Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02 Ran by Les (administrator) on LES-PC on 28-05-2014 01:39:11 Running from C:\Users\Les\Desktop\PopUp Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (Macrovision) C:\Program Files (x86)\Belkin Automatic Power Management Software\BelkinAPMmonitor.exe (MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Belkin Automatic Power Management Software\jre\bin\javaw.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe () C:\Program Files\pcreg\pcreg.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe () C:\ProgramData\TVersity\Media Server\MediaServer.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (Macrovision) C:\Program Files (x86)\Belkin Automatic Power Management Software\BelkinAPM.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Belkin Automatic Power Management Software\jre\bin\javaw.exe (The Chromium Authors) C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (Macrovision) C:\Program Files (x86)\Belkin Automatic Power Management Software\BelkinAPMRMI.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Belkin Automatic Power Management Software\jre\bin\javaw.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [belkinAPM] => C:\Program Files (x86)\Belkin Automatic Power Management Software\BelkinAPM.exe [114688 2013-03-15] (Macrovision) HKLM\...\Policies\Explorer: [HideSCAHealth] 1 ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://my.yahoo.com/?mkg=015 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Les\AppData\Roaming\Mozilla\Firefox\Profiles\bgiwwrqg.default-1366599260262 FF Homepage: hxxp://my.yahoo.com/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Extension: Adblock Plus Pop-up Addon - C:\Users\Les\AppData\Roaming\Mozilla\Firefox\Profiles\bgiwwrqg.default-1366599260262\Extensions\adblockpopups@jessehakanen.net.xpi [2014-04-24] FF Extension: Adblock Plus - C:\Users\Les\AppData\Roaming\Mozilla\Firefox\Profiles\bgiwwrqg.default-1366599260262\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-04-26] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-03-16] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION ==================== Services (Whitelisted) ================= S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1473792 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.) R2 BelkinAPMmonitor; C:\Program Files (x86)\Belkin Automatic Power Management Software\BelkinAPMmonitor.exe [114688 2013-03-15] (Macrovision) R3 BelkinAPMRMI; C:\Program Files (x86)\Belkin Automatic Power Management Software\BelkinAPMRMI.exe [114688 2013-03-15] (Macrovision) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [103992 2012-10-26] (MSI) R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [143416 2012-10-25] (MSI) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) R2 pcregservice; C:\Program Files\pcreg\pcreg.exe [249024 2014-05-25] () R2 Spooler; C:\Windows\SysWOW64\spoolsv.exe [0 2013-08-24] () R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2100024 2013-08-29] (TuneUp Software) R2 TVersityMediaServer; C:\ProgramData\TVersity\Media Server\MediaServer.exe [5283624 2013-03-13] () ==================== Drivers (Whitelisted) ==================== R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [273176 2014-05-13] (AVG Technologies CZ, s.r.o.) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-06-23] (GFI Software) R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37456 2011-04-12] (Paragon Software Group) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-05-28] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 MEMSWEEP2; C:\Windows\system32\63D1.tmp [6144 2011-05-12] (Sophos Plc) R3 MODEMCSA; C:\Windows\System32\drivers\MODEMCSA.sys [24064 2009-07-13] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI) R3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI) S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [47632 2013-04-29] (Panda Security, S.L.) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.) R3 smserial; C:\Windows\System32\DRIVERS\smserial.sys [1202688 2009-10-26] (Motorola Inc.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-28 01:21 - 2014-05-28 01:21 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-28 01:20 - 2014-05-28 01:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-05-28 01:20 - 2014-05-28 01:20 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-05-28 01:20 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-28 01:20 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-28 01:20 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-28 01:13 - 2014-05-28 01:13 - 00001726 _____ () C:\Users\Les\Desktop\JRT.txt 2014-05-27 22:42 - 2014-05-27 22:42 - 00004317 _____ () C:\Users\Les\Desktop\AdwCleaner[s0].txt 2014-05-27 22:35 - 2014-05-28 01:03 - 00000000 ____D () C:\AdwCleaner 2014-05-27 22:35 - 2014-05-27 22:36 - 00004482 _____ () C:\Users\Les\Desktop\AdwCleaner[R0].txt 2014-05-27 22:35 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-27 10:34 - 2014-05-27 