Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 Ran by Pat (administrator) on MININT-ALOG0PC on 17-03-2014 22:18:26 Running from C:\Users\Pat\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Download link for 64-Bit Version: Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Dell) C:\Users\Pat\AppData\Local\Apps\2.0\YOXQPG0L.VKR\QAJ1NXHJ.45Y\dell..tion_0f612f649c4a10af_0005.0005_9914611622934cec\DellSystemDetect.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe (Google Inc.) C:\Users\Pat\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pat\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pat\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Pat\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [608112 2011-03-29] (Alps Electric Co., Ltd.) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6561384 2010-12-14] (Realtek Semiconductor) HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [4479648 2011-01-25] (Dell Inc.) HKLM\...\Run: [intelliPoint] - c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411952 2013-11-20] (AVG Technologies CZ, s.r.o.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-820448776-4151400007-3516740655-1002\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1093976 2013-09-19] (Garmin Ltd or its subsidiaries) HKU\S-1-5-21-820448776-4151400007-3516740655-1002\...\Run: [DellSystemDetect] - C:\Users\Pat\AppData\Local\Apps\2.0\YOXQPG0L.VKR\QAJ1NXHJ.45Y\dell..tion_0f612f649c4a10af_0005.0005_9914611622934cec\DellSystemDetect.exe [253952 2014-02-27] (Dell) HKU\S-1-5-21-820448776-4151400007-3516740655-1002\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-10-05] (Google Inc.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62 Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Users\Pat\AppData\Local\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Pat\AppData\Local\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Pat\AppData\Local\Google\Chrome\Application\33.0.1750.154\pdf.dll () CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Garmin Communicator Plug-In) - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Java Platform SE 7 U40) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Google Update) - C:\Users\Pat\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.400.43) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (Bloglovin') - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\agcgnofbabeggkbjcogfmjfaojpdnehm [2013-05-03] CHR Extension: (YouTube) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-14] CHR Extension: (Google Search) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-14] CHR Extension: (Local Events and Activities) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\gifkhdglojdcphjokffbgbmapcbhedfc [2013-02-23] CHR Extension: (Google Wallet) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21] CHR Extension: (Google Reader) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjjhlfkghdhmijklfnahfkpgmhcmfgcm [2012-10-29] CHR Extension: (Gmail) - C:\Users\Pat\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-14] ==================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.) R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250200 2013-09-19] (Garmin Ltd or its subsidiaries) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2102072 2013-12-18] (AVG) ==================== Drivers (Whitelisted) ==================== R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [206648 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2013-03-21] (AVG Technologies CZ, s.r.o.