Jump to content

Infected computer need help


Recommended Posts

Hi! 

 

I hope you don't mind me hijacking your thread, but I'm having the same problem, and have followed the steps outlined above. Here is the output I've generated:

via Rkill: 
 

Rkill 2.6.2 by Lawrence Abrams (Grinler)
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 11/20/2013 12:17:07 PM in x64 mode.
Windows Version: Windows 8 
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * No malware processes found to kill.
 
Checking Registry for malware related settings:
 
 * Explorer Policy Removed:  NoActiveDesktopChanges [HKLM]
 
Backup Registry file created at:
 C:\Users\Naima\Desktop\rkill\rkill-11-20-2013-12-17-15.reg
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * Windows Defender Disabled
 
   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001
 
Checking Windows Service Integrity: 
 
 * No issues found.
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * No issues found.
 
Program finished at: 11/20/2013 12:18:55 PM
Execution time: 0 hours(s), 1 minute(s), and 48 seconds(s)
 
 
 
 
and via Rogue Killer: 
 
RogueKiller V8.7.8 _x64_ [Nov 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
 
Operating System : Windows 8 (6.2.9200 ) 64 bits version
Started in : Normal mode
User : Naima [Admin rights]
Mode : Scan -- Date : 11/20/2013 12:32:50
| ARK || FAK || MBR |
 
¤¤¤ Bad processes : 0 ¤¤¤
 
¤¤¤ Registry Entries : 3 ¤¤¤
[PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:49280;hxxps=127.0.0.1:49280 [Country: (Private Address) (XX), City: (Private Address)]) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
 
¤¤¤ Scheduled tasks : 0 ¤¤¤
 
¤¤¤ Startup Entries : 0 ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ Particular Files / Folders: ¤¤¤
 
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
 
¤¤¤ External Hives: ¤¤¤
 
¤¤¤ Infection :  ¤¤¤
 
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
 
 
 
 
¤¤¤ MBR Check: ¤¤¤
 
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD5000AAKX-22ERMA0 +++++
--- User ---
[MBR] f7a04f3e15587fab8bfae5d99b01237b
[bSP] eb91e1a3123f4f6989d4b0b321b3318a : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!
 
Finished : << RKreport[0]_S_11202013_123250.txt >>
 
 
 
How should I proceed? 
 
I notice that it says Windows Defender is deactivated in the registry, but I've tried multiple times to activate it, even before the bug, it seemed to say it was active in some places, and inactive in others.
 
Should I simply edit the registry value' "DisableAntiSpyware" = dword:00000001' to 00000000 ? 
 
TIA!
 
Link to post
Share on other sites

Hello and post-32477-1261866970.gif

 

P2P/Piracy Warning:

 

   

If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the policy on Piracy.

 

Next,

 

Download Farbar Recovery Scan Tool and save it to your desktop.

 

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

 

Next,

 

Download Security Check by screen317 from either of the following:
http://screen317.spywareinfoforum.org/SecurityCheck.exe or http://screen317.changelog.fr/SecurityCheck.exe
Save it to your Desktop. (If your security alerts either accept the alert, or turn the security off while Secuirity Check runs)
Double click SecurityCheck.exe (Vista or Windows 7 users right click and select "Run as Administrator") and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
 

Post those logs...

 

Kevin

Link to post
Share on other sites

from Farbar: 

 

  Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2013

Ran by Naima (administrator) on NAIMAS on 23-11-2013 04:14:00
Running from C:\Users\Naima\Desktop
Windows 8 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.165\GoogleCrashHandler64.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
(Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\regedit.exe
() C:\Users\Naima\Downloads\RogueKillerX64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12921488 2012-07-02] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareTray.exe [2493272 2013-10-18] ()
HKLM-x32\...\Run: [startCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-11-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2994880 2012-08-15] (Symantec Corporation)
HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [dnsshield] - C:\Program Files (x86)\Social Privacy  DNS\dnswatch.exe [147456 2013-10-27] ()
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-10-17] (Adobe Systems Incorporated)
AppInit_DLLs:   [ ] ()
 
==================== Internet (Whitelisted) ====================
 
ProxyServer: http=127.0.0.1:49280;https=127.0.0.1:49280
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope {66D0D484-C76F-439A-A558-06B7D0A62EA4} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAGWJS
SearchScopes: HKLM - {66D0D484-C76F-439A-A558-06B7D0A62EA4} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAGWJS
SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://us.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 - {66D0D484-C76F-439A-A558-06B7D0A62EA4} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAGWJS
SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://us.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKCU - DefaultScope {66D0D484-C76F-439A-A558-06B7D0A62EA4} URL = 
SearchScopes: HKCU - {66D0D484-C76F-439A-A558-06B7D0A62EA4} URL = 
SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://us.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKCU - {F96F9252-9772-4B38-A79C-0D5582623664} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289663&CUI=UN27321531082059620&UM=2
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: ScorpionSaver - {10AD2C61-0898-4348-8600-14A342F22AC3} - C:\Program Files (x86)\ScorpionSaver\IECore.dll ()
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\IPSBHO.dll (Symantec Corporation)
BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{97e1de57-d6fa-11e1-be62-806e6f6e6963}: [NameServer]8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{B5B6E80B-A4BF-4B04-90ED-573BA531BD03}: [NameServer]8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{C02CAB3E-C922-4371-A1DD-E72CF76EF979}: [NameServer]8.8.8.8,8.8.4.4
 
Chrome: 
=======
CHR Extension: (Google Docs) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Social Privacy) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfaifkapfifnanhhiidacmhldddojchn\1.0_0
CHR Extension: (Google Search) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Retro Robots Theme) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejiklfknjocjccolialojlfhliacoeoo\1.1_0
CHR Extension: (Norton Identity Protection) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.0.27_0
CHR Extension: (Google Wallet) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (GreatArcadeHits Add-on) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcogajbgikalbpphmoedjlcfjkhgh\1.0.0_0
CHR Extension: (Gmail) - C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\Exts\Chrome.crx
 