10:34 - 00028557 _____ () C:\ComboFix.txt 2014-05-27 10:29 - 2014-05-27 10:34 - 00000000 ____D () C:\Qoobox 2014-05-27 10:29 - 2014-05-27 10:33 - 00000000 ____D () C:\Windows\erdnt 2014-05-27 10:29 - 2011-06-26 02:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-27 10:29 - 2010-11-07 13:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-27 10:29 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-27 10:29 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-27 10:29 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-27 10:29 - 2000-08-30 20:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-27 10:29 - 2000-08-30 20:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-27 10:29 - 2000-08-30 20:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-27 10:15 - 2014-05-27 10:15 - 00000000 ____D () C:\TDSSKiller_Quarantine 2014-05-27 09:58 - 2014-05-28 01:08 - 00000000 ____D () C:\Windows\ERUNT 2014-05-27 09:58 - 2014-05-27 09:58 - 00000256 _____ () C:\DelFix.txt 2014-05-27 08:04 - 2014-05-27 08:09 - 00000000 ____D () C:\Users\Les\Desktop\RK_Quarantine 2014-05-27 07:28 - 2014-05-27 07:28 - 00177680 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe.7d45.deleteme 2014-05-27 05:20 - 2014-05-27 07:37 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2014-05-27 05:20 - 2014-05-27 05:37 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-05-27 05:20 - 2014-05-27 05:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2014-05-26 22:36 - 2014-05-28 01:39 - 00000000 ____D () C:\Users\Les\Desktop\PopUp 2014-05-26 19:42 - 2014-05-28 01:39 - 00000000 ____D () C:\FRST 2014-05-26 00:14 - 2014-05-26 00:14 - 00110080 _____ () C:\Users\Les\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-25 23:37 - 2014-05-28 01:20 - 00180030 _____ () C:\Windows\setupact.log 2014-05-25 23:37 - 2014-05-27 22:44 - 00002568 _____ () C:\Windows\PFRO.log 2014-05-25 23:37 - 2014-05-25 23:37 - 00418152 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-25 23:37 - 2014-05-25 23:37 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-25 09:34 - 2014-05-06 00:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-25 09:34 - 2014-05-06 00:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-25 09:34 - 2014-05-05 23:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-25 09:34 - 2014-05-05 23:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-25 09:34 - 2014-05-05 23:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-25 09:34 - 2014-05-05 22:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-25 09:13 - 2014-04-11 22:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-25 09:13 - 2014-04-11 22:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-25 09:13 - 2014-04-11 22:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-25 09:13 - 2014-04-11 22:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-25 09:13 - 2014-04-11 22:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-25 09:13 - 2014-04-11 22:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-25 09:13 - 2014-04-11 22:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-25 09:13 - 2014-04-11 22:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-25 09:13 - 2014-04-11 22:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-25 09:13 - 2014-03-04 05:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-25 09:13 - 2014-03-04 05:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-25 09:13 - 2014-03-04 05:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-25 09:13 - 2014-03-04 05:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-25 09:13 - 2014-03-04 05:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-25 09:13 - 2014-03-04 05:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-25 09:13 - 2014-03-04 05:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-25 09:13 - 2014-03-04 05:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-25 09:13 - 2014-03-04 05:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-25 09:13 - 2014-03-04 05:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-25 09:13 - 2014-03-04 05:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-25 09:13 - 2014-03-04 05:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-25 09:13 - 2014-03-04 05:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-25 09:13 - 2014-03-04 05:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-25 09:13 - 2014-03-04 05:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-25 09:13 - 2014-03-04 05:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-25 09:13 - 2014-03-04 05:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-25 09:13 - 2014-03-04 05:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-25 09:13 - 2014-03-04 05:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-25 09:13 - 2014-03-04 05:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-25 09:13 - 2014-03-04 05:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-25 09:12 - 2014-03-24 22:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-25 09:11 - 2014-05-09 02:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-25 09:11 - 2014-05-09 02:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-25 09:11 - 2014-03-24 22:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-25 04:54 - 2014-05-27 07:31 - 00000000 ____D () C:\Program Files\stinger 2014-05-25 04:38 - 2014-05-27 11:18 - 00003684 _____ () C:\Windows\System32\Tasks\pcreg 2014-05-25 04:38 - 2014-05-26 20:24 - 00000000 ____D () C:\Program Files\pcreg 2014-05-25 04:34 - 2011-05-12 14:03 - 00006144 ____N (Sophos Plc) C:\Windows\system32\F095.tmp 2014-05-25 04:34 - 2011-05-12 14:03 - 00006144 ____N (Sophos Plc) C:\Windows\system32\63D1.tmp 2014-05-25 04:20 - 2011-05-12 14:03 - 00006144 ____N (Sophos Plc) C:\Windows\system32\390B.tmp 2014-05-25 04:19 - 2011-05-12 14:03 - 00006144 ____N (Sophos Plc) C:\Windows\system32\C8E9.tmp 2014-05-25 04:09 - 2011-05-12 14:03 - 00006144 ____N (Sophos Plc) C:\Windows\system32\CA45.tmp 2014-05-25 04:09 - 2011-05-12 14:03 - 00006144 ____N (Sophos Plc) C:\Windows\system32\3FD2.tmp 2014-05-25 04:08 - 2014-05-25 05:51 - 00000000 ____D () C:\Program Files (x86)\Sophos 2014-05-24 10:28 - 2014-05-24 10:28 - 00283182 _____ () C:\Users\Les\AppData\Local\census.cache 2014-05-24 10:28 - 2014-05-24 10:28 - 00197179 _____ () C:\Users\Les\AppData\Local\ars.cache 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\TrayIcon12.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\atiuxpag.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\atiu9pag.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\atidxx32.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\aticfx32.dll 2014-05-24 10:08 - 2014-05-24 10:08 - 00000036 _____ () C:\Users\Les\AppData\Local\housecall.guid.cache 2014-05-24 10:08 - 2013-09-02 03:58 - 00175528 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmcomm.sys 2014-05-24 09:22 - 2013-04-29 09:17 - 00047632 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PSKMAD.sys 2014-05-24 00:45 - 2014-05-24 00:45 - 00012326 _____ () C:\Users\Les\AppData\Local\hpjijmtp 2014-05-24 00:44 - 2014-05-24 00:44 - 00068314 _____ () C:\Users\Les\AppData\Local\qfvexiee 2014-05-24 00:42 - 2014-05-24 00:42 - 00000000 _____ () C:\Users\Les\AppData\Roaming\SharedSettings.ccs 2014-05-14 13:18 - 2014-05-14 13:18 - 00000859 _____ () C:\Users\Les\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys 2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys 2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys 2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys 2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys 2014-05-09 19:23 - 2014-05-27 07:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-05-28 01:39 - 2014-05-26 22:36 - 00000000 ____D () C:\Users\Les\Desktop\PopUp 2014-05-28 01:39 - 2014-05-26 19:42 - 00000000 ____D () C:\FRST 2014-05-28 01:38 - 2013-05-28 01:53 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-28 01:27 - 2009-07-14 00:45 - 00031104 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-28 01:27 - 2009-07-14 00:45 - 00031104 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-28 01:24 - 2013-05-26 05:01 - 00000000 ____D () C:\ProgramData\MFAData 2014-05-28 01:24 - 2009-07-14 01:13 - 00786254 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-28 01:23 - 2013-09-23 14:00 - 01397940 _____ () C:\Windows\WindowsUpdate.log 2014-05-28 01:21 - 2014-05-28 01:21 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-28 01:20 - 2014-05-28 01:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-05-28 01:20 - 2014-05-28 01:20 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-05-28 01:20 - 2014-05-25 23:37 - 00180030 _____ () C:\Windows\setupact.log 2014-05-28 01:20 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-28 01:13 - 2014-05-28 01:13 - 00001726 _____ () C:\Users\Les\Desktop\JRT.txt 2014-05-28 01:08 - 2014-05-27 09:58 - 00000000 ____D () C:\Windows\ERUNT 2014-05-28 01:08 - 2013-03-14 20:56 - 00000000 ____D () C:\Users\Les\Documents\Outlook Files 2014-05-28 01:03 - 2014-05-27 22:35 - 00000000 ____D () C:\AdwCleaner 2014-05-27 23:18 - 2013-03-15 05:39 - 00000000 ____D () C:\Program Files (x86)\Belkin Automatic Power Management Software 2014-05-27 22:44 - 2014-05-25 23:37 - 00002568 _____ () C:\Windows\PFRO.log 2014-05-27 22:42 - 2014-05-27 22:42 - 00004317 _____ () C:\Users\Les\Desktop\AdwCleaner[s0].txt 2014-05-27 22:42 - 2013-09-23 14:01 - 00000000 ____D () C:\Users\Les 2014-05-27 22:36 - 2014-05-27 22:35 - 00004482 _____ () C:\Users\Les\Desktop\AdwCleaner[R0].txt 2014-05-27 21:37 - 2013-03-16 22:19 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-27 21:37 - 2013-03-16 22:19 - 00000888 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-27 11:43 - 2013-03-16 22:19 - 00003900 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-27 11:43 - 2013-03-16 22:19 - 00003648 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-27 11:18 - 2014-05-25 04:38 - 00003684 _____ () C:\Windows\System32\Tasks\pcreg 2014-05-27 11:14 - 2013-08-25 05:46 - 00000000 ____D () C:\Users\Les\AppData\Roaming\Malwarebytes 2014-05-27 11:14 - 2013-08-25 05:46 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-27 11:06 - 2013-03-15 16:23 - 00042739 _____ () C:\Windows\SysWOW64\TVersityMediaServer.log 2014-05-27 10:34 - 2014-05-27 10:34 - 00028557 _____ () C:\ComboFix.txt 2014-05-27 10:34 - 2014-05-27 10:29 - 00000000 ____D () C:\Qoobox 2014-05-27 10:34 - 2009-07-13 23:20 - 00000000 __RHD () C:\Users\Default 2014-05-27 10:33 - 2014-05-27 10:29 - 00000000 ____D () C:\Windows\erdnt 2014-05-27 10:33 - 2009-07-13 22:34 - 00000215 _____ () C:\Windows\system.ini 2014-05-27 10:33 - 2009-07-13 22:34 - 00000027 _____ () C:\Windows\system32\Drivers\etc\hosts.old 2014-05-27 10:15 - 2014-05-27 10:15 - 00000000 ____D () C:\TDSSKiller_Quarantine 2014-05-27 09:58 - 2014-05-27 09:58 - 00000256 _____ () C:\DelFix.txt 2014-05-27 08:09 - 2014-05-27 08:04 - 00000000 ____D () C:\Users\Les\Desktop\RK_Quarantine 2014-05-27 07:37 - 2014-05-27 05:20 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2014-05-27 07:37 - 2014-05-09 19:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-27 07:37 - 2014-04-26 04:04 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-27 07:37 - 2013-03-19 22:43 - 00000000 ____D () C:\Users\Les\AppData\Roaming\uTorrent 2014-05-27 07:37 - 2013-03-14 22:18 - 00000000 ____D () C:\Program Files\Microsoft Mouse and Keyboard Center 2014-05-27 07:37 - 2013-03-14 02:10 - 00000000 ____D () C:\SuperChargerProfile 2014-05-27 07:37 - 2011-01-01 02:15 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2014-05-27 07:37 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\security 2014-05-27 07:37 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\schemas 2014-05-27 07:37 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache 2014-05-27 07:37 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\registration 2014-05-27 07:37 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-27 07:37 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\AppCompat 2014-05-27 07:37 - 2009-07-13 23:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-05-27 07:31 - 2014-05-25 04:54 - 00000000 ____D () C:\Program Files\stinger 2014-05-27 07:28 - 2014-05-27 07:28 - 00177680 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe.7d45.deleteme 2014-05-27 06:55 - 2014-03-31 09:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2014-05-27 06:48 - 2009-07-14 01:08 - 00032578 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-27 05:37 - 2014-05-27 05:20 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-05-27 05:20 - 2014-05-27 05:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2014-05-27 02:43 - 2013-06-29 18:56 - 00379038 _____ () C:\Users\Les\Desktop\- Knicks-.txt 2014-05-26 21:44 - 2013-03-15 14:52 - 00000000 ____D () C:\ProgramData\Zoom Player 2014-05-26 20:24 - 2014-05-25 04:38 - 00000000 ____D () C:\Program Files\pcreg 2014-05-26 20:20 - 2013-09-23 15:24 - 00000000 ____D () C:\ProgramData\AVG2014 2014-05-26 01:26 - 2011-01-01 02:19 - 00000000 ____D () C:\Users\Les\AppData\Roaming\Mipony 2014-05-26 00:14 - 2014-05-26 00:14 - 00110080 _____ () C:\Users\Les\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-25 23:37 - 2014-05-25 23:37 - 00418152 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-25 23:37 - 2014-05-25 23:37 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-25 23:37 - 2013-03-14 01:58 - 00000000 ___RD () C:\Users\Les\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-25 23:37 - 2013-03-14 01:58 - 00000000 ___RD () C:\Users\Les\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-25 09:37 - 2011-01-01 01:36 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-25 09:18 - 2014-04-05 19:08 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-25 09:15 - 2014-04-05 19:08 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-25 06:07 - 2013-03-20 05:52 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-05-25 05:51 - 2014-05-25 04:08 - 00000000 ____D () C:\Program Files (x86)\Sophos 2014-05-25 05:03 - 2013-10-21 16:24 - 00000000 ____D () C:\Windows\Minidump 2014-05-24 10:28 - 2014-05-24 10:28 - 00283182 _____ () C:\Users\Les\AppData\Local\census.cache 2014-05-24 10:28 - 2014-05-24 10:28 - 00197179 _____ () C:\Users\Les\AppData\Local\ars.cache 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\TrayIcon12.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\atiuxpag.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\atiu9pag.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\atidxx32.