16:32 - 2012-08-30 18:46 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-03 15:41 - 2009-01-17 17:20 - 00000125 ___SH C:\ProgramData\.zreglib
2013-11-01 08:29 - 2009-01-17 16:59 - 00000376 _____ C:\Windows\ODBC.INI
2013-11-01 08:29 - 2006-11-02 07:34 - 00000240 _____ C:\Windows\win.ini
2013-10-27 12:04 - 2013-10-27 12:02 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-10-27 12:04 - 2013-10-27 12:02 - 00000000 ____D C:\Program Files\iTunes
2013-10-27 12:04 - 2013-07-01 12:41 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-10-27 12:02 - 2013-10-27 12:02 - 00000000 ____D C:\Program Files\iPod
2013-10-21 07:04 - 2009-01-18 16:05 - 00120976 _____ C:\Users\Bill @ Deb\AppData\Roaming\GDIPFONTCACHEV1.DAT
2013-10-18 15:01 - 2013-11-06 15:49 - 00285747 _____ C:\shldr
2013-10-18 15:01 - 2013-11-06 15:49 - 00008192 _____ C:\shldr.mbr
2013-10-16 12:29 - 2012-07-08 10:59 - 00000000 ____D C:\Users\Bill @ Deb\AppData\Roaming\MusicNet
2013-10-12 06:13 - 2009-07-25 12:08 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-12 06:13 - 2009-07-25 12:08 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
Files to move or delete:
====================
C:\Users\Bill @ Deb\AppData\Roaming\skype.ini
C:\Users\Bill @ Deb\CTX.DAT
C:\Users\Bill @ Deb\msconfig.exe
C:\Users\Bill @ Deb\vlcplayer.exe
Some content of TEMP:
====================
C:\Users\Bill @ Deb\AppData\Local\Temp\5cf8a65e-decc-4761-8c43-071f91b09b56.exe
C:\Users\Bill @ Deb\AppData\Local\Temp\ntdll_dump.dll
C:\Users\Bill @ Deb\AppData\Local\Temp\pn2683.exe
C:\Users\Bill @ Deb\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll
C:\Users\Bill @ Deb\AppData\Local\Temp\uninstall.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-11 10:49
==================== End Of Log ============================