Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-09-2014 Ran by Administrator (administrator) on NB200-NETBOOK on 05-09-2014 05:57:38 Running from C:\Users\Administrator\Desktop Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: English (United States) Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: http://www.geekstogo...very-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe () C:\ProgramData\MobileBrServ\mbbService.exe (TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe (TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\Utilities\KeNotify.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ThpSrv] => C:\Windows\system32\thpsrv /logon HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [184320 2009-03-29] (Alps Electric Co., Ltd.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7625248 2009-07-28] (Realtek Semiconductor) HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [476512 2009-08-21] (TOSHIBA Corporation) HKLM\...\Run: [smoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [460088 2009-07-28] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [738616 2009-08-05] (TOSHIBA Corporation) HKLM\...\Run: [KeNotify] => C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM\...\RunOnce: [1] => C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\mbam-chameleon.exe [750392 2014-05-12] (MalwareBytes) HKU\S-1-5-21-4096279028-3035823704-499056865-500\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4796696 2014-08-21] (Piriform Ltd) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab DPF: {CAFEEFAC-0017-0000-0067-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\i6olledz.default-1409856200851 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Windows\system32\npdeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazon-en-GB.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\chambers-en-GB.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-en-GB.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-en-GB.xml FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-23] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-02] FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-30] FF HKLM\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] - C:\Program Files\CheckPoint\ZAForceField\TrustChecker Chrome: ======= ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [233344 2012-06-28] () R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [251728 2010-12-08] (AVG Technologies CZ, s.r.o.) R0 LPCFilter; C:\Windows\System32\DRIVERS\LPCFilter.sys [25896 2008-05-07] (COMPAL ELECTRONIC INC.) R4 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [74456 2014-09-05] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-09-05] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation) S3 icsak; \??\C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-05 05:57 - 2014-09-05 05:59 - 00010737 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-09-05 05:57 - 2014-09-05 05:58 - 00000000 ____D () C:\FRST 2014-09-05 05:52 - 2014-09-05 05:53 - 01096704 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe 2014-09-05 03:14 - 2014-09-05 03:14 - 00025010 _____ () C:\Users\Administrator\Documents\cc_20140905_031401.reg 2014-09-05 02:22 - 2014-09-05 02:22 - 00000000 __RHD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC 2014-09-05 02:22 - 2014-09-05 02:22 - 00000000 ____D () C:\Program Files\Windows Journal 2014-09-04 22:21 - 2014-09-04 22:21 - 00000000 ____D () C:\Program Files\ReviverSoft 2014-09-04 04:08 - 2014-09-04 04:11 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Games 2014-09-04 02:14 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-09-04 02:14 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-09-04 02:14 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-09-04 02:14 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-09-04 02:14 - 2014-07-09 02:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-09-04 02:14 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-09-03 21:17 - 2014-09-03 21:17 - 00000578 _____ () C:\Users\Administrator\Documents\cc_20140903_211741.reg 2014-09-03 21:10 - 2014-09-03 21:10 - 00000020 ___SH () C:\Users\Classic .NET AppPool\ntuser.ini 2014-09-03 21:10 - 2014-09-03 21:10 - 00000000 ____D () C:\Users\Classic .NET AppPool 2014-09-03 21:10 - 2010-03-30 10:40 - 00000000 ____D () C:\Users\Classic .NET AppPool\AppData\Roaming\Macromedia 2014-09-03 21:10 - 2010-03-14 23:55 - 00000000 ____D () C:\Users\Classic .NET AppPool\AppData\Local\Microsoft Help 2014-09-03 21:10 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-09-03 21:10 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-09-03 21:06 - 2014-09-05 02:27 - 00194019 _____ () C:\Windows\iis7.log 2014-09-03 21:05 - 2014-09-05 02:22 - 00000000 ____D () C:\Program Files\Microsoft Games 2014-09-03 21:05 - 2014-09-05 02:22 - 00000000 ____D () C:\inetpub 2014-09-03 20:49 - 2014-09-03 20:50 - 00195578 _____ () C:\Users\Administrator\Documents\cc_20140903_204927.reg 2014-09-03 20:47 - 2014-09-03 20:56 - 24758792 _____ (Microsoft Corporation) C:\Users\Administrator\Downloads\NetFx20SP1_x86.exe 2014-09-03 20:47 - 2014-09-03 20:48 - 00000000 ____D () C:\Program Files\CCleaner 2014-09-03 20:47 - 2014-09-03 20:47 - 00000972 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-09-03 20:47 - 2014-09-03 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-09-03 20:41 - 2014-09-03 20:45 - 04902336 _____ (Piriform Ltd) C:\Users\Administrator\Downloads\ccsetup417pro.exe 2014-09-01 02:50 - 2014-09-01 02:51 - 00000000 ____D () C:\ProgramData\MobileBrServ 2014-09-01 02:08 - 2014-09-01 02:08 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\EPSON 2014-09-01 02:03 - 2007-04-10 01:06 - 00008192 _____ (SEIKO EPSON CORP.) C:\Windows\system32\E_DCINST.DLL 2014-09-01 02:02 - 2008-11-12 03:00 - 00093696 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_FLBFIE.DLL 2014-09-01 02:02 - 2008-11-12 03:00 - 00079360 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_FD4BFIE.DLL 2014-09-01 02:01 - 2014-09-01 02:15 - 00000000 ____D () C:\ProgramData\EPSON 2014-09-01 01:59 - 2014-09-01 02:00 - 15802368 _____ () C:\Users\Administrator\Downloads\epson325334eu.exe 2014-09-01 01:43 - 2014-09-01 02:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2014-09-01 01:43 - 2014-09-01 01:43 - 00000937 _____ () C:\Users\Public\Desktop\EPSON Scan.lnk 2014-09-01 01:43 - 2014-09-01 01:43 - 00000000 ____D () C:\Program Files\epson 2014-09-01 01:43 - 2009-05-01 00:00 - 00128392 _____ (Seiko Epson Corporation) C:\Windows\system32\esdevapp.exe 2014-09-01 01:43 - 2009-05-01 00:00 - 00015872 _____ (SEIKO EPSON CORP.) C:\Windows\system32\escdev.dll 2014-09-01 01:43 - 2008-11-17 00:00 - 00342016 _____ (Seiko Epson Corporation) C:\Windows\system32\eswiaud.dll 2014-09-01 01:36 - 2014-09-01 01:37 - 12873216 _____ () C:\Users\Administrator\Downloads\epson324758eu.exe 2014-08-31 05:11 - 2014-08-31 05:11 - 00000000 ____D () C:\Program Files\Application Compatibility Toolkit 2014-08-31 04:08 - 2013-04-10 00:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2014-08-30 00:48 - 2014-08-30 00:37 - 00880040 _____ (Oracle Corporation) C:\Windows\system32\npdeployJava1.dll 2014-08-30 00:48 - 2014-08-30 00:37 - 00802728 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2014-08-30 00:38 - 2014-08-30 00:37 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-08-30 00:37 - 2014-08-30 00:37 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-08-30 00:37 - 2014-08-30 00:37 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-08-30 00:37 - 2014-08-30 00:37 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-08-30 00:37 - 2014-08-30 00:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-08-30 00:21 - 2014-08-30 00:22 - 00918952 _____ (Oracle Corporation) C:\Users\Administrator\Downloads\jxpiinstall.exe 2014-08-29 23:58 - 2014-08-29 23:59 - 00244136 _____ () C:\Users\Administrator\Downloads\Firefox Setup Stub 31.0(1).exe 2014-08-29 07:24 - 2014-08-23 02:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-29 07:24 - 2014-08-23 01:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-28 19:21 - 2014-08-28 19:21 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Oracle 2014-08-28 18:37 - 2014-08-28 18:37 - 00000000 ____D () C:\Windows\Sun 2014-08-28 17:29 - 2014-08-30 00:38 - 00000000 ____D () C:\ProgramData\Oracle 2014-08-28 17:27 - 2014-08-28 17:27 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-08-28 16:43 - 2014-05-14 17:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-08-28 16:43 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-08-28 16:43 - 2014-05-14 17:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-08-28 16:43 - 2014-05-14 17:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2014-08-28 16:43 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2014-08-28 16:43 - 2014-05-14 17:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-08-28 16:43 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-08-28 16:42 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-08-28 16:42 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-08-28 16:40 - 2014-09-05 04:53 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-28 16:39 - 2014-08-28 16:39 - 00001067 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-08-28 16:39 - 2014-08-28 16:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-08-28 16:38 - 2014-09-05 04:50 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-28 16:38 - 2014-08-29 07:10 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-08-28 16:38 - 2014-08-28 16:38 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 16:38 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-28 16:38 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-28 16:26 - 2014-08-28 16:38 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-28 16:24 - 2014-08-28 16:24 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Macromedia 2014-08-28 16:16 - 2014-08-29 23:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla 2014-08-28 16:16 - 2014-08-28 16:17 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla 2014-08-26 10:36 - 2014-07-25 13:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-26 10:36 - 2014-07-25 13:10 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-26 10:36 - 2014-07-25 12:59 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-26 10:36 - 2014-07-25 12:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-26 10:35 - 2014-08-01 00:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-26 10:35 - 2014-07-25 14:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-26 10:35 - 2014-07-25 14:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-26 10:35 - 2014-07-25 14:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-26 10:35 - 2014-07-25 13:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-26 10:35 - 2014-07-25 13:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-26 10:35 - 2014-07-25 13:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-26 10:35 - 2014-07-25 13:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-26 10:35 - 2014-07-25 13:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-26 10:35 - 2014-07-25 13:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-26 10:35 - 2014-07-25 13:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-26 10:35 - 2014-07-25 13:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-26 10:35 - 2014-07-25 13:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-26 10:35 - 2014-07-25 13:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-26 10:35 - 2014-07-25 12:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-26 10:35 - 2014-07-25 12:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-26 10:35 - 2014-07-25 12:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-26 10:35 - 2014-07-25 12:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-26 10:35 - 2014-07-25 12:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-26 10:35 - 2014-07-25 12:09 - 00663040 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-26 10:35 - 2014-07-25 12:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-26 10:35 - 2014-07-25 12:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-26 10:35 - 2014-07-25 12:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-26 10:35 - 2014-07-25 11:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-26 10:35 - 2014-07-25 11:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-26 10:35 - 2014-07-25 11:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-26 10:34 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-08-26 10:34 - 2014-01-09 03:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-08-26 10:34 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-08-26 10:34 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-08-26 10:34 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-08-26 10:22 - 2014-08-26 10:22 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\toshiba 2014-08-18 13:27 - 2014-08-18 13:27 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieUserList 2014-08-18 13:27 - 2014-08-18 13:27 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieSiteList 2014-08-18 12:37 - 2013-10-02 01:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-08-18 12:37 - 2013-10-02 01:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-08-18 12:37 - 2013-10-02 01:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-08-18 12:37 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-08-18 12:37 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-08-18 12:37 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-08-18 12:37 - 2013-10-02 00:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-08-18 12:37 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-08-18 12:37 - 2013-10-02 00:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-08-18 12:37 - 2013-10-01 23:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-08-18 12:37 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-08-18 12:33 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-08-18 09:58 - 2014-08-18 09:58 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-08-18 09:28 - 2014-08-18 09:28 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-08-18 09:28 - 2014-08-18 09:28 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-08-18 09:28 - 2014-08-18 09:28 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-08-18 09:28 - 2014-08-18 09:28 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-08-18 09:25 - 2014-08-18 09:25 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-08-18 09:17 - 2014-08-18 09:32 - 00009908 _____ () C:\Windows\IE11_main.log 2014-08-18 08:54 - 2014-08-18 08:54 - 00109280 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-08-18 08:53 - 2014-08-18 08:53 - 00001415 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-08-18 08:52 - 2014-08-29 07:10 - 00000000 ____D () C:\Users\Administrator 2014-08-18 08:52 - 2014-08-18 08:52 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-08-18 08:52 - 2010-03-30 10:40 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-08-18 08:52 - 2010-03-14 23:55 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Help 2014-08-18 08:52 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-08-18 08:52 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-08-18 08:42 - 2014-08-31 03:19 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-08-18 08:42 - 2014-08-18 08:42 - 00000000 ____D () C:\ProgramData\Mozilla 2014-08-18 06:21 - 2014-08-18 06:21 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-18 05:33 - 2014-08-18 05:39 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-18 04:46 - 2014-08-18 04:46 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-08-18 04:07 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-18 04:07 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-18 04:06 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-18 04:06 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-18 03:44 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-08-18 03:44 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-08-18 01:47 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2014-08-18 01:47 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2014-08-18 01:47 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2014-08-18 01:47 - 2013-07-03 05:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2014-08-18 01:47 - 2013-07-03 04:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2014-08-18 01:47 - 2013-07-03 04:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2014-08-18 01:46 - 2014-07-14 02:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-18 01:46 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-08-18 01:46 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2014-08-18 01:46 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2014-08-18 01:45 - 2014-06-16 02:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-18 01:45 - 2014-06-16 02:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2014-08-18 01:45 - 2014-06-16 02:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2014-08-18 01:45 - 2014-03-04 10:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2014-08-18 01:45 - 2014-03-04 10:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-08-18 01:45 - 2014-03-04 10:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-08-18 01:45 - 2014-03-04 10:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-08-18 01:45 - 2014-03-04 10:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-08-18 01:45 - 2014-03-04 10:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-08-18 01:45 - 2014-03-04 10:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-08-18 01:45 - 2014-03-04 10:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-08-18 01:45 - 2014-03-04 10:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-08-18 01:45 - 2014-03-04 10:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-08-18 01:45 - 2014-03-04 10:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-08-18 01:45 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2014-08-18 01:44 - 2014-03-26 15:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-08-18 01:44 - 2014-03-26 15:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-08-18 