==================== Services (Whitelisted) =================
 
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [240736 2013-10-07] (WildTangent)
R2 HPSLPSVC; C:\Users\Dana\AppData\Local\Temp\7zS61FB\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.)
R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareService.exe [517344 2013-10-18] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe [275696 2013-10-08] (Symantec Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-09-17] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-01] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [96768 2012-11-06] (Advanced Micro Devices)
R3 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20131114.001\BHDrvx64.sys [1524824 2013-11-01] (Symantec Corporation)
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-25] (Symantec Corporation)
R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-25] (Symantec Corporation)
R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-20] (Symantec Corporation)
U3 EraserUtilDrv11312; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11312.sys [137648 2013-11-20] (Symantec Corporation)
R3 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20131122.001\IDSvia64.sys [521816 2013-11-19] (Symantec Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20131121.023\ENG64.SYS [126040 2013-11-20] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20131121.023\EX64.SYS [2099288 2013-11-20] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-26] (Symantec Corporation)
R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-09] (Symantec Corporation)
R3 SymDS; C:\Windows\system32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-09] (Symantec Corporation)
R3 SymEFA; C:\Windows\system32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-26] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NISx64\1501000.012\SymELAM.sys [23568 2013-09-09] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-19] (Symantec Corporation)
R3 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-26] (Symantec Corporation)
R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-25] (Symantec Corporation)
R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [329800 2013-07-17] (BitDefender S.R.L.)
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2013-11-23 04:14 - 2013-11-23 04:17 - 00015999 _____ C:\Users\Naima\Desktop\FRST.txt
2013-11-23 04:13 - 2013-11-23 04:13 - 00000000 ____D C:\FRST
2013-11-23 03:52 - 2013-11-23 03:52 - 01957916 _____ (Farbar) C:\Users\Naima\Desktop\FRST64.exe
2013-11-20 12:32 - 2013-11-20 12:32 - 00001593 _____ C:\Users\Naima\Desktop\RKreport[0]_S_11202013_123250.txt
2013-11-20 12:28 - 2013-11-20 12:32 - 00000000 ____D C:\Users\Naima\Desktop\RK_Quarantine
2013-11-20 12:27 - 2013-11-20 12:27 - 04161024 _____ C:\Users\Naima\Downloads\RogueKillerX64.exe
2013-11-20 12:21 - 2013-11-20 12:22 - 251139748 _____ C:\Users\Naima\Desktop\REGISTRY_BACKUP.reg
2013-11-20 12:17 - 2013-11-20 12:18 - 00002426 _____ C:\Users\Naima\Desktop\Rkill.txt
2013-11-20 12:17 - 2013-11-20 12:17 - 00000000 ____D C:\Users\Naima\Desktop\rkill
2013-11-20 12:16 - 2013-11-20 12:16 - 01898232 _____ (Bleeping Computer, LLC) C:\Users\Naima\Downloads\rkill.exe
2013-11-20 07:36 - 2013-11-20 07:36 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security
2013-11-19 14:08 - 2013-10-08 20:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2013-11-19 14:08 - 2013-10-08 17:30 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-11-19 14:08 - 2013-10-08 17:30 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-11-19 14:08 - 2013-10-08 17:30 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-11-19 14:08 - 2013-10-08 17:30 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-11-19 14:08 - 2013-10-08 17:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2013-11-19 14:08 - 2013-10-08 17:27 - 03279872 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2013-11-19 14:08 - 2013-10-08 17:27 - 01622016 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2013-11-19 14:08 - 2013-10-08 17:27 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2013-11-19 14:08 - 2013-10-08 17:27 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2013-11-19 14:08 - 2013-10-08 17:27 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2013-11-19 14:08 - 2013-10-08 17:27 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2013-11-19 14:08 - 2013-10-08 17:27 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2013-11-19 14:08 - 2013-10-05 01:10 - 00285016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2013-11-19 14:08 - 2013-10-03 17:09 - 00385528 _____ C:\Windows\system32\ApnDatabase.xml
2013-11-19 14:08 - 2013-10-01 21:50 - 00447320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2013-11-19 14:08 - 2013-09-28 00:48 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-11-19 14:08 - 2013-09-27 22:58 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2013-11-19 14:08 - 2013-09-24 17:18 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-11-19 14:08 - 2013-09-19 02:32 - 01455448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-11-19 14:08 - 2013-08-30 00:19 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2013-11-19 14:08 - 2013-08-30 00:18 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2013-11-19 14:08 - 2013-08-29 18:48 - 00488960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
2013-11-19 14:08 - 2013-08-29 18:47 - 00302080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
2013-11-19 08:15 - 2013-11-19 08:15 - 00000000 ____D C:\Users\Naima\AppData\Roaming\LavasoftStatistics
2013-11-19 07:42 - 2013-11-19 07:42 - 00001334 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2013-11-19 07:41 - 2013-11-19 07:41 - 00000000 ____D C:\Program Files\Lavasoft
2013-11-19 07:40 - 2013-11-19 07:40 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2013-11-19 07:39 - 2013-11-19 07:39 - 00000000 ____D C:\ProgramData\Lavasoft
2013-11-19 07:35 - 2013-11-19 07:35 - 01723528 _____ C:\Users\Naima\Downloads\Adaware_Installer.exe
2013-11-18 21:22 - 2013-11-18 21:22 - 00000000 ____D C:\Users\Public\Downloads\Norton
2013-11-17 01:39 - 2013-11-17 01:40 - 05094064 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-16 21:30 - 2013-11-16 21:30 - 00000670 _____ C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft.lnk
2013-11-16 19:16 - 2013-11-16 21:31 - 00000000 ____D C:\Users\Leila\AppData\Roaming\.minecraft
2013-11-16 19:15 - 2013-11-02 22:45 - 00675988 _____ C:\Users\Leila\Desktop\Minecraft.exe
2013-11-16 19:13 - 2013-11-16 19:13 - 06316293 _____ C:\Users\Leila\Downloads\JoshSommersIllusions.themepack
2013-11-16 19:02 - 2013-11-16 19:02 - 00000000 ____D C:\Users\Leila\AppData\Local\Google
2013-11-16 18:56 - 2013-11-22 19:39 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1005
2013-11-16 18:50 - 2013-11-16 18:50 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-16 18:50 - 2013-11-16 18:50 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-16 18:49 - 2013-11-16 18:49 - 00001441 _____ C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-16 18:49 - 2013-11-16 18:49 - 00000000 ____D C:\Users\Leila\AppData\Roaming\Adobe
2013-11-16 18:48 - 2013-11-16 18:48 - 00000000 ____D C:\Users\Leila\AppData\Local\VirtualStore
2013-11-16 18:47 - 2013-11-16 18:50 - 00000000 ____D C:\Users\Leila
2013-11-16 18:47 - 2013-11-16 18:49 - 00000000 ____D C:\Users\Leila\AppData\Local\Packages
2013-11-16 18:47 - 2013-11-16 18:47 - 00000020 ___SH C:\Users\Leila\ntuser.ini
2013-11-16 18:47 - 2013-11-04 18:54 - 00002111 _____ C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-11-16 18:47 - 2013-11-03 20:44 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-16 18:47 - 2013-11-03 20:41 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-16 18:47 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-16 18:47 - 2012-07-26 03:13 - 00000000 ____D C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-16 09:23 - 2013-11-16 09:23 - 00000000 ____D C:\Users\Dana\AppData\Roaming\SketchUp
2013-11-16 07:38 - 2013-11-05 17:58 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-16 07:38 - 2013-11-05 17:58 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-14 02:49 - 2013-11-14 02:49 - 00003120 _____ C:\Windows\SysWOW64\ALLFSAF13a.ocx
2013-11-14 02:48 - 2013-11-14 02:49 - 00002195 _____ C:\Users\Public\Desktop\Style Builder 2013.lnk
2013-11-14 02:48 - 2013-11-14 02:48 - 00002109 _____ C:\Users\Public\Desktop\LayOut 2013.lnk
2013-11-14 02:48 - 2013-11-14 02:48 - 00002024 _____ C:\Users\Public\Desktop\SketchUp 2013.lnk
2013-11-14 02:48 - 2013-11-14 02:48 - 00000000 ____D C:\ProgramData\SketchUp
2013-11-14 02:48 - 2013-11-14 02:48 - 00000000 ____D C:\Program Files (x86)\SketchUp
2013-11-14 02:46 - 2013-11-14 02:47 - 75726696 _____ (Trimble Navigation Limited) C:\Users\Dana\Downloads\SketchUpWEN.exe
2013-11-14 02:04 - 2013-11-14 02:04 - 00000057 _____ C:\Users\Dana\AppData\Roaming\mbam.context.scan
2013-11-14 00:20 - 2013-11-14 00:20 - 00000000 ____D C:\Users\Dana\AppData\Local\WinZip
2013-11-14 00:13 - 2013-11-14 00:13 - 00035001 _____ C:\Users\Dana\Downloads\VillageInfo_1.6.4.zip
2013-11-13 03:49 - 2013-10-10 06:53 - 00096600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys
2013-11-13 03:49 - 2013-10-10 04:21 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 03:49 - 2013-10-10 04:20 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2013-11-13 03:49 - 2013-10-02 18:25 - 01300992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 03:49 - 2013-10-01 18:37 - 01569280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-13 03:49 - 2013-10-01 18:26 - 01890816 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-13 03:49 - 2013-10-01 17:22 - 01022976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-13 03:49 - 2013-09-13 17:36 - 00247296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2013-11-13 03:49 - 2013-09-13 17:33 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2013-11-13 03:49 - 2013-09-03 22:11 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-13 03:49 - 2013-08-30 00:43 - 00061784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys
2013-11-13 03:49 - 2013-08-30 00:20 - 01173504 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2013-11-13 03:49 - 2013-08-29 18:48 - 00914432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2013-11-13 03:49 - 2013-08-21 01:39 - 00465240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2013-11-13 03:49 - 2013-08-10 01:30 - 00151896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys
2013-11-13 03:49 - 2013-08-10 00:21 - 00817152 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2013-11-13 03:49 - 2013-08-09 22:58 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2013-11-13 03:49 - 2013-07-24 18:10 - 10799104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-11-13 03:49 - 2013-07-24 18:07 - 13661696 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2013-11-13 03:49 - 2013-07-11 20:38 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2013-11-13 03:49 - 2013-07-11 20:30 - 00485376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSDApi.dll
2013-11-13 03:48 - 2013-10-12 03:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-13 03:47 - 2013-10-12 03:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-13 03:47 - 2013-10-12 03:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-13 03:47 - 2013-10-12 03:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-13 03:47 - 2013-10-12 03:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-13 03:47 - 2013-10-12 03:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-13 03:47 - 2013-10-12 03:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-13 03:47 - 2013-10-12 03:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-13 03:47 - 2013-10-12 03:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-13 03:47 - 2013-10-12 02:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-13 03:47 - 2013-10-12 02:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-13 03:47 - 2013-10-12 02:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-13 03:47 - 2013-10-12 02:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-13 03:47 - 2013-10-12 02:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-13 03:47 - 2013-10-12 02:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-13 03:47 - 2013-10-12 02:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-13 03:47 - 2013-10-12 02:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-13 03:47 - 2013-10-01 18:37 - 02035712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-13 03:47 - 2013-10-01 18:26 - 02304512 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-13 03:47 - 2013-09-23 17:30 - 00419328 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 03:47 - 2013-09-23 17:30 - 00323072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-13 03:47 - 2013-08-23 02:22 - 02062848 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-11-13 03:47 - 2013-08-22 20:44 - 01711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-11-11 22:54 - 2013-11-11 22:54 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Malwarebytes
2013-11-11 07:02 - 2013-11-11 07:02 - 13487104 _____ C:\Users\Naima\Downloads\Chapter 8 - Water and Minerals.ppt
2013-11-11 00:13 - 2013-11-11 00:13 - 00000000 ____D C:\Users\Naima\Desktop\Chromium movie_AME
2013-11-10 23:57 - 2013-11-10 23:58 - 15654458 _____ C:\Users\Naima\Downloads\audiojungle-113870-intense-cinematic-intro-.zip
2013-11-10 21:10 - 2013-11-10 21:10 - 00005256 _____ C:\Users\Naima\Desktop\No_smoking_sign.svg
2013-11-10 20:58 - 2013-11-10 20:58 - 00000000 ____D C:\Users\Naima\AppData\Local\WinZip
2013-11-10 19:56 - 2013-11-10 20:04 - 00002415 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome (2).lnk
2013-11-10 17:04 - 2013-11-10 18:17 - 03932214 _____ C:\Users\Dana\Desktop\screen.bmp
2013-11-10 11:08 - 2013-11-20 08:38 - 00000000 ____D C:\Users\Naima\Desktop\New folder
2013-11-10 04:08 - 2013-11-10 04:08 - 00000703 _____ C:\Users\Dana\Desktop\Minecraft - Shortcut.lnk
2013-11-10 04:06 - 2013-11-10 04:06 - 00000638 _____ C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft.lnk
2013-11-09 21:37 - 2013-11-09 21:37 - 00000000 ____D C:\Users\Dana\AppData\Local\CrashDumps
2013-11-09 19:13 - 2013-11-09 19:15 - 00002415 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2013-11-09 14:28 - 2013-11-09 14:28 - 00239388 _____ C:\Users\Dana\Downloads\cccoup.oxps
2013-11-09 13:56 - 2013-11-09 13:56 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\Macromedia
2013-11-09 05:23 - 2013-11-09 05:29 - 00000000 ____D C:\Users\Naima\AppData\Roaming\.minecraft
2013-11-09 04:16 - 2013-11-10 10:26 - 00000000 ____D C:\Minecraft
2013-11-09 04:05 - 2013-11-09 04:06 - 00000000 ____D C:\Users\Dana\AppData\Local\Adobe
2013-11-08 22:36 - 2013-11-08 22:36 - 00000056 _____ C:\{FDD44B5A-CE95-4D59-8DF7-603B4620362E}
2013-11-08 21:33 - 2013-11-08 21:33 - 01378230 _____ C:\Users\Naima\Downloads\image (8).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01851671 _____ C:\Users\Naima\Downloads\image (7).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01831828 _____ C:\Users\Naima\Downloads\image (6).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01519267 _____ C:\Users\Naima\Downloads\image (3).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01385587 _____ C:\Users\Naima\Downloads\image (1).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01378230 _____ C:\Users\Naima\Downloads\image.jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01370168 _____ C:\Users\Naima\Downloads\image (5).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01331029 _____ C:\Users\Naima\Downloads\image (4).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01206559 _____ C:\Users\Naima\Downloads\image (2).jpeg
2013-11-08 17:27 - 2013-11-08 17:29 - 00000000 ____D C:\Users\Aria\AppData\Local\Adobe
2013-11-08 14:49 - 2013-11-08 14:49 - 00000682 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft.lnk
2013-11-08 14:49 - 2013-11-08 14:49 - 00000682 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft (2).lnk
2013-11-08 14:49 - 2013-11-08 14:49 - 00000000 ____D C:\Users\singi_000\AppData\Local\CrashDumps
2013-11-07 19:18 - 2013-11-07 19:19 - 123600840 _____ C:\Users\Naima\Downloads\videohive-2475633--intense-movie-trailer.zip
2013-11-07 19:18 - 2013-11-07 19:19 - 00000821 _____ C:\Users\Naima\Downloads\-intense-movie-trailer-license.txt
2013-11-07 12:24 - 2013-11-11 22:48 - 00000000 ____D C:\Program Files (x86)\Steam
2013-11-07 12:24 - 2013-11-07 12:24 - 00000924 _____ C:\Users\Public\Desktop\Steam.lnk
2013-11-07 12:18 - 2013-11-07 12:18 - 01669632 _____ C:\Users\Dana\Downloads\SteamInstall (1).msi
2013-11-07 12:17 - 2013-11-07 12:18 - 01669632 _____ C:\Users\Dana\Downloads\SteamInstall.msi
2013-11-07 11:40 - 2013-11-07 11:40 - 00000000 ____D C:\Users\Naima\AppData\Local\HP
2013-11-06 17:29 - 2013-11-06 17:29 - 00002288 _____ C:\Users\Public\Desktop\WinZip.lnk
2013-11-06 17:28 - 2013-11-06 17:33 - 00000000 ____D C:\ProgramData\WinZip
2013-11-06 17:28 - 2013-11-06 17:28 - 00000000 ____D C:\Program Files\WinZip
2013-11-06 17:21 - 2013-11-06 17:21 - 00000000 ____D C:\Users\Naima\Documents\Add-in Express
2013-11-06 17:20 - 2013-11-06 17:20 - 00000000 ____D C:\Windows\CD95F661A5C444F5A6AAECDD91C240DD.TMP
2013-11-06 17:14 - 2013-11-06 17:15 - 00424392 _____ (WinZip Computing) C:\Users\Naima\Downloads\WinZip175.exe
2013-11-06 17:13 - 2013-11-06 17:14 - 00424392 _____ (WinZip Computing) C:\Users\Naima\Downloads\WinZip175 (1).exe
2013-11-06 17:12 - 2013-11-06 17:14 - 00420808 _____ (WinZip Computing) C:\Users\Naima\Downloads\WinZip180.exe
2013-11-06 15:48 - 2013-11-06 15:48 - 07389078 _____ C:\Users\Naima\Downloads\Project File N°35.rar
2013-11-06 12:27 - 2013-11-06 12:28 - 00000000 ____D C:\Users\Naima\Downloads\cinematic-embers
2013-11-06 11:39 - 2013-11-06 11:40 - 124200452 _____ C:\Users\Naima\Downloads\cinematic-embers.zip
2013-11-06 08:34 - 2013-11-11 00:14 - 00000000 ____D C:\Users\Naima\Documents\Adobe
2013-11-05 21:18 - 2013-11-05 21:19 - 00000000 ____D C:\Users\singi_000\AppData\Local\Adobe
2013-11-05 20:25 - 2013-11-05 20:25 - 00003498 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Naimas-Naima
2013-11-05 20:24 - 2013-11-08 19:57 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-11-05 20:24 - 2013-11-05 20:24 - 00000000 ____D C:\Users\Naima\AppData\Roaming\PDAppFlex
2013-11-05 17:37 - 2013-11-05 19:19 - 00000000 ____D C:\Program Files\Adobe
2013-11-05 17:36 - 2013-11-05 19:19 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-05 17:19 - 2013-11-05 18:49 - 00000000 ____D C:\ProgramData\Adobe
2013-11-05 17:07 - 2013-11-05 17:07 - 00001074 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2013-11-05 17:05 - 2013-11-05 19:14 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-11-05 17:03 - 2013-11-23 02:18 - 00000000 ____D C:\Users\Naima\AppData\Local\Adobe
