I got a unwanted guest that will not go away.  took over . please i need some help.




I tried to do a re-install vista, nothing ran a program like this it show 

I ran tddkiller, roguekiller,  others still there.  


here is txt. information off the vista.




DDS (Ver_2012-11-20.01)
Microsoft® Windows Vista™ Home Premium 
Boot Device: \Device\HarddiskVolume1
Install Date: 11/25/2013 9:16:15 PM
System Uptime: 12/1/2013 3:26:16 PM (0 hours ago)
Motherboard: ASUSTek Computer INC. |  | Acacia
Processor: AMD Athlon 64 X2 Dual Core Processor 5200+ | Socket AM2  | 2700/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 456 GiB total, 412.216 GiB free.
D: is FIXED (NTFS) - 9 GiB total, 1.267 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
==== Installed Programs ======================
Adobe Flash Player ActiveX
Adobe Reader 8.1.0
Compatibility Pack for the 2007 Office system
CyberLink DVD Suite Deluxe
Enhanced Multimedia Keyboard Solution
Google Chrome
Google Update Helper
Hardware Diagnostic Tools
Hewlett-Packard Active Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Experience Enhancements
HP Customer Feedback
HP Demo
HP Easy Setup - Frontend
HP On-Screen Cap/Num/Scroll Lock Indicator
HP Photosmart Essential 2.5
HP Picasso Media Center Add-In
HP Total Care Advisor
HP Update
Java SE Runtime Environment 6 Update 1
LightScribe System Software
Microsoft .NET Framework 3.5 SP1
Microsoft Office Home and Student 60 day trial
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
muvee autoProducer 6.1
My HP Games
NVIDIA Drivers
Python 2.5
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Snapfish Picture Mover
Soft Data Fax Modem with SmartCP
Toolwiz Care
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
WeatherBug Gadget
Yahoo! Toolbar
==== End Of File ===========================
DDS (Ver_2012-11-20.01) - NTFS_x86 NETWORK
Internet Explorer: 7.0.6001.18639
Run by zeeland at 15:27:43 on 2013-12-01
#Option MBR scan  is disabled.
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3454.3018 [GMT -8:00]
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
============== Running Processes ================
c:\Program Files\Microsoft Security Client\MsMpEng.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
============== Pseudo HJT Report ===============
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [ToolwizCareFree] "c:\program files\toolwizcarefree\ToolwizCares.exe" -autorun
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [sunJavaUpdateSched] "c:\program files\java\jre1.6.0_01\bin\jusched.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\snapfi~1.lnk - c:\program files\snapfish picture mover\SnapfishMediaDetector.exe
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
LSA: Security Packages =  kerberos msv1_0 schannel wdigest tspkg
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\31.0.1650.57\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
============= SERVICES / DRIVERS ===============
R0 BTOWSVF;BTOWSVF;c:\windows\system32\drivers\BTOWSVF.sys [2013-11-26 45952]
R0 KSafeDISK;KSafeDISK;c:\windows\system32\drivers\KSafeDISK.sys [2013-11-26 48640]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\drivers\netr73.sys [2008-2-27 464384]
S0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-9-27 214696]
S1 BTOWSFF;BTOWSFF;c:\windows\system32\drivers\BTOWSFF.sys [2013-11-26 27648]
S1 MpKsl4057042a;MpKsl4057042a;c:\programdata\microsoft\microsoft antimalware\definition updates\{7af0674d-3bce-42a8-8af8-cdd11248f09c}\MpKsl4057042a.sys [2013-12-1 40392]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2013-9-27 104768]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013-10-23 280288]
=============== Created Last 30 ================
2013-12-01 20:32:31 40392 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{7af0674d-3bce-42a8-8af8-cdd11248f09c}\MpKsl4057042a.sys
2013-12-01 20:12:48 62576 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{7af0674d-3bce-42a8-8af8-cdd11248f09c}\offreg.dll
2013-11-30 02:18:30 7772552 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{7af0674d-3bce-42a8-8af8-cdd11248f09c}\mpengine.dll
2013-11-30 02:17:56 719224 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2013-11-30 02:17:56 719224 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{928b0087-c1fc-4efc-bc57-4784ad9819db}\gapaengine.dll
2013-11-29 22:58:38 -------- d-----w- c:\windows\system32\MRT
2013-11-29 22:57:01 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2013-11-29 22:57:00 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2013-11-29 22:57:00 1695744 ----a-w- c:\windows\system32\gameux.dll
2013-11-28 18:07:28 -------- d-----w- C:\TDSSKiller_Quarantine
2013-11-28 17:43:01 7772552 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2013-11-28 17:33:39 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2013-11-28 17:33:39 49472 ----a-w- c:\windows\system32\netfxperf.dll
2013-11-28 17:33:39 297808 ----a-w- c:\windows\system32\mscoree.dll
2013-11-28 17:33:39 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2013-11-28 17:33:39 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-11-27 20:32:00 -------- d-----w- c:\users\zeeland\appdata\roaming\QuickScan
2013-11-27 20:27:50 -------- d-----w- c:\users\zeeland\appdata\roaming\HpUpdate
2013-11-27 20:27:49 -------- d-----w- c:\windows\Hewlett-Packard
2013-11-27 20:27:34 17920 ----a-w- c:\windows\system32\netevent.dll
2013-11-27 20:27:34 125952 ----a-w- c:\windows\system32\srvsvc.dll
2013-11-27 20:27:30 378368 ----a-w- c:\windows\system32\winhttp.dll
2013-11-27 20:25:09 -------- d-----w- c:\users\zeeland\appdata\local\Hewlett-Packard
2013-11-27 15:51:27 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2013-11-27 15:39:56 97800 ----a-w- c:\windows\system32\infocardapi.dll
2013-11-27 15:39:55 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-27 15:39:54 622080 ----a-w- c:\windows\system32\icardagt.exe
2013-11-27 15:39:54 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2013-11-27 15:39:54 11264 ----a-w- c:\windows\system32\icardres.dll
2013-11-27 15:39:51 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2013-11-27 15:35:31 158720 ----a-w- c:\windows\system32\mscorier.dll
2013-11-27 15:35:25 83968 ----a-w- c:\windows\system32\mscories.dll
2013-11-27 15:33:37 24064 ----a-w- c:\windows\system32\nshhttp.dll
2013-11-27 15:33:34 411136 ----a-w- c:\windows\system32\drivers\http.sys
2013-11-27 15:33:33 31232 ----a-w- c:\windows\system32\httpapi.dll
2013-11-26 21:46:40 -------- d-----w- c:\program files\Microsoft Security Client
2013-11-26 21:24:54 48640 ----a-w- c:\windows\system32\drivers\KSafeDISK.sys
2013-11-26 21:24:53 45952 ----a-w- c:\windows\system32\drivers\BTOWSVF.sys
2013-11-26 21:24:53 27648 ----a-w- c:\windows\system32\drivers\BTOWSFF.sys
2013-11-26 21:24:53 -------- d--h--w- C:\TOOLWIZ
2013-11-26 21:24:52 -------- d-----w- c:\users\zeeland\appdata\local\ToolwizCareFree
2013-11-26 21:24:50 -------- d-----w- c:\program files\ToolwizCareFree
2013-11-26 21:15:58 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2013-11-26 21:15:56 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2013-11-26 21:15:50 801280 ----a-w- c:\windows\system32\NaturalLanguage6.dll
2013-11-26 21:12:35 -------- d-----w- c:\users\zeeland\appdata\local\Google
2013-11-26 21:12:11 -------- d-----w- c:\users\zeeland\appdata\roaming\Symantec
2013-11-26 18:13:52 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2013-11-26 18:12:59 302592 ----a-w- c:\windows\system32\wlansec.dll
2013-11-26 18:11:59 954288 ----a-w- c:\windows\system32\mfc40u.dll
2013-11-26 18:10:59 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2013-11-26 18:05:40 276992 ----a-w- c:\windows\system32\schannel.dll
2013-11-26 18:04:51 2730536 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-11-26 18:04:40 7772552 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{e5c07f36-803f-42f4-8e05-0a389246cac0}\mpengine.dll
2013-11-26 18:04:37 230048 ------w- c:\windows\system32\MpSigStub.exe
2013-11-26 18:03:27 171520 ----a-w- c:\windows\system32\wintrust.dll
2013-11-26 18:03:09 98304 ----a-w- c:\windows\system32\cabview.dll
2013-11-26 05:21:30 -------- d-sh--we C:\Documents and Settings
==================== Find3M  ====================
2013-09-27 17:53:06 214696 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2013-09-27 17:53:06 104768 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
============= FINISH: 15:28:35.54 ===============
Hello stuff2 and :welcome:! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
Why do you think that your system is infected with Alureon? Please give me more details.

Please download Malwarebytes Anti-Rootkit from here

  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder... mbar-log.txt and system-log.txt
The scan came back with nothing wrong and this is the only log I saw in the folder.


Microsoft essential show Trojandos/alureon.k was only partially removed.



File system is: NTFS
CPU speed: 2.700000 GHz
Memory total: 3621404672, free: 2614796288
Host not found
Downloaded database version: v2013.12.05.01
Downloaded database version: v2013.10.11.02
------------ Kernel report ------------
     12/04/2013 19:13:11
------------ Loaded modules -----------
----------- End -----------
Upper Device Name: \Device\Harddisk4\DR4
Upper Device Object: 0xffffffff876d7190
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\0000005c\
Lower Device Object: 0xffffffff876cd088
Lower Device Driver Name: \Driver\USBSTOR\
Upper Device Name: \Device\Harddisk3\DR3
Upper Device Object: 0xffffffff876cf190
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\0000005b\
Lower Device Object: 0xffffffff876d9398
Lower Device Driver Name: \Driver\USBSTOR\
Upper Device Name: \Device\Harddisk2\DR2
Upper Device Object: 0xffffffff876cb190
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\0000005a\
Lower Device Object: 0xffffffff876c3398
Lower Device Driver Name: \Driver\USBSTOR\
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xffffffff876d3190
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\00000059\
Lower Device Object: 0xffffffff876c9398
Lower Device Driver Name: \Driver\USBSTOR\
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff859f98e0
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\00000050\
Lower Device Object: 0xffffffff846324f8
Lower Device Driver Name: \Driver\nvstor32\
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff859f98e0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff859f95d0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff859f98e0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xffffffff846144a0, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffffff846324f8, DeviceName: \Device\00000050\, DriverName: \Driver\nvstor32\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 1549F232
Partition information:
    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 63  Numsec = 957200832
    Partition file system is NTFS
    Partition is bootable
    Partition 1 type is HIDDEN (0x17)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 976768065  Numsec = 5087
    Partition is not bootable
Hidden partition VBR is not infected.
    Partition 2 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 957200895  Numsec = 19567170
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
Disk Size: 500107862016 bytes
Sector size: 512 bytes
Scanning physical sectors of unpartitioned space on drive 0 (1-62-976753168-976773168)...
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff876d3190, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff876cd3e8, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff876d3190, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
DevicePointer: 0xffffffff876c9398, DeviceName: \Device\00000059\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xffffffff876cb190, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff876b1208, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff876cb190, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\disk\
DevicePointer: 0xffffffff876c3398, DeviceName: \Device\0000005a\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xffffffff876cf190, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff876d53e8, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff876cf190, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\disk\
DevicePointer: 0xffffffff876d9398, DeviceName: \Device\0000005b\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffffff876d7190, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff876d9088, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff876d7190, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\disk\
DevicePointer: 0xffffffff876cd088, DeviceName: \Device\0000005c\, DriverName: \Driver\USBSTOR\
------------ End ----------
For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
On the System Recovery Options menu you will get the following options:
    • Startup Repair

      System Restore

      Windows Complete PC Restore

      Windows Memory Diagnostic Tool

      Command Prompt

  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

    Note: Replace letter e with the drive letter of your flash drive.

  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
I am lost


I looked and looked hit and hit the F8 for the days, still no Advanced Boot Options.

a screen comes on and offer; safe mode, network safe mode or safe mode with command prompts. I even went to safe mode with command prompts nothing no offer to repair machine.


 I even checked on a vista board to see how to find Advanced Boot Options.  

Looked like I was doing every thing right still nothing but safe mode.


This is a friend computer and she has no disc around.


Any ideas?

Try to run it in Regular mode.

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system.  You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Link to post
 Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-12-2013

Ran by zeeland (administrator) on DONNATANAKA-PC on 11-12-2013 12:06:10
Running from C:\Users\zeeland\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(OsdMaestro) C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Toolwiz) C:\Program Files\ToolwizCareFree\ToolwizCares.exe
() C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe
(Toolwiz.com) C:\Program Files\ToolwizCareFree\ToolwizTools.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Hewlett-Packard Company) C:\hp\KBD\kbd.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-20] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\WINDOWS\RtHDVCpl.exe [4874240 2008-01-15] (Realtek Semiconductor)
HKLM\...\Run: [hpsysdrv] - C:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company)
HKLM\...\Run: [KBD] - C:\hp\KBD\KbdStub.exe [65536 2006-12-08] ()
HKLM\...\Run: [OsdMaestro] - C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro)
HKLM\...\Run: [NvSvc] - RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\...\Run: [HP Health Check Scheduler] - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [40048 2007-05-11] (Adobe Systems Incorporated)
HKLM\...\Run: [sunJavaUpdateSched] - C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe [132760 2007-04-07] (Sun Microsystems, Inc.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKCU\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKCU\...\Run: [ToolwizCareFree] - C:\Program Files\ToolwizCareFree\ToolwizCares.exe [5286160 2013-11-26] (Toolwiz)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)
HKU\Donna Tanaka\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Donna Tanaka\...\Run: [HPAdvisor] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)
HKU\Guest\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Guest\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
SearchScopes: HKLM - DefaultScope {508A4A7F-C702-4AE4-B67F-0343CD614D48} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt
SearchScopes: HKLM - {3A3F7E4B-FA3B-4DDF-9929-8994B6A30D65} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
SearchScopes: HKLM - {508A4A7F-C702-4AE4-B67F-0343CD614D48} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt
SearchScopes: HKCU - DefaultScope {508A4A7F-C702-4AE4-B67F-0343CD614D48} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt
SearchScopes: HKCU - {3A3F7E4B-FA3B-4DDF-9929-8994B6A30D65} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd
SearchScopes: HKCU - {508A4A7F-C702-4AE4-B67F-0343CD614D48} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt
BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]
CHR DefaultSearchKeyword: google.com
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding}
CHR Extension: (Google Docs) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\
CHR Extension: (Google Wallet) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\
CHR Extension: (Bitdefender QuickScan) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\
CHR Extension: (Gmail) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
========================== Services (Whitelisted) =================
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [65536 2007-09-19] (Hewlett-Packard)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R1 BTOWSFF; C:\Windows\system32\Drivers\BTOWSFF.sys [27648 2013-11-26] (Toolwiz.com)
R0 BTOWSVF; C:\Windows\System32\Drivers\BTOWSVF.sys [45952 2013-11-26] (Toolwiz.com)
R0 KSafeDISK; C:\Windows\System32\Drivers\KSafeDISK.sys [48640 2013-11-26] (Toolwiz.com)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 MFE_RR; \??\C:\Users\zeeland\AppData\Local\Temp\mfe_rr.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
part 2 it said my post was to long