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 sscdserd; C:\Windows\System32\DRIVERS\sscdserd.sys [141384 2010-11-11] (MCCI Corporation) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2013-12-16] (TuneUp Software) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X] S0 ntcdrdrv; system32\DRIVERS\ntcdrdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-17 22:18 - 2014-03-17 22:18 - 00012260 _____ () C:\Users\Pat\Downloads\FRST.txt 2014-03-17 22:17 - 2014-03-17 22:18 - 00000000 ____D () C:\FRST 2014-03-17 22:16 - 2014-03-17 22:16 - 02157056 _____ (Farbar) C:\Users\Pat\Downloads\FRST64.exe 2014-03-17 20:16 - 2014-03-17 20:17 - 24322678 _____ () C:\Users\Pat\Downloads\retiring_patterns_part_2.zip 2014-03-17 19:00 - 2014-03-17 19:00 - 00000056 _____ () C:\Windows\setupact.log 2014-03-17 19:00 - 2014-03-17 19:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-17 18:22 - 2014-03-17 18:22 - 01950720 _____ () C:\Users\Pat\Downloads\AdwCleaner (2).exe 2014-03-17 04:30 - 2014-03-17 04:30 - 63210976 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\PowerPointViewer.exe 2014-03-17 04:30 - 2014-03-17 04:30 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-03-16 22:23 - 2014-03-16 22:23 - 00002395 _____ () C:\Users\Pat\Desktop\RKreport[0]_S_03162014_222315.txt 2014-03-16 22:20 - 2014-03-16 22:20 - 04497920 _____ () C:\Users\Pat\Desktop\RogueKillerX64 (1).exe 2014-03-16 22:19 - 2014-03-16 22:23 - 00000000 ____D () C:\Users\Pat\Desktop\RK_Quarantine 2014-03-16 22:09 - 2014-03-16 22:17 - 00004629 _____ () C:\Users\Pat\Desktop\attach.txt 2014-03-16 22:09 - 2014-03-16 22:09 - 00016169 _____ () C:\Users\Pat\Desktop\dds.txt 2014-03-16 22:08 - 2014-03-16 22:08 - 00688992 ____R (Swearware) C:\Users\Pat\Downloads\dds.scr 2014-03-16 22:08 - 2014-03-16 22:08 - 00000000 ___RD () C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-16 02:41 - 2014-03-16 02:41 - 00000084 _____ () C:\Users\Pat\Desktop\Need Help to Remove PUM.Bad.Proxy - Malware Removal Help - Malwarebytes Forum.url 2014-03-15 15:34 - 2014-03-15 15:34 - 00000000 __RHD () C:\MSOCache 2014-03-15 10:26 - 2014-03-15 10:26 - 00002762 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2014-03-14 13:26 - 2014-03-14 13:26 - 00000000 ____D () C:\Windows\PCHEALTH 2014-03-14 13:26 - 2014-03-14 13:26 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-03-14 13:26 - 2014-03-14 13:26 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client 2014-03-14 12:55 - 2014-03-14 12:55 - 00000000 ____D () C:\Users\Pat\Documents\CyberLink 2014-03-14 12:55 - 2014-03-14 12:55 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\CyberLink 2014-03-14 12:55 - 2014-03-14 12:55 - 00000000 ____D () C:\Users\Pat\AppData\Local\Cyberlink 2014-03-14 12:55 - 2014-03-14 12:55 - 00000000 ____D () C:\ProgramData\CyberLink 2014-03-14 12:52 - 2014-03-17 15:08 - 00126344 _____ () C:\Users\Pat\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-14 12:50 - 2014-03-17 19:00 - 00455840 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 12:42 - 2014-03-14 12:42 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler 2014-03-14 12:25 - 2013-12-18 09:38 - 00040248 _____ (AVG) C:\Windows\system32\TURegOpt.exe 2014-03-14 12:25 - 2013-12-18 09:38 - 00029496 _____ (AVG) C:\Windows\system32\authuitu.dll 2014-03-14 12:25 - 2013-12-18 09:38 - 00025400 _____ (AVG) C:\Windows\SysWOW64\authuitu.dll 2014-03-14 12:24 - 2014-03-14 12:24 - 00002231 _____ () C:\Users\Public\Desktop\AVG 1-Click Maintenance.lnk 2014-03-14 12:24 - 2014-03-14 12:24 - 00002205 _____ () C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk 2014-03-14 12:23 - 2014-03-14 12:42 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2014-03-14 12:23 - 2014-03-14 12:25 - 00000000 ____D () C:\ProgramData\AVG 2014-03-14 12:22 - 2014-03-14 12:22 - 78353832 _____ (AVG) C:\Users\Pat\Downloads\avg_tuht_stf_all_2014_295.exe 2014-03-14 12:09 - 2014-03-17 18:58 - 00000000 ____D () C:\AdwCleaner 2014-03-14 12:08 - 2014-03-14 12:08 - 01950720 _____ () C:\Users\Pat\Downloads\AdwCleaner (1).exe 2014-03-14 11:32 - 2014-03-14 12:50 - 00001712 _____ () C:\Windows\PFRO.log 2014-03-14 05:09 - 2014-03-14 05:09 - 00180000 _____ (Kaspersky Lab) C:\Users\Pat\Downloads\kss12.0.1.117EN_RU_DE_FR_2926 (1).exe 2014-03-14 05:05 - 2014-03-14 05:06 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\Pat\Downloads\tdsskiller (1).exe 2014-03-14 04:19 - 2014-03-14 04:19 - 00000000 _____ () C:\autoexec.bat 2014-03-14 04:16 - 2014-03-14 04:16 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Pat\Downloads\SpyHunter-Installer.exe 2014-03-14 04:07 - 2014-03-14 04:07 - 00003146 _____ () C:\Windows\System32\Tasks\{91EC9130-86F4-4152-BA4F-E4544B9D52BD} 2014-03-14 04:06 - 2014-03-14 04:06 - 01632144 