2013-11-05 17:03 - 2013-11-05 17:03 - 02841464 _____ (Adobe Systems Incorporated) C:\Users\Naima\Downloads\CreativeCloudSet-Up.exe
2013-11-04 23:02 - 2013-11-04 23:02 - 00020653 _____ C:\Users\Naima\Downloads\4LTR_Excel2010_Ch14_Pr1a_NaimaCostello_2.xlsx
2013-11-04 21:37 - 2013-11-04 22:59 - 00020570 _____ C:\Users\Naima\Downloads\4LTR_Excel2010_Ch14_Pr1a_NaimaCostello_1.xlsx
2013-11-04 21:34 - 2013-11-04 21:34 - 00013097 _____ C:\Users\Naima\Downloads\4LTR_Excel2010_Ch13_Pr1a_NaimaCostello_2.xlsx
2013-11-04 20:50 - 2013-11-04 20:50 - 00000000 ____D C:\Users\Naima\AppData\Local\Microsoft Help
2013-11-04 20:19 - 2013-11-04 21:33 - 00013096 _____ C:\Users\Naima\Downloads\4LTR_Excel2010_Ch13_Pr1a_NaimaCostello_1.xlsx
2013-11-04 18:54 - 2013-11-04 18:54 - 00002129 _____ C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-11-04 18:54 - 2013-11-04 18:54 - 00002111 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-11-04 18:54 - 2013-11-04 18:54 - 00002111 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-11-04 18:54 - 2013-11-04 18:54 - 00000000 ___RD C:\Users\Naima\SkyDrive
2013-11-04 18:54 - 2013-11-04 18:54 - 00000000 ____D C:\ProgramData\Microsoft SkyDrive
2013-11-04 18:54 - 2013-11-04 18:54 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2013-11-04 18:43 - 2013-11-12 21:28 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-11-04 18:43 - 2013-11-04 18:43 - 00572088 _____ (Microsoft Corporation) C:\Users\Naima\Downloads\Setup.X86.en-US_O365HomePremRetail_7fa16cfe-386e-4146-84aa-dec280ae03a2_TX_PR_.exe
2013-11-04 16:56 - 2013-11-04 16:56 - 00177229 _____ C:\Users\Naima\Desktop\Naima 4.htm
2013-11-04 16:56 - 2013-11-04 16:56 - 00000000 ____D C:\Users\Naima\Desktop\Naima 4_files
2013-11-04 16:46 - 2013-11-04 16:46 - 00177529 _____ C:\Users\Naima\Desktop\naima2.htm
2013-11-04 16:46 - 2013-11-04 16:46 - 00000000 ____D C:\Users\Naima\Desktop\naima2_files
2013-11-04 16:42 - 2013-11-04 16:42 - 00177343 _____ C:\Users\Naima\Desktop\naima1.htm
2013-11-04 16:42 - 2013-11-04 16:42 - 00000000 ____D C:\Users\Naima\Desktop\naima1_files
2013-11-04 13:42 - 2013-11-22 21:14 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\.minecraft
2013-11-04 13:42 - 2013-11-02 22:45 - 00675988 _____ C:\Users\singi_000\Desktop\Minecraft.exe
2013-11-04 08:30 - 2013-05-02 10:29 - 00278800 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-04 07:24 - 2013-11-04 07:24 - 00001120 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-04 07:24 - 2013-11-04 07:24 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Malwarebytes
2013-11-04 07:23 - 2013-11-04 07:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-04 07:23 - 2013-11-04 07:23 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-04 07:23 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-04 07:22 - 2013-11-04 07:22 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Naima\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-04 07:21 - 2013-11-04 07:21 - 00683016 _____ C:\Users\Naima\Downloads\malwarebytes-anti-malware_setup.exe
2013-11-04 07:19 - 2013-11-19 08:15 - 00000000 ____D C:\Users\Naima\AppData\Local\CrashDumps
2013-11-04 07:15 - 2013-11-04 07:15 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-11-04 07:08 - 2013-11-04 07:12 - 00000000 ____D C:\AdwCleaner
2013-11-04 07:07 - 2013-11-04 07:07 - 01073258 _____ C:\Users\Naima\Downloads\adwcleaner.exe
2013-11-04 00:34 - 2013-06-16 17:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2013-11-04 00:34 - 2013-06-01 06:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2013-11-04 00:34 - 2013-06-01 06:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-11-04 00:34 - 2013-06-01 06:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2013-11-04 00:34 - 2013-06-01 05:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2013-11-04 00:34 - 2013-06-01 04:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-11-04 00:34 - 2013-06-01 04:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2013-11-04 00:34 - 2013-06-01 04:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2013-11-04 00:34 - 2013-06-01 04:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2013-11-04 00:34 - 2013-06-01 04:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2013-11-04 00:34 - 2013-06-01 04:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2013-11-04 00:34 - 2013-06-01 04:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2013-11-04 00:34 - 2013-06-01 04:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-11-04 00:34 - 2013-06-01 04:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2013-11-04 00:34 - 2013-06-01 04:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe
2013-11-04 00:34 - 2013-06-01 04:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2013-11-04 00:34 - 2013-06-01 04:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2013-11-04 00:34 - 2013-06-01 04:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2013-11-04 00:34 - 2013-06-01 04:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2013-11-04 00:34 - 2013-06-01 04:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2013-11-04 00:34 - 2013-06-01 04:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2013-11-04 00:34 - 2013-06-01 04:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2013-11-04 00:34 - 2013-06-01 04:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll
2013-11-04 00:34 - 2013-05-31 22:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys
2013-11-04 00:34 - 2013-05-24 17:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2013-11-04 00:34 - 2013-05-24 17:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2013-11-04 00:34 - 2013-05-24 17:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2013-11-04 00:34 - 2013-05-24 17:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2013-11-04 00:33 - 2013-08-10 00:21 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2013-11-04 00:33 - 2013-08-10 00:21 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncInfo.dll
2013-11-04 00:33 - 2013-08-09 22:58 - 00356352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2013-11-04 00:33 - 2013-08-03 01:40 - 01374208 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2013-11-04 00:33 - 2013-08-03 01:40 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2013-11-04 00:33 - 2013-08-03 01:40 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2013-11-04 00:33 - 2013-08-03 00:14 - 00399360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2013-11-04 00:33 - 2013-08-03 00:13 - 01245696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2013-11-04 00:33 - 2013-08-03 00:13 - 00437248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2013-11-04 00:33 - 2013-08-02 01:28 - 19758080 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-11-04 00:33 - 2013-08-02 01:28 - 10116608 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2013-11-04 00:33 - 2013-08-02 01:28 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-11-04 00:33 - 2013-08-02 00:08 - 17561088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-11-04 00:33 - 2013-08-02 00:08 - 08858112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-11-04 00:33 - 2013-08-02 00:08 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2013-11-04 00:33 - 2013-08-01 05:41 - 02233688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-11-04 00:33 - 2013-07-24 18:10 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll
2013-11-04 00:33 - 2013-07-24 18:06 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\mbsmsapi.dll
2013-11-04 00:33 - 2013-04-09 18:17 - 01125888 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2013-11-04 00:33 - 2013-04-09 17:29 - 00893952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2013-11-04 00:32 - 2013-07-09 03:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys
2013-11-04 00:32 - 2013-07-09 01:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2013-11-04 00:32 - 2013-07-08 23:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2013-11-04 00:32 - 2013-07-08 22:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2013-11-04 00:32 - 2013-07-08 17:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2013-11-04 00:32 - 2013-07-08 17:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2013-11-04 00:32 - 2013-07-08 17:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Wwanadvui.dll
2013-11-04 00:32 - 2013-07-08 17:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2013-11-04 00:32 - 2013-07-05 19:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2013-11-04 00:32 - 2013-07-02 19:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2013-11-04 00:32 - 2013-07-02 19:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2013-11-04 00:32 - 2013-07-02 19:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-11-04 00:32 - 2013-07-02 19:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2013-11-04 00:32 - 2013-06-30 17:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe
2013-11-04 00:32 - 2013-06-30 17:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\openfiles.exe
2013-11-04 00:32 - 2013-06-29 01:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-11-04 00:32 - 2013-06-29 01:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-11-04 00:32 - 2013-06-29 00:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2013-11-04 00:32 - 2013-06-25 22:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2013-11-04 00:32 - 2013-06-25 21:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2013-11-04 00:32 - 2013-06-24 17:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-11-04 00:32 - 2013-06-24 17:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2013-11-04 00:32 - 2013-06-24 17:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2013-11-04 00:32 - 2013-06-19 00:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll
2013-11-04 00:32 - 2013-06-19 00:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2013-11-04 00:32 - 2013-06-18 17:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll
2013-11-04 00:32 - 2013-06-18 17:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll
2013-11-04 00:32 - 2013-06-11 18:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2013-11-04 00:32 - 2013-06-11 18:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2013-11-04 00:32 - 2013-06-10 14:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-04 00:32 - 2013-06-10 14:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-04 00:32 - 2013-06-10 14:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-04 00:32 - 2013-06-10 14:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-04 00:32 - 2013-06-06 03:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2013-11-04 00:32 - 2012-11-27 01:39 - 01122768 _____ (Microsoft Corporation) C:\Windows\system32\Taskmgr.exe
2013-11-04 00:32 - 2012-11-26 23:49 - 01027152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Taskmgr.exe
2013-11-04 00:32 - 2012-11-26 23:20 - 01217536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll
2013-11-04 00:32 - 2012-11-26 23:20 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-11-04 00:32 - 2012-11-26 23:20 - 01048064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-11-04 00:32 - 2012-11-26 23:20 - 00798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
2013-11-04 00:32 - 2012-11-26 23:20 - 00560128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserLanguagesCpl.dll
2013-11-04 00:32 - 2012-11-26 23:20 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2013-11-04 00:32 - 2012-11-26 23:20 - 00046592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vds_ps.dll
2013-11-04 00:32 - 2012-11-26 23:19 - 03245568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-11-04 00:32 - 2012-11-26 23:19 - 01536512 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll
2013-11-04 00:32 - 2012-11-26 23:19 - 00955904 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
2013-11-04 00:32 - 2012-11-26 23:19 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\UserLanguagesCpl.dll
2013-11-04 00:32 - 2012-11-26 23:19 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2013-11-04 00:32 - 2012-09-11 00:28 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\vdsldr.exe
2013-11-04 00:32 - 2012-09-11 00:27 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\vds_ps.dll
2013-11-04 00:17 - 2013-11-04 00:17 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Macromedia
2013-11-03 21:59 - 2013-11-03 22:04 - 00000000 ____D C:\8100b355c6640be0a64b
2013-11-03 21:59 - 2013-11-03 21:59 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-11-03 21:59 - 2013-11-03 21:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-11-03 21:58 - 2013-11-03 21:58 - 13079688 _____ (Microsoft Corporation) C:\Users\Naima\Downloads\Silverlight_x64.exe
2013-11-03 21:53 - 2013-11-03 21:53 - 00001114 _____ C:\Users\Naima\Desktop\Flash Player Pro.lnk
2013-11-03 21:53 - 2013-11-03 21:53 - 00000000 ____D C:\Users\Naima\Documents\Flash Player Pro
2013-11-03 21:53 - 2013-11-03 21:53 - 00000000 ____D C:\Users\Naima\AppData\Local\NativeMessaging
2013-11-03 21:53 - 2013-11-03 21:53 - 00000000 ____D C:\Users\Naima\AppData\Local\CRE
2013-11-03 21:53 - 2013-11-03 21:53 - 00000000 ____D C:\Program Files (x86)\Flash Player Pro
2013-11-03 19:57 - 2013-11-03 19:57 - 00000000 ____D C:\Users\Dana\AppData\Roaming\WildTangent
2013-11-03 19:57 - 2013-11-03 19:57 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Macromedia
2013-11-03 19:49 - 2013-11-03 19:49 - 08402527 _____ C:\Users\Dana\Downloads\DarkSkiesTracyHymas.themepack
2013-11-03 17:34 - 2013-11-03 17:34 - 00000000 ____D C:\Users\Aria\AppData\Local\CrashDumps
2013-11-03 17:14 - 2013-11-03 17:14 - 07330863 _____ C:\Users\Dana\Downloads\FrostMacros_DLawler.themepack
2013-11-03 17:14 - 2013-11-03 17:14 - 06823554 _____ C:\Users\Dana\Downloads\CreepyCobwebs.themepack
2013-11-03 16:51 - 2013-11-03 16:51 - 00002002 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk
2013-11-03 16:51 - 2013-11-03 16:51 - 00000000 ____D C:\ProgramData\Visan
2013-11-03 16:51 - 2013-11-03 16:51 - 00000000 ____D C:\ProgramData\HP Photo Creations
2013-11-03 16:51 - 2013-11-03 16:51 - 00000000 ____D C:\Program Files (x86)\HP Photo Creations
2013-11-03 16:51 - 2013-11-03 16:51 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2013-11-03 16:50 - 2013-11-10 17:13 - 00000000 ____D C:\Users\Dana\AppData\Roaming\HpUpdate
2013-11-03 16:50 - 2013-11-03 16:50 - 00003606 _____ C:\Windows\System32\Tasks\HPCustParticipation HP Deskjet 2540 series
2013-11-03 16:50 - 2013-11-03 16:50 - 00002219 _____ C:\Users\Public\Desktop\HP Deskjet 2540 series.lnk
2013-11-03 16:50 - 2013-11-03 16:50 - 00001166 _____ C:\Users\Public\Desktop\Shop for Supplies - HP Deskjet 2540 series.lnk
2013-11-03 16:50 - 2013-11-03 16:50 - 00000000 ____D C:\Program Files (x86)\HP
2013-11-03 16:50 - 2013-08-13 13:42 - 00762400 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPMC211.dll
2013-11-03 16:49 - 2013-11-03 16:49 - 00000057 _____ C:\ProgramData\Ament.ini
2013-11-03 16:49 - 2013-11-03 16:49 - 00000000 ____D C:\Program Files\HP
2013-11-03 16:48 - 2013-11-03 16:55 - 00000000 ____D C:\Users\Dana\AppData\Local\HP
2013-11-03 16:46 - 2013-11-03 16:46 - 02338824 _____ C:\Users\Dana\Downloads\hppiw.exe
2013-11-03 16:41 - 2013-11-03 16:50 - 00000000 ____D C:\ProgramData\HP
2013-11-03 16:41 - 2013-11-03 16:41 - 15166732 _____ C:\Users\Dana\Downloads\PanoramicAnimals.deskthemepack
2013-11-03 15:53 - 2013-11-03 15:53 - 00000000 ____D C:\Users\singi_000\AppData\Local\Google
2013-11-03 15:50 - 2013-11-22 20:34 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1003
2013-11-03 15:43 - 2013-11-05 21:19 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\Adobe
2013-11-03 15:43 - 2013-11-04 12:39 - 00000000 ___RD C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-03 15:43 - 2013-11-04 12:39 - 00000000 ___RD C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-03 15:43 - 2013-11-03 15:43 - 00001441 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-03 15:43 - 2013-11-03 15:43 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\AcerRemote
2013-11-03 15:42 - 2013-11-18 21:21 - 00000000 ____D C:\Users\singi_000
2013-11-03 15:42 - 2013-11-03 16:53 - 00000000 ____D C:\Users\singi_000\AppData\Local\Packages
2013-11-03 15:42 - 2013-11-03 15:42 - 00000020 ___SH C:\Users\singi_000\ntuser.ini
2013-11-03 15:42 - 2013-11-03 15:42 - 00000000 ____D C:\Users\singi_000\AppData\Local\VirtualStore
2013-11-03 15:42 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-03 15:42 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-03 15:42 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-03 15:42 - 2012-07-26 03:13 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Users\Aria\AppData\Local\Google
2013-11-03 14:34 - 2013-11-03 14:34 - 00000000 ____D C:\Users\Aria\AppData\Roaming\Macromedia
2013-11-03 14:32 - 2013-11-13 20:46 - 00000000 ____D C:\Users\Aria\AppData\Roaming\.minecraft
2013-11-03 14:22 - 2013-11-02 22:45 - 00675988 _____ C:\Users\Aria\Desktop\Minecraft.exe
2013-11-03 14:17 - 2013-11-22 08:49 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1004
2013-11-03 14:10 - 2013-11-03 14:10 - 00000000 ____D C:\Users\Aria\AppData\Roaming\AcerRemote
2013-11-03 14:09 - 2013-11-08 17:29 - 00000000 ____D C:\Users\Aria\AppData\Roaming\Adobe
2013-11-03 14:09 - 2013-11-08 17:26 - 00000000 ___RD C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-03 14:09 - 2013-11-08 17:26 - 00000000 ___RD C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-03 14:09 - 2013-11-03 14:09 - 00001441 _____ C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-03 14:09 - 2013-11-03 14:09 - 00000000 ____D C:\Users\Aria\AppData\Local\VirtualStore
2013-11-03 14:08 - 2013-11-03 14:16 - 00000000 ____D C:\Users\Aria\AppData\Local\Packages
2013-11-03 14:05 - 2013-11-03 14:09 - 00000000 ____D C:\Users\Aria
2013-11-03 14:05 - 2013-11-03 14:05 - 00000020 ___SH C:\Users\Aria\ntuser.ini
2013-11-03 14:05 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-03 14:05 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-03 14:05 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-03 14:05 - 2012-07-26 03:13 - 00000000 ____D C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-03 10:13 - 2013-11-03 10:13 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-11-03 08:24 - 2013-11-03 08:24 - 00003854 _____ C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2013-11-03 08:23 - 2013-11-17 01:38 - 00000000 ____D C:\Program Files (x86)\ScorpionSaver
2013-11-03 08:23 - 2013-11-03 08:23 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WordOv
2013-11-03 08:22 - 2013-11-03 08:22 - 00000000 ____D C:\Program Files (x86)\sp
2013-11-03 08:22 - 2013-11-03 08:22 - 00000000 ____D C:\Program Files (x86)\Social Privacy  DNS
2013-11-03 02:53 - 2013-11-13 07:12 - 00000000 ____D C:\Windows\system32\MRT
<SNIP>
Link to post
Share on other sites

