Re run of Scan
Frst.txt
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-06-2013
Ran by Vivek (administrator) on 09-06-2013 12:50:50
Running from F:\
Windows 8 (X64) OS Language: English(UK)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Windows\SysWOW64\ASGT.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe\LiveComm.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Microsoft Corporation) C:\Windows\sysWow64\SearchProtocolHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Stardock) C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
(Stardock) C:\Program Files (x86)\Stardock\ObjectDockFree\Dock64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Reader_sl.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s [6548112 2012-06-12] (Realtek Semiconductor)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY [4408368 2013-04-29] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized [702024 2012-12-13] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup [362432 2011-12-22] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-19] (Adobe Systems Incorporated)
Startup: C:\Users\Vivek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
ShortcutTarget: Stardock ObjectDock.lnk -> C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe (Stardock)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://ninemsn.com.au/?ocid=iehp
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.1.1.1
Chrome:
=======
CHR HomePage: hxxp://
www.google.com
CHR RestoreOnStartup: "hxxp://
www.google.com"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google
riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
CHR Plugin: (Norton Confidential) - C:\Users\Vivek\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.0.140_0\npcoplgn.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Extension: (YouTube) - C:\Users\Vivek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Vivek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Vivek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.63_0
CHR Extension: (Gmail) - C:\Users\Vivek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] ()
S2 avgfws; C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [1428472 2013-04-10] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20912 2012-10-26] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\system32\DRIVERS\avgfwd6a.sys [50296 2012-09-04] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [246072 2013-03-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\system32\DRIVERS\avgldx64.sys [206136 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [248120 2013-03-21] (AVG Technologies CZ, s.r.o.)
R4 IOMap; C:\Windows\system32\drivers\IOMap64.sys [23680 2010-02-23] (ASUSTeK Computer Inc.)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [50128 2012-12-13] (Cisco Systems, Inc.)
S3 WUDFSensorLP; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-06-09 20:49 - 2013-06-09 20:49 - 00000000 ____D C:\Windows\System32\config\HiveBackup
2013-06-09 11:46 - 2013-06-09 11:46 - 00000000 ____D C:\_OTL
2013-06-09 11:17 - 2013-06-09 11:17 - 00104712 ____A C:\Users\Vivek\Desktop\OTL.Txt
2013-06-09 11:17 - 2013-06-09 11:17 - 00046738 ____A C:\Users\Vivek\Desktop\Extras.Txt
2013-06-09 11:14 - 2013-06-09 11:14 - 00602112 ____A (OldTimer Tools) C:\Users\Vivek\Desktop\OTL.exe
2013-06-09 11:08 - 2013-06-09 11:08 - 00000620 ____A C:\Users\Vivek\Desktop\JRT.txt
2013-06-09 11:07 - 2013-06-09 11:07 - 00000000 ____D C:\Windows\ERUNT
2013-06-09 11:06 - 2013-06-09 11:07 - 00000000 ____D C:\JRT
2013-06-09 11:06 - 2013-06-09 11:06 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Vivek\Desktop\JRT.exe
2013-06-09 11:02 - 2013-06-09 11:02 - 00001071 ____A C:\Users\Vivek\Desktop\AdwCleaner[S1].txt
2013-06-09 11:00 - 2013-06-09 11:01 - 00001071 ____A C:\AdwCleaner[S1].txt
2013-06-09 10:58 - 2013-06-09 10:59 - 00648201 ____A C:\Users\Vivek\Desktop\adwcleaner.exe
2013-06-08 12:58 - 2013-06-08 12:11 - 00039162 ____A C:\Users\Vivek\Desktop\FRST.txt
2013-06-08 12:58 - 2013-06-08 12:11 - 00012924 ____A C:\Users\Vivek\Desktop\Addition.txt
2013-06-08 12:58 - 2013-06-08 12:07 - 01919218 ____A (Farbar) C:\Users\Vivek\Desktop\FRST64.exe