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\setupconsumerc2rolw.exe 2014-03-13 18:02 - 2014-03-13 18:02 - 00001419 _____ () C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-13 18:02 - 2014-03-13 18:02 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-13 17:55 - 2014-03-13 17:55 - 00280204 _____ () C:\Users\Pat\Downloads\WindowsUpdateDiagnostic.diagcab 2014-03-13 17:22 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-03-13 17:09 - 2014-03-13 17:09 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-13 17:09 - 2014-03-13 17:09 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-13 17:09 - 2014-03-13 17:09 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 17:09 - 2014-03-13 17:09 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 17:09 - 2014-03-13 17:09 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-03-13 17:09 - 2014-03-13 17:09 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-03-13 17:09 - 2014-03-13 17:09 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-03-13 17:09 - 2014-03-13 17:09 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-03-13 17:09 - 2014-03-13 17:09 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-03-13 17:09 - 2014-03-13 17:09 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-03-13 17:09 - 2014-03-13 17:09 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-13 17:00 - 2014-02-06 21:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 17:00 - 2014-02-03 22:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-13 17:00 - 2014-02-03 22:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 17:00 - 2014-02-03 22:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-13 17:00 - 2014-02-03 22:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 17:00 - 2014-01-27 22:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-11 22:27 - 2014-03-11 22:27 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\AVAST Software 2014-03-11 21:49 - 2014-03-11 21:49 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-03-11 21:48 - 2014-03-11 21:48 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-03-11 21:48 - 2014-03-11 21:48 - 00000000 ____D () C:\Program Files\AVAST Software 2014-03-11 17:48 - 2014-03-11 17:48 - 01041920 _____ () C:\Users\Pat\Downloads\MicrosoftFixit50599.msi 2014-03-11 05:25 - 2014-03-11 05:25 - 00000017 _____ () C:\Users\Pat\AppData\Local\resmon.resmoncfg 2014-03-11 03:08 - 2014-03-11 03:08 - 00821760 _____ (Browser Opt-out) C:\Users\Pat\Downloads\uninstall.exe 2014-03-11 01:27 - 2014-03-11 01:27 - 00000000 ___RD () C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-11 01:23 - 2014-03-11 01:23 - 01122960 _____ (AnyProtect.com) C:\Users\Pat\AppData\Local\nsk3221.tmp 2014-03-11 01:22 - 2014-03-11 01:22 - 00000258 __RSH () C:\ProgramData\ntuser.pol 2014-03-10 05:17 - 2014-03-11 03:08 - 00003006 _____ () C:\Windows\System32\Tasks\{EAA8BF05-EA41-40FD-84B1-B2F916A56D4C} 2014-03-10 05:16 - 2014-03-11 03:08 - 00003006 _____ () C:\Windows\System32\Tasks\{9DD4AC70-B708-494E-AB35-E52CAC2FC68F} 2014-02-27 19:43 - 2014-03-11 03:08 - 00003442 _____ () C:\Windows\System32\Tasks\PCDEventLauncherTask 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\Dell 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\ProgramData\PCDr 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\ProgramData\PC-Doctor for Windows 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\Program Files\My Dell 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\Program Files\Dell Support Center 2014-02-27 19:41 - 2014-02-27 19:41 - 00404048 _____ () C:\Users\Pat\Downloads\DellSystemDetect (1).exe 2014-02-27 19:41 - 2014-02-27 19:41 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\PCDr 2014-02-27 19:36 - 2014-02-28 03:41 - 00000000 ____D () C:\Users\Pat\AppData\Local\Deployment 2014-02-27 19:35 - 2014-02-27 19:35 - 00404048 _____ () C:\Users\Pat\Downloads\DellSystemDetect.exe 2014-02-27 17:53 - 2014-02-27 17:53 - 00006492 _____ () C:\Users\Pat\Documents\cc_20140227_165303.reg 2014-02-27 14:26 - 2013-12-03 22:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-27 14:26 - 2013-12-03 22:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-27 14:26 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-27 14:26 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-27 14:26 - 2013-12-03 22:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-27 14:26 - 2013-12-03 22:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-27 14:26 - 2013-12-03 22:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-27 14:26 - 2013-12-03 22:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-27 14:26 - 2013-12-03 22:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-27 14:26 - 2013-12-03 22:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-27 14:26 - 2013-12-03 22:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-27 14:26 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-27 14:26 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-27 14:26 - 2013-12-03 22:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-27 14:26 - 2013-12-03 21:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-27 14:26 - 2013-12-03 21:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-27 14:26 - 2013-12-03 21:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-27 14:26 - 2013-12-03 21:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-27 14:26 - 2013-11-26 21:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-02-27 14:26 - 2013-11-26 21:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-02-27 14:26 - 2013-11-26 21:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-02-27 14:26 - 2013-11-26 21:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-02-27 14:26 - 2013-11-26 21:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-02-27 14:26 - 2013-11-26 21:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-02-27 14:26 - 2013-11-26 21:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-02-27 14:25 - 2013-12-31 19:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-27 14:25 - 2013-12-31 19:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-27 14:25 - 2013-12-24 19:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-27 14:25 - 2013-12-24 18:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-27 14:25 - 2013-12-05 22:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-27 14:25 - 2013-12-05 22:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-27 14:25 - 2013-12-05 22:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-27 14:25 - 2013-12-05 22:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-27 14:25 - 2013-11-26 04:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-27 14:25 - 2013-11-22 18:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-27 14:23 - 2013-11-26 07:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-02-26 22:55 - 2014-02-26 22:55 - 00001789 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-02-26 22:54 - 2014-02-26 22:55 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-02-26 22:54 - 2014-02-26 22:55 - 00000000 ____D () C:\Program Files\iTunes 2014-02-26 22:54 - 2014-02-26 22:55 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-02-26 22:54 - 2014-02-26 22:54 - 00000000 ____D () C:\Program Files\iPod 2014-02-26 06:51 - 2014-02-26 06:52 - 04765152 _____ (Piriform Ltd) C:\Users\Pat\Downloads\ccsetup411.exe 2014-02-25 18:51 - 2014-02-25 18:51 - 01324940 _____ () C:\Users\Pat\Downloads\NetStumblerInstaller_0_4_0.exe 2014-02-24 17:58 - 2014-02-24 17:58 - 00000078 _____ () C:\Users\Pat\Desktop\https---access247.ginkgoresidential.com-default.aspx.url 2014-02-19 23:47 - 2014-02-19 23:47 - 00000066 _____ () C:\Users\Pat\Desktop\Digestive Health Specialists, P.A. - Winston-Salem Advance Kernersville Thomasville North Carolina.url ==================== One Month Modified Files and Folders ======= 2014-03-17 22:18 - 2014-03-17 22:18 - 00012260 _____ () C:\Users\Pat\Downloads\FRST.txt 2014-03-17 22:18 - 2014-03-17 22:17 - 00000000 ____D () C:\FRST 2014-03-17 22:16 - 2014-03-17 22:16 - 02157056 _____ (Farbar) C:\Users\Pat\Downloads\FRST64.exe 2014-03-17 22:05 - 2011-10-05 17:49 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-17 21:22 - 2011-10-13 23:07 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-820448776-4151400007-3516740655-1002UA.job 