01:44 - 2014-03-26 15:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-08-18 01:44 - 2014-03-26 15:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-08-18 01:44 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-08-18 01:44 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2014-08-18 01:44 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2014-08-18 01:44 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2014-08-18 01:44 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2014-08-18 01:44 - 2013-08-29 02:50 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-08-18 01:44 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2014-08-18 01:44 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2014-08-18 01:44 - 2013-08-28 01:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-08-18 01:44 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-08-18 01:44 - 2013-06-06 05:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2014-08-18 01:44 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2014-08-18 01:44 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2014-08-18 01:44 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2014-08-18 01:44 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2014-08-18 01:43 - 2014-07-16 03:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-18 01:43 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-08-18 01:43 - 2014-02-04 03:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-08-18 01:43 - 2014-02-04 03:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-08-18 01:43 - 2014-02-04 03:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-08-18 01:43 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-08-18 01:42 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-08-18 01:42 - 2014-06-03 10:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-18 01:42 - 2014-06-03 10:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-18 01:42 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-18 01:42 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-18 01:42 - 2014-05-30 07:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-08-18 01:42 - 2014-04-05 03:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-08-18 01:42 - 2014-04-05 03:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-08-18 01:42 - 2014-01-24 03:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-08-18 01:42 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-08-18 01:42 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2014-08-18 01:42 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2014-08-18 01:42 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2014-08-18 01:42 - 2013-04-26 00:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2014-08-18 01:41 - 2014-05-30 08:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-08-18 01:41 - 2014-05-30 08:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-08-18 01:41 - 2014-05-30 08:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-08-18 01:41 - 2014-05-30 08:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-08-18 01:41 - 2014-05-30 08:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-08-18 01:41 - 2014-05-30 08:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-08-18 01:41 - 2014-05-30 08:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-08-18 01:40 - 2014-08-07 02:43 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-18 01:40 - 2014-08-07 02:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-18 01:40 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2014-08-18 01:40 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2014-08-18 01:40 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2014-08-18 01:40 - 2013-08-05 02:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2014-08-18 01:40 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2014-08-18 01:40 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-08-18 01:40 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-08-18 01:40 - 2013-07-04 10:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2014-08-18 01:39 - 2014-03-04 10:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-08-18 01:39 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-08-18 01:39 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2014-08-18 01:39 - 2013-08-02 02:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 01:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2014-08-18 01:39 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2014-08-18 01:39 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2014-08-18 01:39 - 2013-07-12 11:08 - 00146816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2014-08-18 01:39 - 2013-07-12 11:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2014-08-18 01:39 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2014-08-18 01:39 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2014-08-18 01:33 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-18 01:33 - 2014-05-08 10:06 - 02742784 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-08-18 01:33 - 2014-05-08 10:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-08-18 01:33 - 2014-04-25 03:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-08-18 01:33 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-08-18 01:33 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-08-18 01:33 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-08-18 01:33 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-08-18 01:33 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-08-18 01:33 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-08-18 01:33 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-08-18 01:33 - 2013-06-25 23:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2014-08-18 01:32 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-08-18 01:32 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-08-18 01:32 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-08-18 01:32 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-08-18 01:32 