Jump to content

Infected need help please


Recommended Posts

Good morning, some body can help me i run malawarebytes and after remove the malaware is pop error message BAD IMAGE  and is really annoying 

i run FRST and the log is

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-08-2014 01
Ran by Eduardo (administrator) on EDUARDO-HP on 15-08-2014 09:15:12
Running from C:\Users\Eduardo\Downloads\FRST
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation) C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Intuit) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(CCH Small Firm Services) C:\Program Files (x86)\Common Files\CCH Small Firm Services\ATX 2013 Server\Sfs.ServerHost.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Intuit, Inc.) C:\Program Files (x86)\Intuit\QuickBooks 2013\QBDBMgrN.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM-x32\...\Run: [sunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
AppInit_DLLs: C:\PROGRA~2\SUPPOR~1\SUPPOR~2.DLL => C:\Program Files (x86)\Supporter\Supporter_x64.dll [4397056 2014-08-14] ()
AppInit_DLLs-x32: c:\progra~2\suppor~1\suppor~1.dll => c:\Program Files (x86)\Supporter\Supporter.dll [4464128 2014-08-14] ()
ShellIconOverlayIdentifiers: Carbonite.Green -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
ShellIconOverlayIdentifiers: Carbonite.Partial -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
ShellIconOverlayIdentifiers: Carbonite.Yellow -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: Carbonite.Green -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: Carbonite.Partial -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: Carbonite.Yellow -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll (Carbonite, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyServer: http=127.0.0.1:13988;https=127.0.0.1:13988
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.com/web?q={searchterms}&l=dis&o=CMDTDF
SearchScopes: HKLM - {455148C3-5261-42E1-9D74-8E1F9F355D5A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMDTDFJS
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMDTDF
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = 
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMDTDFJS
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Handler: intu-help-qb6 - {6898B29B-BF49-43cb-A0B1-D0B9496AF491} -  No File
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} -  No File
Handler-x32: intu-help-qb6 - {6898B29B-BF49-43cb-A0B1-D0B9496AF491} - C:\Program Files (x86)\Intuit\QuickBooks 2013\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
 
Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR StartupUrls: "hxxp://www.google.com"
CHR DefaultNewTabURL: 
CHR Extension: (Google Docs) - C:\Users\Eduardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-18]
CHR Extension: (Google Drive) - C:\Users\Eduardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-18]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Eduardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-10]
CHR Extension: (YouTube) - C:\Users\Eduardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-18]
CHR Extension: (Google Search) - C:\Users\Eduardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-18]
CHR Extension: (Google Wallet) - C:\Users\Eduardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-18]
CHR Extension: (Gmail) - C:\Users\Eduardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-18]
CHR StartMenuInternet: Google Chrome - chrome.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 be0fb33b; c:\Program Files (x86)\Supporter\SupporterSvc.dll [180048 2014-08-14] () [File not signed]
R2 BrcmMgmtAgent; C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe [163840 2011-11-30] (Broadcom Corporation) [File not signed]
R2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [69368 2013-10-23] (Bitdefender)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [86528 2012-09-27] (Hewlett-Packard Company) [File not signed]
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2175264 2014-08-15] (IObit)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-04-18] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1135752 2013-02-07] (PDF Complete Inc)
R2 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2014-01-16] (Intuit) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [61440 2013-11-15] (Intuit Inc.) [File not signed]
R2 QBVSS; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [1248256 2013-11-15] (Intuit Inc.) [File not signed]
R3 QuickBooksDB23; C:\Program Files (x86)\Intuit\QuickBooks 2013\QBDBMgrN.exe [679936 2013-11-15] (Intuit, Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-08-31] (Realtek Semiconductor)
R2 Sfs.ServerHost.exe; C:\Program Files (x86)\Common Files\CCH Small Firm Services\ATX 2013 Server\Sfs.ServerHost.exe [264424 2014-03-10] (CCH Small Firm Services)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3388144 2013-04-18] (Intel® Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [718840 2013-04-17] (BitDefender)
U5 avchv; C:\Windows\System32\Drivers\avchv.sys [261056 2012-11-02] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [593144 2013-04-17] (BitDefender)
R1 bdfwfpf; C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [121928 2013-07-02] (Bitdefender SRL)
R1 CLVirtualDrive; C:\Windows\System32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R1 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [148696 2013-04-22] (BitDefender LLC)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28216 2012-10-09] (Intel Corporation)
U3 TrueSight; C:\Windows\SysWOW64\drivers\TrueSight.sys [29160 2014-08-15] ()
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [382536 2013-05-28] (BitDefender S.R.L.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-15 09:14 - 2014-08-15 09:15 - 00000000 ____D () C:\Users\Eduardo\Downloads\FRST
2014-08-15 08:39 - 2014-08-15 08:39 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\ProductData
2014-08-15 08:38 - 2014-08-15 08:49 - 00000000 ____D () C:\ProgramData\ProductData
2014-08-15 08:38 - 2014-08-15 08:39 - 00000000 ____D () C:\ProgramData\IObit
2014-08-15 08:38 - 2014-08-15 08:38 - 00002890 _____ () C:\Windows\System32\Tasks\Uninstaller_SkipUac_Administrator
2014-08-15 08:38 - 2014-08-15 08:38 - 00001258 _____ () C:\Users\Eduardo\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-08-15 08:38 - 2014-08-15 08:38 - 00001234 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-08-15 08:38 - 2014-08-15 08:38 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\IObit
2014-08-15 08:38 - 2014-08-15 08:38 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-08-15 08:35 - 2014-08-15 08:36 - 12906784 _____ (IObit) C:\Users\Eduardo\Downloads\iobituninstaller (1).exe
2014-08-15 08:35 - 2014-08-15 08:35 - 12906784 _____ (IObit) C:\Users\Eduardo\Downloads\iobituninstaller.exe
2014-08-15 07:56 - 2014-08-15 07:56 - 00380416 _____ () C:\Users\Eduardo\Downloads\unjnneeh.exe
2014-08-15 07:09 - 2014-08-15 07:09 - 00000000 ____D () C:\ProgramData\Splashtop
2014-08-15 07:09 - 2014-08-15 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Splashtop Remote
2014-08-15 07:05 - 2014-08-15 07:05 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-08-15 07:05 - 2014-08-15 07:05 - 00000000 ____D () C:\Users\Eduardo\Documents\Splashtop Whiteboard
2014-08-15 07:05 - 2014-08-15 07:05 - 00000000 ____D () C:\Users\Eduardo\Documents\Splashtop Presenter
2014-08-15 00:21 - 2014-08-15 00:22 - 05571320 _____ (Swearware) C:\Users\Eduardo\Downloads\ComboFix.exe
2014-08-15 00:16 - 2014-08-15 00:16 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Eduardo\Downloads\tdsskiller.exe
2014-08-15 00:14 - 2014-08-15 00:14 - 04817496 _____ () C:\Users\Eduardo\Downloads\RogueKiller.exe
2014-08-15 00:14 - 2014-08-15 00:14 - 00029160 _____ () C:\Windows\SysWOW64\Drivers\TrueSight.sys
2014-08-15 00:14 - 2014-08-15 00:14 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-08-15 00:03 - 2014-08-15 00:05 - 00039954 _____ () C:\Users\Eduardo\Downloads\Addition.txt
2014-08-15 00:02 - 2014-08-15 09:15 - 00000000 ____D () C:\FRST
2014-08-15 00:02 - 2014-08-15 00:05 - 00061492 _____ () C:\Users\Eduardo\Downloads\FRST.txt
2014-08-14 23:55 - 2014-08-14 23:55 - 00240773 _____ () C:\ProgramData\1408074320.bdinstall.bin
2014-08-14 23:50 - 2014-08-14 23:50 - 00002178 _____ () C:\Users\Public\Desktop\Bitdefender Antivirus Free Edition.lnk
2014-08-14 23:50 - 2014-08-14 23:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus Free Edition
2014-08-14 23:50 - 2013-04-17 14:59 - 00718840 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys
2014-08-14 23:50 - 2013-04-17 14:59 - 00593144 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys
2014-08-14 23:50 - 2012-11-02 14:17 - 00261056 _____ (BitDefender) C:\Windows\system32\Drivers\avchv.sys
2014-08-14 23:50 - 2009-07-15 01:21 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2014-08-14 23:48 - 2014-08-14 23:50 - 00000000 ____D () C:\Program Files\Bitdefender