==================== One Month Created Files and Folders ========
2013-12-11 12:06 - 2013-12-11 12:06 - 00010113 _____ C:\Users\zeeland\Desktop\FRST.txt
2013-12-11 12:06 - 2013-12-11 12:06 - 00000000 ____D C:\FRST
2013-12-11 12:05 - 2013-12-11 12:05 - 01060135 _____ (Farbar) C:\Users\zeeland\Desktop\FRST.exe
2013-12-08 15:27 - 2013-12-08 15:27 - 00000714 _____ C:\Windows\setupact.log
2013-12-08 15:27 - 2013-12-08 15:27 - 00000000 _____ C:\Windows\setuperr.log
2013-12-04 19:06 - 2013-12-04 19:21 - 00000000 ____D C:\Users\zeeland\Desktop\mbar
2013-12-04 19:06 - 2013-12-04 19:21 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-12-04 19:06 - 2013-12-04 19:13 - 00105176 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-12-04 19:06 - 2013-12-04 19:12 - 00075992 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-04 19:05 - 2013-12-04 19:05 - 12576792 _____ (Malwarebytes Corp.) C:\Users\zeeland\Downloads\mbar- (1).exe
2013-12-04 19:05 - 2013-12-04 19:05 - 12576792 _____ (Malwarebytes Corp.) C:\Users\zeeland\Desktop\mbar-
2013-12-04 19:03 - 2013-12-04 19:03 - 00000000 ____D C:\Users\zeeland\Desktop\help
2013-12-04 18:16 - 2013-12-04 18:16 - 00000908 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Malwarebytes
2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-04 18:16 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-04 18:15 - 2013-12-04 18:15 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\zeeland\Downloads\mbam-setup-
2013-12-04 18:08 - 2013-12-04 18:08 - 00001917 _____ C:\Users\zeeland\Desktop\aswMBR.txt
2013-12-04 18:04 - 2013-12-04 18:04 - 00000104 _____ C:\Users\zeeland\Documents\Recycle Bin - Shortcut.lnk
2013-12-01 15:29 - 2013-12-01 15:29 - 00002384 _____ C:\Users\zeeland\Desktop\attach.txt
2013-12-01 15:29 - 2013-12-01 15:28 - 00010298 _____ C:\Users\zeeland\Desktop\dds.txt
2013-12-01 15:28 - 2013-12-01 15:28 - 00081276 _____ C:\Users\zeeland\Downloads\2.xps
2013-12-01 12:53 - 2013-12-01 12:53 - 00688992 ____R (Swearware) C:\Users\zeeland\Desktop\dds.com
2013-12-01 12:53 - 2013-12-01 12:53 - 00688992 _____ (Swearware) C:\Users\zeeland\Downloads\dds.scr
2013-12-01 12:32 - 2013-12-01 12:32 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131201_123229.log
2013-12-01 12:13 - 2013-12-01 12:13 - 00072192 _____ C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-01 12:13 - 2013-12-01 12:13 - 00000951 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-01 12:13 - 2013-12-01 12:13 - 00000946 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2013-12-01 12:13 - 2013-12-01 12:13 - 00000917 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2013-12-01 12:13 - 2013-12-01 12:13 - 00000020 ___SH C:\Users\Guest\ntuser.ini
2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Snapfish
2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest\AppData\Local\VirtualStore
2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest
2013-12-01 12:13 - 2008-02-27 13:58 - 00001034 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk
2013-12-01 12:13 - 2008-01-20 18:42 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-12-01 12:13 - 2008-01-20 18:42 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-29 18:53 - 2013-11-29 18:53 - 17245644 _____ C:\Users\zeeland\Downloads\fiction.xps
2013-11-29 18:21 - 2013-11-29 18:21 - 00860176 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\mssstool32.exe
2013-11-29 18:17 - 2013-11-29 18:17 - 00511248 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\nis_full.exe
2013-11-29 15:00 - 2013-12-04 18:03 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-11-29 14:58 - 2013-11-29 14:58 - 00000000 ____D C:\Windows\system32\MRT
2013-11-29 14:57 - 2011-03-03 06:56 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\Apphlpdm.dll
2013-11-29 14:57 - 2011-03-03 05:01 - 04240384 _____ (Microsoft) C:\Windows\system32\GameUXLegacyGDFs.dll
2013-11-29 14:57 - 2008-03-07 20:21 - 01695744 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145639.log
2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145621.log
2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145618.log
2013-11-29 14:46 - 2013-11-29 14:46 - 00000680 _____ C:\Users\zeeland\AppData\Local\d3d9caps.dat
2013-11-29 13:42 - 2013-11-29 13:42 - 01441838 _____ C:\Users\zeeland\Downloads\Daily Deal Millionaires.zip
2013-11-28 19:13 - 2013-11-28 19:13 - 00283757 _____ C:\Users\zeeland\Desktop\3.xps
2013-11-28 19:12 - 2013-11-28 19:12 - 00081276 _____ C:\Users\zeeland\Desktop\2.xps
2013-11-28 19:11 - 2013-11-28 19:12 - 17245644 _____ C:\Users\zeeland\Desktop\fiction.xps
2013-11-28 18:51 - 2013-11-28 18:51 - 13317370 _____ C:\Users\zeeland\Desktop\Tee_Profits.zip
2013-11-28 18:33 - 2013-11-28 18:34 - 02990323 _____ C:\Users\zeeland\Downloads\KM.rar
2013-11-28 18:26 - 2013-11-28 18:26 - 19236964 _____ C:\DONNATANAKA-PC_2013.11.28-1752.27_9B31A9DB-00BD-00A1-006A-00153AC32D20_816.zip
2013-11-28 17:52 - 2013-11-28 18:26 - 00000000 ____D C:\Users\zeeland\Downloads\TrendMicro AntiThreat Toolkit
2013-11-28 17:48 - 2013-11-28 17:49 - 23658800 _____ (Trend Micro Inc.) C:\Users\zeeland\Downloads\attk_ScanCleanOnline_gui_x86.exe
2013-11-28 17:30 - 2013-11-28 17:30 - 03298896 _____ (Trend Micro Inc.) C:\Users\zeeland\Downloads\attk_collector_cli_x86 (1).exe
2013-11-28 17:27 - 2013-11-28 17:27 - 03298896 _____ (Trend Micro Inc.) C:\Users\zeeland\Downloads\attk_collector_cli_x86.exe
2013-11-28 17:24 - 2013-11-28 17:24 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131128_172405.log
2013-11-28 17:23 - 2013-11-28 17:23 - 00782640 _____ (McAfee, Inc.) C:\Users\zeeland\Downloads\rootkitremover.exe
2013-11-28 17:20 - 2013-11-28 17:20 - 07103512 _____ (Bitdefender LLC) C:\Users\zeeland\Desktop\BootkitRemoval_x86.exe
2013-11-28 17:13 - 2013-11-28 17:13 - 01258032 _____ C:\Users\zeeland\Downloads\avg_remover_bootkit (2).exe
2013-11-28 17:13 - 2013-11-28 17:13 - 00000151 _____ C:\Users\zeeland\Documents\VirusRemover.log
2013-11-28 17:12 - 2013-11-28 17:12 - 01258032 _____ C:\Users\zeeland\Downloads\avg_remover_bootkit (1).exe
2013-11-28 17:09 - 2013-11-28 17:09 - 01258032 _____ C:\Users\zeeland\Downloads\avg_remover_bootkit.exe
2013-11-28 17:03 - 2013-11-28 17:03 - 00044607 _____ C:\Users\zeeland\Downloads\bootkit_remover.zip
2013-11-28 17:02 - 2013-12-04 18:08 - 00000512 _____ C:\Users\zeeland\Desktop\MBR.dat
2013-11-28 17:02 - 2013-11-28 17:02 - 00002079 _____ C:\Users\zeeland\Downloads\aswMBR.txt
2013-11-28 15:36 - 2013-11-28 15:36 - 04745728 _____ (AVAST Software) C:\Users\zeeland\Downloads\aswMBR.exe
2013-11-28 15:33 - 2013-11-28 15:33 - 00235560 _____ C:\Users\zeeland\AppData\Local\census.cache
2013-11-28 15:33 - 2013-11-28 15:33 - 00199427 _____ C:\Users\zeeland\AppData\Local\ars.cache
2013-11-28 15:12 - 2013-11-28 15:12 - 02002320 _____ (Trend Micro Inc.) C:\Users\zeeland\Downloads\HousecallLauncher.exe
2013-11-28 15:12 - 2013-11-28 15:12 - 00000036 _____ C:\Users\zeeland\AppData\Local\housecall.guid.cache
2013-11-28 11:33 - 2013-11-28 11:33 - 00456799 _____ C:\Users\zeeland\Downloads\pg1155.txt
2013-11-28 10:41 - 2013-11-28 18:26 - 00000332 _____ C:\Users\zeeland\Downloads\Result.txt
2013-11-28 10:41 - 2013-11-28 10:41 - 00360587 _____ (Farbar) C:\Users\zeeland\Downloads\ListParts.exe
2013-11-28 10:07 - 2013-11-28 10:07 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-11-28 10:04 - 2013-11-28 10:04 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\zeeland\Downloads\tdsskiller.exe
2013-11-28 09:42 - 2013-11-28 09:42 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\CyberLink
2013-11-28 09:42 - 2013-11-28 09:42 - 00000000 ____D C:\Users\Public\CyberLink
2013-11-28 09:42 - 2013-11-28 09:42 - 00000000 ____D C:\ProgramData\CyberLink
2013-11-28 09:36 - 2013-11-28 09:41 - 389330944 _____ C:\Users\zeeland\Downloads\kav_rescue_10.iso
2013-11-28 09:33 - 2009-11-08 10:55 - 01130824 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2013-11-28 09:33 - 2009-11-08 10:55 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2013-11-28 09:33 - 2009-11-08 10:55 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2013-11-28 09:33 - 2009-11-08 10:55 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2013-11-28 09:33 - 2009-11-08 10:55 - 00049472 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2013-11-27 13:43 - 2013-11-27 13:44 - 89886059 _____ C:\Users\zeeland\Downloads\Unconfirmed 419508.crdownload
2013-11-27 12:32 - 2013-11-27 12:32 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\QuickScan
2013-11-27 12:27 - 2013-11-27 12:28 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\HpUpdate
2013-11-27 12:27 - 2013-11-27 12:27 - 00000000 ____D C:\Windows\Hewlett-Packard
2013-11-27 12:27 - 2010-09-06 08:24 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2013-11-27 12:27 - 2010-09-06 08:23 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2013-11-27 12:27 - 2009-08-24 04:16 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2013-11-27 12:25 - 2013-11-27 12:25 - 00000000 ____D C:\Users\zeeland\AppData\Local\Hewlett-Packard
2013-11-27 07:39 - 2008-06-19 17:14 - 00781344 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2013-11-27 07:39 - 2008-06-19 17:14 - 00622080 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2013-11-27 07:39 - 2008-06-19 17:14 - 00105016 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-11-27 07:39 - 2008-06-19 17:14 - 00097800 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2013-11-27 07:39 - 2008-06-19 17:14 - 00037384 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl
2013-11-27 07:39 - 2008-06-19 17:14 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2013-11-27 07:35 - 2008-07-27 10:03 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2013-11-27 07:35 - 2008-07-27 10:03 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2013-11-27 07:33 - 2010-02-20 15:39 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\nshhttp.dll
2013-11-27 07:33 - 2010-02-20 15:37 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll
2013-11-27 07:33 - 2010-02-20 13:18 - 00411136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2013-11-27 07:30 - 2013-11-27 07:30 - 90642704 _____ (Microsoft Corporation) C:\Users\zeeland\Desktop\msert.exe
2013-11-26 13:53 - 2013-11-26 13:53 - 00002154 _____ C:\Windows\epplauncher.mif
2013-11-26 13:48 - 2013-11-26 13:48 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Macromedia
2013-11-26 13:46 - 2013-11-26 13:47 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-11-26 13:46 - 2010-04-05 06:50 - 00208966 _____ C:\Windows\system32\WFP.TMF
2013-11-26 13:37 - 2013-11-26 13:37 - 00869456 _____ C:\Users\zeeland\Downloads\Norton_Removal_Tool (1).exe
2013-11-26 13:35 - 2013-11-26 13:35 - 00869456 _____ C:\Users\zeeland\Downloads\Norton_Removal_Tool.exe
2013-11-26 13:24 - 2013-11-29 18:06 - 00000000 ___HD C:\TOOLWIZ
2013-11-26 13:24 - 2013-11-27 12:42 - 00000000 ____D C:\Users\zeeland\AppData\Local\ToolwizCareFree
2013-11-26 13:24 - 2013-11-26 13:24 - 00048640 _____ (Toolwiz.com) C:\Windows\system32\Drivers\KSafeDISK.sys
2013-11-26 13:24 - 2013-11-26 13:24 - 00045952 _____ (Toolwiz.com) C:\Windows\system32\Drivers\BTOWSVF.sys
2013-11-26 13:24 - 2013-11-26 13:24 - 00027648 _____ (Toolwiz.com) C:\Windows\system32\Drivers\BTOWSFF.sys
2013-11-26 13:24 - 2013-11-26 13:24 - 00000877 _____ C:\Users\zeeland\Desktop\Toolwiz Care.lnk
2013-11-26 13:24 - 2013-11-26 13:24 - 00000877 _____ C:\Users\Donna Tanaka\Desktop\Toolwiz Care.lnk
2013-11-26 13:24 - 2013-11-26 13:24 - 00000000 ____D C:\Program Files\ToolwizCareFree
2013-11-26 13:23 - 2013-11-26 13:23 - 07619344 _____ (ToolWiz) C:\Users\zeeland\Downloads\Setup_ToolwizCare.exe
2013-11-26 13:17 - 2013-11-26 13:18 - 11125072 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\mseinstall.exe
2013-11-26 13:15 - 2008-06-25 19:29 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2013-11-26 13:15 - 2008-06-25 17:45 - 12240896 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0007.dll
2013-11-26 13:15 - 2008-06-25 17:45 - 02644480 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0009.dll
2013-11-26 13:13 - 2013-11-26 13:13 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Hewlett-Packard
2013-11-26 13:12 - 2013-11-27 12:45 - 00072192 _____ C:\Users\zeeland\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-26 13:12 - 2013-11-26 13:12 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Symantec
2013-11-26 13:12 - 2013-11-26 13:12 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Snapfish
2013-11-26 13:12 - 2013-11-26 13:12 - 00000000 ____D C:\Users\zeeland\AppData\Local\Google
2013-11-26 13:11 - 2013-11-29 18:06 - 00000000 ____D C:\Users\zeeland
2013-11-26 13:11 - 2013-11-26 13:12 - 00000000 ____D C:\Users\zeeland\AppData\Local\VirtualStore
2013-11-26 13:11 - 2013-11-26 13:11 - 00000951 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-26 13:11 - 2013-11-26 13:11 - 00000946 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2013-11-26 13:11 - 2013-11-26 13:11 - 00000917 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2013-11-26 13:11 - 2013-11-26 13:11 - 00000020 ___SH C:\Users\zeeland\ntuser.ini
2013-11-26 13:11 - 2008-02-27 13:58 - 00001034 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk
2013-11-26 13:11 - 2008-01-20 18:42 - 00000000 ___RD C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-26 13:11 - 2008-01-20 18:42 - 00000000 ___RD C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-26 10:13 - 2011-04-21 07:00 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 10:13 - 2011-04-21 07:00 - 00833024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 10:13 - 2011-04-21 06:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 10:13 - 2011-04-21 06:58 - 03593728 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 10:13 - 2011-04-21 06:58 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2013-11-26 10:13 - 2011-04-21 06:58 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 10:13 - 2011-04-21 06:58 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 10:13 - 2011-04-21 06:58 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 10:13 - 2011-04-21 06:57 - 06078976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 10:13 - 2011-04-21 06:57 - 00389120 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 10:13 - 2011-04-21 06:57 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 10:13 - 2011-04-21 06:57 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 10:13 - 2011-04-21 06:57 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2013-11-26 10:13 - 2011-04-21 06:57 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 10:13 - 2011-04-21 06:57 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\ieencode.dll
2013-11-26 10:13 - 2011-04-21 05:28 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 10:13 - 2011-04-21 05:08 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 10:13 - 2011-02-22 04:51 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2013-11-26 10:13 - 2011-02-16 07:29 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-11-26 10:13 - 2011-02-16 05:24 - 00292864 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-11-26 10:13 - 2010-12-28 06:57 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2013-11-26 10:13 - 2010-09-10 10:18 - 10626560 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-11-26 10:13 - 2010-09-10 08:37 - 08147456 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-11-26 10:13 - 2010-06-16 07:12 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-11-26 10:13 - 2010-05-04 08:53 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 10:13 - 2010-04-16 08:10 - 00501760 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2013-11-26 10:13 - 2010-02-25 20:03 - 02452872 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 10:13 - 2009-08-14 08:29 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
2013-11-26 10:13 - 2009-08-14 06:16 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\NETSTAT.EXE
2013-11-26 10:13 - 2009-08-14 06:16 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\ARP.EXE
2013-11-26 10:13 - 2009-08-14 06:16 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\ROUTE.EXE
2013-11-26 10:13 - 2009-08-14 06:16 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\MRINFO.EXE
2013-11-26 10:13 - 2009-08-14 06:16 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\finger.exe
2013-11-26 10:13 - 2009-08-14 06:16 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\TCPSVCS.EXE
2013-11-26 10:13 - 2009-08-14 06:16 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\HOSTNAME.EXE
2013-11-26 10:13 - 2009-06-15 07:20 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-11-26 10:13 - 2008-06-18 19:31 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2013-11-26 10:12 - 2011-07-06 06:56 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2013-11-26 10:12 - 2011-06-02 04:59 - 02042368 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-11-26 10:12 - 2011-04-29 04:49 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2013-11-26 10:12 - 2011-04-29 04:49 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2013-11-26 10:12 - 2011-04-29 04:49 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2013-11-26 10:12 - 2011-04-29 04:49 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2013-11-26 10:12 - 2011-04-21 05:16 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-26 10:12 - 2011-04-14 06:24 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2013-11-26 10:12 - 2011-03-10 08:12 - 01161728 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2013-11-26 10:12 - 2011-03-10 08:12 - 01136640 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2013-11-26 10:12 - 2011-03-02 06:49 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2013-11-26 10:12 - 2011-03-02 06:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2013-11-26 10:12 - 2011-02-18 05:31 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2013-11-26 10:12 - 2011-02-16 07:35 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 10:12 - 2011-02-16 07:32 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 10:12 - 2010-12-20 07:39 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2013-11-26 10:12 - 2010-12-14 07:49 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\sdclt.exe
2013-11-26 10:12 - 2010-10-15 06:08 - 03600272 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-11-26 10:12 - 2010-10-15 06:08 - 03548048 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-11-26 10:12 - 2010-10-15 05:48 - 01205080 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-11-26 10:12 - 2010-08-31 07:41 - 00954752 _____ (Microsoft Corporation) C:\Windows\system32\mfc40.dll
2013-11-26 10:12 - 2010-08-26 08:07 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2013-11-26 10:12 - 2010-08-17 05:32 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2013-11-26 10:12 - 2010-06-28 08:15 - 01315840 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2013-11-26 10:12 - 2010-05-27 11:16 - 00081920 _____ (Radius Inc.) C:\Windows\system32\iccvid.dll
2013-11-26 10:12 - 2010-04-05 08:08 - 00317952 _____ (Microsoft Corporation) C:\Windows\system32\MP4SDECD.DLL
2013-11-26 10:12 - 2010-04-05 08:07 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2013-11-26 10:12 - 2009-09-10 09:30 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2013-11-26 10:12 - 2009-08-10 03:01 - 01399296 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2013-11-26 10:12 - 2009-07-17 06:35 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\atl.dll
2013-11-26 10:12 - 2009-07-11 11:32 - 00513024 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2013-11-26 10:12 - 2009-07-11 11:32 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2013-11-26 10:12 - 2009-07-11 11:32 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2013-11-26 10:12 - 2009-07-11 11:29 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\L2SecHC.dll
2013-11-26 10:12 - 2009-07-11 09:18 - 02501921 _____ C:\Windows\system32\wlan.tmf
2013-11-26 10:12 - 2009-07-10 04:21 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\shsvcs.dll
2013-11-26 10:12 - 2009-06-10 04:12 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2013-11-26 10:12 - 2009-06-10 04:11 - 02868224 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2013-11-26 10:12 - 2009-06-10 04:11 - 02386944 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2013-11-26 10:12 - 2009-05-04 02:11 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2013-11-26 10:12 - 2009-04-23 04:42 - 00636928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2013-11-26 10:12 - 2008-10-20 21:25 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-26 10:12 - 2008-10-15 20:47 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2013-11-26 10:12 - 2008-06-25 19:29 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll
2013-11-26 10:12 - 2008-06-05 19:27 - 00562176 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll
2013-11-26 10:12 - 2008-06-05 19:27 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\xolehlp.dll
2013-11-26 10:12 - 2008-04-17 21:48 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\es.dll
2013-11-26 10:12 - 2008-04-04 19:34 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\pacerprf.dll
2013-11-26 10:12 - 2008-04-04 17:21 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2013-11-26 10:11 - 2011-05-02 07:58 - 00738816 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2013-11-26 10:11 - 2011-01-21 07:46 - 11582464 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-11-26 10:11 - 2011-01-21 07:46 - 00351744 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2013-11-26 10:11 - 2010-12-29 09:41 - 00429056 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2013-11-26 10:11 - 2010-12-29 09:41 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2013-11-26 10:11 - 2010-12-29 09:41 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\sbeio.dll
2013-11-26 10:11 - 2010-12-29 09:39 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2013-11-26 10:11 - 2010-11-06 03:10 - 00357376 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2013-11-26 10:11 - 2010-11-06 03:10 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2013-11-26 10:11 - 2010-11-06 03:10 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2013-11-26 10:11 - 2010-11-06 03:09 - 00603648 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2013-11-26 10:11 - 2010-11-04 16:53 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2013-11-26 10:11 - 2010-10-28 04:56 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-11-26 10:11 - 2010-10-18 06:01 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2013-11-26 10:11 - 2010-08-31 07:41 - 00954288 _____ (Microsoft Corporation) C:\Windows\system32\mfc40u.dll
2013-11-26 10:11 - 2010-08-20 07:21 - 00866816 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2013-11-26 10:11 - 2010-06-18 08:43 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2013-11-26 10:11 - 2010-06-11 07:30 - 01257472 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2013-11-26 10:11 - 2010-05-04 10:39 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\msshsq.dll
2013-11-26 10:11 - 2010-04-16 08:10 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2013-11-26 10:11 - 2010-02-18 06:11 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2013-11-26 10:11 - 2010-02-18 03:52 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2013-11-26 10:11 - 2010-01-21 07:59 - 00062464 _____ (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\system32\l3codeca.acm
2013-11-26 10:11 - 2009-07-14 05:00 - 00313344 _____ (Microsoft Corporation) C:\Windows\system32\wmpdxm.dll
2013-11-26 10:11 - 2009-07-14 04:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2013-11-26 10:11 - 2009-07-14 04:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2013-11-26 10:11 - 2009-07-14 04:58 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2013-11-26 10:11 - 2009-07-14 00:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.tlb
2013-11-26 10:11 - 2009-07-14 00:30 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\amcompat.tlb
2013-11-26 10:11 - 2009-06-15 10:20 - 00439896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-26 10:11 - 2009-06-15 07:24 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2013-11-26 10:11 - 2009-06-15 07:24 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-26 10:11 - 2009-06-15 07:23 - 01256448 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-26 10:11 - 2009-06-15 07:21 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2013-11-26 10:11 - 2009-06-15 04:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-26 10:11 - 2009-03-16 19:38 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\amxread.dll