2013-06-08 12:10 - 2013-06-08 12:59 - 00000000 ____D C:\FRST
2013-06-08 11:15 - 2013-06-08 11:20 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-08 11:02 - 2013-06-08 12:13 - 00000000 ____D C:\Users\Vivek\Desktop\Virus
2013-06-08 10:26 - 2013-06-08 10:26 - 00000000 ____D C:\Users\Vivek\AppData\Roaming\Malwarebytes
2013-06-08 10:26 - 2013-06-08 10:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-08 10:26 - 2013-06-08 10:26 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-08 10:26 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-06-08 10:23 - 2013-06-08 10:23 - 00422160 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-08 10:23 - 2013-06-08 10:23 - 00281640 ____A C:\Windows\Minidump\060813-9906-01.dmp
2013-06-07 18:21 - 2013-06-08 18:22 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
2013-06-04 09:01 - 2013-06-04 09:01 - 00000000 ____D C:\ProgramData\Macrovision
2013-06-02 21:29 - 2013-04-09 13:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll
2013-06-02 21:29 - 2013-04-09 13:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll
2013-06-02 21:29 - 2013-04-09 13:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe
2013-06-02 21:29 - 2013-04-09 13:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-06-02 21:29 - 2013-04-09 13:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll
2013-06-02 21:29 - 2013-04-09 13:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll
2013-06-02 21:29 - 2013-04-09 13:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll
2013-06-02 21:29 - 2013-04-09 13:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2013-06-02 21:29 - 2013-04-09 12:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe
2013-06-02 21:29 - 2013-04-09 12:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe
2013-06-02 21:29 - 2013-04-09 12:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe
2013-06-02 21:29 - 2013-04-09 12:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe
2013-06-02 21:29 - 2013-04-09 12:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe
2013-06-02 21:29 - 2013-04-09 12:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll
2013-06-02 21:29 - 2013-04-09 12:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-06-02 21:29 - 2013-04-09 12:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-06-02 21:29 - 2013-04-09 12:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll
2013-06-02 21:29 - 2013-04-09 12:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll
2013-06-02 21:29 - 2013-04-09 12:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll
2013-06-02 21:29 - 2013-04-09 12:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll
2013-06-02 21:29 - 2013-04-09 12:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll
2013-06-02 21:29 - 2013-04-09 12:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe
2013-06-02 21:29 - 2013-04-09 12:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll
2013-06-02 21:29 - 2013-04-09 12:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll
2013-06-02 21:29 - 2013-04-09 12:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll
2013-06-02 21:29 - 2013-04-09 12:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-06-02 21:29 - 2013-04-09 12:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll
2013-06-02 21:29 - 2013-04-09 12:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-06-02 21:29 - 2013-04-09 12:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll
2013-06-02 21:29 - 2013-04-09 10:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-06-02 21:29 - 2013-04-09 10:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys
2013-06-02 21:29 - 2013-04-09 10:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-06-02 21:29 - 2013-04-09 10:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-06-02 21:29 - 2013-04-09 10:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys
2013-06-02 21:29 - 2013-04-09 10:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys
2013-06-02 21:29 - 2013-04-09 10:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys
2013-06-02 21:29 - 2013-04-09 10:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys
2013-06-02 21:29 - 2013-04-09 10:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys
2013-06-02 21:29 - 2013-04-09 07:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-06-02 21:29 - 2013-04-09 07:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-06-02 21:29 - 2013-04-09 07:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-06-02 21:29 - 2013-04-09 07:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-06-02 21:29 - 2013-04-09 05:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-06-02 21:29 - 2013-04-09 05:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-06-02 21:29 - 2013-04-09 05:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-06-02 21:29 - 2013-04-09 05:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-06-02 21:29 - 2013-04-09 05:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-06-02 21:29 - 2013-04-09 05:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-06-02 21:29 - 2013-04-09 05:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-06-02 21:29 - 2013-04-09 05:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-06-02 21:29 - 2013-04-09 05:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-06-02 21:29 - 2013-04-05 07:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll
2013-06-02 21:29 - 2013-04-03 06:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml
2013-06-02 21:29 - 2013-03-31 02:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi
2013-06-02 21:29 - 2013-03-31 02:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe
2013-06-02 21:29 - 2013-03-29 06:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi
2013-06-02 21:29 - 2013-03-29 06:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe
2013-06-02 21:29 - 2013-03-16 06:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll
2013-06-02 21:29 - 2013-03-16 06:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-06-02 21:29 - 2012-12-13 12:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll
2013-06-02 21:29 - 2012-12-13 11:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-05-18 17:05 - 2013-06-05 22:54 - 00011674 ____A C:\Users\Vivek\Desktop\CarComparison.xlsx
2013-05-17 12:52 - 2013-04-10 07:17 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-05-17 12:52 - 2013-04-10 07:17 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-05-17 12:52 - 2013-04-10 07:17 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-05-17 12:52 - 2013-04-10 07:17 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-05-17 12:52 - 2013-04-10 07:17 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-05-17 12:52 - 2013-04-10 07:17 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-05-17 12:52 - 2013-04-10 07:16 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-05-17 12:52 - 2013-04-10 07:16 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-05-17 12:52 - 2013-04-10 07:16 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-05-17 12:52 - 2013-04-10 07:16 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-05-17 12:52 - 2013-04-10 06:30 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-05-17 12:52 - 2013-04-10 06:30 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-05-17 12:52 - 2013-04-10 06:29 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-05-17 12:52 - 2013-04-10 06:29 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-05-17 12:52 - 2013-04-10 06:29 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-05-17 12:52 - 2013-04-10 06:29 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-05-17 12:52 - 2013-04-10 06:29 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-05-17 12:52 - 2013-04-10 06:29 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-05-17 12:52 - 2013-02-12 09:30 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-05-17 12:52 - 2013-02-12 08:56 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-05-17 12:51 - 2013-04-16 10:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2013-05-17 12:51 - 2013-04-11 14:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-05-17 12:51 - 2013-03-22 11:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-05-17 12:51 - 2013-03-22 06:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll
2013-05-17 12:51 - 2013-03-15 08:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2013-05-17 12:51 - 2013-03-06 15:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe
2013-05-17 12:51 - 2013-03-06 14:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2013-05-17 12:51 - 2013-03-06 14:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll
2013-05-17 12:51 - 2013-03-06 14:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll
2013-05-17 12:51 - 2013-03-06 13:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-05-17 12:51 - 2013-03-06 13:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-05-17 12:49 - 2013-05-17 12:49 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-05-16 20:55 - 2013-05-16 20:55 - 00561048 ____A C:\Windows\Minidump\051613-11109-01.dmp
2013-05-11 11:29 - 2013-05-11 11:29 - 00000000 ____D C:\Users\Vivek\AppData\Local\Adobe
2013-05-11 11:28 - 2013-06-08 18:22 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-05-11 11:28 - 2013-05-11 11:28 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-05-11 11:23 - 2013-06-08 18:22 - 00000000 ____D C:\ProgramData\Adobe
2013-05-11 01:37 - 2013-05-11 01:37 - 00679352 ____A C:\Windows\Minidump\051113-11062-01.dmp
2013-05-10 10:24 - 2013-05-10 10:24 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-05-10 10:24 - 2013-05-10 10:24 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
==================== One Month Modified Files and Folders =======
2013-06-09 20:49 - 2013-06-09 20:49 - 00000000 ____D C:\Windows\System32\config\HiveBackup
2013-06-09 12:50 - 2012-07-26 15:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-09 12:50 - 2012-07-26 01:10 - 00000940 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-06-09 12:26 - 2012-07-26 15:21 - 00018914 ____A C:\Windows\setupact.log
2013-06-09 12:23 - 2012-07-26 01:10 - 00000944 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-06-09 12:16 - 2013-04-20 15:06 - 01322167 ____A C:\Windows\WindowsUpdate.log
2013-06-09 12:00 - 2012-07-26 16:12 - 00000000 ____D C:\Windows\System32\sru
2013-06-09 11:54 - 2012-07-26 15:28 - 00850046 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-09 11:47 - 2012-07-26 13:26 - 00524288 __ASH C:\Windows\System32\config\BBI
2013-06-09 11:46 - 2013-06-09 11:46 - 00000000 ____D C:\_OTL
2013-06-09 11:22 - 2013-04-20 15:44 - 00000000 ____D C:\Users\Vivek\AppData\Local\Avg2013
2013-06-09 11:22 - 2013-04-20 15:44 - 00000000 ____D C:\ProgramData\MFAData
2013-06-09 11:17 - 2013-06-09 11:17 - 00104712 ____A C:\Users\Vivek\Desktop\OTL.Txt
2013-06-09 11:17 - 2013-06-09 11:17 - 00046738 ____A C:\Users\Vivek\Desktop\Extras.Txt
2013-06-09 11:14 - 2013-06-09 11:14 - 00602112 ____A (OldTimer Tools) C:\Users\Vivek\Desktop\OTL.exe
2013-06-09 11:08 - 2013-06-09 11:08 - 00000620 ____A C:\Users\Vivek\Desktop\JRT.txt
2013-06-09 11:07 - 2013-06-09 11:07 - 00000000 ____D C:\Windows\ERUNT
2013-06-09 11:07 - 2013-06-09 11:06 - 00000000 ____D C:\JRT
2013-06-09 11:06 - 2013-06-09 11:06 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Vivek\Desktop\JRT.exe
2013-06-09 11:02 - 2013-06-09 11:02 - 00001071 ____A C:\Users\Vivek\Desktop\AdwCleaner[S1].txt
2013-06-09 11:01 - 2013-06-09 11:00 - 00001071 ____A C:\AdwCleaner[S1].txt
2013-06-09 11:01 - 2012-07-26 00:46 - 01342768 ____A C:\Windows\PFRO.log
2013-06-09 10:59 - 2013-06-09 10:58 - 00648201 ____A C:\Users\Vivek\Desktop\adwcleaner.exe
2013-06-08 18:22 - 2013-06-07 18:21 - 00000000 ____D C:\Program Files (x86)\x264 Video Codec
2013-06-08 18:22 - 2013-05-11 11:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-06-08 18:22 - 2013-05-11 11:23 - 00000000 ____D C:\ProgramData\Adobe
2013-06-08 18:22 - 2013-05-07 12:23 - 00000000 ____D C:\Users\Vivek\AppData\Roaming\ICAClient
2013-06-08 18:22 - 2013-05-07 12:22 - 00000000 ____D C:\Users\Vivek\AppData\Local\Citrix
2013-06-08 18:22 - 2013-05-07 12:22 - 00000000 ____D C:\ProgramData\Citrix
2013-06-08 18:22 - 2013-05-07 12:22 - 00000000 ____D C:\Program Files (x86)\Citrix
2013-06-08 18:22 - 2013-05-07 12:17 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-06-08 18:22 - 2013-05-07 12:16 - 00000000 ____D C:\Program Files (x86)\Java
