(FRST.TXT) Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by SHIPPING (administrator) on SHIPPING-HP on 14-10-2013 16:47:56 Running from C:\Users\SHIPPING\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AMD) C:\Windows\system32\atieclxx.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) c:\UPS\WSTD\MSSQL.1\MSSQL\Binn\sqlservr.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe (Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\eCopy PDF Pro Office 6\PDFProFiltSrv.exe (Microsoft Corporation) c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [icq] - C:\Users\SHIPPING\AppData\Roaming\ICQM\icq.exe [27598184 2013-07-24] (ICQ) HKLM-x32\...\Run: [] - [x] Startup: C:\Users\SHIPPING\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5195FF8953C4CE01 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM-x32 - {82F0369C-57A4-4240-BF4A-DBA2FCA64FE5} URL = http://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us1-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-30572-11896-1/4?mpre=http://www.ebay.com/sch/i.html?_nkw={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: SteadyVideoBHO Class - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - c:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: No Name - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - No File BHO-x32: Gaaiho PDF Conversion Toolbar Helper - {C7DA0384-42AA-428c-B832-88AC343DE1A8} - C:\Program Files (x86)\Nuance\eCopy PDF Pro Office 6\bin\GZeonIEFavClient.dll (Zeon Corporation) BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Nuance PDF - {BCCE15AE-AC7E-4bc9-94AF-2A714A412BCB} - C:\Program Files (x86)\Nuance\eCopy PDF Pro Office 6\bin\GZeonIEFavClient.dll (Zeon Corporation) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - c:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) ShellExecuteHooks-x32: - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No File [ ] Hosts: 127.0.0.1 localhost Tcpip\Parameters: [DhcpNameServer] 192.168.1.4 68.109.202.25 68.109.202.30 ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSSQL$UPSWSDBSERVER; c:\UPS\WSTD\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation) R2 PDFProFiltSrv; C:\Program Files (x86)\Nuance\eCopy PDF Pro Office 6\PDFProFiltSrv.exe [135056 2012-11-19] (Nuance Communications, Inc.) R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-08-14] (Western Digital Technologies, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270704 2013-08-14] (Western Digital Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-14 16:47 - 2013-10-14 16:47 - 00000000 ____D C:\FRST 2013-10-14 16:44 - 2013-10-14 16:44 - 01954124 _____ (Farbar) C:\Users\SHIPPING\Desktop\FRST64.exe 2013-10-14 15:12 - 2013-10-14 16:27 - 00023846 ____N C:\Windows\WindowsUpdate.log 2013-10-14 15:05 - 2013-10-14 15:24 - 00000000 ____D C:\Users\SHIPPING\Desktop\RK_Quarantine 2013-10-14 15:05 - 2013-10-14 15:05 - 03985920 _____ C:\Users\SHIPPING\Desktop\RogueKillerX64.exe 2013-10-14 12:35 - 2012-12-10 11:04 - 00356352 _____ (eSellerate Inc.) C:\Windows\eSellerateEngine.dll 2013-10-14 12:35 - 2012-12-10 11:04 - 00081920 _____ (eSellerate Inc.) C:\Windows\eSellerateControl350.dll 2013-10-14 12:35 - 2009-07-23 18:32 - 01122304 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Windows\SysWOW64\libeay32.dll 2013-10-14 12:35 - 2009-07-23 18:32 - 00274432 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Windows\SysWOW64\ssleay32.dll 2013-10-09 03:11 - 2013-09-22 18:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-09 03:11 - 2013-09-22 18:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-09 03:11 - 2013-09-22 18:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-09 03:11 - 2013-09-22 17:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-09 03:11 - 2013-09-22 17:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-09 03:11 - 2013-09-22 17:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-09 03:11 - 2013-09-22 17:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-09 03:11 - 2013-09-22 17:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-09 03:11 - 2013-09-20 22:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-09 03:11 - 2013-09-20 22:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-09 03:11 - 2013-09-20 21:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-09 03:11 - 2013-09-20 21:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-09 00:33 - 2013-09-13 20:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-09 00:33 - 2013-09-07 21:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-09 00:33 - 2013-09-07 21:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-09 00:33 - 2013-09-07 21:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-09 00:33 - 2013-08-28 21:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-09 00:33 - 2013-08-28 21:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-09 00:33 - 2013-08-28 21:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-09 00:33 - 2013-08-28 20:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-09 00:33 - 2013-08-28 20:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-09 00:33 - 2013-08-27 20:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-09 00:33 - 2013-07-12 05:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-09 00:33 - 2013-07-04 07:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-09 00:33 - 2013-07-04 07:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-09 00:33 - 2013-07-04 07:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-09 00:33 - 2013-07-04 06:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-09 00:33 - 2013-07-04 06:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-09 00:33 - 2013-07-04 06:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-09 00:33 - 2013-07-04 05:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-09 00:33 - 2013-07-02 23:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-09 00:33 - 2013-07-02 23:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-09 00:33 - 2013-06-25 17:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-09 00:33 - 2013-06-06 00:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-09 00:33 - 2013-06-06 00:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-09 00:33 - 2013-06-06 00:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-09 00:33 - 2013-06-06 00:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-09 00:33 - 2013-06-05 23:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-09 00:33 - 2013-06-05 23:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-09 00:33 - 2013-06-05 23:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-09 00:33 - 2013-06-05 22:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-09 00:33 - 2013-06-05 22:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-09 00:33 - 2013-06-05 22:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-09 00:32 - 2013-09-04 07:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-09 00:32 - 2013-09-04 07:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-09 00:32 - 2013-09-04 07:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-09 00:32 - 2013-09-04 07:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-09 00:32 - 2013-09-04 07:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-09 00:32 - 2013-09-04 07:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-09 00:32 - 2013-09-04 07:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-09 00:32 - 2013-08-28 21:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-09 00:32 - 2013-08-28 21:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-09 00:32 - 2013-08-28 20:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-09 00:32 - 2013-08-28 20:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-09 00:32 - 2013-08-28 20:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-09 00:32 - 2013-08-28 20:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-09 00:32 - 2013-08-28 19:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-09 00:32 - 2013-08-28 19:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-09 00:32 - 2013-08-28 19:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-09 00:32 - 2013-08-28 19:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-09 00:32 - 2013-08-27 20:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-09 00:32 - 2013-08-01 07:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-09 00:32 - 2013-07-20 05:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 00:32 - 2013-07-20 05:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-03 10:17 - 2013-10-03 10:17 - 00039424 _____ C:\Users\SHIPPING\Documents\Lousiana Pricing Trade-in Form-1 9-27-13_A.xls 2013-09-30 13:40 - 2013-09-30 13:59 - 733476790 _____ C:\Users\SHIPPING\Downloads\Office_Professional_Plus_2013_64bit.exe 2013-09-30 13:15 - 2013-09-30 13:34 - 634799535 _____ C:\Users\SHIPPING\Downloads\Office_Professional_Plus_2013_32bit.exe 2013-09-27 15:13 - 2013-10-03 10:16 - 00043008 _____ C:\Users\SHIPPING\Documents\Lousiana Pricing Trade-in Form-1 9-27-13.xls 2013-09-24 16:47 - 2013-09-24 16:47 - 00000000 ____D C:\Users\SHIPPING\AppData\Local\GoPro 2013-09-24 09:09 - 2013-09-24 09:47 - 00000000 ____D C:\Users\SHIPPING\AppData\Roaming\GoPro 2013-09-24 09:09 - 2013-09-24 09:15 - 00000000 ____D C:\Users\Public\CineForm 2013-09-24 