2013-11-26 10:11 - 2009-03-16 19:38 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\apilogen.dll
2013-11-26 10:11 - 2009-03-02 20:39 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2013-11-26 10:11 - 2009-03-02 20:39 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\sdohlp.dll
2013-11-26 10:11 - 2009-03-02 20:39 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelineprxy.dll
2013-11-26 10:11 - 2009-03-02 20:37 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2013-11-26 10:11 - 2009-03-02 20:37 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\iasads.dll
2013-11-26 10:11 - 2009-03-02 20:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\iasdatastore.dll
2013-11-26 10:11 - 2009-03-02 19:04 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe
2013-11-26 10:11 - 2009-03-02 18:38 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\iashost.exe
2013-11-26 10:11 - 2009-02-13 00:49 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-11-26 10:11 - 2008-10-28 22:29 - 02927104 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2013-11-26 10:11 - 2008-08-11 19:39 - 00443392 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-11-26 10:11 - 2008-08-01 19:26 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-11-26 10:11 - 2008-08-01 17:01 - 00625152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-11-26 10:11 - 2008-06-25 19:29 - 00565248 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll
2013-11-26 10:11 - 2008-06-25 19:29 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dataclen.dll
2013-11-26 10:11 - 2008-05-19 18:07 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2013-11-26 10:11 - 2008-05-09 17:33 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2013-11-26 10:11 - 2008-02-28 23:14 - 00019000 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2013-11-26 10:11 - 2008-02-28 23:11 - 00988216 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2013-11-26 10:11 - 2008-02-28 23:11 - 00927288 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2013-11-26 10:11 - 2008-02-28 22:53 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2013-11-26 10:11 - 2008-02-28 22:53 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2013-11-26 10:11 - 2008-02-28 22:53 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2013-11-26 10:11 - 2008-02-28 22:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\kbd106n.dll
2013-11-26 10:11 - 2008-02-28 20:12 - 00318464 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2013-11-26 10:11 - 2008-02-28 20:12 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\srdelayed.exe
2013-11-26 10:11 - 2008-02-21 21:05 - 00615992 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2013-11-26 10:10 - 2011-04-20 06:47 - 00375808 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-11-26 10:10 - 2011-04-20 06:44 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-11-26 10:10 - 2010-12-17 08:43 - 02067456 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-11-26 10:10 - 2010-12-17 07:06 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2013-11-26 10:10 - 2010-08-31 07:40 - 00531968 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-11-26 10:10 - 2010-06-16 07:56 - 00098192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2013-11-26 10:10 - 2010-06-16 07:55 - 00902032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-11-26 10:10 - 2010-06-16 07:55 - 00220040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2013-11-26 10:10 - 2010-06-16 07:11 - 00438272 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-26 10:10 - 2010-06-16 07:10 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-26 10:10 - 2010-06-16 07:09 - 00328704 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2013-11-26 10:10 - 2009-12-28 04:35 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2013-11-26 10:10 - 2009-12-28 04:32 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\msvfw32.dll
2013-11-26 10:10 - 2009-12-28 04:32 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2013-11-26 10:10 - 2009-12-28 04:32 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2013-11-26 10:10 - 2009-12-28 04:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2013-11-26 10:10 - 2009-12-28 04:31 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\mciavi32.dll
2013-11-26 10:10 - 2009-12-28 04:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2013-11-26 10:10 - 2009-12-28 04:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\avifil32.dll
2013-11-26 10:10 - 2009-12-28 04:28 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\avicap32.dll
2013-11-26 10:10 - 2009-10-07 04:41 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2013-11-26 10:10 - 2009-10-07 04:41 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2013-11-26 10:10 - 2009-09-04 04:24 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2013-11-26 10:10 - 2009-08-10 05:05 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2013-11-26 10:10 - 2009-04-23 04:43 - 00784896 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-11-26 10:10 - 2009-04-02 04:37 - 00604672 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2013-11-26 10:10 - 2008-06-22 17:59 - 00996352 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll
2013-11-26 10:10 - 2008-06-22 17:58 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe
2013-11-26 10:10 - 2008-05-08 13:59 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll
2013-11-26 10:10 - 2008-05-08 13:59 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-11-26 10:10 - 2008-05-08 13:59 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-11-26 10:10 - 2008-05-08 13:59 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\wshext.dll
2013-11-26 10:10 - 2008-05-08 13:58 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-11-26 10:10 - 2008-05-08 13:58 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-11-26 10:05 - 2011-04-29 06:54 - 00276992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-26 10:04 - 2013-11-19 02:21 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-26 10:03 - 2010-01-14 16:04 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2013-11-26 10:03 - 2009-12-23 04:43 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-11-26 10:02 - 2013-11-26 10:02 - 00001973 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-26 10:01 - 2013-12-11 12:02 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-26 10:01 - 2013-12-04 19:11 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-26 10:01 - 2013-11-26 10:02 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Local\Google
2013-11-26 10:01 - 2013-11-26 10:02 - 00000000 ____D C:\Program Files\Google
2013-11-26 10:01 - 2013-11-26 10:01 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Local\Deployment
2013-11-26 10:01 - 2013-11-26 10:01 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Local\Apps\2.0
2013-11-26 09:57 - 2013-11-26 09:57 - 00000680 _____ C:\Users\Donna Tanaka\AppData\Local\d3d9caps.dat
2013-11-25 21:29 - 2013-11-25 21:29 - 00072192 _____ C:\Users\Donna Tanaka\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-25 21:29 - 2013-11-25 21:29 - 00000951 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-25 21:29 - 2013-11-25 21:29 - 00000946 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2013-11-25 21:29 - 2013-11-25 21:29 - 00000917 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2013-11-25 21:29 - 2013-11-25 21:29 - 00000044 _____ C:\Windows\system\hpsysdrv.dat
2013-11-25 21:29 - 2013-11-25 21:29 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Roaming\Symantec
2013-11-25 21:29 - 2013-11-25 21:29 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Roaming\Snapfish
2013-11-25 21:29 - 2013-11-25 21:29 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Local\VirtualStore
2013-11-25 21:27 - 2013-11-25 21:27 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Roaming\Macromedia
2013-11-25 21:26 - 2013-11-25 21:30 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Roaming\Hewlett-Packard
2013-11-25 21:25 - 2013-11-25 21:25 - 00001853 _____ C:\Users\Public\Desktop\Internet & Digital Services.lnk
2013-11-25 21:25 - 2013-11-25 21:25 - 00001834 __RSH C:\Windows\system32\Drivers\103C_HP_CPC_KJ375AA-ABA s3400f_YC_0Pavi_QMXU810_E82NAv3PrA1_49_IAcacia_SASUSTek Computer INC._V1.02_B5.11_T080212_WUH1_L409_M3454_J500_7AMD_8Athlon 64 X2 Dual Core_92.7_#080429_N10DE03EF_Z14F12F20_G10DE03D0.MRK
2013-11-25 21:25 - 2008-02-27 14:08 - 00002117 _____ C:\Users\Public\Desktop\eBay.lnk
2013-11-25 21:25 - 2008-02-27 14:08 - 00002047 _____ C:\Users\Public\Desktop\MSN.lnk
2013-11-25 21:24 - 2013-11-25 21:29 - 00000000 ____D C:\Users\Donna Tanaka
2013-11-25 21:24 - 2013-11-25 21:24 - 00000020 ___SH C:\Users\Donna Tanaka\ntuser.ini
2013-11-25 21:24 - 2008-02-27 13:58 - 00001034 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk
2013-11-25 21:24 - 2008-01-20 18:42 - 00000000 ___RD C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-25 21:24 - 2008-01-20 18:42 - 00000000 ___RD C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-25 21:21 - 2013-12-11 12:06 - 01964121 _____ C:\Windows\WindowsUpdate.log
==================== One Month Modified Files and Folders =======
2013-12-11 12:06 - 2013-12-11 12:06 - 00010113 _____ C:\Users\zeeland\Desktop\FRST.txt
2013-12-11 12:06 - 2013-12-11 12:06 - 00000000 ____D C:\FRST
2013-12-11 12:06 - 2013-11-25 21:21 - 01964121 _____ C:\Windows\WindowsUpdate.log
2013-12-11 12:05 - 2013-12-11 12:05 - 01060135 _____ (Farbar) C:\Users\zeeland\Desktop\FRST.exe
2013-12-11 12:02 - 2013-11-26 10:01 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-11 12:02 - 2006-11-02 05:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-11 12:02 - 2006-11-02 04:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-11 12:02 - 2006-11-02 04:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-08 15:27 - 2013-12-08 15:27 - 00000714 _____ C:\Windows\setupact.log
2013-12-08 15:27 - 2013-12-08 15:27 - 00000000 _____ C:\Windows\setuperr.log
2013-12-08 15:27 - 2006-11-02 05:01 - 00016780 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-04 19:21 - 2013-12-04 19:06 - 00000000 ____D C:\Users\zeeland\Desktop\mbar
2013-12-04 19:21 - 2013-12-04 19:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-12-04 19:13 - 2013-12-04 19:06 - 00105176 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-12-04 19:12 - 2013-12-04 19:06 - 00075992 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-04 19:11 - 2013-11-26 10:01 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-04 19:05 - 2013-12-04 19:05 - 12576792 _____ (Malwarebytes Corp.) C:\Users\zeeland\Downloads\mbar- (1).exe
2013-12-04 19:05 - 2013-12-04 19:05 - 12576792 _____ (Malwarebytes Corp.) C:\Users\zeeland\Desktop\mbar-
2013-12-04 19:03 - 2013-12-04 19:03 - 00000000 ____D C:\Users\zeeland\Desktop\help
2013-12-04 18:16 - 2013-12-04 18:16 - 00000908 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Malwarebytes
2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-04 18:15 - 2013-12-04 18:15 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\zeeland\Downloads\mbam-setup-
2013-12-04 18:08 - 2013-12-04 18:08 - 00001917 _____ C:\Users\zeeland\Desktop\aswMBR.txt
2013-12-04 18:08 - 2013-11-28 17:02 - 00000512 _____ C:\Users\zeeland\Desktop\MBR.dat
2013-12-04 18:04 - 2013-12-04 18:04 - 00000104 _____ C:\Users\zeeland\Documents\Recycle Bin - Shortcut.lnk
2013-12-04 18:03 - 2013-11-29 15:00 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-12-01 15:29 - 2013-12-01 15:29 - 00002384 _____ C:\Users\zeeland\Desktop\attach.txt
2013-12-01 15:28 - 2013-12-01 15:29 - 00010298 _____ C:\Users\zeeland\Desktop\dds.txt
2013-12-01 15:28 - 2013-12-01 15:28 - 00081276 _____ C:\Users\zeeland\Downloads\2.xps
2013-12-01 12:53 - 2013-12-01 12:53 - 00688992 ____R (Swearware) C:\Users\zeeland\Desktop\dds.com
2013-12-01 12:53 - 2013-12-01 12:53 - 00688992 _____ (Swearware) C:\Users\zeeland\Downloads\dds.scr
2013-12-01 12:32 - 2013-12-01 12:32 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131201_123229.log
2013-12-01 12:13 - 2013-12-01 12:13 - 00072192 _____ C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-01 12:13 - 2013-12-01 12:13 - 00000951 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-01 12:13 - 2013-12-01 12:13 - 00000946 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2013-12-01 12:13 - 2013-12-01 12:13 - 00000917 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2013-12-01 12:13 - 2013-12-01 12:13 - 00000020 ___SH C:\Users\Guest\ntuser.ini
2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Snapfish
2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest\AppData\Local\VirtualStore
2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest
2013-11-29 18:53 - 2013-11-29 18:53 - 17245644 _____ C:\Users\zeeland\Downloads\fiction.xps
2013-11-29 18:21 - 2013-11-29 18:21 - 00860176 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\mssstool32.exe
2013-11-29 18:17 - 2013-11-29 18:17 - 00511248 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\nis_full.exe
2013-11-29 18:06 - 2013-11-26 13:24 - 00000000 ___HD C:\TOOLWIZ
2013-11-29 18:06 - 2013-11-26 13:11 - 00000000 ____D C:\Users\zeeland
2013-11-29 14:58 - 2013-11-29 14:58 - 00000000 ____D C:\Windows\system32\MRT
2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145639.log
2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145621.log
2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145618.log
2013-11-29 14:46 - 2013-11-29 14:46 - 00000680 _____ C:\Users\zeeland\AppData\Local\d3d9caps.dat
2013-11-29 13:42 - 2013-11-29 13:42 - 01441838 _____ C:\Users\zeeland\Downloads\Daily Deal Millionaires.zip
2013-11-28 19:13 - 2013-11-28 19:13 - 00283757 _____ C:\Users\zeeland\Desktop\3.xps
2013-11-28 19:12 - 2013-11-28 19:12 - 00081276 _____ C:\Users\zeeland\Desktop\2.xps
2013-11-28 19:12 - 2013-11-28 19:11 - 17245644 _____ C:\Users\zeeland\Desktop\fiction.xps
2013-11-28 18:51 - 2013-11-28 18:51 - 13317370 _____ C:\Users\zeeland\Desktop\Tee_Profits.zip
2013-11-28 18:34 - 2013-11-28 18:33 - 02990323 _____ C:\Users\zeeland\Downloads\KM.rar
2013-11-28 18:26 - 2013-11-28 18:26 - 19236964 _____ C:\DONNATANAKA-PC_2013.11.28-1752.27_9B31A9DB-00BD-00A1-006A-00153AC32D20_816.zip
2013-11-28 18:26 - 2013-11-28 17:52 - 00000000 ____D C:\Users\zeeland\Downloads\TrendMicro AntiThreat Toolkit
2013-11-28 18:26 - 2013-11-28 10:41 - 00000332 _____ C:\Users\zeeland\Downloads\Result.txt
2013-11-28 17:49 - 2013-11-28 17:48 - 23658800 _____ (Trend Micro Inc.) C:\Users\zeeland\Downloads\attk_ScanCleanOnline_gui_x86.exe
2013-11-28 17:30 - 2013-11-28 17:30 - 03298896 _____ (Trend Micro Inc.) C:\Users\zeeland\Downloads\attk_collector_cli_x86 (1).exe
2013-11-28 17:27 - 2013-11-28 17:27 - 03298896 _____ (Trend Micro Inc.) C:\Users\zeeland\Downloads\attk_collector_cli_x86.exe
2013-11-28 17:24 - 2013-11-28 17:24 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131128_172405.log
2013-11-28 17:23 - 2013-11-28 17:23 - 00782640 _____ (McAfee, Inc.) C:\Users\zeeland\Downloads\rootkitremover.exe
2013-11-28 17:20 - 2013-11-28 17:20 - 07103512 _____ (Bitdefender LLC) C:\Users\zeeland\Desktop\BootkitRemoval_x86.exe
2013-11-28 17:13 - 2013-11-28 17:13 - 01258032 _____ C:\Users\zeeland\Downloads\avg_remover_bootkit (2).exe
2013-11-28 17:13 - 2013-11-28 17:13 - 00000151 _____ C:\Users\zeeland\Documents\VirusRemover.log
2013-11-28 17:12 - 2013-11-28 17:12 - 01258032 _____ C:\Users\zeeland\Downloads\avg_remover_bootkit (1).exe
2013-11-28 17:09 - 2013-11-28 17:09 - 01258032 _____ C:\Users\zeeland\Downloads\avg_remover_bootkit.exe
2013-11-28 17:03 - 2013-11-28 17:03 - 00044607 _____ C:\Users\zeeland\Downloads\bootkit_remover.zip
2013-11-28 17:02 - 2013-11-28 17:02 - 00002079 _____ C:\Users\zeeland\Downloads\aswMBR.txt
2013-11-28 15:36 - 2013-11-28 15:36 - 04745728 _____ (AVAST Software) C:\Users\zeeland\Downloads\aswMBR.exe
2013-11-28 15:33 - 2013-11-28 15:33 - 00235560 _____ C:\Users\zeeland\AppData\Local\census.cache
2013-11-28 15:33 - 2013-11-28 15:33 - 00199427 _____ C:\Users\zeeland\AppData\Local\ars.cache
2013-11-28 15:12 - 2013-11-28 15:12 - 02002320 _____ (Trend Micro Inc.) C:\Users\zeeland\Downloads\HousecallLauncher.exe
2013-11-28 15:12 - 2013-11-28 15:12 - 00000036 _____ C:\Users\zeeland\AppData\Local\housecall.guid.cache
2013-11-28 11:33 - 2013-11-28 11:33 - 00456799 _____ C:\Users\zeeland\Downloads\pg1155.txt
2013-11-28 10:41 - 2013-11-28 10:41 - 00360587 _____ (Farbar) C:\Users\zeeland\Downloads\ListParts.exe
2013-11-28 10:24 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\rescache
2013-11-28 10:17 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-11-28 10:07 - 2013-11-28 10:07 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-11-28 10:04 - 2013-11-28 10:04 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\zeeland\Downloads\tdsskiller.exe
2013-11-28 09:42 - 2013-11-28 09:42 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\CyberLink
2013-11-28 09:42 - 2013-11-28 09:42 - 00000000 ____D C:\Users\Public\CyberLink
2013-11-28 09:42 - 2013-11-28 09:42 - 00000000 ____D C:\ProgramData\CyberLink
2013-11-28 09:42 - 2006-11-02 03:18 - 00000000 ___RD C:\Users\Public
2013-11-28 09:41 - 2013-11-28 09:36 - 389330944 _____ C:\Users\zeeland\Downloads\kav_rescue_10.iso
2013-11-27 13:44 - 2013-11-27 13:43 - 89886059 _____ C:\Users\zeeland\Downloads\Unconfirmed 419508.crdownload
2013-11-27 12:45 - 2013-11-26 13:12 - 00072192 _____ C:\Users\zeeland\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-27 12:45 - 2006-11-02 04:47 - 00286144 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-27 12:42 - 2013-11-26 13:24 - 00000000 ____D C:\Users\zeeland\AppData\Local\ToolwizCareFree
2013-11-27 12:42 - 2008-02-27 14:13 - 00000000 ____D C:\Windows\SMINST
2013-11-27 12:32 - 2013-11-27 12:32 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\QuickScan
2013-11-27 12:28 - 2013-11-27 12:27 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\HpUpdate
2013-11-27 12:27 - 2013-11-27 12:27 - 00000000 ____D C:\Windows\Hewlett-Packard
2013-11-27 12:27 - 2008-02-27 13:52 - 00000000 ____D C:\Program Files\HP
2013-11-27 12:25 - 2013-11-27 12:25 - 00000000 ____D C:\Users\zeeland\AppData\Local\Hewlett-Packard
2013-11-27 08:41 - 2006-11-02 02:33 - 00690960 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-27 08:34 - 2006-11-02 04:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-11-27 08:34 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Movie Maker
2013-11-27 07:49 - 2008-02-27 14:01 - 00000000 ____D C:\Program Files\Microsoft Works
2013-11-27 07:32 - 2006-11-02 03:18 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-27 07:30 - 2013-11-27 07:30 - 90642704 _____ (Microsoft Corporation) C:\Users\zeeland\Desktop\msert.exe
2013-11-26 13:53 - 2013-11-26 13:53 - 00002154 _____ C:\Windows\epplauncher.mif
2013-11-26 13:48 - 2013-11-26 13:48 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Macromedia
2013-11-26 13:47 - 2013-11-26 13:46 - 00000000 ____D C:\Program Files\Microsoft Security Client
2013-11-26 13:41 - 2008-02-27 14:10 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-11-26 13:37 - 2013-11-26 13:37 - 00869456 _____ C:\Users\zeeland\Downloads\Norton_Removal_Tool (1).exe
2013-11-26 13:35 - 2013-11-26 13:35 - 00869456 _____ C:\Users\zeeland\Downloads\Norton_Removal_Tool.exe
2013-11-26 13:24 - 2013-11-26 13:24 - 00048640 _____ (Toolwiz.com) C:\Windows\system32\Drivers\KSafeDISK.sys
2013-11-26 13:24 - 2013-11-26 13:24 - 00045952 _____ (Toolwiz.com) C:\Windows\system32\Drivers\BTOWSVF.sys
2013-11-26 13:24 - 2013-11-26 13:24 - 00027648 _____ (Toolwiz.com) C:\Windows\system32\Drivers\BTOWSFF.sys
2013-11-26 13:24 - 2013-11-26 13:24 - 00000877 _____ C:\Users\zeeland\Desktop\Toolwiz Care.lnk
2013-11-26 13:24 - 2013-11-26 13:24 - 00000877 _____ C:\Users\Donna Tanaka\Desktop\Toolwiz Care.lnk
2013-11-26 13:24 - 2013-11-26 13:24 - 00000000 ____D C:\Program Files\ToolwizCareFree
2013-11-26 13:23 - 2013-11-26 13:23 - 07619344 _____ (ToolWiz) C:\Users\zeeland\Downloads\Setup_ToolwizCare.exe
2013-11-26 13:18 - 2013-11-26 13:17 - 11125072 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\mseinstall.exe
2013-11-26 13:13 - 2013-11-26 13:13 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Hewlett-Packard
2013-11-26 13:12 - 2013-11-26 13:12 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Symantec
2013-11-26 13:12 - 2013-11-26 13:12 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Snapfish
2013-11-26 13:12 - 2013-11-26 13:12 - 00000000 ____D C:\Users\zeeland\AppData\Local\Google
2013-11-26 13:12 - 2013-11-26 13:11 - 00000000 ____D C:\Users\zeeland\AppData\Local\VirtualStore
2013-11-26 13:11 - 2013-11-26 13:11 - 00000951 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-26 13:11 - 2013-11-26 13:11 - 00000946 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2013-11-26 13:11 - 2013-11-26 13:11 - 00000917 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2013-11-26 13:11 - 2013-11-26 13:11 - 00000020 ___SH C:\Users\zeeland\ntuser.ini
2013-11-26 10:02 - 2013-11-26 10:02 - 00001973 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-11-26 10:02 - 2013-11-26 10:01 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Local\Google
2013-11-26 10:02 - 2013-11-26 10:01 - 00000000 ____D C:\Program Files\Google
2013-11-26 10:01 - 2013-11-26 10:01 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Local\Deployment
2013-11-26 10:01 - 2013-11-26 10:01 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Local\Apps\2.0
2013-11-26 09:57 - 2013-11-26 09:57 - 00000680 _____ C:\Users\Donna Tanaka\AppData\Local\d3d9caps.dat
2013-11-26 09:57 - 2008-02-27 13:37 - 00000000 ___HD C:\hp
2013-11-25 21:30 - 2013-11-25 21:26 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Roaming\Hewlett-Packard
2013-11-25 21:30 - 2008-02-27 14:04 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2013-11-25 21:29 - 2013-11-25 21:29 - 00072192 _____ C:\Users\Donna Tanaka\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-25 21:29 - 2013-11-25 21:29 - 00000951 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-25 21:29 - 2013-11-25 21:29 - 00000946 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2013-11-25 21:29 - 2013-11-25 21:29 - 00000917 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2013-11-25 21:29 - 2013-11-25 21:29 - 00000044 _____ C:\Windows\system\hpsysdrv.dat
2013-11-25 21:29 - 2013-11-25 21:29 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Roaming\Symantec
2013-11-25 21:29 - 2013-11-25 21:29 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Roaming\Snapfish
2013-11-25 21:29 - 2013-11-25 21:29 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Local\VirtualStore
2013-11-25 21:29 - 2013-11-25 21:24 - 00000000 ____D C:\Users\Donna Tanaka
2013-11-25 21:29 - 2008-02-27 13:51 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-25 21:29 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system
2013-11-25 21:27 - 2013-11-25 21:27 - 00000000 ____D C:\Users\Donna Tanaka\AppData\Roaming\Macromedia
2013-11-25 21:25 - 2013-11-25 21:25 - 00001853 _____ C:\Users\Public\Desktop\Internet & Digital Services.lnk
2013-11-25 21:25 - 2013-11-25 21:25 - 00001834 __RSH C:\Windows\system32\Drivers\103C_HP_CPC_KJ375AA-ABA s3400f_YC_0Pavi_QMXU810_E82NAv3PrA1_49_IAcacia_SASUSTek Computer INC._V1.02_B5.11_T080212_WUH1_L409_M3454_J500_7AMD_8Athlon 64 X2 Dual Core_92.7_#080429_N10DE03EF_Z14F12F20_G10DE03D0.MRK
2013-11-25 21:25 - 2008-02-27 14:05 - 00000000 ___RD C:\Program Files\Online Services
2013-11-25 21:25 - 2006-11-02 04:37 - 00000000 ____D C:\Windows\system32\restore
2013-11-25 21:24 - 2013-11-25 21:24 - 00000020 ___SH C:\Users\Donna Tanaka\ntuser.ini
2013-11-25 21:21 - 2006-11-02 03:18 - 00000000 __RHD C:\Users\Default
2013-11-25 21:16 - 2008-02-27 13:37 - 00000000 ____D C:\Windows\Panther
2013-11-19 02:21 - 2013-11-26 10:04 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Some content of TEMP:
C:\Users\Donna Tanaka\AppData\Local\Temp\swt-win32-3333.dll
C:\Users\Donna Tanaka\AppData\Local\Temp\symlcsv1.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-04 18:15
==================== End Of Log ============================


