Jump to content

Plug and Play/DCOM Server terminations causing constant force restarting


Recommended Posts

Hi,

First of all, thanks in advance for any/all help. I really appreciate the time you all spend on helping people.

 

My computer is frequently rebooting due to "plug and play terminating". I even disabled automatic restart on error and my computer still reboots.  I have no rhyme or reason why it reboots, it doesnt seem to correlate to any programs in particular.  It seems ...seems.. to happen slightly more often when im playing Diablo 3, but I can go for hrs and hrs with no reboots at times as well.

I researched a previous topic on this and saw to download FarBar Recovery Scan Tool.  These are the logs after running it.

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-06-2014 01
Ran by JOSHUA LARSEN (administrator) on JOSHUALARSEN-PC on 11-06-2014 21:34:27
Running from C:\Users\JOSHUA LARSEN\Downloads
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\pcreg\pcreg.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(WinZip Computing International, LLC) C:\Program Files\File Association Helper\FAHWindow.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [216248 2013-09-26] (WinZip Computing International, LLC)
HKLM\...\Run: [pcreg] => C:\Program Files\pcreg\service.exe [83416 2014-01-04] ()
HKLM\...\Run: [bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1743088 2014-05-22] (Bitdefender)
HKLM-x32\...\Run: [startCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [pcreg] => C:\Program Files\pcreg\service.exe [83416 2014-01-04] ()
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2014-01-22] (RealNetworks, Inc.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1985824 2013-07-25] (Wondershare)
HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\.DEFAULT\...\Run: [bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-05-22] (Bitdefender)
HKU\.DEFAULT\...\Run: [bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-05-22] (Bitdefender)
HKU\.DEFAULT\...\Run: [bitdefender Wallet Application Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614744 2014-05-22] (Bitdefender)
HKU\.DEFAULT\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2866715121-2728793360-866404133-1000\...\Run: [pcreg] => C:\Program Files\pcreg\service.exe [83416 2014-01-04] ()
HKU\S-1-5-21-2866715121-2728793360-866404133-1000\...\Run: [bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-05-22] (Bitdefender)
HKU\S-1-5-21-2866715121-2728793360-866404133-1000\...\Run: [bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-05-22] (Bitdefender)
HKU\S-1-5-21-2866715121-2728793360-866404133-1000\...\Run: [bitdefender Wallet Application Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614744 2014-05-22] (Bitdefender)
HKU\S-1-5-21-2866715121-2728793360-866404133-1000\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-2866715121-2728793360-866404133-1000\...\MountPoints2: {d4c73feb-7b3d-11e3-b44e-3fcdfd911a80} - H:\setup.exe -a
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0F6A47B762EDCD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=100&itype=n&ver=10572&tm=229&src=ds&p={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=100&itype=n&ver=10572&tm=229&src=ds&p={searchTerms}
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3322968&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP9DB2573A-9C79-4034-8843-85AFABFC18DE&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx?ctid=CT3322968&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP9DB2573A-9C79-4034-8843-85AFABFC18DE&q={searchTerms}&SSPV=
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = http://www.default-search.net/search?sid=476&aid=100&itype=n&ver=10572&tm=229&src=ds&p={searchTerms}
BHO: Bitdefender Wallet  - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender)
BHO: LinkeyBHO - {4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} - C:\PROGRA~2\Linkey\IEEXTE~1\iedll64.dll No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\JOSHUA LARSEN\AppData\Roaming\Mozilla\Firefox\Profiles\ve8ypt89.default-1389993233119
FF Homepage: hxxp://www.yahoo.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @gpac/osmozilla,version=1.0 - C:\Program Files (x86)\GPAC\nposmozilla.dll ( )
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman [2014-01-30]
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-01-30]
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\ []
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-01-22]
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender\bdtbext [2014-01-30]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

==================== Services (Whitelisted) =================

S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [77632 2013-11-21] (Bitdefender)
R2 DcomLaunch; C:\Windows\system32\rpcss.dll [512512 2010-11-20] (Microsoft Corporation) [File not signed]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 pcregservice; C:\Program Files\pcreg\pcreg.exe [33824 2013-12-17] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 RpcSs; C:\Windows\system32\rpcss.dll [512512 2010-11-20] (Microsoft Corporation) [File not signed]
R2 SafeBox; C:\Program Files\Bitdefender\Bitdefender SafeBox\safeboxservice.exe [94624 2013-07-08] (Bitdefender)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2013-10-07] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1526800 2014-05-22] (Bitdefender)

