Jump to content
Due to inclement weather in Southwest Florida, our Clearwater support team is offline. Our other offices are available to assist you, however their responses may be delayed. We appreciate your patience and understanding during this time. ×

Search the Community

Showing results for tags 'csrss.exe'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


Forums

  • Announcements
    • Malwarebytes News
    • Beta Testing Program
  • Malware Removal Help
    • Windows Malware Removal Help & Support
    • Mac Malware Removal Help & Support
    • Mobile Malware Removal Help & Support
    • Malware Removal Self-Help Guides
  • Malwarebytes for Home Support
    • Malwarebytes for Windows Support Forum
    • Malwarebytes for Mac Support Forum
    • Malwarebytes for Android Support Forum
    • Malwarebytes for iOS Support
    • Malwarebytes Privacy
    • Malwarebytes Browser Guard
    • False Positives
    • Comments and Suggestions
  • Malwarebytes for Business Support
    • Malwarebytes Nebula
    • Malwarebytes Nebula Modules
    • Malwarebytes Endpoint Security
    • Other Malwarebytes Business Products
    • Malwarebytes Business Products Comments and Suggestions
  • Malwarebytes Tools and Other Products
    • Malwarebytes AdwCleaner
    • Malwarebytes Junkware Removal Tool Support
    • Malwarebytes Anti-Rootkit BETA Support
    • Malwarebytes Techbench USB (Legacy)
    • Malwarebytes Secure Backup discontinued
    • Other Tools
    • Malwarebytes Tools Comments and Suggestions
  • General Computer Help and Security Updates
    • BSOD, Crashes, Kernel Debugging
    • General Windows PC Help
  • Research Center
    • Newest Rogue-Ransomware Threats
    • Newest Malware Threats
    • Newest Mobile Threats
    • Newest IP or URL Threats
    • Newest Mac Threats
    • Report Scam Phone Numbers
  • General
    • General Chat
    • Forums Announcements & Feedback

Find results in...

Find results that contain...


Date Created

  • Start

    End


Last Updated

  • Start

    End


Filter by number of...