here is the second scan


Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-12-2013
Ran by zeeland at 2013-12-11 12:06:55
Running from C:\Users\zeeland\Desktop
Boot Mode: Normal
==================== Security Center ========================
AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
==================== Installed Programs ======================
Adobe Flash Player ActiveX (Version:
Adobe Reader 8.1.0 (Version: 8.1.0)
Cards_Calendar_OrderGift_DoMorePlugout (Version: 1.00.0000)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
CyberLink DVD Suite Deluxe (Version: 5.5.1126)
Enhanced Multimedia Keyboard Solution
Google Chrome (Version: 31.0.1650.57)
Google Update Helper (Version:
Hardware Diagnostic Tools (Version: 5.1.4708.19)
Hewlett-Packard Active Check (Version:
Hewlett-Packard Asset Agent for Health Check (Version:
HP Customer Experience Enhancements (Version:
HP Customer Feedback (Version: 1.0.0)
HP Demo (Version: 4.1.0)
HP Easy Setup - Frontend (Version:
HP On-Screen Cap/Num/Scroll Lock Indicator
HP Photosmart Essential 2.5 (Version: 1.02.0000)
HP Photosmart Essential 2.5 (Version: 2.5)
HP Picasso Media Center Add-In (Version: 1.0.0)
HP Total Care Advisor (Version:
HP Update (Version:
HPPhotoSmartPhotobookWebPack1 (Version: 1.00.0000)
Java SE Runtime Environment 6 Update 1 (Version:
LabelPrint (Version: 2.2.2329)
LightScribe System Software (Version:
LightScribeTemplateLabeler (Version:
Malwarebytes Anti-Malware version (Version:
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Office Home and Student 60 day trial
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000)
Microsoft Security Client (Version: 4.4.0304.0)
Microsoft Security Essentials (Version: 4.4.304.0)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Works (Version: 9.7.0621)
muvee autoProducer 6.1 (Version: 6.10.050)
My HP Games (Version: HPCMPQ1902)
NVIDIA Drivers
Power2Go (Version: 5.6.3610)
PowerDirector (Version: 6.5.2420)
PSSWCORE (Version: 2.02.0000)
Python 2.5 (Version: 2.5.150)
Realtek High Definition Audio Driver
Snapfish Picture Mover (Version:
Soft Data Fax Modem with SmartCP (Version: 7.74.00)
Toolwiz Care (Version:
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
VideoToolkit01 (Version:
WeatherBug Gadget (Version:
Yahoo! Toolbar
==================== Restore Points  =========================
26-11-2013 05:25:15 Scripted restore
26-11-2013 18:04:20 Windows Update
26-11-2013 21:24:42 Toolwiz Care(
26-11-2013 21:46:25 Windows Update
26-11-2013 21:51:10 Windows Update
26-11-2013 22:00:06 Windows Update
27-11-2013 15:30:51 Windows Update
28-11-2013 17:32:32 Windows Update
28-11-2013 17:41:50 Windows Update
29-11-2013 21:44:14 Windows Update
29-11-2013 22:57:36 Windows Update
29-11-2013 23:18:11 Windows Update
30-11-2013 02:15:41 Windows Update
30-11-2013 02:18:22 Windows Update
05-12-2013 01:52:34 Windows Update
05-12-2013 03:15:28 Windows Update
==================== Hosts content: ==========================
2006-11-02 02:23 - 2006-09-18 13:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts       localhost
::1             localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {14BE614B-BFEE-4332-84E9-5577E2FF7E50} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-26] (Google Inc.)
Task: {1C4F2298-1498-4526-8383-4F6CB5437ED0} - System32\Tasks\ExtendedServicePlan => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-12-17] ()
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {29FBD9BE-9C1F-4EB9-8151-B9F090620079} - System32\Tasks\PC-Doctor\Scheduled Maintenance => C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe [2007-10-04] (PC-Doctor, Inc.)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3FE2FF18-EFF6-4249-8E42-C61ABC6F52BB} - System32\Tasks\ServicePlan => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-12-17] ()
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\WINDOWS\System32\RacAgent.exe [2008-01-20] (Microsoft Corporation)
Task: {5B1F54CC-7F50-4B7D-9C33-86B5E427E135} - System32\Tasks\PC-Doctor\Scheduled Maintenance Swap => C:\Program Files\PC-Doctor 5 for Windows\task_swap.bat [2008-02-27] ()
Task: {73F25119-D79E-4FEA-9265-72C3292D2848} - System32\Tasks\IntenetServiceOffers => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-12-17] ()
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => C:\WINDOWS\System32\pla.dll [2008-01-20] (Microsoft Corporation)
Task: {C2518D44-021D-40B8-B161-22170A16F23A} - System32\Tasks\ToolwizCareFree => C:\Program Files\ToolwizCareFree\ToolwizCares.exe [2013-11-26] (Toolwiz)
Task: {C2E45A30-41F1-45B2-9C0B-CB35B473A2A4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-26] (Google Inc.)
Task: {D58921BA-0D80-4346-99BA-796CEA5807DD} - System32\Tasks\RecoveryCD => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-12-17] ()
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\WINDOWS\System32\gatherWirelessInfo.vbs [2008-01-20] ()
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
Error: (12/11/2013 00:03:14 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/04/2013 06:11:56 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/04/2013 06:04:53 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/04/2013 05:50:28 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/01/2013 03:28:17 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/01/2013 03:27:20 PM) (Source: EventSystem) (User: )
Description: d:\vistasp1_gdr\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
Error: (12/01/2013 00:14:28 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/01/2013 00:07:35 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/29/2013 06:07:59 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/29/2013 03:07:59 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
Error: (12/11/2013 00:03:15 PM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
Error: (12/11/2013 00:03:07 PM) (Source: Microsoft Antimalware) (User: )
Description: %Trojan:DOS/Alureon.K60 has encountered a critical error when taking action on malware or other potentially unwanted software.
For more information please see the following:
Name: Trojan:DOS/Alureon.K
Severity: %Trojan:DOS/Alureon.K600
Category: %Trojan:DOS/Alureon.K602
Path: 4.4.0304.02
Detection Origin: 4.4.0304.04
Detection Type: 4.4.0304.08
Detection Source: %Trojan:DOS/Alureon.K608
User: {C18C25C1-0222-4014-8C0F-D028060F7894}9
Process Name: %Trojan:DOS/Alureon.K609
Action: {C18C25C1-0222-4014-8C0F-D028060F7894}1
Action Status:  {C18C25C1-0222-4014-8C0F-D028060F7894}8
Error Code: {C18C25C1-0222-4014-8C0F-D028060F7894}3
Error description: {C18C25C1-0222-4014-8C0F-D028060F7894}4
Signature Version: 2013-12-11T20:02:28.122Z1
Engine Version: 2013-12-11T20:02:28.122Z2
Error: (12/11/2013 00:02:16 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (12/08/2013 03:27:34 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (12/04/2013 08:05:26 PM) (Source: DCOM) (User: )
Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED}
Error: (12/04/2013 08:05:03 PM) (Source: DCOM) (User: )
Description: {6295DF2D-35EE-11D1-8707-00C04FD93327}
Error: (12/04/2013 07:21:49 PM) (Source: mbamchameleon) (User: )
Error: (12/04/2013 07:21:49 PM) (Source: mbamchameleon) (User: )
Error: (12/04/2013 07:21:49 PM) (Source: mbamchameleon) (User: )
Error: (12/04/2013 07:21:49 PM) (Source: mbamchameleon) (User: )
Microsoft Office Sessions:
Error: (12/11/2013 00:03:14 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/04/2013 06:11:56 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/04/2013 06:04:53 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/04/2013 05:50:28 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/01/2013 03:28:17 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/01/2013 03:27:20 PM) (Source: EventSystem)(User: )
Description: d:\vistasp1_gdr\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
Error: (12/01/2013 00:14:28 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/01/2013 00:07:35 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/29/2013 06:07:59 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/29/2013 03:07:59 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
  Date: 2013-12-11 12:06:52.968
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:52.906
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:52.832
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:52.769
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:51.589
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:51.529
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:51.465
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:51.400
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:51.341
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-11 12:06:51.281
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info =========================== 
Percentage of memory in use: 34%
Total physical RAM: 3453.64 MB
Available physical RAM: 2251.72 MB
Total Pagefile: 7097.76 MB
Available Pagefile: 5898.94 MB
Total Virtual: 2047.88 MB
Available Virtual: 1912.92 MB
==================== Drives ================================
Drive c: (HP) (Fixed) (Total:456.43 GB) (Free:407.07 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (FACTORY_IMAGE) (Fixed) (Total:9.33 GB) (Free:1.27 GB) NTFS ==>[system with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
Disk: 0 (Size: 466 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=456 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=2544 KB) - (Type=17) ATTENTION ===> Suspicious partition bootkit on partition 2
Partition 3: (Not Active) - (Size=9 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Step 1

Please download the latest version of TDSSKiller from here and save it to your Desktop.

  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.


  • Put a checkmark beside loaded modules.


  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.


  • Click the Start Scan button.


  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.


  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.

    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.


    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
  • Step 2

    Note: Please do not run this tool without special supervision and instructions of someone authorized to do so. Otherwise, you could end up with serious problems. For more details, read this article: ComboFix usage, Questions, Help? - Look here

    Please visit this webpage and read the ComboFix User's Guide:

    • Once you've read the article and are ready to use the program you can download it directly from the link below.
    • Important! - Please make sure you save combofix to your desktop and do not run it from your browser
    • Direct download link for: ComboFix.exe
    • Please make sure you disable your security applications before running ComboFix.
    • Once Combofix has completed it will produce and open a log file. Please be patient as it can take some time to load.
    • Please copy/paste the contents or attach that log file to your next reply.
    • If needed the file can be located here: C:\combofix.txt
    • NOTE: If you receive the message "illegal operation has been attempted on a registry key that has been marked for deletion", just reboot the computer.
    In your next reply, post the following log files:
    • TDSSKiller log
    • ComboFix log
Thank you so much for your help.


I am now using a libarary computer.  I think both computers are have some problem with trojans

can not open virus, or dowload one or send to some bogus page.  when i do get one to run it comes back from a full scan in 30 seconds or less.

even in safe mode having the same problems. 

I will still keep tring it's it putting a drain on me.  I am sorry it looks like it will be slow going tackling this one.

I do have a tddsskiller log I will send that one to you as soon as I can. :wacko:


Link to post
Share on other sites


I did the killer tdsskiller and the combo fix 2 or more times they were no logs made at all.  I looked around and no logs.    I even tried in safe mode same   I even tried it on my laptop it just crash or frozen.   


If nothing else I was thinking about erasing hard drive, reformatting did not get rid of it before.. 

Link to post
Share on other sites

Please download Rkill by Grinler from one of the links below and save it to your desktop.

Link 1

Link 2

  • On Windows XP double-click on the Rkill desktop icon to run the tool.
  • On Windows Vista/Windows 7 or 8, right-click on the Rkill desktop icon and select Run As Administrator
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • If the tool does not run from any of the links provided, please let me know.
  • Do not reboot the computer, you will need to run the application again.
comfix must have rebooted I had to take care of something else when i got back the log in screen was on, i log back in waited a box pop up and sad windows have to shout down. I left it there an just waited not sure what i was waiting for. that was it.




tdsskiller I no log pop up below is the report i copy and paste below.  trojan still there..



14:54:26.0179 0x125c  ============================================================

14:54:26.0179 0x125c  Current date / time: 2013/12/28 14:54:26.0179

14:54:26.0179 0x125c  SystemInfo:

14:54:26.0179 0x125c  

14:54:26.0179 0x125c  OS Version: 6.0.6002 ServicePack: 2.0

14:54:26.0179 0x125c  Product type: Workstation

14:54:26.0179 0x125c  ComputerName: DONNATANAKA-PC

14:54:26.0179 0x125c  UserName: zeeland

14:54:26.0179 0x125c  Windows directory: C:\Windows

14:54:26.0179 0x125c  System windows directory: C:\Windows

14:54:26.0179 0x125c  Processor architecture: Intel x86

14:54:26.0180 0x125c  Number of processors: 2

14:54:26.0180 0x125c  Page size: 0x1000

14:54:26.0180 0x125c  Boot type: Normal boot

14:54:26.0180 0x125c  ============================================================

14:54:26.0306 0x125c  KLMD registered as C:\Windows\system32\drivers\00753558.sys

14:54:26.0405 0x125c  System UUID: {9E7FC0FF-1A65-040B-BE06-621358B97DDF}

14:54:26.0849 0x125c  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050

14:54:26.0867 0x125c  ============================================================

14:54:26.0867 0x125c  \Device\Harddisk0\DR0:

14:54:26.0867 0x125c  MBR partitions:

14:54:26.0867 0x125c  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x390DB9C0

14:54:26.0867 0x125c  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x390DB9FF, BlocksNum 0x12A9242

14:54:26.0867 0x125c  ============================================================

14:54:26.0899 0x125c  C: <-> \Device\Harddisk0\DR0\Partition1

14:54:26.0949 0x125c  D: <-> \Device\Harddisk0\DR0\Partition2

14:54:26.0949 0x125c  ============================================================

14:54:26.0949 0x125c  Initialize success

14:54:26.0949 0x125c  ============================================================

14:54:34.0218 0x12ac  ============================================================

14:54:34.0218 0x12ac  Scan started

14:54:34.0218 0x12ac  Mode: Manual; SigCheck; TDLFS; 

14:54:34.0218 0x12ac  ============================================================

14:54:34.0218 0x12ac  KSN ping started

14:54:34.0267 0x12ac  KSN ping finished: false

14:54:38.0278 0x12ac  ================ Scan system memory ========================

14:54:38.0279 0x12ac  System memory - ok

14:54:38.0279 0x12ac  ================ Scan services =============================

14:54:38.0407 0x12ac  22475791 - ok

14:54:38.0456 0x12ac  [ 82B296AE1892FE3DBEE00C9CF92F8AC7, 54B22BA63E1DA616B546992141B0C3117BA057283B8F60CB9BECE203661FEBF3 ] ACPI            C:\Windows\system32\drivers\acpi.sys

14:54:38.0547 0x12ac  ACPI - ok

14:54:38.0873 0x12ac  [ 04F0FCAC69C7C71A3AC4EB97FAFC8303, FBBDD38574A1F66A5AA12B82E34FDE60B870180C4B7100C15757539DC869ED4B ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys

14:54:38.0895 0x12ac  adp94xx - ok

14:54:38.0917 0x12ac  [ 60505E0041F7751BDBB80F88BF45C2CE, 1DE16042B8ABD7B643189E836DE273832EE743FD66AFBB641E8049C4E0CD04D8 ] adpahci         C:\Windows\system32\drivers\adpahci.sys

14:54:38.0931 0x12ac  adpahci - ok

14:54:38.0960 0x12ac  [ 8A42779B02AEC986EAB64ECFC98F8BD7, B89938EFF4E81FA44197D2D839EBD3340DDE01FBC79605049C088621784C1B91 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys

14:54:38.0970 0x12ac  adpu160m - ok

14:54:39.0000 0x12ac  [ 241C9E37F8CE45EF51C3DE27515CA4E5, 1A03E93DD8C1F3640C96124A14A3D0F4E349B06CCA2118CE40B8AE201A4030A7 ] adpu320         C:\Windows\system32\drivers\adpu320.sys

14:54:39.0010 0x12ac  adpu320 - ok

14:54:39.0043 0x12ac  [ 9D1FDA9E086BA64E3C93C9DE32461BCF, 200FD0BFC811EC8993AF9FC78F58823ECC717063F438B627FBCDD6BD7790CAA8 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll

14:54:39.0072 0x12ac  AeLookupSvc - ok

14:54:39.0112 0x12ac  [ 3911B972B55FEA0478476B2E777B29FA, 62545B90C7DD3F73777E62CD8264E611A4D71B6956CABFD2D820D25F41F471FD ] AFD             C:\Windows\system32\drivers\afd.sys

14:54:39.0130 0x12ac  AFD - ok

14:54:39.0187 0x12ac  [ 13F9E33747E6B41A3FF305C37DB0D360, 066DD6060B1CF93F85BBAAA52848C801128CD294E8B7EACD912E0EF219DBFBC2 ] agp440          C:\Windows\system32\drivers\agp440.sys

14:54:39.0195 0x12ac  agp440 - ok

14:54:39.0214 0x12ac  [ AE1FDF7BF7BB6C6A70F67699D880592A, B831BF156FC49287A19FC149383D437B1034EA6F42CE9D761EB90ABD0F8D96B1 ] aic78xx         C:\Windows\system32\drivers\djsvs.sys

14:54:39.0224 0x12ac  aic78xx - ok

14:54:39.0244 0x12ac  [ A1545B731579895D8CC44FC0481C1192, 6B0EE833BA39C142D625A03586CCD8F6C9C3136C603CE5DF5BAC1AA3423E3E7F ] ALG             C:\Windows\System32\alg.exe

14:54:39.0268 0x12ac  ALG - ok

14:54:39.0290 0x12ac  [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91, 0EADB6AE21FEDAB55D41F41B638198B556CC2BE2EE57F6C8B40EB044A318319F ] aliide          C:\Windows\system32\drivers\aliide.sys

14:54:39.0297 0x12ac  aliide - ok

14:54:39.0321 0x12ac  [ C47344BC706E5F0B9DCE369516661578, 689C9CDAF6F38227F1C34359CAEB3C7798F318EDFD4B7FE532FBE3C8E4EE3DC8 ] amdagp          C:\Windows\system32\drivers\amdagp.sys

14:54:39.0329 0x12ac  amdagp - ok

14:54:39.0355 0x12ac  [ 9B78A39A4C173FDBC1321E0DD659B34C, 2CA66EB68AD7A317D91C13B8CFD4E8CA985926A610D19595B613F5553B145C7B ] amdide          C:\Windows\system32\drivers\amdide.sys

14:54:39.0362 0x12ac  amdide - ok

14:54:39.0385 0x12ac  [ 18F29B49AD23ECEE3D2A826C725C8D48, 0FA08882301D218E367E63E1966B6406220EE94BAE7E7DAD6E55EB70BF6FED7F ] AmdK7           C:\Windows\system32\drivers\amdk7.sys

14:54:39.0408 0x12ac  AmdK7 - ok

14:54:39.0461 0x12ac  [ 93AE7F7DD54AB986A6F1A1B37BE7442D, ECE0ABA2DECEED94AC678240A4B604F04022F0740F2295CBD07D25F5917E878A ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys

14:54:39.0518 0x12ac  AmdK8 - ok

14:54:39.0550 0x12ac  [ C6D704C7F0434DC791AAC37CAC4B6E14, 35CF7D1895F97637E0C678A39F3049B871BCA9526D379C7793ED33B87D2EAC4C ] Appinfo         C:\Windows\System32\appinfo.dll

14:54:39.0563 0x12ac  Appinfo - ok

14:54:39.0621 0x12ac  [ 5D2888182FB46632511ACEE92FDAD522, 2E53231ACAF9B2FB7993DBC1CD15C06D7B0CCE0D08DAFF7B0CC13A2040028A75 ] arc             C:\Windows\system32\drivers\arc.sys

14:54:39.0632 0x12ac  arc - ok

14:54:39.0680 0x12ac  [ 5E2A321BD7C8B3624E41FDEC3E244945, 9D47FF6C823868F2267FEFAB5851D3CD2BC3F619A2D6EFF803EA22DB0509C450 ] arcsas          C:\Windows\system32\drivers\arcsas.sys

14:54:39.0690 0x12ac  arcsas - ok

14:54:39.0723 0x12ac  [ 53B202ABEE6455406254444303E87BE1, 4C91CA8DD345FEDD74A6AF2C07580717703F979B7DE2532B1D00B9F6896DDE70 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys

14:54:39.0749 0x12ac  AsyncMac - ok

14:54:39.0817 0x12ac  [ 1F05B78AB91C9075565A9D8A4B880BC4, 737BE9F9376DAB0CCDFED93EA6D67F0C432367EA63CD772A453485BE769AF3BD ] atapi           C:\Windows\system32\drivers\atapi.sys

14:54:39.0827 0x12ac  atapi - ok

14:54:39.0908 0x12ac  [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll

14:54:39.0940 0x12ac  AudioEndpointBuilder - ok

14:54:39.0965 0x12ac  [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] Audiosrv        C:\Windows\System32\Audiosrv.dll

14:54:39.0998 0x12ac  Audiosrv - ok

14:54:40.0017 0x12ac  [ 67E506B75BD5326A3EC7B70BD014DFB6, 3B07243970CAB4E93A858BEA6E31F56AD0157C42D624F3FEB469E68EEEF65669 ] Beep            C:\Windows\system32\drivers\Beep.sys

14:54:40.0043 0x12ac  Beep - ok

14:54:40.0102 0x12ac  [ C789AF0F724FDA5852FB9A7D3A432381, 4B0F7A3A8F2D45E49630D24F2630B8014BCDB793B9C6E83FD2B2863A54F62BF5 ] BFE             C:\Windows\System32\bfe.dll

14:54:40.0170 0x12ac  BFE - ok

14:54:40.0247 0x12ac  [ 93952506C6D67330367F7E7934B6A02F, 1D9A6B10B9489C1A32F730E22CC399BFF0796E3FCB3BA52BE45ED487CAC59EBD ] BITS            C:\Windows\System32\qmgr.dll

14:54:40.0327 0x12ac  BITS - ok

14:54:40.0342 0x12ac  [ D4DF28447741FD3D953526E33A617397, E7239BA432090F8AC7DF453DB876507CD4419ECA964D289408A1B2B353618693 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys

14:54:40.0367 0x12ac  blbdrive - ok

14:54:40.0399 0x12ac  [ 35F376253F687BDE63976CCB3F2108CA, C5EF6301D7BC067050038DB75D961681D1CBE418285AD60167C1334B0B54DFE9 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys

14:54:40.0417 0x12ac  bowser - ok

14:54:40.0440 0x12ac  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys

14:54:40.0465 0x12ac  BrFiltLo - ok

14:54:40.0479 0x12ac  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys

14:54:40.0504 0x12ac  BrFiltUp - ok

14:54:40.0530 0x12ac  [ A3629A0C4226F9E9C72FAAEEBC3AD33C, FB4D2738B64AADA52B95A6CF7ED4CDBFE4DD4BEBCAF1AE9CE64317F97DB38DDF ] Browser         C:\Windows\System32\browser.dll

14:54:40.0553 0x12ac  Browser - ok

14:54:40.0697 0x12ac  [ B304E75CFF293029EDDF094246747113, CB6B219B186C3511A0DE3CDE7F7B8966A9E32D808A952CA8C5B42B3A3A17BFB0 ] Brserid         C:\Windows\system32\drivers\brserid.sys

14:54:40.0764 0x12ac  Brserid - ok

14:54:40.0789 0x12ac  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys

14:54:40.0833 0x12ac  BrSerWdm - ok

14:54:40.0842 0x12ac  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys

14:54:40.0913 0x12ac  BrUsbMdm - ok

14:54:40.0925 0x12ac  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys

14:54:40.0963 0x12ac  BrUsbSer - ok

14:54:40.0972 0x12ac  [ AD07C1EC6665B8B35741AB91200C6B68, DCE1305A30D6713222A01C1F1D03ED0ADABE23C742CE1E82BB142531B82A3FF7 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys

14:54:41.0015 0x12ac  BTHMODEM - ok

14:54:41.0079 0x12ac  [ 9026258E6FD965982CBB090569AD7042, A9D0BC5273D165B6320602EF03CAA8A88ED20D07C2F3395E7EB401027B69234F ] BTOWSFF         C:\Windows\system32\Drivers\BTOWSFF.sys

14:54:41.0103 0x12ac  BTOWSFF - ok

14:54:41.0158 0x12ac  [ E12F2E9E0CF646FEBCB948EDDF76CAB4, D865B4642777DB97000BB11FEA34E871917D749E04CCFD62DC61F980246E99F2 ] BTOWSVF         C:\Windows\system32\Drivers\BTOWSVF.sys

14:54:41.0166 0x12ac  BTOWSVF - ok

14:54:41.0229 0x12ac  catchme - ok

14:54:41.0246 0x12ac  [ 7ADD03E75BEB9E6DD102C3081D29840A, 0CA14A77CE990B5AA32C0725C22CA190ECBC73B75064DD959CABAD79B8846F1D ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys

14:54:41.0272 0x12ac  cdfs - ok

14:54:41.0307 0x12ac  [ 6B4BFFB9BECD728097024276430DB314, 4451EFEAD37B05C8A3CB610B6D72E73B55D3D1E1CC1B17405598C1EDAA93C2D5 ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys

14:54:41.0327 0x12ac  cdrom - ok

14:54:41.0378 0x12ac  [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] CertPropSvc     C:\Windows\System32\certprop.dll

14:54:41.0419 0x12ac  CertPropSvc - ok

14:54:41.0436 0x12ac  [ E5D4133F37219DBCFE102BC61072589D, 74C7F8C53D9C71CE3C8B33BC0331948571318402B0A8E1AC4552360504092A46 ] circlass        C:\Windows\system32\drivers\circlass.sys

14:54:41.0463 0x12ac  circlass - ok

14:54:41.0510 0x12ac  [ D7659D3B5B92C31E84E53C1431F35132, 6BFE644AD9890A8CEEDCC4B97ADD564AD57202FBC5D21599469E0C4B31BB27C6 ] CLFS            C:\Windows\system32\CLFS.sys

14:54:41.0538 0x12ac  CLFS - ok

14:54:41.0612 0x12ac  [ 8EE772032E2FE80A924F3B8DD5082194, B743DF91563A22CC15D9B44105804B5866A29D3DFC156DBE88DFAFEF903B94C0 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

14:54:41.0622 0x12ac  clr_optimization_v2.0.50727_32 - ok

14:54:41.0649 0x12ac  [ 0CA25E686A4928484E9FDABD168AB629, C2CB2333CAB40CDF93219870E66700F957188C86A1B1A004BC4652953091E5C5 ] cmdide          C:\Windows\system32\drivers\cmdide.sys