==================== Drivers (Whitelisted) ====================

R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [893440 2013-12-02] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [635392 2013-12-02] (BitDefender)
R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2014-05-22] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-07-02] (Bitdefender SRL)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
R1 BDVEDISK; C:\Windows\System32\DRIVERS\bdvedisk.sys [76944 2012-04-17] (BitDefender)
R3 BfEdge7x64; C:\Windows\System32\DRIVERS\Edge7x64.sys [31336 2011-07-14] (Bigfoot Networks, Inc.)
R3 BFN7x64; C:\Windows\System32\DRIVERS\Xeno7x64.sys [157288 2011-07-14] (Bigfoot Networks, Inc.)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R2 PfFilter; C:\Program Files (x86)\IObit\Protected Folder\pffilter.sys [38392 2012-11-23] (IObit Information Technology)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-08-07] (BitDefender S.R.L.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-11 21:34 - 2014-06-11 21:35 - 00014803 _____ () C:\Users\JOSHUA LARSEN\Downloads\FRST.txt
2014-06-11 21:34 - 2014-06-11 21:34 - 02081792 _____ (Farbar) C:\Users\JOSHUA LARSEN\Downloads\FRST64.exe
2014-06-11 21:34 - 2014-06-11 21:34 - 00000000 ____D () C:\FRST
2014-06-10 12:31 - 2014-06-10 12:31 - 23261563 _____ () C:\Users\JOSHUA LARSEN\Downloads\bw1.flv
2014-06-10 12:31 - 2014-06-10 12:31 - 02253476 _____ () C:\Users\JOSHUA LARSEN\Downloads\upnopanty2.flv
2014-06-10 00:07 - 2014-06-10 00:07 - 02081531 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (51).ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01213155 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG2 5 43 Sun am in shower 0A76A2V2.ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01073891 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (54).ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01069795 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (53).ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01049315 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (44).ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01000157 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (45).ASF
2014-06-10 00:04 - 2014-06-10 00:04 - 03719350 _____ () C:\Users\JOSHUA LARSEN\Downloads\Window_Neighbour.flv
2014-06-10 00:03 - 2014-06-10 00:04 - 82270774 _____ () C:\Users\JOSHUA LARSEN\Downloads\b30.avi
2014-06-10 00:02 - 2014-06-10 00:02 - 04076325 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG11 1 104338 shower squeegee great full frontal.ASF
2014-06-10 00:02 - 2014-06-10 00:02 - 01864437 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG11 1 103931 shower nice labia legs split.ASF
2014-06-09 23:59 - 2014-06-09 23:59 - 15706475 _____ () C:\Users\JOSHUA LARSEN\Downloads\sunburn.flv
2014-06-09 23:58 - 2014-06-10 00:00 - 266826681 _____ () C:\Users\JOSHUA LARSEN\Downloads\Holy grail of pool changing.wmv
2014-06-09 23:58 - 2014-06-09 23:59 - 08599393 _____ () C:\Users\JOSHUA LARSEN\Downloads\caught(1).flv
2014-06-09 22:27 - 2014-06-09 22:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-06-09 22:27 - 2014-06-09 22:27 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-06-06 10:19 - 2014-06-06 10:20 - 177339443 _____ () C:\Users\JOSHUA LARSEN\Downloads\WP_20131110_21_35_53_Pro.mp4
2014-06-06 10:19 - 2014-06-06 10:20 - 05849452 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 06.mp4
2014-06-06 10:17 - 2014-06-06 10:17 - 24320811 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2167.wmv
2014-06-06 10:17 - 2014-06-06 10:17 - 03999533 _____ () C:\Users\JOSHUA LARSEN\Downloads\my-gfs-sister.mp4
2014-06-05 11:09 - 2014-06-05 11:10 - 202260067 _____ () C:\Users\JOSHUA LARSEN\Downloads\tre00056734(1).mov
2014-06-05 11:06 - 2014-06-05 11:06 - 15773351 _____ () C:\Users\JOSHUA LARSEN\Downloads\WP_20131110_23_30_48_Pro.mp4
2014-06-05 11:05 - 2014-06-05 11:05 - 14550318 _____ () C:\Users\JOSHUA LARSEN\Downloads\Sister_shwr.flv
2014-06-05 11:05 - 2014-06-05 11:05 - 05987730 _____ () C:\Users\JOSHUA LARSEN\Downloads\Uniform.avi
2014-06-05 11:00 - 2014-06-05 11:00 - 24386640 _____ () C:\Users\JOSHUA LARSEN\Downloads\tvf_show_spy2141.avi
2014-06-05 11:00 - 2014-06-05 11:00 - 10964307 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2092.wmv
2014-06-05 11:00 - 2014-06-05 11:00 - 10953688 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1858.flv
2014-06-03 10:37 - 2014-06-03 10:37 - 17782770 _____ () C:\Users\JOSHUA LARSEN\Downloads\mom_spy_cam.avi
2014-06-03 10:25 - 2014-06-03 10:27 - 170035338 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1449.avi
2014-06-03 10:25 - 2014-06-03 10:27 - 153948176 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1444.avi
2014-06-03 01:19 - 2014-06-03 01:19 - 01086016 _____ () C:\Users\JOSHUA LARSEN\Downloads\SIL_Shower.flv
2014-06-03 01:18 - 2014-06-03 01:19 - 86171652 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2029.mpg
2014-06-03 01:18 - 2014-06-03 01:19 - 35462588 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1964.avi
2014-06-01 23:23 - 2014-06-01 23:25 - 102288922 _____ () C:\Users\JOSHUA LARSEN\Downloads\wetteacher-02.avi
2014-06-01 23:23 - 2014-06-01 23:24 - 76242846 _____ () C:\Users\JOSHUA LARSEN\Downloads\wetteacher-01.avi
2014-06-01 23:23 - 2014-06-01 23:24 - 31369846 _____ () C:\Users\JOSHUA LARSEN\Downloads\murziq_sm09-22.avi
2014-06-01 21:01 - 2014-06-01 21:01 - 00860531 _____ () C:\Users\JOSHUA LARSEN\Downloads\caught in shower.mp4
2014-05-31 14:11 - 2014-05-31 14:11 - 42428474 _____ () C:\Users\JOSHUA LARSEN\Downloads\CS-CUT.avi
2014-05-31 14:11 - 2014-05-31 14:11 - 16612632 _____ () C:\Users\JOSHUA LARSEN\Downloads\wolter_downblouse_257.avi
2014-05-31 14:10 - 2014-05-31 14:11 - 136402537 _____ () C:\Users\JOSHUA LARSEN\Downloads\Hot rehead nice pussy view.wmv
2014-05-31 14:10 - 2014-05-31 14:10 - 48338393 _____ () C:\Users\JOSHUA LARSEN\Downloads\Yellow bottom perfect teen.wmv
2014-05-31 14:09 - 2014-05-31 14:10 - 33628189 _____ () C:\Users\JOSHUA LARSEN\Downloads\Intense clit orgasm with two vibrators.mp4
2014-05-31 14:09 - 2014-05-31 14:10 - 21920176 _____ () C:\Users\JOSHUA LARSEN\Downloads\Capture_20101003.mp4
2014-05-31 14:05 - 2014-05-31 14:09 - 277522791 _____ () C:\Users\JOSHUA LARSEN\Downloads\kt2.mp4
2014-05-31 14:05 - 2014-05-31 14:08 - 178636160 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1458.avi
2014-05-31 14:05 - 2014-05-31 14:07 - 156390338 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1440.avi
2014-05-31 14:05 - 2014-05-31 14:05 - 18657619 _____ () C:\Users\JOSHUA LARSEN\Downloads\a_real_video_from_a_very_hairy_american_girl.flv
2014-05-29 22:14 - 2014-05-29 22:16 - 125366770 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1442.avi
2014-05-29 22:10 - 2014-05-29 22:10 - 00277960 _____ () C:\Windows\Minidump\052914-21684-01.dmp
2014-05-28 22:54 - 2014-05-28 22:54 - 71718912 _____ () C:\Users\JOSHUA LARSEN\Downloads\Orgasm Contractions.mpg
2014-05-28 22:54 - 2014-05-28 22:54 - 50615618 _____ () C:\Users\JOSHUA LARSEN\Downloads\tumblr_lpmlih42Cw1qju8nw.mp4
2014-05-28 22:54 - 2014-05-28 22:54 - 19254700 _____ () C:\Users\JOSHUA LARSEN\Downloads\6631S4rOhJM.avi
2014-05-28 22:54 - 2014-05-28 22:54 - 17385155 _____ () C:\Users\JOSHUA LARSEN\Downloads\tumblr_loyh4ajaWL1qg2upe_r1.mov
2014-05-28 22:54 - 2014-05-28 22:54 - 10958094 _____ () C:\Users\JOSHUA LARSEN\Downloads\22yearoldwife3b_161.wmv
2014-05-28 22:54 - 2014-05-28 22:54 - 08847986 _____ () C:\Users\JOSHUA LARSEN\Downloads\135475_genuine_orgasm_contractions.mp4
2014-05-28 20:45 - 2014-05-28 20:45 - 00000000 ____D () C:\Windows\Sun
2014-05-28 20:45 - 2014-05-28 20:45 - 00000000 ____D () C:\Users\JOSHUA LARSEN\AppData\Roaming\Oracle
2014-05-28 20:44 - 2014-05-28 20:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-28 20:44 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-28 20:44 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-28 20:44 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-28 20:44 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-28 20:43 - 2014-05-28 20:44 - 00004430 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-28 14:03 - 2014-05-28 14:03 - 00011921 _____ () C:\Users\JOSHUA LARSEN\AppData\Local\recently-used.xbel
2014-05-28 09:35 - 2014-05-28 09:35 - 10823057 _____ () C:\Users\JOSHUA LARSEN\Downloads\bouncy.mp4
2014-05-28 09:34 - 2014-05-28 09:34 - 51187676 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2116.avi
2014-05-28 09:34 - 2014-05-28 09:34 - 37831187 _____ () C:\Users\JOSHUA LARSEN\Downloads\gsbeach1.wmv
2014-05-27 23:39 - 2014-05-27 23:39 - 00928564 _____ () C:\Users\JOSHUA LARSEN\Downloads\wedgie.mp4
2014-05-27 23:39 - 2014-05-27 23:39 - 00875576 _____ () C:\Users\JOSHUA LARSEN\Downloads\Pantsed.avi
2014-05-27 23:39 - 2014-05-27 23:39 - 00804954 _____ () C:\Users\JOSHUA LARSEN\Downloads\bikini oops.mp4
2014-05-27 23:38 - 2014-05-27 23:38 - 09182284 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 05.mp4
2014-05-27 23:35 - 2014-05-27 23:35 - 62095360 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1649.avi