Joined

  • Start

    End


Group


AIM


MSN


Website URL


ICQ


Yahoo


Jabber


Location


Interests

Found 13 results

  1. Need solution, My PC got infected with EpicNet.inc/CloudNet/glupteba/or whatever, they keep coming after rebooting, I need your help to get rid of these pesky malware, step by step guide will be appreciated.
  2. C:\Users\Chris\AppData\Local\Temp\phantomows\bin Around 2-4 days ago my malwarebytes detected that it blocked a malicious site from attacking my PC and it was CSRSS.exe. I know that its a normal file so I was curious why it was coming up. I searched my computer for the file, all the other files locations were normal, in the windows folders, except for the one I posted above. Yesterday I found it and had Microsoft Essentials and Malewarebytes scan it. Neither found anything, virus or spyware. I deleted it and used CCleaner to clean up all my temp stuff. I was good, until a hour ago it came back. Same folder, same location. Does anyone have an idea on why this suddenly has come up and why it can't stay gone? I tried to delete it just now and it won't let me. It says another program is using it but I had nothing open. Thanks to anyone who can help me out.
  3. Are these duplicate files normal or a virus? I have the latest version of mbam premium and my threat scan results are zero. I also downloaded the Farbar recovery tool to my desktop and ran a scan. I have copied / pasted the content from FRST.txt below. Please advise. I'm thinking it's not normal to see these duplicate files in task manager. I can delete one but when I reboot, they call come back in multiples. Please advise -------------- Farbar's FRST.txt ----- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-09-2016 Ran by GImagineG (administrator) on WWBFANBSWHTALAM (19-09-2016 22:30:16) Running from C:\Users\GImagineG\Desktop Loaded Profiles: GImagineG (Available Profiles: GImagineG) Platform: Windows 10 Home Version 1607 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe (Károly Pados) C:\Program Files (x86)\TinyWall\TinyWall.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSAS10.MSSQLSERVER\OLAP\bin\msmdsrv.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe () C:\Windows\System32\igfxTray.exe (Károly Pados) C:\Program Files (x86)\TinyWall\TinyWall.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech, Inc.) HKLM\...\Run: [TinyWall Controller] => C:\Program Files (x86)\TinyWall\TinyWall.exe [693080 2016-01-04] (Károly Pados) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-09-15] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [286992 2016-01-11] (RealNetworks, Inc.) HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [719632 2015-11-04] () HKU\S-1-5-21-1554107894-1944105626-794477097-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [455968 2007-08-23] (Hewlett-Packard Company) HKU\S-1-5-21-1554107894-1944105626-794477097-1001\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG) HKU\S-1-5-21-1554107894-1944105626-794477097-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd) HKU\S-1-5-21-1554107894-1944105626-794477097-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2016-08-31] (SUPERAntiSpyware) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2015-12-11] ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2016-02-21] ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealTimes.lnk [2016-01-11] ShortcutTarget: RealTimes.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 108.7.45.5 Tcpip\..\Interfaces\{0f755d79-3aa7-445a-9614-10e3e0e860bf}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{0f755d79-3aa7-445a-9614-10e3e0e860bf}: [DhcpNameServer] 108.7.45.5 Internet Explorer: ================== HKU\S-1-5-21-1554107894-1944105626-794477097-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE03&ocid=UE03DHP BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2015-11-04] (RealDownloader) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2015-11-04] (RealDownloader) BHO-x32: Microsoft Web Test Recorder 9.0 Helper -> {E31CE47F-C268-41ba-897B-B415E613947D} -> C:\Program Files (x86)\Microsoft Visual Studio 9.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO90.dll [2007-11-08] (Microsoft Corporation) Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\GImagineG\AppData\Roaming\Mozilla\Firefox\Profiles\60esv6ob.default FF DefaultSearchEngine: Bing FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Bing FF Homepage: hxxps://www.google.com/ FF Keyword.URL: hxxp://www.bing.com/search?FORM=SL5HDF&PC=SL5H&q= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-08-09] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-08-09] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll [2016-07-11] ( Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=18.1.2.175 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2016-01-11] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=18.1.2.175 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2016-01-11] (RealPlayer) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-01] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-01] (Google Inc.) FF SearchPlugin: C:\Users\GImagineG\AppData\Roaming\Mozilla\Firefox\Profiles\60esv6ob.default\searchplugins\bing-.xml [2016-03-29] FF Extension: (Bing Search) - C:\Users\GImagineG\AppData\Roaming\Mozilla\Firefox\Profiles\60esv6ob.default\Extensions\bingsearch.full@microsoft.com.xpi [2016-03-29] FF Extension: (Firefox Hotfix) - C:\Users\GImagineG\AppData\Roaming\Mozilla\Firefox\Profiles\60esv6ob.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-09-12] Chrome: ======= CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us CHR StartupUrls: Default -> "hxxps://www.google.com/" CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms} CHR DefaultSearchKeyword: Default -> bing.com CHR Plugin: (Widevine Content Decryption Module) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x64\widevinecdmadapter.dll => No File CHR Plugin: (Shockwave Flash) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\PepperFlash\21.0.0.216\pepflashplayer.dll => No File CHR Profile: C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default [2016-09-19] CHR Extension: (Google Slides) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-10] CHR Extension: (Google Docs) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-10] CHR Extension: (Google Drive) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-10] CHR Extension: (YouTube) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-10] CHR Extension: (Google Search) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-10] CHR Extension: (Google Sheets) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-10] CHR Extension: (Google Docs Offline) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17] CHR Extension: (Deluminate) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\iebboopaeangfpceklajfohhbpkkfiaa [2016-05-10] CHR Extension: (Chrome Web Store Payments) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-13] CHR Extension: (Gmail) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-10] CHR Extension: (Chrome Media Router) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-19] CHR Extension: (Abstract Blue) - C:\Users\GImagineG\AppData\Local\Google\Chrome\User Data\Default\Extensions\plnacehkknmafkjgkikclamogikoiaaa [2016-09-05] CHR HKU\S-1-5-21-1554107894-1944105626-794477097-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com) R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2015-03-27] (Broadcom Corporation.) R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [374360 2016-05-27] (Intel Corporation) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [21184 2015-11-20] (Microsoft Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) R2 MsDtsServer100; C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [220088 2012-06-15] (Microsoft Corporation) R3 MSSQLFDLauncher; C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [34840 2008-07-10] (Microsoft Corporation) R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [57967032 2012-06-15] (Microsoft Corporation) R2 MSSQLServerOLAPService; C:\Program Files\Microsoft SQL Server\MSAS10.MSSQLSERVER\OLAP\bin\msmdsrv.exe [43774808 2010-09-17] (Microsoft Corporation) S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation) S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG) S4 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [33088 2015-11-04] () S4 RealTimes Desktop Service; C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [1095976 2016-01-11] (RealNetworks, Inc.) R2 ReportServer; C:\Program Files\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2094520 2012-06-15] (Microsoft Corporation) S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [439736 2012-06-15] (Microsoft Corporation) S4 Te.Service; C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [137216 2015-11-19] (Microsoft Corporation) [File not signed] R2 TinyWall; C:\Program Files (x86)\TinyWall\TinyWall.exe [693080 2016-01-04] (Károly Pados) [File not signed] R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [173312 2015-03-27] (Broadcom Corporation.) R3 KillerEth; C:\Windows\System32\drivers\e22w10x64.sys [124464 2015-04-27] (Qualcomm Atheros, Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-09-19] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 SensorsSimulatorDriver; C:\Windows\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) U3 aspnet_state; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-09-19 22:30 - 2016-09-19 22:30 - 00017610 _____ C:\Users\GImagineG\Desktop\FRST.txt 2016-09-19 22:30 - 2016-09-19 22:30 - 00000000 ____D C:\FRST 2016-09-19 22:15 - 2016-09-19 22:29 - 02400256 _____ (Farbar) C:\Users\GImagineG\Desktop\FRST64.exe 2016-09-19 21:22 - 2016-09-19 21:22 - 02400256 _____ (Farbar) C:\Users\GImagineG\Downloads\FRST64.exe 2016-09-19 21:19 - 2016-09-19 21:20 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\GImagineG\Downloads\rkill.exe 2016-09-19 15:20 - 2016-09-19 15:20 - 00000000 ____D C:\Users\GImagineG\AppData\Local\ZipScript 10 2016-09-19 14:27 - 2016-09-19 14:27 - 01130830 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2016-09-19 14:24 - 2016-05-25 14:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2016-09-19 14:24 - 2016-05-25 14:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2016-09-19 14:24 - 2016-05-25 14:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2016-09-19 14:24 - 2016-05-25 11:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2016-09-19 14:24 - 2016-05-25 11:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2016-09-19 14:24 - 2016-05-25 11:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2016-09-19 14:14 - 2016-09-19 14:15 - 00000000 ____D C:\sqlsv2k8 2016-09-15 05:03 - 2016-09-15 01:16 - 00000000 ___DC C:\WINDOWS\Panther 2016-09-15 05:02 - 2016-09-15 05:02 - 00000000 ____D C:\Windows.old 2016-09-15 05:01 - 2016-09-15 05:01 - 23681024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 22566400 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 22218808 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 20965248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 19417088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 19416576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 17187840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 13867520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 13434368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 13081088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 12345856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 12174336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL 2016-09-15 05:01 - 2016-09-15 05:01 - 09260032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL 2016-09-15 05:01 - 2016-09-15 05:01 - 09128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 08156592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 08122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 07813472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 07792640 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 07654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 07623680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 07468032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 07220224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 06653592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 06574592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 06043136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 05721808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 05684736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 05622600 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 05384192 _____ (Microsoft) C:\WINDOWS\system32\dbgeng.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 05376000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 04747776 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 04557824 _____ (Microsoft) C:\WINDOWS\SysWOW64\dbgeng.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 04130944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 03893376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 03776512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 03617792 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 03435008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 03305984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 03299328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 03245056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 03116544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAJApi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 02999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 02947072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02913104 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02846208 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2016-09-15 05:01 - 2016-09-15 05:01 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2016-09-15 05:01 - 2016-09-15 05:01 - 02745224 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02711040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02688512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02630144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02537824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02485760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02481768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02446696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02424320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Perception.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02423296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAJApi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02360832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02315264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02289664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02264064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02256224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 02251432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02217472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02214784 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02190688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 02183792 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02143232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02107392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02095616 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2016-09-15 05:01 - 2016-09-15 05:01 - 02083840 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02049480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 02026496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2016-09-15 05:01 - 2016-09-15 05:01 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01990640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01966288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01935360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01905664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01891328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01883784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01853232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01847048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01780736 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01738040 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01707512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01690112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Perception.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01656320 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01637888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01595904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01570680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01557296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01555456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.3D.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 01503032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01491968 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01472536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01469120 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01453992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01430208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01377008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 01362504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01349120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2016-09-15 05:01 - 2016-09-15 05:01 - 01349120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01343928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01316352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 01293312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 01282048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01280352 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01267504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01264912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01232384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01217880 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01176664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01163696 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 01123360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01106944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01105408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MiracastReceiver.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01099616 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 01082368 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01081856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01078784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01077760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01071728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01066328 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01066104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01052672 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01046976 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2016-09-15 05:01 - 2016-09-15 05:01 - 01029632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01014784 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 01006080 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00996192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2016-09-15 05:01 - 2016-09-15 05:01 - 00988000 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00980824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00963584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebcamUi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00959488 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00959104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00955520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00942432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi 2016-09-15 05:01 - 2016-09-15 05:01 - 00939872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pidgenx.