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-08-18 01:32 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-08-18 01:32 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-08-18 01:32 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-08-18 01:32 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-08-18 01:32 - 2013-06-15 04:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-08-18 01:22 - 2014-06-05 15:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-08-18 01:22 - 2014-04-12 03:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-08-18 01:22 - 2014-04-12 03:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-08-18 01:22 - 2014-04-12 03:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-08-18 01:22 - 2014-04-12 03:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-08-18 01:22 - 2014-04-12 03:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-08-18 01:22 - 2014-04-12 03:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-08-18 01:22 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2014-08-18 01:21 - 2013-02-12 04:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023x.sys 2014-08-18 01:21 - 2013-02-12 04:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys 2014-08-18 01:16 - 2013-05-10 04:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2014-08-18 01:16 - 2013-01-24 05:47 - 00196328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2014-08-17 20:26 - 2014-08-17 20:28 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-08-17 20:26 - 2014-08-17 20:26 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-08-17 15:47 - 2013-05-13 04:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2014-08-17 15:47 - 2013-05-13 04:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2014-08-17 15:47 - 2013-04-26 05:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2014-08-17 15:47 - 2013-03-19 04:33 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2014-08-17 15:19 - 2013-03-19 05:48 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2014-08-17 15:19 - 2013-03-19 03:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2014-08-17 14:49 - 2013-02-27 05:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-05 05:59 - 2014-09-05 05:57 - 00010737 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-09-05 05:58 - 2014-09-05 05:57 - 00000000 ____D () C:\FRST 2014-09-05 05:53 - 2014-09-05 05:52 - 01096704 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe 2014-09-05 05:32 - 2012-05-06 09:56 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-05 04:53 - 2014-08-28 16:40 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-05 04:50 - 2014-08-28 16:38 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-09-05 04:28 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-09-05 03:27 - 2010-03-14 17:15 - 01282834 _____ () C:\Windows\WindowsUpdate.log 2014-09-05 03:14 - 2014-09-05 03:14 - 00025010 _____ () C:\Users\Administrator\Documents\cc_20140905_031401.reg 2014-09-05 02:32 - 2009-07-14 05:34 - 00028176 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-05 02:32 - 2009-07-14 05:34 - 00028176 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-05 02:27 - 2014-09-03 21:06 - 00194019 _____ () C:\Windows\iis7.log 2014-09-05 02:27 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\inetsrv 2014-09-05 02:27 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\registration 2014-09-05 02:25 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-05 02:25 - 2009-07-14 05:39 - 00068138 _____ () C:\Windows\setupact.log 2014-09-05 02:22 - 2014-09-05 02:22 - 00000000 __RHD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC 2014-09-05 02:22 - 2014-09-05 02:22 - 00000000 ____D () C:\Program Files\Windows Journal 2014-09-05 02:22 - 2014-09-03 21:05 - 00000000 ____D () C:\Program Files\Microsoft Games 2014-09-05 02:22 - 2014-09-03 21:05 - 00000000 ____D () C:\inetpub 2014-09-05 02:22 - 2009-07-14 08:50 - 00000000 ____D () C:\Windows\ShellNew 2014-09-05 02:22 - 2009-07-14 05:56 - 00000000 ____D () C:\Windows\system32\0409 2014-09-05 02:22 - 2009-07-14 05:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-09-05 02:22 - 2009-07-14 05:52 - 00000000 ____D () C:\Program Files\DVD Maker 2014-09-05 02:22 - 2009-07-14 03:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-09-04 22:21 - 2014-09-04 22:21 - 00000000 ____D () C:\Program Files\ReviverSoft 2014-09-04 16:35 - 2009-07-14 05:33 - 00405992 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-09-04 04:11 - 2014-09-04 04:08 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Microsoft Games 2014-09-04 04:07 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF 2014-09-03 21:17 - 2014-09-03 21:17 - 00000578 _____ () C:\Users\Administrator\Documents\cc_20140903_211741.reg 2014-09-03 21:10 - 2014-09-03 21:10 - 00000020 ___SH () C:\Users\Classic .NET AppPool\ntuser.ini 2014-09-03 21:10 - 2014-09-03 21:10 - 00000000 ____D () C:\Users\Classic .NET AppPool 2014-09-03 21:09 - 2010-03-14 10:37 - 00847030 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-03 20:56 - 2014-09-03 20:47 - 24758792 _____ (Microsoft Corporation) C:\Users\Administrator\Downloads\NetFx20SP1_x86.exe 2014-09-03 20:50 - 2014-09-03 20:49 - 00195578 _____ () C:\Users\Administrator\Documents\cc_20140903_204927.reg 2014-09-03 20:48 - 2014-09-03 20:47 - 00000000 ____D () C:\Program Files\CCleaner 2014-09-03 20:47 - 2014-09-03 20:47 - 00000972 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-09-03 20:47 - 2014-09-03 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-09-03 20:45 - 2014-09-03 20:41 - 04902336 _____ (Piriform Ltd) C:\Users\Administrator\Downloads\ccsetup417pro.exe 2014-09-03 20:28 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-09-02 16:07 - 2010-03-14 11:35 - 00000000 ____D () C:\Windows\Minidump 2014-09-01 02:51 - 2014-09-01 02:50 - 00000000 ____D () C:\ProgramData\MobileBrServ 2014-09-01 02:15 - 2014-09-01 02:01 - 00000000 ____D () C:\ProgramData\EPSON 2014-09-01 02:15 - 2014-09-01 01:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON 2014-09-01 02:08 - 2014-09-01 02:08 