2014-08-14 23:48 - 2013-05-28 12:12 - 00382536 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2014-08-14 23:48 - 2013-04-22 13:21 - 00148696 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2014-08-14 23:40 - 2014-08-15 09:04 - 00549858 _____ () C:\Windows\PFRO.log
2014-08-14 23:40 - 2014-08-15 09:04 - 00001028 _____ () C:\Windows\setupact.log
2014-08-14 23:40 - 2014-08-14 23:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-14 23:35 - 2014-08-14 23:35 - 00045491 _____ () C:\ProgramData\1408073683.bdinstall.bin
2014-08-14 23:34 - 2014-08-14 23:49 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\QuickScan
2014-08-14 23:33 - 2014-08-14 23:33 - 00002776 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-14 23:33 - 2014-08-14 23:33 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-14 23:33 - 2014-08-14 23:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-14 23:33 - 2014-08-14 23:33 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-14 23:30 - 2014-08-14 23:30 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\Oracle
2014-08-14 23:29 - 2014-08-14 23:29 - 00000000 ____D () C:\ProgramData\Sun
2014-08-14 23:29 - 2014-08-14 23:29 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-14 23:28 - 2014-08-14 23:28 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-14 23:28 - 2014-08-14 23:28 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-14 23:28 - 2014-08-14 23:28 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-14 23:28 - 2014-08-14 23:28 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-14 23:28 - 2014-08-14 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-14 23:28 - 2014-08-14 23:28 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-14 23:24 - 2014-08-14 23:24 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Splashtop
2014-08-14 23:20 - 2014-08-15 07:27 - 00000564 _____ () C:\SSUUpdater.log
2014-08-14 23:02 - 2014-08-15 07:09 - 00000000 ____D () C:\Program Files (x86)\Splashtop
2014-08-14 22:59 - 2014-08-14 23:00 - 20638872 _____ (Splashtop Inc.) C:\Users\Eduardo\Downloads\Splashtop_Streamer_WIN_v2.5.8.8.EXE
2014-08-14 22:19 - 2014-08-14 22:19 - 00000000 ____D () C:\Windows\pss
2014-08-14 22:01 - 2014-08-15 07:35 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\CrossLoop
2014-08-14 22:00 - 2014-08-14 22:00 - 02174544 _____ (CrossLoop, Inc. ) C:\Users\Eduardo\Downloads\CrossLoopSetup.exe
2014-08-14 21:59 - 2014-08-14 23:11 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-14 21:59 - 2014-08-14 21:59 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-14 21:59 - 2014-08-14 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-14 21:59 - 2014-08-14 21:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-14 21:59 - 2014-08-14 21:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-14 21:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-14 21:59 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-14 21:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-14 21:58 - 2014-08-14 22:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 21:58 - 2014-07-31 23:41 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 21:41 - 2014-08-14 21:42 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Eduardo\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-14 14:35 - 2014-08-14 14:35 - 00001103 _____ () C:\Users\Eduardo\Desktop\Continue Live Installation.lnk
2014-08-14 14:28 - 2014-08-14 14:48 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-08-14 14:28 - 2014-08-14 14:32 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-08-14 14:28 - 2014-08-14 14:32 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-08-14 14:28 - 2014-08-14 14:30 - 00000318 _____ () C:\Users\Eduardo\AppData\Roaming\aps.uninstall.scan.results
2014-08-14 14:28 - 2014-08-14 14:28 - 00002832 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2014-08-14 14:28 - 2014-08-14 14:28 - 00002830 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2014-08-14 14:28 - 2014-08-14 14:28 - 00002830 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2014-08-14 14:26 - 2014-08-14 14:26 - 00575544 _____ (ClickMeIn Limited) C:\Users\Eduardo\AppData\Local\nsc8059.tmp
2014-08-14 13:48 - 2014-08-14 23:49 - 00000300 _____ () C:\Windows\Tasks\WSE_Astromenda.job
2014-08-14 13:48 - 2014-08-14 13:48 - 00003248 _____ () C:\Windows\System32\Tasks\WSE_Astromenda
2014-08-14 13:29 - 2014-08-14 19:33 - 00001969 _____ () C:\Users\Eduardo\Desktop\Search.lnk
2014-08-14 13:29 - 2014-08-14 13:29 - 00002497 _____ () C:\Users\Eduardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-14 13:28 - 2014-08-14 23:25 - 00000000 ____D () C:\Support
2014-08-14 13:27 - 2014-08-14 22:02 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-08-14 13:27 - 2014-08-14 13:27 - 00004034 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-08-14 13:27 - 2014-08-14 13:27 - 00000000 ____D () C:\Users\Eduardo\Documents\Optimizer Pro
2014-08-14 13:27 - 2014-08-14 13:27 - 00000000 ____D () C:\Program Files (x86)\Supporter
2014-08-14 13:26 - 2014-08-14 13:26 - 00000394 __RSH () C:\ProgramData\ntuser.pol
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\QBDataServiceUser23\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\QBDataServiceUser23\AppData\Local\Google
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\QBDataServiceUser23\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\QBDataServiceUser23\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Packages
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\ProgramData\c5b0cd74f8fdb77a
2014-08-14 13:25 - 2014-08-14 23:25 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\VOPackage