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00911872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00885824 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00853344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebcamUi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00811416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00807776 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MiracastReceiver.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00790760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00782176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00773200 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00764936 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00761344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00758784 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00755656 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00755200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00714240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00681304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00665768 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00658272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00650240 _____ (Microsoft) C:\WINDOWS\system32\DbgModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00640976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00619368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00601200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00595488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00590952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00587968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.UXRes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00554496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00552288 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00538112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00529928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00526848 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00523712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMRServer.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00509952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00500224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.InkControls.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00461312 _____ (Microsoft) C:\WINDOWS\SysWOW64\DbgModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00450392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\das.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00442368 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00435040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00423776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00409944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2016-09-15 05:01 - 2016-09-15 05:01 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00408600 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsmf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00405344 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00396168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00389000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00382272 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00379744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NmaDirect.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00361096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsmf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00354264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00321792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00313560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00303968 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00302592 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NmaDirect.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00244816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafpos.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpipcfg.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_G18030.DLL 2016-09-15 05:01 - 2016-09-15 05:01 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_G18030.DLL 2016-09-15 05:01 - 2016-09-15 05:01 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00224096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToReceiver.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00204288 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DscCoreConfProv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfksproxy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00178528 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00168800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS 2016-09-15 05:01 - 2016-09-15 05:01 - 00160096 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XamlTileRender.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00151224 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00141824 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DscCoreConfProv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MediaFoundation.DefaultPerceptionProvider.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00133472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00121368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\EhStorTcgDrv.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00114192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00108384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastLaunch.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dasHost.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00079536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00077664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00073568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappprxy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AddressParser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00062816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ConfigureExpandedStorage.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00057400 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappprxy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AddressParser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactActivation.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00050880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactActivation.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceassociation.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00044472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00041824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidusb.sys 2016-09-15 05:01 - 2016-09-15 05:01 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00036168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceassociation.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiougc.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\encapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerSvc.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\delegatorprovider.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiougc.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi_passthru.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smphost.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\encapi.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smphost.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\delegatorprovider.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi_passthru.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\C_IS2022.DLL 2016-09-15 05:01 - 2016-09-15 05:01 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanhlp.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\c_GSM7.DLL 2016-09-15 05:01 - 2016-09-15 05:01 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\C_IS2022.DLL 2016-09-15 05:01 - 2016-09-15 05:01 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\c_GSM7.DLL 2016-09-15 05:01 - 2016-09-15 05:01 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe 2016-09-15 05:01 - 2016-09-15 05:01 - 00010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwmp.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccessRes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccessRes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdxm.ocx 2016-09-15 05:01 - 2016-09-15 05:01 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxmasf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx 2016-09-15 05:01 - 2016-09-15 05:01 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneutilRes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneutilRes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneServiceRes.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll 2016-09-15 05:01 - 2016-09-15 05:01 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll 2016-09-15 04:59 - 2016-09-15 04:59 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2016-09-15 04:59 - 2016-09-15 01:04 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2016-09-15 04:59 - 2016-07-15 23:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll 2016-09-15 04:59 - 2016-07-15 23:28 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll 2016-09-15 04:59 - 2016-07-15 23:28 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARP12Debug.dll 2016-09-15 04:59 - 2016-07-15 23:26 - 00376320 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe 2016-09-15 04:59 - 2016-07-15 23:26 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll 2016-09-15 04:59 - 2016-07-15 23:25 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll 2016-09-15 04:59 - 2016-07-15 23:23 - 14388224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll 2016-09-15 04:59 - 2016-07-15 23:22 - 00429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll 2016-09-15 04:59 - 2016-07-15 23:22 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll 2016-09-15 04:59 - 2016-07-15 23:19 - 01323520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll 2016-09-15 04:59 - 2016-07-15 23:16 - 05850624 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe 2016-09-15 04:59 - 2016-07-15 23:16 - 04969472 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe 2016-09-15 04:59 - 2016-07-15 23:15 - 06582784 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12warp.dll 2016-09-15 04:59 - 2016-07-15 23:13 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll 2016-09-15 04:59 - 2016-07-15 23:13 - 01198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe 2016-09-15 04:59 - 2016-07-15 23:13 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll 2016-09-15 04:59 - 2016-07-15 23:12 - 00297984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll 2016-09-15 04:59 - 2016-07-15 23:12 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll 2016-09-15 04:59 - 2016-07-15 23:11 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll 2016-09-15 04:59 - 2016-07-15 22:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxToolsReportGenerator.dll 2016-09-15 04:59 - 2016-07-15 22:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsProxyStub.dll 2016-09-15 04:59 - 2016-07-15 22:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARP12Debug.dll 2016-09-15 04:59 - 2016-07-15 22:42 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARPDebug.dll 2016-09-15 04:59 - 2016-07-15 22:41 - 00355840 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe 2016-09-15 04:59 - 2016-07-15 22:41 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXGIDebug.dll 2016-09-15 04:59 - 2016-07-15 22:39 - 11670528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCaptureReplay.dll 2016-09-15 04:59 - 2016-07-15 22:38 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll 2016-09-15 04:59 - 2016-07-15 22:37 - 01074176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll 2016-09-15 04:59 - 2016-07-15 22:35 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perf_gputiming.dll 2016-09-15 04:59 - 2016-07-15 22:32 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe 2016-09-15 04:59 - 2016-07-15 22:32 - 03701248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsRemoteEngine.exe 2016-09-15 04:59 - 2016-07-15 22:31 - 04977664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12warp.dll 2016-09-15 04:59 - 2016-07-15 22:29 - 00953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCap.exe 2016-09-15 04:59 - 2016-07-15 22:29 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsExperiment.dll 2016-09-15 04:59 - 2016-07-15 22:29 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsCapture.dll 2016-09-15 04:59 - 2016-07-15 22:28 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsOfflineAnalysis.dll 2016-09-15 04:59 - 2016-07-15 22:28 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsMonitor.dll 2016-09-15 04:59 - 2016-07-15 22:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsReporting.dll 2016-09-15 04:58 - 2016-09-15 04:58 - 00199008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys 2016-09-15 03:30 - 2016-09-19 13:02 - 00000000 ____D C:\Users\GImagineG\Documents\Bulls announce 2016-17 Television Schedule _ Chicago Bulls_files 2016-09-15 03:30 - 2016-09-15 03:30 - 00135491 _____ C:\Users\GImagineG\Documents\Bulls announce 2016-17 Television Schedule _ Chicago Bulls.htm 2016-09-15 03:25 - 2016-09-15 03:27 - 00025088 _____ C:\Users\GImagineG\Documents\Chicago Vulls Schedule.xls 2016-09-15 02:04 - 2016-09-15 02:04 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2016-09-15 02:03 - 2016-09-15 02:03 - 00000000 ____D C:\Users\GImagineG\AppData\Local\ConnectedDevicesPlatform 2016-09-15 01:16 - 2016-09-15 01:16 - 00000000 _SHDL C:\Users\Default\My Documents 2016-09-15 01:16 - 2016-09-15 01:16 - 00000000 _SHDL C:\Users\Default\Documents\My Videos 2016-09-15 01:16 - 2016-09-15 01:16 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures 2016-09-15 01:16 - 2016-09-15 01:16 - 00000000 _SHDL C:\Users\Default\Documents\My Music 2016-09-15 01:16 - 2016-09-15 01:16 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos 2016-09-15 01:16 - 2016-09-15 01:16 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures 2016-09-15 01:16 - 2016-09-15 01:16 - 00000000 _SHDL C:\Users\Default User\Documents\My Music 2016-09-15 01:16 - 2016-09-15 01:16 - 00000000 ____D C:\ProgramData\USOShared 2016-09-15 01:15 - 2016-09-15 01:15 - 00007623 _____ C:\WINDOWS\diagwrn.xml 2016-09-15 01:15 - 2016-09-15 01:15 - 00007623 _____ C:\WINDOWS\diagerr.xml 2016-09-15 01:14 - 2016-09-19 15:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-09-15 01:14 - 2016-09-15 01:14 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat 2016-09-15 01:14 - 2016-09-15 01:14 - 00003454 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-09-15 01:14 - 2016-09-15 01:14 - 00003432 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1469256672 2016-09-15 01:14 - 2016-09-15 01:14 - 00003392 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task bdd463d5-961f-4895-aa8b-12fed1956349 2016-09-15 01:14 - 2016-09-15 01:14 - 00003326 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task 9c97e707-2f6a-49fa-9c39-bf57a7fce1cb 2016-09-15 01:14 - 2016-09-15 01:14 - 00003316 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6149F0C1-0742-44DD-A521-14C41333BEE7} 2016-09-15 01:14 - 2016-09-15 01:14 - 00003230 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-09-15 01:14 - 2016-09-15 01:14 - 00002954 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2016-09-15 01:14 - 2016-09-15 01:14 - 00002672 _____ C:\WINDOWS\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1554107894-1944105626-794477097-1001 2016-09-15 01:14 - 2016-09-15 01:14 - 00002654 _____ C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1554107894-1944105626-794477097-1001 2016-09-15 01:14 - 2016-09-15 01:14 - 00002552 _____ C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1554107894-1944105626-794477097-1001 2016-09-15 01:14 - 2016-09-15 01:14 - 00002494 _____ C:\WINDOWS\System32\Tasks\RealDownloader Update Check 2016-09-15 01:14 - 2016-09-15 01:14 - 00002162 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2016-09-15 01:14 - 2016-09-15 01:14 - 00000020 ___SH C:\Users\GImagineG\ntuser.ini 2016-09-15 01:13 - 2016-09-15 01:13 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-09-15 01:13 - 2016-09-15 01:13 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2008 2016-09-15 01:13 - 2016-09-15 01:13 - 00000000 ____D C:\Users\Default\Documents\Visual Studio 2005 2016-09-15 01:13 - 2016-09-15 01:13 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2016-09-15 01:13 - 2016-09-15 01:13 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2008 2016-09-15 01:13 - 2016-09-15 01:13 - 00000000 ____D C:\Users\Default User\Documents\Visual Studio 2005 2016-09-15 01:13 - 2016-09-15 01:13 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2016-09-15 01:06 - 2016-07-16 07:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2016-09-15 01:05 - 2016-09-19 13:03 - 00000000 ____D C:\Users\GImagineG 2016-09-15 01:05 - 2016-09-15 01:13 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate 2016-09-15 01:05 - 2016-09-15 01:05 - 00000000 _SHDL C:\Users\GImagineG\My Documents 2016-09-15 01:05 - 2016-09-15 01:05 - 00000000 _SHDL C:\Users\GImagineG\Documents\My Videos 2016-09-15 01:05 - 2016-09-15 01:05 - 00000000 _SHDL C:\Users\GImagineG\Documents\My Pictures 2016-09-15 01:05 - 2016-09-15 01:05 - 00000000 _SHDL C:\Users\GImagineG\Documents\My Music 2016-09-15 01:04 - 2016-09-19 18:58 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2016-09-15 01:04 - 2016-09-19 15:22 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2016-09-15 01:04 - 2016-09-15 02:57 - 00329720 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-09-15 01:04 - 2016-09-15 01:04 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat 2016-09-15 01:04 - 2016-09-15 01:04 - 00000000 ____D C:\Program Files\Intel 2016-09-15 01:04 - 2016-09-15 01:04 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin 2016-09-15 01:04 - 2016-05-27 15:50 - 00104584 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL 2016-09-15 01:04 - 2016-05-27 15:50 - 00100488 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL 2016-09-05 13:44 - 2016-09-05 16:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-08-31 06:58 - 2016-09-13 02:00 - 00000550 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task bdd463d5-961f-4895-aa8b-12fed1956349.job 2016-08-31 06:58 - 2016-09-05 16:46 - 00000550 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 9c97e707-2f6a-49fa-9c39-bf57a7fce1cb.job ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-09-19 21:11 - 2015-12-10 02:56 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2016-09-19 18:31 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\rescache 2016-09-19 16:28 - 2016-04-11 17:10 - 00000000 ____D C:\zzmp4 2016-09-19 15:28 - 2016-01-19 15:40 - 00000000 ____D C:\Users\GImagineG\AppData\Local\WORDsearch 11 2016-09-19 15:26 - 2016-01-19 15:40 - 00000000 ____D C:\Program Files (x86)\WORDsearch 11 2016-09-19 15:25 - 2015-12-10 03:29 - 01174306 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-09-19 15:22 - 2015-12-10 03:43 - 00000000 __SHD C:\Users\GImagineG\IntelGraphicsProfiles 2016-09-19 15:20 - 2016-07-16 02:04 - 00262144 _____ C:\WINDOWS\system32\config\BBI 2016-09-19 15:20 - 2016-01-19 15:40 - 00000000 ____D C:\Users\GImagineG\Documents\WORDsearch 2016-09-19 15:20 - 2016-01-19 15:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WORDsearch 11 2016-09-19 15:00 - 2016-05-16 21:27 - 00000000 ____D C:\Users\GImagineG\AppData\Local\Sling_cache 2016-09-19 14:35 - 2016-07-16 07:45 - 00000000 ____D C:\WINDOWS\INF 2016-09-19 14:35 - 2015-12-11 07:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2008 2016-09-19 14:27 - 2016-07-16 07:36 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-09-19 13:02 - 2016-07-16 07:47 - 00000000 ___RD C:\Program Files\Windows Defender 2016-09-19 13:02 - 2016-07-16 07:47 - 00000000 ___HD C:\Program Files\WindowsApps 2016-09-19 13:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2016-09-19 13:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\MUI 