Jump to content

Recommended Posts

Hello,

 

I've recently been experiencing problems with Chrome / other applications sometimes taking a long time to load pages and sometimes sort of freeze up. I've also been seeing that my RAM / CPU usage is a bit higher than normal. At the current moment I'm at 72% RAM usage yet I only have a few tabs / programs open.

 

I've PMed AdvancedSetup seeing as DDS isn't compatible with 8.1. I used the FRST tool, as he said, to produce the following logs.

 

FRST.txt:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-03-2014 03
Ran by Matthew01_2 (administrator) on MATTHEW-DESKTOP on 02-03-2014 20:21:43
Running from C:\Users\Matthew01_2\Desktop
Windows 8.1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link for 32-Bit version:
Download link for 64-Bit Version:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Binary Fortress Software) A:\DisplayFusion\DisplayFusionService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Samsung Electronics Co., Ltd.) C:\Windows\system32\RAPID\SamsungRapidSvc.exe
(www.shadowexplorer.com) C:\Program Files (x86)\ShadowExplorer\sesvc.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe
(Flux Software LLC) C:\Users\Matthew01_2\AppData\Local\FluxSoftware\Flux\flux.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe
(http://shotty.devs-on.net) A:\Shotty\Shotty.exe
(Binary Fortress Software) A:\DisplayFusion\DisplayFusion.exe
() C:\Program Files (x86)\WhatPulse2\whatpulse.exe
(Binary Fortress Software) A:\DisplayFusion\DisplayFusionHookAppWIN6032.exe
(Dominik Reichl) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET 4.0\EMET_Agent.exe
(Skype Technologies S.A.) C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.exe
(Binary Fortress Software) A:\DisplayFusion\DisplayFusionHookAppWIN6064.exe
(Valve Corporation) A:\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(www.startisback.com) C:\Program Files (x86)\StartIsBack\StartScreen.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files (x86)\Java\jre7\bin\javaw.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
HKLM\...\Run: [samsungRapidApp] - C:\Program Files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe [109280 2013-07-29] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [startCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Everything] - "A:\Everything\Everything.exe" -startup
HKLM-x32\...\Run: [EMET Agent] - C:\Program Files (x86)\EMET 4.0\EMET_agent.exe [78496 2013-06-14] (Microsoft Corporation)
HKLM-x32\...\Run: [KeePass 2 PreLoad] - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2092032 2014-02-03] (Dominik Reichl)
HKU\.DEFAULT\...\Policies\system: [DisableChangePassword] 0
HKU\.DEFAULT\...\Policies\system: [DisableLockWorkstation] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [f.lux] - C:\Users\Matthew01_2\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [Gyazo] - C:\Program Files (x86)\Gyazo\GyStation.exe [2990304 2013-10-30] (Nota Inc.)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [WhatPulse] - C:\Program Files (x86)\WhatPulse2\whatpulse.exe [3126272 2013-12-11] ()
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [shotty] - A:\Shotty\Shotty.exe [724480 2013-12-29] (http://shotty.devs-on.net)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [DisplayFusion] - A:\DisplayFusion\DisplayFusion.exe [7952224 2013-11-27] (Binary Fortress Software)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [sandboxieControl] - C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2013-10-16] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [VoxOx] - A:\VoxOx\VoxOx.exe -b
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [KeePass Password Safe 2] - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2092032 2014-02-03] (Dominik Reichl)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\MountPoints2: {e6db129c-63ad-11e3-82a8-806e6f6e6963} - "D:\Install Navigator.exe" 
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.exe (Dxtory Software)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mbam.exe (Malwarebytes Corporation)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Omnimo.lnk
ShortcutTarget: Omnimo.lnk -> C:\Users\Matthew01_2\Documents\Rainmeter\Skins\WP7\@Resources\Common\Settings\Omnimo.exe ()
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerMenu.lnk
ShortcutTarget: PowerMenu.lnk -> C:\Program Files (x86)\PowerMenu\PowerMenu.exe (Thong Nguyen)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShiftWindow.exe - Shortcut.lnk
ShortcutTarget: ShiftWindow.exe - Shortcut.lnk -> A:\ShiftWindow\ShiftWindow.exe ()
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.exe (Skype Technologies S.A.)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Steam.lnk
ShortcutTarget: Steam.lnk -> A:\Steam\Steam.exe (Valve Corporation)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thunderbird.lnk
ShortcutTarget: Thunderbird.lnk -> C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
SSODL-x32: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - A:\IconPackager\iprepair.dll No File
 
==================== Internet (Whitelisted) ====================
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x16E04B237615CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US,en;q=0.5
BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {43D9786F-A485-683B-9B5B-ACC97ABC17FC} -  No File
BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: WSIEChrome - {6D02ED5F-FD0D-4C4C -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: WSIEChrome - {6D02ED5F-FD0D-4C4C -  No File
Hosts: 127.0.0.1            rad.msn.com
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF ProfilePath: C:\Users\Matthew01_2\AppData\Roaming\Mozilla\Firefox\Profiles\fn0utjks.default
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @wolfram.com/Mathematica - C:\Program Files (x86)\Common Files\Wolfram Research\Browser\9.0.1.4092550\npmathplugin.dll (Wolfram Research, Inc.)
FF Plugin-x32: adobe.com/AdobeExManDetect - A:\Dreamweaver\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Matthew01_2\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: Interfaces Downloader - C:\Users\Matthew01_2\AppData\Roaming\Mozilla\Firefox\Profiles\fn0utjks.default\Extensions\interfacesdownloader@tailgate.googlecode.com.xpi [2014-01-18]
FF Extension: Lightbeam - C:\Users\Matthew01_2\AppData\Roaming\Mozilla\Firefox\Profiles\fn0utjks.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2014-01-29]
FF Extension: unedditredditAddon - C:\Users\Matthew01_2\AppData\Roaming\Mozilla\Firefox\Profiles\fn0utjks.default\Extensions\unedditreddit@unedditreddit.com.xpi [2013-12-30]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-11-13]
FF HKLM-x32\...\Firefox\Extensions: [Player@Wondershare.com] - C:\ProgramData\Wondershare\Player\Player@Wondershare.com\
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-11-13]
FF StartMenuInternet: FIREFOX.EXE - A:\Firefox\firefox.exe
 
Chrome: 
=======
 
CHR Extension: (Duolingo) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2013-11-02]
CHR Extension: (BetterTTV) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2013-10-29]
CHR Extension: (Google Docs) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-29]
CHR Extension: (Google Drive) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-29]
CHR Extension: (YouTube Center Developer Build) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcegdpionpopahcglnfiiioapcclamdj [2014-01-19]
CHR Extension: (YouTube Options) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn [2013-10-29]
CHR Extension: (YouTube) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-29]
CHR Extension: (Adblock Plus) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-10-29]
CHR Extension: (Google Search) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-29]
CHR Extension: (Pandora Listener) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\danjmbbdjabpapehlajpomcignjnoidp [2013-11-17]
CHR Extension: (SoundControl - free for Pandora) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dckjilenognecmpjjpeckgekikdpchli [2013-11-17]
CHR Extension: (Tampermonkey) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-10-29]
CHR Extension: (Search All) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\eekjldapjblgadclklmgolijbagmdnfk [2014-02-01]
CHR Extension: (Untamed Now Playing) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\elmdghkkehlmfllejpgikgpjgfalppei [2013-12-30]
CHR Extension: (Pandora) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl [2013-11-17]
CHR Extension: (Twitch Stream) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjaicoojlfoococemdcaollmhaiolole [2014-01-19]
CHR Extension: (Stylish) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2013-12-15]
CHR Extension: (Wolfram|Alpha (Official)) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp [2014-01-30]
CHR Extension: (New Tab Redirect!) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna [2013-11-21]
CHR Extension: (Twitch Stream) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce [2014-01-19]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2013-12-25]
CHR Extension: (Youtube Subscriptions as Default Page) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\klljlfcipmgohgfdgmliaobikgdoeaah [2013-10-29]
CHR Extension: (Auto HD For YouTubeâ„¢) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2013-10-29]
CHR Extension: (Ghostery) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2014-01-19]
CHR Extension: (Google Wallet) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-29]
CHR Extension: (Enhanced Steam) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-02-28]
CHR Extension: (Gmail) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-29]
CHR Extension: (Twitch Giveaways) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\poohjpljfecljomfhhimjhddddlidhdd [2013-12-26]
 