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\aticfx32.dll 2014-05-24 10:08 - 2014-05-24 10:08 - 00000036 _____ () C:\Users\Les\AppData\Local\housecall.guid.cache 2014-05-24 00:45 - 2014-05-24 00:45 - 00012326 _____ () C:\Users\Les\AppData\Local\hpjijmtp 2014-05-24 00:44 - 2014-05-24 00:44 - 00068314 _____ () C:\Users\Les\AppData\Local\qfvexiee 2014-05-24 00:42 - 2014-05-24 00:42 - 00000000 _____ () C:\Users\Les\AppData\Roaming\SharedSettings.ccs 2014-05-22 20:55 - 2013-03-15 22:59 - 00000000 ____D () C:\Users\Les\AppData\Roaming\MediaMonkey 2014-05-14 13:18 - 2014-05-14 13:18 - 00000859 _____ () C:\Users\Les\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2014-05-14 13:18 - 2013-03-19 22:44 - 00000000 ____D () C:\Program Files (x86)\uTorrent 2014-05-14 04:38 - 2013-05-28 01:53 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-14 04:38 - 2013-03-15 16:22 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-14 04:38 - 2013-03-15 16:22 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-13 14:20 - 2014-05-13 14:20 - 00273176 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys 2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx64.sys 2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgloga.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsha.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiska.sys 2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys 2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys 2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx64.sys 2014-05-12 07:26 - 2014-05-28 01:20 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-05-28 01:20 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-28 01:20 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-10 06:51 - 2013-07-04 15:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-09 02:14 - 2014-05-25 09:11 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 02:11 - 2014-05-25 09:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-07 04:14 - 2013-03-15 16:23 - 01024098 _____ () C:\Windows\SysWOW64\TVersityMediaServer.log.1 2014-05-06 23:41 - 2013-03-16 02:41 - 00003696 _____ () C:\Windows\System32\Tasks\Adobe online update program 2014-05-06 00:40 - 2014-05-25 09:34 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 00:17 - 2014-05-25 09:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-05 23:25 - 2014-05-25 09:34 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-05 23:07 - 2014-05-25 09:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-05 23:00 - 2014-05-25 09:34 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-05 22:10 - 2014-05-25 09:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll Some content of TEMP: ==================== C:\Users\Les\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-19 00:20 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-05-2014 02 Ran by Les at 2014-05-28 01:39:29 Running from C:\Users\Les\Desktop\PopUp Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: AVG Internet Security 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AV: Microsoft Security Essentials (Disabled - Up to date) {3F839487-C7A2-C958-E30C-E2825BA31FB5} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG Internet Security 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} AS: Microsoft Security Essentials (Disabled - Up to date) {84E27563-E198-C6D6-D9BC-D9F020245508} FW: AVG Internet Security 2014 (Enabled) {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2} ==================== Installed Programs ====================== µTorrent (HKCU\...\uTorrent) (Version: 3.4.1.31139 - BitTorrent Inc.) µTorrent (HKLM-x32\...\uTorrent) (Version: 3.3.0.29462 - BitTorrent Inc.) AC3Filter 2.6.0b (HKLM-x32\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky) Acoustica CD/DVD Label Maker (HKLM-x32\...\Acoustica CD/DVD Label Maker) (Version: - ) Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.2 - Adobe Systems) Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 12.5.100.21219 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{5E03A267-415E-5383-FA8F-3CE4145663B9}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Fuel (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.71219.1540 - Advanced Micro Devices, Inc.) Hidden AMD Steady Video Plug-In (Version: 2.06.0000 - AMD) Hidden AMD VISION Engine Control Center (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden Ashampoo Burning Studio 12 v.12.0.1 (HKLM-x32\...\Ashampoo Burning Studio 12_is1) (Version: 12.0.1 - Ashampoo GmbH & Co. KG) AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4592 - AVG Technologies) AVG 2014 (Version: 14.0.3950 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4592 - AVG Technologies) Hidden Bass Audio Decoder (remove only) (HKLM-x32\...\Bass Audio Decoder) (Version: - ) Belkin Automatic Power Management Software (HKLM-x32\...\Belkin Automatic Power Management Software) (Version: 2.3.0.6 - ) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 3.28 - Piriform) CD Audio Reader Filter (remove only) (HKLM-x32\...\CD Audio Reader Filter) (Version: - ) CLICKBIOSII (HKLM-x32\...\{EBCB111F-4907-4B28-BD03-F5BD901106D2}_is1) (Version: 1.0.107 - MSI) Combined Community Codec Pack 2013-03-02 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2013.03.02.0 - CCCP Project) CPUID CPU-Z 1.63.0 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) CrystalDiskMark 3.0.2e (HKLM\...\CrystalDiskMark_is1) (Version: 3.0.2e - Crystal Dew World) DCoder Image Source (remove only) (HKLM-x32\...