2016-09-19 13:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\registration 2016-09-19 13:02 - 2016-07-16 02:04 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel 2016-09-19 13:02 - 2016-07-16 02:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2016-09-19 13:02 - 2016-07-16 02:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2016-09-19 13:02 - 2016-07-16 02:04 - 00000000 ____D C:\WINDOWS\system32\downlevel 2016-09-19 13:02 - 2016-07-16 02:04 - 00000000 ____D C:\WINDOWS\system32\Dism 2016-09-19 13:02 - 2016-07-16 02:04 - 00000000 ____D C:\WINDOWS\servicing 2016-09-19 13:02 - 2016-02-19 09:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Transcender 2016-09-19 13:02 - 2016-01-11 22:35 - 00000000 ____D C:\ProgramData\WORDsearch 2016-09-19 13:02 - 2015-12-15 12:19 - 00000000 ____D C:\Users\GImagineG\AppData\Roaming\vlc 2016-09-19 13:02 - 2015-12-10 07:41 - 00000000 ____D C:\Users\GImagineG\AppData\Roaming\Winamp 2016-09-19 13:01 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\appcompat 2016-09-19 13:01 - 2016-01-11 23:37 - 00000000 ____D C:\ProgramData\Real 2016-09-19 13:01 - 2015-12-11 06:25 - 00000000 ____D C:\Program Files\Reference Assemblies 2016-09-19 13:01 - 2015-12-11 06:25 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2016-09-19 13:01 - 2015-12-11 06:25 - 00000000 ____D C:\Program Files (x86)\MSBuild 2016-09-16 05:04 - 2015-12-11 07:05 - 00000000 ____D C:\Users\GImagineG\Documents\SQL Server Management Studio 2016-09-15 05:03 - 2016-07-16 07:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ___SD C:\WINDOWS\system32\F12 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ___SD C:\WINDOWS\system32\dsc 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\lv-LV 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\lt-LT 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\et-EE 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\es-MX 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\en-GB 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\ShellExperiences 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\Provisioning 2016-09-15 05:02 - 2016-07-16 07:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2016-09-15 02:26 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-09-15 02:21 - 2015-12-10 03:31 - 00000000 ____D C:\Users\GImagineG\AppData\Local\Packages 2016-09-15 02:04 - 2015-12-10 03:32 - 00002375 _____ C:\Users\GImagineG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-09-15 02:04 - 2015-12-10 03:32 - 00000000 ___RD C:\Users\GImagineG\OneDrive 2016-09-15 02:03 - 2015-12-10 03:31 - 00000000 __RHD C:\Users\Public\AccountPictures 2016-09-15 01:16 - 2016-07-16 07:47 - 00000000 ____D C:\ProgramData\USOPrivate 2016-09-15 01:15 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2016-09-15 01:15 - 2016-07-16 02:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2016-09-15 01:15 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2016-09-15 01:14 - 2016-07-16 07:47 - 00000000 __RSD C:\WINDOWS\Media 2016-09-15 01:14 - 2016-07-16 07:47 - 00000000 __RHD C:\Users\Public\Libraries 2016-09-15 01:14 - 2015-12-10 01:47 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-09-15 01:13 - 2016-08-01 13:56 - 00000000 ____D C:\Users\GImagineG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2016-09-15 01:13 - 2016-07-16 07:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-09-15 01:13 - 2016-04-21 04:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TinyWall 2016-09-15 01:13 - 2016-03-29 07:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-09-15 01:13 - 2016-02-21 11:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools 2016-09-15 01:13 - 2016-01-27 00:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2016-09-15 01:13 - 2016-01-11 23:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks 2016-09-15 01:13 - 2015-12-29 19:36 - 00000000 ____D C:\Users\GImagineG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-09-15 01:13 - 2015-12-15 14:10 - 00000000 ____D C:\Users\GImagineG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yamb 2.1.0.0 beta 2 2016-09-15 01:13 - 2015-12-15 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2016-09-15 01:13 - 2015-12-15 12:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2016-09-15 01:13 - 2015-12-14 16:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008R2 Community & Samples 2016-09-15 01:13 - 2015-12-12 04:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015 2016-09-15 01:13 - 2015-12-11 08:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Developer Network 2016-09-15 01:13 - 2015-12-11 06:58 - 00000000 ____D C:\WINDOWS\SysWOW64\1033 2016-09-15 01:13 - 2015-12-11 06:58 - 00000000 ____D C:\WINDOWS\system32\1033 2016-09-15 01:13 - 2015-12-11 06:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 2016-09-15 01:13 - 2015-12-10 09:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cool Edit Pro 2.0 2016-09-15 01:13 - 2015-12-10 09:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Essentials 2016-09-15 01:13 - 2015-12-10 09:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling 2016-09-15 01:13 - 2015-12-10 07:41 - 00000000 ____D C:\Users\GImagineG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Detector Plug-in 2016-09-15 01:13 - 2015-12-10 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp 2016-09-15 01:13 - 2015-12-10 05:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2016-09-15 01:13 - 2015-12-10 02:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-09-15 01:13 - 2015-10-30 02:28 - 00000000 ____D C:\Users\Default.migrated 2016-09-15 01:08 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2016-09-15 01:08 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\spool 2016-09-15 01:08 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\Macromed 2016-09-15 01:07 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2016-09-15 01:07 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\Help 2016-09-15 01:07 - 2016-07-16 07:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-09-15 01:07 - 2016-01-26 22:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperNZB 2016-09-15 01:07 - 2015-12-14 17:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 R2 2016-09-15 01:07 - 2015-12-12 05:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits 2016-09-15 01:07 - 2015-12-12 04:55 - 00000000 ____D C:\Program Files\IIS 2016-09-15 01:07 - 2015-12-11 08:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v6.0A 2016-09-15 01:07 - 2015-12-11 08:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft SQL Server 2008 R2 November CTP 2016-09-15 01:07 - 2015-12-11 06:25 - 00000000 ____D C:\Program Files\MSBuild 2016-09-15 01:07 - 2015-10-30 05:07 - 00000000 ____D C:\WINDOWS\ShellNew 2016-09-15 01:05 - 2016-06-23 23:27 - 00000000 ____D C:\Users\GImagineG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sling 2016-09-15 01:05 - 2015-12-10 05:48 - 00000000 ____D C:\Users\GImagineG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon 2016-09-15 01:04 - 2016-07-16 07:47 - 00000000 ___RD C:\WINDOWS\PrintDialog 2016-09-15 01:04 - 2016-07-16 07:47 - 00000000 ___RD C:\WINDOWS\MiracastView 2016-09-15 01:04 - 2016-07-16 07:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-09-15 00:50 - 2016-07-16 11:17 - 00000000 ___HD C:\$WINDOWS.~BT 2016-09-15 00:12 - 2015-12-10 03:56 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-09-15 00:10 - 2015-12-10 03:56 - 144199024 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-09-15 00:02 - 2015-12-10 01:47 - 00000942 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-09-14 23:51 - 2016-03-29 07:04 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2016-09-14 23:51 - 2016-03-29 07:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-09-14 23:38 - 2015-10-30 03:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll 2016-09-14 23:38 - 2015-10-30 03:19 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll 2016-09-14 23:31 - 2015-12-12 05:05 - 00000000 ____D C:\Users\GImagineG\Documents\Visual Studio 2015 2016-09-14 23:26 - 2015-12-10 01:47 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-09-13 07:03 - 2015-12-11 07:02 - 00000000 ____D C:\Users\GImagineG\Documents\Visual Studio 2008 2016-09-07 12:32 - 2016-07-16 07:49 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-09-07 12:32 - 2016-07-16 07:49 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-09-05 16:46 - 2016-08-01 13:55 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2016-09-05 16:46 - 2016-03-29 06:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service ==================== Files in the root of some directories ======= 2016-03-29 01:23 - 2016-03-29 01:23 - 0000017 _____ () C:\Users\GImagineG\AppData\Local\resmon.resmoncfg ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-09-15 01:03 ==================== End of FRST.txt ============================
  4. As I was looking through my Task Manager, I noticed something odd. There were two conhost.exe running. One of them didn't have a file location, description, or even a user name (well, SYSTEM, but not really). Showing all processes made it decide that it had a description. It was also using more memory. The one that was selected didn't reveal a location. Look at the first and second image ("Windows5", "Windows10"). TaskMan (not Task Manager) revealed that the one using less memory was in System32. The other one was in my user folder ("Windows11"), but when I looked, there was nothing new. Showing all processes also made another csrss.exe appear, which was also using a lot more memory, but I don't think (keyword: think) that's an issue. As for the actual csrss.exe that was running, it didn't reveal a location either ("Windows6"). When showing all processes, both csrss.exe were were claiming to be running from the System32 folder, but so were the two conhost.exe. The winlogon.exe didn't have a location, TaskMan was also claiming it was in my user folder. (Simple picture to help: "Windows8".) Showing all processes made it give a location. (Picture to illustrate conhost.exe and csrss.exe: "Windows2", and a picture for winlogon.exe: "Windows4".) Also, noticed that TaskMan was claiming there were two nvwmi64.exe running, while Task Manager claimed one, but showing all processes revealed another ("Windows3", "Windows7", "Windows12"). Don't worry about the picture naming scheme. The numbers were the order I took them in; nothing else. I left out 1 and 9 because they turned out to be irrelevant. As a note, Kaspersky and Malwarebytes scans came back clean. My computer appears to be operating normally with no kind of slowdowns. The only problem is the mouse sometimes acting up, but this is the mouse's fault. If this is Windows being rude, then sorry for wasting your time. But I don't really think it's the fault of Windows. I've read other posts where the processes didn't have a location, like now, and they actually found something. Help is appreciated. FRST.txt Addition.txt
  5. I don't know what it's called by It looks like I have the same csrss.exe, winlogon.exe problem discussed in other posts. It appears in Task Manager/Performance that they are consistently chewing up memory and CPU. They also appear as the top #1 & #2 in the Processes list. Performance is generally slow. I'm reluctant to follow the resolution in other threads since there appears to be some uniqueness with them. I would be grateful to receive some assistance with this.
  6. Additionally, a Malwarebytes scan returned >71,000 threats yet the program was unresponsive when I tried to remove all threats. Help?! Addition.txt FRST.txt THREATS.txt
  7. I just found out we'd exceeded our (very high) Internet data cap. I started installing Internet usage checkers on our computers, and found that one was using far more data than it should (it's unused most of the day.) I Googled and found Malwarebytes, ran Process Explorer, and found that the computer's having two running instances of csrss.exe wasn't good. Herewith the logs: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-06-2014 Ran by Elizabeth (administrator) on ELIZABETH-PC on 15-06-2014 19:21:44Running from C:\Users\Elizabeth\DownloadsPlatform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)Internet Explorer Version 11Boot Mode: Normal The only official download link for FRST:Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated.See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe(SugarSync, Inc.) C:\Program Files (x86)\SugarSync\SugarSync.exe(MediaMall Technologies, Inc.) C:\Program Files (x86)\MediaMall\PlayOn.exe(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe(PFU LIMITED) C:\Windows\SSDriver\fi5110\SsWiaChecker.exe() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe( ) C:\Program Files (x86)\Codebox\BitMeter\BitMeter2.exe(Sysinternals - www.sysinternals.com) C:\Program Files (x86)\Procexp\procexp.exe(Sysinternals - www.sysinternals.com) C:\Users\Elizabeth\AppData\Local\Temp\procexp64.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(OldTimer Tools) C:\Users\Elizabeth\Downloads\OTL.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1275608 2014-03-25] (COMODO)HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)HKLM-x32\...\Run: [scanSnap WIA Service Checker] => C:\Windows\SSDriver\fi5110\SsWiaChecker.exe [86016 2009-09-30] (PFU LIMITED)HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-09] ()HKLM-x32\...\Run: [sDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-06-06] (Comodo Security Solutions, Inc.)Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]HKU\.DEFAULT\...\RunOnce: [sPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2013-11-21] (Microsoft Corporation)HKU\S-1-5-21-1674408116-3729613793-3804784409-1000\...\Run: [AVG-Secure-Search-Update_1113a] => C:\Users\Elizabeth\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=f94c2ef0443247d3a0c0d16f6bccd0f4-8ef3814ccf598f88d202c4ef86d692c3e0fa97ec /CMPID=1113aHKU\S-1-5-21-1674408116-3729613793-3804784409-1000\...\Run: [sugarSync] => C:\Program Files (x86)\SugarSync\SugarSync.exe [13119328 2014-05-06] (SugarSync, Inc.)HKU\S-1-5-21-1674408116-3729613793-3804784409-1000\...\Run: [PlayOn] => C:\Program Files (x86)\MediaMall\PlayOn.exe [67904 2014-03-05] (MediaMall Technologies, Inc.)HKU\S-1-5-21-1674408116-3729613793-3804784409-1000\...\Run: [GoogleChromeAutoLaunch_BC42A7D22EA4C9EEEC843EF2870E3FB5] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-06-05] (Google Inc.)HKU\S-1-5-21-1674408116-3729613793-3804784409-1000\...\Run: [62CF4B14FAA12E534B4ED8B0C8F7755415803ECD._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-06-05] (Google Inc.)Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bitmeter2.lnkShortcutTarget: Bitmeter2.lnk -> C:\Program Files (x86)\Codebox\BitMeter\BitMeter2.exe ( )Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnkShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnkShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnkShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()SSODL: EldosMountNotificator - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\system32\SSCbFsMntNtf3.dll (EldoS Corporation)SSODL-x32: EldosMountNotificator - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\SysWOW64\SSCbFsMntNtf3.dll (EldoS Corporation)BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:TabsHKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehpHKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6822DBB640E6CE01HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-USSearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={9F6D5DA2-67A9-49B9-A5FE-CAC77D8A26DA}&mid=f94c2ef0443247d3a0c0d16f6bccd0f4-8ef3814ccf598f88d202c4ef86d692c3e0fa97ec〈=en&ds=AVG&coid=avgtbavg&pr=fr&d=2013-11-22 09:21:04&v=17.1.2.1&pid=safeguard&sg=0&sap=dsp&q={searchTerms} BHO-x32: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No FileToolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No FileTcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 FireFox:========FF Plugin: @microsoft.com/GENUINE - disabled No FileFF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)FF Plugin-x32: @microsoft.com/GENUINE - disabled No FileFF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)FF Plugin-x32: @playon.tv/PlayOnToolbar - C:\Program Files (x86)\MediaMall\toolbar\npVT.dll (MediaMall Technologies, Inc.)FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: =======CHR HomePage: hxxp://my.yahoo.com/CHR StartupUrls: "hxxp://mail.google.com/"CHR Extension: (Google Translate) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2013-11-22]CHR Extension: (Text URL Linker) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegfbpchoheaflicfmggkmlmcccpjpgd [2013-11-22]CHR Extension: (Duolingo) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2013-11-22]CHR Extension: (Angry Birds) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2013-11-22]CHR Extension: (Google Docs) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-22]CHR Extension: (Google Drive) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-22]CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-07]CHR Extension: (YouTube) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-22]CHR Extension: (Webmail Ad Blocker) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbhfdchmklhpcngcgjmpdbjakdggkkjp [2013-11-22]CHR Extension: (Send to Kindle for Google Chrome™) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgdjpilhipecahhcilnafpblkieebhea [2014-04-28]CHR Extension: (Remember The Milk) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\chdiaibgndcpagmnpkjoelgfkommjbni [2013-11-22]CHR Extension: (Google Search) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-22]CHR Extension: (Logitech Smooth Scrolling) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2014-04-04]CHR Extension: (Timer) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\edebbhkhcaafmolanelponjjanocpacd [2013-11-22]CHR Extension: (Chromebleed) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeoekjnjgppnaegdjbcafdggilajhpic [2014-04-13]CHR Extension: (Camera) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabandfpdnfaojfnelmcgcplhbecchpn [2014-04-13]CHR Extension: (XKit) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfgeeomkfdefkckijiabdbogjkdaecd [2014-04-02]CHR Extension: (MagicScroll eBook Reader) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgnmgfdoiplfmhgghbmlphanpfmjble [2013-11-22]CHR Extension: (AdBlock) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-22]CHR Extension: (Hola Better Internet) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2013-11-22]CHR Extension: (Pin It Button) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2014-03-26]CHR Extension: (TinEye Reverse Image Search) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2014-01-11]CHR Extension: (Don't Starve) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\hiledapehlkhdehbhppgmekfalnlfajc [2013-11-22]CHR Extension: (Kindle Cloud Reader) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-02-28]CHR Extension: (PlayOn) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ienaefcpghbmccojmklhdffdobkbencj [2014-02-12]CHR Extension: (Evernote Web) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2013-11-22]CHR Extension: (Google Maps) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2013-11-22]CHR Extension: (Window Close Protector) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnpifgapnmpninomacbhdlconlpikdai [2013-11-22]CHR Extension: (Ghostery) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2013-11-22]CHR Extension: (Google Play Books) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2013-11-22]CHR Extension: (Extensions Update Notifier) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlldbplhbaopldicmcoogopmkonpebjm [2014-01-17]CHR Extension: (Google Wallet) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-22]CHR Extension: (Tumblr Savior) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefddkjnflmjbclpnnoegglmmdfkidip [2013-12-15]CHR Extension: (Modern New Tab Page) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogllliimbhgmclkgjldeffhjbhaenapo [2014-04-13]CHR Extension: (Twitter Preview URLs) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijgblonhcagdhfbgjilnpjipmijimmn [2014-01-21]CHR Extension: (Send from Gmail (by Google)) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2013-11-22]CHR Extension: (Gmail) - C:\Users\Elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-22]CHR HKLM-x32\...