2014-05-27 23:35 - 2014-05-27 23:35 - 01929366 _____ () C:\Users\JOSHUA LARSEN\Downloads\milfs-in-shower-3.mp4
2014-05-27 23:34 - 2014-05-27 23:35 - 88610820 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1768.mpg
2014-05-27 23:34 - 2014-05-27 23:35 - 60395542 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2366.avi
2014-05-27 23:34 - 2014-05-27 23:35 - 37115012 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2218.avi
2014-05-27 23:34 - 2014-05-27 23:35 - 17593552 _____ () C:\Users\JOSHUA LARSEN\Downloads\dark-bush-in-shower.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 15255050 _____ () C:\Users\JOSHUA LARSEN\Downloads\zc.wmv
2014-05-27 23:34 - 2014-05-27 23:34 - 15216736 _____ () C:\Users\JOSHUA LARSEN\Downloads\zu.wmv
2014-05-27 23:34 - 2014-05-27 23:34 - 12622000 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-1.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 09673178 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2132.mov
2014-05-27 23:34 - 2014-05-27 23:34 - 09416260 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-2.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 09005592 _____ () C:\Users\JOSHUA LARSEN\Downloads\spycam-in-shower-2.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 06698000 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-4.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 05863520 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-3.mp4
2014-05-27 23:33 - 2014-05-27 23:34 - 09572649 _____ () C:\Users\JOSHUA LARSEN\Downloads\my-sister-anya-1.mp4
2014-05-27 23:33 - 2014-05-27 23:34 - 08522932 _____ () C:\Users\JOSHUA LARSEN\Downloads\spycam-in-shower-1.mp4
2014-05-27 23:33 - 2014-05-27 23:33 - 09032330 _____ () C:\Users\JOSHUA LARSEN\Downloads\shower-clock-hidden-camera-voyeur-3.mp4
2014-05-27 23:33 - 2014-05-27 23:33 - 06987794 _____ () C:\Users\JOSHUA LARSEN\Downloads\shower-clock-hidden-camera-voyeur-1.mp4
2014-05-27 23:33 - 2014-05-27 23:33 - 04300853 _____ () C:\Users\JOSHUA LARSEN\Downloads\shower-clock-hidden-camera-voyeur-2.mp4
2014-05-24 01:54 - 2014-05-24 01:54 - 23035717 _____ () C:\Users\JOSHUA LARSEN\Downloads\Busty2.mp4
2014-05-24 01:54 - 2014-05-24 01:54 - 01674747 _____ () C:\Users\JOSHUA LARSEN\Downloads\Old_big.mp4
2014-05-24 01:53 - 2014-05-24 01:55 - 214793694 _____ () C:\Users\JOSHUA LARSEN\Downloads\frndsis.mp4
2014-05-24 01:48 - 2014-05-24 01:50 - 125620694 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1464.avi
2014-05-24 01:48 - 2014-05-24 01:49 - 49198819 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1880.wmv
2014-05-24 01:48 - 2014-05-24 01:49 - 37632124 _____ () C:\Users\JOSHUA LARSEN\Downloads\chubby.mp4
2014-05-24 01:48 - 2014-05-24 01:49 - 29009104 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1481.avi
2014-05-24 01:48 - 2014-05-24 01:48 - 17870637 _____ () C:\Users\JOSHUA LARSEN\Downloads\watch-out-below.flv
2014-05-23 08:30 - 2014-05-23 08:31 - 134283264 _____ () C:\Users\JOSHUA LARSEN\Downloads\00048.mpg
2014-05-23 08:28 - 2014-05-23 08:29 - 61238664 _____ () C:\Users\JOSHUA LARSEN\Downloads\bath.avi
2014-05-23 08:28 - 2014-05-23 08:29 - 40114584 _____ () C:\Users\JOSHUA LARSEN\Downloads\sister_in_jacuzzi.mp4
2014-05-23 08:28 - 2014-05-23 08:28 - 25839282 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2093.mp4
2014-05-23 08:28 - 2014-05-23 08:28 - 17488670 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2137.mov
2014-05-23 08:28 - 2014-05-23 08:28 - 01781772 _____ () C:\Users\JOSHUA LARSEN\Downloads\dolphin-pantsing.flv
2014-05-22 08:54 - 2014-05-22 08:54 - 42056830 _____ () C:\Users\JOSHUA LARSEN\Downloads\VID00007.AVI
2014-05-22 08:54 - 2014-05-22 08:54 - 32331670 _____ () C:\Users\JOSHUA LARSEN\Downloads\VID00005.AVI
2014-05-22 08:54 - 2014-05-22 08:54 - 16117828 _____ () C:\Users\JOSHUA LARSEN\Downloads\VID00008.AVI
2014-05-22 08:53 - 2014-05-22 08:53 - 21543836 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-of-woman-at-her-computer.avi
2014-05-20 21:45 - 2014-05-20 21:45 - 00277960 _____ () C:\Windows\Minidump\052014-20451-01.dmp
2014-05-20 10:21 - 2014-05-20 10:21 - 06984077 _____ () C:\Users\JOSHUA LARSEN\Downloads\Indian Aunty_voyeured(1).FLV
2014-05-18 23:47 - 2014-05-18 23:47 - 14350516 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 04.mp4
2014-05-18 23:46 - 2014-05-18 23:46 - 06984077 _____ () C:\Users\JOSHUA LARSEN\Downloads\Indian Aunty_voyeured.FLV
2014-05-18 14:49 - 2014-05-18 14:49 - 31065180 _____ () C:\Users\JOSHUA LARSEN\Downloads\Flowery.avi
2014-05-18 14:48 - 2014-05-18 14:49 - 12520806 _____ () C:\Users\JOSHUA LARSEN\Downloads\perfect blonde topless.mp4
2014-05-18 14:47 - 2014-05-18 14:47 - 26743366 _____ () C:\Users\JOSHUA LARSEN\Downloads\Ebony_DR.mp4
2014-05-18 14:47 - 2014-05-18 14:47 - 10426752 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 03(1).mp4
2014-05-18 14:45 - 2014-05-18 14:46 - 16126228 _____ () C:\Users\JOSHUA LARSEN\Downloads\some pair.mp4
2014-05-18 14:45 - 2014-05-18 14:45 - 19877517 _____ () C:\Users\JOSHUA LARSEN\Downloads\2(1).3gp
2014-05-18 14:45 - 2014-05-18 14:45 - 06744719 _____ () C:\Users\JOSHUA LARSEN\Downloads\2(1).mp4
2014-05-18 14:43 - 2014-05-18 14:43 - 68058648 _____ () C:\Users\JOSHUA LARSEN\Downloads\water-jet-hidden-cam.avi
2014-05-18 14:43 - 2014-05-18 14:43 - 61473956 _____ () C:\Users\JOSHUA LARSEN\Downloads\roommate-in-her-bedroom-in-the-mroning.avi
2014-05-18 14:43 - 2014-05-18 14:43 - 12619684 _____ () C:\Users\JOSHUA LARSEN\Downloads\voy-the-voyeur.wmv
2014-05-18 14:43 - 2014-05-18 14:43 - 09962656 _____ () C:\Users\JOSHUA LARSEN\Downloads\under-chest-cam.wmv
2014-05-17 21:58 - 2014-05-17 21:58 - 00277960 _____ () C:\Windows\Minidump\051714-20077-01.dmp
2014-05-17 08:30 - 2014-05-17 08:30 - 00277960 _____ () C:\Windows\Minidump\051714-19110-01.dmp
2014-05-16 22:41 - 2014-05-16 22:41 - 10426752 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 03.mp4
2014-05-16 15:16 - 2014-05-16 15:16 - 09091950 _____ () C:\Users\JOSHUA LARSEN\Downloads\Mss_Bouquet(1).avi
2014-05-16 15:16 - 2014-05-16 15:16 - 07362481 _____ () C:\Users\JOSHUA LARSEN\Downloads\out_shower.mp4
2014-05-16 15:15 - 2014-05-16 15:16 - 25342388 _____ () C:\Users\JOSHUA LARSEN\Downloads\nice tits.avi
2014-05-16 02:10 - 2014-05-16 02:10 - 09091950 _____ () C:\Users\JOSHUA LARSEN\Downloads\Mss_Bouquet.avi
2014-05-16 02:08 - 2014-05-16 02:08 - 22950041 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1826.wmv
2014-05-16 02:08 - 2014-05-16 02:08 - 01332047 _____ () C:\Users\JOSHUA LARSEN\Downloads\kaily3_upload.wmv
2014-05-15 08:14 - 2014-05-15 08:14 - 46981971 _____ () C:\Users\JOSHUA LARSEN\Downloads\Belga 2.mp4
2014-05-15 08:11 - 2014-05-15 08:11 - 28973346 _____ () C:\Users\JOSHUA LARSEN\Downloads\wcfresariquisima.wmv
2014-05-15 08:11 - 2014-05-15 08:11 - 07773082 _____ () C:\Users\JOSHUA LARSEN\Downloads\tina.avi
2014-05-15 08:11 - 2014-05-15 08:11 - 06363108 _____ () C:\Users\JOSHUA LARSEN\Downloads\two-girl-caught.mp4
2014-05-15 08:11 - 2014-05-15 08:11 - 03225067 _____ () C:\Users\JOSHUA LARSEN\Downloads\paf-.mp4
2014-05-15 08:11 - 2014-05-15 08:11 - 00438677 _____ () C:\Users\JOSHUA LARSEN\Downloads\price-is-right-nipslip.mp4
2014-05-14 19:31 - 2014-05-14 19:32 - 49500098 _____ () C:\Users\JOSHUA LARSEN\Downloads\bik_change.avi
2014-05-14 19:31 - 2014-05-14 19:32 - 101461591 _____ () C:\Users\JOSHUA LARSEN\Downloads\poolpeep.wmv
2014-05-14 19:31 - 2014-05-14 19:32 - 02739418 _____ () C:\Users\JOSHUA LARSEN\Downloads\Keyhole.mp4
2014-05-14 19:29 - 2014-05-14 19:29 - 31364128 _____ () C:\Users\JOSHUA LARSEN\Downloads\Inside Basket.mp4
2014-05-14 19:18 - 2014-05-14 19:19 - 66342912 _____ () C:\Users\JOSHUA LARSEN\Downloads\hidden-spycam-british-oma-55yr-bathroom.avi
2014-05-14 19:18 - 2014-05-14 19:18 - 06618788 _____ () C:\Users\JOSHUA LARSEN\Downloads\safeway-02.m4v
2014-05-14 19:18 - 2014-05-14 19:18 - 05839721 _____ () C:\Users\JOSHUA LARSEN\Downloads\gets-naked.flv
2014-05-13 09:23 - 2014-05-13 09:23 - 21944181 _____ () C:\Users\JOSHUA LARSEN\Downloads\sis in law shower hidden cam.flv
2014-05-13 09:22 - 2014-05-13 09:23 - 81528194 _____ () C:\Users\JOSHUA LARSEN\Downloads\Latin.flv
2014-05-13 09:21 - 2014-05-13 09:21 - 18902755 _____ () C:\Users\JOSHUA LARSEN\Downloads\2531729_hidden_cam_pool_cabin_49.flv
2014-05-13 09:21 - 2014-05-13 09:21 - 06523982 _____ () C:\Users\JOSHUA LARSEN\Downloads\2532533_hidden_cam_pool_cabin_50.flv
2014-05-13 09:20 - 2014-05-13 09:20 - 04569444 _____ () C:\Users\JOSHUA LARSEN\Downloads\woohoo.avi
2014-05-13 09:19 - 2014-05-13 09:20 - 62054598 _____ () C:\Users\JOSHUA LARSEN\Downloads\pool_vid769.avi
2014-05-13 09:19 - 2014-05-13 09:20 - 41406763 _____ () C:\Users\JOSHUA LARSEN\Downloads\IMG_3029.MOV
2014-05-13 09:19 - 2014-05-13 09:20 - 35552502 _____ () C:\Users\JOSHUA LARSEN\Downloads\pool_vid768.avi
2014-05-13 09:18 - 2014-05-13 09:18 - 31793492 _____ () C:\Users\JOSHUA LARSEN\Downloads\White Bathroom.flv
2014-05-13 09:18 - 2014-05-13 09:18 - 26390500 _____ () C:\Users\JOSHUA LARSEN\Downloads\Sporty(1).avi
2014-05-12 09:07 - 2014-05-12 09:09 - 130306048 _____ () C:\Users\JOSHUA LARSEN\Downloads\voye_226.mpeg