==================== Services (Whitelisted) =================
 
R2 DisplayFusionService; A:\DisplayFusion\DisplayFusionService.exe [1375600 2013-11-27] (Binary Fortress Software)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-02-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-02-21] (Malwarebytes Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2014-02-16] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc.)
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [27360 2013-07-29] (Samsung Electronics Co., Ltd.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC)
R2 sesvc; C:\Program Files (x86)\ShadowExplorer\sesvc.exe [9216 2013-01-02] (www.shadowexplorer.com)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-22] (Advanced Micro Devices, Inc.)
R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Windows ® Win 7 DDK provider)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfw; C:\Windows\system32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2013-12-16] (REALiX)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-09] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-10] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-02-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-03-02] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-02-21] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc.)
S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] ()
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [240864 2013-07-29] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111328 2013-07-29] (Samsung Electronics Co., Ltd.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-25] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [113936 2013-11-01] (Oracle Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 VIAHdAudAddService; \SystemRoot\system32\drivers\viahduaa.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2014-03-02 20:21 - 2014-03-02 20:21 - 00023710 _____ () C:\Users\Matthew01_2\Desktop\FRST.txt
2014-03-02 20:21 - 2014-03-02 20:21 - 00000000 ____D () C:\FRST
2014-03-02 20:21 - 2014-03-02 20:20 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Desktop\FRST64.exe
2014-03-02 20:20 - 2014-03-02 20:20 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Downloads\FRST64.exe
2014-03-02 16:59 - 2014-03-02 16:59 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds (1).scr
2014-03-02 16:56 - 2014-03-02 16:56 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds.scr
2014-03-02 16:56 - 2014-03-02 16:56 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds.com
2014-03-02 16:30 - 2014-03-02 16:31 - 83329736 _____ () C:\Users\Matthew01_2\Downloads\iconpackager_public.exe
2014-03-02 16:29 - 2014-03-02 16:29 - 00623206 _____ () C:\Users\Matthew01_2\Downloads\TokenDark___icons_by_brsev___by_naymlezwun.rar
2014-03-02 12:46 - 2014-03-02 12:46 - 00001050 _____ () C:\Users\Matthew01_2\Desktop\Scan 3-2 - 12 PM.txt
2014-03-02 12:45 - 2014-03-02 12:45 - 00001051 _____ () C:\Users\Matthew01_2\Desktop\Scan 3-2 - 12 AM.txt
2014-03-02 05:03 - 2014-03-02 05:03 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-02 05:03 - 2014-03-02 05:03 - 00000000 _____ () C:\Windows\setupact.log
2014-03-02 00:06 - 2014-03-02 00:06 - 00186318 _____ () C:\Users\Matthew01_2\Downloads\notes_by_easy_art-d33ki08.rmskin
2014-03-02 00:05 - 2014-03-02 00:05 - 01470335 _____ () C:\Users\Matthew01_2\Downloads\notes_plus_for_rainmeter_by_charliedogfhhfd-d4fiba3.rmskin
2014-03-02 00:03 - 2014-03-02 00:03 - 00850168 _____ () C:\Users\Matthew01_2\Downloads\muji_tasknote_by_activecolors-d6bf31b.rmskin
2014-03-02 00:02 - 2014-03-02 00:02 - 00563264 _____ () C:\Users\Matthew01_2\Downloads\scrolltext2_for_rm_by_eclectic_tech-d6oqvnq.rmskin
2014-03-02 00:01 - 2014-03-02 00:01 - 00328414 _____ () C:\Users\Matthew01_2\Downloads\blackboardteach_by_amadis33-d5f9m8n.rmskin
2014-03-01 23:59 - 2014-03-01 23:59 - 00108764 _____ () C:\Users\Matthew01_2\Downloads\note_paper_1_1_by_sa3er-d6hmlfd.rmskin
2014-03-01 23:47 - 2014-03-02 20:10 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-01 23:47 - 2014-03-01 23:47 - 16555688 _____ (Malwarebytes Corporation ) C:\Users\Matthew01_2\Downloads\mbam-setup-2.0.0.504.exe
2014-03-01 23:47 - 2014-03-01 23:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-01 23:47 - 2014-02-21 14:55 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-01 22:04 - 2014-03-01 22:04 - 00092052 _____ () C:\Users\Matthew01_2\Downloads\Pandora_Player.rar
2014-03-01 18:42 - 2014-03-01 23:27 - 00000000 ____D () C:\Program Files (x86)\PowerMenu
2014-03-01 18:42 - 2014-03-01 18:42 - 00112582 _____ () C:\Users\Matthew01_2\Downloads\PowerMenuSetup_1_5_1.exe
2014-03-01 16:39 - 2014-03-01 16:39 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Facepalm Games
2014-03-01 16:22 - 2014-03-01 16:22 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\BridgeProject
2014-02-28 15:59 - 2014-02-28 15:59 - 00129837 _____ () C:\Users\Matthew01_2\Downloads\wildlifepark3_windows_1388183454.zip.torrent
2014-02-27 22:10 - 2014-02-27 22:14 - 216141824 _____ () C:\Users\Matthew01_2\Downloads\LibreOffice_4.1.5_Win_x86.msi
2014-02-27 20:00 - 2014-02-27 20:00 - 00679696 _____ (Shark Labs) C:\Users\Matthew01_2\Downloads\CFSetup350.exe
2014-02-23 17:59 - 2014-02-23 17:59 - 00843976 _____ () C:\Users\Matthew01_2\Downloads\Chatty_0.6.zip
2014-02-22 22:29 - 2014-02-22 22:29 - 01054064 _____ (Amazon Services LLC) C:\Users\Matthew01_2\Downloads\Guns_of_Icarus_Online_Online_Game_Code_Downloader.exe
2014-02-22 17:04 - 2014-02-22 17:04 - 00190686 _____ () C:\Users\Matthew01_2\Downloads\mailbox_alert-0.16.4-sm+tb.xpi
2014-02-21 20:02 - 2014-02-21 20:02 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\SWTOR
2014-02-21 14:30 - 2014-03-02 16:55 - 01759130 _____ () C:\Windows\WindowsUpdate.log
2014-02-20 21:46 - 2014-02-20 21:46 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-02-20 21:46 - 2014-02-20 21:46 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\SWTORPerf
2014-02-20 21:39 - 2014-02-20 21:40 - 00015678 _____ () C:\Users\Matthew01_2\Documents\Install STAR WARS The Old Republic.log
2014-02-20 16:21 - 2014-02-20 16:22 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Guacamelee
2014-02-19 14:56 - 2014-02-19 14:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Unity
2014-02-19 14:52 - 2014-02-19 14:52 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Unity
2014-02-18 23:00 - 2014-02-18 23:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\be.gip.twitch.chat.TwitchChatOAuth
2014-02-18 23:00 - 2014-02-18 23:00 - 00000000 ____D () C:\Program Files (x86)\Air
2014-02-18 22:51 - 2014-02-23 17:45 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\HexChat
2014-02-16 18:57 - 2014-02-16 18:57 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\onOne Software
2014-02-16 10:56 - 2014-02-16 10:56 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Battlefield 3
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\PunkBuster
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\ESN
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-02-16 10:55 - 2014-02-16 10:55 - 00000000 ____D () C:\ProgramData\EA Core
2014-02-16 03:58 - 2014-02-16 10:56 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-02-16 03:58 - 2014-02-16 03:58 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-02-16 03:58 - 2014-02-16 03:58 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-02-16 03:35 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2014-02-15 23:15 - 2014-02-15 23:15 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3
2014-02-15 23:15 - 2014-02-15 23:15 - 00000000 ____D () C:\Users\Matthew01_2\.idlerc
2014-02-15 23:14 - 2014-02-15 23:15 - 00000000 ____D () C:\Python33
2014-02-15 22:35 - 2014-02-18 16:48 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\.purple
2014-02-15 22:22 - 2014-02-15 22:33 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\mIRC
2014-02-15 20:52 - 2014-02-15 20:52 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-02-15 17:59 - 2014-02-15 18:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\TeraCopy
2014-02-15 17:59 - 2014-02-15 17:59 - 00000000 ____D () C:\Program Files\TeraCopy
2014-02-15 17:36 - 2014-02-15 17:36 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Evernote
2014-02-15 16:42 - 2014-02-15 16:49 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Dexpot
2014-02-15 16:41 - 2014-02-15 16:41 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\qBittorrent
2014-02-15 16:40 - 2014-02-28 16:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\qBittorrent
2014-02-15 14:19 - 2014-02-16 10:54 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Origin
2014-02-15 14:19 - 2014-02-16 00:13 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Origin
2014-02-15 14:18 - 2014-02-15 14:18 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-02-14 22:02 - 2014-01-07 17:46 - 00325464 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2014-02-14 22:02 - 2014-01-07 17:41 - 01530712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-02-14 22:02 - 2014-01-07 17:41 - 00382808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-02-14 22:02 - 2014-01-04 07:54 - 00138240 _____ () C:\Windows\system32\OEMLicense.dll
2014-02-14 22:02 - 2014-01-04 07:08 - 00103936 _____ () C:\Windows\SysWOW64\OEMLicense.dll
2014-02-14 22:02 - 2014-01-04 06:08 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2014-02-14 22:02 - 2014-01-04 05:53 - 00174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2014-02-14 22:02 - 2014-01-02 15:54 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-02-14 22:02 - 2014-01-02 15:48 - 00336896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-02-14 22:02 - 2014-01-02 15:40 - 05770752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-14 22:02 - 2014-01-02 15:38 - 06640640 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-14 22:02 - 2013-12-31 17:55 - 01720560 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-02-14 22:02 - 2013-12-31 17:52 - 00481944 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2014-02-14 22:02 - 2013-12-31 16:56 - 01472048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-02-14 22:02 - 2013-12-31 16:55 - 00381168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2014-02-14 22:02 - 2013-12-31 15:59 - 00802816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2014-02-14 22:02 - 2013-12-31 15:57 - 01214976 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-02-14 22:02 - 2013-12-31 15:56 - 00960512 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2014-02-14 22:02 - 2013-12-30 15:34 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sti.dll
2014-02-14 22:02 - 2013-12-30 15:33 - 00770560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2014-02-14 22:02 - 2013-12-30 15:32 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\sti.dll
2014-02-14 22:02 - 2013-12-30 15:31 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2014-02-14 22:02 - 2013-12-30 15:31 - 00914944 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-02-14 22:02 - 2013-12-27 07:09 - 00419160 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-02-14 22:02 - 2013-12-27 02:38 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-14 22:02 - 2013-12-27 00:57 - 00842752 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll
2014-02-14 22:02 - 2013-12-27 00:57 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2014-02-14 22:02 - 2013-12-27 00:23 - 00749056 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2014-02-14 22:02 - 2013-12-27 00:16 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-14 22:02 - 2013-12-26 23:03 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll
2014-02-14 22:02 - 2013-12-26 23:03 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2014-02-14 22:02 - 2013-12-26 22:37 - 00588800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2014-02-14 22:02 - 2013-12-20 23:21 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2014-02-14 22:02 - 2013-12-16 23:21 - 00408576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2014-02-14 22:02 - 2013-12-13 22:31 - 13949440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2014-02-14 22:02 - 2013-12-13 22:19 - 18576384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2014-02-14 22:02 - 2013-12-13 02:54 - 00131160 _____ (Microsoft Corporation) C:\Windows\system32\easinvoker.exe
2014-02-14 22:02 - 2013-12-12 23:24 - 00121088 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2014-02-14 22:02 - 2013-12-12 22:36 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
2014-02-14 22:02 - 2013-12-12 21:32 - 00140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
2014-02-14 22:02 - 2013-12-09 00:05 - 21199256 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-02-14 22:02 - 2013-12-08 20:51 - 18643560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-02-14 22:02 - 2013-12-08 19:25 - 04190720 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-02-14 13:08 - 2014-02-14 13:08 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\PDAppFlex
2014-02-12 15:00 - 2014-02-14 13:11 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-02-12 15:00 - 2014-02-12 15:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Opera Software
2014-02-12 15:00 - 2014-02-12 15:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Opera Software
2014-02-11 14:34 - 2014-02-06 04:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-11 14:34 - 2014-02-06 03:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-11 14:34 - 2014-02-06 03:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-11 14:34 - 2014-02-06 03:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-11 14:34 - 2014-02-06 03:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-11 14:34 - 2014-02-06 03:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-11 14:34 - 2014-02-06 02:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-11 14:34 - 2014-02-06 02:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-11 14:34 - 2014-02-06 02:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-11 14:34 - 2014-02-06 02:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-11 14:34 - 2014-02-06 02:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-11 14:34 - 2014-02-06 02:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-11 14:34 - 2014-02-06 02:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-11 14:34 - 2014-02-06 02:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-11 14:34 - 2014-02-06 02:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-11 14:34 - 2014-02-06 02:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-11 14:34 - 2014-02-06 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-11 14:34 - 2014-02-06 02:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-11 14:34 - 2014-02-06 01:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-11 14:34 - 2014-02-06 01:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-11 14:34 - 2014-02-06 01:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-11 14:34 - 2014-02-06 01:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-11 14:34 - 2014-02-06 01:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-11 14:34 - 2014-02-06 01:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-11 14:34 - 2014-02-06 01:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-11 14:34 - 2014-02-06 01:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-11 14:34 - 2014-02-06 01:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-11 14:34 - 2014-02-06 01:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-11 14:34 - 2014-02-06 01:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-11 14:34 - 2014-02-06 01:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-11 14:34 - 2014-02-06 01:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-11 14:34 - 2014-02-06 01:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-11 14:34 - 2014-02-06 00:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-11 14:34 - 2014-02-06 00:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-11 14:34 - 2014-02-06 00:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-11 14:34 - 2014-02-06 00:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-11 14:34 - 2014-02-06 00:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-11 14:33 - 2014-01-06 21:00 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-11 14:33 - 2014-01-06 20:30 - 02071552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-11 14:33 - 2013-12-08 16:27 - 02152448 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-11 14:33 - 2013-12-08 16:19 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-11 14:33 - 2013-12-08 15:55 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-11 14:33 - 2013-12-08 15:54 - 01317376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-11 14:33 - 2013-11-20 22:42 - 04604416 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-11 14:33 - 2013-11-20 21:44 - 03936256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-11 14:28 - 2014-01-04 06:30 - 13209088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-02-11 14:28 - 2014-01-04 06:23 - 11702272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-02-11 14:28 - 2014-01-04 05:40 - 07416832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2014-02-11 14:27 - 2014-01-09 00:25 - 02804224 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-02-11 14:27 - 2014-01-08 23:59 - 01020928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-02-11 14:27 - 2014-01-08 23:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll
2014-02-11 14:27 - 2014-01-08 23:49 - 00919040 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-02-11 14:27 - 2014-01-08 23:44 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-02-11 14:27 - 2014-01-08 23:43 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll
2014-02-11 14:27 - 2014-01-08 23:29 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll
2014-02-11 14:27 - 2014-01-08 23:28 - 04217344 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-02-11 14:27 - 2014-01-08 23:28 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2014-02-11 14:27 - 2014-01-08 23:18 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
2014-02-11 14:27 - 2014-01-06 23:03 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe
2014-02-11 14:27 - 2014-01-06 21:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe
2014-02-11 14:27 - 2014-01-04 12:50 - 01462216 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-02-11 14:27 - 2014-01-04 11:22 - 01202888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-02-11 14:27 - 2014-01-04 05:42 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-02-11 14:27 - 2014-01-04 05:36 - 00830976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-02-11 14:27 - 2014-01-04 05:28 - 04961792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2014-02-11 14:27 - 2013-12-20 18:10 - 00009701 _____ () C:\Windows\SysWOW64\connectedsearch-results.searchconnector-ms
2014-02-11 14:27 - 2013-12-20 18:10 - 00009701 _____ () C:\Windows\system32\connectedsearch-results.searchconnector-ms
2014-02-11 14:27 - 2013-12-20 02:10 - 01113040 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-02-11 14:27 - 2013-12-19 22:13 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-02-11 14:27 - 2013-12-08 18:57 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-11 14:27 - 2013-12-08 17:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-08 23:55 - 2014-02-08 23:58 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\AcePatrol2
2014-02-08 23:55 - 2014-02-08 23:55 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00122904 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00109080 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2014-02-06 13:45 - 2014-02-06 13:46 - 00000000 ____D () C:\Steam
2014-02-05 14:40 - 2014-02-05 14:58 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Sites
2014-02-05 14:37 - 2014-02-05 14:37 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-02-05 14:24 - 2014-02-05 14:24 - 00000000 ____D () C:\Windows\XSxS
2014-02-04 19:38 - 2014-02-04 19:38 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\www.shadowexplorer.com
2014-02-04 19:38 - 2014-02-04 19:38 - 00000000 ____D () C:\Program Files (x86)\ShadowExplorer
2014-02-04 18:01 - 2014-02-05 13:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-02-03 21:14 - 2014-02-03 21:14 - 00000577 _____ () C:\Users\Guest\Desktop\Juice.lnk
2014-02-03 21:14 - 2014-02-03 21:14 - 00000000 ____D () C:\Users\Matthew01_2\Documents\My Received Podcasts
2014-02-03 21:14 - 2014-02-03 21:14 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Workrave
2014-02-03 21:14 - 2014-02-03 21:14 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\iPodder
2014-02-03 21:13 - 2014-02-03 21:13 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\foobar2000
2014-02-02 11:05 - 2014-02-02 11:05 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Apple Computer
2014-02-01 19:01 - 2014-02-01 19:01 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Apple
2014-02-01 19:01 - 2014-02-01 19:01 - 00000000 ____D () C:\ProgramData\Apple
2014-02-01 18:50 - 2014-02-01 19:07 - 00000000 ____D () C:\Program Files\Lightworks
2014-02-01 18:50 - 2014-02-01 18:52 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2014-02-01 18:45 - 2014-02-01 18:46 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\avidemux
2014-02-01 18:18 - 2014-02-01 18:18 - 00715038 _____ () C:\Windows\unins000.exe
2014-02-01 11:44 - 2014-02-01 11:44 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\WinRAR
2014-02-01 11:44 - 2014-02-01 11:44 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-02-01 11:44 - 2014-02-01 11:44 - 00000000 ____D () C:\Program Files\WinRAR
2014-01-31 21:46 - 2014-02-03 17:44 - 00000000 ____D () C:\Program Files (x86)\KeePass Password Safe 2
2014-01-31 20:45 - 2014-01-31 20:45 - 00000000 ____D () C:\Program Files (x86)\Dashlane
 