09:09 - 2013-09-24 09:09 - 00000000 ____D C:\Program Files\DIFX 2013-09-24 09:09 - 2013-09-24 09:09 - 00000000 ____D C:\Program Files (x86)\CineForm 2013-09-18 14:18 - 2013-09-18 14:18 - 00001745 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-18 14:18 - 2013-09-18 14:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-09-18 14:18 - 2013-09-18 14:18 - 00000000 ____D C:\Program Files\iTunes 2013-09-18 14:18 - 2013-09-18 14:18 - 00000000 ____D C:\Program Files\iPod 2013-09-18 14:18 - 2013-09-18 14:18 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-09-18 09:00 - 2013-09-18 09:26 - 00000000 ____D C:\Users\SHIPPING\AppData\Roaming\Apple Computer 2013-09-18 09:00 - 2013-09-18 09:00 - 00000000 ____D C:\Users\SHIPPING\AppData\Local\Apple Computer 2013-09-18 09:00 - 2013-09-18 09:00 - 00000000 ____D C:\ProgramData\Apple Computer 2013-09-18 09:00 - 2012-08-21 13:01 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys 2013-09-18 08:59 - 2013-09-18 08:59 - 00000000 ____D C:\Users\SHIPPING\AppData\Local\Apple 2013-09-18 08:59 - 2013-09-18 08:59 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-09-18 08:59 - 2013-09-18 08:59 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2013-09-18 08:58 - 2013-09-18 08:59 - 00000000 ____D C:\ProgramData\Apple 2013-09-18 08:58 - 2013-09-18 08:58 - 00000000 ____D C:\Program Files\Bonjour 2013-09-18 08:58 - 2013-09-18 08:58 - 00000000 ____D C:\Program Files (x86)\Bonjour 2013-09-17 11:34 - 2013-09-17 11:34 - 00000000 ____D C:\Program Files\Western Digital ==================== One Month Modified Files and Folders ======= 2013-10-14 16:47 - 2013-10-14 16:47 - 00000000 ____D C:\FRST 2013-10-14 16:46 - 2012-03-14 16:06 - 00000000 ____D C:\Users\SHIPPING\Documents\Outlook Files 2013-10-14 16:44 - 2013-10-14 16:44 - 01954124 _____ (Farbar) C:\Users\SHIPPING\Desktop\FRST64.exe 2013-10-14 16:27 - 2013-10-14 15:12 - 00023846 ____N C:\Windows\WindowsUpdate.log 2013-10-14 15:56 - 2012-03-14 13:22 - 00000000 ___RD C:\Users\SHIPPING\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-14 15:52 - 2013-07-11 15:21 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-14 15:24 - 2013-10-14 15:05 - 00000000 ____D C:\Users\SHIPPING\Desktop\RK_Quarantine 2013-10-14 15:17 - 2009-07-13 23:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-14 15:17 - 2009-07-13 23:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-14 15:14 - 2009-07-14 00:13 - 00850248 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-14 15:10 - 2013-09-10 12:04 - 00008192 _____ C:\Windows\SysWOW64\WDPABKP.dat 2013-10-14 15:09 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-14 15:07 - 2013-07-31 10:12 - 00000000 ____D C:\Users\SHIPPING\AppData\Roaming\BitTorrent 2013-10-14 15:05 - 2013-10-14 15:05 - 03985920 _____ C:\Users\SHIPPING\Desktop\RogueKillerX64.exe 2013-10-14 13:44 - 2013-05-15 12:52 - 00000000 ____D C:\Users\SHIPPING\Documents\Konica Minolta Orders 2013-10-14 11:50 - 2012-10-31 12:28 - 00000000 ____D C:\Program Files (x86)\Kyocera 2013-10-14 11:47 - 2012-01-02 18:30 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2013-10-14 11:02 - 2013-06-11 08:15 - 00000000 ____D C:\Program Files (x86)\Nuance 2013-10-14 10:40 - 2012-01-02 18:31 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information 2013-10-14 10:35 - 2013-07-11 11:17 - 00000000 ____D C:\Windows\pss 2013-10-14 10:20 - 2012-07-18 11:44 - 00000981 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-10-14 10:20 - 2012-01-02 18:49 - 00000000 ____D C:\Program Files (x86)\Windows Live 2013-10-14 10:10 - 2012-03-14 16:03 - 00000000 ____D C:\Program Files (x86)\Zebra Technologies 2013-10-14 07:43 - 2012-03-14 13:22 - 00003950 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9C502401-BCD3-4E0E-928D-CA1F7B457059} 2013-10-14 07:40 - 2012-03-14 16:17 - 00000199 _____ C:\Windows\wstdUPSWSHIP.INI 2013-10-11 15:54 - 2013-03-05 17:40 - 00007604 _____ C:\Users\SHIPPING\AppData\Local\Resmon.ResmonCfg 2013-10-11 08:46 - 2013-07-03 07:59 - 00000000 ____D C:\Users\SHIPPING\AppData\Roaming\Spotify 2013-10-10 08:20 - 2013-07-03 07:59 - 00000000 ____D C:\Users\SHIPPING\AppData\Local\Spotify 2013-10-09 13:43 - 2011-02-11 12:00 - 00000000 ____D C:\Windows\Panther 2013-10-09 10:58 - 2013-03-27 08:29 - 00000000 ____D C:\Users\SHIPPING\Documents\STATE 2013-10-09 10:52 - 2013-07-11 15:21 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 10:52 - 2013-07-11 15:21 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 10:52 - 2013-07-11 15:21 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-09 09:24 - 2013-06-25 12:36 - 00000000 ____D C:\Users\SHIPPING\Documents\TIME SHEETS 