==================== One Month Modified Files and Folders =======

2014-06-11 21:35 - 2014-06-11 21:34 - 00014803 _____ () C:\Users\JOSHUA LARSEN\Downloads\FRST.txt
2014-06-11 21:35 - 2013-01-07 23:17 - 00000000 ____D () C:\Users\JOSHUA LARSEN\AppData\Local\Temp
2014-06-11 21:34 - 2014-06-11 21:34 - 02081792 _____ (Farbar) C:\Users\JOSHUA LARSEN\Downloads\FRST64.exe
2014-06-11 21:34 - 2014-06-11 21:34 - 00000000 ____D () C:\FRST
2014-06-11 21:34 - 2013-01-07 23:17 - 01594565 _____ () C:\Windows\WindowsUpdate.log
2014-06-11 21:30 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-11 21:30 - 2009-07-13 22:51 - 00038961 _____ () C:\Windows\setupact.log
2014-06-11 21:29 - 2009-07-13 22:45 - 00022560 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-11 21:29 - 2009-07-13 22:45 - 00022560 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-11 21:23 - 2013-01-09 19:41 - 00000390 _____ () C:\Windows\Tasks\WpsUpdateTask_JOSHUA LARSEN.job
2014-06-11 20:29 - 2013-01-09 13:25 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-11 20:26 - 2013-01-09 19:41 - 00000390 _____ () C:\Windows\Tasks\WpsNotifyTask_JOSHUA LARSEN.job
2014-06-11 17:22 - 2009-07-13 23:13 - 00781790 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-11 03:04 - 2014-01-11 13:15 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-11 03:02 - 2014-01-11 13:15 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-11 03:02 - 2014-01-10 05:06 - 01024971 _____ () C:\Windows\IE11_main.log
2014-06-10 22:13 - 2013-01-08 00:22 - 00000000 ____D () C:\Users\JOSHUA LARSEN\AppData\Local\Battle.net
2014-06-10 12:35 - 2013-01-08 00:25 - 00000000 ____D () C:\Program Files (x86)\Diablo III
2014-06-10 12:35 - 2013-01-08 00:22 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-06-10 12:34 - 2014-02-18 20:16 - 00000000 ____D () C:\The KMPlayer
2014-06-10 12:31 - 2014-06-10 12:31 - 23261563 _____ () C:\Users\JOSHUA LARSEN\Downloads\bw1.flv
2014-06-10 12:31 - 2014-06-10 12:31 - 02253476 _____ () C:\Users\JOSHUA LARSEN\Downloads\upnopanty2.flv
2014-06-10 00:07 - 2014-06-10 00:07 - 02081531 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (51).ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01213155 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG2 5 43 Sun am in shower 0A76A2V2.ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01073891 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (54).ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01069795 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (53).ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01049315 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (44).ASF
2014-06-10 00:07 - 2014-06-10 00:07 - 01000157 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG8 3 00 (45).ASF
2014-06-10 00:04 - 2014-06-10 00:04 - 03719350 _____ () C:\Users\JOSHUA LARSEN\Downloads\Window_Neighbour.flv
2014-06-10 00:04 - 2014-06-10 00:03 - 82270774 _____ () C:\Users\JOSHUA LARSEN\Downloads\b30.avi
2014-06-10 00:02 - 2014-06-10 00:02 - 04076325 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG11 1 104338 shower squeegee great full frontal.ASF
2014-06-10 00:02 - 2014-06-10 00:02 - 01864437 _____ () C:\Users\JOSHUA LARSEN\Downloads\HG11 1 103931 shower nice labia legs split.ASF
2014-06-10 00:01 - 2014-03-21 16:49 - 00000000 ____D () C:\Users\JOSHUA LARSEN\Downloads\New folder
2014-06-10 00:00 - 2014-06-09 23:58 - 266826681 _____ () C:\Users\JOSHUA LARSEN\Downloads\Holy grail of pool changing.wmv
2014-06-09 23:59 - 2014-06-09 23:59 - 15706475 _____ () C:\Users\JOSHUA LARSEN\Downloads\sunburn.flv
2014-06-09 23:59 - 2014-06-09 23:58 - 08599393 _____ () C:\Users\JOSHUA LARSEN\Downloads\caught(1).flv
2014-06-09 22:27 - 2014-06-09 22:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-06-09 22:27 - 2014-06-09 22:27 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-06-09 22:27 - 2014-04-26 00:01 - 00001931 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-06-09 22:27 - 2014-04-26 00:01 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-06-09 22:27 - 2009-07-13 21:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-06 10:20 - 2014-06-06 10:19 - 177339443 _____ () C:\Users\JOSHUA LARSEN\Downloads\WP_20131110_21_35_53_Pro.mp4
2014-06-06 10:20 - 2014-06-06 10:19 - 05849452 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 06.mp4
2014-06-06 10:17 - 2014-06-06 10:17 - 24320811 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2167.wmv
2014-06-06 10:17 - 2014-06-06 10:17 - 03999533 _____ () C:\Users\JOSHUA LARSEN\Downloads\my-gfs-sister.mp4
2014-06-05 17:17 - 2010-11-20 21:47 - 00095348 _____ () C:\Windows\PFRO.log
2014-06-05 11:10 - 2014-06-05 11:09 - 202260067 _____ () C:\Users\JOSHUA LARSEN\Downloads\tre00056734(1).mov
2014-06-05 11:06 - 2014-06-05 11:06 - 15773351 _____ () C:\Users\JOSHUA LARSEN\Downloads\WP_20131110_23_30_48_Pro.mp4
2014-06-05 11:05 - 2014-06-05 11:05 - 14550318 _____ () C:\Users\JOSHUA LARSEN\Downloads\Sister_shwr.flv
2014-06-05 11:05 - 2014-06-05 11:05 - 05987730 _____ () C:\Users\JOSHUA LARSEN\Downloads\Uniform.avi
2014-06-05 11:00 - 2014-06-05 11:00 - 24386640 _____ () C:\Users\JOSHUA LARSEN\Downloads\tvf_show_spy2141.avi
2014-06-05 11:00 - 2014-06-05 11:00 - 10964307 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2092.wmv
2014-06-05 11:00 - 2014-06-05 11:00 - 10953688 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1858.flv
2014-06-03 10:37 - 2014-06-03 10:37 - 17782770 _____ () C:\Users\JOSHUA LARSEN\Downloads\mom_spy_cam.avi
2014-06-03 10:27 - 2014-06-03 10:25 - 170035338 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1449.avi
2014-06-03 10:27 - 2014-06-03 10:25 - 153948176 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1444.avi
2014-06-03 01:19 - 2014-06-03 01:19 - 01086016 _____ () C:\Users\JOSHUA LARSEN\Downloads\SIL_Shower.flv
2014-06-03 01:19 - 2014-06-03 01:18 - 86171652 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2029.mpg
2014-06-03 01:19 - 2014-06-03 01:18 - 35462588 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1964.avi
2014-06-01 23:25 - 2014-06-01 23:23 - 102288922 _____ () C:\Users\JOSHUA LARSEN\Downloads\wetteacher-02.avi
2014-06-01 23:24 - 2014-06-01 23:23 - 76242846 _____ () C:\Users\JOSHUA LARSEN\Downloads\wetteacher-01.avi
2014-06-01 23:24 - 2014-06-01 23:23 - 31369846 _____ () C:\Users\JOSHUA LARSEN\Downloads\murziq_sm09-22.avi
2014-06-01 21:01 - 2014-06-01 21:01 - 00860531 _____ () C:\Users\JOSHUA LARSEN\Downloads\caught in shower.mp4
2014-05-31 14:11 - 2014-05-31 14:11 - 42428474 _____ () C:\Users\JOSHUA LARSEN\Downloads\CS-CUT.avi
2014-05-31 14:11 - 2014-05-31 14:11 - 16612632 _____ () C:\Users\JOSHUA LARSEN\Downloads\wolter_downblouse_257.avi