2014-08-14 03:01 - 2014-06-30 18:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-14 03:01 - 2014-06-30 18:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 03:01 - 2014-06-06 02:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 03:01 - 2014-06-06 02:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-14 03:01 - 2014-03-09 17:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-14 03:01 - 2014-03-09 17:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-14 03:01 - 2014-03-09 17:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 03:01 - 2014-03-09 17:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-13 04:21 - 2014-07-15 23:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-13 04:21 - 2014-07-15 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-13 04:21 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-13 04:21 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-13 04:21 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-13 04:21 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-13 04:21 - 2014-07-08 22:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-13 04:21 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-13 04:21 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-13 04:21 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-13 04:21 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-13 04:21 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-13 04:21 - 2014-07-08 18:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-13 04:21 - 2014-07-08 18:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-13 04:20 - 2014-07-31 19:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-13 04:20 - 2014-07-31 19:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-13 04:20 - 2014-07-25 10:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-13 04:20 - 2014-07-25 10:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-13 04:20 - 2014-07-25 10:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-13 04:20 - 2014-07-25 09:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-13 04:20 - 2014-07-25 09:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-13 04:20 - 2014-07-25 09:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-13 04:20 - 2014-07-25 09:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-13 04:20 - 2014-07-25 09:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-13 04:20 - 2014-07-25 09:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-13 04:20 - 2014-07-25 09:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-13 04:20 - 2014-07-25 09:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-13 04:20 - 2014-07-25 09:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-13 04:20 - 2014-07-25 09:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-13 04:20 - 2014-07-25 09:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-13 04:20 - 2014-07-25 09:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-13 04:20 - 2014-07-25 08:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-13 04:20 - 2014-07-25 08:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-13 04:20 - 2014-07-25 08:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-13 04:20 - 2014-07-25 08:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-13 04:20 - 2014-07-25 08:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-13 04:20 - 2014-07-25 08:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-13 04:20 - 2014-07-25 08:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-13 04:20 - 2014-07-25 08:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-13 04:20 - 2014-07-25 08:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-13 04:20 - 2014-07-25 08:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-13 04:20 - 2014-07-25 08:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-13 04:20 - 2014-07-25 08:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-13 04:20 - 2014-07-25 08:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-13 04:20 - 2014-07-25 08:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-13 04:20 - 2014-07-25 08:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-13 04:20 - 2014-07-25 08:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-13 04:20 - 2014-07-25 08:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-13 04:20 - 2014-07-25 08:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-13 04:20 - 2014-07-25 08:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-13 04:20 - 2014-07-25 07:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-13 04:20 - 2014-07-25 07:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-13 04:20 - 2014-07-25 07:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 04:20 - 2014-07-25 07:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-13 04:20 - 2014-07-25 07:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-13 04:20 - 2014-07-25 07:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-13 04:20 - 2014-07-25 07:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-13 04:20 - 2014-07-25 07:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-13 04:20 - 2014-07-25 07:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-13 04:20 - 2014-07-25 07:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-13 04:20 - 2014-07-25 07:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-13 04:20 - 2014-07-25 07:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-13 04:20 - 2014-07-25 07:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-13 04:20 - 2014-07-25 07:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-13 04:20 - 2014-07-25 06:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-13 04:20 - 2014-07-25 06:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-13 04:20 - 2014-07-25 06:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-13 04:20 - 2014-07-25 06:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-13 04:20 - 2014-07-25 06:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-13 04:20 - 2014-07-25 06:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-13 04:20 - 2014-07-15 23:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-13 04:20 - 2014-07-15 22:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-13 04:20 - 2014-07-15 22:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-13 04:20 - 2014-06-24 22:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-13 04:20 - 2014-06-24 21:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-13 04:20 - 2014-06-15 22:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-13 04:20 - 2014-06-03 06:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-13 04:20 - 2014-06-03 06:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-13 04:20 - 2014-06-03 06:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-13 04:20 - 2014-06-03 06:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-13 04:20 - 2014-06-03 05:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-13 04:20 - 2014-06-03 05:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-13 04:20 - 2014-06-03 05:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-13 04:16 - 2014-08-06 22:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-13 04:16 - 2014-08-06 22:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 04:16 - 2014-07-13 22:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-13 04:16 - 2014-07-13 21:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-11 12:30 - 2014-08-11 12:30 - 00001180 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-11 12:30 - 2014-08-11 12:30 - 00001168 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-11 12:30 - 2014-08-11 12:30 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-11 12:28 - 2014-08-14 23:25 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\Systweak