<CONTINUED>

2013-11-03 02:53 - 2013-11-13 07:08 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-02 23:11 - 2013-11-02 23:11 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-11-02 22:57 - 2013-07-01 19:44 - 00036288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2013-11-02 22:57 - 2013-07-01 17:08 - 00247216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2013-11-02 22:57 - 2013-01-09 20:53 - 00028904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpiowin32.sys
2013-11-02 22:57 - 2013-01-09 20:29 - 00091880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2013-11-02 22:57 - 2013-01-09 18:26 - 01752064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupapi.dll
2013-11-02 22:57 - 2013-01-09 18:26 - 01611776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2013-11-02 22:57 - 2013-01-09 18:26 - 00436736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MP4SDECD.DLL
2013-11-02 22:57 - 2013-01-09 18:26 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2013-11-02 22:57 - 2013-01-09 18:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wiaacmgr.exe
2013-11-02 22:57 - 2013-01-09 18:23 - 02094592 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2013-11-02 22:57 - 2013-01-09 18:23 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2013-11-02 22:57 - 2013-01-09 18:23 - 01886208 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2013-11-02 22:57 - 2013-01-09 18:23 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2013-11-02 22:57 - 2013-01-09 18:23 - 00256000 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll
2013-11-02 22:57 - 2013-01-09 18:23 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\wiaacmgr.exe
2013-11-02 22:57 - 2013-01-09 18:22 - 00894464 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2013-11-02 22:57 - 2013-01-09 18:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2013-11-02 22:57 - 2013-01-09 18:22 - 00438272 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2013-11-02 22:57 - 2013-01-09 18:22 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2013-11-02 22:57 - 2012-11-02 00:19 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ncbservice.dll
2013-11-02 22:57 - 2012-11-02 00:18 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll
2013-11-02 22:57 - 2012-11-02 00:18 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\adhsvc.dll
2013-11-02 22:57 - 2012-11-02 00:18 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\adhapi.dll
2013-11-02 22:57 - 2012-11-02 00:18 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\httpprxp.dll
2013-11-02 22:57 - 2012-11-02 00:18 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\keepaliveprovider.dll
2013-11-02 22:56 - 2013-08-16 00:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2013-11-02 22:56 - 2013-08-16 00:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll
2013-11-02 22:56 - 2013-08-16 00:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2013-11-02 22:56 - 2013-08-16 00:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2013-11-02 22:56 - 2013-08-16 00:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2013-11-02 22:56 - 2013-08-16 00:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2013-11-02 22:56 - 2013-08-16 00:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2013-11-02 22:56 - 2013-08-15 17:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2013-11-02 22:56 - 2013-08-15 17:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2013-11-02 22:56 - 2013-08-15 17:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll
2013-11-02 22:56 - 2013-08-15 17:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2013-11-02 22:56 - 2013-08-15 17:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-11-02 22:56 - 2013-08-15 17:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll
2013-11-02 22:56 - 2013-08-15 17:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2013-11-02 22:56 - 2013-08-15 17:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll
2013-11-02 22:56 - 2013-08-15 17:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll
2013-11-02 22:50 - 2013-07-05 19:15 - 00652288 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-11-02 22:50 - 2013-07-03 21:13 - 00541696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-11-02 22:50 - 2012-11-25 23:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll
2013-11-02 22:50 - 2012-11-25 23:20 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll
2013-11-02 22:45 - 2013-11-20 23:53 - 00000000 ____D C:\Users\Dana\AppData\Roaming\.minecraft
2013-11-02 22:45 - 2013-11-02 22:45 - 00675988 _____ C:\Users\Dana\Desktop\Minecraft.exe
2013-11-02 22:44 - 2013-11-09 04:13 - 00000664 _____ C:\Users\Dana\Downloads\server.properties
2013-11-02 22:44 - 2013-11-09 04:13 - 00000000 ____D C:\Users\Dana\Downloads\world
2013-11-02 22:44 - 2013-11-09 04:12 - 00000110 _____ C:\Users\Dana\Downloads\banned-players.txt
2013-11-02 22:44 - 2013-11-09 04:12 - 00000110 _____ C:\Users\Dana\Downloads\banned-ips.txt
2013-11-02 22:44 - 2013-11-09 04:12 - 00000000 _____ C:\Users\Dana\Downloads\ops.txt
2013-11-02 22:44 - 2013-11-02 22:44 - 00000000 _____ C:\Users\Dana\Downloads\white-list.txt
2013-11-02 22:43 - 2013-11-02 22:43 - 00000000 ____D C:\ProgramData\Sun
2013-11-02 22:43 - 2013-11-02 22:43 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 22:43 - 2013-05-15 17:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-11-02 22:43 - 2013-05-15 17:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-11-02 22:43 - 2013-05-14 08:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-02 22:43 - 2013-05-14 04:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-02 22:43 - 2013-04-28 17:28 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-11-02 22:43 - 2013-02-21 05:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-02 22:43 - 2013-02-21 05:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-02 22:43 - 2013-02-21 05:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-02 22:43 - 2013-02-21 05:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-02 22:43 - 2013-02-21 05:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-02 22:43 - 2013-02-21 05:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-02 22:43 - 2013-02-19 04:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-11-02 22:42 - 2013-11-02 22:42 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-02 22:42 - 2013-11-02 22:42 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-02 22:42 - 2013-11-02 22:42 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-02 22:42 - 2013-11-02 22:42 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-02 22:42 - 2013-11-02 22:42 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-02 22:42 - 2013-06-22 00:45 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-11-02 22:42 - 2013-06-22 00:45 - 00054488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2013-11-02 22:40 - 2013-11-02 22:40 - 00915368 _____ (Oracle Corporation) C:\Users\Dana\Downloads\chromeinstall-7u45.exe
2013-11-02 22:39 - 2013-07-05 17:02 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-11-02 22:39 - 2013-07-01 17:14 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbprint.sys
2013-11-02 22:39 - 2013-06-28 22:08 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-11-02 22:39 - 2013-06-28 22:07 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-11-02 22:39 - 2013-05-03 23:48 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2013-11-02 22:37 - 2013-03-02 05:57 - 00332520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2013-11-02 22:37 - 2013-03-02 05:57 - 00077544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storahci.sys
2013-11-02 22:37 - 2013-03-02 05:39 - 00495336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2013-11-02 22:37 - 2013-03-02 03:23 - 01338880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-11-02 22:37 - 2013-03-02 03:23 - 00893952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2013-11-02 22:37 - 2013-03-02 03:23 - 00601088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2013-11-02 22:37 - 2013-03-02 03:23 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2013-11-02 22:37 - 2013-03-02 03:23 - 00100864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncInfo.dll
2013-11-02 22:37 - 2013-03-02 03:22 - 05091840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-11-02 22:37 - 2013-03-02 03:22 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll
2013-11-02 22:37 - 2013-03-02 03:21 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvstore.dll
2013-11-02 22:37 - 2013-03-02 03:21 - 00145408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\powercfg.cpl
2013-11-02 22:37 - 2013-03-02 03:21 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevDispItemProvider.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 01627648 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 01149952 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 01101824 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 00951808 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\usbmon.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\TimeBrokerServer.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2013-11-02 22:37 - 2013-03-01 21:45 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\WSDPrintProxy.DLL
2013-11-02 22:37 - 2013-03-01 21:44 - 05978624 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-11-02 22:37 - 2013-03-01 21:44 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll
2013-11-02 22:37 - 2013-03-01 21:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2013-11-02 22:37 - 2013-03-01 21:44 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\discan.dll
2013-11-02 22:37 - 2013-03-01 21:44 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\NdisImPlatform.dll
2013-11-02 22:37 - 2013-03-01 21:44 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\DevDispItemProvider.dll
2013-11-02 22:37 - 2013-03-01 21:43 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl
2013-11-02 22:37 - 2013-03-01 21:15 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mouhid.sys
2013-11-02 22:37 - 2013-02-28 23:56 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\monitor.sys
2013-11-02 22:32 - 2013-05-23 18:02 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-11-02 22:32 - 2013-05-23 17:25 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-11-02 22:31 - 2013-04-23 18:13 - 01013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-11-02 22:31 - 2013-04-23 18:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-11-02 22:31 - 2013-04-23 17:56 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-11-02 22:31 - 2013-04-23 17:55 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-11-02 22:28 - 2013-03-02 04:59 - 00411880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2013-11-02 22:26 - 2013-06-01 04:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-11-02 22:26 - 2013-06-01 04:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-11-02 22:25 - 2013-05-26 18:17 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-11-02 22:25 - 2013-05-26 17:59 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-11-02 22:25 - 2013-05-24 22:15 - 00362496 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-11-02 22:25 - 2013-05-24 21:32 - 00300032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-11-02 22:25 - 2013-03-02 03:23 - 00375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2013-11-02 22:25 - 2013-03-01 21:44 - 01011200 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2013-11-02 22:25 - 2013-02-19 10:07 - 00083688 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_AuthenticAMD.dll
2013-11-02 22:24 - 2013-08-23 00:11 - 04040192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-11-02 22:24 - 2013-04-11 17:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-11-02 22:24 - 2013-04-11 17:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-11-02 22:24 - 2013-02-02 03:40 - 00410624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlroamextension.dll
2013-11-02 22:24 - 2013-02-02 03:40 - 00370688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWanAPI.dll
2013-11-02 22:24 - 2013-02-02 03:40 - 00197632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2013-11-02 22:24 - 2013-02-02 03:40 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tasklist.exe
2013-11-02 22:24 - 2013-02-02 03:40 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskkill.exe
2013-11-02 22:24 - 2013-02-02 03:39 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2013-11-02 22:24 - 2013-02-02 03:38 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\duser.dll
2013-11-02 22:24 - 2013-02-02 03:24 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\taskkill.exe
2013-11-02 22:24 - 2013-02-02 03:24 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\tasklist.exe
2013-11-02 22:24 - 2013-02-02 03:23 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2013-11-02 22:24 - 2013-02-02 03:23 - 00543232 _____ (Microsoft Corporation) C:\Windows\system32\wlroamextension.dll
2013-11-02 22:24 - 2013-02-02 03:23 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll
2013-11-02 22:23 - 2013-06-30 20:42 - 00623448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-11-02 22:23 - 2013-06-30 20:42 - 00498008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-11-02 22:23 - 2013-06-30 20:42 - 00079192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-11-02 22:23 - 2013-06-30 20:42 - 00021848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-11-02 22:23 - 2013-06-28 22:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-11-02 22:23 - 2013-06-28 22:06 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-11-02 22:23 - 2013-02-11 19:17 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-11-02 22:23 - 2013-02-05 17:29 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2013-11-02 22:23 - 2013-02-05 17:28 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2013-11-02 22:23 - 2013-02-02 05:54 - 01933544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-11-02 22:23 - 2013-02-02 03:23 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll
2013-11-02 22:23 - 2013-02-02 03:23 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll
2013-11-02 22:23 - 2013-02-02 03:21 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2013-11-02 22:23 - 2013-02-02 03:20 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\duser.dll
2013-11-02 22:23 - 2013-02-02 03:20 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\hotspotauth.dll
2013-11-02 22:23 - 2013-02-02 02:25 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2013-11-02 22:23 - 2013-02-02 00:41 - 01437184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2013-11-02 22:23 - 2013-02-02 00:31 - 01690624 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2013-11-02 22:23 - 2012-11-26 22:57 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BtaMPM.sys
2013-11-02 22:23 - 2012-11-26 22:55 - 00029952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthhfHid.sys
2013-11-02 22:22 - 2013-03-06 02:10 - 00112872 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-11-02 22:22 - 2013-03-06 01:29 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2013-11-02 22:21 - 2013-05-04 01:59 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2013-11-02 22:21 - 2013-05-04 01:58 - 01332736 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2013-11-02 22:21 - 2013-05-04 01:58 - 00470528 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll
2013-11-02 22:21 - 2013-05-04 01:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\netprofm.dll
2013-11-02 22:21 - 2013-05-04 01:57 - 01131520 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2013-11-02 22:21 - 2013-05-04 01:57 - 00389120 _____ (Microsoft Corporation) C:\Windows\system32\BCP47Langs.dll
2013-11-02 22:21 - 2013-05-03 23:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BCP47Langs.dll
2013-11-02 22:21 - 2013-05-03 23:47 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2013-11-02 22:20 - 2013-05-30 18:24 - 01257472 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-11-02 22:20 - 2013-05-30 18:08 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-11-02 22:20 - 2013-05-14 21:25 - 00888320 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2013-11-02 22:20 - 2013-05-14 21:25 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2013-11-02 22:20 - 2013-05-14 21:24 - 00793088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2013-11-02 22:20 - 2013-05-14 21:24 - 00482816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2013-11-02 22:20 - 2013-05-04 02:58 - 00120736 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
2013-11-02 22:20 - 2013-05-04 01:59 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe
2013-11-02 22:20 - 2013-05-04 01:58 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2013-11-02 22:20 - 2013-05-04 01:58 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2013-11-02 22:20 - 2013-05-04 01:58 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2013-11-02 22:20 - 2013-05-04 01:57 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2013-11-02 22:20 - 2013-05-04 01:57 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2013-11-02 22:20 - 2013-05-04 01:57 - 00501760 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2013-11-02 22:20 - 2013-05-04 01:57 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2013-11-02 22:20 - 2013-05-04 01:57 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\biwinrt.dll
2013-11-02 22:20 - 2013-05-04 01:57 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll
2013-11-02 22:20 - 2013-05-04 01:56 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2013-11-02 22:20 - 2013-05-03 23:58 - 00758784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Magnify.exe
2013-11-02 22:20 - 2013-05-03 23:57 - 00303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2013-11-02 22:20 - 2013-05-03 23:57 - 00151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netplwiz.dll
2013-11-02 22:20 - 2013-05-03 23:57 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netprofm.dll
2013-11-02 22:20 - 2013-05-03 23:57 - 00018432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\npmproxy.dll
2013-11-02 22:20 - 2013-05-03 23:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\muifontsetup.dll
2013-11-02 22:20 - 2013-05-03 23:56 - 00449536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll
2013-11-02 22:20 - 2013-05-03 23:56 - 00411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2013-11-02 22:20 - 2013-05-03 23:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\biwinrt.dll
2013-11-02 22:20 - 2013-05-03 23:55 - 00389632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-11-02 22:20 - 2013-05-03 23:51 - 00014848 _____ (Microsoft) C:\Windows\system32\rars.rs
2013-11-02 22:20 - 2013-05-03 23:10 - 00014848 _____ (Microsoft) C:\Windows\SysWOW64\rars.rs
2013-11-02 22:20 - 2013-03-01 21:45 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2013-11-02 22:20 - 2013-03-01 21:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\taskhostex.exe
2013-11-02 22:20 - 2013-02-02 03:39 - 00015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlmproxy.dll
2013-11-02 22:20 - 2013-02-02 03:39 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlmsprep.dll
2013-11-02 22:17 - 2013-07-19 17:13 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-02 22:17 - 2013-07-19 17:13 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-11-02 22:17 - 2013-05-04 01:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-11-02 22:17 - 2013-05-03 23:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-11-02 22:16 - 2013-07-13 01:18 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-11-02 22:16 - 2013-07-13 01:16 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-11-02 22:16 - 2013-07-13 01:15 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2013-11-02 22:16 - 2013-07-13 01:15 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2013-11-02 22:16 - 2013-07-12 23:24 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-11-02 22:16 - 2013-07-12 23:23 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2013-11-02 22:16 - 2013-07-12 23:23 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2013-11-02 22:16 - 2013-07-01 20:41 - 00337752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2013-11-02 22:16 - 2013-07-01 20:41 - 00213336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2013-11-02 22:15 - 2013-04-08 23:51 - 14267904 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-11-02 22:15 - 2013-04-08 23:51 - 03552768 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2013-11-02 22:15 - 2013-04-08 23:50 - 02107904 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2013-11-02 22:15 - 2013-04-08 16:52 - 11878912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-11-02 22:15 - 2013-04-08 16:51 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2013-11-02 22:14 - 2013-04-09 00:33 - 00489576 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2013-11-02 22:14 - 2013-04-09 00:33 - 00446792 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2013-11-02 22:14 - 2013-04-09 00:33 - 00253544 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2013-11-02 22:14 - 2013-04-09 00:20 - 00306952 _____ (Microsoft Corporation) C:\Windows\system32\kd_02_10ec.dll
2013-11-02 22:14 - 2013-04-09 00:20 - 00086280 _____ (Microsoft Corporation) C:\Windows\system32\kdnet.dll
2013-11-02 22:14 - 2013-04-09 00:18 - 00077960 _____ (Microsoft Corporation) C:\Windows\system32\kdvm.dll
2013-11-02 22:14 - 2013-04-09 00:17 - 01829408 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-11-02 22:14 - 2013-04-08 23:52 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2013-11-02 22:14 - 2013-04-08 23:52 - 00804352 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2013-11-02 22:14 - 2013-04-08 23:52 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2013-11-02 22:14 - 2013-04-08 23:52 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2013-11-02 22:14 - 2013-04-08 23:52 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe
2013-11-02 22:14 - 2013-04-08 23:51 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2013-11-02 22:14 - 2013-04-08 23:51 - 00456704 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2013-11-02 22:14 - 2013-04-08 23:51 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-11-02 22:14 - 2013-04-08 23:51 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2013-11-02 22:14 - 2013-04-08 23:50 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2013-11-02 22:14 - 2013-04-08 23:50 - 00745984 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2013-11-02 22:14 - 2013-04-08 23:50 - 00435200 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2013-11-02 22:14 - 2013-04-08 23:50 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\GenuineCenter.dll
2013-11-02 22:14 - 2013-04-08 23:50 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2013-11-02 22:14 - 2013-04-08 23:50 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2013-11-02 22:14 - 2013-04-08 23:50 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2013-11-02 22:14 - 2013-04-08 23:49 - 01444864 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll
2013-11-02 22:14 - 2013-04-08 23:49 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2013-11-02 22:14 - 2013-04-08 23:49 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2013-11-02 22:14 - 2013-04-08 23:49 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\fhengine.dll
2013-11-02 22:14 - 2013-04-08 23:49 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\iuilp.dll
2013-11-02 22:14 - 2013-04-08 23:49 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\dmvdsitf.dll
2013-11-02 22:14 - 2013-04-08 23:49 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2013-11-02 22:14 - 2013-04-08 23:49 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\fmifs.dll
2013-11-02 22:14 - 2013-04-08 23:48 - 00169472 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2013-11-02 22:14 - 2013-04-08 21:34 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys
2013-11-02 22:14 - 2013-04-08 21:33 - 00623104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2013-11-02 22:14 - 2013-04-08 21:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2013-11-02 22:14 - 2013-04-08 21:32 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2013-11-02 22:14 - 2013-04-08 21:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2013-11-02 22:14 - 2013-04-08 21:31 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2013-11-02 22:14 - 2013-04-08 18:44 - 00123880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2013-11-02 22:14 - 2013-04-08 18:39 - 01408896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-11-02 22:14 - 2013-04-08 18:37 - 00426024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2013-11-02 22:14 - 2013-04-08 18:37 - 00324368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2013-11-02 22:14 - 2013-04-08 16:52 - 00670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2013-11-02 22:14 - 2013-04-08 16:52 - 00302592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2013-11-02 22:14 - 2013-04-08 16:52 - 00171008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2013-11-02 22:14 - 2013-04-08 16:52 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2013-11-02 22:14 - 2013-04-08 16:51 - 01593344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 01113600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00659456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00411136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00403968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00361984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00214528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00155648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2013-11-02 22:14 - 2013-04-08 16:51 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2013-11-02 22:14 - 2013-04-04 18:30 - 00503080 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2013-11-02 22:14 - 2013-03-15 17:05 - 00298456 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll
2013-11-02 22:14 - 2013-03-15 17:05 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2013-11-02 22:14 - 2013-03-02 05:39 - 00069864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2013-11-02 22:14 - 2013-03-01 21:43 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2013-11-02 22:14 - 2013-02-06 20:33 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2013-11-02 22:14 - 2013-02-02 03:40 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsRasterService.dll
2013-11-02 22:14 - 2013-02-02 03:23 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll
2013-11-02 22:14 - 2013-01-09 20:40 - 00303848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2013-11-02 22:14 - 2012-12-12 23:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-11-02 22:14 - 2012-12-12 22:59 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-11-02 22:09 - 2013-04-02 18:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-11-02 22:09 - 2013-04-02 18:12 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-11-02 22:08 - 2013-08-07 00:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2013-11-02 22:08 - 2012-11-09 23:23 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2013-11-02 22:08 - 2012-11-09 23:23 - 00132608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2013-11-02 22:08 - 2012-11-09 23:22 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\RDWebAI.dll
2013-11-02 22:08 - 2012-11-09 23:22 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\VmHostAI.dll
2013-11-02 22:08 - 2012-11-09 23:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\appserverai.dll
2013-11-02 21:55 - 2013-11-02 21:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-11-02 21:52 - 2013-11-20 08:12 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1002
2013-11-02 21:50 - 2013-11-14 00:28 - 00000000 ____D C:\Users\Dana\AppData\Local\Google
2013-11-02 21:44 - 2013-11-09 04:06 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Adobe
2013-11-02 21:44 - 2013-11-04 11:12 - 00000000 ___RD C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-02 21:44 - 2013-11-04 11:12 - 00000000 ___RD C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-02 21:44 - 2013-11-02 21:44 - 00001441 _____ C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-02 21:44 - 2013-11-02 21:44 - 00000000 ____D C:\Users\Dana\AppData\Roaming\AcerRemote
2013-11-02 21:43 - 2013-11-11 22:47 - 00000000 ____D C:\Users\Dana\AppData\Local\VirtualStore
2013-11-02 21:43 - 2013-11-03 16:42 - 00000000 ____D C:\Users\Dana\AppData\Local\Packages
2013-11-02 21:08 - 2013-04-27 00:20 - 00733184 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-11-02 21:08 - 2013-03-21 22:49 - 02382336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2013-11-02 21:08 - 2013-03-21 17:47 - 02851840 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2013-11-02 21:08 - 2013-03-14 19:17 - 00861184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2013-11-02 21:08 - 2012-10-31 23:41 - 01802240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2013-11-02 21:08 - 2012-10-31 23:41 - 01438720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2013-11-02 21:08 - 2012-10-31 23:40 - 02361344 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2013-11-02 21:08 - 2012-10-31 23:40 - 01836032 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2013-11-02 21:08 - 2012-10-31 23:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2013-11-02 21:08 - 2012-10-31 23:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2013-11-02 21:08 - 2012-10-31 23:20 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2013-11-02 21:08 - 2012-10-31 23:20 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2013-11-02 21:04 - 2013-11-07 12:24 - 00000000 ____D C:\Users\Dana
2013-11-02 21:04 - 2013-11-02 21:04 - 00000020 ___SH C:\Users\Dana\ntuser.ini
2013-11-02 21:04 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-02 21:04 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-02 21:04 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-02 21:04 - 2012-07-26 03:13 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-02 20:56 - 2013-11-14 19:11 - 00002190 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-02 20:54 - 2013-11-23 04:04 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-02 20:54 - 2013-11-22 20:29 - 00000906 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-02 20:54 - 2013-11-02 20:59 - 00003882 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-11-02 20:54 - 2013-11-02 20:59 - 00003646 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-11-02 20:54 - 2013-11-02 20:56 - 00000000 ____D C:\Users\Naima\AppData\Local\Google
2013-11-02 20:54 - 2013-11-02 20:56 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-02 20:53 - 2013-11-02 20:54 - 00000000 ____D C:\Users\Naima\AppData\Local\Deployment
2013-11-02 20:53 - 2013-11-02 20:53 - 00000000 ____D C:\Users\Naima\AppData\Local\Apps\2.0
2013-10-26 20:35 - 2013-10-26 20:35 - 00000000 ____D C:\Users\Naima\AppData\Roaming\WildTangent
2013-10-24 18:46 - 2013-11-20 12:47 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1001
2013-10-24 18:40 - 2013-11-04 07:19 - 00000859 _____ C:\Users\Naima\Downloads\Downloads.lnk
2013-10-24 18:40 - 2013-11-04 07:19 - 00000000 ___RD C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-24 18:40 - 2013-11-04 07:19 - 00000000 ___RD C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-10-24 18:40 - 2013-10-24 18:40 - 00001967 _____ C:\Users\Public\Desktop\Netflix.lnk
2013-10-24 18:40 - 2013-10-24 18:40 - 00001768 _____ C:\Users\Public\Desktop\Buy Online.lnk
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\Users\Naima\AppData\Roaming\AcerRemote
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\ProgramData\OEM_YAHOO
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\ProgramData\OEM_E471269A730D
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\Program Files\Accessory Store
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\Program Files (x86)\OEM
2013-10-24 18:40 - 2012-08-23 22:39 - 00000000 _____ C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
2013-10-24 18:39 - 2013-11-11 00:18 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Adobe
2013-10-24 18:39 - 2013-10-24 18:39 - 00001441 _____ C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-24 18:38 - 2013-11-11 12:32 - 00000000 ____D C:\Users\Naima\AppData\Local\Packages
2013-10-24 18:38 - 2013-11-04 18:54 - 00000000 ____D C:\Users\Naima
2013-10-24 18:38 - 2013-11-04 18:44 - 00000000 ____D C:\Users\Naima\AppData\Local\VirtualStore
2013-10-24 18:38 - 2013-10-24 18:38 - 00000020 ___SH C:\Users\Naima\ntuser.ini
2013-10-24 18:38 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-10-24 18:38 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-10-24 18:38 - 2012-07-26 03:13 - 00000000 ___RD C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-10-24 18:38 - 2012-07-26 03:13 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
 