==================== One Month Modified Files and Folders =======
 
2014-03-02 20:22 - 2013-12-21 14:39 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\WhatPulse
2014-03-02 20:21 - 2014-03-02 20:21 - 00023710 _____ () C:\Users\Matthew01_2\Desktop\FRST.txt
2014-03-02 20:21 - 2014-03-02 20:21 - 00000000 ____D () C:\FRST
2014-03-02 20:20 - 2014-03-02 20:21 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Desktop\FRST64.exe
2014-03-02 20:20 - 2014-03-02 20:20 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Downloads\FRST64.exe
2014-03-02 20:19 - 2013-10-29 14:04 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Skype
2014-03-02 20:18 - 2014-01-11 18:17 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\DisplayFusion
2014-03-02 20:13 - 2013-11-07 14:21 - 00003978 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{2B960C1B-1F4E-471A-81FD-7E523F049F77}
2014-03-02 20:10 - 2014-03-01 23:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-02 20:06 - 2013-12-30 22:48 - 00000063 _____ () C:\Users\Matthew01_2\Documents\unp_now_playing.txt
2014-03-02 20:00 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\system32\sru
2014-03-02 19:48 - 2013-10-29 14:04 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1086244806-2233730069-3771371249-1004
2014-03-02 19:43 - 2013-11-26 14:12 - 00000938 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1ceeaf4957a29c8.job
2014-03-02 19:43 - 2013-11-26 14:12 - 00000934 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1ceeaf4955c36c4.job
2014-03-02 16:59 - 2014-03-02 16:59 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds (1).scr
2014-03-02 16:56 - 2014-03-02 16:56 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds.scr
2014-03-02 16:56 - 2014-03-02 16:56 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds.com
2014-03-02 16:55 - 2014-02-21 14:30 - 01759130 _____ () C:\Windows\WindowsUpdate.log
2014-03-02 16:31 - 2014-03-02 16:30 - 83329736 _____ () C:\Users\Matthew01_2\Downloads\iconpackager_public.exe
2014-03-02 16:29 - 2014-03-02 16:29 - 00623206 _____ () C:\Users\Matthew01_2\Downloads\TokenDark___icons_by_brsev___by_naymlezwun.rar
2014-03-02 14:02 - 2013-12-26 21:01 - 00000000 ____D () C:\Users\Matthew01_2\.chatty
2014-03-02 12:46 - 2014-03-02 12:46 - 00001050 _____ () C:\Users\Matthew01_2\Desktop\Scan 3-2 - 12 PM.txt
2014-03-02 12:45 - 2014-03-02 12:45 - 00001051 _____ () C:\Users\Matthew01_2\Desktop\Scan 3-2 - 12 AM.txt
2014-03-02 05:35 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-03-02 05:03 - 2014-03-02 05:03 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-02 05:03 - 2014-03-02 05:03 - 00000000 _____ () C:\Windows\setupact.log
2014-03-02 00:33 - 2014-01-28 17:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\CrashDumps
2014-03-02 00:06 - 2014-03-02 00:06 - 00186318 _____ () C:\Users\Matthew01_2\Downloads\notes_by_easy_art-d33ki08.rmskin
2014-03-02 00:05 - 2014-03-02 00:05 - 01470335 _____ () C:\Users\Matthew01_2\Downloads\notes_plus_for_rainmeter_by_charliedogfhhfd-d4fiba3.rmskin
2014-03-02 00:03 - 2014-03-02 00:03 - 00850168 _____ () C:\Users\Matthew01_2\Downloads\muji_tasknote_by_activecolors-d6bf31b.rmskin
2014-03-02 00:02 - 2014-03-02 00:02 - 00563264 _____ () C:\Users\Matthew01_2\Downloads\scrolltext2_for_rm_by_eclectic_tech-d6oqvnq.rmskin
2014-03-02 00:02 - 2013-10-29 14:07 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Rainmeter
2014-03-02 00:01 - 2014-03-02 00:01 - 00328414 _____ () C:\Users\Matthew01_2\Downloads\blackboardteach_by_amadis33-d5f9m8n.rmskin
2014-03-01 23:59 - 2014-03-01 23:59 - 00108764 _____ () C:\Users\Matthew01_2\Downloads\note_paper_1_1_by_sa3er-d6hmlfd.rmskin
2014-03-01 23:56 - 2013-10-29 14:52 - 00000000 ____D () C:\Users\Matthew01_2\Desktop\All Files
2014-03-01 23:47 - 2014-03-01 23:47 - 16555688 _____ (Malwarebytes Corporation ) C:\Users\Matthew01_2\Downloads\mbam-setup-2.0.0.504.exe
2014-03-01 23:47 - 2014-03-01 23:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-01 23:47 - 2013-11-08 22:05 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Malwarebytes
2014-03-01 23:47 - 2013-10-19 12:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-01 23:27 - 2014-03-01 18:42 - 00000000 ____D () C:\Program Files (x86)\PowerMenu
2014-03-01 22:04 - 2014-03-01 22:04 - 00092052 _____ () C:\Users\Matthew01_2\Downloads\Pandora_Player.rar
2014-03-01 18:42 - 2014-03-01 18:42 - 00112582 _____ () C:\Users\Matthew01_2\Downloads\PowerMenuSetup_1_5_1.exe
2014-03-01 18:42 - 2013-10-29 13:59 - 00000000 ___RD () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-01 16:39 - 2014-03-01 16:39 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Facepalm Games
2014-03-01 16:22 - 2014-03-01 16:22 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\BridgeProject
2014-03-01 11:31 - 2013-09-29 20:04 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-01 11:24 - 2013-10-29 14:35 - 00000000 __RDO () C:\Users\Matthew01_2\SkyDrive
2014-03-01 11:24 - 2013-08-22 06:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-28 22:01 - 2013-11-29 23:14 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\KeePass
2014-02-28 22:01 - 2013-08-22 05:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-02-28 16:00 - 2014-02-15 16:40 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\qBittorrent
2014-02-28 15:59 - 2014-02-28 15:59 - 00129837 _____ () C:\Users\Matthew01_2\Downloads\wildlifepark3_windows_1388183454.zip.torrent
2014-02-27 23:31 - 2013-10-30 15:45 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Adobe
2014-02-27 23:28 - 2013-11-30 23:50 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Dxtory Software
2014-02-27 23:27 - 2013-12-22 17:31 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-02-27 23:27 - 2013-10-29 13:59 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Adobe
2014-02-27 23:26 - 2013-12-22 17:31 - 00000000 ____D () C:\ProgramData\Adobe
2014-02-27 22:14 - 2014-02-27 22:10 - 216141824 _____ () C:\Users\Matthew01_2\Downloads\LibreOffice_4.1.5_Win_x86.msi
2014-02-27 20:00 - 2014-02-27 20:00 - 00679696 _____ (Shark Labs) C:\Users\Matthew01_2\Downloads\CFSetup350.exe
2014-02-27 16:29 - 2013-12-22 17:30 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Adobe
2014-02-24 13:54 - 2013-08-22 06:44 - 00428104 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-23 17:59 - 2014-02-23 17:59 - 00843976 _____ () C:\Users\Matthew01_2\Downloads\Chatty_0.6.zip
2014-02-23 17:45 - 2014-02-18 22:51 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\HexChat
2014-02-22 22:29 - 2014-02-22 22:29 - 01054064 _____ (Amazon Services LLC) C:\Users\Matthew01_2\Downloads\Guns_of_Icarus_Online_Online_Game_Code_Downloader.exe
2014-02-22 19:57 - 2013-10-29 14:19 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Paint.NET
2014-02-22 17:04 - 2014-02-22 17:04 - 00190686 _____ () C:\Users\Matthew01_2\Downloads\mailbox_alert-0.16.4-sm+tb.xpi
2014-02-21 20:02 - 2014-02-21 20:02 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\SWTOR
2014-02-21 14:55 - 2014-03-01 23:47 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-02-21 14:55 - 2013-11-16 16:08 - 00092376 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-02-21 14:55 - 2013-10-19 12:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-20 21:46 - 2014-02-20 21:46 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-02-20 21:46 - 2014-02-20 21:46 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\SWTORPerf
2014-02-20 21:40 - 2014-02-20 21:39 - 00015678 _____ () C:\Users\Matthew01_2\Documents\Install STAR WARS The Old Republic.log
2014-02-20 21:39 - 2013-06-22 22:35 - 00033755 _____ () C:\END
2014-02-20 18:14 - 2013-11-22 20:33 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\.minecraft
2014-02-20 16:22 - 2014-02-20 16:21 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Guacamelee
2014-02-19 18:50 - 2014-01-26 16:18 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\DisplayFusion
2014-02-19 18:44 - 2013-10-30 15:45 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-19 18:44 - 2013-10-30 15:45 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-02-19 14:56 - 2014-02-19 14:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Unity
2014-02-19 14:52 - 2014-02-19 14:52 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Unity
2014-02-18 23:00 - 2014-02-18 23:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\be.gip.twitch.chat.TwitchChatOAuth
2014-02-18 23:00 - 2014-02-18 23:00 - 00000000 ____D () C:\Program Files (x86)\Air
2014-02-18 17:58 - 2013-11-29 23:01 - 00000000 ____D () C:\ProgramData\Origin
2014-02-18 16:48 - 2014-02-15 22:35 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\.purple
2014-02-17 13:00 - 2013-08-22 07:38 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-17 13:00 - 2013-08-22 07:38 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-16 18:57 - 2014-02-16 18:57 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\onOne Software
2014-02-16 18:57 - 2013-11-04 13:38 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-02-16 10:56 - 2014-02-16 10:56 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Battlefield 3
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\PunkBuster
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\ESN
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-02-16 10:56 - 2014-02-16 03:58 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-02-16 10:55 - 2014-02-16 10:55 - 00000000 ____D () C:\ProgramData\EA Core
2014-02-16 10:54 - 2014-02-15 14:19 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Origin
2014-02-16 03:58 - 2014-02-16 03:58 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-02-16 03:58 - 2014-02-16 03:58 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-02-16 03:51 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\rescache
2014-02-16 00:13 - 2014-02-15 14:19 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Origin
2014-02-15 23:15 - 2014-02-15 23:15 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3
2014-02-15 23:15 - 2014-02-15 23:15 - 00000000 ____D () C:\Users\Matthew01_2\.idlerc
2014-02-15 23:15 - 2014-02-15 23:14 - 00000000 ____D () C:\Python33
2014-02-15 23:15 - 2013-10-29 13:59 - 00000000 ____D () C:\Users\Matthew01_2
2014-02-15 22:33 - 2014-02-15 22:22 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\mIRC
2014-02-15 20:52 - 2014-02-15 20:52 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-02-15 18:00 - 2014-02-15 17:59 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\TeraCopy
2014-02-15 17:59 - 2014-02-15 17:59 - 00000000 ____D () C:\Program Files\TeraCopy
2014-02-15 17:36 - 2014-02-15 17:36 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Evernote
2014-02-15 16:49 - 2014-02-15 16:42 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Dexpot
2014-02-15 16:41 - 2014-02-15 16:41 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\qBittorrent
2014-02-15 16:41 - 2013-12-08 11:10 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\BitTorrent
2014-02-15 16:25 - 2013-10-20 12:03 - 00000000 ____D () C:\Program Files\CCleaner
2014-02-15 15:15 - 2013-10-19 12:10 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-15 14:18 - 2014-02-15 14:18 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-02-15 13:56 - 2013-11-16 16:32 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-02-15 13:41 - 2014-01-18 13:59 - 00000000 ____D () C:\Program Files (x86)\7tsp
2014-02-15 12:53 - 2014-01-26 12:29 - 00000000 ___RD () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-02-15 00:04 - 2013-08-22 07:36 - 00000000 ___RD () C:\Windows\ToastData
2014-02-14 22:04 - 2013-11-12 14:37 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-14 22:03 - 2013-11-12 14:37 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-14 13:11 - 2014-02-12 15:00 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-02-14 13:08 - 2014-02-14 13:08 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\PDAppFlex
2014-02-12 15:00 - 2014-02-12 15:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Opera Software
2014-02-12 15:00 - 2014-02-12 15:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Opera Software
2014-02-11 22:39 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-02-11 22:39 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\FileManager
2014-02-11 22:39 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\Camera
2014-02-11 19:38 - 2013-11-26 14:12 - 00003910 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1ceeaf4957a29c8
2014-02-11 19:38 - 2013-11-26 14:12 - 00003674 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1ceeaf4955c36c4
2014-02-09 13:14 - 2013-12-07 23:04 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\My Games
2014-02-09 13:14 - 2013-10-29 16:58 - 00000000 ____D () C:\Users\Matthew01_2\Documents\My Games
2014-02-09 11:22 - 2013-10-19 12:14 - 00000000 ____D () C:\ProgramData\Skype
2014-02-08 23:58 - 2014-02-08 23:55 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\AcePatrol2
2014-02-08 23:55 - 2014-02-08 23:55 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00122904 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00109080 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2014-02-06 13:46 - 2014-02-06 13:45 - 00000000 ____D () C:\Steam
2014-02-06 13:39 - 2013-10-19 12:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-06 04:16 - 2014-02-11 14:34 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 03:30 - 2014-02-11 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 03:30 - 2014-02-11 14:34 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 03:12 - 2014-02-11 14:34 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 03:07 - 2014-02-11 14:34 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 03:06 - 2014-02-11 14:34 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 02:57 - 2014-02-11 14:34 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 02:56 - 2014-02-11 14:34 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 02:49 - 2014-02-11 14:34 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 02:48 - 2014-02-11 14:34 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 02:48 - 2014-02-11 14:34 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 02:38 - 2014-02-11 14:34 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 02:32 - 2014-02-11 14:34 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 02:20 - 2014-02-11 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 02:17 - 2014-02-11 14:34 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 02:11 - 2014-02-11 14:34 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 02:01 - 2014-02-11 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 02:00 - 2014-02-11 14:34 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 01:57 - 2014-02-11 14:34 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 01:57 - 2014-02-11 14:34 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 01:52 - 2014-02-11 14:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 01:52 - 2014-02-11 14:34 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 01:50 - 2014-02-11 14:34 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 01:47 - 2014-02-11 14:34 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 01:46 - 2014-02-11 14:34 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 01:25 - 2014-02-11 14:34 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 01:25 - 2014-02-11 14:34 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 01:24 - 2014-02-11 14:34 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 01:22 - 2014-02-11 14:34 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 01:13 - 2014-02-11 14:34 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 01:09 - 2014-02-11 14:34 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 01:03 - 2014-02-11 14:34 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 00:55 - 2014-02-11 14:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 00:41 - 2014-02-11 14:34 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 00:40 - 2014-02-11 14:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 00:36 - 2014-02-11 14:34 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 00:34 - 2014-02-11 14:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-05 14:58 - 2014-02-05 14:40 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Sites
2014-02-05 14:37 - 2014-02-05 14:37 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-02-05 14:24 - 2014-02-05 14:24 - 00000000 ____D () C:\Windows\XSxS
2014-02-05 13:41 - 2014-02-04 18:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-02-04 19:38 - 2014-02-04 19:38 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\www.shadowexplorer.com
2014-02-04 19:38 - 2014-02-04 19:38 - 00000000 ____D () C:\Program Files (x86)\ShadowExplorer
2014-02-03 21:14 - 2014-02-03 21:14 - 00000577 _____ () C:\Users\Guest\Desktop\Juice.lnk
2014-02-03 21:14 - 2014-02-03 21:14 - 00000000 ____D () C:\Users\Matthew01_2\Documents\My Received Podcasts
2014-02-03 21:14 - 2014-02-03 21:14 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Workrave
2014-02-03 21:14 - 2014-02-03 21:14 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\iPodder
2014-02-03 21:13 - 2014-02-03 21:13 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\foobar2000
2014-02-03 17:44 - 2014-01-31 21:46 - 00000000 ____D () C:\Program Files (x86)\KeePass Password Safe 2
2014-02-02 11:05 - 2014-02-02 11:05 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Apple Computer
2014-02-01 19:07 - 2014-02-01 18:50 - 00000000 ____D () C:\Program Files\Lightworks
2014-02-01 19:01 - 2014-02-01 19:01 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Apple
2014-02-01 19:01 - 2014-02-01 19:01 - 00000000 ____D () C:\ProgramData\Apple
2014-02-01 18:52 - 2014-02-01 18:50 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2014-02-01 18:46 - 2014-02-01 18:45 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\avidemux
2014-02-01 18:18 - 2014-02-01 18:18 - 00715038 _____ () C:\Windows\unins000.exe
2014-02-01 18:18 - 2013-12-01 02:02 - 00003462 _____ () C:\Windows\unins000.dat
2014-02-01 11:44 - 2014-02-01 11:44 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\WinRAR
2014-02-01 11:44 - 2014-02-01 11:44 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-02-01 11:44 - 2014-02-01 11:44 - 00000000 ____D () C:\Program Files\WinRAR
2014-01-31 20:45 - 2014-01-31 20:45 - 00000000 ____D () C:\Program Files (x86)\Dashlane
2014-01-31 19:32 - 2014-01-01 21:53 - 00000000 ____D () C:\ProgramData\Razer
2014-01-31 13:56 - 2014-01-27 17:01 - 00036864 _____ () C:\Users\Matthew01_2\AppData\Roaming\RZR_00204de5442c974efe2a2eb6e609.db
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
LastRegBack: 2014-02-25 20:33
 