2014-05-31 14:11 - 2014-05-31 14:10 - 136402537 _____ () C:\Users\JOSHUA LARSEN\Downloads\Hot rehead nice pussy view.wmv
2014-05-31 14:10 - 2014-05-31 14:10 - 48338393 _____ () C:\Users\JOSHUA LARSEN\Downloads\Yellow bottom perfect teen.wmv
2014-05-31 14:10 - 2014-05-31 14:09 - 33628189 _____ () C:\Users\JOSHUA LARSEN\Downloads\Intense clit orgasm with two vibrators.mp4
2014-05-31 14:10 - 2014-05-31 14:09 - 21920176 _____ () C:\Users\JOSHUA LARSEN\Downloads\Capture_20101003.mp4
2014-05-31 14:09 - 2014-05-31 14:05 - 277522791 _____ () C:\Users\JOSHUA LARSEN\Downloads\kt2.mp4
2014-05-31 14:08 - 2014-05-31 14:05 - 178636160 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1458.avi
2014-05-31 14:07 - 2014-05-31 14:05 - 156390338 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1440.avi
2014-05-31 14:05 - 2014-05-31 14:05 - 18657619 _____ () C:\Users\JOSHUA LARSEN\Downloads\a_real_video_from_a_very_hairy_american_girl.flv
2014-05-29 22:16 - 2014-05-29 22:14 - 125366770 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1442.avi
2014-05-29 22:10 - 2014-05-29 22:10 - 00277960 _____ () C:\Windows\Minidump\052914-21684-01.dmp
2014-05-29 22:10 - 2014-03-19 16:21 - 865910350 _____ () C:\Windows\MEMORY.DMP
2014-05-29 22:10 - 2014-03-19 16:21 - 00000000 ____D () C:\Windows\Minidump
2014-05-28 22:57 - 2013-01-08 19:05 - 00000000 ____D () C:\Users\JOSHUA LARSEN\AppData\Roaming\vlc
2014-05-28 22:56 - 2014-02-18 19:13 - 00003370 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2866715121-2728793360-866404133-1000
2014-05-28 22:56 - 2014-01-22 00:06 - 00003252 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2866715121-2728793360-866404133-1000
2014-05-28 22:54 - 2014-05-28 22:54 - 71718912 _____ () C:\Users\JOSHUA LARSEN\Downloads\Orgasm Contractions.mpg
2014-05-28 22:54 - 2014-05-28 22:54 - 50615618 _____ () C:\Users\JOSHUA LARSEN\Downloads\tumblr_lpmlih42Cw1qju8nw.mp4
2014-05-28 22:54 - 2014-05-28 22:54 - 19254700 _____ () C:\Users\JOSHUA LARSEN\Downloads\6631S4rOhJM.avi
2014-05-28 22:54 - 2014-05-28 22:54 - 17385155 _____ () C:\Users\JOSHUA LARSEN\Downloads\tumblr_loyh4ajaWL1qg2upe_r1.mov
2014-05-28 22:54 - 2014-05-28 22:54 - 10958094 _____ () C:\Users\JOSHUA LARSEN\Downloads\22yearoldwife3b_161.wmv
2014-05-28 22:54 - 2014-05-28 22:54 - 08847986 _____ () C:\Users\JOSHUA LARSEN\Downloads\135475_genuine_orgasm_contractions.mp4
2014-05-28 20:45 - 2014-05-28 20:45 - 00000000 ____D () C:\Windows\Sun
2014-05-28 20:45 - 2014-05-28 20:45 - 00000000 ____D () C:\Users\JOSHUA LARSEN\AppData\Roaming\Oracle
2014-05-28 20:45 - 2013-01-09 13:19 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-28 20:44 - 2014-05-28 20:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-28 20:44 - 2014-05-28 20:43 - 00004430 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-05-28 20:44 - 2013-01-09 13:19 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-28 14:07 - 2014-03-22 11:00 - 00000000 ____D () C:\Users\JOSHUA LARSEN\.gimp-2.8
2014-05-28 14:03 - 2014-05-28 14:03 - 00011921 _____ () C:\Users\JOSHUA LARSEN\AppData\Local\recently-used.xbel
2014-05-28 09:35 - 2014-05-28 09:35 - 10823057 _____ () C:\Users\JOSHUA LARSEN\Downloads\bouncy.mp4
2014-05-28 09:34 - 2014-05-28 09:34 - 51187676 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2116.avi
2014-05-28 09:34 - 2014-05-28 09:34 - 37831187 _____ () C:\Users\JOSHUA LARSEN\Downloads\gsbeach1.wmv
2014-05-27 23:39 - 2014-05-27 23:39 - 00928564 _____ () C:\Users\JOSHUA LARSEN\Downloads\wedgie.mp4
2014-05-27 23:39 - 2014-05-27 23:39 - 00875576 _____ () C:\Users\JOSHUA LARSEN\Downloads\Pantsed.avi
2014-05-27 23:39 - 2014-05-27 23:39 - 00804954 _____ () C:\Users\JOSHUA LARSEN\Downloads\bikini oops.mp4
2014-05-27 23:38 - 2014-05-27 23:38 - 09182284 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 05.mp4
2014-05-27 23:35 - 2014-05-27 23:35 - 62095360 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1649.avi
2014-05-27 23:35 - 2014-05-27 23:35 - 01929366 _____ () C:\Users\JOSHUA LARSEN\Downloads\milfs-in-shower-3.mp4
2014-05-27 23:35 - 2014-05-27 23:34 - 88610820 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1768.mpg
2014-05-27 23:35 - 2014-05-27 23:34 - 60395542 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2366.avi
2014-05-27 23:35 - 2014-05-27 23:34 - 37115012 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2218.avi
2014-05-27 23:35 - 2014-05-27 23:34 - 17593552 _____ () C:\Users\JOSHUA LARSEN\Downloads\dark-bush-in-shower.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 15255050 _____ () C:\Users\JOSHUA LARSEN\Downloads\zc.wmv
2014-05-27 23:34 - 2014-05-27 23:34 - 15216736 _____ () C:\Users\JOSHUA LARSEN\Downloads\zu.wmv
2014-05-27 23:34 - 2014-05-27 23:34 - 12622000 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-1.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 09673178 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2132.mov
2014-05-27 23:34 - 2014-05-27 23:34 - 09416260 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-2.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 09005592 _____ () C:\Users\JOSHUA LARSEN\Downloads\spycam-in-shower-2.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 06698000 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-4.mp4
2014-05-27 23:34 - 2014-05-27 23:34 - 05863520 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-3.mp4
2014-05-27 23:34 - 2014-05-27 23:33 - 09572649 _____ () C:\Users\JOSHUA LARSEN\Downloads\my-sister-anya-1.mp4
2014-05-27 23:34 - 2014-05-27 23:33 - 08522932 _____ () C:\Users\JOSHUA LARSEN\Downloads\spycam-in-shower-1.mp4
2014-05-27 23:33 - 2014-05-27 23:33 - 09032330 _____ () C:\Users\JOSHUA LARSEN\Downloads\shower-clock-hidden-camera-voyeur-3.mp4
2014-05-27 23:33 - 2014-05-27 23:33 - 06987794 _____ () C:\Users\JOSHUA LARSEN\Downloads\shower-clock-hidden-camera-voyeur-1.mp4
2014-05-27 23:33 - 2014-05-27 23:33 - 04300853 _____ () C:\Users\JOSHUA LARSEN\Downloads\shower-clock-hidden-camera-voyeur-2.mp4
2014-05-24 01:55 - 2014-05-24 01:53 - 214793694 _____ () C:\Users\JOSHUA LARSEN\Downloads\frndsis.mp4
2014-05-24 01:54 - 2014-05-24 01:54 - 23035717 _____ () C:\Users\JOSHUA LARSEN\Downloads\Busty2.mp4
2014-05-24 01:54 - 2014-05-24 01:54 - 01674747 _____ () C:\Users\JOSHUA LARSEN\Downloads\Old_big.mp4
2014-05-24 01:50 - 2014-05-24 01:48 - 125620694 _____ () C:\Users\JOSHUA LARSEN\Downloads\hz_lck_1464.avi
2014-05-24 01:49 - 2014-05-24 01:48 - 49198819 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1880.wmv
2014-05-24 01:49 - 2014-05-24 01:48 - 37632124 _____ () C:\Users\JOSHUA LARSEN\Downloads\chubby.mp4