\DCoder Image Source) (Version: - ) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{349F73CA-653A-43A6-AE77-970B07D6EDA0}) (Version: - Microsoft) DivX 4.0 Final Codec (HKLM-x32\...\DivXCodec) (Version: - ) DScaler 5 Mpeg Decoders (HKLM-x32\...\DScaler 5 Mpeg Decoders_is1) (Version: - ) Easy Duplicate Finder v. 2.2.1 (HKLM-x32\...\Easy Duplicate Finder_is1) (Version: - EasyDuplicateFinder.com) EasyBCD 2.1 (HKLM-x32\...\EasyBCD) (Version: 2.1 - NeoSmart Technologies) EvilLyrics (HKLM-x32\...\EvilLyrics) (Version: - ) <==== ATTENTION Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.0.8 - MSI) ffdshow v1.2.4453 [2012-05-21] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4453.0 - ) FFMPEG Core Files (remove only) (HKLM-x32\...\FFMPEG Core Files) (Version: - ) Forté Agent (HKLM-x32\...\Forte Agent) (Version: 6.00 - Forté Internet Software, Inc.) Gabest MPEG Splitter (remove only) (HKLM-x32\...\Gabest MPEG Splitter) (Version: - ) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.35 - Irfan Skiljan) Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden LAV Filters 0.60.1 (HKLM-x32\...\lavfilters_is1) (Version: 0.60.1 - Hendrik Leppkes) Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) Logitech Harmony Remote Software 7 (x32 Version: 7.7.0.0 - Logitech) Hidden MadVR (remove only) (HKLM-x32\...\MadVR) (Version: - ) Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) MediaMonkey 4.0 (HKLM-x32\...\MediaMonkey_is1) (Version: 4.0 - Ventis Media Inc.) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation) Microsoft Mouse and Keyboard Center (Version: 2.3.188.0 - Microsoft Corporation) Hidden Microsoft Office Access MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Access Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.2.0223.1 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MiPony 2.1.1 (HKLM-x32\...\MiPony) (Version: 2.1.1 - ) Motorola SM56 Speakerphone Modem (HKLM\...\SMSERIAL) (Version: 6.12.25.06 - Motorola Inc) Mozilla Firefox 29.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 en-US)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MPC-HC 1.6.6.6957 (3975d54) (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.6.6.6957 - MPC-HC Team) OpenSource AVI Splitter (remove only) (HKLM-x32\...\OpenSource AVI Splitter) (Version: - ) OpenSource DTS/AC3/DD+ Source Filter (remove only) (HKLM-x32\...\OpenSource DTS/AC3/DD+ Source Filter) (Version: - ) OpenSource Flash Video Splitter (remove only) (HKLM-x32\...\OpenSource Flash Video Splitter) (Version: - ) Paragon Hard Disk Manager™ 11 Server (HKLM-x32\...\{AF58CE7A-B48F-4DDF-8FB7-838DDC22D63C}) (Version: 90.00.0003 - Paragon Software) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.53.216.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6782 - Realtek Semiconductor Corp.) Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) Revo Uninstaller Pro 3.0.5 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.0.5 - VS Revo Group, Ltd.) Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung) Sansa Updater (HKCU\...\Sansa Updater) (Version: 1.406 - SanDisk Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden SIW 2011 Home Edition (HKLM-x32\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2011.10.30 - Topala Software Solutions) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.014 - MSI) TuneUp Utilities 2014 (en-US) (x32 Version: 14.0.1000.88 - TuneUp Software) Hidden TuneUp Utilities 2014 (HKLM-x32\...\TuneUp Utilities 2014) (Version: 14.0.1000.88 - TuneUp Software) TuneUp Utilities 2014 (x32 Version: 14.0.1000.88 - TuneUp Software) Hidden TuneUp Utilities Language Pack (en-US) (x32 Version: 13.0.2020.14 - TuneUp Software) Hidden TVersity Codec Pack 1.7 (HKLM-x32\...\TVersity Codec Pack) (Version: 1.7 - TVersity Inc.) TVersity Media Server Pro 2.4 (HKLM-x32\...\TVersity Media Server Pro) (Version: 2.4 - TVersity) Ultra Video Joiner 6.3.0103 (HKLM-x32\...\Ultra Video Joiner_is1) (Version: - Aone Software) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{DCE104A1-1875-4469-A83D-A5BFA6C4640F}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{334AA0A1-2BB1-4D74-B66A-2B2C4D9C2C87}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VueScan (HKLM\...\VueScan) (Version: - ) WinDFT (HKLM-x32\...\{065F384A-5C64-4532-814A-A24BA5374503}) (Version: 1.0.0 - HGST) WinRAR 4.10 beta 2 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.10.2 - win.rar GmbH) WinZip 15.5 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240C2}) (Version: 15.5.9468 - WinZip Computing, S.L. ) Xilisoft Video Converter Ultimate 6 (HKLM-x32\...\Xilisoft Video Converter Ultimate 6) (Version: 6.8.0.1101 - Xilisoft) XviD Video Codec (remove only) (HKLM-x32\...\XviD Video Codec) (Version: - ) Zoom Player (remove only) (HKLM-x32\...