14:54:41.0657 0x12ac  cmdide - ok

14:54:41.0686 0x12ac  [ 6AFEF0B60FA25DE07C0968983EE4F60A, E4037EF9EDE57A1039AB814EBCE9A8B12C9A084E7FAC6296212ACF2394DD37B6 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys

14:54:41.0694 0x12ac  Compbatt - ok

14:54:41.0700 0x12ac  COMSysApp - ok

14:54:41.0711 0x12ac  [ 741E9DFF4F42D2D8477D0FC1DC0DF871, 06EA43D771E3455F943AB624CC00C2259FE5E561164908630755E933EF44A522 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys

14:54:41.0720 0x12ac  crcdisk - ok

14:54:41.0742 0x12ac  [ 1F07BECDCA750766A96CDA811BA86410, F4E36F0003184BCB36D59B23AC903421AD8C0A1FD2D6315E06375235ABC9A0AD ] Crusoe          C:\Windows\system32\drivers\crusoe.sys

14:54:41.0769 0x12ac  Crusoe - ok

14:54:41.0818 0x12ac  [ FB27772BEAF8E1D28CCD825C09DA939B, D074A314FB3E6B2248F2DB0A734B98A110F618804449E055B4178BF414826982 ] CryptSvc        C:\Windows\system32\cryptsvc.dll

14:54:41.0842 0x12ac  CryptSvc - ok

14:54:41.0899 0x12ac  [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] DcomLaunch      C:\Windows\system32\rpcss.dll

14:54:41.0963 0x12ac  DcomLaunch - ok

14:54:42.0005 0x12ac  [ 622C41A07CA7E6DD91770F50D532CB6C, 2A9040949CB45F9970FDE930278F30D2F08E957290CB3D4DC4F2CA94F3D444D2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys

14:54:42.0021 0x12ac  DfsC - ok

14:54:42.0160 0x12ac  [ 2CC3DCFB533A1035B13DCAB6160AB38B, C88C91F662ADE248EEE3B568E70C2BC2D5075B7D9B7D3C63E83D011C5F7812B0 ] DFSR            C:\Windows\system32\DFSR.exe

14:54:42.0308 0x12ac  DFSR - ok

14:54:42.0390 0x12ac  [ 9028559C132146FB75EB7ACF384B086A, 35159D86706441ED94895B4629411B4445FCB4526AFD1F7036EE647931B7A94D ] Dhcp            C:\Windows\System32\dhcpcsvc.dll

14:54:42.0441 0x12ac  Dhcp - ok

14:54:42.0469 0x12ac  [ 5D4AEFC3386920236A548271F8F1AF6A, 11B74D6800EC6F7AAEFB0B6A9F2E8376C7C3B8DB677F03AC3743CB004CA96B08 ] disk            C:\Windows\system32\drivers\disk.sys

14:54:42.0478 0x12ac  disk - ok

14:54:42.0544 0x12ac  [ 57D762F6F5974AF0DA2BE88A3349BAAA, D9E7DC8F9FB7837F88BBB95B52147AA80E688FB9762EEA99B8046D9C6AD48F3C ] Dnscache        C:\Windows\System32\dnsrslvr.dll

14:54:42.0571 0x12ac  Dnscache - ok

14:54:42.0617 0x12ac  [ 324FD74686B1EF5E7C19A8AF49E748F6, DC6EB4304555B60DD17E04D20DFE4E279718E4041A9310DE29E678834BB22C5B ] dot3svc         C:\Windows\System32\dot3svc.dll

14:54:42.0639 0x12ac  dot3svc - ok

14:54:42.0678 0x12ac  [ A622E888F8AA2F6B49E9BC466F0E5DEF, 3DED7F22A29AD2F8C927DFA0FD87FDE5ED0BDCAC7260BD9F71D8EA34328C772A ] DPS             C:\Windows\system32\dps.dll

14:54:42.0703 0x12ac  DPS - ok

14:54:42.0754 0x12ac  [ 97FEF831AB90BEE128C9AF390E243F80, A7F4118603E2D5DDDB117EF7C058684EA5B37690EFAB2BEBA570EEF9C36281BE ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys

14:54:42.0769 0x12ac  drmkaud - ok

14:54:42.0873 0x12ac  [ FB85F7F69E9B109820409243F578CC4D, FBE0426E51B83DD973EC08ABA4E69E99F54B1C44995E0FD42B68A07549D52D7F ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys

14:54:42.0928 0x12ac  DXGKrnl - ok

14:54:42.0949 0x12ac  [ 5425F74AC0C1DBD96A1E04F17D63F94C, AD133CEDCDEA75420C75A91BB4CF7152475D46ED7B7703E3BAE5F9946D610292 ] E1G60           C:\Windows\system32\DRIVERS\E1G60I32.sys

14:54:42.0985 0x12ac  E1G60 - ok

14:54:43.0003 0x12ac  [ C0B95E40D85CD807D614E264248A45B9, 30421DAF1722A225222268CB8BA4FE60CB76C6FD0C9157B0F53FC1368F806A4E ] EapHost         C:\Windows\System32\eapsvc.dll

14:54:43.0021 0x12ac  EapHost - ok

14:54:43.0073 0x12ac  [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371, F3E9CF5D8E9124CB06F08454C5F0E510DE19A92780151FB2F8A58A0905D59B8F ] Ecache          C:\Windows\system32\drivers\ecache.sys

14:54:43.0096 0x12ac  Ecache - ok

14:54:43.0153 0x12ac  [ 9BE3744D295A7701EB425332014F0797, 1A139EE9232581E466591C5EBEF41E4BF1F82D99C1959F1C68C879B240E9F46D ] ehRecvr         C:\Windows\ehome\ehRecvr.exe

14:54:43.0173 0x12ac  ehRecvr - ok

14:54:43.0183 0x12ac  [ AD1870C8E5D6DD340C829E6074BF3C3F, 064D07106A1BBE80294F1913354832F2B67D22274BB4D36C81D2D83C96FE0B88 ] ehSched         C:\Windows\ehome\ehsched.exe

14:54:43.0198 0x12ac  ehSched - ok

14:54:43.0226 0x12ac  [ C27C4EE8926E74AA72EFCAB24C5242C3, F1EBF78CCE9BA76AFD0478BC66B67CA44DEAF3C380369BFCE91BD8F678C8608A ] ehstart         C:\Windows\ehome\ehstart.dll

14:54:43.0237 0x12ac  ehstart - ok

14:54:43.0267 0x12ac  [ 23B62471681A124889978F6295B3F4C6, A90C521F06125B86A26EA625B0E7F811AF7D328E1313165E7AD4A83596A23819 ] elxstor         C:\Windows\system32\drivers\elxstor.sys

14:54:43.0289 0x12ac  elxstor - ok

14:54:43.0355 0x12ac  [ 4E6B23DFC917EA39306B529B773950F4, C4BA77632B4BD46C4C1797F7F57399DB506D3EB6E5A0A36C269A793DAA3445C2 ] EMDMgmt         C:\Windows\system32\emdmgmt.dll

14:54:43.0428 0x12ac  EMDMgmt - ok

14:54:43.0476 0x12ac  [ 3DB974F3935483555D7148663F726C61, C288CFC04213B0340ABEC752C0A7B308B29122B5F51E68387BA1D9E9D7166FDD ] ErrDev          C:\Windows\system32\drivers\errdev.sys

14:54:43.0501 0x12ac  ErrDev - ok

14:54:43.0552 0x12ac  [ 67058C46504BC12D821F38CF99B7B28F, E8D19F305F78BCA1DA8425315F2C77A377CD51E3CC54323DC2FF355120EA097D ] EventSystem     C:\Windows\system32\es.dll

14:54:43.0578 0x12ac  EventSystem - ok

14:54:43.0682 0x12ac  [ 22B408651F9123527BCEE54B4F6C5CAE, 31AF9649333A9496A9224001266D1B68CE2A31B9FB182A755D127FC5492AA6B2 ] exfat           C:\Windows\system32\drivers\exfat.sys

14:54:43.0698 0x12ac  exfat - ok

14:54:43.0726 0x12ac  [ 1E9B9A70D332103C52995E957DC09EF8, 7E709D545D4025A2E9F3489CF2A231040904CB53E3E4EEAC15A22468FAB2A5B3 ] fastfat         C:\Windows\system32\drivers\fastfat.sys

14:54:43.0750 0x12ac  fastfat - ok

14:54:43.0784 0x12ac  [ AFE1E8B9782A0DD7FB46BBD88E43F89A, B4CBE1DC3430F2F3485F49007C71293D5B86E9C405741EA00A67B00A38BE1F8D ] fdc             C:\Windows\system32\DRIVERS\fdc.sys

14:54:43.0810 0x12ac  fdc - ok

14:54:43.0864 0x12ac  [ 6629B5F0E98151F4AFDD87567EA32BA3, 8CC02D5E0639CDF74B2F85DB56D6199E1858F1A58465ED1D8B25C968E986132C ] fdPHost         C:\Windows\system32\fdPHost.dll

14:54:43.0892 0x12ac  fdPHost - ok

14:54:43.0911 0x12ac  [ 89ED56DCE8E47AF40892778A5BD31FD2, 924360875796C3DDDDA8097FDF53F6846B227F7413766F00AEDD981EFD691BF9 ] FDResPub        C:\Windows\system32\fdrespub.dll

14:54:43.0960 0x12ac  FDResPub - ok

14:54:43.0997 0x12ac  [ A8C0139A884861E3AAE9CFE73B208A9F, 3B021D148A2989AAA46AE58E5FED8A2DCA25E9212C2FA7F922880EF5A077E49B ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys

14:54:44.0007 0x12ac  FileInfo - ok

14:54:44.0041 0x12ac  [ 0AE429A696AECBC5970E3CF2C62635AE, 1ECC315C099D17835788B68F0DE00EC98DC5AEE8F329D739E0DB90A898F22244 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys

14:54:44.0072 0x12ac  Filetrace - ok

14:55:04.0413 0x12ac  [ 78FE9542363F297B18C027B2D7E7C07F, 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE ] Wd              C:\Windows\system32\drivers\wd.sys

14:55:04.0422 0x12ac  Wd - ok

14:55:04.0447 0x12ac  [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96, 6A6EFFDB538DE1E201058A00F3E056F1256E92EED943FBFBCE28E54BE751E33D ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys

14:55:04.0480 0x12ac  Wdf01000 - ok

14:55:04.0501 0x12ac  [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiServiceHost  C:\Windows\system32\wdi.dll

14:55:04.0526 0x12ac  WdiServiceHost - ok

14:55:04.0532 0x12ac  [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiSystemHost   C:\Windows\system32\wdi.dll

14:55:04.0556 0x12ac  WdiSystemHost - ok

14:55:04.0691 0x12ac  [ 04C37D8107320312FBAE09926103D5E2, 1C6726A9871CBACB240AFA93E57781515F01758D43693DDA395EA683D97234F0 ] WebClient       C:\Windows\System32\webclnt.dll

14:55:04.0751 0x12ac  WebClient - ok

14:55:04.0797 0x12ac  [ 905214925A88311FCE52F66153DE7610, 5D18C6E835A2EA4108C93D9E6AA976142119860C8FC8ECB2DFA961A241B6E61C ] Wecsvc          C:\Windows\system32\wecsvc.dll

14:55:04.0863 0x12ac  Wecsvc - ok

14:55:04.0880 0x12ac  [ 670FF720071ED741206D69BD995EA453, 4B96F5E3545F69AE9EBC75DC4AB27B87306D656EE526AE39E7EC7E2B6F83F7FD ] wercplsupport   C:\Windows\System32\wercplsupport.dll

14:55:04.0909 0x12ac  wercplsupport - ok

14:55:04.0965 0x12ac  [ 32B88481D3B326DA6DEB07B1D03481E7, 821FBAF147E525ED15EB9391B16A96C6D5464841258B11F277EFB57A3BD50E37 ] WerSvc          C:\Windows\System32\WerSvc.dll

14:55:04.0996 0x12ac  WerSvc - ok

14:55:05.0164 0x12ac  [ 72CC6A8CA7891031D6380DB5025C773C, 33D5021C3A2FE8E9F6E2C22F4777E1D82A6B3998EB857B618A3C8838D3C8B03E ] winachsf        C:\Windows\system32\DRIVERS\HSX_CNXT.sys

14:55:05.0216 0x12ac  winachsf - ok

14:55:05.0264 0x12ac  [ 4575AA12561C5648483403541D0D7F2B, 2DBB7904285F16E879E1662C4CC4DFAA420D5EB24DDFC4BAC0B7616F5F44649A ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll

14:55:05.0281 0x12ac  WinDefend - ok

14:55:05.0291 0x12ac  WinHttpAutoProxySvc - ok

14:55:05.0352 0x12ac  [ 6B2A1D0E80110E3D04E6863C6E62FD8A, EE8BC7C378993EFE90273764C83119EBF331768CD7B24DE949233C74A51306C2 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll

14:55:05.0394 0x12ac  Winmgmt - ok

14:55:05.0465 0x12ac  [ 01874D4689C212460FBABF0ECD7CB7F7, 8FC46BAD704A1E057DC4A8DC7374AAB93A96CC4A46E06FF9C2E06A6D62820469 ] WinRM           C:\Windows\system32\WsmSvc.dll

14:55:05.0539 0x12ac  WinRM - ok

14:55:05.0671 0x12ac  [ C008405E4FEEB069E30DA1D823910234, C392A7B5FEACB7D11A3A231C1AD65D533984E6E7429ECD3BFBF90A27E8DEB157 ] Wlansvc         C:\Windows\System32\wlansvc.dll

14:55:05.0712 0x12ac  Wlansvc - ok

14:55:05.0753 0x12ac  [ 2E7255D172DF0B8283CDFB7B433B864E, 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys

14:55:05.0792 0x12ac  WmiAcpi - ok

14:55:05.0834 0x12ac  [ 43BE3875207DCB62A85C8C49970B66CC, 27169F2E8A30807794407DA8F80611E4287F940AAE2A1F00F547901872FB9703 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe

14:55:05.0880 0x12ac  wmiApSrv - ok

14:55:06.0043 0x12ac  [ 3978704576A121A9204F8CC49A301A9B, 936CC13B90A183613BDA4081556C96D48CA415B5F65D61E18CB5F2E51EEBE59F ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe

14:55:06.0126 0x12ac  WMPNetworkSvc - ok

14:55:06.0156 0x12ac  [ CFC5A04558F5070CEE3E3A7809F3FF52, 45899E04000E21C4E009BE8B6149F199A5B2E0512C657A525770BF9DBFED7D2B ] WPCSvc          C:\Windows\System32\wpcsvc.dll

14:55:06.0194 0x12ac  WPCSvc - ok

14:55:06.0251 0x12ac  [ 396D406292B0CD26E3504FFE82784702, 5F9015BB515AC13D4DFE8F4B532352CF2C5B61DEFD3D0D61BCD82C781D36E7AF ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll

14:55:06.0284 0x12ac  WPDBusEnum - ok

14:55:06.0303 0x12ac  [ E3A3CB253C0EC2494D4A61F5E43A389C, 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys

14:55:06.0332 0x12ac  ws2ifsl - ok

14:55:06.0434 0x12ac  [ 1CA6C40261DDC0425987980D0CD2AAAB, 727C1E3A170316641F832A8D197EDA6D6EE1206E4ED7B741E5A4017B7F2F7B88 ] wscsvc          C:\Windows\system32\wscsvc.dll

14:55:06.0474 0x12ac  wscsvc - ok

14:55:06.0480 0x12ac  WSearch - ok

14:55:06.0774 0x12ac  [ 01E1499A7A4FCA7CDE102B60976544C1, E0DFC8F229A3B9235658DC47237715E41FC71DC6F7C0EBB4FF0C632FCA89FB91 ] wuauserv        C:\Windows\system32\wuaueng.dll

14:55:06.0886 0x12ac  wuauserv - ok

14:55:06.0910 0x12ac  [ AC13CB789D93412106B0FB6C7EB2BCB6, 8F5B0BD0CBBAB182A400F8994D4727BC0C978D749B6429A2D41B412AE97428B6 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys

14:55:06.0933 0x12ac  WUDFRd - ok

14:55:06.0979 0x12ac  [ 575A4190D989F64732119E4114045A4F, 373C344B106AFDB1E6125A21DFE28CA6CFC77FA87FE904656A4F209DB2ED69C7 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll

14:55:07.0010 0x12ac  wudfsvc - ok

14:55:07.0032 0x12ac  [ DAB33CFA9DD24251AAA389FF36B64D4B, 1C5D7C3D6C3552BDD52EB7E76031746D7DAAF64CA2432CC23329DA72BE7252D0 ] XAudio          C:\Windows\system32\DRIVERS\xaudio.sys

14:55:07.0041 0x12ac  XAudio - ok

14:55:07.0073 0x12ac  [ CD5F291A1161F15896D1A4D63DAFF5DF, 4F30DC454F255249431FCD14DE17858A79A088A4084F2CEDD0CF25382D427285 ] XAudioService   C:\Windows\system32\DRIVERS\xaudio.exe

14:55:07.0094 0x12ac  XAudioService - ok

14:55:07.0104 0x12ac  ================ Scan global ===============================

14:55:07.0132 0x12ac  [ F31EEBC1A1C81FD04005489CC3DCDFE7, 098C35ACFCCE1686C5A6DB6057001CBF8B06A863A0802CB2E9D793F4795F8CEE ] C:\Windows\system32\basesrv.dll

14:55:07.0171 0x12ac  [ 5DF01708D214FDC0075AD197F1889557, 7E9ABB5C1F873AD3CE4FDB66CA6E2278F966F238CB4E78994D6A2014B10BCAC4 ] C:\Windows\system32\winsrv.dll

14:55:07.0214 0x12ac  [ 5DF01708D214FDC0075AD197F1889557, 7E9ABB5C1F873AD3CE4FDB66CA6E2278F966F238CB4E78994D6A2014B10BCAC4 ] C:\Windows\system32\winsrv.dll

14:55:07.0265 0x12ac  [ D4E6D91C1349B7BFB3599A6ADA56851B, 8748091BF27F05D28D45688E04DD9229A4B2E159209A64F457703F66A8CECE4D ] C:\Windows\system32\services.exe

14:55:07.0273 0x12ac  [ Global ] - ok

14:55:07.0274 0x12ac  ================ Scan MBR ==================================

14:55:07.0299 0x12ac  [ 03BA8F890B47C0BE359A4D5A636D214D ] \Device\Harddisk0\DR0

14:55:07.0839 0x12ac  \Device\Harddisk0\DR0 - ok

14:55:07.0839 0x12ac  ================ Scan VBR ==================================

14:55:07.0873 0x12ac  [ E30625107FE6AB8675B0F338CA3BEFB1 ] \Device\Harddisk0\DR0\Partition1

14:55:07.0900 0x12ac  \Device\Harddisk0\DR0\Partition1 - ok

14:55:07.0929 0x12ac  [ 60F98F500C7AE6BD3EC70C13646926C3 ] \Device\Harddisk0\DR0\Partition2

14:55:07.0955 0x12ac  \Device\Harddisk0\DR0\Partition2 - ok

14:55:07.0973 0x12ac  AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.4.304.0 ), 0x60000 ( disabled : updated )

14:55:07.0979 0x12ac  Win FW state via NFP2: enabled

14:55:07.0980 0x12ac  ============================================================

14:55:07.0980 0x12ac  Scan finished

14:55:07.0980 0x12ac  ============================================================

14:55:07.0995 0x12a4  Detected object count: 1

14:55:07.0995 0x12a4  Actual detected object count: 1

14:55:20.0285 0x12a4  HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user

14:55:20.0285 0x12a4  HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 
can result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-12-2013 01

Ran by zeeland (administrator) on DONNATANAKA-PC on 29-12-2013 18:30:41

Running from C:\Users\zeeland\Desktop

Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: English(US)

Internet Explorer Version 7

Boot Mode: Normal


==================== Processes (Whitelisted) ===================


(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe

(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe

(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe

() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe

(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe

(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

(Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe

(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe

(OsdMaestro) C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

(Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe

() C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe

(Toolwiz) C:\Program Files\ToolwizCareFree\ToolwizCares.exe

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe

(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Toolwiz.com) C:\Program Files\ToolwizCareFree\ToolwizTools.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Hewlett-Packard Company) C:\hp\KBD\kbd.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe


==================== Registry (Whitelisted) ==================


HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-20] (Microsoft Corporation)

HKLM\...\Run: [RtHDVCpl] - C:\WINDOWS\RtHDVCpl.exe [4874240 2008-01-15] (Realtek Semiconductor)

HKLM\...\Run: [hpsysdrv] - C:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company)

HKLM\...\Run: [KBD] - C:\hp\KBD\KbdStub.exe [65536 2006-12-08] ()

HKLM\...\Run: [OsdMaestro] - C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro)

HKLM\...\Run: [NvSvc] - RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

HKLM\...\Run: [HP Health Check Scheduler] - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [40048 2007-05-11] (Adobe Systems Incorporated)

HKLM\...\Run: [sunJavaUpdateSched] - C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe [132760 2007-04-07] (Sun Microsystems, Inc.)

HKLM\...\Run: [] - [x]

HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)

HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard)

HKCU\...\Run: [ToolwizCareFree] - C:\Program Files\ToolwizCareFree\ToolwizCares.exe [5286160 2013-11-26] (Toolwiz)

HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

HKU\Default\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)

HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)

HKU\Donna Tanaka\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

HKU\Donna Tanaka\...\Run: [HPAdvisor] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)

HKU\Guest\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

HKU\Guest\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-12-2013 01

Ran by zeeland (administrator) on DONNATANAKA-PC on 29-12-2013 18:37:34

Running from C:\Users\zeeland\Desktop

Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: English(US)

Internet Explorer Version 7

Boot Mode: Normal


==================== Processes (Whitelisted) ===================


(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe

(Microsoft Corporation) C:\WINDOWS\System32\SLsvc.exe

(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe

() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe

(Conexant Systems, Inc.) C:\WINDOWS\System32\drivers\XAudio.exe

(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

(Realtek Semiconductor) C:\WINDOWS\RtHDVCpl.exe

(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe

(OsdMaestro) C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe

(Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe

(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe

() C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe

(Toolwiz) C:\Program Files\ToolwizCareFree\ToolwizCares.exe

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe

(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Toolwiz.com) C:\Program Files\ToolwizCareFree\ToolwizTools.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Hewlett-Packard Company) C:\hp\KBD\kbd.exe

(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

(Microsoft Corporation) C:\WINDOWS\System32\wuauclt.exe

(Microsoft Corporation) C:\WINDOWS\System32\mcbuilder.exe


==================== Registry (Whitelisted) ==================


HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-20] (Microsoft Corporation)

HKLM\...\Run: [RtHDVCpl] - C:\WINDOWS\RtHDVCpl.exe [4874240 2008-01-15] (Realtek Semiconductor)

HKLM\...\Run: [hpsysdrv] - C:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company)

HKLM\...\Run: [KBD] - C:\hp\KBD\KbdStub.exe [65536 2006-12-08] ()

HKLM\...\Run: [OsdMaestro] - C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [118784 2007-02-15] (OsdMaestro)

HKLM\...\Run: [NvSvc] - RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

HKLM\...\Run: [HP Health Check Scheduler] - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe

HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [40048 2007-05-11] (Adobe Systems Incorporated)

HKLM\...\Run: [sunJavaUpdateSched] - C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe [132760 2007-04-07] (Sun Microsystems, Inc.)