2013-10-09 04:07 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache 2013-10-09 03:30 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-09 03:30 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-09 03:13 - 2012-03-14 15:56 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-09 03:09 - 2011-02-11 12:15 - 00843972 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-09 03:06 - 2013-08-15 03:01 - 00000000 ____D C:\Windows\system32\MRT 2013-10-09 03:04 - 2012-03-16 14:18 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-07 09:06 - 2012-03-14 16:11 - 00000000 ____D C:\UPS 2013-10-04 13:58 - 2012-03-22 10:52 - 00003204 _____ C:\Windows\System32\Tasks\HPCeeScheduleForSHIPPING 2013-10-04 13:58 - 2012-03-22 10:52 - 00000344 _____ C:\Windows\Tasks\HPCeeScheduleForSHIPPING.job 2013-10-03 10:17 - 2013-10-03 10:17 - 00039424 _____ C:\Users\SHIPPING\Documents\Lousiana Pricing Trade-in Form-1 9-27-13_A.xls 2013-10-03 10:16 - 2013-09-27 15:13 - 00043008 _____ C:\Users\SHIPPING\Documents\Lousiana Pricing Trade-in Form-1 9-27-13.xls 2013-09-30 13:59 - 2013-09-30 13:40 - 733476790 _____ C:\Users\SHIPPING\Downloads\Office_Professional_Plus_2013_64bit.exe 2013-09-30 13:34 - 2013-09-30 13:15 - 634799535 _____ C:\Users\SHIPPING\Downloads\Office_Professional_Plus_2013_32bit.exe 2013-09-30 08:32 - 2013-03-19 10:10 - 00000000 ____D C:\Users\SHIPPING\AppData\Local\Deployment 2013-09-26 16:56 - 2012-07-18 11:44 - 00000000 ____D C:\Program Files\CCleaner 2013-09-24 16:47 - 2013-09-24 16:47 - 00000000 ____D C:\Users\SHIPPING\AppData\Local\GoPro 2013-09-24 09:47 - 2013-09-24 09:09 - 00000000 ____D C:\Users\SHIPPING\AppData\Roaming\GoPro 2013-09-24 09:15 - 2013-09-24 09:09 - 00000000 ____D C:\Users\Public\CineForm 2013-09-24 09:09 - 2013-09-24 09:09 - 00000000 ____D C:\Program Files\DIFX 2013-09-24 09:09 - 2013-09-24 09:09 - 00000000 ____D C:\Program Files (x86)\CineForm 2013-09-22 18:28 - 2013-10-09 03:11 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-22 18:28 - 2013-10-09 03:11 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-22 18:27 - 2013-10-09 03:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-22 17:55 - 2013-10-09 03:11 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-22 17:55 - 2013-10-09 03:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-22 17:55 - 2013-10-09 03:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-22 17:54 - 2013-10-09 03:11 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-22 17:54 - 2013-10-09 03:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-20 22:38 - 2013-10-09 03:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-20 22:30 - 2013-10-09 03:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-20 21:48 - 2013-10-09 03:11 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-20 21:39 - 2013-10-09 03:11 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-18 14:18 - 2013-09-18 14:18 - 00001745 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-09-18 14:18 - 2013-09-18 14:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-09-18 14:18 - 2013-09-18 14:18 - 00000000 ____D C:\Program Files\iTunes 2013-09-18 14:18 - 2013-09-18 14:18 - 00000000 ____D C:\Program Files\iPod 2013-09-18 14:18 - 2013-09-18 14:18 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-09-18 09:26 - 2013-09-18 09:00 - 00000000 ____D C:\Users\SHIPPING\AppData\Roaming\Apple Computer 2013-09-18 09:00 - 2013-09-18 09:00 - 00000000 ____D C:\Users\SHIPPING\AppData\Local\Apple Computer 2013-09-18 09:00 - 2013-09-18 09:00 - 00000000 ____D C:\ProgramData\Apple Computer 2013-09-18 08:59 - 2013-09-18 08:59 - 00000000 ____D C:\Users\SHIPPING\AppData\Local\Apple 2013-09-18 08:59 - 2013-09-18 08:59 - 00000000 ____D C:\Program Files\Common Files\Apple 2013-09-18 08:59 - 2013-09-18 08:59 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2013-09-18 08:59 - 2013-09-18 08:58 - 00000000 ____D C:\ProgramData\Apple 2013-09-18 08:58 - 2013-09-18 08:58 - 00000000 ____D C:\Program Files\Bonjour 2013-09-18 08:58 - 2013-09-18 08:58 - 00000000 ____D C:\Program Files (x86)\Bonjour 2013-09-17 11:34 - 2013-09-17 11:34 - 00000000 ____D C:\Program Files\Western Digital 2013-09-17 11:34 - 2013-08-07 16:25 - 00000000 ____D C:\Program Files\Common Files\Western Digital 2013-09-17 11:34 - 2013-08-07 16:25 - 00000000 ____D C:\Program Files (x86)\Western Digital 2013-09-17 11:34 - 2013-08-07 16:24 - 00000000 ____D C:\ProgramData\Package Cache 2013-09-17 11:34 - 2013-08-07 16:13 - 00000000 ____D C:\ProgramData\Western Digital ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-01 00:34 ==================== End Of Log ============================