==================== End Of Log ============================

 

Link to post
Share on other sites

Addition.txt:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-03-2014 03
Ran by Matthew01_2 at 2014-03-02 20:23:09
Running from C:\Users\Matthew01_2\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personal firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
 
==================== Installed Programs ======================
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1380 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.9.0.1380 - Adobe Systems Incorporated) Hidden
AMD Accelerated Video Transcoding (Version: 13.15.100.30830 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{1E9871B6-7C44-9A3A-A1C0-F9729663C7F5}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Audiosurf Demo (HKLM-x32\...\Steam App 12910) (Version:  - Dylan Fitterer)
AutoHotkey 1.1.13.01 (HKLM\...\AutoHotkey) (Version: 1.1.13.01 - Lexikos)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.2 - EA Digital Illusions CE AB)
Bridge Project (HKLM-x32\...\Steam App 232950) (Version:  - Halycon Media GmbH & Co. KG)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center (HKLM-x32\...\{8B1A559A-FB9D-42F5-A8A7-2F132CF28414}) (Version: 1.00.0000 - )
Catalyst Control Center InstallProxy (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform)
CPUID CPU-Z 1.67.1 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
CrystalDiskInfo 6.0.4 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.0.4 - Crystal Dew World)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DCS World (HKLM-x32\...\Steam App 223750) (Version:  - Eagle Dynamics)
DisplayFusion 5.1.1 (HKLM-x32\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 5.1.1.0 - Binary Fortress Software)
Dust: An Elysian Tail (HKLM-x32\...\Steam App 236090) (Version:  - Humble Hearts LLC)
EMET 4.0 (HKLM-x32\...\{1F7019BB-1C9A-4E54-9B59-1744629E63B1}) (Version: 4.0 - Microsoft)
ESET Smart Security (HKLM\...\{F7C525E7-659A-47F6-A25A-7A63FA10E767}) (Version: 7.0.302.26 - ESET, spol s r. o.)
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
Euro Truck Simulator (HKLM-x32\...\Steam App 232010) (Version:  - SCS Software)
Everything 1.2.1.371 (HKLM-x32\...\Everything) (Version:  - )
f.lux (HKCU\...\Flux) (Version:  - )
focus booster (HKLM-x32\...\com.focusboosterapp.focusbooster.air) (Version: 1.3.2 - UNKNOWN)
focus booster (x32 Version: 1.3.2 - UNKNOWN) Hidden
foobar2000 v1.3.1 (HKLM-x32\...\foobar2000) (Version: 1.3.1 - Peter Pawlowski)
Giana Sisters: Twisted Dreams (HKLM-x32\...\Steam App 223220) (Version:  - Black Forest Games)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.117 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Guacamelee! Gold Edition (HKLM-x32\...\Steam App 214770) (Version:  - DrinkBox Studios)
Guns of Icarus Online (HKLM-x32\...\Steam App 209080) (Version:  - Muse Games)
Gyazo 2.0.2 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version:  - Nota Inc.)
HD Tune Pro 5.50 (HKLM-x32\...\HD Tune Pro_is1) (Version:  - EFD Software)
HexChat (x64) (HKLM\...\HexChat (x64)_is1) (Version: 2.9.6 - HexChat)
HWiNFO64 Version 4.30 (HKLM\...\HWiNFO64_is1) (Version: 4.30 - Martin Malík - REALiX)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan)
Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Just Cause 2: Multiplayer Mod (HKLM-x32\...\Steam App 259080) (Version:  - JC2-MP Team)
KeePass Password Safe 1.26 (HKLM-x32\...\KeePass Password Safe_is1) (Version: 1.26 - Dominik Reichl)
KeePass Password Safe 2.25 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.25 - Dominik Reichl)
Lagarith Lossless Codec (1.3.27) (HKLM-x32\...\{F59AC46C-10C3-4023-882C-4212A92283B3}_is1) (Version:  - )
Lame ACM MP3 Codec (HKLM-x32\...\LameACM) (Version:  - )
League of Legends (HKLM-x32\...\League of Legends 3.0.0) (Version: 3.0.0 - Riot Games)
League of Legends (x32 Version: 3.0.0 - Riot Games) Hidden
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Lernout & Hauspie TruVoice American English TTS Engine (HKLM-x32\...\tv_enua) (Version:  - )
LibreOffice 4.1 Help Pack (English (United States)) (HKLM-x32\...\{56764D4E-FDC1-4002-8019-4DB0DC975403}) (Version: 4.1.2.3 - The Document Foundation)
LibreOffice 4.1.5.3 (HKLM-x32\...\{E77773E5-944A-453F-97F3-46767AE0A253}) (Version: 4.1.5.3 - The Document Foundation)
Malwarebytes Anti-Malware version 2.00.0.0504 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.0504 - Malwarebytes Corporation)
Mathematica Extras 9.0 (4092550) (HKLM\...\A-WIN-Extras 9.0.1 4092550_is1) (Version: 9.0.1 - Wolfram Research, Inc.)
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 24.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 24.0 (x86 en-US)) (Version: 24.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.3.0 - Mozilla)
Mozilla Thunderbird 24.3.0 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 24.3.0 (x86 en-US)) (Version: 24.3.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MultiBit 0.5.15 (HKLM-x32\...\MultiBit 0.5.15) (Version: 0.5.15 - )
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.2 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera Stable 19.0.1326.63 (HKLM-x32\...\Opera 19.0.1326.63) (Version: 19.0.1326.63 - Opera Software ASA)
Oracle VM VirtualBox 4.3.2 (HKLM\...\{49C9FDFF-6056-4E8C-B9AF-B7B4D78023E2}) (Version: 4.3.2 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.5.195 - Electronic Arts, Inc.)
ORION: Dino Horde (HKLM-x32\...\Steam App 104900) (Version:  - Spiral Game Studios)
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC)
PAYDAY 2 Demo (HKLM-x32\...\Steam App 251040) (Version:  - OVERKILL - a Starbreeze Studio.)
PAYDAY: The Heist (HKLM-x32\...\Steam App 24240) (Version:  - OVERKILL Software)
Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Pidgin (HKLM-x32\...\Pidgin) (Version: 2.10.9 - )
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.991 - Even Balance, Inc.)
Python 3.3.4 (64-bit) (HKLM\...\{D7E79BB6-DBE5-33C5-B105-CE6871C59DB6}) (Version: 3.3.4150 - Python Software Foundation)
qBittorrent 3.1.8 (HKLM-x32\...\qbittorrent) (Version: 3.1.8 - The qBittorrent project)
Rainmeter (HKLM-x32\...\Rainmeter) (Version: 3.0.2 r2161 - )
RAPID Mode (Version: 1.0.1.42 - Samsung Electronics Co., Ltd.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7071 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RUSH (HKLM-x32\...\Steam App 38720) (Version:  - Two Tribes)
Samsung Data Migration (HKLM-x32\...\{D4DE3DB4-7734-47E5-8D92-B80146311406}) (Version: 2.6 - Samsung)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.3.0 - Samsung Electronics)
Sandboxie 4.06 (64-bit) (HKLM\...\Sandboxie) (Version: 4.06 - Sandboxie Holdings, LLC)
ShadowExplorer 0.9 (HKLM-x32\...\ShadowExplorer_is1) (Version: 0.9.462.0 - ShadowExplorer.com)
ShiftWindow 1.02 (HKLM-x32\...\ShiftWindow_is1) (Version:  - Grismar)
Shotty - Tiny but impressive screenshot utility (HKLM\...\2e730c18-03e8-4d1d-8fc2-0ee3ea04a765) (Version: 2.0.2.216 - Thomas Baumann)
Sid Meier’s Ace Patrol: Pacific Skies (HKLM-x32\...\Steam App 244090) (Version:  - Firaxis)
Sid Meier's Ace Patrol (HKLM-x32\...\Steam App 244070) (Version:  - Firaxis Games)
Sid Meier's Civilization III: Complete (HKLM-x32\...\Steam App 3910) (Version:  - Firaxis Games)
Sid Meier's Civilization IV (HKLM-x32\...\Steam App 3900) (Version:  - Firaxis Games)
Sid Meier's Civilization IV: Beyond the Sword (HKLM-x32\...\Steam App 8800) (Version:  - Firaxis Games)
Sid Meier's Civilization IV: Colonization (HKLM-x32\...\Steam App 16810) (Version:  - Firaxis Games)
Sid Meier's Civilization IV: Warlords (HKLM-x32\...\Steam App 3990) (Version:  - Firaxis Games)
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Sid Meier's Railroads! (HKLM-x32\...\Steam App 7600) (Version:  - Firaxis Games)
Similar Image Finder (HKLM-x32\...\{2E56B8C2-B25C-4B0A-92BE-ACB493CC5048}) (Version: 1.0.0 - Tago Software)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Speakonia (HKLM-x32\...\Speakonia_is1) (Version: 1.0.3.5 - CFS-Technologies)
Speccy (HKLM\...\Speccy) (Version: 1.24 - Piriform)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
StartIsBack+ (HKLM-x32\...\StartIsBack) (Version: 1.5.2 - startisback.com)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.13 - TeamSpeak Systems GmbH)
TeraCopy 2.3 (HKLM\...\TeraCopy_is1) (Version:  - Code Sector)
The Sims 2 (HKLM-x32\...\{8AB8D458-939E-403F-0097-9BA1C1F013D5}) (Version:  - )
The Swapper (HKLM-x32\...\Steam App 231160) (Version:  - Olli Harjola, Otto Hantula, Tom Jubert, Carlo Castellano)
Thief Gold (HKLM-x32\...\Steam App 211600) (Version:  - Looking Glass Studios)
Trainz Simulator 12 (HKLM-x32\...\Steam App 24670) (Version:  - N3V Games)
TreeSize Free V2.7 (HKLM-x32\...\TreeSize Free_is1) (Version: 2.7 - JAM Software)
Twitch Chat OAuth Generator (HKLM-x32\...\be.gip.twitch.chat.TwitchChatOAuth) (Version: 1.0.0 - UNKNOWN)
Twitch Chat OAuth Generator (x32 Version: 1.0.0 - UNKNOWN) Hidden
Unity Web Player (HKCU\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
VoxOx 2.9.2 (HKLM-x32\...\VoxOx) (Version: 2.9.2 - VoxOx)
WhatPulse version 2.3.1 (HKLM-x32\...\{95CC8D5F-90A1-4285-9B2D-8D0FBCFD8D0D}_is1) (Version: 2.3.1 - WhatPulse)
Wildlife Park 3 v1.11 (HKLM-x32\...\Wildlife Park 3_is1) (Version:  - bitComposer Games)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Wolfram CDF Player (M-WIN-D 9.0.1 4092685) (HKLM-x32\...\M-WIN-D 9.0.1 4092685_is1) (Version: 9.0.1 - Wolfram Research, Inc.)
 
==================== Restore Points  =========================
 
16-02-2014 06:33:57 Revo Uninstaller's restore point - mIRC
20-02-2014 22:30:25 Windows Update
28-02-2014 06:16:12 Installed LibreOffice 4.1.5.3
02-03-2014 07:33:37 Revo Uninstaller's restore point - VLC media player 2.1.0
 
==================== Hosts content: ==========================
 
2013-08-22 05:25 - 2014-01-29 17:39 - 00000858 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1            rad.msn.com
 