\ZoomPlayer) (Version: - ) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-13 22:34 - 2013-09-03 17:19 - 00000833 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1746A278-1C7E-4708-811C-0AA9B191C769} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe [2013-08-29] (TuneUp Software) Task: {19C0E852-3997-48DD-A0E4-16B2EB8AC627} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-16] (Google Inc.) Task: {1B80D6B5-2231-4291-A25D-5E8E9027354C} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {26D59E2E-423D-481B-953D-AE59107F726F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-02-25] (Piriform Ltd) Task: {35DB3D34-B4C4-4DF3-9B73-004C3E9E460C} - System32\Tasks\DivX online update program => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2013-02-12] () Task: {4E1CB343-3127-404F-8A35-64A7487E3021} - System32\Tasks\0 => Iexplore.exe <==== ATTENTION Task: {59F155FD-F31F-41CB-B50E-762342510C11} - \Microsoft\Microsoft Antimalware\MpIdleTask No Task File <==== ATTENTION Task: {6826976B-DFFA-46F1-ACFA-E3FCBEFBB17C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {733AE50C-BE22-40BF-B25A-1AE1F259EAF6} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft) Task: {7F455179-CF41-40C5-80E6-B8A01874FE4A} - System32\Tasks\Sansa Dispatch => C:\Users\Les\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [2013-06-20] (SanDisk Corporation) Task: {88AD309C-8007-4AD3-9740-7A4A161BE8FE} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation) Task: {93632E7A-3CFD-4139-825A-7030AB5B8E8B} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation) Task: {A1D60D55-A6B8-401B-BC05-2938E02DF2F2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => d:\program files\windows defender\MpCmdRun.exe Task: {BE480E89-BA3E-40EE-8384-0965F88DBC6C} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03] (Adobe Systems Incorporated) Task: {C4E8B14A-4159-4C58-BDAD-281DBBFC97E8} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => d:\program files\windows defender\MpCmdRun.exe Task: {D6A61A8C-A109-4E5E-A54E-B8EC780E544F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-16] (Google Inc.) Task: {E1F32578-DDFC-45D5-891C-EA9124A91E72} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {F38CC064-C0BD-4A70-BCB1-E14880C749E5} - System32\Tasks\pcreg => C:\Program Files\pcreg\service.exe <==== ATTENTION Task: {FE810340-EF6D-4202-B127-6EFED12D30DF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2013-03-24 06:50 - 2011-10-30 11:24 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2014-05-25 03:28 - 2014-05-25 03:28 - 00249024 _____ () C:\Program Files\pcreg\pcreg.exe 2013-08-29 12:08 - 2013-08-29 12:08 - 00757048 _____ () C:\Program Files (x86)\TuneUp Utilities 2014\avgrepliba.dll 2013-03-13 15:13 - 2013-03-13 15:13 - 05283624 _____ () C:\ProgramData\TVersity\Media Server\MediaServer.exe 2013-03-15 05:40 - 2013-03-15 05:40 - 00045056 _____ () C:\Program Files (x86)\Belkin Automatic Power Management Software\jspWin.dll 2013-03-15 05:40 - 2013-03-15 05:40 - 00032768 _____ () C:\Program Files (x86)\Belkin Automatic Power Management Software\jusb.dll 2011-12-17 17:14 - 2011-12-17 17:14 - 00102184 _____ () C:\ProgramData\TVersity\Media Server\EasyHook32.dll 2013-03-05 23:02 - 2013-03-05 23:02 - 33073664 _____ () C:\ProgramData\TVersity\Media Server\berkelium.dll 2011-12-17 17:15 - 2011-12-17 17:15 - 00081704 _____ () C:\ProgramData\TVersity\Media Server\portaudio_x86.dll 2011-12-17 17:15 - 2011-12-17 17:15 - 00556840 _____ () C:\ProgramData\TVersity\Media Server\taglib.dll 2011-12-17 17:14 - 2011-12-17 17:14 - 00225064 _____ () C:\ProgramData\TVersity\Media Server\CORE_RL_lcms_.dll 2011-12-17 17:14 - 2011-12-17 17:14 - 00031528 _____ () C:\ProgramData\TVersity\Media Server\CORE_RL_xlib_.dll 2011-12-17 17:14 - 2011-12-17 17:14 - 00716584 _____ () C:\ProgramData\TVersity\Media Server\log4cxx.dll 2011-12-17 17:14 - 2011-12-17 17:14 - 04534072 _____ () C:\ProgramData\TVersity\Media Server\avcodec-52.dll 2011-12-17 17:14 - 2011-12-17 17:14 - 00083768 _____ () C:\ProgramData\TVersity\Media Server\avutil-50.dll 2011-12-17 17:14 - 2011-12-17 17:14 - 00313640 _____ () C:\ProgramData\TVersity\Media Server\libmp3lame-0.dll 2011-12-17 17:14 - 2011-12-17 17:14 - 00795448 _____ () C:\ProgramData\TVersity\Media Server\avformat-52.dll 2011-12-17 17:15 - 2011-12-17 17:15 - 00203064 _____ () C:\ProgramData\TVersity\Media Server\swscale-0.dll 2011-12-17 17:15 - 2011-12-17 17:15 - 00562072 _____ () C:\ProgramData\TVersity\Media Server\sqlite3.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\System32\TrayIcon12.dll 2013-03-05 23:02 - 2013-03-05 23:02 - 33073664 _____ () C:\ProgramData\TVersity\Media Server\berkelium\berkelium.dll 2013-03-05 23:02 - 2013-03-05 23:02 - 01305102 _____ () C:\ProgramData\TVersity\Media Server\berkelium\avcodec-52.dll 2013-03-05 23:02 - 2013-03-05 23:02 - 00096782 _____ () C:\ProgramData\TVersity\Media Server\berkelium\avutil-50.dll 2013-03-05 23:02 - 2013-03-05 23:02 - 00160782 _____ () C:\ProgramData\TVersity\Media Server\berkelium\avformat-52.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2010-10-20 15:45 - 2010-10-20 15:45 - 08801120 _____ () C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll 2014-05-09 19:23 - 2014-05-09 19:23 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\aticfx32.