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\EPSON 2014-09-01 02:00 - 2014-09-01 01:59 - 15802368 _____ () C:\Users\Administrator\Downloads\epson325334eu.exe 2014-09-01 01:43 - 2014-09-01 01:43 - 00000937 _____ () C:\Users\Public\Desktop\EPSON Scan.lnk 2014-09-01 01:43 - 2014-09-01 01:43 - 00000000 ____D () C:\Program Files\epson 2014-09-01 01:43 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\twain_32 2014-09-01 01:37 - 2014-09-01 01:36 - 12873216 _____ () C:\Users\Administrator\Downloads\epson324758eu.exe 2014-08-31 10:58 - 2010-03-14 11:39 - 00159734 _____ () C:\Windows\PFRO.log 2014-08-31 05:11 - 2014-08-31 05:11 - 00000000 ____D () C:\Program Files\Application Compatibility Toolkit 2014-08-31 03:19 - 2014-08-18 08:42 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-08-31 03:19 - 2010-03-14 23:23 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-08-30 00:48 - 2010-03-16 15:04 - 00000000 ____D () C:\Program Files\Java 2014-08-30 00:38 - 2014-08-28 17:29 - 00000000 ____D () C:\ProgramData\Oracle 2014-08-30 00:37 - 2014-08-30 00:48 - 00880040 _____ (Oracle Corporation) C:\Windows\system32\npdeployJava1.dll 2014-08-30 00:37 - 2014-08-30 00:48 - 00802728 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2014-08-30 00:37 - 2014-08-30 00:38 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-08-30 00:37 - 2014-08-30 00:37 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-08-30 00:37 - 2014-08-30 00:37 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-08-30 00:37 - 2014-08-30 00:37 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2014-08-30 00:37 - 2014-08-30 00:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-08-30 00:22 - 2014-08-30 00:21 - 00918952 _____ (Oracle Corporation) C:\Users\Administrator\Downloads\jxpiinstall.exe 2014-08-30 00:17 - 2011-05-14 06:46 - 00001124 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-08-30 00:17 - 2010-03-14 23:24 - 00001112 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-08-29 23:59 - 2014-08-29 23:58 - 00244136 _____ () C:\Users\Administrator\Downloads\Firefox Setup Stub 31.0(1).exe 2014-08-29 23:58 - 2014-08-28 16:16 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla 2014-08-29 07:10 - 2014-08-28 16:38 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware 2014-08-29 07:10 - 2014-08-18 08:52 - 00000000 ____D () C:\Users\Administrator 2014-08-29 07:10 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\wfp 2014-08-29 07:08 - 2009-07-14 08:49 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-08-29 07:08 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries 2014-08-28 19:21 - 2014-08-28 19:21 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Oracle 2014-08-28 18:37 - 2014-08-28 18:37 - 00000000 ____D () C:\Windows\Sun 2014-08-28 17:27 - 2014-08-28 17:27 - 00000000 ____D () C:\Program Files\Common Files\Java 2014-08-28 16:39 - 2014-08-28 16:39 - 00001067 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2014-08-28 16:39 - 2014-08-28 16:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2014-08-28 16:38 - 2014-08-28 16:38 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-28 16:38 - 2014-08-28 16:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-28 16:24 - 2014-08-28 16:24 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Macromedia 2014-08-28 16:17 - 2014-08-28 16:16 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla 2014-08-26 10:22 - 2014-08-26 10:22 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\toshiba 2014-08-23 02:46 - 2014-08-29 07:24 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-23 01:42 - 2014-08-29 07:24 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-18 13:27 - 2014-08-18 13:27 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieUserList 2014-08-18 13:27 - 2014-08-18 13:27 - 00000000 __SHD () C:\Users\Administrator\AppData\Local\EmieSiteList 2014-08-18 09:58 - 2014-08-18 09:58 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-TW 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-HK 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-CN 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\tr-TR 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\sv-SE 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ru-RU 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pt-PT 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pt-BR 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pl-PL 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\nl-NL 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\nb-NO 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ko-KR 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ja-JP 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\it-IT 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\hu-HU 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\fr-FR 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\fi-FI 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\el-GR 2014-08-18 09:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-08-18 09:32 - 2014-08-18 09:17 - 00009908 _____ () C:\Windows\IE11_main.log 2014-08-18 09:28 - 2014-08-18 09:28 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-08-18 09:28 - 2014-08-18 09:28 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-08-18 09:28 - 2014-08-18 09:28 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-08-18 09:28 - 2014-08-18 09:28 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-08-18 09:28 - 2014-08-18 09:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-08-18 09:28 - 2014-08-18 09:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-08-18 09:25 - 2014-08-18 09:25 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-08-18 09:25 - 2014-08-18 09:25 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-08-18 08:55 - 2010-06-27 19:51 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-08-18 08:54 - 2014-08-18 08:54 - 00109280 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-08-18 08:53 - 2014-08-18 08:53 - 00001415 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-08-18 08:53 - 2009-07-14 