==================== Scheduled Tasks (whitelisted) =============
 
Task: {05289514-25E1-4C5C-9BFD-15D448B13119} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-02-14] (Microsoft Corporation)
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-21] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {5A4D0CB5-9551-4ED0-9901-A993A9B7A978} - System32\Tasks\GoogleUpdateTaskMachineCore1ceeaf4955c36c4 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-19] (Google Inc.)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {712542C1-CF7C-465A-9760-2F1790CD17D8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-21] (Piriform Ltd)
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A08600EB-5923-4151-9D3E-B7EFA684FF0B} - System32\Tasks\Malwarebytes Update => mbam.exe
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DC26C305-429E-419C-8D63-9770C54854E7} - System32\Tasks\GoogleUpdateTaskMachineUA1ceeaf4957a29c8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-19] (Google Inc.)
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {EBD89D5D-E654-40D2-B313-320667A8F637} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-1086244806-2233730069-3771371249-1001
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1ceeaf4955c36c4.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1ceeaf4957a29c8.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2013-06-14 16:19 - 2013-06-14 16:19 - 00069280 _____ () C:\Program Files (x86)\EMET 4.0\EMET_CE64.DLL
2014-02-16 03:58 - 2014-02-16 03:58 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2013-12-21 14:39 - 2013-12-11 19:40 - 03126272 _____ () C:\Program Files (x86)\WhatPulse2\whatpulse.exe
2013-06-14 16:19 - 2013-06-14 16:19 - 00116384 _____ () C:\Program Files (x86)\EMET 4.0\HelperLib.dll
2013-06-14 16:19 - 2013-06-14 16:19 - 00034464 _____ () C:\Program Files (x86)\EMET 4.0\ReportingSubsystem.dll
2013-06-12 16:53 - 2013-06-12 16:53 - 00348160 _____ () C:\Program Files (x86)\EMET 4.0\DevExpress.UserSkins.HighContrast.dll
2013-06-14 16:19 - 2013-06-14 16:19 - 00029856 _____ () C:\Program Files (x86)\EMET 4.0\TrayIconSubsystem.dll
2013-06-14 16:19 - 2013-06-14 16:19 - 00049824 _____ () C:\Program Files (x86)\EMET 4.0\PKIPinningSubsystem.dll
2014-02-15 17:59 - 2012-01-29 16:55 - 00657920 _____ () C:\Program Files\TeraCopy\TeraCopy64.dll
2013-10-29 12:45 - 2013-10-29 12:45 - 00036536 _____ () C:\Program Files\Rainmeter\Rainmeter.exe
2013-10-29 12:45 - 2013-10-29 12:45 - 00798392 _____ () C:\Program Files\Rainmeter\Rainmeter.dll
2013-10-29 12:41 - 2013-10-29 12:41 - 00058880 _____ () C:\Program Files\Rainmeter\Plugins\WebParser.dll
2013-10-29 12:41 - 2013-10-29 12:41 - 00023040 _____ () C:\Program Files\Rainmeter\Plugins\WifiStatus.dll
2013-10-29 12:41 - 2013-10-29 12:41 - 00025088 _____ () C:\Program Files\Rainmeter\Plugins\QuotePlugin.dll
2013-06-14 16:19 - 2013-06-14 16:19 - 00062112 _____ () C:\Program Files (x86)\EMET 4.0\EMET_CE.DLL
2013-12-21 14:39 - 2013-04-08 09:34 - 00137728 _____ () C:\Program Files (x86)\WhatPulse2\CrashRpt1402.dll
2013-12-26 00:48 - 2013-12-12 14:19 - 00142848 _____ () A:\Steam\libavresample-1.dll
2013-12-26 00:48 - 2013-11-04 17:12 - 00890592 _____ () A:\Steam\libavutil-52.dll
2013-10-30 14:00 - 2014-02-10 18:34 - 00751616 _____ () A:\Steam\SDL2.dll
2013-10-30 14:00 - 2014-02-25 13:57 - 01135296 _____ () A:\Steam\bin\chromehtml.DLL
2013-10-30 14:00 - 2014-01-10 15:33 - 20625832 _____ () A:\Steam\bin\libcef.dll
2013-10-19 21:20 - 2013-06-14 15:49 - 01100800 _____ () A:\Steam\bin\avcodec-53.dll
2013-10-19 21:20 - 2013-06-14 15:49 - 00124416 _____ () A:\Steam\bin\avutil-51.dll
2013-10-19 21:20 - 2013-06-14 15:49 - 00192000 _____ () A:\Steam\bin\avformat-53.dll
2013-10-30 14:00 - 2014-02-25 13:57 - 00119488 _____ () A:\Steam\bin\audio.dll
2013-10-19 21:20 - 2013-06-14 15:49 - 00071680 _____ () A:\Steam\bin\mssmp3.asi
2013-10-19 21:20 - 2013-06-14 15:49 - 00153088 _____ () A:\Steam\bin\mssvoice.asi
2014-02-20 19:47 - 2014-02-19 17:02 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\chrome_elf.dll
2014-02-20 19:47 - 2014-02-19 17:02 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libglesv2.dll
2014-02-20 19:47 - 2014-02-19 17:02 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libegl.dll
2014-02-20 19:47 - 2014-02-19 17:03 - 04060488 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll
2014-02-20 19:47 - 2014-02-19 17:03 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll
2014-02-20 19:47 - 2014-02-19 17:02 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ffmpegsumo.dll
2014-02-20 19:47 - 2014-02-19 17:03 - 13632840 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll
2014-02-04 18:01 - 2014-02-04 18:01 - 03019376 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2014-02-04 18:01 - 2014-02-04 18:01 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2014-02-04 18:01 - 2014-02-04 18:01 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
AlternateDataStreams: C:\Users\Matthew01_2\SkyDrive:ms-properties
 
==================== Safe Mode (whitelisted) ===================
 
 
==================== Disabled items from MSCONFIG ==============
 
 
==================== Faulty Device Manager Devices =============
 
Name: VirtualBox Host-Only Ethernet Adapter
Description: VirtualBox Host-Only Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Oracle Corporation
Service: VBoxNetAdp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/02/2014 07:39:21 PM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 05:39:22 PM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 03:39:21 PM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 01:39:23 PM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 11:39:20 AM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 09:39:20 AM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 07:39:20 AM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 05:39:20 AM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 03:39:20 AM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 01:39:20 AM) (Source: Microsoft-Windows-AppModel-State) (User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
 
System errors:
=============
Error: (03/02/2014 00:32:13 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 00:32:13 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 00:32:13 PM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 11:25:04 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 11:25:04 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 11:25:04 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 11:25:04 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 11:25:04 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 11:25:04 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
Error: (03/02/2014 11:25:01 AM) (Source: Schannel) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
 
 
Microsoft Office Sessions:
=========================
Error: (03/02/2014 07:39:21 PM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 05:39:22 PM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 03:39:21 PM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 01:39:23 PM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 11:39:20 AM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 09:39:20 AM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 07:39:20 AM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 05:39:20 AM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 03:39:20 AM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
Error: (03/02/2014 01:39:20 AM) (Source: Microsoft-Windows-AppModel-State)(User: MATTHEW-DESKTOP)
Description: Microsoft.BingWeather_8wekyb3d8bbwe5
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 72%
Total physical RAM: 8154.3 MB
Available physical RAM: 2275.23 MB
Total Pagefile: 9501.15 MB
Available Pagefile: 2490.71 MB
Total Virtual: 131072 MB
Available Virtual: 131071.78 MB
 
==================== Drives ================================
 
Drive a: (Data) (Fixed) (Total:1397.26 GB) (Free:1044.54 GB) NTFS
Drive c: (OS) (Fixed) (Total:111.69 GB) (Free:56.26 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1397 GB) (Disk ID: E16EA10D)
 
Partition: GPT Partition Type.
 
========================================================
Disk: 1 (Size: 112 GB) (Disk ID: 820DF525)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
Link to post
Share on other sites

  • Root Admin

Okay then, Please read the following information below and post back the requested logs when ready.

General P2P/Piracy Warning:
 

 
If you're using
Peer 2 Peer
software such as
uTorrent, BitTorrent
or similar you must either fully uninstall them or completely disable them from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

If you have
illegal/cracked software, cracks, keygens etc
. on the system, please remove or uninstall them now and read the policy on
Piracy
.




Before we proceed further, please read all of the following instructions carefully.
If there is anything that you do not understand kindly ask before proceeding.
If needed please print out these instructions.
  • Please do not post logs using CODE, QUOTE, or FONT tags. Just paste them as direct text.
  • If the log is too large then you can use attachments by clicking on the More Reply Options button.
  • Please enable your system to show hidden files: How to see hidden files in Windows
  • Make sure you're subscribed to this topic:
    • Click on the Follow This Topic Button (at the top right of this page), make sure that the Receive notification box is checked and that it is set to Instantly

    [*]Removing malware can be unpredictable...It is unlikely but things can go very wrong! Please make sure you Backup all files that cannot be replaced if something were to happen. You can copy them to a CD/DVD, external drive or a pen drive [*]Please don't run any other scans, download, install or uninstall any programs unless requested by me while I'm working with you. [*]The removal of malware is not instantaneous, please be patient. Often we are also on a different Time Zone. [*]Perform everything in the correct order. Sometimes one step requires the previous one. [*]If you have any problems while following my instructions, Stop there and tell me the exact nature of the issue. [*]You can check here if you're not sure if your computer is 32-bit or 64-bit [*]Please disable your antivirus while running any requested scanners so that they do not interfere with the scanners. [*]When we are done, I'll give you instructions on how to cleanup all the tools and logs [*]Please stick with me until I give you the "all clear" and Please don't waste my time by leaving before that. [*]Your topic will be closed if you haven't replied within 3 days [*](If I have not responded within 24 hours, please send me a Private Message as a reminder)


 
STEP 0
RKill is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes
so that your normal security software can then run and clean your computer of infections.
When RKill runs it will kill malware processes and then removes incorrect executable associations and fixes policies
that stop us from using certain tools. When finished it will display a log file that shows the processes that were
terminated while the program was running.

As RKill only terminates a program's running process, and does not delete any files, after running it you should not reboot
your computer as any malware processes that are configured to start automatically will just be started again.
Instead, after running RKill you should immediately scan your computer using the requested scans I've included.

Please download Rkill by Grinler from one of the links below and save it to your desktop.
 


Link 2

  • On Windows XP double-click on the Rkill desktop icon to run the tool.
  • On Windows Vista/Windows 7 or 8, right-click on the Rkill desktop icon and select Run As Administrator
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • If the tool does not run from any of the links provided, please let me know.
  • Do not reboot the computer, you will need to run the application again.

 
STEP 01
Backup the Registry:
Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.
  • Please download ERUNT from one of the following links: Link1 | Link2 | Link3
  • ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.
  • Double click on erunt-setup.exe to Install ERUNT by following the prompts.
  • NOTE: Do not choose to allow ERUNT to add an Entry to the Startup folder. Click NO.
  • Start ERUNT either by double clicking on the desktop icon or choosing to start the program at the end of the setup process.
  • Choose a location for the backup.
    • Note: the default location is C:\Windows\ERDNT which is acceptable.

    [*]Make sure that at least the first two check boxes are selected. [*]Click on OK [*]Then click on YES to create the folder. [*]Note: if it is necessary to restore the registry, open the backup folder and start ERDNT.exe


 
 
STEP 02
Please run a Quick Scan with Malwarebytes
Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.
Please Update and run a Quick Scan with Malwarebytes Anti-Malware, post back the report.
Make sure that everything is checked, and click Remove Selected if anything is found.
 
 
STEP 03
Please download RogueKiller and save it to your desktop.

You can check here if you're not sure if your computer is 32-bit or 64-bit

  • RogueKiller 32-bit | RogueKiller 64-bit
  • Quit all running programs.
  • For Windows XP, double-click to start.
  • For Vista,Windows 7/8, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
  • Read and accept the EULA (End User Licene Agreement)
  • Click Scan to scan the system.
  • When the scan completes Close the program > Don't Fix anything!
  • Don't run any other options, they're not all bad!!
  • Post back the report which should be located on your desktop.


 
Thanks
 

Link to post
Share on other sites

I upgraded to version 2.0 of Malwarebytes - and assumed Hyper Scan equals to Quick scan? Hopefully this is true.

 

It didn't seem to find anything, RAM/CPU stayed at about the same.

 

Hyper scan:

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 3/7/2014
Scan Time: 10:33:30 PM
Logfile: mb quick.txt
Administrator: Yes
 
Version: 2.00.0.0504
Malware Database: v2014.03.08.01
Rootkit Database: v2014.02.20.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
 
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Matthew01_2
 
Scan Type: Hyper Scan
Result: Completed
Objects Scanned: 223104
Time Elapsed: 1 min, 4 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Disabled
Archives: Enabled
Rootkits: Enabled
Shuriken: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
 
RK Report: 
 
RogueKiller V8.8.10 _x64_ [Feb 28 2014] by Adlice Software
 
Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : Matthew01_2 [Admin rights]
Mode : Scan -- Date : 03/07/2014 22:37:27
| ARK || FAK || MBR |
 
¤¤¤ Bad processes : 0 ¤¤¤
 
¤¤¤ Registry Entries : 3 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
 
¤¤¤ Scheduled tasks : 0 ¤¤¤
 
¤¤¤ Startup Entries : 0 ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ Browser Addons : 0 ¤¤¤
 
¤¤¤ Particular Files / Folders: ¤¤¤
 
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
 
¤¤¤ External Hives: ¤¤¤
 
¤¤¤ Infection :  ¤¤¤
 
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
 
 
127.0.0.1            rad.msn.com
 
 
¤¤¤ MBR Check: ¤¤¤
 
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD15EZRX-00DC0B0 ATA Device +++++
--- User ---
[MBR] cab50c10f109a1f6e46a1032bc7a9a98
[bSP] 33e83a3994a9b5e538807ae768bc06ad : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 1430795 Mo
User = LL1 ... OK!
User = LL2 ... OK!
 
+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) Samsung SSD 840 EVO 120GB ATA Device +++++
--- User ---
[MBR] c01ba2c2e83fd4a1ac957f1fb84b6bb2
[bSP] f2e5423cedb60be72bc888ff26c61291 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 114369 Mo
User = LL1 ... OK!
User = LL2 ... OK!
 
Finished : << RKreport[0]_S_03072014_223727.txt >>
 
 
 
 
Link to post
Share on other sites

  • Root Admin

Well 2.0 is beta software and is not fully tested and released.  That said its pretty hard to believe that 1.75 and 2.0 are using the same amount of memory as the 2.0 is using much less memory than 1.75 so I would have to assume something else may be going on.  Can you please show me a screen shot of the MBAM services or processes that are showing them and how much resource they're consuming

 

Thank you

Link to post
Share on other sites

The image you're showing is very normal RAM usage.   The average Windows 8.1 computer now days comes with 4GB of RAM which means you're using less .1% of RAM for the program.  Some computers come with 8GB of RAM

 

I have 8GB in my system at the moment. 

 

I guess it was just me being cautious. Other than that, all my scans check out? I should be fine, correct?

 

Thank you for the help!

Link to post
Share on other sites

  • Root Admin

Let me have you run a NEW scan with this and we'll see if it finds anything odd or not.