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\atiuxpag.dll 2014-05-24 10:19 - 2014-05-24 10:19 - 00000000 _____ () C:\Windows\system32\atidxx32.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: Futuremark SystemInfo Service => 3 MSCONFIG\Services: TuneUp.UtilitiesSvc => 2 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/28/2014 01:39:30 AM) (Source: VSS) (EventID: 12292) (User: ) Description: Volume Shadow Copy Service error: Error creating the Shadow Copy Provider COM class with CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. ]. Operation: Obtain a callable interface for this provider List interfaces for all providers supporting this context Query Shadow Copies Context: Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Class ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshot Context: 13 Snapshot Context: 13 Execution Context: Coordinator Error: (05/28/2014 01:39:30 AM) (Source: VSS) (EventID: 13) (User: ) Description: Volume Shadow Copy Service information: The COM Server with CLSID {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} and name SW_PROV cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. ] Operation: Obtain a callable interface for this provider List interfaces for all providers supporting this context Query Shadow Copies Context: Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Class ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshot Context: 13 Snapshot Context: 13 Execution Context: Coordinator Error: (05/28/2014 01:22:00 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/28/2014 01:21:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbamservice.exe, version: 3.0.2.0, time stamp: 0x5318d363 Faulting module name: mbamservice.exe, version: 3.0.2.0, time stamp: 0x5318d363 Exception code: 0x40000015 Fault offset: 0x0007da8a Faulting process id: 0x1170 Faulting application start time: 0xmbamservice.exe0 Faulting application path: mbamservice.exe1 Faulting module path: mbamservice.exe2 Report Id: mbamservice.exe3 System errors: ============= Microsoft Office Sessions: ========================= Error: (05/28/2014 01:39:30 AM) (Source: VSS) (EventID: 12292) (User: ) Description: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Operation: Obtain a callable interface for this provider List interfaces for all providers supporting this context Query Shadow Copies Context: Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Class ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshot Context: 13 Snapshot Context: 13 Execution Context: Coordinator Error: (05/28/2014 01:39:30 AM) (Source: VSS) (EventID: 13) (User: ) Description: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a}SW_PROV0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Operation: Obtain a callable interface for this provider List interfaces for all providers supporting this context Query Shadow Copies Context: Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} Class ID: {65ee1dba-8ff4-4a58-ac1c-3470ee2f376a} Snapshot Context: 13 Snapshot Context: 13 Execution Context: Coordinator Error: (05/28/2014 01:22:00 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/28/2014 01:21:14 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: mbamservice.exe3.0.2.05318d363mbamservice.exe3.0.2.05318d363400000150007da8a117001cf7a3498eb1533C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exee2e5981d-e627-11e3-afa8-d43d7e90d9e5 CodeIntegrity Errors: =================================== Date: 2013-03-24 16:02:51.251 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-03-24 16:02:51.236 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\AtihdW76.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-03-24 16:02:50.066 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\atikmpag.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-03-24 16:02:50.034 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\atikmpag.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Percentage of memory in use: 15% Total physical RAM: 15822.91 MB Available physical RAM: 13367.36 MB Total Pagefile: 79112.71 MB Available Pagefile: 76525.71 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (Patriot_Pyro_SE_240GB_Win7-64Pro) (Fixed) (Total:223.57 GB) (Free:166.47 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Toshiba_2TB_Misc_203GB) (Fixed) (Total:203.33 GB) (Free:177.15 GB) NTFS Drive e: (Seagate _2TB_Movies) (Fixed) (Total:1863.01 GB) (Free:816.01 GB) NTFS Drive f: (Toshiba_2TB_Data_1.7TB) (Fixed) (Total:1659.69 GB) (Free:593.55 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 224 GB) (Disk ID: 4D2652EF) Partition 1: (Active) - (Size=224 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 1E0C6B29) Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 77EA1D8F) Partition 1: (Not Active) - (Size=203 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=-416948500992) - (Type=07 NTFS) ==================== End Of Log ============================