\Chrome\Extension: [ienaefcpghbmccojmklhdffdobkbencj] - C:\Program Files (x86)\MediaMall\toolbar\ce.crx [2014-01-03] ==================== Services (Whitelisted) ================= R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70864 2014-06-10] (Comodo Security Solutions, Inc.)R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6817544 2014-04-16] (COMODO)S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2264280 2014-03-25] (COMODO)R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2135232 2014-05-21] ()R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-06-06] (Comodo Security Solutions, Inc.)S2 MediaMall Server; C:\Program Files (x86)\MediaMall\MediaMallServer.exe [5425968 2014-03-05] (MediaMall Technologies, Inc.)R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)S3 SensrSvc; C:\Windows\system32\sensrsvc.dll [29184 2009-07-13] (Microsoft Corporation) [File not signed] ==================== Drivers (Whitelisted) ==================== R3 AX88772B; C:\Windows\System32\DRIVERS\ax88772b.sys [114176 2013-07-22] (ASIX Electronics Corp.)R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2013-05-07] (Windows ® Win 7 DDK provider) [File not signed]R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2014-04-16] (COMODO)R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [738472 2014-04-16] (COMODO)R1 HMD; C:\Windows\System32\DRIVERS\hmd.sys [14888 2013-10-06] ()R3 msvad_simple; C:\Windows\System32\drivers\povrtdev.sys [28528 2013-12-17] (MediaMall Technologies, Inc.)S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)R3 SSCBFS3; C:\Windows\System32\DRIVERS\sscbfs3.sys [347904 2013-01-30] (EldoS Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-15 19:21 - 2014-06-15 19:22 - 00017204 _____ () C:\Users\Elizabeth\Downloads\FRST.txt2014-06-15 19:21 - 2014-06-15 19:21 - 02081280 _____ (Farbar) C:\Users\Elizabeth\Downloads\FRST64.exe2014-06-15 19:21 - 2014-06-15 19:21 - 00000000 ____D () C:\FRST2014-06-15 19:05 - 2014-06-15 19:05 - 00052736 _____ () C:\Users\Elizabeth\Downloads\Extras.Txt2014-06-15 19:04 - 2014-06-15 19:04 - 00095254 _____ () C:\Users\Elizabeth\Downloads\OTL.Txt2014-06-15 18:54 - 2014-06-15 18:54 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys2014-06-15 18:54 - 2014-06-15 18:54 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk2014-06-15 18:54 - 2014-06-15 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware2014-06-15 18:54 - 2014-06-15 18:54 - 00000000 ____D () C:\ProgramData\Malwarebytes2014-06-15 18:54 - 2014-06-15 18:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware2014-06-15 18:54 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys2014-06-15 18:54 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys2014-06-15 18:54 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys2014-06-15 18:53 - 2014-06-15 18:53 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Elizabeth\Downloads\mbam-setup-2.0.2.1012.exe2014-06-15 18:50 - 2014-06-15 18:50 - 00380416 _____ () C:\Users\Elizabeth\Downloads\8frw3bx8.exe2014-06-15 18:49 - 2014-06-15 18:49 - 00602112 _____ (OldTimer Tools) C:\Users\Elizabeth\Downloads\OTL.exe2014-06-15 18:34 - 2014-06-15 19:21 - 00000000 ____D () C:\ProgramData\Bitmeter22014-06-15 18:34 - 2014-06-15 18:52 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\Bitmeter22014-06-15 18:34 - 2014-06-15 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitMeter2014-06-15 18:34 - 2014-06-15 18:34 - 00000000 ____D () C:\Program Files (x86)\Codebox2014-06-15 18:33 - 2014-06-15 18:33 - 01360256 _____ () C:\Users\Elizabeth\Downloads\BitMeter2.zip2014-06-15 18:25 - 2014-06-15 18:25 - 00372376 _____ (AddGadgets.com) C:\Users\Elizabeth\Downloads\NetworkMeterVersion96.exe2014-06-14 15:00 - 2014-06-14 15:00 - 00019334 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e08.hannibal.torrent2014-06-14 15:00 - 2014-06-14 15:00 - 00019334 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e07.hannibal.torrent2014-06-14 14:59 - 2014-06-14 14:59 - 00019334 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e06.hannibal.torrent2014-06-14 14:59 - 2014-06-14 14:59 - 00019327 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e05.hannibal.torrent2014-06-13 21:09 - 2014-06-13 21:09 - 00020930 _____ () C:\Users\Elizabeth\Downloads\Mock the Week s13e01.hannibal.torrent2014-06-11 01:37 - 2014-05-30 03:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb2014-06-11 01:37 - 2014-05-30 03:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll2014-06-11 01:37 - 2014-05-30 02:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll2014-06-11 01:37 - 2014-05-30 02:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe2014-06-11 01:37 - 2014-05-30 02:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll2014-06-11 01:37 - 2014-05-30 02:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll2014-06-11 01:37 - 2014-05-30 01:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll2014-06-11 01:37 - 2014-05-30 01:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll2014-06-11 01:37 - 2014-05-30 01:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll2014-06-11 01:37 - 2014-05-30 01:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll2014-06-11 01:37 - 2014-05-30 01:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll2014-06-11 01:37 - 2014-05-30 01:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll2014-06-11 01:37 - 2014-05-30 01:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll2014-06-11 01:37 - 2014-05-30 01:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll2014-06-11 01:37 - 2014-05-30 01:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll2014-06-11 01:37 - 2014-05-30 01:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll2014-06-11 01:37 - 2014-05-30 01:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll2014-06-11 01:37 - 2014-05-30 01:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll2014-06-11 01:37 - 2014-05-30 01:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll2014-06-11 01:37 - 2014-05-30 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll2014-06-11 01:37 - 2014-05-30 00:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl2014-06-11 01:37 - 2014-05-30 00:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll2014-06-11 01:37 - 2014-05-30 00:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll2014-06-11 01:37 - 2014-05-08 02:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll2014-06-11 01:37 - 2014-05-08 02:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll2014-06-11 01:37 - 2014-04-24 19:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll2014-06-11 01:37 - 2014-04-24 19:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll2014-06-11 01:37 - 2014-04-04 19:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys2014-06-11 01:37 - 2014-04-04 19:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS2014-06-11 01:37 - 2014-03-26 07:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll2014-06-11 01:37 - 2014-03-26 07:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll2014-06-11 01:37 - 2014-03-26 07:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll2014-06-11 01:37 - 2014-03-26 07:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll2014-06-11 01:37 - 2014-03-26 07:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll2014-06-11 01:37 - 2014-03-26 07:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll2014-06-11 01:37 - 2014-03-26 07:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll2014-06-11 01:37 - 2014-03-26 07:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll2014-06-11 01:36 - 2014-05-30 03:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll2014-06-11 01:36 - 2014-05-30 02:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll2014-06-11 01:36 - 2014-05-30 02:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll2014-06-11 01:36 - 2014-05-30 02:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll2014-06-11 01:36 - 2014-05-30 02:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll2014-06-11 01:36 - 2014-05-30 02:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll2014-06-11 01:36 - 2014-05-30 02:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll2014-06-11 01:36 - 2014-05-30 02:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe2014-06-11 01:36 - 2014-05-30 02:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll2014-06-11 01:36 - 2014-05-30 02:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe2014-06-11 01:36 - 2014-05-30 02:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll2014-06-11 01:36 - 2014-05-30 02:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb2014-06-11 01:36 - 2014-05-30 01:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll2014-06-11 01:36 - 2014-05-30 01:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll2014-06-11 01:36 - 2014-05-30 01:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll2014-06-11 01:36 - 2014-05-30 01:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll2014-06-11 01:36 - 2014-05-30 01:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe2014-06-11 01:36 - 2014-05-30 01:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe2014-06-11 01:36 - 2014-05-30 01:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll2014-06-11 01:36 - 2014-05-30 01:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl2014-06-11 01:36 - 2014-05-30 01:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll2014-06-11 01:36 - 2014-05-30 00:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll2014-06-11 01:36 - 2014-05-30 00:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll2014-06-11 01:36 - 2014-05-30 00:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll2014-06-11 01:36 - 2014-05-30 00:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll2014-06-11 01:36 - 2014-05-30 00:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll2014-06-11 01:36 - 2014-05-30 00:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll2014-06-11 01:36 - 2014-05-30 00:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll2014-06-11 01:36 - 2014-05-30 00:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll2014-06-11 01:34 - 2014-06-08 02:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll2014-06-11 01:34 - 2014-06-08 02:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll2014-06-10 21:05 - 2014-06-10 21:05 - 00000373 _____ () C:\Users\Elizabeth\Documents\googleprob.txt2014-06-08 20:10 - 2014-06-08 20:10 - 00019487 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e04.hannibal.torrent2014-06-08 20:09 - 2014-06-08 20:09 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e03.hannibal.torrent2014-06-08 20:09 - 2014-06-08 20:09 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e03.hannibal (1).torrent2014-06-08 13:03 - 2014-06-08 13:08 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy2014-06-08 13:03 - 2014-06-08 13:03 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk2014-06-08 13:03 - 2014-06-08 13:03 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk2014-06-08 13:03 - 2014-06-08 13:03 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking2014-06-08 13:03 - 2014-06-08 13:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 22014-06-08 13:03 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe2014-06-08 13:02 - 2014-06-08 13:05 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 22014-06-08 13:01 - 2014-06-08 13:02 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Elizabeth\Downloads\spybot-2.3.exe2014-06-07 17:17 - 2014-06-07 17:17 - 00000000 ____D () C:\Program Files (x86)\Comodo2014-06-01 13:02 - 2014-06-01 13:02 - 00019720 _____ () C:\Users\Elizabeth\Downloads\Have I Got News For You s47e09.hannibal.torrent2014-06-01 13:01 - 2014-06-01 13:01 - 00019600 _____ () C:\Users\Elizabeth\Downloads\Have I Got News For You s47e08.hannibal.torrent2014-05-30 22:03 - 2014-05-30 22:03 - 00031638 _____ () C:\Users\Elizabeth\Downloads\A Very British Murder with Lucy Worsley - Series 1 (2013) [PDTV (XviD)][sUBS].torrent2014-05-30 20:37 - 2014-05-30 20:37 - 00021007 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e01.hannibal.torrent2014-05-30 20:37 - 2014-05-30 20:37 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e02.hannibal.torrent2014-05-30 20:36 - 2014-05-30 20:36 - 00021642 _____ () C:\Users\Elizabeth\Downloads\Only Connect - series 7 (2013) [PDTV(XviD)].torrent2014-05-28 19:58 - 2014-05-28 19:58 - 00020252 _____ () C:\Users\Elizabeth\Downloads\The Duchess of Malfi.HD.hannibal.torrent2014-05-28 19:55 - 2014-05-28 19:59 - 243283968 _____ () C:\Users\Elizabeth\Downloads\IC219.avi2014-05-28 19:54 - 2014-05-28 19:58 - 243746816 _____ () C:\Users\Elizabeth\Downloads\IC217.avi2014-05-27 20:43 - 2014-05-27 20:45 - 329862086 _____ () C:\Users\Elizabeth\Downloads\IC215.avi2014-05-27 20:38 - 2014-05-27 20:40 - 243292160 _____ () C:\Users\Elizabeth\Downloads\IC216.avi2014-05-27 20:37 - 2014-05-27 20:39 - 244226048 _____ () C:\Users\Elizabeth\Downloads\IC110.avi2014-05-23 20:57 - 2014-05-23 20:57 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e05.hannibal.torrent2014-05-23 20:57 - 2014-05-23 20:57 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e04.hannibal.torrent2014-05-23 20:56 - 2014-05-23 20:56 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e03.hannibal.torrent2014-05-23 20:56 - 2014-05-23 20:56 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e02.hannibal.torrent2014-05-23 20:15 - 2014-05-23 20:15 - 00019727 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e01.hannibal.torrent2014-05-21 19:59 - 2014-05-21 19:59 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\NVIDIA2014-05-21 19:51 - 2014-05-26 20:19 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\avidemux2014-05-21 19:51 - 2014-05-21 19:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (64bits)2014-05-21 19:51 - 2014-05-21 19:51 - 00000000 ____D () C:\Program Files\Avidemux 2.6 - 64bits2014-05-21 19:41 - 2014-05-21 19:43 - 16456460 _____ () C:\Users\Elizabeth\Downloads\avidemux_2.6.8_win64_v2.exe2014-05-21 19:40 - 2014-05-21 19:42 - 242352128 _____ () C:\Users\Elizabeth\Downloads\IC308.avi2014-05-21 19:36 - 2014-05-21 19:39 - 243767296 _____ () C:\Users\Elizabeth\Downloads\IC618.avi2014-05-21 19:33 - 2014-05-21 19:33 - 00001621 _____ () C:\Users\Elizabeth\Desktop\DivX Movies.lnk2014-05-21 19:33 - 2014-05-21 19:33 - 00001066 _____ () C:\Users\Public\Desktop\DivX Player.lnk2014-05-21 19:32 - 2014-05-21 19:33 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\DivX2014-05-21 19:32 - 2014-05-21 19:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX2014-05-21 19:32 - 2014-05-21 19:32 - 00001131 _____ () C:\Users\Public\Desktop\DivX Converter.lnk2014-05-21 19:32 - 2014-05-21 19:32 - 00000000 ____D () C:\Program Files\DivX2014-05-21 19:31 - 2014-05-21 19:33 - 00000000 ____D () C:\ProgramData\DivX2014-05-21 19:31 - 2014-05-21 19:33 - 00000000 ____D () C:\Program Files (x86)\DivX2014-05-21 19:31 - 2014-05-21 19:31 - 01001280 _____ (DivX, LLC) C:\Users\Elizabeth\Downloads\DivXWebPlayerInstaller.exe2014-05-21 19:30 - 2014-05-21 19:37 - 243724288 _____ () C:\Users\Elizabeth\Downloads\IC329.avi2014-05-19 10:14 - 2014-05-19 10:14 - 00015521 _____ () C:\Users\Elizabeth\Downloads\Peaky Blinders s01e01.hannibal.mkv.torrent2014-05-16 20:42 - 2014-05-16 20:42 - 00019840 _____ () C:\Users\Elizabeth\Downloads\Have I Got News For You s47e07.hannibal.torrent2014-05-16 01:32 - 2014-05-16 01:32 - 00289728 _____ () C:\Windows\Minidump\051614-21044-01.dmp2014-05-16 01:29 - 2014-05-16 01:29 - 00289728 _____ () C:\Windows\Minidump\051614-22994-01.dmp2014-05-16 01:28 - 2014-05-16 01:28 - 00000000 _____ () C:\Users\Elizabeth\AppData\Local\{0696DE3E-19AF-4D80-8B57-CEB9D467074D}2014-05-16 01:27 - 2014-05-16 01:27 - 00291792 _____ () C:\Windows\Minidump\051614-27003-01.dmp ==================== One Month Modified Files and Folders ======= 2014-06-15 19:22 - 2014-06-15 19:21 - 00017204 _____ () C:\Users\Elizabeth\Downloads\FRST.txt2014-06-15 19:22 - 2013-11-20 12:23 - 00000000 ____D () C:\Users\Elizabeth\AppData\Local\Temp2014-06-15 19:21 - 2014-06-15 19:21 - 02081280 _____ (Farbar) C:\Users\Elizabeth\Downloads\FRST64.exe2014-06-15 19:21 - 2014-06-15 19:21 - 00000000 ____D () C:\FRST2014-06-15 19:21 - 2014-06-15 18:34 - 00000000 ____D () C:\ProgramData\Bitmeter22014-06-15 19:18 - 2014-05-04 20:14 - 01442529 _____ () C:\Windows\system32\Drivers\sfi.dat2014-06-15 19:06 - 2013-11-22 13:33 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job2014-06-15 19:05 - 2014-06-15 19:05 - 00052736 _____ () C:\Users\Elizabeth\Downloads\Extras.Txt2014-06-15 19:04 - 2014-06-15 19:04 - 00095254 _____ () C:\Users\Elizabeth\Downloads\OTL.Txt2014-06-15 18:54 - 2014-06-15 18:54 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys2014-06-15 18:54 - 2014-06-15 18:54 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk2014-06-15 18:54 - 2014-06-15 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware2014-06-15 18:54 - 2014-06-15 18:54 - 00000000 ____D () C:\ProgramData\Malwarebytes2014-06-15 18:54 - 2014-06-15 18:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware2014-06-15 18:53 - 2014-06-15 18:53 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Elizabeth\Downloads\mbam-setup-2.0.2.1012.exe2014-06-15 18:52 - 2014-06-15 18:34 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\Bitmeter22014-06-15 18:50 - 2014-06-15 18:50 - 00380416 _____ () C:\Users\Elizabeth\Downloads\8frw3bx8.exe2014-06-15 18:49 - 2014-06-15 18:49 - 00602112 _____ (OldTimer Tools) C:\Users\Elizabeth\Downloads\OTL.exe2014-06-15 18:34 - 2014-06-15 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitMeter2014-06-15 18:34 - 2014-06-15 18:34 - 00000000 ____D () C:\Program Files (x86)\Codebox2014-06-15 18:34 - 2009-07-13 20:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup2014-06-15 18:33 - 2014-06-15 18:33 - 01360256 _____ () C:\Users\Elizabeth\Downloads\BitMeter2.zip2014-06-15 18:33 - 2010-08-28 13:59 - 01378637 _____ () C:\Users\Elizabeth\Downloads\BitMeterInstaller.exe2014-06-15 18:25 - 2014-06-15 18:25 - 00372376 _____ (AddGadgets.com) C:\Users\Elizabeth\Downloads\NetworkMeterVersion96.exe2014-06-15 17:35 - 2013-11-20 11:06 - 01595351 _____ () C:\Windows\WindowsUpdate.log2014-06-15 17:29 - 2013-11-22 13:40 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\Azureus2014-06-15 17:10 - 2009-07-13 21:45 - 00019136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A02014-06-15 17:10 - 2009-07-13 21:45 - 00019136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A02014-06-15 17:06 - 2013-11-22 13:33 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job2014-06-15 16:58 - 2013-11-21 15:49 - 00000000 ____D () C:\ProgramData\NVIDIA2014-06-15 16:58 - 2009-07-13 22:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT2014-06-15 16:58 - 2009-07-13 21:51 - 00021837 _____ () C:\Windows\setupact.log2014-06-15 16:57 - 2013-11-29 13:00 - 00000000 ____D () C:\ProgramData\MediaMall2014-06-15 16:49 - 2013-11-20 14:56 - 00237152 _____ () C:\Windows\PFRO.log2014-06-14 15:00 - 2014-06-14 15:00 - 00019334 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e08.hannibal.torrent2014-06-14 15:00 - 2014-06-14 15:00 - 00019334 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e07.hannibal.torrent2014-06-14 14:59 - 2014-06-14 14:59 - 00019334 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e06.hannibal.torrent2014-06-14 14:59 - 2014-06-14 14:59 - 00019327 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e05.hannibal.torrent2014-06-13 21:09 - 2014-06-13 21:09 - 00020930 _____ () C:\Users\Elizabeth\Downloads\Mock the Week s13e01.hannibal.torrent2014-06-12 21:25 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\rescache2014-06-12 20:29 - 2013-11-22 19:51 - 00000000 ____D () C:\Users\Elizabeth\AppData\Local\SugarSync2014-06-12 02:36 - 2014-05-04 20:12 - 00002013 _____ () C:\Users\Public\Desktop\GeekBuddy.lnk2014-06-12 