2014-05-24 01:49 - 2014-05-24 01:48 - 29009104 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1481.avi
2014-05-24 01:48 - 2014-05-24 01:48 - 17870637 _____ () C:\Users\JOSHUA LARSEN\Downloads\watch-out-below.flv
2014-05-23 08:31 - 2014-05-23 08:30 - 134283264 _____ () C:\Users\JOSHUA LARSEN\Downloads\00048.mpg
2014-05-23 08:29 - 2014-05-23 08:28 - 61238664 _____ () C:\Users\JOSHUA LARSEN\Downloads\bath.avi
2014-05-23 08:29 - 2014-05-23 08:28 - 40114584 _____ () C:\Users\JOSHUA LARSEN\Downloads\sister_in_jacuzzi.mp4
2014-05-23 08:28 - 2014-05-23 08:28 - 25839282 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2093.mp4
2014-05-23 08:28 - 2014-05-23 08:28 - 17488670 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy2137.mov
2014-05-23 08:28 - 2014-05-23 08:28 - 01781772 _____ () C:\Users\JOSHUA LARSEN\Downloads\dolphin-pantsing.flv
2014-05-22 08:54 - 2014-05-22 08:54 - 42056830 _____ () C:\Users\JOSHUA LARSEN\Downloads\VID00007.AVI
2014-05-22 08:54 - 2014-05-22 08:54 - 32331670 _____ () C:\Users\JOSHUA LARSEN\Downloads\VID00005.AVI
2014-05-22 08:54 - 2014-05-22 08:54 - 16117828 _____ () C:\Users\JOSHUA LARSEN\Downloads\VID00008.AVI
2014-05-22 08:53 - 2014-05-22 08:53 - 21543836 _____ () C:\Users\JOSHUA LARSEN\Downloads\window-peep-of-woman-at-her-computer.avi
2014-05-20 21:45 - 2014-05-20 21:45 - 00277960 _____ () C:\Windows\Minidump\052014-20451-01.dmp
2014-05-20 10:21 - 2014-05-20 10:21 - 06984077 _____ () C:\Users\JOSHUA LARSEN\Downloads\Indian Aunty_voyeured(1).FLV
2014-05-18 23:47 - 2014-05-18 23:47 - 14350516 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 04.mp4
2014-05-18 23:46 - 2014-05-18 23:46 - 06984077 _____ () C:\Users\JOSHUA LARSEN\Downloads\Indian Aunty_voyeured.FLV
2014-05-18 14:49 - 2014-05-18 14:49 - 31065180 _____ () C:\Users\JOSHUA LARSEN\Downloads\Flowery.avi
2014-05-18 14:49 - 2014-05-18 14:48 - 12520806 _____ () C:\Users\JOSHUA LARSEN\Downloads\perfect blonde topless.mp4
2014-05-18 14:47 - 2014-05-18 14:47 - 26743366 _____ () C:\Users\JOSHUA LARSEN\Downloads\Ebony_DR.mp4
2014-05-18 14:47 - 2014-05-18 14:47 - 10426752 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 03(1).mp4
2014-05-18 14:46 - 2014-05-18 14:45 - 16126228 _____ () C:\Users\JOSHUA LARSEN\Downloads\some pair.mp4
2014-05-18 14:45 - 2014-05-18 14:45 - 19877517 _____ () C:\Users\JOSHUA LARSEN\Downloads\2(1).3gp
2014-05-18 14:45 - 2014-05-18 14:45 - 06744719 _____ () C:\Users\JOSHUA LARSEN\Downloads\2(1).mp4
2014-05-18 14:43 - 2014-05-18 14:43 - 68058648 _____ () C:\Users\JOSHUA LARSEN\Downloads\water-jet-hidden-cam.avi
2014-05-18 14:43 - 2014-05-18 14:43 - 61473956 _____ () C:\Users\JOSHUA LARSEN\Downloads\roommate-in-her-bedroom-in-the-mroning.avi
2014-05-18 14:43 - 2014-05-18 14:43 - 12619684 _____ () C:\Users\JOSHUA LARSEN\Downloads\voy-the-voyeur.wmv
2014-05-18 14:43 - 2014-05-18 14:43 - 09962656 _____ () C:\Users\JOSHUA LARSEN\Downloads\under-chest-cam.wmv
2014-05-17 21:58 - 2014-05-17 21:58 - 00277960 _____ () C:\Windows\Minidump\051714-20077-01.dmp
2014-05-17 08:30 - 2014-05-17 08:30 - 00277960 _____ () C:\Windows\Minidump\051714-19110-01.dmp
2014-05-16 22:41 - 2014-05-16 22:41 - 10426752 _____ () C:\Users\JOSHUA LARSEN\Downloads\Beach model 03.mp4
2014-05-16 15:16 - 2014-05-16 15:16 - 09091950 _____ () C:\Users\JOSHUA LARSEN\Downloads\Mss_Bouquet(1).avi
2014-05-16 15:16 - 2014-05-16 15:16 - 07362481 _____ () C:\Users\JOSHUA LARSEN\Downloads\out_shower.mp4
2014-05-16 15:16 - 2014-05-16 15:15 - 25342388 _____ () C:\Users\JOSHUA LARSEN\Downloads\nice tits.avi
2014-05-16 02:10 - 2014-05-16 02:10 - 09091950 _____ () C:\Users\JOSHUA LARSEN\Downloads\Mss_Bouquet.avi
2014-05-16 02:08 - 2014-05-16 02:08 - 22950041 _____ () C:\Users\JOSHUA LARSEN\Downloads\spy1826.wmv
2014-05-16 02:08 - 2014-05-16 02:08 - 01332047 _____ () C:\Users\JOSHUA LARSEN\Downloads\kaily3_upload.wmv
2014-05-15 08:14 - 2014-05-15 08:14 - 46981971 _____ () C:\Users\JOSHUA LARSEN\Downloads\Belga 2.mp4
2014-05-15 08:11 - 2014-05-15 08:11 - 28973346 _____ () C:\Users\JOSHUA LARSEN\Downloads\wcfresariquisima.wmv
2014-05-15 08:11 - 2014-05-15 08:11 - 07773082 _____ () C:\Users\JOSHUA LARSEN\Downloads\tina.avi
2014-05-15 08:11 - 2014-05-15 08:11 - 06363108 _____ () C:\Users\JOSHUA LARSEN\Downloads\two-girl-caught.mp4
2014-05-15 08:11 - 2014-05-15 08:11 - 03225067 _____ () C:\Users\JOSHUA LARSEN\Downloads\paf-.mp4
2014-05-15 08:11 - 2014-05-15 08:11 - 00438677 _____ () C:\Users\JOSHUA LARSEN\Downloads\price-is-right-nipslip.mp4
2014-05-14 19:32 - 2014-05-14 19:31 - 49500098 _____ () C:\Users\JOSHUA LARSEN\Downloads\bik_change.avi
2014-05-14 19:32 - 2014-05-14 19:31 - 101461591 _____ () C:\Users\JOSHUA LARSEN\Downloads\poolpeep.wmv
2014-05-14 19:32 - 2014-05-14 19:31 - 02739418 _____ () C:\Users\JOSHUA LARSEN\Downloads\Keyhole.mp4
2014-05-14 19:29 - 2014-05-14 19:29 - 31364128 _____ () C:\Users\JOSHUA LARSEN\Downloads\Inside Basket.mp4
2014-05-14 19:19 - 2014-05-14 19:18 - 66342912 _____ () C:\Users\JOSHUA LARSEN\Downloads\hidden-spycam-british-oma-55yr-bathroom.avi
2014-05-14 19:18 - 2014-05-14 19:18 - 06618788 _____ () C:\Users\JOSHUA LARSEN\Downloads\safeway-02.m4v
2014-05-14 19:18 - 2014-05-14 19:18 - 05839721 _____ () C:\Users\JOSHUA LARSEN\Downloads\gets-naked.flv
2014-05-13 22:29 - 2013-01-09 13:25 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-13 22:29 - 2013-01-09 13:25 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-13 22:29 - 2013-01-09 13:25 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-13 09:23 - 2014-05-13 09:23 - 21944181 _____ () C:\Users\JOSHUA LARSEN\Downloads\sis in law shower hidden cam.flv
2014-05-13 09:23 - 2014-05-13 09:22 - 81528194 _____ () C:\Users\JOSHUA LARSEN\Downloads\Latin.flv
2014-05-13 09:21 - 2014-05-13 09:21 - 18902755 _____ () C:\Users\JOSHUA LARSEN\Downloads\2531729_hidden_cam_pool_cabin_49.flv
2014-05-13 09:21 - 2014-05-13 09:21 - 06523982 _____ () C:\Users\JOSHUA LARSEN\Downloads\2532533_hidden_cam_pool_cabin_50.flv
2014-05-13 09:20 - 2014-05-13 09:20 - 04569444 _____ () C:\Users\JOSHUA LARSEN\Downloads\woohoo.avi
2014-05-13 09:20 - 2014-05-13 09:19 - 62054598 _____ () C:\Users\JOSHUA LARSEN\Downloads\pool_vid769.avi
2014-05-13 09:20 - 2014-05-13 09:19 - 41406763 _____ () C:\Users\JOSHUA LARSEN\Downloads\IMG_3029.MOV
2014-05-13 09:20 - 2014-05-13 09:19 - 35552502 _____ () C:\Users\JOSHUA LARSEN\Downloads\pool_vid768.avi
2014-05-13 09:18 - 2014-05-13 09:18 - 31793492 _____ () C:\Users\JOSHUA LARSEN\Downloads\White Bathroom.flv
2014-05-13 09:18 - 2014-05-13 09:18 - 26390500 _____ () C:\Users\JOSHUA LARSEN\Downloads\Sporty(1).avi
2014-05-12 09:09 - 2014-05-12 09:07 - 130306048 _____ () C:\Users\JOSHUA LARSEN\Downloads\voye_226.mpeg