2014-03-17 20:17 - 2014-03-17 20:16 - 24322678 _____ () C:\Users\Pat\Downloads\retiring_patterns_part_2.zip 2014-03-17 19:08 - 2009-07-14 00:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-17 19:08 - 2009-07-14 00:45 - 00021472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-17 19:04 - 2011-09-23 20:42 - 01586053 _____ () C:\Windows\WindowsUpdate.log 2014-03-17 19:03 - 2013-02-27 05:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-17 19:03 - 2011-10-05 17:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-17 19:01 - 2011-10-05 17:49 - 00000888 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-17 19:00 - 2014-03-17 19:00 - 00000056 _____ () C:\Windows\setupact.log 2014-03-17 19:00 - 2014-03-17 19:00 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-17 19:00 - 2014-03-14 12:50 - 00455840 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-17 19:00 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-17 18:58 - 2014-03-14 12:09 - 00000000 ____D () C:\AdwCleaner 2014-03-17 18:58 - 2011-10-08 13:25 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\SoftGrid Client 2014-03-17 18:22 - 2014-03-17 18:22 - 01950720 _____ () C:\Users\Pat\Downloads\AdwCleaner (2).exe 2014-03-17 17:40 - 2011-11-06 11:26 - 00000000 ____D () C:\ProgramData\MFAData 2014-03-17 15:08 - 2014-03-14 12:52 - 00126344 _____ () C:\Users\Pat\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-17 04:30 - 2014-03-17 04:30 - 63210976 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\PowerPointViewer.exe 2014-03-17 04:30 - 2014-03-17 04:30 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-03-17 04:24 - 2011-10-10 13:58 - 00000000 ____D () C:\Users\Pat\Documents\My PSP Files 2014-03-16 22:23 - 2014-03-16 22:23 - 00002395 _____ () C:\Users\Pat\Desktop\RKreport[0]_S_03162014_222315.txt 2014-03-16 22:23 - 2014-03-16 22:19 - 00000000 ____D () C:\Users\Pat\Desktop\RK_Quarantine 2014-03-16 22:20 - 2014-03-16 22:20 - 04497920 _____ () C:\Users\Pat\Desktop\RogueKillerX64 (1).exe 2014-03-16 22:17 - 2014-03-16 22:09 - 00004629 _____ () C:\Users\Pat\Desktop\attach.txt 2014-03-16 22:09 - 2014-03-16 22:09 - 00016169 _____ () C:\Users\Pat\Desktop\dds.txt 2014-03-16 22:08 - 2014-03-16 22:08 - 00688992 ____R (Swearware) C:\Users\Pat\Downloads\dds.scr 2014-03-16 22:08 - 2014-03-16 22:08 - 00000000 ___RD () C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-16 17:31 - 2011-10-13 23:07 - 00000848 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-820448776-4151400007-3516740655-1002Core.job 2014-03-16 02:41 - 2014-03-16 02:41 - 00000084 _____ () C:\Users\Pat\Desktop\Need Help to Remove PUM.Bad.Proxy - Malware Removal Help - Malwarebytes Forum.url 2014-03-16 01:28 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-15 15:34 - 2014-03-15 15:34 - 00000000 __RHD () C:\MSOCache 2014-03-15 13:04 - 2011-10-10 14:03 - 00002265 _____ () C:\Users\Pat\Desktop\Photobucket.website 2014-03-15 10:26 - 2014-03-15 10:26 - 00002762 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 2014-03-15 08:27 - 2009-07-14 01:13 - 00783400 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-14 16:36 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache 2014-03-14 13:27 - 2011-10-08 13:24 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\TP 2014-03-14 13:26 - 2014-03-14 13:26 - 00000000 ____D () C:\Windows\PCHEALTH 2014-03-14 13:26 - 2014-03-14 13:26 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-03-14 13:26 - 2014-03-14 13:26 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client 2014-03-14 13:26 - 2011-10-08 13:24 - 00800096 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-03-14 13:26 - 2011-09-23 21:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-03-14 13:26 - 2009-07-13 23:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-03-14 12:55 - 2014-03-14 12:55 - 00000000 ____D () C:\Users\Pat\Documents\CyberLink 2014-03-14 12:55 - 2014-03-14 12:55 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\CyberLink 2014-03-14 12:55 - 2014-03-14 12:55 - 00000000 ____D () C:\Users\Pat\AppData\Local\Cyberlink 2014-03-14 12:55 - 2014-03-14 12:55 - 00000000 ____D () C:\ProgramData\CyberLink 