02:36 - 2014-05-04 20:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo2014-06-11 09:09 - 2013-11-22 13:33 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk2014-06-11 03:05 - 2013-11-20 13:04 - 00000000 ____D () C:\Windows\system32\MRT2014-06-11 03:03 - 2013-11-20 13:04 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe2014-06-11 03:00 - 2014-05-06 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel2014-06-10 21:05 - 2014-06-10 21:05 - 00000373 _____ () C:\Users\Elizabeth\Documents\googleprob.txt2014-06-08 20:10 - 2014-06-08 20:10 - 00019487 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e04.hannibal.torrent2014-06-08 20:09 - 2014-06-08 20:09 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e03.hannibal.torrent2014-06-08 20:09 - 2014-06-08 20:09 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e03.hannibal (1).torrent2014-06-08 13:08 - 2014-06-08 13:03 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy2014-06-08 13:05 - 2014-06-08 13:02 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 22014-06-08 13:03 - 2014-06-08 13:03 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk2014-06-08 13:03 - 2014-06-08 13:03 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk2014-06-08 13:03 - 2014-06-08 13:03 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking2014-06-08 13:03 - 2014-06-08 13:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 22014-06-08 13:02 - 2014-06-08 13:01 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Elizabeth\Downloads\spybot-2.3.exe2014-06-08 02:13 - 2014-06-11 01:34 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll2014-06-08 02:08 - 2014-06-11 01:34 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll2014-06-07 17:19 - 2014-05-04 20:14 - 00048392 _____ (COMODO CA Limited) C:\Windows\SysWOW64\certsentry.dll2014-06-07 17:19 - 2014-05-04 20:11 - 00057096 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll2014-06-07 17:17 - 2014-06-07 17:17 - 00000000 ____D () C:\Program Files (x86)\Comodo2014-06-01 13:02 - 2014-06-01 13:02 - 00019720 _____ () C:\Users\Elizabeth\Downloads\Have I Got News For You s47e09.hannibal.torrent2014-06-01 13:01 - 2014-06-01 13:01 - 00019600 _____ () C:\Users\Elizabeth\Downloads\Have I Got News For You s47e08.hannibal.torrent2014-05-30 22:03 - 2014-05-30 22:03 - 00031638 _____ () C:\Users\Elizabeth\Downloads\A Very British Murder with Lucy Worsley - Series 1 (2013) [PDTV (XviD)][sUBS].torrent2014-05-30 20:37 - 2014-05-30 20:37 - 00021007 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e01.hannibal.torrent2014-05-30 20:37 - 2014-05-30 20:37 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s08e02.hannibal.torrent2014-05-30 20:36 - 2014-05-30 20:36 - 00021642 _____ () C:\Users\Elizabeth\Downloads\Only Connect - series 7 (2013) [PDTV(XviD)].torrent2014-05-30 03:21 - 2014-06-11 01:36 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll2014-05-30 03:02 - 2014-06-11 01:37 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb2014-05-30 03:02 - 2014-06-11 01:37 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll2014-05-30 02:45 - 2014-06-11 01:36 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll2014-05-30 02:39 - 2014-06-11 01:36 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll2014-05-30 02:39 - 2014-06-11 01:36 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll2014-05-30 02:38 - 2014-06-11 01:37 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll2014-05-30 02:28 - 2014-06-11 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll2014-05-30 02:27 - 2014-06-11 01:36 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll2014-05-30 02:24 - 2014-06-11 01:36 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll2014-05-30 02:21 - 2014-06-11 01:37 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe2014-05-30 02:21 - 2014-06-11 01:36 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe2014-05-30 02:20 - 2014-06-11 01:36 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll2014-05-30 02:18 - 2014-06-11 01:37 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll2014-05-30 02:11 - 2014-06-11 01:36 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe2014-05-30 02:08 - 2014-06-11 01:36 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll2014-05-30 02:06 - 2014-06-11 01:37 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll2014-05-30 02:02 - 2014-06-11 01:36 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb2014-05-30 01:55 - 2014-06-11 01:37 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll2014-05-30 01:49 - 2014-06-11 01:36 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll2014-05-30 01:46 - 2014-06-11 01:36 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll2014-05-30 01:44 - 2014-06-11 01:36 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll2014-05-30 01:44 - 2014-06-11 01:36 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll2014-05-30 01:43 - 2014-06-11 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll2014-05-30 01:42 - 2014-06-11 01:37 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll2014-05-30 01:38 - 2014-06-11 01:37 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll2014-05-30 01:35 - 2014-06-11 01:36 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe2014-05-30 01:34 - 2014-06-11 01:37 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll2014-05-30 01:33 - 2014-06-11 01:37 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll2014-05-30 01:30 - 2014-06-11 01:37 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll2014-05-30 01:29 - 2014-06-11 01:37 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll2014-05-30 01:28 - 2014-06-11 01:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe2014-05-30 01:27 - 2014-06-11 01:37 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll2014-05-30 01:24 - 2014-06-11 01:36 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll2014-05-30 01:23 - 2014-06-11 01:36 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl2014-05-30 01:16 - 2014-06-11 01:37 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll2014-05-30 01:10 - 2014-06-11 01:37 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll2014-05-30 01:06 - 2014-06-11 01:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll2014-05-30 01:04 - 2014-06-11 01:37 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll2014-05-30 01:02 - 2014-06-11 01:37 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll2014-05-30 00:56 - 2014-06-11 01:36 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll2014-05-30 00:56 - 2014-06-11 01:36 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll2014-05-30 00:54 - 2014-06-11 01:37 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll2014-05-30 00:50 - 2014-06-11 01:36 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll2014-05-30 00:49 - 2014-06-11 01:37 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl2014-05-30 00:43 - 2014-06-11 01:36 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll2014-05-30 00:40 - 2014-06-11 01:36 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll2014-05-30 00:30 - 2014-06-11 01:37 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll2014-05-30 00:21 - 2014-06-11 01:36 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll2014-05-30 00:15 - 2014-06-11 01:37 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll2014-05-30 00:13 - 2014-06-11 01:36 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll2014-05-30 00:13 - 2014-06-11 01:36 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll2014-05-28 19:59 - 2014-05-28 19:55 - 243283968 _____ () C:\Users\Elizabeth\Downloads\IC219.avi2014-05-28 19:58 - 2014-05-28 19:58 - 00020252 _____ () C:\Users\Elizabeth\Downloads\The Duchess of Malfi.HD.hannibal.torrent2014-05-28 19:58 - 2014-05-28 19:54 - 243746816 _____ () C:\Users\Elizabeth\Downloads\IC217.avi2014-05-27 20:45 - 2014-05-27 20:43 - 329862086 _____ () C:\Users\Elizabeth\Downloads\IC215.avi2014-05-27 20:40 - 2014-05-27 20:38 - 243292160 _____ () C:\Users\Elizabeth\Downloads\IC216.avi2014-05-27 20:39 - 2014-05-27 20:37 - 244226048 _____ () C:\Users\Elizabeth\Downloads\IC110.avi2014-05-26 20:19 - 2014-05-21 19:51 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\avidemux2014-05-23 20:57 - 2014-05-23 20:57 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e05.hannibal.torrent2014-05-23 20:57 - 2014-05-23 20:57 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e04.hannibal.torrent2014-05-23 20:56 - 2014-05-23 20:56 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e03.hannibal.torrent2014-05-23 20:56 - 2014-05-23 20:56 - 00019567 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e02.hannibal.torrent2014-05-23 20:15 - 2014-05-23 20:15 - 00019727 _____ () C:\Users\Elizabeth\Downloads\Only Connect s09e01.hannibal.torrent2014-05-21 19:59 - 2014-05-21 19:59 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\NVIDIA2014-05-21 19:51 - 2014-05-21 19:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (64bits)2014-05-21 19:51 - 2014-05-21 19:51 - 00000000 ____D () C:\Program Files\Avidemux 2.6 - 64bits2014-05-21 19:43 - 2014-05-21 19:41 - 16456460 _____ () C:\Users\Elizabeth\Downloads\avidemux_2.6.8_win64_v2.exe2014-05-21 19:42 - 2014-05-21 19:40 - 242352128 _____ () C:\Users\Elizabeth\Downloads\IC308.avi2014-05-21 19:39 - 2014-05-21 19:36 - 243767296 _____ () C:\Users\Elizabeth\Downloads\IC618.avi2014-05-21 19:37 - 2014-05-21 19:30 - 243724288 _____ () C:\Users\Elizabeth\Downloads\IC329.avi2014-05-21 19:33 - 2014-05-21 19:33 - 00001621 _____ () C:\Users\Elizabeth\Desktop\DivX Movies.lnk2014-05-21 19:33 - 2014-05-21 19:33 - 00001066 _____ () C:\Users\Public\Desktop\DivX Player.lnk2014-05-21 19:33 - 2014-05-21 19:32 - 00000000 ____D () C:\Users\Elizabeth\AppData\Roaming\DivX2014-05-21 19:33 - 2014-05-21 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX2014-05-21 19:33 - 2014-05-21 19:31 - 00000000 ____D () C:\ProgramData\DivX2014-05-21 19:33 - 2014-05-21 19:31 - 00000000 ____D () C:\Program Files (x86)\DivX2014-05-21 19:32 - 2014-05-21 19:32 - 00001131 _____ () C:\Users\Public\Desktop\DivX Converter.lnk2014-05-21 19:32 - 2014-05-21 19:32 - 00000000 ____D () C:\Program Files\DivX2014-05-21 19:31 - 2014-05-21 19:31 - 01001280 _____ (DivX, LLC) C:\Users\Elizabeth\Downloads\DivXWebPlayerInstaller.exe2014-05-19 10:14 - 2014-05-19 10:14 - 00015521 _____ () C:\Users\Elizabeth\Downloads\Peaky Blinders s01e01.hannibal.mkv.torrent2014-05-16 20:42 - 2014-05-16 20:42 - 00019840 _____ () C:\Users\Elizabeth\Downloads\Have I Got News For You s47e07.hannibal.torrent2014-05-16 01:32 - 2014-05-16 01:32 - 00289728 _____ () C:\Windows\Minidump\051614-21044-01.dmp2014-05-16 01:32 - 2013-11-20 11:03 - 457800814 _____ () C:\Windows\MEMORY.DMP2014-05-16 01:32 - 2013-11-20 11:03 - 00000000 ____D () C:\Windows\Minidump2014-05-16 01:29 - 2014-05-16 01:29 - 00289728 _____ () C:\Windows\Minidump\051614-22994-01.dmp2014-05-16 01:28 - 2014-05-16 01:28 - 00000000 _____ () C:\Users\Elizabeth\AppData\Local\{0696DE3E-19AF-4D80-8B57-CEB9D467074D}2014-05-16 01:27 - 2014-05-16 01:27 - 00291792 _____ () C:\Windows\Minidump\051614-27003-01.dmp Some content of TEMP:====================C:\Users\Elizabeth\AppData\Local\Temp\i4jdel0.exeC:\Users\Elizabeth\AppData\Local\Temp\procexp64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signedC:\Windows\System32\wininit.exe => File is digitally signedC:\Windows\SysWOW64\wininit.exe => File is digitally signedC:\Windows\explorer.exe => File is digitally signedC:\Windows\SysWOW64\explorer.exe => File is digitally signedC:\Windows\System32\svchost.exe => File is digitally signedC:\Windows\SysWOW64\svchost.exe => File is digitally signedC:\Windows\System32\services.exe => File is digitally signedC:\Windows\System32\User32.dll => File is digitally signedC:\Windows\SysWOW64\User32.dll => File is digitally signedC:\Windows\System32\userinit.exe => File is digitally signedC:\Windows\SysWOW64\userinit.exe => File is digitally signedC:\Windows\System32\rpcss.dll => File is digitally signedC:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-08 00:40 ==================== End Of Log ============================Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-06-2014Ran by Elizabeth at 2014-06-15 19:22:32Running from C:\Users\Elizabeth\DownloadsBoot Mode: Normal========================================================== ==================== Security Center ======================== ==================== Installed Programs ====================== Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.3.183.7 - Adobe Systems Incorporated)Adobe Reader XI (11.0.07) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)Avidemux 2.6 - 64bits (HKLM-x32\...\Avidemux 2.6 - 64bits (64-bit)) (Version: 2.6.8.9046 - )BitMeter (HKLM-x32\...\BitMeter) (Version: - )Canon MP560 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP560_series) (Version: - )COMODO Antivirus (HKLM\...\{2736B6BD-31EC-4FC8-A48C-F0A5C914C0B6}) (Version: 7.0.55655.4142 - COMODO Security Solutions Inc.)Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 33.1.0.0 - COMODO)DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.3.22 - DivX, LLC)GeekBuddy (HKLM\...\{3FFD7EE1-7D2D-4F57-ADF7-914CE0CAC616}) (Version: 4.13.104 - Comodo Security Solutions Inc)Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) HiddenMalwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) HiddenMicrosoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)NVIDIA 3D Vision Driver 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation)NVIDIA Control Panel 331.65 (Version: 331.65 - NVIDIA Corporation) HiddenNVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)NVIDIA Graphics Driver 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)NVIDIA HD Audio Driver 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) HiddenNVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165 - NVIDIA Corporation) HiddenNVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) HiddenPlayLater (HKLM-x32\...\{5ABDB125-7725-40B6-A1E3-B7D8BFFAA303}) (Version: 1.4.15 - MediaMall Technologies, Inc.)PlayOn (HKLM-x32\...\{9489257A-CED5-45E7-8D16-7B20A2E48744}) (Version: 3.8.14 - MediaMall Technologies, Inc.)ScanSnap (x32 Version: 5.1.30.19 - PFU Limited) HiddenScanSnap Manager (HKLM-x32\...\{DBCDB997-EEEB-4BE9-BAFF-26B4094DBDE6}) (Version: V5.1L30 - PFU)Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.3.39 - Safer-Networking Ltd.)SugarSync (HKLM-x32\...\SugarSync) (Version: 2.0.46.127183 - SugarSync, Inc.)TP-LINK TL-WDN3200 Driver (HKLM-x32\...\{C0C6BCBC-0884-4C66-B5EF-0B7668FE2B10}) (Version: 1.1.0 - TP-LINK)TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.1.0 - TP-LINK)VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) HiddenVisual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.3.0.0 - Azureus Software, Inc.) ==================== Restore Points ========================= Could not list Restore Points. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== 2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {10BAFF3E-ADA7-43E9-887F-1E01814BECAE} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-04-16] (COMODO)Task: {16B1E1E2-F6E5-4D63-B77D-F2477BF7CA4E} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-04-16] (COMODO)Task: {1CAC9922-FA1A-41EC-BD5C-74AF661B3A58} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exeTask: {6978169E-B576-442D-AC70-E8E29EB148F3} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exeTask: {85240FD8-3568-418A-A29F-B04ED39BFFC7} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exeTask: {9E01E993-01F3-455E-89B9-2C1922DD028E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-22] (Google Inc.)Task: {A7D96285-F4C3-4DD0-8CE3-D40A2B81BEAD} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-04-16] (COMODO)Task: {B4853E33-2F02-4CB8-BFD4-14578B5FBF43} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-22] (Google Inc.)Task: {DFD6C514-934E-4B91-8E50-31F5272B9061} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-04-16] (COMODO)Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exeTask: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-11-15 19:07 - 2014-05-06 11:03 - 00301920 _____ () C:\Program Files (x86)\SugarSync\x64\SugarSyncVFSNamespace64.dll2013-12-30 14:45 - 2012-02-23 12:09 - 00838656 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe2014-01-09 22:26 - 2014-01-09 22:26 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Elizabeth\Downloads\avg_remover_stf_x64_2014_4116.exe:BDUAlternateDataStreams: C:\Users\Elizabeth\Downloads\cav_installer.exe:BDU ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= Could not list Devices. Check "winmgmt" service or repair WMI. ==================== Event log errors: ========================= Application errors:==================Error: (06/04/2014 02:34:47 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )Description: The volume SugarSync Drive was not defragmented because an error was encountered: Incorrect function. (0x80070001) Error: (06/01/2014 05:12:40 PM) (Source: Application Error) (EventID: 1000) (User: )Description: Faulting application name: GoogleUpdate.exe, version: 1.3.21.103, time stamp: 0x4f3c6d6cFaulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7Exception code: 0xc0000005Fault offset: 0x000223e0Faulting process id: 0x1950Faulting application start time: 0xGoogleUpdate.exe0Faulting application path: GoogleUpdate.exe1Faulting module path: GoogleUpdate.exe2Report Id: GoogleUpdate.exe3 Error: (05/28/2014 08:20:21 PM) (Source: Application Error) (EventID: 1000) (User: )Description: Faulting application name: dragon_updater.exe, version: 0.0.0.0, time stamp: 0x535051ddFaulting module name: ole32.dll, version: 6.1.7601.17514, time stamp: 0x4ce7b96fException code: 0xc0000005Fault offset: 0x00039342Faulting process id: 0x71cFaulting application start time: 0xdragon_updater.exe0Faulting application path: dragon_updater.exe1Faulting module path: dragon_updater.exe2Report Id: dragon_updater.exe3 Error: (05/28/2014 02:58:06 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )Description: The volume SugarSync Drive was not defragmented because an error was encountered: Incorrect function. (0x80070001) Error: (05/26/2014 05:19:53 PM) (Source: Application Error) (EventID: 1000) (User: )Description: Faulting application name: GoogleUpdate.exe, version: 1.3.21.103, time stamp: 0x4f3c6d6cFaulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7Exception code: 0xc0000005Fault offset: 0x000223e0Faulting process id: 0x3310Faulting application start time: 0xGoogleUpdate.exe0Faulting application path: GoogleUpdate.exe1Faulting module path: GoogleUpdate.exe2Report Id: GoogleUpdate.exe3 Error: (05/23/2014 05:14:37 PM) (Source: Application Error) (EventID: 1000) (User: )Description: Faulting application name: GoogleUpdate.exe, version: 1.3.21.103, time stamp: 0x4f3c6d6cFaulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7Exception code: 0xc0000005Fault offset: 0x000223e0Faulting process id: 0x2d28Faulting application start time: 0xGoogleUpdate.exe0Faulting application path: GoogleUpdate.exe1Faulting module path: GoogleUpdate.exe2Report Id: GoogleUpdate.exe3 Error: (05/22/2014 05:12:06 PM) (Source: Application Error) (EventID: 1000) (User: )Description: Faulting application name: GoogleUpdate.exe, version: 1.3.21.103, time stamp: 0x4f3c6d6cFaulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521ea8e7Exception code: 0xc0000005Fault offset: 0x0002ff47Faulting process id: 0x1618Faulting application start time: 0xGoogleUpdate.exe0Faulting application path: GoogleUpdate.exe1Faulting module path: GoogleUpdate.exe2Report Id: GoogleUpdate.exe3 Error: (05/21/2014 07:33:08 PM) (Source: SideBySide) (EventID: 33) (User: )Description: Activation context generation failed for "Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195" could not be found.Please use sxstrace.exe for detailed diagnosis. Error: (05/21/2014 07:32:44 PM) (Source: SideBySide) (EventID: 33) (User: )Description: Activation context generation failed for "Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195" could not be found.Please use sxstrace.exe for detailed diagnosis. Error: (05/21/2014 03:29:21 