 

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system.
You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it also makes another log (Addition.txt). Please copy and paste it to your reply as well.
Link to post
Share on other sites

FRST.txt:

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-03-2014 01

Ran by Matthew01_2 (administrator) on MATTHEW-DESKTOP on 07-03-2014 22:53:46
Running from C:\Users\Matthew01_2\Desktop
Windows 8.1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link for 32-Bit version:
Download link for 64-Bit Version:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Binary Fortress Software) A:\DisplayFusion\DisplayFusionService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Samsung Electronics Co., Ltd.) C:\Windows\system32\RAPID\SamsungRapidSvc.exe
(www.shadowexplorer.com) C:\Program Files (x86)\ShadowExplorer\sesvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\skydrive.exe
(www.startisback.com) C:\Program Files (x86)\StartIsBack\StartScreen.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe
(Flux Software LLC) C:\Users\Matthew01_2\AppData\Local\FluxSoftware\Flux\flux.exe
(http://shotty.devs-on.net) A:\Shotty\Shotty.exe
(Binary Fortress Software) A:\DisplayFusion\DisplayFusion.exe
() C:\Program Files (x86)\WhatPulse2\whatpulse.exe
(Binary Fortress Software) A:\DisplayFusion\DisplayFusionHookAppWIN6032.exe
(Dominik Reichl) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe
(Binary Fortress Software) A:\DisplayFusion\DisplayFusionHookAppWIN6064.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Rainmeter\Rainmeter.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET 4.0\EMET_Agent.exe
(Skype Technologies S.A.) C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) A:\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Matthew01_2\Desktop\FRST64 (1).exe
 
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
HKLM\...\Run: [samsungRapidApp] - C:\Program Files (x86)\RAPID\CacheFilter\SamsungRapidApp.exe [109280 2013-07-29] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [sunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [startCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Everything] - "A:\Everything\Everything.exe" -startup
HKLM-x32\...\Run: [EMET Agent] - C:\Program Files (x86)\EMET 4.0\EMET_agent.exe [78496 2013-06-14] (Microsoft Corporation)
HKLM-x32\...\Run: [KeePass 2 PreLoad] - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2092032 2014-02-03] (Dominik Reichl)
HKU\.DEFAULT\...\Policies\system: [DisableChangePassword] 0
HKU\.DEFAULT\...\Policies\system: [DisableLockWorkstation] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [f.lux] - C:\Users\Matthew01_2\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [Gyazo] - C:\Program Files (x86)\Gyazo\GyStation.exe [2990304 2013-10-30] (Nota Inc.)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [WhatPulse] - C:\Program Files (x86)\WhatPulse2\whatpulse.exe [3126272 2013-12-11] ()
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [shotty] - A:\Shotty\Shotty.exe [724480 2013-12-29] (http://shotty.devs-on.net)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [DisplayFusion] - A:\DisplayFusion\DisplayFusion.exe [7952224 2013-11-27] (Binary Fortress Software)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [sandboxieControl] - C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2013-10-16] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [VoxOx] - A:\VoxOx\VoxOx.exe -b
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Run: [KeePass Password Safe 2] - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2092032 2014-02-03] (Dominik Reichl)
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1086244806-2233730069-3771371249-1004\...\MountPoints2: {e6db129c-63ad-11e3-82a8-806e6f6e6963} - "D:\Install Navigator.exe" 
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dxtory.exe (Dxtory Software)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
ShortcutTarget: ERUNT AutoBackup.lnk -> C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mbam.exe (Malwarebytes Corporation)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Omnimo.lnk
ShortcutTarget: Omnimo.lnk -> C:\Users\Matthew01_2\Documents\Rainmeter\Skins\WP7\@Resources\Common\Settings\Omnimo.exe ()
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerMenu.lnk
ShortcutTarget: PowerMenu.lnk -> C:\Program Files (x86)\PowerMenu\PowerMenu.exe (Thong Nguyen)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe ()
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShiftWindow.exe - Shortcut.lnk
ShortcutTarget: ShiftWindow.exe - Shortcut.lnk -> A:\ShiftWindow\ShiftWindow.exe ()
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Skype.exe (Skype Technologies S.A.)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Steam.lnk
ShortcutTarget: Steam.lnk -> A:\Steam\Steam.exe (Valve Corporation)
Startup: C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Thunderbird.lnk
ShortcutTarget: Thunderbird.lnk -> C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)
SSODL-x32: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} -  No File
 
==================== Internet (Whitelisted) ====================
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x16E04B237615CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US,en;q=0.5
BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: No Name - {43D9786F-A485-683B-9B5B-ACC97ABC17FC} -  No File
BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: WSIEChrome - {6D02ED5F-FD0D-4C4C -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: WSIEChrome - {6D02ED5F-FD0D-4C4C -  No File
Hosts: 127.0.0.1            rad.msn.com
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
 
FireFox:
========
FF ProfilePath: C:\Users\Matthew01_2\AppData\Roaming\Mozilla\Firefox\Profiles\fn0utjks.default
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @wolfram.com/Mathematica - C:\Program Files (x86)\Common Files\Wolfram Research\Browser\9.0.1.4092550\npmathplugin.dll (Wolfram Research, Inc.)
FF Plugin-x32: adobe.com/AdobeExManDetect - A:\Dreamweaver\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Matthew01_2\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: Interfaces Downloader - C:\Users\Matthew01_2\AppData\Roaming\Mozilla\Firefox\Profiles\fn0utjks.default\Extensions\interfacesdownloader@tailgate.googlecode.com.xpi [2014-01-18]
FF Extension: Lightbeam - C:\Users\Matthew01_2\AppData\Roaming\Mozilla\Firefox\Profiles\fn0utjks.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2014-01-29]
FF Extension: unedditredditAddon - C:\Users\Matthew01_2\AppData\Roaming\Mozilla\Firefox\Profiles\fn0utjks.default\Extensions\unedditreddit@unedditreddit.com.xpi [2013-12-30]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-11-13]
FF HKLM-x32\...\Firefox\Extensions: [Player@Wondershare.com] - C:\ProgramData\Wondershare\Player\Player@Wondershare.com\
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-11-13]
FF StartMenuInternet: FIREFOX.EXE - A:\Firefox\firefox.exe
 
Chrome: 
=======
CHR Extension: (Duolingo) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2013-11-02]
CHR Extension: (BetterTTV) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2013-10-29]
CHR Extension: (Google Docs) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-29]
CHR Extension: (Google Drive) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-29]
CHR Extension: (YouTube Center Developer Build) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcegdpionpopahcglnfiiioapcclamdj [2014-01-19]
CHR Extension: (YouTube Options) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn [2013-10-29]
CHR Extension: (YouTube) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-29]
CHR Extension: (Adblock Plus) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-10-29]
CHR Extension: (OneTab) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall [2014-03-06]
CHR Extension: (Google Search) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-29]
CHR Extension: (Pandora Listener) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\danjmbbdjabpapehlajpomcignjnoidp [2013-11-17]
CHR Extension: (SoundControl - free for Pandora) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dckjilenognecmpjjpeckgekikdpchli [2013-11-17]
CHR Extension: (Tampermonkey) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2013-10-29]
CHR Extension: (Search All) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\eekjldapjblgadclklmgolijbagmdnfk [2014-02-01]
CHR Extension: (Untamed Now Playing) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\elmdghkkehlmfllejpgikgpjgfalppei [2013-12-30]
CHR Extension: (Pandora) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl [2013-11-17]
CHR Extension: (Twitch Stream) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjaicoojlfoococemdcaollmhaiolole [2014-01-19]
CHR Extension: (Stylish) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2013-12-15]
CHR Extension: (Wolfram|Alpha (Official)) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp [2014-01-30]
CHR Extension: (New Tab Redirect) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna [2013-11-21]
CHR Extension: (Twitch Stream) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce [2014-01-19]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2013-12-25]
CHR Extension: (The Great Suspender) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2014-03-06]
CHR Extension: (Youtube Subscriptions as Default Page) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\klljlfcipmgohgfdgmliaobikgdoeaah [2013-10-29]
CHR Extension: (Auto HD For YouTubeâ„¢) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2013-10-29]
CHR Extension: (Ghostery) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2014-01-19]
CHR Extension: (Google Wallet) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-29]
CHR Extension: (Enhanced Steam) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-02-28]
CHR Extension: (Gmail) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-29]
CHR Extension: (Twitch Giveaways) - C:\Users\Matthew01_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\poohjpljfecljomfhhimjhddddlidhdd [2013-12-26]
 