==================== One Month Modified Files and Folders =======
 
2013-11-23 04:17 - 2013-11-23 04:14 - 00015999 _____ C:\Users\Naima\Desktop\FRST.txt
2013-11-23 04:13 - 2013-11-23 04:13 - 00000000 ____D C:\FRST
2013-11-23 04:04 - 2013-11-02 20:54 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-23 04:00 - 2012-07-26 03:12 - 00000000 ____D C:\Windows\system32\sru
2013-11-23 03:52 - 2013-11-23 03:52 - 01957916 _____ (Farbar) C:\Users\Naima\Desktop\FRST64.exe
2013-11-23 03:20 - 2013-07-10 04:32 - 01831067 _____ C:\Windows\WindowsUpdate.log
2013-11-23 02:18 - 2013-11-05 17:03 - 00000000 ____D C:\Users\Naima\AppData\Local\Adobe
2013-11-22 21:14 - 2013-11-04 13:42 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\.minecraft
2013-11-22 20:34 - 2013-11-03 15:50 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1003
2013-11-22 20:29 - 2013-11-02 20:54 - 00000906 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-22 19:39 - 2013-11-16 18:56 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1005
2013-11-22 08:49 - 2013-11-03 14:17 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1004
2013-11-20 23:53 - 2013-11-02 22:45 - 00000000 ____D C:\Users\Dana\AppData\Roaming\.minecraft
2013-11-20 12:47 - 2013-10-24 18:46 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1001
2013-11-20 12:32 - 2013-11-20 12:32 - 00001593 _____ C:\Users\Naima\Desktop\RKreport[0]_S_11202013_123250.txt
2013-11-20 12:32 - 2013-11-20 12:28 - 00000000 ____D C:\Users\Naima\Desktop\RK_Quarantine
2013-11-20 12:27 - 2013-11-20 12:27 - 04161024 _____ C:\Users\Naima\Downloads\RogueKillerX64.exe
2013-11-20 12:22 - 2013-11-20 12:21 - 251139748 _____ C:\Users\Naima\Desktop\REGISTRY_BACKUP.reg
2013-11-20 12:18 - 2013-11-20 12:17 - 00002426 _____ C:\Users\Naima\Desktop\Rkill.txt
2013-11-20 12:17 - 2013-11-20 12:17 - 00000000 ____D C:\Users\Naima\Desktop\rkill
2013-11-20 12:16 - 2013-11-20 12:16 - 01898232 _____ (Bleeping Computer, LLC) C:\Users\Naima\Downloads\rkill.exe
2013-11-20 10:04 - 2012-07-26 03:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-11-20 08:38 - 2013-11-10 11:08 - 00000000 ____D C:\Users\Naima\Desktop\New folder
2013-11-20 08:12 - 2013-11-02 21:52 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3272078143-3078414041-1248702186-1002
2013-11-20 07:36 - 2013-11-20 07:36 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security
2013-11-20 07:36 - 2012-07-26 00:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2013-11-20 07:35 - 2013-03-01 00:14 - 00000000 ____D C:\Windows\system32\Drivers\NISx64
2013-11-20 07:34 - 2013-03-01 00:14 - 00003234 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-11-20 07:34 - 2013-03-01 00:14 - 00002508 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk
2013-11-20 07:34 - 2012-07-26 03:12 - 00000000 ___HD C:\Windows\ELAMBKUP
2013-11-20 01:36 - 2012-07-26 03:12 - 00000000 ____D C:\Windows\rescache
2013-11-19 18:57 - 2013-03-01 00:14 - 00177752 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2013-11-19 18:57 - 2013-03-01 00:14 - 00008222 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2013-11-19 18:56 - 2013-03-01 00:14 - 00000000 ____D C:\ProgramData\Norton
2013-11-19 18:55 - 2013-03-01 00:14 - 00000000 ____D C:\Program Files (x86)\Norton Internet Security
2013-11-19 14:15 - 2012-07-26 02:28 - 00848230 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-19 14:11 - 2012-07-26 02:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-19 14:10 - 2012-07-26 00:26 - 00786432 ___SH C:\Windows\system32\config\BBI
2013-11-19 14:00 - 2013-02-28 22:35 - 00065016 _____ C:\Windows\PFRO.log
2013-11-19 08:15 - 2013-11-19 08:15 - 00000000 ____D C:\Users\Naima\AppData\Roaming\LavasoftStatistics
2013-11-19 08:15 - 2013-11-04 07:19 - 00000000 ____D C:\Users\Naima\AppData\Local\CrashDumps
2013-11-19 07:42 - 2013-11-19 07:42 - 00001334 _____ C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2013-11-19 07:41 - 2013-11-19 07:41 - 00000000 ____D C:\Program Files\Lavasoft
2013-11-19 07:40 - 2013-11-19 07:40 - 00000000 ____D C:\Program Files\Common Files\Lavasoft
2013-11-19 07:39 - 2013-11-19 07:39 - 00000000 ____D C:\ProgramData\Lavasoft
2013-11-19 07:35 - 2013-11-19 07:35 - 01723528 _____ C:\Users\Naima\Downloads\Adaware_Installer.exe
2013-11-18 21:22 - 2013-11-18 21:22 - 00000000 ____D C:\Users\Public\Downloads\Norton
2013-11-18 21:21 - 2013-11-03 15:42 - 00000000 ____D C:\Users\singi_000
2013-11-17 01:40 - 2013-11-17 01:39 - 05094064 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-17 01:38 - 2013-11-03 08:23 - 00000000 ____D C:\Program Files (x86)\ScorpionSaver
2013-11-16 21:31 - 2013-11-16 19:16 - 00000000 ____D C:\Users\Leila\AppData\Roaming\.minecraft
2013-11-16 21:30 - 2013-11-16 21:30 - 00000670 _____ C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft.lnk
2013-11-16 19:13 - 2013-11-16 19:13 - 06316293 _____ C:\Users\Leila\Downloads\JoshSommersIllusions.themepack
2013-11-16 19:02 - 2013-11-16 19:02 - 00000000 ____D C:\Users\Leila\AppData\Local\Google
2013-11-16 18:50 - 2013-11-16 18:50 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-16 18:50 - 2013-11-16 18:50 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-16 18:50 - 2013-11-16 18:47 - 00000000 ____D C:\Users\Leila
2013-11-16 18:49 - 2013-11-16 18:49 - 00001441 _____ C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-16 18:49 - 2013-11-16 18:49 - 00000000 ____D C:\Users\Leila\AppData\Roaming\Adobe
2013-11-16 18:49 - 2013-11-16 18:47 - 00000000 ____D C:\Users\Leila\AppData\Local\Packages
2013-11-16 18:48 - 2013-11-16 18:48 - 00000000 ____D C:\Users\Leila\AppData\Local\VirtualStore
2013-11-16 18:47 - 2013-11-16 18:47 - 00000020 ___SH C:\Users\Leila\ntuser.ini
2013-11-16 09:23 - 2013-11-16 09:23 - 00000000 ____D C:\Users\Dana\AppData\Roaming\SketchUp
2013-11-16 07:35 - 2012-07-26 03:12 - 00000000 ___RD C:\Windows\ToastData
2013-11-16 07:35 - 2012-07-26 03:12 - 00000000 ____D C:\Windows\WinStore
2013-11-14 19:11 - 2013-11-02 20:56 - 00002190 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-14 02:49 - 2013-11-14 02:49 - 00003120 _____ C:\Windows\SysWOW64\ALLFSAF13a.ocx
2013-11-14 02:49 - 2013-11-14 02:48 - 00002195 _____ C:\Users\Public\Desktop\Style Builder 2013.lnk
2013-11-14 02:48 - 2013-11-14 02:48 - 00002109 _____ C:\Users\Public\Desktop\LayOut 2013.lnk
2013-11-14 02:48 - 2013-11-14 02:48 - 00002024 _____ C:\Users\Public\Desktop\SketchUp 2013.lnk
2013-11-14 02:48 - 2013-11-14 02:48 - 00000000 ____D C:\ProgramData\SketchUp
2013-11-14 02:48 - 2013-11-14 02:48 - 00000000 ____D C:\Program Files (x86)\SketchUp
2013-11-14 02:47 - 2013-11-14 02:46 - 75726696 _____ (Trimble Navigation Limited) C:\Users\Dana\Downloads\SketchUpWEN.exe
2013-11-14 02:04 - 2013-11-14 02:04 - 00000057 _____ C:\Users\Dana\AppData\Roaming\mbam.context.scan
2013-11-14 00:28 - 2013-11-02 21:50 - 00000000 ____D C:\Users\Dana\AppData\Local\Google
2013-11-14 00:20 - 2013-11-14 00:20 - 00000000 ____D C:\Users\Dana\AppData\Local\WinZip
2013-11-14 00:13 - 2013-11-14 00:13 - 00035001 _____ C:\Users\Dana\Downloads\VillageInfo_1.6.4.zip
2013-11-13 20:46 - 2013-11-03 14:32 - 00000000 ____D C:\Users\Aria\AppData\Roaming\.minecraft
2013-11-13 07:12 - 2013-11-03 02:53 - 00000000 ____D C:\Windows\system32\MRT
2013-11-13 07:08 - 2013-11-03 02:53 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-12 21:28 - 2013-11-04 18:43 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-11-11 22:54 - 2013-11-11 22:54 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Malwarebytes
2013-11-11 22:48 - 2013-11-07 12:24 - 00000000 ____D C:\Program Files (x86)\Steam
2013-11-11 22:47 - 2013-11-02 21:43 - 00000000 ____D C:\Users\Dana\AppData\Local\VirtualStore
2013-11-11 12:32 - 2013-10-24 18:38 - 00000000 ____D C:\Users\Naima\AppData\Local\Packages
2013-11-11 07:02 - 2013-11-11 07:02 - 13487104 _____ C:\Users\Naima\Downloads\Chapter 8 - Water and Minerals.ppt
2013-11-11 00:18 - 2013-10-24 18:39 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Adobe
2013-11-11 00:14 - 2013-11-06 08:34 - 00000000 ____D C:\Users\Naima\Documents\Adobe
2013-11-11 00:13 - 2013-11-11 00:13 - 00000000 ____D C:\Users\Naima\Desktop\Chromium movie_AME
2013-11-10 23:58 - 2013-11-10 23:57 - 15654458 _____ C:\Users\Naima\Downloads\audiojungle-113870-intense-cinematic-intro-.zip
2013-11-10 21:10 - 2013-11-10 21:10 - 00005256 _____ C:\Users\Naima\Desktop\No_smoking_sign.svg
2013-11-10 20:58 - 2013-11-10 20:58 - 00000000 ____D C:\Users\Naima\AppData\Local\WinZip
2013-11-10 20:04 - 2013-11-10 19:56 - 00002415 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome (2).lnk
2013-11-10 18:17 - 2013-11-10 17:04 - 03932214 _____ C:\Users\Dana\Desktop\screen.bmp
2013-11-10 17:13 - 2013-11-03 16:50 - 00000000 ____D C:\Users\Dana\AppData\Roaming\HpUpdate
2013-11-10 10:26 - 2013-11-09 04:16 - 00000000 ____D C:\Minecraft
2013-11-10 04:08 - 2013-11-10 04:08 - 00000703 _____ C:\Users\Dana\Desktop\Minecraft - Shortcut.lnk
2013-11-10 04:06 - 2013-11-10 04:06 - 00000638 _____ C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft.lnk
2013-11-09 21:37 - 2013-11-09 21:37 - 00000000 ____D C:\Users\Dana\AppData\Local\CrashDumps
2013-11-09 19:15 - 2013-11-09 19:13 - 00002415 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2013-11-09 14:28 - 2013-11-09 14:28 - 00239388 _____ C:\Users\Dana\Downloads\cccoup.oxps
2013-11-09 13:56 - 2013-11-09 13:56 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\Macromedia
2013-11-09 05:29 - 2013-11-09 05:23 - 00000000 ____D C:\Users\Naima\AppData\Roaming\.minecraft
2013-11-09 04:13 - 2013-11-02 22:44 - 00000664 _____ C:\Users\Dana\Downloads\server.properties
2013-11-09 04:13 - 2013-11-02 22:44 - 00000000 ____D C:\Users\Dana\Downloads\world
2013-11-09 04:12 - 2013-11-02 22:44 - 00000110 _____ C:\Users\Dana\Downloads\banned-players.txt
2013-11-09 04:12 - 2013-11-02 22:44 - 00000110 _____ C:\Users\Dana\Downloads\banned-ips.txt
2013-11-09 04:12 - 2013-11-02 22:44 - 00000000 _____ C:\Users\Dana\Downloads\ops.txt
2013-11-09 04:06 - 2013-11-09 04:05 - 00000000 ____D C:\Users\Dana\AppData\Local\Adobe
2013-11-09 04:06 - 2013-11-02 21:44 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Adobe
2013-11-08 22:36 - 2013-11-08 22:36 - 00000056 _____ C:\{FDD44B5A-CE95-4D59-8DF7-603B4620362E}
2013-11-08 21:33 - 2013-11-08 21:33 - 01378230 _____ C:\Users\Naima\Downloads\image (8).jpeg
2013-11-08 19:57 - 2013-11-05 20:24 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-11-08 19:55 - 2013-11-08 19:55 - 01851671 _____ C:\Users\Naima\Downloads\image (7).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01831828 _____ C:\Users\Naima\Downloads\image (6).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01519267 _____ C:\Users\Naima\Downloads\image (3).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01385587 _____ C:\Users\Naima\Downloads\image (1).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01378230 _____ C:\Users\Naima\Downloads\image.jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01370168 _____ C:\Users\Naima\Downloads\image (5).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01331029 _____ C:\Users\Naima\Downloads\image (4).jpeg
2013-11-08 19:55 - 2013-11-08 19:55 - 01206559 _____ C:\Users\Naima\Downloads\image (2).jpeg
2013-11-08 17:29 - 2013-11-08 17:27 - 00000000 ____D C:\Users\Aria\AppData\Local\Adobe
2013-11-08 17:29 - 2013-11-03 14:09 - 00000000 ____D C:\Users\Aria\AppData\Roaming\Adobe
2013-11-08 17:26 - 2013-11-03 14:09 - 00000000 ___RD C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-08 17:26 - 2013-11-03 14:09 - 00000000 ___RD C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-08 14:49 - 2013-11-08 14:49 - 00000682 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft.lnk
2013-11-08 14:49 - 2013-11-08 14:49 - 00000682 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft (2).lnk
2013-11-08 14:49 - 2013-11-08 14:49 - 00000000 ____D C:\Users\singi_000\AppData\Local\CrashDumps
2013-11-07 19:19 - 2013-11-07 19:18 - 123600840 _____ C:\Users\Naima\Downloads\videohive-2475633--intense-movie-trailer.zip
2013-11-07 19:19 - 2013-11-07 19:18 - 00000821 _____ C:\Users\Naima\Downloads\-intense-movie-trailer-license.txt
2013-11-07 12:24 - 2013-11-07 12:24 - 00000924 _____ C:\Users\Public\Desktop\Steam.lnk
2013-11-07 12:24 - 2013-11-02 21:04 - 00000000 ____D C:\Users\Dana
2013-11-07 12:18 - 2013-11-07 12:18 - 01669632 _____ C:\Users\Dana\Downloads\SteamInstall (1).msi
2013-11-07 12:18 - 2013-11-07 12:17 - 01669632 _____ C:\Users\Dana\Downloads\SteamInstall.msi
2013-11-07 11:40 - 2013-11-07 11:40 - 00000000 ____D C:\Users\Naima\AppData\Local\HP
2013-11-06 17:33 - 2013-11-06 17:28 - 00000000 ____D C:\ProgramData\WinZip
2013-11-06 17:29 - 2013-11-06 17:29 - 00002288 _____ C:\Users\Public\Desktop\WinZip.lnk
2013-11-06 17:28 - 2013-11-06 17:28 - 00000000 ____D C:\Program Files\WinZip
2013-11-06 17:21 - 2013-11-06 17:21 - 00000000 ____D C:\Users\Naima\Documents\Add-in Express
2013-11-06 17:20 - 2013-11-06 17:20 - 00000000 ____D C:\Windows\CD95F661A5C444F5A6AAECDD91C240DD.TMP
2013-11-06 17:15 - 2013-11-06 17:14 - 00424392 _____ (WinZip Computing) C:\Users\Naima\Downloads\WinZip175.exe
2013-11-06 17:14 - 2013-11-06 17:13 - 00424392 _____ (WinZip Computing) C:\Users\Naima\Downloads\WinZip175 (1).exe
2013-11-06 17:14 - 2013-11-06 17:12 - 00420808 _____ (WinZip Computing) C:\Users\Naima\Downloads\WinZip180.exe
2013-11-06 15:48 - 2013-11-06 15:48 - 07389078 _____ C:\Users\Naima\Downloads\Project File N°35.rar
2013-11-06 12:28 - 2013-11-06 12:27 - 00000000 ____D C:\Users\Naima\Downloads\cinematic-embers
2013-11-06 11:40 - 2013-11-06 11:39 - 124200452 _____ C:\Users\Naima\Downloads\cinematic-embers.zip
2013-11-05 21:19 - 2013-11-05 21:18 - 00000000 ____D C:\Users\singi_000\AppData\Local\Adobe
2013-11-05 21:19 - 2013-11-03 15:43 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\Adobe
2013-11-05 20:25 - 2013-11-05 20:25 - 00003498 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-Naimas-Naima
2013-11-05 20:24 - 2013-11-05 20:24 - 00000000 ____D C:\Users\Naima\AppData\Roaming\PDAppFlex
2013-11-05 19:19 - 2013-11-05 17:37 - 00000000 ____D C:\Program Files\Adobe