2014-03-14 12:50 - 2014-03-14 11:32 - 00001712 _____ () C:\Windows\PFRO.log 2014-03-14 12:42 - 2014-03-14 12:42 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler 2014-03-14 12:42 - 2014-03-14 12:23 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2014-03-14 12:25 - 2014-03-14 12:23 - 00000000 ____D () C:\ProgramData\AVG 2014-03-14 12:24 - 2014-03-14 12:24 - 00002231 _____ () C:\Users\Public\Desktop\AVG 1-Click Maintenance.lnk 2014-03-14 12:24 - 2014-03-14 12:24 - 00002205 _____ () C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk 2014-03-14 12:24 - 2012-06-01 02:25 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\AVG 2014-03-14 12:22 - 2014-03-14 12:22 - 78353832 _____ (AVG) C:\Users\Pat\Downloads\avg_tuht_stf_all_2014_295.exe 2014-03-14 12:08 - 2014-03-14 12:08 - 01950720 _____ () C:\Users\Pat\Downloads\AdwCleaner (1).exe 2014-03-14 05:09 - 2014-03-14 05:09 - 00180000 _____ (Kaspersky Lab) C:\Users\Pat\Downloads\kss12.0.1.117EN_RU_DE_FR_2926 (1).exe 2014-03-14 05:06 - 2014-03-14 05:05 - 04130656 _____ (Kaspersky Lab ZAO) C:\Users\Pat\Downloads\tdsskiller (1).exe 2014-03-14 04:19 - 2014-03-14 04:19 - 00000000 _____ () C:\autoexec.bat 2014-03-14 04:16 - 2014-03-14 04:16 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Pat\Downloads\SpyHunter-Installer.exe 2014-03-14 04:07 - 2014-03-14 04:07 - 00003146 _____ () C:\Windows\System32\Tasks\{91EC9130-86F4-4152-BA4F-E4544B9D52BD} 2014-03-14 04:06 - 2014-03-14 04:06 - 01632144 _____ (Microsoft Corporation) C:\Users\Pat\Downloads\setupconsumerc2rolw.exe 2014-03-14 03:08 - 2011-09-23 23:33 - 00000000 ____D () C:\Windows\Panther 2014-03-13 18:04 - 2013-03-22 16:03 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\Mp3tag 2014-03-13 18:02 - 2014-03-13 18:02 - 00001419 _____ () C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-03-13 18:02 - 2014-03-13 18:02 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-03-13 17:58 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-03-13 17:55 - 2014-03-13 17:55 - 00280204 _____ () C:\Users\Pat\Downloads\WindowsUpdateDiagnostic.diagcab 2014-03-13 17:09 - 2014-03-13 17:09 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-13 17:09 - 2014-03-13 17:09 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-13 17:09 - 2014-03-13 17:09 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 17:09 - 2014-03-13 17:09 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 17:09 - 2014-03-13 17:09 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-03-13 17:09 - 2014-03-13 17:09 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-03-13 17:09 - 2014-03-13 17:09 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-03-13 17:09 - 2014-03-13 17:09 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-03-13 17:09 - 2014-03-13 17:09 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-03-13 17:09 - 2014-03-13 17:09 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-03-13 17:09 - 2014-03-13 17:09 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-03-13 17:09 - 2014-03-13 17:09 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-03-13 17:09 - 2014-03-13 17:09 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-13 17:05 - 2013-10-03 22:20 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-13 17:02 - 2011-10-10 09:58 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-12 04:51 - 2013-10-29 22:40 - 00000000 ____D () C:\Users\Pat\SecurityScans 2014-03-12 04:51 - 2011-10-05 10:04 - 00000000 ____D () C:\Users\Pat 2014-03-12 03:00 - 2013-11-06 23:36 - 00000000 ____D () C:\Users\Pat\AppData\Local\BearShare 2014-03-11 23:22 - 2010-11-21 03:16 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-11 23:22 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\registration 2014-03-11 22:27 - 2014-03-11 22:27 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\AVAST Software 2014-03-11 21:49 - 2014-03-11 21:49 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-03-11 21:48 - 2014-03-11 21:48 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-03-11 21:48 - 2014-03-11 21:48 - 00000000 ____D () C:\Program Files\AVAST Software 2014-03-11 17:48 - 2014-03-11 17:48 - 01041920 _____ () C:\Users\Pat\Downloads\MicrosoftFixit50599.msi 2014-03-11 05:25 - 2014-03-11 05:25 - 00000017 _____ () C:\Users\Pat\AppData\Local\resmon.resmoncfg 2014-03-11 03:08 - 2014-03-11 03:08 - 00821760 _____ (Browser Opt-out) C:\Users\Pat\Downloads\uninstall.exe 2014-03-11 03:08 - 2014-03-10 05:17 - 00003006 _____ () C:\Windows\System32\Tasks\{EAA8BF05-EA41-40FD-84B1-B2F916A56D4C} 2014-03-11 03:08 - 2014-03-10 05:16 - 00003006 _____ () C:\Windows\System32\Tasks\{9DD4AC70-B708-494E-AB35-E52CAC2FC68F} 2014-03-11 03:08 - 2014-02-27 19:43 - 00003442 _____ () C:\Windows\System32\Tasks\PCDEventLauncherTask 2014-03-11 03:08 - 2013-08-11 13:01 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-03-11 03:08 - 2012-12-23 03:28 - 00003010 _____ () C:\Windows\System32\Tasks\{BB4AADCA-0373-4D08-9327-9B1200AD6AAB} 2014-03-11 03:08 - 2011-11-06 11:30 - 00003232 _____ () C:\Windows\System32\Tasks\SidebarExecute 2014-03-11 01:27 - 2014-03-11 01:27 - 00000000 ___RD () C:\Users\Pat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-11 01:26 - 2011-10-05 17:49 - 00000000 ____D () C:\Program Files (x86)\Google 2014-03-11 01:23 - 2014-03-11 01:23 - 01122960 _____ (AnyProtect.com) C:\Users\Pat\AppData\Local\nsk3221.tmp 2014-03-11 01:22 - 2014-03-11 01:22 - 00000258 __RSH () C:\ProgramData\ntuser.pol 2014-03-11 01:22 - 2009-07-13 23:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-03-11 01:22 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-02-28 03:41 - 2014-02-27 19:36 - 00000000 ____D () C:\Users\Pat\AppData\Local\Deployment 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\Dell 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\ProgramData\PCDr 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\ProgramData\PC-Doctor for Windows 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\Program Files\My Dell 2014-02-27 19:43 - 2014-02-27 19:43 - 00000000 ____D () C:\Program Files\Dell Support Center 2014-02-27 19:41 - 2014-02-27 19:41 - 00404048 _____ () C:\Users\Pat\Downloads\DellSystemDetect (1).exe 2014-02-27 19:41 - 2014-02-27 19:41 - 00000000 ____D () C:\Users\Pat\AppData\Roaming\PCDr 2014-02-27 19:36 - 2013-02-04 10:59 - 00000000 ____D () C:\Users\Pat\AppData\Local\Apps\2.0 2014-02-27 19:35 - 2014-02-27 19:35 - 00404048 _____ () C:\Users\Pat\Downloads\DellSystemDetect.exe 2014-02-27 17:53 - 2014-02-27 17:53 - 00006492 _____ () C:\Users\Pat\Documents\cc_20140227_165303.reg 2014-02-26 22:55 - 2014-02-26 22:55 - 00001789 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-02-26 22:55 - 2014-02-26 22:54 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-02-26 22:55 - 2014-02-26 22:54 - 00000000 ____D () C:\Program Files\iTunes 2014-02-26 22:55 - 2014-02-26 22:54 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-02-26 22:54 - 2014-02-26 22:54 - 00000000 ____D () C:\Program Files\iPod 2014-02-26 06:52 - 2014-02-26 06:51 - 04765152 _____ (Piriform Ltd) C:\Users\Pat\Downloads\ccsetup411.exe 2014-02-26 06:52 - 2013-08-11 13:01 - 00000828 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-26 06:52 - 2013-08-11 13:01 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-25 18:51 - 2014-02-25 18:51 - 01324940 _____ () C:\Users\Pat\Downloads\NetStumblerInstaller_0_4_0.exe 2014-02-24 17:58 - 2014-02-24 17:58 - 00000078 _____ () C:\Users\Pat\Desktop\https---access247.ginkgoresidential.com-default.aspx.url 2014-02-19 23:47 - 2014-02-19 23:47 - 00000066 _____ () C:\Users\Pat\Desktop\Digestive Health Specialists, P.A. - Winston-Salem Advance Kernersville Thomasville North Carolina.url 2014-02-16 12:00 - 2011-10-05 17:49 - 00003888 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-16 12:00 - 2011-10-05 17:49 - 00003636 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore Some content of TEMP: ==================== C:\Users\Pat\AppData\Local\Temp\ntdll_dump.dll C:\Users\Pat\AppData\Local\Temp\Quarantine.exe C:\Users\Pat\AppData\Local\Temp\SHSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-12 16:02 ==================== End Of Log ============================Addition.txt Hope I did this right, and am glad YOU understand all this! Thanks SO much! Pat O