HKLM\...\Run: [] - [x]

HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)

HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard)

HKCU\...\Run: [ToolwizCareFree] - C:\Program Files\ToolwizCareFree\ToolwizCares.exe [5286160 2013-11-26] (Toolwiz)

HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

HKU\Default\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)

HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

HKU\Default User\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)

HKU\Donna Tanaka\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

HKU\Donna Tanaka\...\Run: [HPAdvisor] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)

HKU\Guest\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter

HKU\Guest\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [ 2008-01-18] (Hewlett-Packard)


==================== Internet (Whitelisted) ====================


HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop

HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop

SearchScopes: HKLM - DefaultScope {508A4A7F-C702-4AE4-B67F-0343CD614D48} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt

SearchScopes: HKLM - {3A3F7E4B-FA3B-4DDF-9929-8994B6A30D65} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd

SearchScopes: HKLM - {508A4A7F-C702-4AE4-B67F-0343CD614D48} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt

SearchScopes: HKCU - DefaultScope {508A4A7F-C702-4AE4-B67F-0343CD614D48} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt

SearchScopes: HKCU - {3A3F7E4B-FA3B-4DDF-9929-8994B6A30D65} URL = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpd

SearchScopes: HKCU - {508A4A7F-C702-4AE4-B67F-0343CD614D48} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt

SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={A0D24AFC-3F5F-4975-8497-97DD9311F974}&mid=26c3c34aa62147d2b594d157ca21f3b8-cef38b5d3d50a79db66d7f07723e5e77d74d4ff3〈=en&ds=st011&pr=sa&d=2013-12-28 16:48:38&v={searchTerms}

BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)

Toolbar: HKLM - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG SafeGuard toolbar\\AVG SafeGuard toolbar_toolbar.dll ()

Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)

Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll ()

Tcpip\Parameters: [DhcpNameServer]




CHR DefaultSearchKeyword: mysearch.avg.com

CHR DefaultSearchProvider: AVG Secure Search

CHR DefaultSearchURL: http://mysearch.avg.com/search?cid={A0D24AFC-3F5F-4975-8497-97DD9311F974}&mid=26c3c34aa62147d2b594d157ca21f3b8-cef38b5d3d50a79db66d7f07723e5e77d74d4ff3〈=en&ds=st011&pr=sa&d=2013-12-28 16:48:38&v={searchTerms}

CHR DefaultNewTabURL: 

CHR Extension: (Google Docs) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0

CHR Extension: (Google Drive) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0

CHR Extension: (YouTube) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0

CHR Extension: (Google Search) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\

CHR Extension: (Google Wallet) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\

CHR Extension: (Bitdefender QuickScan) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\

CHR Extension: (Gmail) - C:\Users\zeeland\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\\avg.crx


========================== Services (Whitelisted) =================


R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [65536 2007-09-19] (Hewlett-Packard)

R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)

S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)

R2 vToolbarUpdater14.0.1; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [945480 2013-12-28] ()


==================== Drivers (Whitelisted) ====================


R1 BTOWSFF; C:\Windows\system32\Drivers\BTOWSFF.sys [27648 2013-11-26] (Toolwiz.com)

R0 BTOWSVF; C:\Windows\System32\Drivers\BTOWSVF.sys [45952 2013-11-26] (Toolwiz.com)

R0 KSafeDISK; C:\Windows\System32\Drivers\KSafeDISK.sys [48640 2013-11-26] (Toolwiz.com)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)

R1 SCDEmu; C:\Windows\System32\Drivers\SCDEmu.sys [114376 2013-10-23] (Power Software Ltd)

S0 22475791; system32\drivers\19334667.sys [x]

U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)

S3 catchme; \??\C:\Users\zeeland\AppData\Local\Temp\catchme.sys [x]

S3 IpInIp; system32\DRIVERS\ipinip.sys [x]

S3 MFE_RR; \??\C:\Users\zeeland\AppData\Local\Temp\mfe_rr.sys [x]

S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]

S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]


==================== NetSvcs (Whitelisted) ===================



==================== One Month Created Files and Folders ========


2013-12-29 18:33 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll

2013-12-29 18:33 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe

2013-12-29 18:33 - 2012-06-02 14:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll

2013-12-29 18:33 - 2012-06-02 14:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe

2013-12-29 18:33 - 2012-06-02 14:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll

2013-12-29 18:33 - 2012-06-02 14:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll

2013-12-29 18:28 - 2013-12-29 18:28 - 01064199 _____ (Farbar) C:\Users\zeeland\Desktop\FRST.exe

2013-12-29 18:26 - 2013-12-29 18:27 - 00112023 _____ C:\Users\zeeland\Downloads\FRST.txt

2013-12-29 18:05 - 2013-12-29 18:06 - 00002286 _____ C:\Windows\IE9_main.log

2013-12-28 19:28 - 2013-12-28 19:29 - 79388215 _____ C:\Users\zeeland\Downloads\create-book.zip

2013-12-28 19:28 - 2013-12-28 19:28 - 11326541 _____ C:\Users\zeeland\Downloads\install-mac.zip

2013-12-28 19:28 - 2013-12-28 19:28 - 02431989 _____ C:\Users\zeeland\Desktop\add-account.zip

2013-12-28 19:20 - 2013-12-28 19:20 - 00436558 _____ C:\Users\zeeland\Downloads\TheKindleProfitSystem.zip

2013-12-28 19:20 - 2013-10-29 16:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

2013-12-28 19:20 - 2013-07-31 19:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys

2013-12-28 19:20 - 2013-07-31 18:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll

2013-12-28 19:20 - 2013-06-15 05:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll

2013-12-28 19:20 - 2013-06-15 03:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys

2013-12-28 19:20 - 2012-05-11 07:57 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll

2013-12-28 19:20 - 2011-10-14 08:03 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll

2013-12-28 19:20 - 2011-10-14 08:00 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\mciseq.dll

2013-12-28 19:20 - 2011-07-29 08:01 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll

2013-12-28 19:20 - 2011-07-29 08:01 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax

2013-12-28 19:20 - 2011-07-29 08:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax

2013-12-28 19:20 - 2011-07-29 08:00 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax

2013-12-28 19:19 - 2013-07-20 02:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll

2013-12-28 19:12 - 2013-10-29 18:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll

2013-12-28 19:12 - 2013-10-29 17:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys

2013-12-28 19:12 - 2013-10-29 16:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

2013-12-28 19:12 - 2013-10-23 18:17 - 06119424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 03626496 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 01177600 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00480256 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll

2013-12-28 19:12 - 2013-10-23 18:17 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll

2013-12-28 19:12 - 2013-10-23 18:16 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll

2013-12-28 19:12 - 2013-10-23 16:55 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec

2013-12-28 19:12 - 2013-10-23 16:44 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb

2013-12-28 19:12 - 2013-07-17 11:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll

2013-12-28 19:12 - 2013-07-10 01:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll

2013-12-28 19:12 - 2013-07-04 19:20 - 00914880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys

2013-12-28 19:12 - 2013-07-04 17:43 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys

2013-12-28 19:12 - 2012-11-02 02:18 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll

2013-12-28 19:12 - 2012-11-02 00:26 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\dpnsvr.exe

2013-12-28 19:12 - 2012-09-25 08:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll

2013-12-28 19:12 - 2012-08-21 03:47 - 00224640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys

2013-12-28 19:12 - 2012-06-29 08:01 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll

2013-12-28 19:12 - 2012-06-08 09:47 - 11586048 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll

2013-12-28 19:12 - 2012-03-20 15:28 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys

2013-12-28 19:12 - 2011-11-18 09:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll

2013-12-28 19:12 - 2011-10-14 08:02 - 00429056 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll

2013-12-28 19:11 - 2013-10-21 23:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll

2013-12-28 19:11 - 2013-10-10 18:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL

2013-12-28 19:11 - 2013-10-10 18:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll

2013-12-28 19:11 - 2013-10-10 18:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx

2013-12-28 19:11 - 2013-10-10 18:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll

2013-12-28 19:11 - 2013-10-10 18:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL

2013-12-28 19:11 - 2013-10-10 16:39 - 00218228 _____ C:\Windows\system32\WFP.TMF

2013-12-28 19:11 - 2013-10-10 16:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe

2013-12-28 19:11 - 2013-10-10 16:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe

2013-12-28 19:11 - 2013-10-03 04:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll

2013-12-28 19:11 - 2013-10-03 04:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll

2013-12-28 19:11 - 2013-08-01 20:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL

2013-12-28 19:11 - 2013-07-15 20:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll

2013-12-28 19:11 - 2013-07-09 04:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll

2013-12-28 19:11 - 2013-07-07 20:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe

2013-12-28 19:11 - 2013-07-07 20:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe

2013-12-28 19:11 - 2013-06-28 18:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys

2013-12-28 19:11 - 2013-06-28 18:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys

2013-12-28 19:11 - 2013-06-28 18:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys

2013-12-28 19:11 - 2013-06-26 15:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys

2013-12-28 19:11 - 2013-06-26 15:01 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys

2013-12-28 19:11 - 2013-06-26 15:01 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll

2013-12-28 19:11 - 2013-06-03 20:16 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll

2013-12-28 19:11 - 2013-06-03 17:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll

2013-12-28 19:11 - 2013-05-31 20:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll

2013-12-28 19:11 - 2013-05-01 20:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll

2013-12-28 19:11 - 2013-05-01 20:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll

2013-12-28 19:11 - 2013-04-23 20:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll

2013-12-28 19:11 - 2013-04-23 17:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe

2013-12-28 19:11 - 2013-03-08 19:45 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll

2013-12-28 19:11 - 2013-03-08 17:28 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe

2013-12-28 19:11 - 2013-03-03 11:07 - 01082232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys

2013-12-28 19:11 - 2012-11-19 20:22 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll

2013-12-28 19:11 - 2012-11-07 19:48 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll

2013-12-28 19:11 - 2012-11-02 02:19 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll

2013-12-28 19:11 - 2012-09-28 08:11 - 00892928 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll

2013-12-28 19:11 - 2012-02-29 07:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll

2013-12-28 19:11 - 2012-02-29 05:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys

2013-12-28 19:11 - 2011-12-14 08:17 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll

2013-12-28 19:11 - 2011-11-16 08:23 - 00377344 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll

2013-12-28 19:11 - 2011-10-25 07:58 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll

2013-12-28 19:11 - 2011-08-25 08:15 - 00555520 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll

2013-12-28 19:11 - 2011-08-25 08:14 - 00563712 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll

2013-12-28 19:11 - 2011-08-25 08:14 - 00238080 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll

2013-12-28 19:11 - 2011-08-25 05:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\oleaccrc.dll

2013-12-28 19:11 - 2011-05-05 05:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys

2013-12-28 19:11 - 2011-05-05 05:54 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys

2013-12-28 19:10 - 2013-07-07 20:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll

2013-12-28 19:10 - 2013-07-07 20:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll

2013-12-28 19:10 - 2013-07-07 20:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll

2013-12-28 19:10 - 2013-07-03 20:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll

2013-12-28 19:10 - 2013-03-07 19:53 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll

2013-12-28 19:10 - 2013-03-07 19:52 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll

2013-12-28 19:10 - 2013-02-11 17:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys

2013-12-28 19:10 - 2012-06-05 08:47 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll

2013-12-28 19:10 - 2012-06-04 07:26 - 00440704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys

2013-12-28 19:10 - 2012-06-01 16:04 - 00278528 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll

2013-12-28 19:10 - 2012-05-01 06:03 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys

2013-12-28 19:10 - 2011-11-16 08:23 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll

2013-12-28 19:10 - 2011-11-16 08:21 - 01259008 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll

2013-12-28 19:10 - 2011-11-16 06:12 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe

2013-12-28 19:05 - 2012-01-09 07:54 - 00613376 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll

2013-12-28 17:17 - 2013-12-28 17:17 - 00000000 ____D C:\Users\zeeland\Documents\Ashampoo Burning Studio FREE

2013-12-28 16:56 - 2013-12-28 16:56 - 00000844 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio FREE.lnk

2013-12-28 16:56 - 2013-12-28 16:56 - 00000000 ____D C:\Users\zeeland\Ashampoo Burning Studio FREE

2013-12-28 16:56 - 2013-12-28 16:56 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Ashampoo

2013-12-28 16:56 - 2013-12-28 16:56 - 00000000 ____D C:\Users\zeeland\AppData\Local\ashampoo

2013-12-28 16:56 - 2013-12-28 16:56 - 00000000 ____D C:\ProgramData\Ashampoo

2013-12-28 16:52 - 2013-12-28 16:52 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\PowerISO

2013-12-28 16:50 - 2013-12-28 16:50 - 30465288 _____ (Ashampoo GmbH & Co. KG                                      ) C:\Users\zeeland\Downloads\ashampoo_burning_studio_free_1.12.0_sm.exe

2013-12-28 16:48 - 2013-12-28 16:48 - 00031576 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys

2013-12-28 16:48 - 2013-12-28 16:48 - 00000806 _____ C:\Users\Public\Desktop\PowerISO.lnk

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\Users\zeeland\AppData\Local\AVG SafeGuard toolbar

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\Program Files\PowerISO

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\Program Files\AVG SafeGuard toolbar

2013-12-28 16:30 - 2013-12-28 16:30 - 00008224 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT

2013-12-28 14:59 - 2013-12-28 15:01 - 00000000 ___SD C:\ComboFix

2013-12-28 14:58 - 2013-12-28 14:58 - 00082513 _____ C:\Users\zeeland\Desktop\12 .28 tdds.txt

2013-12-28 14:46 - 2013-12-28 14:46 - 00000000 ____D C:\Windows\system32\vi-VN

2013-12-28 14:46 - 2013-12-28 14:46 - 00000000 ____D C:\Windows\system32\eu-ES

2013-12-28 14:46 - 2013-12-28 14:46 - 00000000 ____D C:\Windows\system32\ca-ES

2013-12-28 14:21 - 2013-12-28 14:21 - 00000000 ____D C:\Windows\system32\EventProviders

2013-12-25 19:27 - 2013-12-25 19:27 - 00071451 _____ C:\Users\zeeland\Desktop\FRST 25.txt

2013-12-25 19:18 - 2013-12-25 19:18 - 00860176 _____ (Microsoft Corporation) C:\Users\zeeland\Desktop\mssstool32 (1).exe

2013-12-25 19:13 - 2013-12-25 19:13 - 11125072 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\mseinstall (1).exe

2013-12-25 19:12 - 2013-12-25 19:13 - 92215576 _____ (Microsoft Corporation) C:\Users\zeeland\Desktop\msert.exe

2013-12-25 18:18 - 2011-06-25 22:45 - 00256000 _____ C:\Windows\PEV.exe

2013-12-25 18:18 - 2010-11-07 09:20 - 00208896 _____ C:\Windows\MBR.exe

2013-12-25 18:18 - 2009-04-19 20:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe

2013-12-25 18:18 - 2000-08-30 16:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe

2013-12-25 18:18 - 2000-08-30 16:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe

2013-12-25 18:18 - 2000-08-30 16:00 - 00098816 _____ C:\Windows\sed.exe

2013-12-25 18:18 - 2000-08-30 16:00 - 00080412 _____ C:\Windows\grep.exe

2013-12-25 18:18 - 2000-08-30 16:00 - 00068096 _____ C:\Windows\zip.exe

2013-12-25 17:08 - 2013-12-25 17:08 - 05158070 ____R (Swearware) C:\Users\zeeland\Downloads\ComboFix.exe

2013-12-25 17:08 - 2013-12-25 17:08 - 00000855 _____ C:\Users\zeeland\Desktop\ComboFix - Shortcut.lnk

2013-12-25 16:16 - 2013-12-28 14:54 - 00002198 _____ C:\Users\zeeland\Desktop\Rkill.txt

2013-12-25 16:10 - 2013-12-25 16:10 - 00000855 _____ C:\Users\zeeland\Desktop\iExplore - Shortcut.lnk

2013-12-25 16:00 - 2013-12-25 16:00 - 01937144 _____ (Bleeping Computer, LLC) C:\Users\zeeland\Downloads\iExplore.exe

2013-12-25 16:00 - 2013-12-25 16:00 - 01937144 _____ (Bleeping Computer, LLC) C:\Users\zeeland\Desktop\rkill.exe

2013-12-23 10:15 - 2013-12-23 10:15 - 04101441 _____ C:\Users\zeeland\Downloads\tdsskiller.zip

2013-12-23 10:08 - 2013-12-28 19:04 - 00000000 ____D C:\Windows\Minidump

2013-12-23 09:40 - 2013-12-23 10:15 - 00000000 ____D C:\Users\zeeland\Desktop\hp

2013-12-23 09:40 - 2013-12-19 13:29 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\zeeland\Desktop\tdsskiller.exe

2013-12-23 09:38 - 2013-12-23 09:39 - 00000000 ____D C:\Qoobox

2013-12-23 09:37 - 2013-12-23 09:37 - 00000000 ____D C:\Windows\erdnt

2013-12-22 11:15 - 2013-12-22 11:15 - 49940480 _____ C:\Program Files\GUT6049.tmp

2013-12-22 11:15 - 2013-12-22 11:15 - 00000000 ____D C:\Program Files\GUM6019.tmp

2013-12-16 18:23 - 2013-12-16 18:23 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\zeeland\Downloads\tdsskiller (1).exe

2013-12-11 12:06 - 2013-12-29 18:37 - 00011179 _____ C:\Users\zeeland\Desktop\FRST.txt

2013-12-11 12:06 - 2013-12-11 12:07 - 00017087 _____ C:\Users\zeeland\Desktop\Addition.txt

2013-12-11 12:06 - 2013-12-11 12:06 - 00000000 ____D C:\FRST

2013-12-04 19:06 - 2013-12-23 10:18 - 00075992 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys

2013-12-04 19:06 - 2013-12-23 10:18 - 00000000 ____D C:\Users\zeeland\Desktop\mbar

2013-12-04 19:06 - 2013-12-23 09:28 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)

2013-12-04 19:05 - 2013-12-04 19:05 - 12576792 _____ (Malwarebytes Corp.) C:\Users\zeeland\Downloads\mbar- (1).exe

2013-12-04 19:05 - 2013-12-04 19:05 - 12576792 _____ (Malwarebytes Corp.) C:\Users\zeeland\Desktop\16m7bar.exe

2013-12-04 19:03 - 2013-12-04 19:03 - 00000000 ____D C:\Users\zeeland\Desktop\help

2013-12-04 18:16 - 2013-12-04 18:16 - 00000908 _____ C:\Users\Public\Desktop\may.lnk

2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Malwarebytes

2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\ProgramData\Malwarebytes

2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware

2013-12-04 18:16 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys

2013-12-04 18:15 - 2013-12-04 18:15 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\zeeland\Downloads\mbam-setup-

2013-12-04 18:08 - 2013-12-04 18:08 - 00001917 _____ C:\Users\zeeland\Desktop\aswMBR.txt

2013-12-04 18:04 - 2013-12-04 18:04 - 00000104 _____ C:\Users\zeeland\Documents\Recycle Bin - Shortcut.lnk

2013-12-01 15:29 - 2013-12-01 15:29 - 00002384 _____ C:\Users\zeeland\Desktop\attach.txt

2013-12-01 15:29 - 2013-12-01 15:28 - 00010298 _____ C:\Users\zeeland\Desktop\dds.txt

2013-12-01 15:28 - 2013-12-01 15:28 - 00081276 _____ C:\Users\zeeland\Downloads\2.xps

2013-12-01 12:53 - 2013-12-01 12:53 - 00688992 ____R (Swearware) C:\Users\zeeland\Desktop\dds.com

2013-12-01 12:53 - 2013-12-01 12:53 - 00688992 _____ (Swearware) C:\Users\zeeland\Downloads\dds.scr

2013-12-01 12:40 - 2009-04-10 22:33 - 00986600 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe

2013-12-01 12:40 - 2009-04-10 22:33 - 00926184 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe

2013-12-01 12:40 - 2009-04-10 22:33 - 00614376 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll

2013-12-01 12:40 - 2009-04-10 22:32 - 00438744 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 03217408 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe

2013-12-01 12:40 - 2009-04-10 22:28 - 03174400 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 02167808 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 02134528 _____ (Microsoft Corporation) C:\Windows\system32\FunctionDiscoveryFolder.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 02012160 _____ (Microsoft Corporation) C:\Windows\system32\milcore.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01985024 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01856512 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01788416 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01730560 _____ (Microsoft Corporation) C:\Windows\system32\apds.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01591296 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01589248 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01576960 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01524736 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01480704 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01459200 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01381376 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01324032 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01209856 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01112064 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01086464 _____ (Microsoft Corporation) C:\Windows\system32\NetProjW.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01081344 _____ (Microsoft Corporation) C:\Windows\system32\SLCExt.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01078784 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01055232 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe

2013-12-01 12:40 - 2009-04-10 22:28 - 01053696 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 01017856 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00978432 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00968192 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz2.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00950784 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00928768 _____ (Microsoft Corporation) C:\Windows\system32\scavenge.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00807424 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00747008 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL

2013-12-01 12:40 - 2009-04-10 22:28 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00670720 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00644608 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\msrepl40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00627712 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00618496 _____ (Microsoft Corporation) C:\Windows\system32\mswstr10.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2VDEC.DLL