2013-11-05 19:19 - 2013-11-05 17:36 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-05 19:14 - 2013-11-05 17:05 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-11-05 18:49 - 2013-11-05 17:19 - 00000000 ____D C:\ProgramData\Adobe
2013-11-05 17:58 - 2013-11-16 07:38 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-05 17:58 - 2013-11-16 07:38 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-05 17:07 - 2013-11-05 17:07 - 00001074 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2013-11-05 17:03 - 2013-11-05 17:03 - 02841464 _____ (Adobe Systems Incorporated) C:\Users\Naima\Downloads\CreativeCloudSet-Up.exe
2013-11-04 23:02 - 2013-11-04 23:02 - 00020653 _____ C:\Users\Naima\Downloads\4LTR_Excel2010_Ch14_Pr1a_NaimaCostello_2.xlsx
2013-11-04 22:59 - 2013-11-04 21:37 - 00020570 _____ C:\Users\Naima\Downloads\4LTR_Excel2010_Ch14_Pr1a_NaimaCostello_1.xlsx
2013-11-04 21:34 - 2013-11-04 21:34 - 00013097 _____ C:\Users\Naima\Downloads\4LTR_Excel2010_Ch13_Pr1a_NaimaCostello_2.xlsx
2013-11-04 21:33 - 2013-11-04 20:19 - 00013096 _____ C:\Users\Naima\Downloads\4LTR_Excel2010_Ch13_Pr1a_NaimaCostello_1.xlsx
2013-11-04 20:50 - 2013-11-04 20:50 - 00000000 ____D C:\Users\Naima\AppData\Local\Microsoft Help
2013-11-04 18:54 - 2013-11-16 18:47 - 00002111 _____ C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-11-04 18:54 - 2013-11-04 18:54 - 00002129 _____ C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-11-04 18:54 - 2013-11-04 18:54 - 00002111 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-11-04 18:54 - 2013-11-04 18:54 - 00002111 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-11-04 18:54 - 2013-11-04 18:54 - 00000000 ___RD C:\Users\Naima\SkyDrive
2013-11-04 18:54 - 2013-11-04 18:54 - 00000000 ____D C:\ProgramData\Microsoft SkyDrive
2013-11-04 18:54 - 2013-11-04 18:54 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2013-11-04 18:54 - 2013-10-24 18:38 - 00000000 ____D C:\Users\Naima
2013-11-04 18:44 - 2013-10-24 18:38 - 00000000 ____D C:\Users\Naima\AppData\Local\VirtualStore
2013-11-04 18:43 - 2013-11-04 18:43 - 00572088 _____ (Microsoft Corporation) C:\Users\Naima\Downloads\Setup.X86.en-US_O365HomePremRetail_7fa16cfe-386e-4146-84aa-dec280ae03a2_TX_PR_.exe
2013-11-04 16:56 - 2013-11-04 16:56 - 00177229 _____ C:\Users\Naima\Desktop\Naima 4.htm
2013-11-04 16:56 - 2013-11-04 16:56 - 00000000 ____D C:\Users\Naima\Desktop\Naima 4_files
2013-11-04 16:46 - 2013-11-04 16:46 - 00177529 _____ C:\Users\Naima\Desktop\naima2.htm
2013-11-04 16:46 - 2013-11-04 16:46 - 00000000 ____D C:\Users\Naima\Desktop\naima2_files
2013-11-04 16:42 - 2013-11-04 16:42 - 00177343 _____ C:\Users\Naima\Desktop\naima1.htm
2013-11-04 16:42 - 2013-11-04 16:42 - 00000000 ____D C:\Users\Naima\Desktop\naima1_files
2013-11-04 12:39 - 2013-11-03 15:43 - 00000000 ___RD C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-04 12:39 - 2013-11-03 15:43 - 00000000 ___RD C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-04 11:12 - 2013-11-02 21:44 - 00000000 ___RD C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-04 11:12 - 2013-11-02 21:44 - 00000000 ___RD C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-04 07:24 - 2013-11-04 07:24 - 00001120 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-11-04 07:24 - 2013-11-04 07:24 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Malwarebytes
2013-11-04 07:24 - 2013-11-04 07:23 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-04 07:23 - 2013-11-04 07:23 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-04 07:22 - 2013-11-04 07:22 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Naima\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-04 07:21 - 2013-11-04 07:21 - 00683016 _____ C:\Users\Naima\Downloads\malwarebytes-anti-malware_setup.exe
2013-11-04 07:19 - 2013-10-24 18:40 - 00000859 _____ C:\Users\Naima\Downloads\Downloads.lnk
2013-11-04 07:19 - 2013-10-24 18:40 - 00000000 ___RD C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-04 07:19 - 2013-10-24 18:40 - 00000000 ___RD C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-04 07:15 - 2013-11-04 07:15 - 00000000 ____D C:\ProgramData\boost_interprocess
2013-11-04 07:13 - 2012-07-26 00:38 - 00000000 ____D C:\Windows\system32\oobe
2013-11-04 07:12 - 2013-11-04 07:08 - 00000000 ____D C:\AdwCleaner
2013-11-04 07:07 - 2013-11-04 07:07 - 01073258 _____ C:\Users\Naima\Downloads\adwcleaner.exe
2013-11-04 00:17 - 2013-11-04 00:17 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Macromedia
2013-11-03 22:04 - 2013-11-03 21:59 - 00000000 ____D C:\8100b355c6640be0a64b
2013-11-03 21:59 - 2013-11-03 21:59 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-11-03 21:59 - 2013-11-03 21:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-11-03 21:58 - 2013-11-03 21:58 - 13079688 _____ (Microsoft Corporation) C:\Users\Naima\Downloads\Silverlight_x64.exe
2013-11-03 21:53 - 2013-11-03 21:53 - 00001114 _____ C:\Users\Naima\Desktop\Flash Player Pro.lnk
2013-11-03 21:53 - 2013-11-03 21:53 - 00000000 ____D C:\Users\Naima\Documents\Flash Player Pro
2013-11-03 21:53 - 2013-11-03 21:53 - 00000000 ____D C:\Users\Naima\AppData\Local\NativeMessaging
2013-11-03 21:53 - 2013-11-03 21:53 - 00000000 ____D C:\Users\Naima\AppData\Local\CRE
2013-11-03 21:53 - 2013-11-03 21:53 - 00000000 ____D C:\Program Files (x86)\Flash Player Pro
2013-11-03 20:49 - 2012-07-26 00:37 - 00000000 ____D C:\Windows\servicing
2013-11-03 20:44 - 2013-11-16 18:47 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-03 20:44 - 2012-07-26 03:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-03 20:44 - 2012-07-26 03:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-11-03 20:44 - 2012-07-26 03:12 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-03 20:44 - 2012-07-26 03:12 - 00000000 ____D C:\Program Files\Windows Defender
2013-11-03 20:44 - 2012-07-26 03:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-03 20:44 - 2012-07-26 03:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-11-03 20:44 - 2012-07-26 02:52 - 00000000 ____D C:\Program Files\Windows Journal
2013-11-03 20:41 - 2013-11-16 18:47 - 00000000 ___RD C:\Users\Leila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-03 20:41 - 2012-07-26 03:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-03 20:41 - 2012-07-26 03:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-11-03 20:41 - 2012-07-26 03:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-11-03 20:41 - 2012-07-26 03:12 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-11-03 20:41 - 2012-07-26 00:38 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-11-03 20:41 - 2012-07-26 00:38 - 00000000 ____D C:\Windows\system32\Dism
2013-11-03 19:57 - 2013-11-03 19:57 - 00000000 ____D C:\Users\Dana\AppData\Roaming\WildTangent
2013-11-03 19:57 - 2013-11-03 19:57 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Macromedia
2013-11-03 19:57 - 2013-03-01 00:08 - 00000000 ____D C:\ProgramData\WildTangent
2013-11-03 19:57 - 2013-03-01 00:08 - 00000000 ____D C:\Program Files (x86)\WildTangent Games
2013-11-03 19:49 - 2013-11-03 19:49 - 08402527 _____ C:\Users\Dana\Downloads\DarkSkiesTracyHymas.themepack
2013-11-03 17:34 - 2013-11-03 17:34 - 00000000 ____D C:\Users\Aria\AppData\Local\CrashDumps
2013-11-03 17:14 - 2013-11-03 17:14 - 07330863 _____ C:\Users\Dana\Downloads\FrostMacros_DLawler.themepack
2013-11-03 17:14 - 2013-11-03 17:14 - 06823554 _____ C:\Users\Dana\Downloads\CreepyCobwebs.themepack
2013-11-03 16:55 - 2013-11-03 16:48 - 00000000 ____D C:\Users\Dana\AppData\Local\HP
2013-11-03 16:53 - 2013-11-03 15:42 - 00000000 ____D C:\Users\singi_000\AppData\Local\Packages
2013-11-03 16:51 - 2013-11-03 16:51 - 00002002 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk
2013-11-03 16:51 - 2013-11-03 16:51 - 00000000 ____D C:\ProgramData\Visan
2013-11-03 16:51 - 2013-11-03 16:51 - 00000000 ____D C:\ProgramData\HP Photo Creations
2013-11-03 16:51 - 2013-11-03 16:51 - 00000000 ____D C:\Program Files (x86)\HP Photo Creations
2013-11-03 16:51 - 2013-11-03 16:51 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2013-11-03 16:50 - 2013-11-03 16:50 - 00003606 _____ C:\Windows\System32\Tasks\HPCustParticipation HP Deskjet 2540 series
2013-11-03 16:50 - 2013-11-03 16:50 - 00002219 _____ C:\Users\Public\Desktop\HP Deskjet 2540 series.lnk
2013-11-03 16:50 - 2013-11-03 16:50 - 00001166 _____ C:\Users\Public\Desktop\Shop for Supplies - HP Deskjet 2540 series.lnk
2013-11-03 16:50 - 2013-11-03 16:50 - 00000000 ____D C:\Program Files (x86)\HP
2013-11-03 16:50 - 2013-11-03 16:41 - 00000000 ____D C:\ProgramData\HP
2013-11-03 16:49 - 2013-11-03 16:49 - 00000057 _____ C:\ProgramData\Ament.ini
2013-11-03 16:49 - 2013-11-03 16:49 - 00000000 ____D C:\Program Files\HP
2013-11-03 16:46 - 2013-11-03 16:46 - 02338824 _____ C:\Users\Dana\Downloads\hppiw.exe
2013-11-03 16:42 - 2013-11-02 21:43 - 00000000 ____D C:\Users\Dana\AppData\Local\Packages
2013-11-03 16:41 - 2013-11-03 16:41 - 15166732 _____ C:\Users\Dana\Downloads\PanoramicAnimals.deskthemepack
2013-11-03 15:53 - 2013-11-03 15:53 - 00000000 ____D C:\Users\singi_000\AppData\Local\Google
2013-11-03 15:43 - 2013-11-03 15:43 - 00001441 _____ C:\Users\singi_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-03 15:43 - 2013-11-03 15:43 - 00000000 ____D C:\Users\singi_000\AppData\Roaming\AcerRemote
2013-11-03 15:42 - 2013-11-03 15:42 - 00000020 ___SH C:\Users\singi_000\ntuser.ini
2013-11-03 15:42 - 2013-11-03 15:42 - 00000000 ____D C:\Users\singi_000\AppData\Local\VirtualStore
2013-11-03 14:41 - 2013-11-03 14:41 - 00000000 ____D C:\Users\Aria\AppData\Local\Google
2013-11-03 14:34 - 2013-11-03 14:34 - 00000000 ____D C:\Users\Aria\AppData\Roaming\Macromedia
2013-11-03 14:16 - 2013-11-03 14:08 - 00000000 ____D C:\Users\Aria\AppData\Local\Packages
2013-11-03 14:10 - 2013-11-03 14:10 - 00000000 ____D C:\Users\Aria\AppData\Roaming\AcerRemote
2013-11-03 14:09 - 2013-11-03 14:09 - 00001441 _____ C:\Users\Aria\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-03 14:09 - 2013-11-03 14:09 - 00000000 ____D C:\Users\Aria\AppData\Local\VirtualStore
2013-11-03 14:09 - 2013-11-03 14:05 - 00000000 ____D C:\Users\Aria
2013-11-03 14:05 - 2013-11-03 14:05 - 00000020 ___SH C:\Users\Aria\ntuser.ini
2013-11-03 10:13 - 2013-11-03 10:13 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2013-11-03 10:13 - 2012-07-26 02:21 - 00019860 _____ C:\Windows\setupact.log
2013-11-03 08:24 - 2013-11-03 08:24 - 00003854 _____ C:\Windows\System32\Tasks\BrowserSafeguard Update Task
2013-11-03 08:23 - 2013-11-03 08:23 - 00000000 ____D C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WordOv
2013-11-03 08:22 - 2013-11-03 08:22 - 00000000 ____D C:\Program Files (x86)\sp
2013-11-03 08:22 - 2013-11-03 08:22 - 00000000 ____D C:\Program Files (x86)\Social Privacy  DNS
2013-11-02 23:11 - 2013-11-02 23:11 - 00000000 ____D C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-11-02 22:45 - 2013-11-16 19:15 - 00675988 _____ C:\Users\Leila\Desktop\Minecraft.exe
2013-11-02 22:45 - 2013-11-04 13:42 - 00675988 _____ C:\Users\singi_000\Desktop\Minecraft.exe
2013-11-02 22:45 - 2013-11-03 14:22 - 00675988 _____ C:\Users\Aria\Desktop\Minecraft.exe
2013-11-02 22:45 - 2013-11-02 22:45 - 00675988 _____ C:\Users\Dana\Desktop\Minecraft.exe
2013-11-02 22:44 - 2013-11-02 22:44 - 00000000 _____ C:\Users\Dana\Downloads\white-list.txt
2013-11-02 22:43 - 2013-11-02 22:43 - 00000000 ____D C:\ProgramData\Sun
2013-11-02 22:43 - 2013-11-02 22:43 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 22:42 - 2013-11-02 22:42 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-02 22:42 - 2013-11-02 22:42 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-02 22:42 - 2013-11-02 22:42 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-02 22:42 - 2013-11-02 22:42 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-02 22:42 - 2013-11-02 22:42 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-02 22:40 - 2013-11-02 22:40 - 00915368 _____ (Oracle Corporation) C:\Users\Dana\Downloads\chromeinstall-7u45.exe
2013-11-02 21:55 - 2013-11-02 21:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2013-11-02 21:44 - 2013-11-02 21:44 - 00001441 _____ C:\Users\Dana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-02 21:44 - 2013-11-02 21:44 - 00000000 ____D C:\Users\Dana\AppData\Roaming\AcerRemote
2013-11-02 21:04 - 2013-11-02 21:04 - 00000020 ___SH C:\Users\Dana\ntuser.ini
2013-11-02 20:59 - 2013-11-02 20:54 - 00003882 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-11-02 20:59 - 2013-11-02 20:54 - 00003646 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-11-02 20:56 - 2013-11-02 20:54 - 00000000 ____D C:\Users\Naima\AppData\Local\Google
2013-11-02 20:56 - 2013-11-02 20:54 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-02 20:54 - 2013-11-02 20:53 - 00000000 ____D C:\Users\Naima\AppData\Local\Deployment
2013-11-02 20:53 - 2013-11-02 20:53 - 00000000 ____D C:\Users\Naima\AppData\Local\Apps\2.0
2013-11-02 20:44 - 2013-07-10 04:51 - 00000000 ____D C:\ProgramData\OEM
2013-11-02 10:55 - 2012-07-26 03:12 - 00000000 ____D C:\Windows\system32\restore
2013-10-26 20:35 - 2013-10-26 20:35 - 00000000 ____D C:\Users\Naima\AppData\Roaming\WildTangent
2013-10-24 18:41 - 2013-02-28 22:29 - 00000000 ___HD C:\OEM
2013-10-24 18:40 - 2013-10-24 18:40 - 00001967 _____ C:\Users\Public\Desktop\Netflix.lnk
2013-10-24 18:40 - 2013-10-24 18:40 - 00001768 _____ C:\Users\Public\Desktop\Buy Online.lnk
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\Users\Naima\AppData\Roaming\AcerRemote
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\ProgramData\OEM_YAHOO
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\ProgramData\OEM_E471269A730D
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\Program Files\Accessory Store
2013-10-24 18:40 - 2013-10-24 18:40 - 00000000 ____D C:\Program Files (x86)\OEM
2013-10-24 18:39 - 2013-10-24 18:39 - 00001441 _____ C:\Users\Naima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-24 18:38 - 2013-10-24 18:38 - 00000020 ___SH C:\Users\Naima\ntuser.ini
2013-10-24 18:38 - 2012-07-26 03:12 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
 