2014-08-11 12:28 - 2014-08-14 23:25 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-11 12:28 - 2014-08-11 12:28 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\globalUpdate
2014-08-11 12:28 - 2014-08-05 19:14 - 00020328 _____ () C:\Windows\system32\roboot64.exe
2014-08-11 12:27 - 2014-08-11 12:28 - 07500112 _____ (TeamViewer GmbH) C:\Users\Eduardo\Downloads\TeamViewer_Setup.exe
2014-07-31 05:24 - 2014-05-14 12:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-07-31 05:24 - 2014-05-14 12:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-07-31 05:24 - 2014-05-14 12:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-07-31 05:24 - 2014-05-14 12:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-07-31 05:24 - 2014-05-14 12:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-07-31 05:24 - 2014-05-14 12:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-07-31 05:24 - 2014-05-14 12:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-07-31 05:24 - 2014-05-14 12:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-07-31 05:24 - 2014-05-14 12:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-07-31 05:24 - 2014-05-14 12:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-07-31 05:23 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-07-31 05:23 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-07-31 05:23 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-07-31 05:23 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-07-16 14:19 - 2014-07-16 14:19 - 00070876 _____ () C:\Users\Eduardo\Downloads\PGRDeclarationsPage (1).html
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-08-15 09:15 - 2014-08-15 09:14 - 00000000 ____D () C:\Users\Eduardo\Downloads\FRST
2014-08-15 09:15 - 2014-08-15 00:02 - 00000000 ____D () C:\FRST
2014-08-15 09:13 - 2014-01-18 12:34 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-15 09:13 - 2009-07-14 00:45 - 00027344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-15 09:13 - 2009-07-14 00:45 - 00027344 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-15 09:06 - 2013-12-05 00:25 - 00000000 ____D () C:\ProgramData\PDFC
2014-08-15 09:05 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-15 09:04 - 2014-08-14 23:40 - 00549858 _____ () C:\Windows\PFRO.log
2014-08-15 09:04 - 2014-08-14 23:40 - 00001028 _____ () C:\Windows\setupact.log
2014-08-15 09:03 - 2014-01-15 20:08 - 01151144 _____ () C:\Windows\WindowsUpdate.log
2014-08-15 08:49 - 2014-08-15 08:38 - 00000000 ____D () C:\ProgramData\ProductData
2014-08-15 08:39 - 2014-08-15 08:39 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\ProductData
2014-08-15 08:39 - 2014-08-15 08:38 - 00000000 ____D () C:\ProgramData\IObit
2014-08-15 08:38 - 2014-08-15 08:38 - 00002890 _____ () C:\Windows\System32\Tasks\Uninstaller_SkipUac_Administrator
2014-08-15 08:38 - 2014-08-15 08:38 - 00001258 _____ () C:\Users\Eduardo\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-08-15 08:38 - 2014-08-15 08:38 - 00001234 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-08-15 08:38 - 2014-08-15 08:38 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\IObit
2014-08-15 08:38 - 2014-08-15 08:38 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-08-15 08:36 - 2014-08-15 08:35 - 12906784 _____ (IObit) C:\Users\Eduardo\Downloads\iobituninstaller (1).exe
2014-08-15 08:35 - 2014-08-15 08:35 - 12906784 _____ (IObit) C:\Users\Eduardo\Downloads\iobituninstaller.exe
2014-08-15 07:56 - 2014-08-15 07:56 - 00380416 _____ () C:\Users\Eduardo\Downloads\unjnneeh.exe
2014-08-15 07:35 - 2014-08-14 22:01 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\CrossLoop
2014-08-15 07:27 - 2014-08-14 23:20 - 00000564 _____ () C:\SSUUpdater.log
2014-08-15 07:09 - 2014-08-15 07:09 - 00000000 ____D () C:\ProgramData\Splashtop
2014-08-15 07:09 - 2014-08-15 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Splashtop Remote
2014-08-15 07:09 - 2014-08-14 23:02 - 00000000 ____D () C:\Program Files (x86)\Splashtop
2014-08-15 07:05 - 2014-08-15 07:05 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-08-15 07:05 - 2014-08-15 07:05 - 00000000 ____D () C:\Users\Eduardo\Documents\Splashtop Whiteboard
2014-08-15 07:05 - 2014-08-15 07:05 - 00000000 ____D () C:\Users\Eduardo\Documents\Splashtop Presenter
2014-08-15 00:22 - 2014-08-15 00:21 - 05571320 _____ (Swearware) C:\Users\Eduardo\Downloads\ComboFix.exe
2014-08-15 00:16 - 2014-08-15 00:16 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Eduardo\Downloads\tdsskiller.exe
2014-08-15 00:14 - 2014-08-15 00:14 - 04817496 _____ () C:\Users\Eduardo\Downloads\RogueKiller.exe
2014-08-15 00:14 - 2014-08-15 00:14 - 00029160 _____ () C:\Windows\SysWOW64\Drivers\TrueSight.sys
2014-08-15 00:14 - 2014-08-15 00:14 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-08-15 00:05 - 2014-08-15 00:03 - 00039954 _____ () C:\Users\Eduardo\Downloads\Addition.txt
2014-08-15 00:05 - 2014-08-15 00:02 - 00061492 _____ () C:\Users\Eduardo\Downloads\FRST.txt
2014-08-15 00:05 - 2014-01-18 12:34 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-14 23:55 - 2014-08-14 23:55 - 00240773 _____ () C:\ProgramData\1408074320.bdinstall.bin
2014-08-14 23:50 - 2014-08-14 23:50 - 00002178 _____ () C:\Users\Public\Desktop\Bitdefender Antivirus Free Edition.lnk
2014-08-14 23:50 - 2014-08-14 23:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus Free Edition
2014-08-14 23:50 - 2014-08-14 23:48 - 00000000 ____D () C:\Program Files\Bitdefender
2014-08-14 23:49 - 2014-08-14 23:34 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\QuickScan
2014-08-14 23:49 - 2014-08-14 13:48 - 00000300 _____ () C:\Windows\Tasks\WSE_Astromenda.job
2014-08-14 23:41 - 2009-07-14 00:45 - 00438112 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-14 23:40 - 2014-08-14 23:40 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-14 23:39 - 2010-11-21 03:17 - 00000000 ____D () C:\Windows\ShellNew
2014-08-14 23:36 - 2013-12-05 00:25 - 00001945 _____ () C:\Windows\epplauncher.mif
2014-08-14 23:36 - 2013-12-05 00:23 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-14 23:36 - 2011-02-11 16:13 - 00000000 ____D () C:\Windows\Panther
2014-08-14 23:35 - 2014-08-14 23:35 - 00045491 _____ () C:\ProgramData\1408073683.bdinstall.bin