2013-12-01 12:40 - 2009-04-10 22:28 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00582144 _____ (Microsoft Corporation) C:\Windows\system32\SLCommDlg.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\emdmgmt.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00550400 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00476672 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00472064 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00469504 _____ (Microsoft Corporation) C:\Windows\system32\newdev.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00466944 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\msxbde40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00454144 _____ (Microsoft) C:\Windows\system32\IasMigPlugin.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\msexch40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\msvcp60.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00398848 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00385536 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe

2013-12-01 12:40 - 2009-04-10 22:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\devmgr.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\mspbde40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\SLUI.exe

2013-12-01 12:40 - 2009-04-10 22:28 - 00351744 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\msrd3x40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00339968 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00334848 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL

2013-12-01 12:40 - 2009-04-10 22:28 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\P2PGraph.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\sdohlp.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\msrd2x40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL

2013-12-01 12:40 - 2009-04-10 22:28 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\WscEapPr.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\msjtes40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe

2013-12-01 12:40 - 2009-04-10 22:28 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\mstext40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\es.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00250368 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\msltus40.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\SLC.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\adsldpc.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\sperror.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\WcnNetsh.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\wevtutil.exe

2013-12-01 12:40 - 2009-04-10 22:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\spoolss.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\korwbrkr.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\nlhtml.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00117248 _____ C:\Windows\system32\EhStorAuthn.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayDriverLib.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\EhStorShell.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe

2013-12-01 12:40 - 2009-04-10 22:28 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\fdBth.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\msctfp.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\propdefs.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\slwmi.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\xmlfilter.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingProxy.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\EhStorPwdMgr.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\msscb.dll

2013-12-01 12:40 - 2009-04-10 22:28 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\fdBthProxy.dll

2013-12-01 12:40 - 2009-04-10 22:27 - 03408896 _____ (Microsoft Corporation) C:\Windows\system32\SLsvc.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 02926592 _____ (Microsoft Corporation) C:\Windows\explorer.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 02092544 _____ (Microsoft Corporation) C:\Windows\system32\dfsr.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelinesvc.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl

2013-12-01 12:40 - 2009-04-10 22:27 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00518144 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\IasMigReader.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00441344 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\drvinst.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\PresentationSettings.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingWizard.exe

2013-12-01 12:40 - 2009-04-10 22:27 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\compcln.exe

2013-12-01 12:40 - 2009-04-10 22:22 - 00883712 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME

2013-12-01 12:40 - 2009-04-10 21:03 - 12240896 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0007.dll
2013-12-01 12:40 - 2009-04-10 21:03 - 02644480 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0009.dll

2013-12-01 12:40 - 2009-04-10 20:48 - 00344698 _____ C:\Windows\system32\eaphost.tmf

2013-12-01 12:40 - 2009-04-10 20:43 - 00442788 _____ C:\Windows\system32\dot3.tmf

2013-12-01 12:40 - 2009-04-10 20:43 - 00392170 _____ C:\Windows\system32\onex.tmf

2013-12-01 12:40 - 2009-04-10 20:42 - 00561152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys

2013-12-01 12:40 - 2009-04-10 20:42 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS

2013-12-01 12:40 - 2009-04-10 20:14 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys

2013-12-01 12:40 - 2009-04-10 20:14 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys

2013-12-01 12:40 - 2009-04-10 18:52 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spsys.sys

2013-12-01 12:40 - 2009-04-10 17:59 - 00107612 _____ C:\Windows\system32\StructuredQuerySchema.bin

2013-12-01 12:40 - 2009-04-10 17:54 - 03662128 _____ C:\Windows\system32\locale.nls

2013-12-01 12:40 - 2009-03-06 17:11 - 00130008 _____ C:\Windows\system32\systemsf.ebd

2013-12-01 12:40 - 2009-02-19 16:20 - 00009239 _____ C:\Windows\system32\spcinstrumentation.man

2013-12-01 12:40 - 2009-02-18 10:39 - 00779136 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll

2013-12-01 12:40 - 2009-02-18 10:38 - 11967524 _____ C:\Windows\system32\korwbrkr.lex

2013-12-01 12:40 - 2009-02-18 10:38 - 00619864 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe

2013-12-01 12:40 - 2009-02-18 10:38 - 00099680 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll

2013-12-01 12:39 - 2009-04-10 22:33 - 00292840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00527848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00265688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00245736 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00190424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00180712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00161752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00149480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00141288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ecache.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00125928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00122344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Storport.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00109032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00099816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS

2013-12-01 12:39 - 2009-04-10 22:32 - 00053736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00053224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00050664 _____ (Microsoft Corporation) C:\Windows\system32\PSHED.DLL

2013-12-01 12:39 - 2009-04-10 22:32 - 00048104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00043496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pciidex.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00035304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\crashdmp.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00027624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Dumpata.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00019944 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll

2013-12-01 12:39 - 2009-04-10 22:32 - 00019944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\atapi.sys

2013-12-01 12:39 - 2009-04-10 22:32 - 00017896 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll

2013-12-01 12:39 - 2009-04-10 22:32 - 00017384 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll

2013-12-01 12:39 - 2009-04-10 22:32 - 00014312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pciide.sys

2013-12-01 12:39 - 2009-04-10 22:28 - 06103040 _____ (Microsoft Corporation) C:\Windows\system32\chtbrkr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 03072000 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 02515968 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 02226688 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 02225664 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 02205184 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 02153472 _____ (Microsoft Corporation) C:\Windows\system32\oobefldr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01823744 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01671680 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01671680 _____ (Microsoft Corporation) C:\Windows\system32\chsbrkr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01645568 _____ (Microsoft Corporation) C:\Windows\system32\connect.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01580544 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01575936 _____ (Microsoft Corporation) C:\Windows\system32\WMVENCOD.DLL

2013-12-01 12:39 - 2009-04-10 22:28 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01541120 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01533440 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01502720 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01382912 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL

2013-12-01 12:39 - 2009-04-10 22:28 - 01342464 _____ (Microsoft Corporation) C:\Windows\system32\brcpl.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01224192 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01152000 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\wercon.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 01123840 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01107968 _____ (Microsoft Corporation) C:\Windows\system32\pidgenx.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 01020928 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00996352 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00876032 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\mswdat10.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00852992 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00825856 _____ (Microsoft Corporation) C:\Windows\system32\rasdlg.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00777216 _____ (Microsoft Corporation) C:\Windows\system32\slcc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00759296 _____ (Microsoft Corporation) C:\Windows\system32\ipsecsnp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00712704 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00657408 _____ (Microsoft Corporation) C:\Windows\system32\WMVXENCD.DLL

2013-12-01 12:39 - 2009-04-10 22:28 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\rasgcw.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\Utilman.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\CertEnrollUI.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\comuid.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\prnntfy.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\wiaaut.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00542720 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00542208 _____ (Microsoft Corporation) C:\Windows\system32\pnpui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00533504 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00532992 _____ (Microsoft Corporation) C:\Windows\system32\wpcao.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00516608 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00507904 _____ (Microsoft Corporation) C:\Windows\system32\vdsdyn.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00481792 _____ (Microsoft Corporation) C:\Windows\system32\cmdial32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00464384 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00449024 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\dsound.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00425472 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00425472 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00399360 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\rasplap.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00368640 _____ C:\Windows\system32\msjetoledb40.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00364032 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL

2013-12-01 12:39 - 2009-04-10 22:28 - 00356864 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00342528 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\RelMon.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00332800 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00313344 _____ (Microsoft Corporation) C:\Windows\system32\thawbrkr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\modemui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00286720 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\w32time.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\SnippingTool.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\wow32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\iassdo.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\wscntfy.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\mscandui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00217600 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00200704 _____ (Microsoft Corporation) C:\Windows\system32\input.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\offfilt.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\SLLUA.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\iassam.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\pnpsetup.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\scrobj.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\WSDMon.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00163328 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceTypes.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\rasmontr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\fundisc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iasnap.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wpcsvc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\dsprop.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\tcpmon.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\extmgr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\softkbd.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\ntmarta.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\imapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\regsvc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\dmsynth.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\dmusic.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\ulib.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\powrprof.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\oleprn.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\SCardSvr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceClassExtension.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL

2013-12-01 12:39 - 2009-04-10 22:28 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\wshext.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\msctfui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mstlsapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00083456 _____ (Microsoft) C:\Windows\system32\SMBHelperClass.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\wlgpclnt.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\iassvcs.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\iashlpr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\PNPXAssoc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\mpr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\fdSSDP.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\fdWSD.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\msjter40.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\SLUINotify.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\iasads.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Storprop.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\feclient.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\mmci.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\l2nacp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\iasdatastore.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\bthci.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dataclen.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msstrc.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\slcinst.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\bthserv.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\networkitemfactory.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\TSTheme.exe

2013-12-01 12:39 - 2009-04-10 22:28 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\rtffilt.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iaspolcy.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\perfdisk.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\bitsigd.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\whealogr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\msimtf.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\ifmon.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\wsepno.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\uxsms.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\printfilterpipelineprxy.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\hidserv.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\msjint40.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\fdProxy.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\version.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\winrnr.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\NcdProp.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\MsCtfMonitor.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wscisvif.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\vdmdbg.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\midimap.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\msisip.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\spcmsg.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mmcico.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\spwinsat.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll

2013-12-01 12:39 - 2009-04-10 22:28 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\CHxReadingStringIME.dll

2013-12-01 12:39 - 2009-04-10 22:27 - 01827840 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl

2013-12-01 12:39 - 2009-04-10 22:27 - 01689600 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl

2013-12-01 12:39 - 2009-04-10 22:27 - 01122304 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl

2013-12-01 12:39 - 2009-04-10 22:27 - 01102848 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl

2013-12-01 12:39 - 2009-04-10 22:27 - 00714240 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl

2013-12-01 12:39 - 2009-04-10 22:27 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr

2013-12-01 12:39 - 2009-04-10 22:27 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00636416 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00407040 _____ (Microsoft Corporation) C:\Windows\system32\dpapimig.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx

2013-12-01 12:39 - 2009-04-10 22:27 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp

2013-12-01 12:39 - 2009-04-10 22:27 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00258048 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv

2013-12-01 12:39 - 2009-04-10 22:27 - 00241128 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll

2013-12-01 12:39 - 2009-04-10 22:27 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\certreq.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv

2013-12-01 12:39 - 2009-04-10 22:27 - 00130024 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll

2013-12-01 12:39 - 2009-04-10 22:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\gpresult.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax

2013-12-01 12:39 - 2009-04-10 22:27 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\dwm.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax

2013-12-01 12:39 - 2009-04-10 22:27 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\hdwwiz.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\newdev.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\conime.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\reg.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00058368 _____ (Microsoft Corporation) C:\Windows\system32\cipher.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\cmmon32.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\csrstub.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cbsra.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\rekeywiz.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\bthudtask.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\PnPutil.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\ipconfig.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEject.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\msacm32.drv

2013-12-01 12:39 - 2009-04-10 22:27 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\fc.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\rasdial.exe

2013-12-01 12:39 - 2009-04-10 22:27 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\gpupdate.exe

2013-12-01 12:39 - 2009-04-10 22:23 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime

2013-12-01 12:39 - 2009-04-10 22:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime

2013-12-01 12:39 - 2009-04-10 22:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime

2013-12-01 12:39 - 2009-04-10 22:23 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime

2013-12-01 12:39 - 2009-04-10 22:23 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime

2013-12-01 12:39 - 2009-04-10 22:22 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime

2013-12-01 12:39 - 2009-04-10 22:22 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime

2013-12-01 12:39 - 2009-04-10 22:22 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime

2013-12-01 12:39 - 2009-04-10 22:22 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\f3ahvoas.dll

2013-12-01 12:39 - 2009-04-10 21:42 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys

2013-12-01 12:39 - 2009-04-10 20:46 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys

2013-12-01 12:39 - 2009-04-10 20:46 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rassstp.sys

2013-12-01 12:39 - 2009-04-10 20:46 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspppoe.sys

2013-12-01 12:39 - 2009-04-10 20:46 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys

2013-12-01 12:39 - 2009-04-10 20:45 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys

2013-12-01 12:39 - 2009-04-10 20:45 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys

2013-12-01 12:39 - 2009-04-10 20:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys

2013-12-01 12:39 - 2009-04-10 20:45 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys

2013-12-01 12:39 - 2009-04-10 20:45 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\smb.sys

2013-12-01 12:39 - 2009-04-10 20:43 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys

2013-12-01 12:39 - 2009-04-10 20:43 - 00062208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ohci1394.sys

2013-12-01 12:39 - 2009-04-10 20:42 - 00052992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys

2013-12-01 12:39 - 2009-04-10 20:42 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys

2013-12-01 12:39 - 2009-04-10 20:42 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD.sys

2013-12-01 12:39 - 2009-04-10 20:39 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys

2013-12-01 12:39 - 2009-04-10 20:39 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys

2013-12-01 12:39 - 2009-04-10 20:39 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll

2013-12-01 12:39 - 2009-04-10 20:38 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys

2013-12-01 12:39 - 2009-04-10 20:27 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll

2013-12-01 12:39 - 2009-04-10 20:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxg.sys

2013-12-01 12:39 - 2009-04-10 20:22 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\watchdog.sys

2013-12-01 12:39 - 2009-04-10 20:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys

2013-12-01 12:39 - 2009-04-10 20:13 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys

2013-12-01 12:39 - 2009-04-10 20:13 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys

2013-12-01 12:39 - 2009-04-10 20:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys

2013-12-01 12:39 - 2009-04-10 20:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll

2013-12-01 12:39 - 2009-04-10 17:59 - 00018904 _____ C:\Windows\system32\StructuredQuerySchemaTrivial.bin

2013-12-01 12:39 - 2009-03-29 20:42 - 00155456 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll

2013-12-01 12:39 - 2009-03-29 20:42 - 00080720 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll

2013-12-01 12:39 - 2009-02-19 16:20 - 00009212 _____ C:\Windows\system32\RacUR.xml

2013-12-01 12:39 - 2009-02-18 10:43 - 00000153 _____ C:\Windows\system32\RacUREx.xml

2013-12-01 12:39 - 2009-02-18 10:39 - 00092918 _____ C:\Windows\system32\slmgr.vbs

2013-12-01 12:39 - 2009-02-18 10:39 - 00035680 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe

2013-12-01 12:39 - 2009-02-18 10:38 - 00035168 _____ (Microsoft Corporation) C:\Windows\system32\infocardcpl.cpl

2013-12-01 12:39 - 2009-02-18 10:38 - 00009048 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll

2013-12-01 12:38 - 2009-04-10 22:28 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll

2013-12-01 12:38 - 2009-04-10 22:28 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll

2013-12-01 12:38 - 2009-04-10 22:28 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\wdscore.dll

2013-12-01 12:38 - 2009-04-10 22:27 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe

2013-12-01 12:32 - 2013-12-01 12:32 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131201_123229.log

2013-12-01 12:13 - 2013-12-01 12:13 - 00072192 _____ C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT

2013-12-01 12:13 - 2013-12-01 12:13 - 00000951 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2013-12-01 12:13 - 2013-12-01 12:13 - 00000946 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk

2013-12-01 12:13 - 2013-12-01 12:13 - 00000917 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk

2013-12-01 12:13 - 2013-12-01 12:13 - 00000020 ___SH C:\Users\Guest\ntuser.ini

2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Snapfish

2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest\AppData\Local\VirtualStore

2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest

2013-12-01 12:13 - 2008-02-27 13:58 - 00001034 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite Deluxe.lnk

2013-12-01 12:13 - 2008-01-20 18:42 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

2013-12-01 12:13 - 2008-01-20 18:42 - 00000000 ___RD C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

2013-11-29 18:53 - 2013-11-29 18:53 - 17245644 _____ C:\Users\zeeland\Downloads\fiction.xps

2013-11-29 18:21 - 2013-11-29 18:21 - 00860176 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\mssstool32.exe

2013-11-29 18:17 - 2013-11-29 18:17 - 00511248 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\nis_full.exe

2013-11-29 15:00 - 2013-12-04 18:03 - 00000000 ____D C:\Program Files\Microsoft Silverlight

2013-11-29 14:58 - 2013-12-25 15:27 - 00000000 ____D C:\Windows\system32\MRT

2013-11-29 14:57 - 2011-03-03 07:40 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\Apphlpdm.dll

2013-11-29 14:57 - 2011-03-03 05:35 - 04240384 _____ (Microsoft) C:\Windows\system32\GameUXLegacyGDFs.dll

2013-11-29 14:57 - 2010-08-26 08:34 - 01696256 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll

2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145639.log

2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145621.log

2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145618.log

2013-11-29 14:46 - 2013-11-29 14:46 - 00000680 _____ C:\Users\zeeland\AppData\Local\d3d9caps.dat

2013-11-29 13:42 - 2013-11-29 13:42 - 01441838 _____ C:\Users\zeeland\Downloads\Daily Deal Millionaires.zip


==================== One Month Modified Files and Folders =======


2013-12-29 18:37 - 2013-12-11 12:06 - 00011179 _____ C:\Users\zeeland\Desktop\FRST.txt

2013-12-29 18:34 - 2013-11-25 21:21 - 01989560 _____ C:\Windows\WindowsUpdate.log

2013-12-29 18:28 - 2013-12-29 18:28 - 01064199 _____ (Farbar) C:\Users\zeeland\Desktop\FRST.exe

2013-12-29 18:28 - 2006-11-02 02:33 - 00690960 _____ C:\Windows\system32\PerfStringBackup.INI

2013-12-29 18:27 - 2013-12-29 18:26 - 00112023 _____ C:\Users\zeeland\Downloads\FRST.txt

2013-12-29 18:24 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\Microsoft.NET

2013-12-29 18:23 - 2013-11-26 10:01 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-12-29 18:22 - 2006-11-02 05:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2013-12-29 18:22 - 2006-11-02 04:47 - 00286144 _____ C:\Windows\system32\FNTCACHE.DAT

2013-12-29 18:22 - 2006-11-02 04:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0

2013-12-29 18:22 - 2006-11-02 04:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0

2013-12-29 18:20 - 2008-02-27 13:41 - 00000000 ____D C:\Windows\system32\RTCOM

2013-12-29 18:20 - 2006-11-02 05:01 - 00025574 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2013-12-29 18:20 - 2006-11-02 04:37 - 00000000 ____D C:\Windows\system32\XPSViewer

2013-12-29 18:20 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Windows Journal

2013-12-29 18:20 - 2006-11-02 03:18 - 00000000 ____D C:\Program Files\Common Files\System

2013-12-29 18:17 - 2013-11-26 10:01 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-12-29 18:06 - 2013-12-29 18:05 - 00002286 _____ C:\Windows\IE9_main.log

2013-12-29 18:02 - 2013-11-27 12:27 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\HpUpdate

2013-12-28 19:29 - 2013-12-28 19:28 - 79388215 _____ C:\Users\zeeland\Downloads\create-book.zip

2013-12-28 19:28 - 2013-12-28 19:28 - 11326541 _____ C:\Users\zeeland\Downloads\install-mac.zip

2013-12-28 19:28 - 2013-12-28 19:28 - 02431989 _____ C:\Users\zeeland\Desktop\add-account.zip

2013-12-28 19:20 - 2013-12-28 19:20 - 00436558 _____ C:\Users\zeeland\Downloads\TheKindleProfitSystem.zip

2013-12-28 19:04 - 2013-12-23 10:08 - 00000000 ____D C:\Windows\Minidump

2013-12-28 17:17 - 2013-12-28 17:17 - 00000000 ____D C:\Users\zeeland\Documents\Ashampoo Burning Studio FREE

2013-12-28 16:56 - 2013-12-28 16:56 - 00000844 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio FREE.lnk

2013-12-28 16:56 - 2013-12-28 16:56 - 00000000 ____D C:\Users\zeeland\Ashampoo Burning Studio FREE

2013-12-28 16:56 - 2013-12-28 16:56 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Ashampoo

2013-12-28 16:56 - 2013-12-28 16:56 - 00000000 ____D C:\Users\zeeland\AppData\Local\ashampoo

2013-12-28 16:56 - 2013-12-28 16:56 - 00000000 ____D C:\ProgramData\Ashampoo

2013-12-28 16:56 - 2013-11-26 13:11 - 00000000 ____D C:\Users\zeeland

2013-12-28 16:52 - 2013-12-28 16:52 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\PowerISO

2013-12-28 16:50 - 2013-12-28 16:50 - 30465288 _____ (Ashampoo GmbH & Co. KG                                      ) C:\Users\zeeland\Downloads\ashampoo_burning_studio_free_1.12.0_sm.exe

2013-12-28 16:48 - 2013-12-28 16:48 - 00031576 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys

2013-12-28 16:48 - 2013-12-28 16:48 - 00000806 _____ C:\Users\Public\Desktop\PowerISO.lnk

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\Users\zeeland\AppData\Local\AVG SafeGuard toolbar

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\Program Files\PowerISO

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search

2013-12-28 16:48 - 2013-12-28 16:48 - 00000000 ____D C:\Program Files\AVG SafeGuard toolbar

2013-12-28 16:30 - 2013-12-28 16:30 - 00008224 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT

2013-12-28 16:30 - 2013-11-25 21:29 - 00008224 _____ C:\Users\Donna Tanaka\AppData\Local\GDIPFONTCACHEV1.DAT

2013-12-28 16:30 - 2013-11-25 21:29 - 00000951 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2013-12-28 16:30 - 2013-11-25 21:29 - 00000917 _____ C:\Users\Donna Tanaka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk

2013-12-28 16:30 - 2008-02-27 13:51 - 00000000 ____D C:\ProgramData\NVIDIA

2013-12-28 15:42 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\rescache

2013-12-28 15:01 - 2013-12-28 14:59 - 00000000 ___SD C:\ComboFix

2013-12-28 14:58 - 2013-12-28 14:58 - 00082513 _____ C:\Users\zeeland\Desktop\12 .28 tdds.txt

2013-12-28 14:54 - 2013-12-25 16:16 - 00002198 _____ C:\Users\zeeland\Desktop\Rkill.txt

2013-12-28 14:52 - 2013-11-26 13:11 - 00000951 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2013-12-28 14:52 - 2013-11-26 13:11 - 00000917 _____ C:\Users\zeeland\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk

2013-12-28 14:47 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Windows Sidebar

2013-12-28 14:47 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Windows Photo Gallery

2013-12-28 14:47 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Windows Defender

2013-12-28 14:47 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Windows Collaboration

2013-12-28 14:47 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Windows Calendar

2013-12-28 14:47 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Movie Maker