Some content of TEMP:
====================
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\13-12_win7_win8_64_dd_ccc_whql.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\Delta.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\DeltaTB.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\install_reader11_en_mssd_aaa_aih.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\KMP_3.8.0.121.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\lowproc.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\MotoHelper_2.1.41_Driver_5.5.0.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\MybabylonTB.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\oi_{18CB11F4-992C-484A-B352-6C44DFEF2126}.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\SettingsManagerSetup.exe
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\stubhelper.dll
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\JOSHUA LARSEN\AppData\Local\Temp\WSSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll
[2010-11-20 21:24] - [2010-11-20 21:24] - 0512512 ____A (Microsoft Corporation) 7B418BCD873A321E77098A330C798B70

 ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-10 00:41

==================== End Of Log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-06-2014 01
Ran by JOSHUA LARSEN at 2014-06-11 21:36:05
Running from C:\Users\JOSHUA LARSEN\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Bitdefender Antivirus (Disabled - Out of date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
AS: Bitdefender Antispyware (Disabled - Out of date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Bitdefender Firewall (Disabled) {A23392FD-84B9-F933-2C71-81E751F6EF46}

==================== Installed Programs ======================

Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{308051DA-0048-7A07-FE8B-9B6EC119A9E8}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bitdefender Total Security (HKLM\...\Bitdefender) (Version: 17.25.0.1074 - Bitdefender)
BitTorrent (HKCU\...\BitTorrent) (Version: 7.8.2.30445 - BitTorrent Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.09 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\...\Defraggler) (Version: 2.16 - Piriform)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
File Association Helper (HKLM\...\{572D0504-2C67-4016-801F-D70879A3026A}) (Version: 1.1.6.53763 - WinZip Computing International, LLC)
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.600 - Oracle)
Java Auto Updater (x32 Version: 2.1.60.19 - Oracle, Inc.) Hidden
Kingsoft Office 2013 (9.1.0.4480) (HKLM-x32\...\Kingsoft Office) (Version: 9.1.0.4480 - Kingsoft Corp.)
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
MotoHelper 2.1.41 Driver 5.5.0 (HKLM-x32\...\MotoHelper) (Version: 2.1.41 - Motorola)
Motorola Mobile Drivers Installation 5.5.0 (Version: 5.5.0 - Motorola Inc.) Hidden
Mozilla Firefox 29.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 en-US)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
Osmo4/GPAC (remove only) (HKLM-x32\...\Osmo4) (Version:  - )
Protected Folder (HKLM-x32\...\Protected Folder_is1) (Version:  - IObit)
RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Recuva (HKLM\...\Recuva) (Version: 1.49 - Piriform)
Speccy (HKLM\...\Speccy) (Version: 1.24 - Piriform)
The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.8.0.121 - PandoraTV)
ValueApps (HKLM-x32\...\ValueApps) (Version: 1.1.1.1 - Conduit LTD) <==== ATTENTION
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WinZip 18.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DF}) (Version: 18.0.10661 - WinZip Computing, S.L. )
Wondershare Video Editor(Build 3.5.1) (HKLM-x32\...\Wondershare Video Editor_is1) (Version:  - Wondershare Software)
Yodot MOV Repair (HKLM-x32\...\{DA12623E-713B-43BF-A33B-2071594805F5}_is1) (Version: 1.0.0.2 - Yodot Software)

==================== Restore Points  =========================

12-06-2014 00:21:54 Scheduled Checkpoint

==================== Hosts content: ==========================

2009-07-13 20:34 - 2009-06-10 15:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {0F604513-AF48-4150-9A9A-DDB1A5E76543} - System32\Tasks\WpsUpdateTask_JOSHUA LARSEN => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe [2013-12-26] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {15F6508A-5643-4389-BBC9-EE352A382D3D} - System32\Tasks\pcreg => C:\Program Files\pcreg\service.exe [2014-01-04] () <==== ATTENTION
Task: {3235D8CC-F3F7-4972-B994-6BE98D70002A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: {33816F57-90C3-4B99-BEB0-81A28F9820AE} - System32\Tasks\WpsNotifyTask_JOSHUA LARSEN => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsnotify.exe [2013-12-26] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {62BF3E50-1DED-4878-AF30-E9A4D0A11604} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2866715121-2728793360-866404133-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {E3BDF07D-1F33-4DF9-AF9B-FDDEDDC7D712} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-13] (Adobe Systems Incorporated)
Task: {E818ADA5-59F4-4DEC-8655-30B856BA3504} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2866715121-2728793360-866404133-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\WpsNotifyTask_JOSHUA LARSEN.job => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsnotify.exe
Task: C:\Windows\Tasks\WpsUpdateTask_JOSHUA LARSEN.job => C:\Program Files (x86)\Kingsoft\Kingsoft Office\wtoolex\wpsupdate.exe