2014-08-14 23:33 - 2014-08-14 23:33 - 00002776 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-14 23:33 - 2014-08-14 23:33 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-14 23:33 - 2014-08-14 23:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-14 23:33 - 2014-08-14 23:33 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-14 23:30 - 2014-08-14 23:30 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\Oracle
2014-08-14 23:29 - 2014-08-14 23:29 - 00000000 ____D () C:\ProgramData\Sun
2014-08-14 23:29 - 2014-08-14 23:29 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-14 23:29 - 2013-12-05 00:23 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-14 23:29 - 2013-12-05 00:23 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-14 23:29 - 2013-12-05 00:23 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-14 23:28 - 2014-08-14 23:28 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-14 23:28 - 2014-08-14 23:28 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-14 23:28 - 2014-08-14 23:28 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-14 23:28 - 2014-08-14 23:28 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-14 23:28 - 2014-08-14 23:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-14 23:28 - 2014-08-14 23:28 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-14 23:25 - 2014-08-14 13:28 - 00000000 ____D () C:\Support
2014-08-14 23:25 - 2014-08-14 13:25 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\VOPackage
2014-08-14 23:25 - 2014-08-11 12:28 - 00000000 ____D () C:\Users\Eduardo\AppData\Roaming\Systweak
2014-08-14 23:25 - 2014-08-11 12:28 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-08-14 23:24 - 2014-08-14 23:24 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Splashtop
2014-08-14 23:11 - 2014-08-14 21:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-14 23:10 - 2014-01-15 20:10 - 00003942 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{9A1679FB-801D-41DE-AAA9-69800B9570D8}
2014-08-14 23:00 - 2014-08-14 22:59 - 20638872 _____ (Splashtop Inc.) C:\Users\Eduardo\Downloads\Splashtop_Streamer_WIN_v2.5.8.8.EXE
2014-08-14 22:19 - 2014-08-14 22:19 - 00000000 ____D () C:\Windows\pss
2014-08-14 22:02 - 2014-08-14 21:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 22:02 - 2014-08-14 13:27 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-08-14 22:00 - 2014-08-14 22:00 - 02174544 _____ (CrossLoop, Inc. ) C:\Users\Eduardo\Downloads\CrossLoopSetup.exe
2014-08-14 21:59 - 2014-08-14 21:59 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-14 21:59 - 2014-08-14 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-14 21:59 - 2014-08-14 21:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-14 21:59 - 2014-08-14 21:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-14 21:59 - 2014-01-18 14:32 - 00000000 ____D () C:\Users\Eduardo\Documents\Quickbooks back up
2014-08-14 21:42 - 2014-08-14 21:41 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Eduardo\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-14 19:33 - 2014-08-14 13:29 - 00001969 _____ () C:\Users\Eduardo\Desktop\Search.lnk
2014-08-14 19:33 - 2014-01-15 20:10 - 00001377 _____ () C:\Users\Eduardo\Desktop\Internet Explorer.lnk
2014-08-14 19:27 - 2009-07-13 22:34 - 00000489 _____ () C:\Windows\win.ini
2014-08-14 14:48 - 2014-08-14 14:28 - 00000378 _____ () C:\Windows\Tasks\APSnotifierPP1.job
2014-08-14 14:35 - 2014-08-14 14:35 - 00001103 _____ () C:\Users\Eduardo\Desktop\Continue Live Installation.lnk
2014-08-14 14:32 - 2014-08-14 14:28 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP3.job
2014-08-14 14:32 - 2014-08-14 14:28 - 00000376 _____ () C:\Windows\Tasks\APSnotifierPP2.job
2014-08-14 14:31 - 2014-03-10 14:43 - 00646069 _____ () C:\Users\Public\Documents\ATB PAYROLL SHEET (Autosaved).xlsx
2014-08-14 14:30 - 2014-08-14 14:28 - 00000318 _____ () C:\Users\Eduardo\AppData\Roaming\aps.uninstall.scan.results
2014-08-14 14:28 - 2014-08-14 14:28 - 00002832 _____ () C:\Windows\System32\Tasks\APSnotifierPP1
2014-08-14 14:28 - 2014-08-14 14:28 - 00002830 _____ () C:\Windows\System32\Tasks\APSnotifierPP3
2014-08-14 14:28 - 2014-08-14 14:28 - 00002830 _____ () C:\Windows\System32\Tasks\APSnotifierPP2
2014-08-14 14:26 - 2014-08-14 14:26 - 00575544 _____ (ClickMeIn Limited) C:\Users\Eduardo\AppData\Local\nsc8059.tmp
2014-08-14 13:48 - 2014-08-14 13:48 - 00003248 _____ () C:\Windows\System32\Tasks\WSE_Astromenda
2014-08-14 13:37 - 2014-01-18 12:36 - 00002243 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-14 13:36 - 2014-01-18 12:34 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-14 13:29 - 2014-08-14 13:29 - 00002497 _____ () C:\Users\Eduardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-14 13:27 - 2014-08-14 13:27 - 00004034 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-08-14 13:27 - 2014-08-14 13:27 - 00000000 ____D () C:\Users\Eduardo\Documents\Optimizer Pro
2014-08-14 13:27 - 2014-08-14 13:27 - 00000000 ____D () C:\Program Files (x86)\Supporter
2014-08-14 13:26 - 2014-08-14 13:26 - 00000394 __RSH () C:\ProgramData\ntuser.pol
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\QBDataServiceUser23\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\QBDataServiceUser23\AppData\Local\Google
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\QBDataServiceUser23\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\QBDataServiceUser23\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Guest
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Packages
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Chromatic Browser
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\Users\Administrator
2014-08-14 13:26 - 2014-08-14 13:26 - 00000000 ____D () C:\ProgramData\c5b0cd74f8fdb77a
2014-08-14 13:26 - 2014-01-18 12:34 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\Google
2014-08-14 13:26 - 2009-07-13 23:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-08-14 13:26 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-08-14 12:05 - 2014-01-15 20:45 - 00000000 ____D () C:\Users\Eduardo\Documents\ABA
2014-08-14 12:03 - 2009-07-14 01:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-08-14 11:32 - 2014-01-15 20:46 - 00000000 ____D () C:\Users\Eduardo\Documents\LALO
2014-08-14 10:44 - 2014-06-16 10:20 - 04264960 _____ () C:\Users\Public\Documents\Copy of Copy of Daily Hoja de Ruta ATB 2.xls