==================== Services (Whitelisted) =================
 
R2 DisplayFusionService; A:\DisplayFusion\DisplayFusionService.exe [1375600 2013-11-27] (Binary Fortress Software)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-02-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-02-21] (Malwarebytes Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2014-02-16] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc.)
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [27360 2013-07-29] (Samsung Electronics Co., Ltd.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC)
R2 sesvc; C:\Program Files (x86)\ShadowExplorer\sesvc.exe [9216 2013-01-02] (www.shadowexplorer.com)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-22] (Advanced Micro Devices, Inc.)
R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-22] (Advanced Micro Devices)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Windows ® Win 7 DDK provider)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfw; C:\Windows\system32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2013-12-16] (REALiX)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-09] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-10] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-02-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-03-07] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-02-21] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc.)
S3 pwdrvio; C:\WINDOWS\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] ()
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [240864 2013-07-29] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111328 2013-07-29] (Samsung Electronics Co., Ltd.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-25] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [113936 2013-11-01] (Oracle Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 VIAHdAudAddService; \SystemRoot\system32\drivers\viahduaa.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2014-03-07 22:53 - 2014-03-07 22:53 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Downloads\FRST64 (1).exe
2014-03-07 22:53 - 2014-03-07 22:53 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Desktop\FRST64 (1).exe
2014-03-07 22:53 - 2014-03-07 22:53 - 00024084 _____ () C:\Users\Matthew01_2\Desktop\FRST.txt
2014-03-07 22:35 - 2014-03-07 22:37 - 00000000 ____D () C:\Users\Matthew01_2\Desktop\RK_Quarantine
2014-03-07 22:35 - 2014-03-07 22:35 - 04413952 _____ () C:\Users\Matthew01_2\Downloads\RogueKillerX64.exe
2014-03-07 22:31 - 2014-03-07 22:31 - 00000942 _____ () C:\Users\Guest\Desktop\NTREGOPT.lnk
2014-03-07 22:31 - 2014-03-07 22:31 - 00000923 _____ () C:\Users\Guest\Desktop\ERUNT.lnk
2014-03-07 22:31 - 2014-03-07 22:31 - 00000000 ____D () C:\Program Files (x86)\ERUNT
2014-03-07 22:30 - 2014-03-07 22:30 - 00791393 _____ (Lars Hederer ) C:\Users\Matthew01_2\Downloads\erunt-setup.exe
2014-03-07 22:29 - 2014-03-07 22:30 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Matthew01_2\Downloads\rkill.exe
2014-03-03 20:39 - 2014-03-03 20:39 - 00107674 _____ () C:\Users\Matthew01_2\Downloads\Extras.Txt
2014-03-03 20:38 - 2014-03-03 20:39 - 00160778 _____ () C:\Users\Matthew01_2\Downloads\OTL.Txt
2014-03-03 20:27 - 2014-03-03 20:27 - 00602112 _____ (OldTimer Tools) C:\Users\Matthew01_2\Downloads\OTL.exe
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Skype
2014-03-03 20:23 - 2014-03-03 20:24 - 00000000 ____D () C:\AdwCleaner
2014-03-03 20:23 - 2014-03-03 20:23 - 01244192 _____ () C:\Users\Matthew01_2\Downloads\AdwCleaner.exe
2014-03-03 19:23 - 2014-03-03 19:23 - 00987425 _____ () C:\Users\Matthew01_2\Downloads\SecurityCheck.exe
2014-03-03 14:19 - 2014-03-07 21:02 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Euro Truck Simulator
2014-03-03 14:02 - 2014-03-03 14:02 - 00000438 _____ () C:\Windows\PFRO.log
2014-03-02 21:36 - 2014-03-02 21:36 - 01243588 _____ () C:\Users\Matthew01_2\Downloads\ProcessExplorer.zip
2014-03-02 20:21 - 2014-03-07 22:53 - 00000000 ____D () C:\FRST
2014-03-02 20:20 - 2014-03-02 20:20 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Downloads\FRST64.exe
2014-03-02 16:59 - 2014-03-02 16:59 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds (1).scr
2014-03-02 16:56 - 2014-03-02 16:56 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds.scr
2014-03-02 16:56 - 2014-03-02 16:56 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds.com
2014-03-02 16:30 - 2014-03-02 16:31 - 83329736 _____ () C:\Users\Matthew01_2\Downloads\iconpackager_public.exe
2014-03-02 16:29 - 2014-03-02 16:29 - 00623206 _____ () C:\Users\Matthew01_2\Downloads\TokenDark___icons_by_brsev___by_naymlezwun.rar
2014-03-02 05:03 - 2014-03-02 05:03 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-02 05:03 - 2014-03-02 05:03 - 00000000 _____ () C:\Windows\setupact.log
2014-03-02 00:06 - 2014-03-02 00:06 - 00186318 _____ () C:\Users\Matthew01_2\Downloads\notes_by_easy_art-d33ki08.rmskin
2014-03-02 00:05 - 2014-03-02 00:05 - 01470335 _____ () C:\Users\Matthew01_2\Downloads\notes_plus_for_rainmeter_by_charliedogfhhfd-d4fiba3.rmskin
2014-03-02 00:03 - 2014-03-02 00:03 - 00850168 _____ () C:\Users\Matthew01_2\Downloads\muji_tasknote_by_activecolors-d6bf31b.rmskin
2014-03-02 00:02 - 2014-03-02 00:02 - 00563264 _____ () C:\Users\Matthew01_2\Downloads\scrolltext2_for_rm_by_eclectic_tech-d6oqvnq.rmskin
2014-03-02 00:01 - 2014-03-02 00:01 - 00328414 _____ () C:\Users\Matthew01_2\Downloads\blackboardteach_by_amadis33-d5f9m8n.rmskin
2014-03-01 23:59 - 2014-03-01 23:59 - 00108764 _____ () C:\Users\Matthew01_2\Downloads\note_paper_1_1_by_sa3er-d6hmlfd.rmskin
2014-03-01 23:47 - 2014-03-07 21:10 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-01 23:47 - 2014-03-01 23:47 - 16555688 _____ (Malwarebytes Corporation ) C:\Users\Matthew01_2\Downloads\mbam-setup-2.0.0.504.exe
2014-03-01 23:47 - 2014-03-01 23:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-01 23:47 - 2014-02-21 14:55 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-01 22:04 - 2014-03-01 22:04 - 00092052 _____ () C:\Users\Matthew01_2\Downloads\Pandora_Player.rar
2014-03-01 18:42 - 2014-03-01 23:27 - 00000000 ____D () C:\Program Files (x86)\PowerMenu
2014-03-01 18:42 - 2014-03-01 18:42 - 00112582 _____ () C:\Users\Matthew01_2\Downloads\PowerMenuSetup_1_5_1.exe
2014-03-01 16:39 - 2014-03-01 16:39 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Facepalm Games
2014-03-01 16:22 - 2014-03-01 16:22 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\BridgeProject
2014-02-28 15:59 - 2014-02-28 15:59 - 00129837 _____ () C:\Users\Matthew01_2\Downloads\wildlifepark3_windows_1388183454.zip.torrent
2014-02-27 22:10 - 2014-02-27 22:14 - 216141824 _____ () C:\Users\Matthew01_2\Downloads\LibreOffice_4.1.5_Win_x86.msi
2014-02-27 20:00 - 2014-02-27 20:00 - 00679696 _____ (Shark Labs) C:\Users\Matthew01_2\Downloads\CFSetup350.exe
2014-02-23 17:59 - 2014-02-23 17:59 - 00843976 _____ () C:\Users\Matthew01_2\Downloads\Chatty_0.6.zip
2014-02-22 22:29 - 2014-02-22 22:29 - 01054064 _____ (Amazon Services LLC) C:\Users\Matthew01_2\Downloads\Guns_of_Icarus_Online_Online_Game_Code_Downloader.exe
2014-02-22 17:04 - 2014-02-22 17:04 - 00190686 _____ () C:\Users\Matthew01_2\Downloads\mailbox_alert-0.16.4-sm+tb.xpi
2014-02-21 20:02 - 2014-02-21 20:02 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\SWTOR
2014-02-21 14:30 - 2014-03-07 20:04 - 01410394 _____ () C:\Windows\WindowsUpdate.log
2014-02-20 21:46 - 2014-02-20 21:46 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-02-20 21:46 - 2014-02-20 21:46 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\SWTORPerf
2014-02-20 21:39 - 2014-02-20 21:40 - 00015678 _____ () C:\Users\Matthew01_2\Documents\Install STAR WARS The Old Republic.log
2014-02-20 16:21 - 2014-02-20 16:22 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Guacamelee
2014-02-19 14:56 - 2014-02-19 14:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Unity
2014-02-19 14:52 - 2014-02-19 14:52 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Unity
2014-02-18 23:00 - 2014-02-18 23:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\be.gip.twitch.chat.TwitchChatOAuth
2014-02-18 23:00 - 2014-02-18 23:00 - 00000000 ____D () C:\Program Files (x86)\Air
2014-02-18 22:51 - 2014-02-23 17:45 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\HexChat
2014-02-16 18:57 - 2014-02-16 18:57 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\onOne Software
2014-02-16 10:56 - 2014-02-16 10:56 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Battlefield 3
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\PunkBuster
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\ESN
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-02-16 10:55 - 2014-02-16 10:55 - 00000000 ____D () C:\ProgramData\EA Core
2014-02-16 03:58 - 2014-02-16 10:56 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-02-16 03:58 - 2014-02-16 03:58 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-02-16 03:58 - 2014-02-16 03:58 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-02-16 03:35 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2014-02-15 23:15 - 2014-02-15 23:15 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3
2014-02-15 23:15 - 2014-02-15 23:15 - 00000000 ____D () C:\Users\Matthew01_2\.idlerc
2014-02-15 23:14 - 2014-02-15 23:15 - 00000000 ____D () C:\Python33
2014-02-15 22:35 - 2014-02-18 16:48 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\.purple
2014-02-15 22:22 - 2014-02-15 22:33 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\mIRC
2014-02-15 20:52 - 2014-02-15 20:52 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-02-15 17:59 - 2014-02-15 18:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\TeraCopy
2014-02-15 17:59 - 2014-02-15 17:59 - 00000000 ____D () C:\Program Files\TeraCopy
2014-02-15 17:36 - 2014-02-15 17:36 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Evernote
2014-02-15 16:42 - 2014-02-15 16:49 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Dexpot
2014-02-15 16:41 - 2014-02-15 16:41 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\qBittorrent
2014-02-15 16:40 - 2014-02-28 16:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\qBittorrent
2014-02-15 14:19 - 2014-02-16 10:54 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Origin
2014-02-15 14:19 - 2014-02-16 00:13 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Origin
2014-02-15 14:18 - 2014-02-15 14:18 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-02-14 22:02 - 2014-01-07 17:46 - 00325464 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2014-02-14 22:02 - 2014-01-07 17:41 - 01530712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-02-14 22:02 - 2014-01-07 17:41 - 00382808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-02-14 22:02 - 2014-01-04 07:54 - 00138240 _____ () C:\Windows\system32\OEMLicense.dll
2014-02-14 22:02 - 2014-01-04 07:08 - 00103936 _____ () C:\Windows\SysWOW64\OEMLicense.dll
2014-02-14 22:02 - 2014-01-04 06:08 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll
2014-02-14 22:02 - 2014-01-04 05:53 - 00174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll
2014-02-14 22:02 - 2014-01-02 15:54 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-02-14 22:02 - 2014-01-02 15:48 - 00336896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-02-14 22:02 - 2014-01-02 15:40 - 05770752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-02-14 22:02 - 2014-01-02 15:38 - 06640640 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-02-14 22:02 - 2013-12-31 17:55 - 01720560 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-02-14 22:02 - 2013-12-31 17:52 - 00481944 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2014-02-14 22:02 - 2013-12-31 16:56 - 01472048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-02-14 22:02 - 2013-12-31 16:55 - 00381168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2014-02-14 22:02 - 2013-12-31 15:59 - 00802816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2014-02-14 22:02 - 2013-12-31 15:57 - 01214976 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-02-14 22:02 - 2013-12-31 15:56 - 00960512 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2014-02-14 22:02 - 2013-12-30 15:34 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sti.dll
2014-02-14 22:02 - 2013-12-30 15:33 - 00770560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2014-02-14 22:02 - 2013-12-30 15:32 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\sti.dll
2014-02-14 22:02 - 2013-12-30 15:31 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2014-02-14 22:02 - 2013-12-30 15:31 - 00914944 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-02-14 22:02 - 2013-12-27 07:09 - 00419160 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-02-14 22:02 - 2013-12-27 02:38 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-02-14 22:02 - 2013-12-27 00:57 - 00842752 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll
2014-02-14 22:02 - 2013-12-27 00:57 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2014-02-14 22:02 - 2013-12-27 00:23 - 00749056 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2014-02-14 22:02 - 2013-12-27 00:16 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-02-14 22:02 - 2013-12-26 23:03 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll
2014-02-14 22:02 - 2013-12-26 23:03 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2014-02-14 22:02 - 2013-12-26 22:37 - 00588800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2014-02-14 22:02 - 2013-12-20 23:21 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2014-02-14 22:02 - 2013-12-16 23:21 - 00408576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2014-02-14 22:02 - 2013-12-13 22:31 - 13949440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2014-02-14 22:02 - 2013-12-13 22:19 - 18576384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2014-02-14 22:02 - 2013-12-13 02:54 - 00131160 _____ (Microsoft Corporation) C:\Windows\system32\easinvoker.exe
2014-02-14 22:02 - 2013-12-12 23:24 - 00121088 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2014-02-14 22:02 - 2013-12-12 22:36 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll
2014-02-14 22:02 - 2013-12-12 21:32 - 00140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll
2014-02-14 22:02 - 2013-12-09 00:05 - 21199256 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-02-14 22:02 - 2013-12-08 20:51 - 18643560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-02-14 22:02 - 2013-12-08 19:25 - 04190720 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-02-14 13:08 - 2014-02-14 13:08 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\PDAppFlex
2014-02-12 15:00 - 2014-02-14 13:11 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-02-12 15:00 - 2014-02-12 15:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Opera Software
2014-02-12 15:00 - 2014-02-12 15:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Opera Software
2014-02-11 14:34 - 2014-02-06 04:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-11 14:34 - 2014-02-06 03:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-11 14:34 - 2014-02-06 03:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-11 14:34 - 2014-02-06 03:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-11 14:34 - 2014-02-06 03:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-11 14:34 - 2014-02-06 03:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-11 14:34 - 2014-02-06 02:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-11 14:34 - 2014-02-06 02:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-11 14:34 - 2014-02-06 02:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-11 14:34 - 2014-02-06 02:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-11 14:34 - 2014-02-06 02:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-11 14:34 - 2014-02-06 02:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-11 14:34 - 2014-02-06 02:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-11 14:34 - 2014-02-06 02:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-11 14:34 - 2014-02-06 02:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-11 14:34 - 2014-02-06 02:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-11 14:34 - 2014-02-06 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-11 14:34 - 2014-02-06 02:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-11 14:34 - 2014-02-06 01:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-11 14:34 - 2014-02-06 01:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-11 14:34 - 2014-02-06 01:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-11 14:34 - 2014-02-06 01:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-11 14:34 - 2014-02-06 01:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-11 14:34 - 2014-02-06 01:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-11 14:34 - 2014-02-06 01:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-11 14:34 - 2014-02-06 01:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-11 14:34 - 2014-02-06 01:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-11 14:34 - 2014-02-06 01:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-11 14:34 - 2014-02-06 01:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-11 14:34 - 2014-02-06 01:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-11 14:34 - 2014-02-06 01:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-11 14:34 - 2014-02-06 01:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-11 14:34 - 2014-02-06 00:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-11 14:34 - 2014-02-06 00:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-11 14:34 - 2014-02-06 00:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-11 14:34 - 2014-02-06 00:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-11 14:34 - 2014-02-06 00:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-11 14:33 - 2014-01-06 21:00 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-11 14:33 - 2014-01-06 20:30 - 02071552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-11 14:33 - 2013-12-08 16:27 - 02152448 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-11 14:33 - 2013-12-08 16:19 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-11 14:33 - 2013-12-08 15:55 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-11 14:33 - 2013-12-08 15:54 - 01317376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-11 14:33 - 2013-11-20 22:42 - 04604416 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-11 14:33 - 2013-11-20 21:44 - 03936256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-11 14:28 - 2014-01-04 06:30 - 13209088 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-02-11 14:28 - 2014-01-04 06:23 - 11702272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-02-11 14:28 - 2014-01-04 05:40 - 07416832 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2014-02-11 14:27 - 2014-01-09 00:25 - 02804224 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-02-11 14:27 - 2014-01-08 23:59 - 01020928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-02-11 14:27 - 2014-01-08 23:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll
2014-02-11 14:27 - 2014-01-08 23:49 - 00919040 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-02-11 14:27 - 2014-01-08 23:44 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-02-11 14:27 - 2014-01-08 23:43 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll
2014-02-11 14:27 - 2014-01-08 23:29 - 00105984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll
2014-02-11 14:27 - 2014-01-08 23:28 - 04217344 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-02-11 14:27 - 2014-01-08 23:28 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2014-02-11 14:27 - 2014-01-08 23:18 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
2014-02-11 14:27 - 2014-01-06 23:03 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\pcaui.exe
2014-02-11 14:27 - 2014-01-06 21:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pcaui.exe
2014-02-11 14:27 - 2014-01-04 12:50 - 01462216 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-02-11 14:27 - 2014-01-04 11:22 - 01202888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-02-11 14:27 - 2014-01-04 05:42 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-02-11 14:27 - 2014-01-04 05:36 - 00830976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-02-11 14:27 - 2014-01-04 05:28 - 04961792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2014-02-11 14:27 - 2013-12-20 18:10 - 00009701 _____ () C:\Windows\SysWOW64\connectedsearch-results.searchconnector-ms
2014-02-11 14:27 - 2013-12-20 18:10 - 00009701 _____ () C:\Windows\system32\connectedsearch-results.searchconnector-ms
2014-02-11 14:27 - 2013-12-20 02:10 - 01113040 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-02-11 14:27 - 2013-12-19 22:13 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-02-11 14:27 - 2013-12-08 18:57 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-11 14:27 - 2013-12-08 17:51 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-08 23:55 - 2014-02-08 23:58 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\AcePatrol2
2014-02-08 23:55 - 2014-02-08 23:55 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00122904 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00109080 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2014-02-06 13:45 - 2014-02-06 13:46 - 00000000 ____D () C:\Steam
2014-02-05 14:40 - 2014-02-05 14:58 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Sites
2014-02-05 14:37 - 2014-02-05 14:37 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-02-05 14:24 - 2014-02-05 14:24 - 00000000 ____D () C:\Windows\XSxS
 