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )Description: The volume SugarSync Drive was not defragmented because an error was encountered: Incorrect function. (0x80070001) System errors:=============Error: (06/15/2014 04:59:33 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (06/15/2014 04:59:13 PM) (Source: Service Control Manager) (EventID: 7009) (User: )Description: A timeout was reached (30000 milliseconds) while waiting for the MediaMall Server service to connect. Error: (06/15/2014 04:50:33 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (06/15/2014 04:50:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )Description: The Spybot-S&D 2 Scanner Service service failed to start due to the following error: %%1053 Error: (06/15/2014 04:50:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: )Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D 2 Scanner Service service to connect. Error: (06/11/2014 03:26:08 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (06/11/2014 03:25:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )Description: The Windows Search service failed to start due to the following error: %%1053 Error: (06/11/2014 03:25:49 AM) (Source: Service Control Manager) (EventID: 7009) (User: )Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. Error: (06/11/2014 03:25:49 AM) (Source: DCOM) (EventID: 10005) (User: )Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (06/10/2014 09:09:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Microsoft Office Sessions:=========================Error: (06/04/2014 02:34:47 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )Description: SugarSync DriveIncorrect function. (0x80070001) Error: (06/01/2014 05:12:40 PM) (Source: Application Error) (EventID: 1000) (User: )Description: GoogleUpdate.exe1.3.21.1034f3c6d6cntdll.dll6.1.7601.18247521ea8e7c0000005000223e0195001cf7df66fa1b850C:\Program Files (x86)\Google\Update\GoogleUpdate.exeC:\Windows\SysWOW64\ntdll.dll9be8c830-e9ea-11e3-a3d9-0000000000a9 Error: (05/28/2014 08:20:21 PM) (Source: Application Error) (EventID: 1000) (User: )Description: dragon_updater.exe0.0.0.0535051ddole32.dll6.1.7601.175144ce7b96fc00000050003934271c01cf70e1628fb760C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exeC:\Windows\syswow64\ole32.dll2a2075c0-e6e0-11e3-a3d9-0000000000a9 Error: (05/28/2014 02:58:06 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )Description: SugarSync DriveIncorrect function. (0x80070001) Error: (05/26/2014 05:19:53 PM) (Source: Application Error) (EventID: 1000) (User: )Description: GoogleUpdate.exe1.3.21.1034f3c6d6cntdll.dll6.1.7601.18247521ea8e7c0000005000223e0331001cf793f7124ee60C:\Program Files (x86)\Google\Update\GoogleUpdate.exeC:\Windows\SysWOW64\ntdll.dll9f533f60-e534-11e3-a3d9-0000000000a9 Error: (05/23/2014 05:14:37 PM) (Source: Application Error) (EventID: 1000) (User: )Description: GoogleUpdate.exe1.3.21.1034f3c6d6cntdll.dll6.1.7601.18247521ea8e7c0000005000223e02d2801cf76e3f1c643b0C:\Program Files (x86)\Google\Update\GoogleUpdate.exeC:\Windows\SysWOW64\ntdll.dll6400bc70-e2d8-11e3-a3d9-0000000000a9 Error: (05/22/2014 05:12:06 PM) (Source: Application Error) (EventID: 1000) (User: )Description: GoogleUpdate.exe1.3.21.1034f3c6d6cntdll.dll6.1.7601.18247521ea8e7c00000050002ff47161801cf761ac75e5870C:\Program Files (x86)\Google\Update\GoogleUpdate.exeC:\Windows\SysWOW64\ntdll.dlldf728250-e20e-11e3-a3d9-0000000000a9 Error: (05/21/2014 07:33:08 PM) (Source: SideBySide) (EventID: 33) (User: )Description: Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Program Files (x86)\DivX\DivX Player\DPXIconHandler.dll Error: (05/21/2014 07:32:44 PM) (Source: SideBySide) (EventID: 33) (User: )Description: Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll Error: (05/21/2014 03:29:21 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )Description: SugarSync DriveIncorrect function. (0x80070001) ==================== Memory info =========================== Percentage of memory in use: 56%Total physical RAM: 3838.55 MBAvailable physical RAM: 1663.7 MBTotal Pagefile: 7675.28 MBAvailable Pagefile: 4617.52 MBTotal Virtual: 8192 MBAvailable Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:501.46 GB) NTFS ==================== MBR & Partition Table ================== ========================================================Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 6FE17F47)Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Note: I uninstalled Vuze after I got to the end of the instructions and saw the warning. There are now no (or should be no) peer-to-peer apps running.
  8. in safe mode csrss.exe and winlogon look normal However when Win 7 64bit pc is booted into normal mode there is no description for either and no username. I can also not find the file location of either process. Have run malwarebytes in normal mode as well as Kapersky 6 and have not found a virus. Still suspicious though?
  9. RE: Winlogon.exe and csrss.exe infections Hello, I’m running XP Pro, SP3. I noticed in Glarysoft Pro 3 under processes these two items which appear to be Trojans from my research. One indicator is the executable path which is not my normal system32 folder which on my machine is E:\WINDOWS\system32 folder. The infections have the same file name but with two questionmarks in front. They are also the only two processes that have high priority. My windows system32 folder has the real winlogon.exe that is only 496kb versus the infection file which shows memory of 2554 kb. Same deal for csrss.exe which is 6kb versus the infection at 2764kb. I read that malware files are much larger than the real windows files. Under the Windows Task Manager, they cannot be ended because they are “critical” system processes nor could I end them in Glarysoft 3. Akso, these are not showing up on the attached DDS log. Infections Name Executable winlogon.exe \\??\E:\WINDOWS\system32\winlogon.exe csrss.exe \\??\E:\WINDOWS\system32\csrss.exe Also, are these processes legit as they have no information.: System System Idle Processes I read another thread for troubleshooting winlogon.exe in this forum and ran Roguekiller as was suggested and have attached the report but didn’t delete anything. Thought it might give an indication. I’m running a trial version of Kaspersky Pure 3.0 and MBAM Pro which hasn’t been automatically starting. A few weeks ago, I had to reinstall XP Pro which is why it is on my E partition. I tried to restore a registry backup from Glarysoft and when windows tried to load it would get into a reboot loop. I figured I had nuked the registry. The required dds and attach.txt logs are attached. Thanks! dds.txt attach.txt
  10. Hello All I'm trying to Remove a virus from my computer. I believe it is still on here because My mcafee will not run. I Followed instructions from a previous post and did a clean and also did the combo fix. the combo fix log i will list below. i need to know where to go from here. THanks for any Help you have Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4058.2856 [GMT -4:00] Running from: c:\users\Babiegryle\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892} FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Resident AV is active . . . ((((((((((((((((((((((((( Files Created from 2012-08-19 to 2012-09-19 ))))))))))))))))))))))))))))))) . . 2012-09-19 21:54 . 2012-09-19 21:54 -------- d-----w- c:\users\Kitashava\AppData\Local\temp 2012-09-19 21:54 . 2012-09-19 21:54 -------- d-----w- c:\users\Default\AppData\Local\temp 2012-09-19 20:12 . 2012-09-19 20:12 -------- d-----w- c:\program files (x86)\Sophos 2012-09-15 00:23 . 2012-09-15 00:32 -------- d-----w- C:\43afcb5cb37c354970d83a55 2012-09-15 00:22 . 2012-09-15 00:22 -------- d-----w- c:\program files (x86)\The Weather Channel 2012-09-15 00:22 . 2012-09-15 00:39 -------- d-----w- c:\program files (x86)\Moon Secure Antivirus 2012-09-15 00:21 . 2012-09-15 00:22 -------- d-----w- c:\users\Babiegryle\AppData\Local\The Weather Channel 2012-09-14 21:59 . 2012-09-14 21:59 73696 ----a-w- c:\program files (x86)\Mozilla Firefox\breakpadinjector.dll 2012-09-12 02:13 . 2012-08-02 17:58 574464 ----a-w- c:\windows\system32\d3d10level9.dll 2012-09-12 02:13 . 2012-08-02 16:57 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2012-09-12 02:13 . 2012-08-22 18:12 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-12 02:13 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys 2012-09-12 02:13 . 2012-08-22 18:12 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-12 02:12 . 2012-08-22 18:12 950128 ----a-w- c:\windows\system32\drivers\ndis.sys 2012-09-12 02:12 . 2012-07-04 20:26 41472 ----a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-10 23:03 . 2012-09-10 23:03 -------- d-----w- c:\program files (x86)\Security Task Manager 2012-09-10 19:16 . 2011-02-17 22:26 356352 ----a-w- c:\windows\eSellerateEngine.dll 2012-09-10 19:16 . 2011-02-17 22:26 81920 ----a-w- c:\windows\eSellerateControl350.dll 2012-09-10 19:16 . 2012-09-15 08:33 -------- d-----w- c:\program files (x86)\CSRSSRemoval Tool 2012-09-07 21:57 . 2012-09-07 21:58 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-09-07 21:57 . 2012-07-03 17:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-09-07 17:54 . 2012-09-07 17:54 -------- d-----w- C:\_OTL 2012-09-07 16:23 . 2009-06-29 16:44 487424 ----a-w- c:\windows\system32\drivers\stwrt64.sys 2012-09-07 16:23 . 2009-06-29 16:44 598016 ------w- c:\windows\system32\stapi64.dll 2012-09-07 16:23 . 2009-06-29 16:44 431616 ----a-w- c:\windows\system32\stcplx64.dll 2012-09-07 16:23 . 2009-06-29 16:44 1431040 ----a-w- c:\windows\system32\stapo64.dll 2012-09-07 16:23 . 2009-05-12 18:25 511488 ----a-w- c:\windows\SysWow64\ctapo32.dll 2012-09-07 16:23 . 2012-09-07 16:24 -------- d-----w- c:\program files\IDT 2012-09-07 16:20 . 2012-09-07 16:20 -------- d-----w- c:\program files (x86)\Dell Wireless 2012-09-07 16:20 . 2009-06-05 19:10 1478144 ----a-w- c:\windows\system32\athrx.sys 2012-09-07 14:25 . 2012-09-07 15:22 -------- d-----w- c:\program files (x86)\PC Cleaners 2012-09-07 13:48 . 2012-09-07 16:07 -------- d-----w- c:\users\Babiegryle\AppData\Local\LogMeIn Rescue Applet 2012-09-02 02:04 . 2012-09-02 02:04 -------- d-----w- c:\program files (x86)\NetRatingsNetSight 2012-09-01 04:37 . 2012-09-01 04:37 -------- d-----w- c:\program files (x86)\Citrix 2012-09-01 04:36 . 2012-09-01 04:36 -------- d-----w- c:\users\Babiegryle\AppData\Local\Citrix 2012-08-31 23:59 . 2012-09-19 21:06 -------- d-----w- c:\windows\system32\drivers\AVG 2012-08-31 23:59 . 2012-08-31 23:59 -------- d-----w- C:\$AVG 2012-08-31 23:07 . 2010-04-14 00:10 66040 ----a-w- c:\windows\system32\drivers\MOBK.sys 2012-08-31 23:07 . 2012-08-31 23:07 -------- d-----w- c:\program files (x86)\McAfee Online Backup 2012-08-31 23:07 . 2012-04-20 20:40 196440 ----a-w- c:\windows\system32\drivers\HipShieldK.sys 2012-08-31 23:07 . 2012-06-15 16:04 73096 ----a-w- c:\windows\system32\drivers\McPvDrv.sys 2012-08-31 23:07 . 2012-08-31 23:07 -------- d-----w- c:\users\Babiegryle\AppData\Local\McAfee Anti-Theft 2012-08-31 23:06 . 2012-06-22 11:37 10288 ----a-w- c:\windows\system32\drivers\mfeclnk.sys 2012-08-31 23:06 . 2012-06-22 11:40 69672 ----a-w- c:\windows\system32\drivers\cfwids.sys 2012-08-31 23:06 . 2012-06-22 11:36 106112 ----a-w- c:\windows\system32\drivers\mferkdet.sys 2012-08-31 23:06 . 2012-06-22 11:35 513456 ----a-w- c:\windows\system32\drivers\mfefirek.sys 2012-08-31 23:06 . 2012-06-22 11:34 300392 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2012-08-31 23:06 . 2012-08-31 23:07 -------- d-----w- c:\program files\McAfee 2012-08-31 23:00 . 2012-08-31 23:06 -------- d-----w- c:\program files (x86)\Common Files\McAfee 2012-08-31 23:00 . 2012-09-05 02:25 -------- d-----w- c:\program files (x86)\McAfee 2012-08-31 22:59 . 2012-06-22 11:38 177144 ----a-w- c:\windows\system32\mfevtps.exe 2012-08-30 23:07 . 2012-08-30 23:07 -------- d-----w- c:\users\Babiegryle\AppData\Local\CRE 2012-08-30 19:02 . 2012-08-30 19:02 -------- d-----w- c:\program files (x86)\Gophoto.it 2012-08-30 19:01 . 2012-08-30 21:49 -------- d-----w- c:\program files (x86)\1ClickDownload 2012-08-29 19:38 . 2012-08-31 22:24 -------- d-----w- c:\program files (x86)\Best Iso Recovery 2012-08-29 19:32 . 2012-08-31 22:24 -------- d-----w- c:\program files (x86)\Software Informer 2012-08-29 19:31 . 2012-08-29 19:31 -------- d-----w- c:\users\Babiegryle\AppData\Local\Wajam 2012-08-24 19:43 . 2012-08-24 19:43 384352 ----a-w- c:\windows\system32\drivers\avgtdia.sys 2012-08-23 15:58 . 2012-08-23 15:58 -------- d-----w- c:\program files (x86)\EasyBurner 2012-08-23 15:08 . 2012-08-23 15:08 -------- d-----w- c:\program files (x86)\ImgBurn 2012-08-21 14:04 . 2012-08-21 14:04 -------- d-----w- c:\users\Babiegryle\AppData\Local\Apps 2012-08-21 14:04 . 2012-08-21 14:04 -------- d-----w- c:\users\Babiegryle\AppData\Local\Deployment . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-19 20:12 . 2012-09-19 20:12 73728 ----a-r- c:\users\Babiegryle\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe 2012-09-19 20:12 . 2012-09-19 20:12 73728 ----a-r- c:\users\Babiegryle\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe 2012-09-19 20:12 . 2012-09-19 20:12 73728 ----a-r- c:\users\Babiegryle\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe 2012-09-12 10:41 . 2012-03-21 13:17 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2012-09-12 10:41 . 2012-03-25 23:27 4278384 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2012-09-12 10:30 . 2012-03-25 23:27 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-09-12 10:30 . 2012-03-21 13:06 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2012-09-12 02:22 . 2011-11-21 05:52 64462936 ----a-w- c:\windows\system32\MRT.exe 2012-09-03 00:06 . 2012-03-21 13:17 4278384 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-09-03 00:05 . 2012-03-21 13:07 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2012-08-28 22:27 . 2012-04-05 03:51 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-28 22:27 . 2011-11-17 15:38 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-23 08:26 . 2012-08-31 22:36 9310152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{45097542-7E51-4340-AFCF-D80D7A96E36D}\mpengine.dll 2012-08-21 09:13 . 2011-11-17 15:24 359464 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-08-21 09:13 . 2011-11-17 15:24 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-08-21 09:13 . 2011-11-17 15:24 969200 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-08-21 09:13 . 2012-03-05 02:43 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-08-21 09:13 . 2011-11-17 15:24 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-08-21 09:13 . 2011-11-17 15:24 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-08-21 09:12 . 2011-11-17 15:23 41224 ----a-w- c:\windows\avastSS.scr 2012-08-21 09:12 . 2011-11-17 15:23 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe 2012-08-21 09:12 . 2011-11-17 15:24 285328 ----a-w- c:\windows\system32\aswBoot.exe 2012-08-16 03:11 . 2012-03-25 23:28 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-08-16 03:10 . 2012-08-16 03:10 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2012-07-31 20:10 . 2012-07-31 20:10 5 ----a-w- c:\windows\SysWow64\lMMLDeleteUserData42107612FX.tmp 2012-07-26 07:21 . 2012-07-26 07:21 291680 ----a-w- c:\windows\system32\drivers\avgldx64.sys 2012-07-23 19:59 . 2011-11-17 17:25 24960 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe 2012-07-18 18:15 . 2012-08-14 18:43 3148800 ----a-w- c:\windows\system32\win32k.sys 2012-07-04 22:16 . 2012-08-14 18:44 73216 ----a-w- c:\windows\system32\netapi32.dll 2012-07-04 22:13 . 2012-08-14 18:44 136704 ----a-w- c:\windows\system32\browser.dll 2012-07-04 22:13 . 2012-08-14 18:44 59392 ----a-w- c:\windows\system32\browcli.dll 2012-07-04 21:14 . 2012-08-14 18:44 41984 ----a-w- c:\windows\SysWow64\browcli.dll 2012-06-29 04:55 . 2012-08-15 00:52 17809920 ----a-w- c:\windows\system32\mshtml.dll 2012-06-29 04:09 . 2012-08-15 00:52 10925568 ----a-w- c:\windows\system32\ieframe.dll 2012-06-29 03:56 . 2012-08-15 00:52 2312704 ----a-w- c:\windows\system32\jscript9.dll 2012-06-29 03:49 . 2012-08-15 00:52 1346048 ----a-w- c:\windows\system32\urlmon.dll 2012-06-29 03:49 . 2012-08-15 00:52 1392128 ----a-w- c:\windows\system32\wininet.dll 2012-06-29 03:48 . 2012-08-15 00:52 1494528 ----a-w- c:\windows\system32\inetcpl.cpl 2012-06-29 03:47 . 2012-08-15 00:52 237056 ----a-w- c:\windows\system32\url.dll 2012-06-29 03:45 . 2012-08-15 00:52 85504 ----a-w- c:\windows\system32\jsproxy.dll 2012-06-29 03:44 . 2012-08-15 00:52 816640 ----a-w- c:\windows\system32\jscript.dll 2012-06-29 03:43 . 2012-08-15 00:52 173056 ----a-w- c:\windows\system32\ieUnatt.exe 2012-06-29 03:42 . 2012-08-15 00:52 2144768 ----a-w- c:\windows\system32\iertutil.dll 2012-06-29 03:40 . 2012-08-15 00:52 96768 ----a-w- c:\windows\system32\mshtmled.dll 2012-06-29 03:39 . 2012-08-15 00:52 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2012-06-29 03:35 . 2012-08-15 00:52 248320 ----a-w- c:\windows\system32\ieui.dll 2012-06-29 00:16 . 2012-08-15 00:52 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll 2012-06-29 00:09 . 2012-08-15 00:52 1129472 ----a-w- c:\windows\SysWow64\wininet.dll 2012-06-29 00:08 . 2012-08-15 00:52 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2012-06-29 00:04 . 2012-08-15 00:52 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2012-06-29 00:00 . 2012-08-15 00:52 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb 2012-06-25 20:04 . 2012-06-25 20:04 1394248 ----a-w- c:\windows\SysWow64\msxml4.dll 2012-06-22 11:38 . 2012-06-22 11:38 335784 ----a-w- c:\windows\system32\drivers\mfewfpk.sys 2012-06-22 11:36 . 2012-06-22 11:36 752672 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2012-06-22 11:34 . 2012-06-22 11:34 169320 ----a-w- c:\windows\system32\drivers\mfeapfk.sys . . ((((((((((((((((((((((((((((( SnapShot@2012-09-07_20.20.49 ))))))))))))))))))))))))))))))))))))))))) . - 2009-07-14 04:54 . 2012-09-07 18:39 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-09-19 21:58 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-09-07 18:39 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-09-19 21:58 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-09-07 18:39 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-09-19 21:58 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-03-18 20:47 . 2010-03-18 20:47 17760 c:\windows\SysWOW64\aspnet_counters.dll + 2011-11-19 01:22 . 2012-09-19 21:59 50362 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-09-19 21:59 43904 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-11-17 19:24 . 2012-09-19 21:59 15980 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2626001246-2232820001-3214855623-1000_UserData.bin + 2009-07-14 05:30 . 2012-09-15 02:39 86016 c:\windows\system32\DriverStore\infpub.dat - 2009-07-14 05:30 . 2012-09-07 16:24 86016 c:\windows\system32\DriverStore\infpub.dat + 2009-07-14 00:09 . 2009-07-14 00:09 19968 c:\windows\system32\DriverStore\FileRepository\netrndis.inf_amd64_neutral_0b46e86f0f566f5a\usb8023x.sys + 2009-07-14 00:09 . 2009-07-14 00:09 19968 c:\windows\system32\DriverStore\FileRepository\netrndis.inf_amd64_neutral_0b46e86f0f566f5a\usb80236.sys + 2012-09-12 02:12 . 2012-07-04 20:26 41472 c:\windows\system32\DriverStore\FileRepository\netrndis.inf_amd64_neutral_0b46e86f0f566f5a\rndismpx.sys + 2012-09-12 02:12 . 2012-07-04 20:26 35840 c:\windows\system32\DriverStore\FileRepository\netrndis.inf_amd64_neutral_0b46e86f0f566f5a\rndismp6.sys + 2011-11-17 17:25 . 2012-09-19 21:30 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-11-17 17:25 . 2012-09-07 18:46 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-11-17 17:25 . 2012-09-19 21:30 49152 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-11-17 17:25 . 2012-09-07 18:46 49152 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-09-07 18:46 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-09-19 21:30 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-03-18 21:23 . 2010-03-18 21:23 20832 c:\windows\system32\aspnet_counters.dll - 2009-07-14 04:46 . 