2014-08-14 03:32 - 2014-03-19 18:14 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-08-14 03:32 - 2014-03-19 18:14 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-08-14 03:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-14 03:14 - 2014-01-18 11:14 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-14 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-13 09:44 - 2014-01-15 20:46 - 00000000 ____D () C:\Users\Eduardo\Documents\QBOOKS FILES
2014-08-13 09:36 - 2014-01-15 20:10 - 00118848 _____ () C:\Users\Eduardo\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-11 16:12 - 2014-01-15 20:45 - 00000000 ____D () C:\Users\Eduardo\Documents\ATB INVOICES
2014-08-11 12:30 - 2014-08-11 12:30 - 00001180 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-11 12:30 - 2014-08-11 12:30 - 00001168 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-08-11 12:30 - 2014-08-11 12:30 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-08-11 12:28 - 2014-08-11 12:28 - 00000000 ____D () C:\Users\Eduardo\AppData\Local\globalUpdate
2014-08-11 12:28 - 2014-08-11 12:27 - 07500112 _____ (TeamViewer GmbH) C:\Users\Eduardo\Downloads\TeamViewer_Setup.exe
2014-08-06 22:06 - 2014-08-13 04:16 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-06 22:01 - 2014-08-13 04:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-05 19:14 - 2014-08-11 12:28 - 00020328 _____ () C:\Windows\system32\roboot64.exe
2014-08-05 09:20 - 2010-11-20 23:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-04 16:11 - 2014-01-15 20:45 - 00000000 ____D () C:\Users\Eduardo\Documents\ATB LABELS
2014-07-31 23:41 - 2014-08-14 21:58 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-31 19:41 - 2014-08-13 04:20 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-31 19:16 - 2014-08-13 04:20 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-25 10:52 - 2014-08-13 04:20 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-25 10:02 - 2014-08-13 04:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-25 10:01 - 2014-08-13 04:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-25 09:51 - 2014-08-13 04:20 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-25 09:30 - 2014-08-13 04:20 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-25 09:28 - 2014-08-13 04:20 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-25 09:28 - 2014-08-13 04:20 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-25 09:25 - 2014-08-13 04:20 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-25 09:25 - 2014-08-13 04:20 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-25 09:11 - 2014-08-13 04:20 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-25 09:10 - 2014-08-13 04:20 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-25 09:04 - 2014-08-13 04:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-25 09:03 - 2014-08-13 04:20 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-25 09:00 - 2014-08-13 04:20 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-25 09:00 - 2014-08-13 04:20 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-25 08:59 - 2014-08-13 04:20 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-25 08:47 - 2014-08-13 04:20 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-25 08:40 - 2014-08-13 04:20 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-25 08:34 - 2014-08-13 04:20 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-25 08:34 - 2014-08-13 04:20 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-25 08:33 - 2014-08-13 04:20 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-25 08:30 - 2014-08-13 04:20 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-25 08:28 - 2014-08-13 04:20 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-25 08:28 - 2014-08-13 04:20 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-25 08:21 - 2014-08-13 04:20 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-25 08:19 - 2014-08-13 04:20 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-25 08:18 - 2014-08-13 04:20 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-25 08:17 - 2014-08-13 04:20 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-25 08:17 - 2014-08-13 04:20 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-25 08:12 - 2014-08-13 04:20 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-25 08:10 - 2014-08-13 04:20 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-25 08:10 - 2014-08-13 04:20 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-25 08:08 - 2014-08-13 04:20 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-25 08:06 - 2014-08-13 04:20 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-25 07:52 - 2014-08-13 04:20 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-25 07:47 - 2014-08-13 04:20 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-25 07:43 - 2014-08-13 04:20 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-25 07:42 - 2014-08-13 04:20 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-25 07:39 - 2014-08-13 04:20 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-25 07:39 - 2014-08-13 04:20 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-25 07:36 - 2014-08-13 04:20 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-25 07:34 - 2014-08-13 04:20 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-25 07:29 - 2014-08-13 04:20 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-25 07:23 - 2014-08-13 04:20 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-25 07:13 - 2014-08-13 04:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-25 07:07 - 2014-08-13 04:20 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-25 07:07 - 2014-08-13 04:20 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-25 07:03 - 2014-08-13 04:20 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-25 06:52 - 2014-08-13 04:20 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-25 06:26 - 2014-08-13 04:20 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-25 06:17 - 2014-08-13 04:20 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-25 06:09 - 2014-08-13 04:20 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-25 06:05 - 2014-08-13 04:20 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-25 06:00 - 2014-08-13 04:20 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-24 03:01 - 2014-03-19 18:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-22 11:33 - 2014-04-03 12:10 - 00000000 ____D () C:\Users\Public\Documents\W7
2014-07-16 14:19 - 2014-07-16 14:19 - 00070876 _____ () C:\Users\Eduardo\Downloads\PGRDeclarationsPage (1).html
 