2013-12-28 14:46 - 2013-12-28 14:46 - 00000000 ____D C:\Windows\system32\vi-VN

2013-12-28 14:46 - 2013-12-28 14:46 - 00000000 ____D C:\Windows\system32\eu-ES

2013-12-28 14:46 - 2013-12-28 14:46 - 00000000 ____D C:\Windows\system32\ca-ES

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\zh-TW

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\zh-CN

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\uk-UA

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\tr-TR

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\th-TH

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\sv-SE

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\sr-Latn-CS

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\SLUI

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\sl-SI

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\sk-SK

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\ru-RU

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\ro-RO

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\pt-PT

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\pt-BR

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\pl-PL

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\nl-NL

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\nb-NO

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\lv-LV

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\lt-LT

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\ko-KR

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\ja-JP

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\it-IT

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\hu-HU

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\hr-HR

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\he-IL

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\fr-FR

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\fi-FI

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\et-EE

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\el-GR

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\de-DE

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\bg-BG

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\ar-SA

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\AdvancedInstallers

2013-12-28 14:46 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\IME

2013-12-28 14:21 - 2013-12-28 14:21 - 00000000 ____D C:\Windows\system32\EventProviders

2013-12-25 19:27 - 2013-12-25 19:27 - 00071451 _____ C:\Users\zeeland\Desktop\FRST 25.txt

2013-12-25 19:18 - 2013-12-25 19:18 - 00860176 _____ (Microsoft Corporation) C:\Users\zeeland\Desktop\mssstool32 (1).exe

2013-12-25 19:14 - 2013-11-26 13:53 - 00002198 _____ C:\Windows\epplauncher.mif

2013-12-25 19:13 - 2013-12-25 19:13 - 11125072 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\mseinstall (1).exe

2013-12-25 19:13 - 2013-12-25 19:12 - 92215576 _____ (Microsoft Corporation) C:\Users\zeeland\Desktop\msert.exe

2013-12-25 17:08 - 2013-12-25 17:08 - 05158070 ____R (Swearware) C:\Users\zeeland\Downloads\ComboFix.exe

2013-12-25 17:08 - 2013-12-25 17:08 - 00000855 _____ C:\Users\zeeland\Desktop\ComboFix - Shortcut.lnk

2013-12-25 16:10 - 2013-12-25 16:10 - 00000855 _____ C:\Users\zeeland\Desktop\iExplore - Shortcut.lnk

2013-12-25 16:05 - 2008-02-27 14:13 - 00000000 ____D C:\Windows\SMINST

2013-12-25 16:00 - 2013-12-25 16:00 - 01937144 _____ (Bleeping Computer, LLC) C:\Users\zeeland\Downloads\iExplore.exe

2013-12-25 16:00 - 2013-12-25 16:00 - 01937144 _____ (Bleeping Computer, LLC) C:\Users\zeeland\Desktop\rkill.exe

2013-12-25 15:27 - 2013-11-29 14:58 - 00000000 ____D C:\Windows\system32\MRT

2013-12-25 15:27 - 2006-11-02 02:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe

2013-12-23 10:18 - 2013-12-04 19:06 - 00075992 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys

2013-12-23 10:18 - 2013-12-04 19:06 - 00000000 ____D C:\Users\zeeland\Desktop\mbar

2013-12-23 10:18 - 2013-11-28 10:07 - 00000000 ____D C:\TDSSKiller_Quarantine

2013-12-23 10:15 - 2013-12-23 10:15 - 04101441 _____ C:\Users\zeeland\Downloads\tdsskiller.zip

2013-12-23 10:15 - 2013-12-23 09:40 - 00000000 ____D C:\Users\zeeland\Desktop\hp

2013-12-23 09:39 - 2013-12-23 09:38 - 00000000 ____D C:\Qoobox

2013-12-23 09:37 - 2013-12-23 09:37 - 00000000 ____D C:\Windows\erdnt

2013-12-23 09:28 - 2013-12-04 19:06 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)

2013-12-22 11:15 - 2013-12-22 11:15 - 49940480 _____ C:\Program Files\GUT6049.tmp

2013-12-22 11:15 - 2013-12-22 11:15 - 00000000 ____D C:\Program Files\GUM6019.tmp

2013-12-22 11:14 - 2006-11-02 04:37 - 00000000 ____D C:\Windows\DigitalLocker

2013-12-19 13:29 - 2013-12-23 09:40 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\zeeland\Desktop\tdsskiller.exe

2013-12-16 18:23 - 2013-12-16 18:23 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\zeeland\Downloads\tdsskiller (1).exe

2013-12-11 12:07 - 2013-12-11 12:06 - 00017087 _____ C:\Users\zeeland\Desktop\Addition.txt

2013-12-11 12:06 - 2013-12-11 12:06 - 00000000 ____D C:\FRST

2013-12-04 19:05 - 2013-12-04 19:05 - 12576792 _____ (Malwarebytes Corp.) C:\Users\zeeland\Downloads\mbar- (1).exe

2013-12-04 19:05 - 2013-12-04 19:05 - 12576792 _____ (Malwarebytes Corp.) C:\Users\zeeland\Desktop\16m7bar.exe

2013-12-04 19:03 - 2013-12-04 19:03 - 00000000 ____D C:\Users\zeeland\Desktop\help

2013-12-04 18:16 - 2013-12-04 18:16 - 00000908 _____ C:\Users\Public\Desktop\may.lnk

2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\Users\zeeland\AppData\Roaming\Malwarebytes

2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\ProgramData\Malwarebytes

2013-12-04 18:16 - 2013-12-04 18:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware

2013-12-04 18:15 - 2013-12-04 18:15 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\zeeland\Downloads\mbam-setup-

2013-12-04 18:08 - 2013-12-04 18:08 - 00001917 _____ C:\Users\zeeland\Desktop\aswMBR.txt

2013-12-04 18:08 - 2013-11-28 17:02 - 00000512 _____ C:\Users\zeeland\Desktop\MBR.dat

2013-12-04 18:04 - 2013-12-04 18:04 - 00000104 _____ C:\Users\zeeland\Documents\Recycle Bin - Shortcut.lnk

2013-12-04 18:03 - 2013-11-29 15:00 - 00000000 ____D C:\Program Files\Microsoft Silverlight

2013-12-01 15:29 - 2013-12-01 15:29 - 00002384 _____ C:\Users\zeeland\Desktop\attach.txt

2013-12-01 15:28 - 2013-12-01 15:29 - 00010298 _____ C:\Users\zeeland\Desktop\dds.txt

2013-12-01 15:28 - 2013-12-01 15:28 - 00081276 _____ C:\Users\zeeland\Downloads\2.xps

2013-12-01 12:53 - 2013-12-01 12:53 - 00688992 ____R (Swearware) C:\Users\zeeland\Desktop\dds.com

2013-12-01 12:53 - 2013-12-01 12:53 - 00688992 _____ (Swearware) C:\Users\zeeland\Downloads\dds.scr

2013-12-01 12:32 - 2013-12-01 12:32 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131201_123229.log

2013-12-01 12:13 - 2013-12-01 12:13 - 00072192 _____ C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT

2013-12-01 12:13 - 2013-12-01 12:13 - 00000951 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk

2013-12-01 12:13 - 2013-12-01 12:13 - 00000946 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk

2013-12-01 12:13 - 2013-12-01 12:13 - 00000917 _____ C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk

2013-12-01 12:13 - 2013-12-01 12:13 - 00000020 ___SH C:\Users\Guest\ntuser.ini

2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest\AppData\Roaming\Snapfish

2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest\AppData\Local\VirtualStore

2013-12-01 12:13 - 2013-12-01 12:13 - 00000000 ____D C:\Users\Guest

2013-11-29 18:53 - 2013-11-29 18:53 - 17245644 _____ C:\Users\zeeland\Downloads\fiction.xps

2013-11-29 18:21 - 2013-11-29 18:21 - 00860176 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\mssstool32.exe

2013-11-29 18:17 - 2013-11-29 18:17 - 00511248 _____ (Microsoft Corporation) C:\Users\zeeland\Downloads\nis_full.exe

2013-11-29 18:06 - 2013-11-26 13:24 - 00000000 ___HD C:\TOOLWIZ

2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145639.log

2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145621.log

2013-11-29 14:56 - 2013-11-29 14:56 - 00000310 _____ C:\Users\zeeland\Downloads\RootkitRemover_20131129_145618.log

2013-11-29 14:46 - 2013-11-29 14:46 - 00000680 _____ C:\Users\zeeland\AppData\Local\d3d9caps.dat

2013-11-29 13:42 - 2013-11-29 13:42 - 01441838 _____ C:\Users\zeeland\Downloads\Daily Deal Millionaires.zip


==================== Bamital & volsnap Check =================


C:\Windows\explorer.exe => MD5 is legit

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



LastRegBack: 2013-12-29 18:27


==================== End Of Log ============================

Sorry about the double post I could not find how to delete it.


  Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-12-2013 01

Ran by zeeland at 2013-12-30 15:54:19
Running from C:\Users\zeeland\Desktop
Boot Mode: Normal
==================== Security Center ========================
AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
==================== Installed Programs ======================
Adobe Flash Player ActiveX (Version: - Adobe Systems Incorporated)
Adobe Reader 8.1.0 (Version: 8.1.0 - Adobe Systems Incorporated)
Ashampoo Burning Studio FREE v.1.12.0 (Version: 1.12.0 - Ashampoo GmbH & Co. KG)
AVG SafeGuard toolbar (Version: - AVG Technologies)
Cards_Calendar_OrderGift_DoMorePlugout (Version: 1.00.0000 - Hewlett-Packard)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000 - Microsoft Corporation)
CyberLink DVD Suite Deluxe (Version: 5.5.1126 - CyberLink Corp.)
Enhanced Multimedia Keyboard Solution (Version:  - Hewlett-Packard)
Google Chrome (Version: 31.0.1650.57 - Google Inc.)
Google Update Helper (Version: - Google Inc.)
Hardware Diagnostic Tools (Version: 5.1.4708.19 - PC-Doctor, Inc.)
Hewlett-Packard Active Check (Version: - Hewlett-Packard)
Hewlett-Packard Asset Agent for Health Check (Version: - HP)
HP Customer Experience Enhancements (Version: - Hewlett-Packard)
HP Customer Feedback (Version: 1.0.0 - Hewlett-Packard)
HP Demo (Version: 4.1.0 - Hewlett-Packard)
HP Easy Setup - Frontend (Version: - Hewlett-Packard)
HP On-Screen Cap/Num/Scroll Lock Indicator (Version:  - Hewlett-Packard)
HP Photosmart Essential 2.5 (Version: 1.02.0000 - Hewlett-Packard)
HP Photosmart Essential 2.5 (Version: 2.5 - HP)
HP Picasso Media Center Add-In (Version: 1.0.0 - HP)
HP Total Care Advisor (Version: - Hewlett-Packard)
HP Update (Version: - Hewlett-Packard)
HPPhotoSmartPhotobookWebPack1 (Version: 1.00.0000 - Hewlett-Packard)
Java SE Runtime Environment 6 Update 1 (Version: - Sun Microsystems, Inc.)
LabelPrint (Version: 2.2.2329 - CyberLink Corp.)
LightScribe System Software (Version: - http://www.lightscribe.com)
LightScribeTemplateLabeler (Version: - LightScribe)
Malwarebytes Anti-Malware version (Version: - Malwarebytes Corporation)
Microsoft .NET Framework 3.5 SP1 (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation)
Microsoft Office Home and Student 60 day trial (Version:  - )
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation)
Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation)
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Works (Version: 9.7.0621 - Microsoft Corporation)
muvee autoProducer 6.1 (Version: 6.10.050 - muvee Technologies)
My HP Games (Version: HPCMPQ1902 - WildTangent)
NVIDIA Drivers (Version:  - )
Power2Go (Version: 5.6.3610 - CyberLink Corp.)
PowerDirector (Version: 6.5.2420 - CyberLink Corp.)
PowerISO (Version: 5.8 - Power Software Ltd)
PSSWCORE (Version: 2.02.0000 - Hewlett-Packard)
Python 2.5 (Version: 2.5.150 - Martin v. Löwis)
Realtek High Definition Audio Driver (Version:  - )
Snapfish Picture Mover (Version: - HP Snapfish)
Soft Data Fax Modem with SmartCP (Version: 7.74.00 - Conexant Systems)
Toolwiz Care (Version: - ToolWiz Care)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation)
VideoToolkit01 (Version: - Hewlett-Packard)
WeatherBug Gadget (Version: - AWS Convergence Technologies)
Yahoo! Toolbar (Version:  - )
==================== Restore Points  =========================
26-11-2013 05:25:15 Scripted restore
26-11-2013 18:04:20 Windows Update
26-11-2013 21:24:42 Toolwiz Care(
26-11-2013 21:46:25 Windows Update
26-11-2013 21:51:10 Windows Update
26-11-2013 22:00:06 Windows Update
27-11-2013 15:30:51 Windows Update
28-11-2013 17:32:32 Windows Update
28-11-2013 17:41:50 Windows Update
29-11-2013 21:44:14 Windows Update
29-11-2013 22:57:36 Windows Update
29-11-2013 23:18:11 Windows Update
30-11-2013 02:15:41 Windows Update
30-11-2013 02:18:22 Windows Update
05-12-2013 01:52:34 Windows Update
05-12-2013 03:15:28 Windows Update
22-12-2013 17:33:43 Scheduled Checkpoint
22-12-2013 17:53:18 Malwarebytes Anti-Rootkit Restore Point
25-12-2013 23:26:40 Windows Update
26-12-2013 00:08:01 Windows Update
26-12-2013 00:30:22 Windows Update
26-12-2013 03:06:34 Windows Update
26-12-2013 04:38:36 Microsoft Antimalware Checkpoint
28-12-2013 22:16:28 Microsoft Antimalware Checkpoint
28-12-2013 22:21:18 Windows Update
29-12-2013 00:45:28 Windows Update
30-12-2013 01:57:21 Microsoft Antimalware Checkpoint
30-12-2013 02:00:44 Windows Update
30-12-2013 02:32:49 Windows Update
30-12-2013 23:50:42 Windows Update
==================== Hosts content: ==========================
2006-11-02 02:23 - 2006-09-18 13:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts       localhost
::1             localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {14BE614B-BFEE-4332-84E9-5577E2FF7E50} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-26] (Google Inc.)
Task: {1C4F2298-1498-4526-8383-4F6CB5437ED0} - System32\Tasks\ExtendedServicePlan => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-12-17] ()
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {29FBD9BE-9C1F-4EB9-8151-B9F090620079} - System32\Tasks\PC-Doctor\Scheduled Maintenance => C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe [2007-10-04] (PC-Doctor, Inc.)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3FE2FF18-EFF6-4249-8E42-C61ABC6F52BB} - System32\Tasks\ServicePlan => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-12-17] ()
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\WINDOWS\System32\RacAgent.exe [2008-01-20] (Microsoft Corporation)
Task: {5B1F54CC-7F50-4B7D-9C33-86B5E427E135} - System32\Tasks\PC-Doctor\Scheduled Maintenance Swap => C:\Program Files\PC-Doctor 5 for Windows\task_swap.bat [2008-02-27] ()
Task: {73F25119-D79E-4FEA-9265-72C3292D2848} - System32\Tasks\IntenetServiceOffers => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-12-17] ()
Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries
Task: {C2518D44-021D-40B8-B161-22170A16F23A} - System32\Tasks\ToolwizCareFree => C:\Program Files\ToolwizCareFree\ToolwizCares.exe [2013-11-26] (Toolwiz)
Task: {C2E45A30-41F1-45B2-9C0B-CB35B473A2A4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-11-26] (Google Inc.)
Task: {D58921BA-0D80-4346-99BA-796CEA5807DD} - System32\Tasks\RecoveryCD => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-12-17] ()
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\WINDOWS\System32\gatherWirelessInfo.vbs [2008-01-20] ()
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-11-26 10:02 - 2013-11-14 03:29 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-26 10:02 - 2013-11-14 03:29 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-26 10:02 - 2013-11-14 03:28 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\11654386.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\19343800.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\22475791.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\26363123.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\65533879.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\77338195.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\11654386.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\19343800.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\22475791.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\26363123.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\65533879.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\77338195.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
Error: (12/30/2013 03:48:44 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/29/2013 06:22:35 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/29/2013 05:57:55 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/29/2013 05:57:20 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005.
This is often caused by incorrect security settings in either the writer or requestor process.
   Gathering Writer Data
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {f79e8b95-1a32-4916-97e3-3fddcb104531}
Error: (12/28/2013 06:58:01 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/28/2013 04:31:37 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/28/2013 04:30:26 PM) (Source: ESENT) (User: )
Description: WinMail (2676) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
Error: (12/28/2013 03:28:09 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/28/2013 02:52:08 PM) (Source: ESENT) (User: )
Description: WinMail (2832) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.
Error: (12/28/2013 02:50:18 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
Error: (12/30/2013 03:54:32 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: 0x80070643Windows Internet Explorer 9 for Windows Vista{CE545479-357C-49F8-8DB9-D1434AC00075}101
Error: (12/30/2013 03:48:45 PM) (Source: Service Control Manager) (User: )
Description: 22475791
Error: (12/30/2013 03:48:45 PM) (Source: Service Control Manager) (User: )
Description: Parallel port driver%%1058
Error: (12/30/2013 03:48:09 PM) (Source: Microsoft Antimalware) (User: )
Description: %Trojan:DOS/Alureon.K60 has encountered a critical error when taking action on malware or other potentially unwanted software.
For more information please see the following:
Name: Trojan:DOS/Alureon.K
ID: 2147660148
Severity: %Trojan:DOS/Alureon.K600
Category: %Trojan:DOS/Alureon.K602
Path: 4.4.0304.02
Detection Origin: 4.4.0304.04
Detection Type: 4.4.0304.08
Detection Source: %Trojan:DOS/Alureon.K608
User: {43F5D604-D786-4B5B-A146-312CB8191FE4}9
Process Name: %Trojan:DOS/Alureon.K609
Action: {43F5D604-D786-4B5B-A146-312CB8191FE4}1
Action Status:  {43F5D604-D786-4B5B-A146-312CB8191FE4}8
Error Code: {43F5D604-D786-4B5B-A146-312CB8191FE4}3
Error description: {43F5D604-D786-4B5B-A146-312CB8191FE4}4
Signature Version: 2013-12-30T23:47:31.298Z1
Engine Version: 2013-12-30T23:47:31.298Z2
Error: (12/29/2013 06:34:01 PM) (Source: Microsoft-Windows-Servicing) (User: NT AUTHORITY)
Description: Windows Servicing failed to complete the process of changing update Aux from package WindowsUpdateClient-SelfUpdate-Aux-AuxComp-Package_en-US(Language Pack) into Staged(Staged) state
Error: (12/29/2013 06:34:01 PM) (Source: Microsoft-Windows-Servicing) (User: NT AUTHORITY)
Description: Windows Servicing failed to complete the process of setting package WindowsUpdateClient-SelfUpdate-Aux-AuxComp-Package_en-US (Language Pack) into Install Requested(Install Requested) state
Error: (12/29/2013 06:34:01 PM) (Source: Microsoft-Windows-Servicing) (User: NT AUTHORITY)
Description: Windows Servicing failed to complete the process of changing update AuxResourcesLP from package WindowsUpdateClient-SelfUpdate-Aux-Package(Language Pack) into Staged(Staged) state
Error: (12/29/2013 06:34:01 PM) (Source: Microsoft-Windows-Servicing) (User: NT AUTHORITY)
Description: Windows Servicing failed to complete the process of setting package WindowsUpdateClient-SelfUpdate-Aux-Package (Language Pack) into Install Requested(Install Requested) state
Error: (12/29/2013 06:34:01 PM) (Source: Microsoft-Windows-Servicing) (User: NT AUTHORITY)
Description: Windows Servicing failed to complete the process of changing update WUClient-SelfUpdate-Aux-en-us-LP from package WUClient-SelfUpdate-Aux-Package-en-us-MiniLP(Feature Pack) into Staged(Staged) state
Error: (12/29/2013 06:34:01 PM) (Source: Microsoft-Windows-Servicing) (User: NT AUTHORITY)
Description: Windows Servicing failed to complete the process of setting package WUClient-SelfUpdate-Aux-Package-en-us-MiniLP (Feature Pack) into Install Requested(Install Requested) state
Microsoft Office Sessions:
Error: (12/30/2013 03:48:44 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/29/2013 06:22:35 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/29/2013 05:57:55 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/29/2013 05:57:20 PM) (Source: VSS)(User: )
Description: 0x80070005
   Gathering Writer Data
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {f79e8b95-1a32-4916-97e3-3fddcb104531}
Error: (12/28/2013 06:58:01 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/28/2013 04:31:37 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/28/2013 04:30:26 PM) (Source: ESENT)(User: )
Description: WinMail2676WindowsMail0:
Error: (12/28/2013 03:28:09 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/28/2013 02:52:08 PM) (Source: ESENT)(User: )
Description: WinMail2832WindowsMail0:
Error: (12/28/2013 02:50:18 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
CodeIntegrity Errors:
  Date: 2013-12-30 15:54:09.571
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-30 15:54:09.454
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-30 15:54:09.345
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-30 15:54:09.233
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-30 15:54:09.107
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-30 15:54:08.987
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-30 15:54:08.870
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-30 15:54:08.730
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-29 18:38:33.867
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
  Date: 2013-12-29 18:38:33.762
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\WINDOWS\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info =========================== 
Percentage of memory in use: 43%
Total physical RAM: 3453.64 MB
Available physical RAM: 1954.07 MB
Total Pagefile: 7097.7 MB
Available Pagefile: 5667.79 MB
Total Virtual: 2047.88 MB
Available Virtual: 1940.84 MB
==================== Drives ================================
Drive c: (HP) (Fixed) (Total:456.43 GB) (Free:382.11 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (FACTORY_IMAGE) (Fixed) (Total:9.33 GB) (Free:1.27 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive e: (WTLIB10E) (CDROM) (Total:0.39 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
Disk: 0 (Size: 466 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=456 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=2544 KB) - (Type=17) ATTENTION ===> Suspicious partition bootkit on partition 2
Partition 3: (Not Active) - (Size=9 GB) - (Type=07 NTFS)
==================== End Of Log ============================
It is okay, you couldn't delete it.

Open Notepad (Start => All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open Notepad and select Paste). Save it on the flashdrive as fixlist.txt

Partition 2: (Not Active) - (Size=2544 KB) - (Type=17) ATTENTION ===> Suspicious partition bootkit on partition 2

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options then select Command Prompt

Run FRST (or FRST64 if you have the 64bit version) and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Reboot Normally.

Share on other sites