2012-08-27 23:53 94000 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2009-07-14 04:46 . 2012-09-17 21:21 94000 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2010-03-18 20:47 . 2010-03-18 20:47 97624 c:\windows\Microsoft.NET\Framework64\v4.0.30319\XamlBuildTask.dll + 2011-12-26 09:18 . 2011-12-26 09:18 16656 c:\windows\Microsoft.NET\Framework64\v4.0.30319\webengine.dll + 2010-03-18 21:23 . 2010-03-18 21:23 81224 c:\windows\Microsoft.NET\Framework64\v4.0.30319\TLBREF.DLL + 2010-03-18 20:47 . 2010-03-18 20:47 29544 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Xaml.Hosting.dll + 2010-03-18 20:47 . 2010-03-18 20:47 70040 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Windows.Forms.DataVisualization.Design.dll + 2010-03-18 20:47 . 2010-03-18 20:47 24928 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Routing.dll + 2010-03-18 20:47 . 2010-03-18 20:47 81272 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.RegularExpressions.dll + 2010-03-18 20:47 . 2010-03-18 20:47 33144 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.DynamicData.Design.dll + 2010-03-18 20:47 . 2010-03-18 20:47 93576 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.DataVisualization.Design.dll + 2010-03-18 20:47 . 2010-03-18 20:47 24944 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Web.Abstractions.dll + 2010-03-18 20:47 . 2010-03-18 20:47 28024 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.WasHosting.dll + 2010-03-18 20:47 . 2010-03-18 20:47 12168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.ServiceModel.ServiceMoniker40.dll + 2011-05-17 12:44 . 2011-05-17 12:44 98152 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Runtime.Caching.dll + 2010-03-18 20:47 . 2010-03-18 20:47 86888 c:\windows\Microsoft.NET\Framework64\v4.0.30319\System.Drawing.Design.dll + 2010-03-18 19:58 . 2010-03-18 19:58 96088 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\SetupUtility.exe + 2010-03-18 20:16 . 2010-03-18 20:16 78152 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\Setup.exe + 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\3082\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 14168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\3076\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 18776 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\2070\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 14168 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\2052\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1055\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1053\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1049\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1046\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 18264 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1045\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 17752 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1044\SetupResources.dll + 2010-03-18 20:16 . 2010-03-18 20:16 19288 c:\windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\1043\SetupResources.dll Attaching the file because the length is so long.
  11. My computer has been doing a lot of strange things - freezing up a lot too. I found "csrss.exe" on the Task Manager; looked it up and was told it is malware. Ran Malwarebytes. csrss.exe is still there. Now what do I do? Thanks
  12. I recently downloaded Malwarebytes after Norton 360 kept telling me that I was getting attacked by a worm. I thought with Norton 360 I was protected from everything, but it appears not. After downloading Malwarebytes I ran a few scans and had to restart my computer a few times. I have run into 8 files that keep coming up on the scan. Here is the log: Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.25.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Owner :: OWNER-PC [administrator] 26/05/2012 3:07:26 PM 1.txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 207390 Time elapsed: 2 minute(s), 22 second(s) Memory Processes Detected: 3 C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 3412 -> No action taken. C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 3424 -> No action taken. C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 2776 -> No action taken. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> No action taken. Registry Values Detected: 2 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|msvcnp (Backdoor.Agent) -> Data: C:\Users\Owner\AppData\Roaming\msvcnp .exe -> No action taken. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|csrss (Trojan.Agent) -> Data: C:\Users\Owner\AppData\Roaming\csrss .exe -> No action taken. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Windows\Temp\svchost.exe (Trojan.Agent) -> No action taken. C:\Users\Owner\AppData\Roaming\csrss .exe (Trojan.Agent) -> No action taken. (end) Here is the removal log of the same files. A popup also appears telling me to restart my computer. Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.05.25.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Owner :: OWNER-PC [administrator] 26/05/2012 3:07:26 PM mbam-log-2012-05-26 (15-07-26).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 207390 Time elapsed: 2 minute(s), 22 second(s) Memory Processes Detected: 3 C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 3412 -> Delete on reboot. C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 3424 -> Delete on reboot. C:\Windows\Temp\svchost.exe (Trojan.Agent) -> 2776 -> Delete on reboot. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Detected: 2 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|msvcnp (Backdoor.Agent) -> Data: C:\Users\Owner\AppData\Roaming\msvcnp .exe -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|csrss (Trojan.Agent) -> Data: C:\Users\Owner\AppData\Roaming\csrss .exe -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Windows\Temp\svchost.exe (Trojan.Agent) -> Delete on reboot. C:\Users\Owner\AppData\Roaming\csrss .exe (Trojan.Agent) -> Quarantined and deleted successfully. (end) After restarting my computer, the same 8 files appear in the next scan. Is there anything I can do to stop this? I had problems before with a file called update.exe appearing in my Roaming folder. When I deleted it, it would just appear again after a few seconds. So I deleted it and then put a folder in Roaming called update.exe. This stopped the file from appearing. Any input or help is appreciated.
  13. Merged post This started happening earlier this week, although I can't pinpoint any action I took on or offline. It has got up to over a thousand instances of csrss.exe, but they are all from the system32 directory. I have process explorer, they list no parents either. They don't take any visible cpu in taskmgr. Baffled. Here is the DDS and attach . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_29 Run by Nick at 20:28:05 on 2012-04-09 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8145.5856 [GMT -7:00] . AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D} FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe C:\Program Files\Bonjour\mDNSResponder.exe E:\Program Files (x86)\Sync\SeagateDriveSettingsService.exe C:\Windows\System32\svchost.exe -k ipripsvc C:\Windows\System32\svchost.exe -k LPDService C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe C:\Windows\SysWOW64\vmnat.exe C:\Windows\SysWOW64\vmnetdhcp.exe C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Program Files\Core Temp\Core Temp.exe C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files\Logitech\SetPointP\SetPoint.exe C:\Windows\System32\rundll32.exe C:\Program Files\Logitech\Gaming Software\LWEMon.exe C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE E:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe C:\Program Files (x86)\Razer\Mamba\RazerMambaSysTray.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe C:\Windows\SysWOW64\WinMsgBalloonServer.exe C:\Windows\SysWOW64\WinMsgBalloonClient.exe C:\Windows\SysWOW64\BeepApp.exe C:\Windows\system32\conhost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\conhost.exe E:\Program Files\Wireshark\wireshark.exe E:\Program Files\Wireshark\dumpcap.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe E:\Downloads\HijackThis.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Users\Nick\Desktop\Process Explorer\procexp.exe C:\Users\Nick\Desktop\Process Explorer\procexp64.exe C:\Windows\system32\taskmgr.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local BHO: SteadyVideoBHO Class: {6c680bae-655c-4e3d-8fc4-e6a520c3d928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO: Foxit PDF Creator Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Foxit PDF Creator Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe mRun: [VirtualCloneDrive] "E:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe" /s mRun: [Razer Mamba Elite Driver] C:\Program Files (x86)\Razer\Mamba\RazerMambaSysTray.exe mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mRun: [iJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll LSP: %SystemRoot%\system32\vsocklib.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab TCP: Interfaces\{69A718A6-5D13-437D-B43C-014945C43E28} : NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{8B5734B2-6B73-4F5C-9773-863D012539DE} : DhcpNameServer = 172.26.38.1 172.26.38.2 TCP: Interfaces\{8E0F0A4D-1465-4FF3-8B20-2BDCEBBA49A8} : DhcpNameServer = 172.26.38.1 172.26.38.2 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL BHO-X64: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll BHO-X64: AMD SteadyVideo BHO - No File BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO-X64: SkypeIEPluginBHO - No File BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Foxit PDF Creator Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll BHO-X64: Ask Toolbar BHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: Foxit PDF Creator Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll mRun-x64: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe mRun-x64: [VirtualCloneDrive] "E:\Program Files (x86)\VirtualCloneDrive\VCDDaemon.exe" /s mRun-x64: [Razer Mamba Elite Driver] C:\Program Files (x86)\Razer\Mamba\RazerMambaSysTray.exe mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mRun-x64: [iJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE mRun-x64: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun AppInit_DLLs-X64: C:\Windows\SysWOW64\guard32.dll SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL . ============= SERVICES / DRIVERS =============== . R0 ahcix64;ahcix64;C:\Windows\system32\DRIVERS\ahcix64.sys --> C:\Windows\system32\DRIVERS\ahcix64.sys [?] R0 ahcix64s;ahcix64s;C:\Windows\system32\DRIVERS\ahcix64s.sys --> C:\Windows\system32\DRIVERS\ahcix64s.sys [?] R0 AiChargerPlus;ASUS Charger Plus Driver;C:\Windows\system32\DRIVERS\AiChargerPlus.sys --> C:\Windows\system32\DRIVERS\AiChargerPlus.sys [?] R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys --> C:\Windows\system32\DRIVERS\avkmgr.sys [?] R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?] R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?] R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-2-14 361984] R2 AMD_RAIDXpert;AMD RAIDXpert;C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe [2010-6-21 128904] R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-2-9 86224] R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-2-9 110032] R2 AODDriver4.01;AODDriver4.01;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-1-3 55936] R2 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-3 918144] R2 asHmComSvc;ASUS HM Com Service;C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-1 915584] R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2011-10-12 586880] R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys --> C:\Windows\system32\DRIVERS\avgntflt.sys [?] R2 cpuz135;cpuz135;\??\C:\Windows\system32\drivers\cpuz135_x64.sys --> C:\Windows\system32\drivers\cpuz135_x64.sys [?] R2 FreeAgentGoFlex Service;Seagate Drive Settings Service;E:\Program Files (x86)\Sync\SeagateDriveSettingsService.exe [2011-2-10 91432] R2 iprip;RIP Listener;C:\Windows\System32\svchost.exe -k ipripsvc [2009-7-13 20992] R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-8-22 846448] R2 VMwareHostd;VMware Workstation Server;C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2011-8-22 11837440] R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\system32\DRIVERS\asmthub3.sys --> C:\Windows\system32\DRIVERS\asmthub3.sys [?] R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\system32\DRIVERS\asmtxhci.sys --> C:\Windows\system32\DRIVERS\asmtxhci.sys [?] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?] R3 ksaud;Creative USB Audio Driver;C:\Windows\system32\drivers\ksaud.sys --> C:\Windows\system32\drivers\ksaud.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?] S2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-1-3 55936] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 copperhd;Razer Copperhead Driver;C:\Windows\system32\drivers\copperhd.sys --> C:\Windows\system32\drivers\copperhd.sys [?] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-10-19 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-10-19 79360] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536] S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?] S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\rtl8187.sys --> C:\Windows\system32\DRIVERS\rtl8187.sys [?] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?] . =============== Created Last 30 ================ . 2012-04-05 03:19:41 3145728 ----a-w- C:\Windows\System32\win32k.sys 2012-04-05 03:19:40 1544192 ----a-w- C:\Windows\System32\DWrite.dll 2012-04-05 03:19:40 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll 2012-04-05 03:19:20 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe 2012-04-05 03:19:20 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll 2012-04-05 03:19:20 77312 ----a-w- C:\Windows\System32\rdpwsx.dll 2012-04-05 03:19:20 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys 2012-04-05 03:19:20 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-04-05 03:19:20 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll 2012-04-05 03:19:20 1031680 ----a-w- C:\Windows\System32\rdpcore.dll 2012-04-05 02:06:32 -------- d-----w- C:\Users\Nick\AppData\Roaming\Malwarebytes 2012-04-05 02:06:29 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys 2012-04-05 02:06:29 -------- d-----w- C:\ProgramData\Malwarebytes 2012-04-05 02:06:29 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-04-04 02:52:39 49664 ----a-w- C:\Windows\System32\CamCodec.dll 2012-03-30 02:09:32 -------- d-----w- C:\Program Files (x86)\Ask.com 2012-03-23 00:49:01 -------- d-----w- C:\Users\Nick\AppData\Roaming\COMODO 2012-03-18 06:27:10 -------- d-----w- C:\Users\Nick\AppData\Roaming\Xilisoft 2012-03-18 06:25:48 -------- d-----w- C:\ProgramData\Xilisoft 2012-03-17 05:06:47 592824 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll 2012-03-17 05:06:47 44472 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll 2012-03-15 02:56:34 -------- d-----w- C:\Program Files\CCleaner 2012-03-15 02:54:28 -------- d-----w- C:\Program Files (x86)\AMD AVT 2012-03-15 02:54:27 -------- d-----w- C:\Program Files\AMD 2012-03-15 02:54:26 -------- d-----w- C:\Program Files (x86)\AMD APP 2012-03-13 23:50:40 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation 2012-03-13 23:39:28 -------- d-----w- C:\Program Files (x86)\Mass Effect 3 . ==================== Find3M ==================== . 2012-03-11 21:13:41 43248 ----a-w- C:\Windows\System32\drivers\cmdhlp.sys 2012-03-11 21:13:40 577824 ----a-w- C:\Windows\System32\drivers\cmdGuard.sys 2012-03-11 21:13:38 22696 ----a-w- C:\Windows\System32\drivers\cmderd.sys 2012-03-11 21:13:20 41200 ----a-w- C:\Windows\System32\cmdcsr.dll 2012-03-11 21:13:18 301224 ----a-w- C:\Windows\SysWow64\guard32.dll 2012-03-11 21:13:17 389840 ----a-w- C:\Windows\System32\guard64.dll 2012-02-15 05:05:32 69632 ----a-w- C:\Windows\System32\OpenVideo64.dll 2012-02-15 05:05:26 59904 ----a-w- C:\Windows\SysWow64\OpenVideo.dll 2012-02-15 05:05:20 61952 ----a-w- C:\Windows\System32\OVDecode64.dll 2012-02-15 05:05:16 54784 ----a-w- C:\Windows\SysWow64\OVDecode.dll 2012-02-15 05:05:08 16507904 ----a-w- C:\Windows\System32\amdocl64.dll 2012-02-15 05:04:26 13238272 ----a-w- C:\Windows\SysWow64\amdocl.dll 2012-02-15 05:03:44 54272 ----a-w- C:\Windows\System32\OpenCL.dll 2012-02-15 05:03:38 48128 ----a-w- C:\Windows\SysWow64\OpenCL.dll 2012-02-15 03:48:32 10856960 ----a-w- C:\Windows\System32\drivers\atikmdag.sys 2012-02-15 03:21:24 25839104 ----a-w- C:\Windows\System32\atio6axx.dll 2012-02-15 03:18:56 159744 ----a-w- C:\Windows\System32\atiapfxx.exe 2012-02-15 03:18:40 791040 ----a-w- C:\Windows\SysWow64\aticfx32.dll 2012-02-15 03:17:04 957952 ----a-w- C:\Windows\System32\aticfx64.dll 2012-02-15 03:13:56 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll 2012-02-15 03:13:40 496128 ----a-w- C:\Windows\System32\atieclxx.exe 2012-02-15 03:13:00 235520 ----a-w- C:\Windows\System32\atiesrxx.exe 2012-02-15 03:11:42 120320 ----a-w- C:\Windows\System32\atitmm64.dll 2012-02-15 03:10:58 21504 ----a-w- C:\Windows\System32\atimuixx.dll 2012-02-15 03:10:54 59392 ----a-w- C:\Windows\System32\atiedu64.dll 2012-02-15 03:10:48 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll 2012-02-15 03:07:44 6200320 ----a-w- C:\Windows\SysWow64\atidxx32.dll 2012-02-15 02:58:56 19392000 ----a-w- C:\Windows\SysWow64\atioglxx.dll 2012-02-15 02:52:28 7646208 ----a-w- C:\Windows\System32\atidxx64.dll 2012-02-15 02:41:28 1113088 ----a-w- C:\Windows\System32\atiumd6v.dll 2012-02-15 02:40:54 1828864 ----a-w- C:\Windows\SysWow64\atiumdmv.dll 2012-02-15 02:40:42 4958208 ----a-w- C:\Windows\System32\atiumd6a.dll 2012-02-15 02:34:56 51200 ----a-w- C:\Windows\System32\aticalrt64.dll 2012-02-15 02:34:54 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll 2012-02-15 02:34:46 44544 ----a-w- C:\Windows\System32\aticalcl64.dll 2012-02-15 02:34:44 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll 2012-02-15 02:34:36 5954048 ----a-w- C:\Windows\SysWow64\atiumdag.dll 2012-02-15 02:34:30 13859840 ----a-w- C:\Windows\System32\aticaldd64.dll 2012-02-15 02:29:52 5062656 ----a-w- C:\Windows\SysWow64\atiumdva.dll 2012-02-15 02:29:50 11561984 ----a-w- C:\Windows\SysWow64\aticaldd.dll 2012-02-15 02:25:06 7551488 ----a-w- C:\Windows\System32\atiumd64.dll 2012-02-15 02:16:38 58880 ----a-w- C:\Windows\System32\coinst.dll 2012-02-15 02:14:00 512000 ----a-w- C:\Windows\System32\atiadlxx.dll 2012-02-15 02:13:50 356352 ----a-w- C:\Windows\SysWow64\atiadlxy.dll 2012-02-15 02:13:36 17408 ----a-w- C:\Windows\System32\atig6pxx.dll 2012-02-15 02:13:32 14336 ----a-w- C:\Windows\SysWow64\atiglpxx.dll 2012-02-15 02:13:32 14336 ----a-w- C:\Windows\System32\atiglpxx.dll 2012-02-15 02:13:28 39936 ----a-w- C:\Windows\System32\atig6txx.dll 2012-02-15 02:13:20 33280 ----a-w- C:\Windows\SysWow64\atigktxx.dll 2012-02-15 02:13:12 327680 ----a-w- C:\Windows\System32\drivers\atikmpag.sys 2012-02-15 02:12:22 43008 ----a-w- C:\Windows\System32\atiuxp64.dll 2012-02-15 02:12:14 33280 ----a-w- C:\Windows\SysWow64\atiuxpag.dll 2012-02-15 02:12:08 39936 ----a-w- C:\Windows\System32\atiu9p64.dll 2012-02-15 02:12:00 30208 ----a-w- C:\Windows\SysWow64\atiu9pag.dll 2012-02-15 02:11:22 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll 2012-02-15 02:11:16 54784 ----a-w- C:\Windows\System32\atimpc64.dll 2012-02-15 02:11:16 54784 ----a-w- C:\Windows\System32\amdpcom64.dll 2012-02-15 02:11:10 53760 ----a-w- C:\Windows\SysWow64\atimpc32.dll 2012-02-15 02:11:10 53760 ----a-w- C:\Windows\SysWow64\amdpcom32.dll 2012-01-31 13:02:26 21504 ----a-w- C:\Windows\System32\kdbsdk64.dll 2012-01-31 13:00:24 16896 ----a-w- C:\Windows\SysWow64\kdbsdk32.dll 2011-09-11 18:52:11 94 ----a-w- C:\Program Files (x86)\visit-forum.bat 2011-09-11 15:46:59 354 ----a-w- C:\Program Files (x86)\cod4key.reg 2011-09-08 04:11:32 292184 ----a-w- C:\Program Files (x86)\dxwebsetup.exe . ============= FINISH: 20:28:40.40 =============== Nothing? \
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.