==================== One Month Modified Files and Folders =======
 
2014-03-07 22:54 - 2013-12-21 14:39 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\WhatPulse
2014-03-07 22:53 - 2014-03-07 22:53 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Downloads\FRST64 (1).exe
2014-03-07 22:53 - 2014-03-07 22:53 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Desktop\FRST64 (1).exe
2014-03-07 22:53 - 2014-03-07 22:53 - 00024084 _____ () C:\Users\Matthew01_2\Desktop\FRST.txt
2014-03-07 22:53 - 2014-03-02 20:21 - 00000000 ____D () C:\FRST
2014-03-07 22:51 - 2014-01-11 18:17 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\DisplayFusion
2014-03-07 22:44 - 2013-10-29 14:04 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Skype
2014-03-07 22:43 - 2013-11-26 14:12 - 00000938 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1ceeaf4957a29c8.job
2014-03-07 22:38 - 2013-11-07 14:21 - 00003978 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{2B960C1B-1F4E-471A-81FD-7E523F049F77}
2014-03-07 22:37 - 2014-03-07 22:35 - 00000000 ____D () C:\Users\Matthew01_2\Desktop\RK_Quarantine
2014-03-07 22:36 - 2013-10-29 14:52 - 00000000 ____D () C:\Users\Matthew01_2\Desktop\All Files
2014-03-07 22:36 - 2013-10-29 14:04 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1086244806-2233730069-3771371249-1004
2014-03-07 22:35 - 2014-03-07 22:35 - 04413952 _____ () C:\Users\Matthew01_2\Downloads\RogueKillerX64.exe
2014-03-07 22:31 - 2014-03-07 22:31 - 00000942 _____ () C:\Users\Guest\Desktop\NTREGOPT.lnk
2014-03-07 22:31 - 2014-03-07 22:31 - 00000923 _____ () C:\Users\Guest\Desktop\ERUNT.lnk
2014-03-07 22:31 - 2014-03-07 22:31 - 00000000 ____D () C:\Program Files (x86)\ERUNT
2014-03-07 22:31 - 2013-10-29 13:59 - 00000000 ___RD () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-07 22:30 - 2014-03-07 22:30 - 00791393 _____ (Lars Hederer ) C:\Users\Matthew01_2\Downloads\erunt-setup.exe
2014-03-07 22:30 - 2014-03-07 22:29 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\Matthew01_2\Downloads\rkill.exe
2014-03-07 22:00 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\system32\sru
2014-03-07 21:10 - 2014-03-01 23:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-07 21:02 - 2014-03-03 14:19 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Euro Truck Simulator
2014-03-07 20:04 - 2014-02-21 14:30 - 01410394 _____ () C:\Windows\WindowsUpdate.log
2014-03-07 19:43 - 2013-11-26 14:12 - 00000934 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1ceeaf4955c36c4.job
2014-03-07 19:11 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-03-07 17:54 - 2013-12-30 22:48 - 00000063 _____ () C:\Users\Matthew01_2\Documents\unp_now_playing.txt
2014-03-07 15:49 - 2013-09-29 20:04 - 00863592 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-07 15:44 - 2013-10-29 14:35 - 00000000 __RDO () C:\Users\Matthew01_2\SkyDrive
2014-03-07 15:43 - 2013-08-22 06:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-06 22:02 - 2013-11-29 23:14 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\KeePass
2014-03-05 21:23 - 2013-12-26 21:01 - 00000000 ____D () C:\Users\Matthew01_2\.chatty
2014-03-05 21:23 - 2013-08-22 05:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-03-03 20:39 - 2014-03-03 20:39 - 00107674 _____ () C:\Users\Matthew01_2\Downloads\Extras.Txt
2014-03-03 20:39 - 2014-03-03 20:38 - 00160778 _____ () C:\Users\Matthew01_2\Downloads\OTL.Txt
2014-03-03 20:27 - 2014-03-03 20:27 - 00602112 _____ (OldTimer Tools) C:\Users\Matthew01_2\Downloads\OTL.exe
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-03 20:26 - 2014-03-03 20:26 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Skype
2014-03-03 20:26 - 2013-10-19 12:14 - 00000000 ____D () C:\ProgramData\Skype
2014-03-03 20:24 - 2014-03-03 20:23 - 00000000 ____D () C:\AdwCleaner
2014-03-03 20:23 - 2014-03-03 20:23 - 01244192 _____ () C:\Users\Matthew01_2\Downloads\AdwCleaner.exe
2014-03-03 19:23 - 2014-03-03 19:23 - 00987425 _____ () C:\Users\Matthew01_2\Downloads\SecurityCheck.exe
2014-03-03 14:19 - 2014-01-28 17:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\CrashDumps
2014-03-03 14:16 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-03 14:02 - 2014-03-03 14:02 - 00000438 _____ () C:\Windows\PFRO.log
2014-03-02 21:36 - 2014-03-02 21:36 - 01243588 _____ () C:\Users\Matthew01_2\Downloads\ProcessExplorer.zip
2014-03-02 20:20 - 2014-03-02 20:20 - 02156544 _____ (Farbar) C:\Users\Matthew01_2\Downloads\FRST64.exe
2014-03-02 16:59 - 2014-03-02 16:59 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds (1).scr
2014-03-02 16:56 - 2014-03-02 16:56 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds.scr
2014-03-02 16:56 - 2014-03-02 16:56 - 00688992 _____ (Swearware) C:\Users\Matthew01_2\Downloads\dds.com
2014-03-02 16:31 - 2014-03-02 16:30 - 83329736 _____ () C:\Users\Matthew01_2\Downloads\iconpackager_public.exe
2014-03-02 16:29 - 2014-03-02 16:29 - 00623206 _____ () C:\Users\Matthew01_2\Downloads\TokenDark___icons_by_brsev___by_naymlezwun.rar
2014-03-02 05:03 - 2014-03-02 05:03 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-02 05:03 - 2014-03-02 05:03 - 00000000 _____ () C:\Windows\setupact.log
2014-03-02 00:06 - 2014-03-02 00:06 - 00186318 _____ () C:\Users\Matthew01_2\Downloads\notes_by_easy_art-d33ki08.rmskin
2014-03-02 00:05 - 2014-03-02 00:05 - 01470335 _____ () C:\Users\Matthew01_2\Downloads\notes_plus_for_rainmeter_by_charliedogfhhfd-d4fiba3.rmskin
2014-03-02 00:03 - 2014-03-02 00:03 - 00850168 _____ () C:\Users\Matthew01_2\Downloads\muji_tasknote_by_activecolors-d6bf31b.rmskin
2014-03-02 00:02 - 2014-03-02 00:02 - 00563264 _____ () C:\Users\Matthew01_2\Downloads\scrolltext2_for_rm_by_eclectic_tech-d6oqvnq.rmskin
2014-03-02 00:02 - 2013-10-29 14:07 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Rainmeter
2014-03-02 00:01 - 2014-03-02 00:01 - 00328414 _____ () C:\Users\Matthew01_2\Downloads\blackboardteach_by_amadis33-d5f9m8n.rmskin
2014-03-01 23:59 - 2014-03-01 23:59 - 00108764 _____ () C:\Users\Matthew01_2\Downloads\note_paper_1_1_by_sa3er-d6hmlfd.rmskin
2014-03-01 23:47 - 2014-03-01 23:47 - 16555688 _____ (Malwarebytes Corporation ) C:\Users\Matthew01_2\Downloads\mbam-setup-2.0.0.504.exe
2014-03-01 23:47 - 2014-03-01 23:47 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-01 23:47 - 2013-11-08 22:05 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Malwarebytes
2014-03-01 23:47 - 2013-10-19 12:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-01 23:27 - 2014-03-01 18:42 - 00000000 ____D () C:\Program Files (x86)\PowerMenu
2014-03-01 22:04 - 2014-03-01 22:04 - 00092052 _____ () C:\Users\Matthew01_2\Downloads\Pandora_Player.rar
2014-03-01 18:42 - 2014-03-01 18:42 - 00112582 _____ () C:\Users\Matthew01_2\Downloads\PowerMenuSetup_1_5_1.exe
2014-03-01 16:39 - 2014-03-01 16:39 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Facepalm Games
2014-03-01 16:22 - 2014-03-01 16:22 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\BridgeProject
2014-02-28 16:00 - 2014-02-15 16:40 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\qBittorrent
2014-02-28 15:59 - 2014-02-28 15:59 - 00129837 _____ () C:\Users\Matthew01_2\Downloads\wildlifepark3_windows_1388183454.zip.torrent
2014-02-27 23:31 - 2013-10-30 15:45 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\Adobe
2014-02-27 23:28 - 2013-11-30 23:50 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Dxtory Software
2014-02-27 23:27 - 2013-12-22 17:31 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-02-27 23:27 - 2013-10-29 13:59 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Adobe
2014-02-27 23:26 - 2013-12-22 17:31 - 00000000 ____D () C:\ProgramData\Adobe
2014-02-27 22:14 - 2014-02-27 22:10 - 216141824 _____ () C:\Users\Matthew01_2\Downloads\LibreOffice_4.1.5_Win_x86.msi
2014-02-27 20:00 - 2014-02-27 20:00 - 00679696 _____ (Shark Labs) C:\Users\Matthew01_2\Downloads\CFSetup350.exe
2014-02-27 16:29 - 2013-12-22 17:30 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Adobe
2014-02-24 13:54 - 2013-08-22 06:44 - 00428104 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-23 17:59 - 2014-02-23 17:59 - 00843976 _____ () C:\Users\Matthew01_2\Downloads\Chatty_0.6.zip
2014-02-23 17:45 - 2014-02-18 22:51 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\HexChat
2014-02-22 22:29 - 2014-02-22 22:29 - 01054064 _____ (Amazon Services LLC) C:\Users\Matthew01_2\Downloads\Guns_of_Icarus_Online_Online_Game_Code_Downloader.exe
2014-02-22 19:57 - 2013-10-29 14:19 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Paint.NET
2014-02-22 17:04 - 2014-02-22 17:04 - 00190686 _____ () C:\Users\Matthew01_2\Downloads\mailbox_alert-0.16.4-sm+tb.xpi
2014-02-21 20:02 - 2014-02-21 20:02 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\SWTOR
2014-02-21 14:55 - 2014-03-01 23:47 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-02-21 14:55 - 2013-11-16 16:08 - 00092376 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-02-21 14:55 - 2013-10-19 12:38 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-20 21:46 - 2014-02-20 21:46 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-02-20 21:46 - 2014-02-20 21:46 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\SWTORPerf
2014-02-20 21:40 - 2014-02-20 21:39 - 00015678 _____ () C:\Users\Matthew01_2\Documents\Install STAR WARS The Old Republic.log
2014-02-20 18:14 - 2013-11-22 20:33 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\.minecraft
2014-02-20 16:22 - 2014-02-20 16:21 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Guacamelee
2014-02-19 18:50 - 2014-01-26 16:18 - 00000000 ____D () C:\Users\Guest\AppData\Roaming\DisplayFusion
2014-02-19 18:44 - 2013-10-30 15:45 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-19 18:44 - 2013-10-30 15:45 - 00000000 ___RD () C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-02-19 14:56 - 2014-02-19 14:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Unity
2014-02-19 14:52 - 2014-02-19 14:52 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Unity
2014-02-18 23:00 - 2014-02-18 23:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\be.gip.twitch.chat.TwitchChatOAuth
2014-02-18 23:00 - 2014-02-18 23:00 - 00000000 ____D () C:\Program Files (x86)\Air
2014-02-18 17:58 - 2013-11-29 23:01 - 00000000 ____D () C:\ProgramData\Origin
2014-02-18 16:48 - 2014-02-15 22:35 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\.purple
2014-02-17 13:00 - 2013-08-22 07:38 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-17 13:00 - 2013-08-22 07:38 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-16 18:57 - 2014-02-16 18:57 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\onOne Software
2014-02-16 18:57 - 2013-11-04 13:38 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-02-16 10:56 - 2014-02-16 10:56 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Battlefield 3
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\PunkBuster
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\ESN
2014-02-16 10:56 - 2014-02-16 10:56 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-02-16 10:56 - 2014-02-16 03:58 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-02-16 10:55 - 2014-02-16 10:55 - 00000000 ____D () C:\ProgramData\EA Core
2014-02-16 10:54 - 2014-02-15 14:19 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Origin
2014-02-16 03:58 - 2014-02-16 03:58 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-02-16 03:58 - 2014-02-16 03:58 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-02-16 03:51 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\rescache
2014-02-16 00:13 - 2014-02-15 14:19 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Origin
2014-02-15 23:15 - 2014-02-15 23:15 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.3
2014-02-15 23:15 - 2014-02-15 23:15 - 00000000 ____D () C:\Users\Matthew01_2\.idlerc
2014-02-15 23:15 - 2014-02-15 23:14 - 00000000 ____D () C:\Python33
2014-02-15 23:15 - 2013-10-29 13:59 - 00000000 ____D () C:\Users\Matthew01_2
2014-02-15 22:33 - 2014-02-15 22:22 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\mIRC
2014-02-15 20:52 - 2014-02-15 20:52 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2014-02-15 18:00 - 2014-02-15 17:59 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\TeraCopy
2014-02-15 17:59 - 2014-02-15 17:59 - 00000000 ____D () C:\Program Files\TeraCopy
2014-02-15 17:36 - 2014-02-15 17:36 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Evernote
2014-02-15 16:49 - 2014-02-15 16:42 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Dexpot
2014-02-15 16:41 - 2014-02-15 16:41 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\qBittorrent
2014-02-15 16:41 - 2013-12-08 11:10 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\BitTorrent
2014-02-15 16:25 - 2013-10-20 12:03 - 00000000 ____D () C:\Program Files\CCleaner
2014-02-15 15:15 - 2013-10-19 12:10 - 00000000 ____D () C:\ProgramData\Package Cache
2014-02-15 14:18 - 2014-02-15 14:18 - 00000000 ____D () C:\ProgramData\Electronic Arts
2014-02-15 13:56 - 2013-11-16 16:32 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-02-15 13:41 - 2014-01-18 13:59 - 00000000 ____D () C:\Program Files (x86)\7tsp
2014-02-15 12:53 - 2014-01-26 12:29 - 00000000 ___RD () C:\Users\Matthew01_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-02-15 00:04 - 2013-08-22 07:36 - 00000000 ___RD () C:\Windows\ToastData
2014-02-14 22:04 - 2013-11-12 14:37 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-14 22:03 - 2013-11-12 14:37 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-14 13:11 - 2014-02-12 15:00 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-02-14 13:08 - 2014-02-14 13:08 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\PDAppFlex
2014-02-12 15:00 - 2014-02-12 15:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Roaming\Opera Software
2014-02-12 15:00 - 2014-02-12 15:00 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\Opera Software
2014-02-11 22:39 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-02-11 22:39 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\FileManager
2014-02-11 22:39 - 2013-08-22 07:36 - 00000000 ____D () C:\Windows\Camera
2014-02-11 19:38 - 2013-11-26 14:12 - 00003910 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1ceeaf4957a29c8
2014-02-11 19:38 - 2013-11-26 14:12 - 00003674 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1ceeaf4955c36c4
2014-02-09 13:14 - 2013-12-07 23:04 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\My Games
2014-02-09 13:14 - 2013-10-29 16:58 - 00000000 ____D () C:\Users\Matthew01_2\Documents\My Games
2014-02-08 23:58 - 2014-02-08 23:55 - 00000000 ____D () C:\Users\Matthew01_2\AppData\Local\AcePatrol2
2014-02-08 23:55 - 2014-02-08 23:55 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00122904 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00109080 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2014-02-08 23:55 - 2014-02-08 23:55 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2014-02-06 13:46 - 2014-02-06 13:45 - 00000000 ____D () C:\Steam
2014-02-06 13:39 - 2013-10-19 12:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-06 04:16 - 2014-02-11 14:34 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 03:30 - 2014-02-11 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 03:30 - 2014-02-11 14:34 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 03:12 - 2014-02-11 14:34 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 03:07 - 2014-02-11 14:34 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 03:06 - 2014-02-11 14:34 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 02:57 - 2014-02-11 14:34 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 02:56 - 2014-02-11 14:34 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 02:49 - 2014-02-11 14:34 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 02:48 - 2014-02-11 14:34 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 02:48 - 2014-02-11 14:34 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 02:38 - 2014-02-11 14:34 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 02:32 - 2014-02-11 14:34 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 02:20 - 2014-02-11 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 02:17 - 2014-02-11 14:34 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 02:11 - 2014-02-11 14:34 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 02:01 - 2014-02-11 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 02:00 - 2014-02-11 14:34 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 01:57 - 2014-02-11 14:34 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 01:57 - 2014-02-11 14:34 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 01:52 - 2014-02-11 14:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 01:52 - 2014-02-11 14:34 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 01:50 - 2014-02-11 14:34 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 01:47 - 2014-02-11 14:34 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 01:46 - 2014-02-11 14:34 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 01:25 - 2014-02-11 14:34 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 01:25 - 2014-02-11 14:34 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 01:24 - 2014-02-11 14:34 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 01:22 - 2014-02-11 14:34 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 01:13 - 2014-02-11 14:34 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 01:09 - 2014-02-11 14:34 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 01:03 - 2014-02-11 14:34 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 00:55 - 2014-02-11 14:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 00:41 - 2014-02-11 14:34 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 00:40 - 2014-02-11 14:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 00:36 - 2014-02-11 14:34 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 00:34 - 2014-02-11 14:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-05 14:58 - 2014-02-05 14:40 - 00000000 ____D () C:\Users\Matthew01_2\Documents\Sites
2014-02-05 14:37 - 2014-02-05 14:37 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-02-05 14:24 - 2014-02-05 14:24 - 00000000 ____D () C:\Windows\XSxS
2014-02-05 13:41 - 2014-02-04 18:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
 
Some content of TEMP:
====================
C:\Users\Matthew01_2\AppData\Local\Temp\ntdll_dump.dll
C:\Users\Matthew01_2\AppData\Local\Temp\Quarantine.exe
 
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
 
 
LastRegBack: 2014-03-07 17:00
 
==================== End Of Log ============================
Link to post
Share on other sites

  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.