==================== Loaded Modules (whitelisted) =============

2014-01-30 14:20 - 2013-06-19 12:45 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender\txmlutil.dll
2014-01-30 14:20 - 2014-01-27 19:21 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender\UI\accessl.ui
2014-01-30 14:20 - 2011-11-14 20:17 - 00153680 _____ () C:\Program Files\Bitdefender\Bitdefender\bdfwcore.dll
2014-02-27 18:05 - 2014-02-27 18:05 - 00770792 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00036_003\ashttpbr.mdl
2014-02-27 18:05 - 2014-02-27 18:05 - 00568400 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00036_003\ashttpdsp.mdl
2014-02-27 18:05 - 2014-02-27 18:05 - 02592904 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00036_003\ashttpph.mdl
2014-02-27 18:05 - 2014-02-27 18:05 - 01315680 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00036_003\ashttprbl.mdl
2013-12-17 19:14 - 2013-12-17 19:14 - 00033824 _____ () C:\Program Files\pcreg\pcreg.exe
2013-08-14 16:19 - 2013-08-14 16:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2014-01-30 14:20 - 2013-03-25 16:16 - 01117920 _____ () C:\Program Files\Bitdefender\Bitdefender SafeBox\System.Data.SQLite.dll
2014-01-30 14:20 - 2014-03-27 10:30 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender\antispam32\txmlutil.dll
2014-02-01 10:33 - 2013-07-24 10:24 - 00137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2014-05-09 16:15 - 2014-05-09 16:15 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-01-30 14:20 - 2014-03-27 10:30 - 00035896 _____ () C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\components\ffpwdman.dll
2014-05-13 22:29 - 2014-05-13 22:29 - 16361136 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:0C52AA8E
AlternateDataStreams: C:\Users\JOSHUA LARSEN\Downloads\Diablo-III-Setup-enUS.exe:BDU
AlternateDataStreams: C:\Users\JOSHUA LARSEN\Downloads\FRST64.exe:BDU
AlternateDataStreams: C:\Users\JOSHUA LARSEN\Downloads\video-editor_setup_full846.exe:BDU
AlternateDataStreams: C:\Users\JOSHUA LARSEN\Downloads\wlsetup-web.exe:BDU
AlternateDataStreams: C:\Users\JOSHUA LARSEN\Downloads\yodot-mov-repair.exe:BDU

==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/11/2014 09:32:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/11/2014 09:28:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: ntdll.dll, version: 6.1.7601.18247, time stamp: 0x521eaf24
Exception code: 0xc0000005
Fault offset: 0x000000000005320e
Faulting process id: 0x11a8
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3

Error: (06/11/2014 09:28:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: MSHTML.dll, version: 10.0.9200.16750, time stamp: 0x5269d4e1
Exception code: 0xc0000005
Fault offset: 0x00000000002a9689
Faulting process id: 0x338
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3

Error: (06/11/2014 09:28:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/11/2014 09:24:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: MSHTML.dll, version: 10.0.9200.16750, time stamp: 0x5269d4e1
Exception code: 0xc0000005
Fault offset: 0x0000000000024ba0
Faulting process id: 0x310
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3

Error: (06/11/2014 05:17:54 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/11/2014 03:02:22 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="*",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (06/11/2014 03:02:05 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "Microsoft.VC80.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1".
Dependent Assembly Microsoft.VC80.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (06/10/2014 06:12:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2014 06:07:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: MSHTML.dll, version: 10.0.9200.16750, time stamp: 0x5269d4e1
Exception code: 0xc0000005
Fault offset: 0x00000000000e7db4
Faulting process id: 0x33c
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3


System errors:
=============
Error: (06/11/2014 09:30:43 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Power service terminated with the following error:
%%4203

Error: (06/11/2014 09:29:04 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Update service terminated with the following error:
%%-2147467243

Error: (06/11/2014 09:28:49 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the DCOM Server Process Launcher service, but this action failed with the following error:
%%1190

Error: (06/11/2014 09:28:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The DCOM Server Process Launcher service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Reboot the machine.

Error: (06/11/2014 09:28:31 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the DCOM Server Process Launcher service, but this action failed with the following error:
%%1190

Error: (06/11/2014 09:28:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Plug and Play service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Reboot the machine.

Error: (06/11/2014 09:28:31 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The DCOM Server Process Launcher service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Reboot the machine.

Error: (06/11/2014 09:26:35 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Power service terminated with the following error:
%%4203

Error: (06/11/2014 09:24:25 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Reboot the machine) after the unexpected termination of the DCOM Server Process Launcher service, but this action failed with the following error:
%%1190

Error: (06/11/2014 09:24:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Plug and Play service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Reboot the machine.


Microsoft Office Sessions:
=========================
Error: (06/11/2014 09:32:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/11/2014 09:28:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc3c1ntdll.dll6.1.7601.18247521eaf24c0000005000000000005320e11a801cf85ee693fc325C:\Windows\system32\svchost.exeC:\Windows\SYSTEM32\ntdll.dlla752a931-f1e1-11e3-aae7-3fcdfd911a80

Error: (06/11/2014 09:28:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc3c1MSHTML.dll10.0.9200.167505269d4e1c000000500000000002a968933801cf85ee1b3072b6C:\Windows\system32\svchost.exeC:\Windows\system32\MSHTML.dll9c068144-f1e1-11e3-aae7-3fcdfd911a80

Error: (06/11/2014 09:28:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/11/2014 09:24:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc3c1MSHTML.dll10.0.9200.167505269d4e1c00000050000000000024ba031001cf85cb21be7a3eC:\Windows\system32\svchost.exeC:\Windows\system32\MSHTML.dll0bf876cf-f1e1-11e3-89de-3fcdfd911a80

Error: (06/11/2014 05:17:54 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/11/2014 03:02:22 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe

Error: (06/11/2014 03:02:05 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files (x86)\Motorola\motohelper\MotoHelperService.exe

Error: (06/10/2014 06:12:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/10/2014 06:07:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe6.1.7600.163854a5bc3c1MSHTML.dll10.0.9200.167505269d4e1c000000500000000000e7db433c01cf84de07b015d9C:\Windows\system32\svchost.exeC:\Windows\system32\MSHTML.dll6ec4e810-f0fc-11e3-bcf0-3fcdfd911a80


==================== Memory info ===========================

Percentage of memory in use: 11%
Total physical RAM: 24574.43 MB
Available physical RAM: 21704.91 MB
Total Pagefile: 49147.04 MB
Available Pagefile: 46039.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:493.43 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 1D69F616)
Partition 1: (Active) - (Size=931 GB) - (Type=07 NTFS)

==================== End Of Log ============================

 

Again, Thanks for any and all help with this

Link to post
Share on other sites

Welcome to the forum.

Make sure you have created a restore point and.....
bwebb7v.jpgDownload Delfix from Here and save it to your desktop.

  • Place a check mark in front of .......
  • Create registry backup <---only!
  • Uncheck the rest!
  • Click the Run button.

    Close the tool out when it's done....we'll use it later.

    --------------------------------

    Download the attached fixlist.txt to the same folder as FRST.exe.
    Run FRST.exe and click Fix only once and wait
    The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

    --------------------------------------------------

    Then: (if TDSSKiller gives you the chance to cure this file: rpcss.dll allow it to do so)

    Make sure you have created that system restore point before you continue!

    Please read the directions carefully so you don't end up deleting something that is good!!

    If in doubt about an entry....please ask or choose Skip!!!!

    Don't Delete anything unless instructed to!

    If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
    Skip and click on Continue

    If a suspicious object is detected, the default action will be Skip, click on Continue

    Please note that TDSSKiller can be run in safe mode if needed.

    Please download the latest version of TDSSKiller from HERE and save it to your Desktop.
    • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters. (Leave the KSN box checked)

      tds2.jpg
    • Put a checkmark beside loaded modules.

      13040712472913819.png
    • A reboot will be needed to apply the changes. Do it.
    • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
    • Then click on Change parameters in TDSSKiller.
    • Check all boxes then click OK.

      clip.jpg
    • Click the Start Scan button.

      19695967.jpg
    • The scan should take no longer than 2 minutes.
    • If a suspicious object is detected, the default action will be Skip, click on Continue.

      67776163.jpg

      Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.

      If in doubt about an entry....please ask or choose Skip
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
      Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.

      62117367.jpg

      Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
    • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here. There may be 3 logs > so post or attach all of them.
    • Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.

    Here's a summary of what to do if you would like to print it out:

    If in doubt about an entry....please ask or choose Skip

    Don't Delete anything unless instructed to!

    If a suspicious object is detected, the default action will be Skip, click on Continue

    If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
    Skip and click on Continue

    Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.

    If malicious objects are found, they will show in the Scan results and offer three (3) options.

    Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

    ~~~~~~~~~~~~~~~~~~~~

    You can attach the logs if they're too long:

    Bottom right corner of this page.
    reply1.jpg

    New window that comes up.
    replyer1.jpg


    Then...........

    Please download and run ComboFix.

    The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

    Please visit this webpage for download links, and instructions for running ComboFix

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    http://www.bleepingcomputer.com/download/combofix/dl/12/ <---ComboFix direct download

    Please make sure you click download buttons that look similar to this, not "sponsored ad links":

    bleep-crop.jpg

    Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    Information on disabling your malware programs can be found Here.

    Make sure you run ComboFix from your desktop.

    Give it at least 30-45 minutes to finish if needed.

    Please include the C:\ComboFix.txt in your next reply for further review.

    ---------->NOTE<----------

    If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix....please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

    MrC
Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.