Some content of TEMP:
====================
C:\Users\Dana\AppData\Local\Temp\HPInstaller.exe
C:\Users\Naima\AppData\Local\Temp\44D8_FPPSetup.exe
C:\Users\Naima\AppData\Local\Temp\7-zip.exe
C:\Users\Naima\AppData\Local\Temp\air1A71.exe
C:\Users\Naima\AppData\Local\Temp\air42F8.exe
C:\Users\Naima\AppData\Local\Temp\air44D7.exe
C:\Users\Naima\AppData\Local\Temp\air4BFA.exe
C:\Users\Naima\AppData\Local\Temp\BackupSetup.exe
C:\Users\Naima\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\Naima\AppData\Local\Temp\ntdll_dump.dll
C:\Users\Naima\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Naima\AppData\Local\Temp\oi_{65C46D49-2049-4E7A-9D2B-162BD7B5A967}.exe
C:\Users\Naima\AppData\Local\Temp\Quarantine.exe
C:\Users\Naima\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\Naima\AppData\Local\Temp\vcredist_x64.exe
 
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
LastRegBack: 2013-11-18 08:19
 
==================== End Of Log ============================
Link to post
Share on other sites

Addition.txt: 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-11-2013
Ran by Naima at 2013-11-23 04:33:30
Running from C:\Users\Naima\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
AV: Ad-Aware Antivirus (Disabled - Out of date) {D87B6541-12A1-DAEA-0033-9B8057AAB996}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Ad-Aware Antivirus (Disabled - Out of date) {631A84A5-349B-D564-3A83-A0F22C2DF32B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
FW: Ad-Aware Firewall (Disabled) {E040E464-58CE-DBB2-2B6C-32B5A979FEED}
 
==================== Installed Programs ======================
 
Acer Remote (x32 Version: 1.0)
Ad-Aware Antivirus (Version: 11.0.4555.0)
AdAwareInstaller (Version: 11.0.4555.0)
AdAwareUpdater (Version: 11.0.4555.0)
Adobe Creative Cloud (x32 Version: 2.2.0.248)
AMD Accelerated Video Transcoding (Version: 12.5.100.21106)
AMD APP SDK Runtime (Version: 10.0.1084.4)
AMD Catalyst Install Manager (Version: 8.0.903.0)
AMD VISION Engine Control Center (x32 Version: 2012.1106.1640.29876)
AntimalwareEngine (Version: 2.6.0.0)
Bejeweled 3 (x32 Version: 2.2.0.98)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center InstallProxy (x32 Version: 2012.1106.1640.29876)
Catalyst Control Center Localization All (x32 Version: 2012.1106.1640.29876)
CCC Help Chinese Standard (x32 Version: 2012.1106.1639.29876)
CCC Help Chinese Traditional (x32 Version: 2012.1106.1639.29876)
CCC Help Czech (x32 Version: 2012.1106.1639.29876)
CCC Help Danish (x32 Version: 2012.1106.1639.29876)
CCC Help Dutch (x32 Version: 2012.1106.1639.29876)
CCC Help English (x32 Version: 2012.1106.1639.29876)
CCC Help Finnish (x32 Version: 2012.1106.1639.29876)
CCC Help French (x32 Version: 2012.1106.1639.29876)
CCC Help German (x32 Version: 2012.1106.1639.29876)
CCC Help Greek (x32 Version: 2012.1106.1639.29876)
CCC Help Hungarian (x32 Version: 2012.1106.1639.29876)
CCC Help Italian (x32 Version: 2012.1106.1639.29876)
CCC Help Japanese (x32 Version: 2012.1106.1639.29876)
CCC Help Korean (x32 Version: 2012.1106.1639.29876)
CCC Help Norwegian (x32 Version: 2012.1106.1639.29876)
CCC Help Polish (x32 Version: 2012.1106.1639.29876)
CCC Help Portuguese (x32 Version: 2012.1106.1639.29876)
CCC Help Russian (x32 Version: 2012.1106.1639.29876)
CCC Help Spanish (x32 Version: 2012.1106.1639.29876)
CCC Help Swedish (x32 Version: 2012.1106.1639.29876)
CCC Help Thai (x32 Version: 2012.1106.1639.29876)
CCC Help Turkish (x32 Version: 2012.1106.1639.29876)
ccc-utility64 (Version: 2012.1106.1640.29876)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110)
CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3318_45364)
CyberLink PowerDVD 12 (x32 Version: 12.0.2531.57)
Delicious: Emily's Childhood Memories Premium Edition (x32 Version: 3.0.2.32)
eBay Worldwide (x32 Version: 2.4.0105)
Flash Player Pro V5.4 (x32)
Game Channels (x32 Version: 8.1.0.17)
Gateway Power Management (Version: 7.00.3012)
Gateway Recovery Management (Version: 6.00.3016)
Google Chrome (x32 Version: 31.0.1650.57)
Google Update Helper (x32 Version: 1.3.21.165)
Hotkey Utility (x32 Version: 3.00.3004)
HP Deskjet 2540 series Basic Device Software (Version: 32.0.1180.44630)
HP Deskjet 2540 series Help (x32 Version: 30.0.0)
HP Photo Creations (x32 Version: 1.0.0.7702)
HP Update (x32 Version: 5.005.002.002)
Identity Card (x32 Version: 2.00.3004)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Jewel Match 3 (x32 Version: 2.2.0.98)
Live Updater (x32 Version: 2.00.3007)
Malwarebytes Anti-Malware version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft Office 365 Home Premium - en-us (Version: 15.0.4551.1005)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SkyDrive (HKCU Version: 16.4.6013.0910)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98)
Nero BackItUp (x32 Version: 12.5.5000)
Nero BackItUp 12 Essentials OEM.a01 (x32 Version: 12.5.00500)
Nero BackItUp Help (CHM) (x32 Version: 12.0.10000)
Nero ControlCenter (x32 Version: 11.0.15600)
Nero ControlCenter Help (CHM) (x32 Version: 12.0.7000)
Nero Core Components (x32 Version: 11.0.20200)
Nero Launcher (x32 Version: 12.2.7000)
Nero RescueAgent (x32 Version: 12.0.3001)
Nero RescueAgent Help (CHM) (x32 Version: 12.0.7000)
Nero Update (x32 Version: 11.0.11800.31.0)
Norton Internet Security (x32 Version: 21.1.0.18)
Norton Online Backup (x32 Version: 2.2.3.51r2)
Norton Online Backup ARA (x32 Version: 4.1.0.14)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4551.1005)
Office 15 Click-to-Run Licensing Component (Version: 15.0.4551.1005)
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4551.1005)
PDF Settings CC (x32 Version: 12.0)
Peggle Nights (x32 Version: 2.2.0.98)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98)
Prerequisite installer (x32 Version: 12.0.0003)
Product Improvement Study for HP Deskjet 2540 series (Version: 32.0.1180.44630)
Realtek Ethernet Controller Driver (x32 Version: 8.3.730.2012)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6680)
Realtek USB 2.0 Card Reader (x32 Version: 6.2.8400.30137)
ScorpionSaver (x32 Version: 1.0.0.0)
SketchUp 2013 (x32 Version: 13.0.4812)
Social Privacy DNS (x32)
Spotify (x32 Version: 0.8.4.99.ga249b5f1)
Steam (x32 Version: 1.0.0.0)
Tales of Lagoona (x32 Version: 2.2.0.110)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.32)
Update Installer for WildTangent Games App (x32)
WildTangent Games (x32 Version: 1.0.4.0)
WildTangent Games App (x32 Version: 4.0.10.5)
WinZip 18.0 (Version: 18.0.10661)
 
==================== Restore Points  =========================
 
19-11-2013 12:39:15 AA11
 
==================== Hosts content: ==========================
 
2012-07-26 00:26 - 2012-07-26 00:26 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
Task: {115133B6-EE23-4CB6-B637-BD54A51597AF} - \BackgroundContainer Startup Task No Task File
Task: {1A5AE40B-7387-42B1-A5FA-4B481D7D742D} - System32\Tasks\BrowserSafeguard Update Task => C:\Program Files (x86)\Browsersafeguard\uninstall.browsersafeguard.exe
Task: {3D8BB530-76C3-4BC5-AEEC-3223ED15C4A2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02] (Google Inc.)
Task: {4C225A27-4663-4FF6-93FC-B1593F7B1ABE} - System32\Tasks\AdobeAAMUpdater-1.0-Naimas-Naima => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2013-09-25] (Adobe Systems Incorporated)
Task: {5A1750FF-10B1-4D67-9A8D-6C0589736E41} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Gateway\Live Updater\liveupdater_agent.exe [2013-01-22] ()
Task: {5AC3D0BE-0B9F-4C0B-99A3-4C683CA1D279} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-17] (Microsoft Corporation)
Task: {62A864A7-44D1-4CCC-86D3-2BECF8824450} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation)
Task: {6A63896E-74E5-4ABE-8A19-0E6988E9DBD9} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\WSCStub.exe [2013-10-08] (Symantec Corporation)
Task: {6CC4CC53-EEC2-49DA-872B-8F6BB517E6AA} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\System32\NotificationUI.exe [2013-08-16] (Microsoft Corporation)
Task: {8FF4806C-5AFF-4EBB-A456-50A73B0FD5E6} - System32\Tasks\Power Management => C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe [2013-01-18] (Acer Incorporated)
Task: {9D8804D8-CFCE-48C6-A50D-37C4C7FF4E86} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2013-11-12] (Microsoft Corporation)
Task: {A45666DE-DBAD-4955-9D58-40DFB899130B} - System32\Tasks\ALU => C:\Program Files (x86)\Gateway\Live Updater\updater.exe [2013-01-22] ()
Task: {B11C7EDB-684B-42E1-BB9E-6BC43BDF4D00} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-09-19] (CyberLink)
Task: {BB3D35F3-D426-459A-AE41-08E1FA53A6D9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02] (Google Inc.)
Task: {D45FF1A1-8629-4278-BC79-D6F975F761EB} - System32\Tasks\HPCustParticipation HP Deskjet 2540 series => C:\Program Files\HP\HP Deskjet 2540 series\Bin\HPCustPartic.exe [2013-08-13] (Hewlett-Packard Co.)
Task: {E6D49A29-2C56-4F5B-85A8-CB15E2BA3F50} - System32\Tasks\Hotkey Utility => C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe [2012-09-20] (Acer Incorporated)
Task: {E83446C0-6596-4383-AFE2-230348E08F0B} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\symerr.exe [2013-08-01] (Symantec Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2013-10-16 18:02 - 2013-10-16 18:02 - 03358064 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
2013-11-12 21:26 - 2013-11-12 21:26 - 08866472 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00158032 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\pugixml.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 02747720 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\RCF.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00123264 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\boost_filesystem-vc100-mt-1_53.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00023928 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\boost_system-vc100-mt-1_53.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00055168 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\boost_date_time-vc100-mt-1_53.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00102264 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\boost_thread-vc100-mt-1_53.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00499576 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\boost_locale-vc100-mt-1_53.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00267616 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\HtmlFramework.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00276816 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\Logger.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00064856 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\DllStorage.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00643440 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\AdAwareTrayDefaultSkin.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00140120 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\Localization.dll
2013-10-18 18:02 - 2013-10-18 18:02 - 00685904 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.0.4555.0\SQLite.dll
2013-11-14 19:11 - 2013-11-14 06:28 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
2013-11-14 19:11 - 2013-11-14 06:28 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\libegl.dll
2013-11-14 19:11 - 2013-11-14 06:29 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-14 19:11 - 2013-11-14 06:29 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-14 19:11 - 2013-11-14 06:28 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
2013-11-14 19:11 - 2013-11-14 06:29 - 13582800 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll
2013-11-23 04:26 - 2013-11-23 04:26 - 00294912 _____ () C:\Users\Dana\AppData\Roaming\.minecraft\versions\1.7.2\1.7.2-natives-310520620972500\lwjgl.dll
2013-11-23 04:26 - 2013-11-23 04:26 - 00390144 _____ () C:\Users\Dana\AppData\Roaming\.minecraft\versions\1.7.2\1.7.2-natives-310520620972500\OpenAL32.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
AlternateDataStreams: C:\ProgramData\Temp:D346F792
 
==================== Safe Mode (whitelisted) ===================
 
 
==================== Faulty Device Manager Devices =============
 
Name: Photosmart D110 series
Description: Photosmart D110 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/22/2013 09:34:15 PM) (Source: Chrome) (User: NT AUTHORITY)
Description: Chrome has encountered a fatal error.
ver=31.0.1650.57;lang=;id=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\bd4a54cb-9fa0-4e98-9c80-e250e9648255.dmp
 
Error: (11/22/2013 08:42:13 PM) (Source: Chrome) (User: NT AUTHORITY)
Description: Chrome has encountered a fatal error.
ver=31.0.1650.57;lang=;id=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\670ed308-cc38-42c6-b3c2-b6574e965032.dmp
 
Error: (11/22/2013 08:11:36 PM) (Source: Application Error) (User: )
Description: Faulting application name: chrome.exe, version: 31.0.1650.57, time stamp: 0x5284a422
Faulting module name: coreclr.dll, version: 5.1.20913.0, time stamp: 0x5232c8ca
Exception code: 0x8013150a
Fault offset: 0x000475eb
Faulting process id: 0x2a04
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
Faulting package full name: chrome.exe4
Faulting package-relative application ID: chrome.exe5
 
Error: (11/22/2013 08:11:34 PM) (Source: .NET Runtime) (User: )
Description: Application: chrome.exe
CoreCLR Version: 5.1.20913.0
Description: The process was terminated due to an internal error in the .NET Runtime at IP 683E75EB (683A0000) with exit code 8013150a.
 