05:46 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2014-08-18 08:52 - 2014-08-18 08:52 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-08-18 08:42 - 2014-08-18 08:42 - 00000000 ____D () C:\ProgramData\Mozilla 2014-08-18 08:19 - 2010-03-15 08:23 - 00000000 ____D () C:\ProgramData\Skype 2014-08-18 06:25 - 2010-10-24 22:43 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-18 06:21 - 2014-08-18 06:21 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-18 05:47 - 2010-03-14 11:57 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-18 05:39 - 2014-08-18 05:33 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-18 04:46 - 2014-08-18 04:46 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER 2014-08-18 03:58 - 2010-10-24 22:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-17 20:28 - 2014-08-17 20:26 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-08-17 20:26 - 2014-08-17 20:26 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-08-17 20:26 - 2010-03-30 10:40 - 00000000 ____D () C:\ProgramData\Adobe 2014-08-17 20:26 - 2010-03-30 10:40 - 00000000 ____D () C:\Program Files\Adobe 2014-08-17 18:18 - 2010-11-01 20:50 - 00000000 ____D () C:\ProgramData\MFAData 2014-08-17 17:38 - 2012-05-06 09:56 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-08-17 17:38 - 2011-05-18 20:58 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-08-17 17:09 - 2012-04-27 09:38 - 00002119 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2014-08-17 17:09 - 2011-01-24 22:37 - 00001945 _____ () C:\Windows\epplauncher.mif 2014-08-17 17:07 - 2011-01-24 22:30 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-08-17 16:49 - 2009-07-14 05:52 - 00000000 ____D () C:\Program Files\Windows Defender 2014-08-07 02:43 - 2014-08-18 01:40 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 02:39 - 2014-08-18 01:40 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-29 08:18 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-09-2014 Ran by Administrator at 2014-09-05 06:00:46 Running from C:\Users\Administrator\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Update for Microsoft Office 2007 (KB2508958) (HKLM\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) Acrobat.com (HKLM\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated) Acrobat.com (Version: 2.0.0 - Adobe Systems Incorporated) Hidden Adobe AIR (HKLM\...\Adobe AIR) (Version: 2.0.4.13090 - Adobe Systems Inc.) Adobe AIR (Version: 2.0.4.13090 - Adobe Systems Inc.) Hidden Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.45.2 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM\...\Adobe Shockwave Player) (Version: 11.5.6.606 - Adobe Systems, Inc.) ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.2.302.105 - ALPS ELECTRIC CO., LTD.) Application Compatibility Toolkit (HKLM\...\{B4CF72FF-4A3F-44A7-BFF2-31A8E1CC70B6}) (Version: 20.00.0713 - Microsoft Corporation) CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden EPSON Scan (HKLM\...\EPSON Scanner) (Version: - ) EPSON SX510W Series Printer Uninstall (HKLM\...\EPSON SX510W Series) (Version: - SEIKO EPSON Corporation) Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation) Java 7 Update 67 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle) Java Auto Updater (Version: 2.1.67.1 - Oracle, Inc.) Hidden Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Standard 2007 (HKLM\...\STANDARDR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Standard 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mobile Broadband HL Service (HKLM\...\Mobile Broadband HL Service) (Version: 22.001.16.00.03 - Huawei Technologies Co.,Ltd) Mozilla Firefox 31.0 (x86 en-GB) (HKLM\...\Mozilla Firefox 31.0 (x86 en-GB)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0 - Microsoft Corporation) Hidden Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5904 - Realtek Semiconductor Corp.) TOSHIBA Flash Cards Support Utility (HKLM\...\InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}) (Version: 1.63.0.3C - TOSHIBA CORPORATION) TOSHIBA Flash Cards Support Utility (Version: 1.63.0.3C - TOSHIBA CORPORATION) Hidden TOSHIBA HDD Protection (HKLM\...\{94A90C69-71C1-470A-88F5-AA47ECC96B40}) (Version: 2.2.0.1 - TOSHIBA Corporation) TOSHIBA Value Added Package (HKLM\...\InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}) (Version: 1.2.28 - TOSHIBA Corporation) TOSHIBA Value Added Package (Version: 1.2.28 - TOSHIBA Corporation) Hidden Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2883097) 32-Bit Edition (HKLM\...\{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{B2260BC9-D561-46EE-B33D-739CF760A2A9}) (Version: - Microsoft) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version: - Microsoft) Update for Microsoft Office Script Editor Help (KB963671) (HKLM\...\{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version: - Microsoft) Update for Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version: - Microsoft) Utility Common Driver (Version: 1.0.50.22C - TOSHIBA) Hidden Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0AFF1EF8-FB46-4257-9D95-10999D8172E3} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {5CA478E6-2430-4D6B-8FE9-2A5A36DB1AE5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd) Task: {9558954F-AD45-457C-B5D7-D4D3E37719DC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-17] (Adobe Systems Incorporated) Task: {E50036FA-55AD-4CC6-A936-413F2F6C5D2E} - System32\Tasks\{200B3F4B-B7A1-4993-9C60-76160A7EC81E} => C:\Program Files\Skype\Phone\Skype.exe Task: {FBBDB636-29EF-4C96-A4B3-823727108E56} - System32\Tasks\{B6755252-56BA-4F4E-84A0-178F47513089} => Firefox.exe http://ui.skype.com/...all?page=tsMain (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-09-01 02:51 - 2012-06-28 07:19 - 00233344 _____ () C:\ProgramData\MobileBrServ\mbbservice.exe 2009-07-16 16:27 - 2009-07-16 16:27 - 07263544 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll 2009-07-16 16:27 - 2009-07-16 16:27 - 00052536 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll 2009-03-12 20:08 - 2009-03-12 20:08 - 00049152 _____ () C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll 2014-04-14 20:41 - 2014-04-14 20:41 - 00039192 _____ () C:\Program Files\CCleaner\branding.dll 2014-08-30 00:15 - 2014-07-17 06:42 - 03800688 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4 ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ==================== Faulty Device Manager Devices ============= Name: Microsoft Teredo Tunneling Adapter Description: Microsoft Teredo Tunneling Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (09/04/2014 02:15:24 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image of service AVG Security Toolbar Service since QueryServiceConfig API failed System Error: The system cannot find the file specified. . Error: (09/03/2014 09:03:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image of service AVG Security Toolbar Service since QueryServiceConfig API failed System Error: The system cannot find the file specified. . Error: (09/03/2014 07:10:29 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program firefox.exe version 31.0.0.5310 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 94c Start Time: 01cfc6c9ea7bc057 Termination Time: 3704 Application Path: C:\Program Files\Mozilla Firefox\firefox.exe Report Id: ac721001-3330-11e4-af6e-582c80139263 Error: (09/01/2014 02:48:38 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: mbbservice.exe, version: 22.16.0.3, time stamp: 0x4febf55e Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea91c Exception code: 0xc0000005 Fault offset: 0x00028109 Faulting process id: 0x7e0 Faulting application start time: 0xmbbservice.exe0 Faulting application path: mbbservice.exe1 Faulting module path: mbbservice.exe2 Report Id: mbbservice.exe3 Error: (08/31/2014 09:17:28 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: plugin-container.exe, version: 31.0.0.5310, time stamp: 0x53c75e91 Faulting module name: NPSWF32_14_0_0_145.dll, version: 14.0.0.145, time stamp: 0x53aa1b9a Exception code: 0x80000003 Fault offset: 0x0035128d Faulting process id: 0x1628 Faulting application start time: 0xplugin-container.exe0 Faulting application path: plugin-container.exe1 Faulting module path: plugin-container.exe2 Report Id: plugin-container.exe3 Error: (08/31/2014 07:00:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: appverif.exe, version: 2.2.0.0, time stamp: 0x3b4fa576 Faulting module name: apihex86.dll_unloaded, version: 0.0.0.0, time stamp: 0x4a5bd9b3 Exception code: 0xc0000005 Fault offset: 0x72463eda Faulting process id: 0x126c Faulting application start time: 0xappverif.exe0 Faulting application path: appverif.exe1 Faulting module path: appverif.exe2 Report Id: appverif.exe3 Error: (08/31/2014 05:03:36 AM) (Source: MsiInstaller) (EventID: 10005) (User: NB200-NETBOOK) Description: Product: Application Compatibility Toolkit -- This release of the Application Compatibility Toolkit is intended for Microsoft Windows® XP. Error: (08/26/2014 10:19:13 AM) (Source: System Restore) (EventID: 8211) (User: ) Description: The scheduled restore point could not be created. Additional information: (0x81000101). Error: (08/26/2014 10:19:13 AM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Description = Scheduled Checkpoint; Error = 0x81000101). Error: (08/18/2014 08:55:40 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1533) (User: NB200-NETBOOK) Description: Windows cannot delete the profile directory C:\Users\Georgia. This error may be caused by files in this directory being used by another program. DETAIL - The directory is not empty. System errors: ============= Error: (09/05/2014 02:25:31 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (09/05/2014 02:25:02 AM) (Source: volsnap) (EventID: 25) (User: ) Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied. Error: (09/05/2014 02:23:21 AM) (Source: FTPSVC) (EventID: 30) (User: ) Description: 15redirection.config0 Error: (09/04/2014 08:20:31 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.183.1505.0 Update Source: %NT AUTHORITY59 Update Stage: 4.5.0216.00 Source Path: 4.5.0216.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (09/04/2014 08:20:31 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.183.1505.0 Update Source: %NT AUTHORITY59 Update Stage: 4.5.0216.00 Source Path: 4.5.0216.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (09/04/2014 07:53:39 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (09/04/2014 07:52:55 PM) (Source: volsnap) (EventID: 25) (User: ) Description: The shadow copies of volume C: were deleted because the shadow copy storage could not grow in time. Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied. Error: (09/04/2014 04:38:14 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80070420 Error: (09/04/2014 04:35:47 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (09/04/2014 02:22:17 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel® Atom™ CPU N270 @ 1.60GHz Percentage of memory in use: 81% Total physical RAM: 1014.43 MB Available physical RAM: 191.19 MB Total Pagefile: 2115.43 MB Available Pagefile: 865.98 MB Total Virtual: 2047.88 MB Available Virtual: 1916.86 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:74.52 GB) (Free:25.59 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Data) (Fixed) (Total:73.24 GB) (Free:11.53 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 5209A946) Partition 1: (Active) - (Size=74.5 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=73.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=1.3 GB) - (Type=17) ==================== End Of Log ============================ Hi admins. This is a newly acquired mini-notebook Toshiba NB200 11L - Windows 7. I would like to check if it is clean please and operating correctly. I have installed the chameleon & scanner, 10 x Pup.optional.rewardarcade was found on registry key. I have quarantined them & deleted them. Please can I have some assistance to see this Toshiba is clean. Please note this is a different computer to the one I am already getting help with! Thanks in advance for your assistance with this one.