2013-06-08 18:22 - 2013-04-21 13:31 - 00000000 ____D C:\Users\Vivek\AppData\Roaming\vlc
2013-06-08 18:22 - 2013-04-21 13:11 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-08 18:22 - 2013-04-21 12:52 - 00000000 ____D C:\Users\Vivek\AppData\Roaming\uTorrent
2013-06-08 18:22 - 2013-04-20 15:10 - 00000000 ____D C:\Users\Vivek\AppData\Local\Google
2013-06-08 18:22 - 2013-04-20 15:06 - 00000000 ____D C:\Users\Vivek\AppData\Roaming\Adobe
2013-06-08 18:22 - 2012-07-26 16:12 - 00000000 ____D C:\Windows\registration
2013-06-08 18:22 - 2012-07-26 16:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-06-08 18:22 - 2012-07-26 16:12 - 00000000 ____D C:\Program Files\Windows Defender
2013-06-08 18:22 - 2012-07-26 16:12 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2013-06-08 18:22 - 2012-07-26 16:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-06-08 18:22 - 2012-07-26 13:37 - 00000000 ____D C:\Windows\servicing
2013-06-08 16:24 - 2012-07-26 01:10 - 00002183 ____A C:\Users\Public\Desktop\Google Chrome.lnk
2013-06-08 12:59 - 2013-06-08 12:10 - 00000000 ____D C:\FRST
2013-06-08 12:13 - 2013-06-08 11:02 - 00000000 ____D C:\Users\Vivek\Desktop\Virus
2013-06-08 12:11 - 2013-06-08 12:58 - 00039162 ____A C:\Users\Vivek\Desktop\FRST.txt
2013-06-08 12:11 - 2013-06-08 12:58 - 00012924 ____A C:\Users\Vivek\Desktop\Addition.txt
2013-06-08 12:07 - 2013-06-08 12:58 - 01919218 ____A (Farbar) C:\Users\Vivek\Desktop\FRST64.exe
2013-06-08 11:20 - 2013-06-08 11:15 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-08 10:26 - 2013-06-08 10:26 - 00000000 ____D C:\Users\Vivek\AppData\Roaming\Malwarebytes
2013-06-08 10:26 - 2013-06-08 10:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-06-08 10:26 - 2013-06-08 10:26 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-06-08 10:23 - 2013-06-08 10:23 - 00422160 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-08 10:23 - 2013-06-08 10:23 - 00281640 ____A C:\Windows\Minidump\060813-9906-01.dmp
2013-06-08 10:23 - 2013-05-07 01:46 - 380871978 ____A C:\Windows\MEMORY.DMP
2013-06-08 10:23 - 2013-05-07 01:46 - 00000000 ____D C:\Windows\Minidump
2013-06-08 10:23 - 2013-04-20 15:06 - 00000000 ____D C:\users\Vivek
2013-06-05 22:54 - 2013-05-18 17:05 - 00011674 ____A C:\Users\Vivek\Desktop\CarComparison.xlsx
2013-06-04 16:14 - 2013-04-21 18:21 - 00000000 ____D C:\Users\Vivek\Documents\Outlook Files
2013-06-04 09:04 - 2013-04-20 15:06 - 00000000 ____D C:\Users\Vivek\AppData\Local\VirtualStore
2013-06-04 09:01 - 2013-06-04 09:01 - 00000000 ____D C:\ProgramData\Macrovision
2013-06-04 09:00 - 2012-07-26 01:10 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-06-04 08:56 - 2012-07-26 16:12 - 00000000 ____D C:\Windows\rescache
2013-06-04 08:19 - 2012-07-26 16:12 - 00000000 ___RD C:\Windows\ToastData
2013-06-04 08:19 - 2012-07-26 16:12 - 00000000 ____D C:\Windows\WinStore
2013-06-04 08:19 - 2012-07-26 16:12 - 00000000 ____D C:\Windows\SysWOW64\en-GB
2013-06-04 08:19 - 2012-07-26 16:12 - 00000000 ____D C:\Windows\System32\en-GB
2013-06-03 00:12 - 2013-04-20 15:50 - 00000965 ____A C:\Users\Public\Desktop\AVG 2013.lnk
2013-06-03 00:12 - 2012-07-26 13:26 - 00262144 __ASH C:\Windows\System32\config\ELAM
2013-06-02 21:37 - 2012-07-26 16:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-05-17 13:33 - 2013-04-21 15:21 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-05-17 12:49 - 2013-05-17 12:49 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-05-17 12:49 - 2013-04-21 13:11 - 00000000 ____D C:\Users\Vivek\AppData\Roaming\Apple Computer
2013-05-16 20:55 - 2013-05-16 20:55 - 00561048 ____A C:\Windows\Minidump\051613-11109-01.dmp
2013-05-11 11:29 - 2013-05-11 11:29 - 00000000 ____D C:\Users\Vivek\AppData\Local\Adobe
2013-05-11 11:28 - 2013-05-11 11:28 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-05-11 01:37 - 2013-05-11 01:37 - 00679352 ____A C:\Windows\Minidump\051113-11062-01.dmp
2013-05-10 10:24 - 2013-05-10 10:24 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-05-10 10:24 - 2013-05-10 10:24 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-06-03 00:20
==================== End Of Log ============================