Error: (11/19/2013 08:15:07 AM) (Source: Application Error) (User: )
Description: Faulting application name: AdAwareUpdater.exe, version: 11.0.4555.0, time stamp: 0x526146a6
Faulting module name: Localization.dll, version: 11.0.4555.0, time stamp: 0x52614435
Exception code: 0xc0000005
Fault offset: 0x0000000000001922
Faulting process id: 0x14bc
Faulting application start time: 0xAdAwareUpdater.exe0
Faulting application path: AdAwareUpdater.exe1
Faulting module path: AdAwareUpdater.exe2
Report Id: AdAwareUpdater.exe3
Faulting package full name: AdAwareUpdater.exe4
Faulting package-relative application ID: AdAwareUpdater.exe5
 
Error: (11/19/2013 07:39:53 AM) (Source: MsiInstaller) (User: Naimas)
Description: Failed to begin a Windows Installer transaction AA11. Error 1618 occurred while beginning the transaction.
 
Error: (11/17/2013 10:12:46 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Naimas)
Description: Activation of app Microsoft.BingFinance_8wekyb3d8bbwe!AppexFinance failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (11/17/2013 10:12:46 PM) (Source: Application Hang) (User: )
Description: The program wwahost.exe version 6.2.9200.16420 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1914
 
Start Time: 01cee40ba06a329b
 
Termination Time: 4294967295
 
Application Path: C:\Windows\system32\wwahost.exe
 
Report Id: ea0e8c12-4ffe-11e3-be7b-7427eab37c02
 
Faulting package full name: Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: AppexFinance
 
Error: (11/17/2013 10:11:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Naimas)
Description: Activation of app Microsoft.XboxLIVEGames_8wekyb3d8bbwe!Microsoft.XboxLIVEGames failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (11/17/2013 10:11:23 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Naimas)
Description: App Microsoft.XboxLIVEGames_8wekyb3d8bbwe!Microsoft.XboxLIVEGames did not launch within its allotted time.
 
 
System errors:
=============
Error: (11/23/2013 03:57:03 AM) (Source: DCOM) (User: Naimas)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/23/2013 03:57:03 AM) (Source: DCOM) (User: Naimas)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/23/2013 03:56:56 AM) (Source: DCOM) (User: Naimas)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/23/2013 03:56:56 AM) (Source: DCOM) (User: Naimas)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
 
Error: (11/22/2013 08:27:34 PM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 9\_TZ.THRM2013-11-23T01:27:34.581046800Z383
 
Error: (11/22/2013 07:30:09 PM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 9\_TZ.THRM2013-11-23T00:30:09.600167700Z383
 
Error: (11/22/2013 05:27:11 PM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 9\_TZ.THRM2013-11-22T22:27:11.635475300Z383
 
Error: (11/22/2013 02:32:24 PM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 9\_TZ.THRM2013-11-22T19:32:24.627367800Z383
 
Error: (11/22/2013 09:52:51 AM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 9\_TZ.THRM2013-11-22T14:52:51.587235100Z383
 
Error: (11/22/2013 03:57:04 AM) (Source: Microsoft-Windows-Kernel-Power) (User: )
Description: 9\_TZ.THRM2013-11-22T08:57:04.583187200Z383
 
 
Microsoft Office Sessions:
=========================
Error: (11/22/2013 09:34:15 PM) (Source: Chrome)(User: NT AUTHORITY)
Description: Chrome has encountered a fatal error.
ver=31.0.1650.57;lang=;id=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\bd4a54cb-9fa0-4e98-9c80-e250e9648255.dmp
 
Error: (11/22/2013 08:42:13 PM) (Source: Chrome)(User: NT AUTHORITY)
Description: Chrome has encountered a fatal error.
ver=31.0.1650.57;lang=;id=;is_machine=1;oop=1;upload=1;minidump=C:\Program Files (x86)\Google\CrashReports\670ed308-cc38-42c6-b3c2-b6574e965032.dmp
 
Error: (11/22/2013 08:11:36 PM) (Source: Application Error)(User: )
Description: chrome.exe31.0.1650.575284a422coreclr.dll5.1.20913.05232c8ca8013150a000475eb2a0401cee7e42cd16643C:\Program Files (x86)\Google\Chrome\Application\chrome.exec:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\coreclr.dll3243392b-53dc-11e3-be7d-7427eab37c02
 
Error: (11/22/2013 08:11:34 PM) (Source: .NET Runtime)(User: )
Description: Application: chrome.exe
CoreCLR Version: 5.1.20913.0
Description: The process was terminated due to an internal error in the .NET Runtime at IP 683E75EB (683A0000) with exit code 8013150a.
 
Error: (11/19/2013 08:15:07 AM) (Source: Application Error)(User: )
Description: AdAwareUpdater.exe11.0.4555.0526146a6Localization.dll11.0.4555.052614435c0000005000000000000192214bc01cee524828cfb8dC:\Program Files\Common Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus Updater\11.0.4555.0\AdAwareUpdater.exeC:\Program Files\Common Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus Updater\11.0.4555.0\Localization.dll9bf8fc51-511c-11e3-be7b-7427eab37c02
 
Error: (11/19/2013 07:39:53 AM) (Source: MsiInstaller)(User: Naimas)
Description: AA111618(NULL)(NULL)(NULL)(NULL)
 
Error: (11/17/2013 10:12:46 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Naimas)
Description: Microsoft.BingFinance_8wekyb3d8bbwe!AppexFinance-2144927142
 
Error: (11/17/2013 10:12:46 PM) (Source: Application Hang)(User: )
Description: wwahost.exe6.2.9200.16420191401cee40ba06a329b4294967295C:\Windows\system32\wwahost.exeea0e8c12-4ffe-11e3-be7b-7427eab37c02Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbweAppexFinance
 
Error: (11/17/2013 10:11:26 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Naimas)
Description: Microsoft.XboxLIVEGames_8wekyb3d8bbwe!Microsoft.XboxLIVEGames-2144927142
 
Error: (11/17/2013 10:11:23 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Naimas)
Description: Microsoft.XboxLIVEGames_8wekyb3d8bbwe!Microsoft.XboxLIVEGames
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 76%
Total physical RAM: 3801.82 MB
Available physical RAM: 911.34 MB
Total Pagefile: 11481.82 MB
Available Pagefile: 4553.73 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB
 
==================== Drives ================================
 
Drive c: (Gateway) (Fixed) (Total:449.21 GB) (Free:363.71 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 466 GB) (Disk ID: F3A2B566)
 
Partition: GPT Partition Type
==================== End Of Log ============================
Link to post
Share on other sites

 Results of screen317's Security Check version 0.99.77  

   x64 (UAC is enabled)  

 Internet Explorer 10 Out of date! 

``````````````Antivirus/Firewall Check:`````````````` 

 Windows Firewall Enabled!  

Ad-Aware Antivirus         

Windows Defender           

Norton Internet Security   

 Antivirus out of date! (On Access scanning disabled!) 

`````````Anti-malware/Other Utilities Check:````````` 

 Malwarebytes Anti-Malware version 1.75.0.1300  

 Java 7 Update 45  

 Google Chrome 31.0.1650.48  

 Google Chrome 31.0.1650.57  

````````Process Check: objlist.exe by Laurent````````  

 Malwarebytes Anti-Malware mbamservice.exe  

 Malwarebytes Anti-Malware mbamgui.exe  

 Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4555.0\AdAwareService.exe 

 Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.0.4555.0\AdAwareTray.exe 

 Malwarebytes' Anti-Malware mbamscheduler.exe   

 Symantec Norton Online Backup NOBuAgent.exe  

`````````````````System Health check````````````````` 

 Total Fragmentation on Drive C:  % 

````````````````````End of Log`````````````````````` 
Link to post
Share on other sites

There is a definite security clash on your system, Windows Defender cannot be enabled whilst you have Norton IS installed. You also have Lavasoft security suite installed.

 

OK do the following to UNnstall Lavasoft and Scorpion. Ensure both are uninstalled

 

Please download and install Revo Uninstaller Free

 

 

  •  

     

  • Double click Revo Uninstaller to run it.

     

     

  • From the list of programs double click on The Program to remove <<--- Scorpion and Lavasoft

     

     

  • When prompted if you want to uninstall click Yes.

     

     

  • Be sure the Moderate option is selected then click Next.

     

     

  • The program will run, If prompted again click Yes

     

     

  • When the built-in uninstaller is finished click on Next.

     

     

  • Once the program has searched for leftovers click Next.

     

     

  • Check/tick the bolded items only on the list then click Delete

     

     

  • When prompted click on Yes and then on next.

     

     

  • Put a check on any folders that are found and select delete

     

     

  • When prompted select yes then on next

     

     

  • Once done click Finish.

     

     

 

 

Next,

 

Download attached fixlist.txt file and save it to the Desktop, or the folder you saved FRST into.

NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

 

Run FRST and press the Fix button just once and wait.


The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

 

Next,

 

Download AdwCleaner by Xplode from here: http://www.bleepingcomputer.com/download/adwcleaner/ and save to your Desktop.

 

  • Double click on AdwCleaner.exe to run the tool.
  • Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Uncheck any elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review.
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted (if necessary):
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.

 

Next,

 

Run Malwarebytes,  Open > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware,

Make sure that everything is checked, and click Remove Selected on any found items.

Post the produced log...

 

Confirm that Scorpion and Lavasoft wee uninstalled, post the logs from FRST, AdwCleaner and Malwarebytes...
 

 

 

 

 

fixlist.txt

Link to post
Share on other sites

Revo could not find LavaSoft, but seemed to do great vs Scorpion Saver..

Here's the fixlog.txt:

 

 Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-11-2013 03

Ran by Naima at 2013-11-24 01:56:35 Run:1
Running from C:\Users\Naima\Desktop
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
Start
SearchScopes: HKCU - {F96F9252-9772-4B38-A79C-0D5582623664} URL = http://search.condui...ultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289663&CUI=UN27321531082059620&UM=2
BHO-x32: ScorpionSaver - {10AD2C61-0898-4348-8600-14A342F22AC3} - C:\Program Files (x86)\ScorpionSaver\IECore.dll ()
C:\Users\Dana\AppData\Local\Temp\HPInstaller.exe
C:\Users\Naima\AppData\Local\Temp\44D8_FPPSetup.exe
C:\Users\Naima\AppData\Local\Temp\7-zip.exe
C:\Users\Naima\AppData\Local\Temp\air1A71.exe
C:\Users\Naima\AppData\Local\Temp\air42F8.exe
C:\Users\Naima\AppData\Local\Temp\air44D7.exe
C:\Users\Naima\AppData\Local\Temp\air4BFA.exe
C:\Users\Naima\AppData\Local\Temp\BackupSetup.exe
C:\Users\Naima\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\Naima\AppData\Local\Temp\ntdll_dump.dll
C:\Users\Naima\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Naima\AppData\Local\Temp\oi_{65C46D49-2049-4E7A-9D2B-162BD7B5A967}.exe
C:\Users\Naima\AppData\Local\Temp\Quarantine.exe
C:\Users\Naima\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\Naima\AppData\Local\Temp\vcredist_x64.exe
AlternateDataStreams: C:\ProgramData\Temp:D346F792
End
 
running the 
 
*****************
 
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F96F9252-9772-4B38-A79C-0D5582623664} => Key deleted successfully.
HKCR\CLSID\{F96F9252-9772-4B38-A79C-0D5582623664} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3} => Key not found.
HKCR\Wow6432Node\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3} => Key not found.
C:\Users\Dana\AppData\Local\Temp\HPInstaller.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\44D8_FPPSetup.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\7-zip.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\air1A71.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\air42F8.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\air44D7.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\air4BFA.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\BackupSetup.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\Creative Cloud Helper.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\ntdll_dump.dll => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\OfficeSetup.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\oi_{65C46D49-2049-4E7A-9D2B-162BD7B5A967}.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\UNINSTALL.EXE => Moved successfully.
C:\Users\Naima\AppData\Local\Temp\vcredist_x64.exe => Moved successfully.
C:\ProgramData\Temp => ":D346F792" ADS removed successfully.
 
==== End of Fixlog ====
 
 
 
running the adwcleaner next.. 
 
 
thanks so much for your help!!
Link to post
Share on other sites

After the adw reboot, I'm still having popup ads, I assume from Lavasoft :(

 

 

Heres the after reboot report: 
 

# AdwCleaner v3.013 - Report created 24/11/2013 at 02:11:06
# Updated 24/11/2013 by Xplode
# Operating System : Windows 8  (64 bits)
# Username : Naima - NAIMAS
# Running from : C:\Users\Naima\Downloads\AdwCleaner (1).exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjkpcnacdgdlpfejlgflolpaigoicibh
Folder Deleted : C:\Users\Dana\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Deleted : C:\Users\singi_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Deleted : C:\Users\Aria\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v10.0.9200.16537
 
 
-\\ Google Chrome v31.0.1650.57
 
[ File : C:\Users\Naima\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
[ File : C:\Users\Dana\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
[ File : C:\Users\singi_000\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
[ File : C:\Users\Aria\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
[ File : C:\Users\Leila\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [8269 octets] - [04/11/2013 07:08:14]
AdwCleaner[R1].txt - [2491 octets] - [24/11/2013 02:04:27]
AdwCleaner[s0].txt - [7038 octets] - [04/11/2013 07:11:12]
AdwCleaner[s1].txt - [2440 octets] - [24/11/2013 02:11:06]
 
########## EOF - C:\AdwCleaner\AdwCleaner[s1].txt - [2500 octets] ##########
 
 
 
running malwarebytes next.. 
Link to post
Share on other sites

ok, I was definitely confused as to why AdAware was bad, I thought they were 'white hat'. .. but its conflicting with Norton? I've uninstalled it via programs and features as you suggested.


Malwarebytes scan turned up nothing,but I realized I hadn't updated my definitions file today, so now I'm re-running it.......

Link to post
Share on other sites

Download Zoek.zip from here http://www.hijackthis.nl/smeenk/220813/zoek.zip and save that zip file to your Desktop.

 

Double click zip file and extract to your  Desktop:

 

 

Zoekd.jpg

 

 

you will now have 3 versions of the tool on the Desktop:

 

 

Zoeke.jpg

 

Before running Zoek make sure all Browsers are closed and Security is turned OFF. Check at the following link: http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html

 

Double click on each in turn until one version of Zoek will run (accept UAC) The following window will open:

 

 

Zoekb.jpg

 

 

Copy and paste the following script from the code box and paste into the field.

 

 

standardsearch;autoclean;emptyclsid;firefoxlook;FFdefaults;Chromelook;CHRdefaults;iedefaults; 

 

 

Select the "Run Script" tab. The following window will open:

 

 

 

Zoekc.jpg

 

 

 

Please be patient and do not use the PC when the scan is in progress.

 

When complete you maybe asked to re-boot your PC, if so please do

 

Zoekf.jpg

 

Post the produced log in your next reply, also tell me if the pops have ceased

Link to post
Share on other sites

  • 2 weeks later...

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.