Some content of TEMP:
====================
C:\Users\Eduardo\AppData\Local\Temp\BackupSetup.exe
C:\Users\Eduardo\AppData\Local\Temp\post2.dll
C:\Users\Eduardo\AppData\Local\Temp\post2.exe
C:\Users\Eduardo\AppData\Local\Temp\SetupUtil.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-01-18 13:06
 
==================== End Of Log ============================
 
Thanks for any help
Link to post
Share on other sites

  • Staff

Hello,
    
 
They call me TwinHeadedEagle around here, and I'll be working with you.
 
    
 
    
Before we start please read and note the following:
    
icon_arrow.gif Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
icon_arrow.gif Please be patient. I know it is frustrating when your PC isn't working properly, but malware removal takes time.
icon_arrow.gif Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
icon_arrow.gif Do not paste the logs in your posts, attachments make my work easier. There is a Attach Files option below which you can use to attach your reports. Always attach reports from all tools.
icon_arrow.gif Stay with me to the end, the absence of symptoms doesn't mean that your machine is fully operational.
icon_arrow.gif Note that we may live in totally different time zones, what may cause some delays between answers.
icon_arrow.gif Do not ask for help for your business PC. Companies are making revenue via computers, so it is good thing to pay someone to repair it.
icon_arrow.gif If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
    
icon_idea.gif I can't foresee everything, so if anything unexpected happens, please stop and inform me!
icon_idea.gif There are no silly questions. Never be afraid to ask if in doubt!
 
 
 
 
P2P/Piracy Warning:

  • If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here.
  • Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.
  • If you have illegal/cracked software, cracks, keygens, etc. on the system, please remove or uninstall them now and read the policy on Piracy.

 

 

 

 

Please download Farbar Recovery Scan Tool and save it to your desktop.
 
Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Link to post
Share on other sites

  • Staff

Go and remove Snap.Do Engine
 
 
 
 
 
 
FRST.gif Fix with Farbar Recovery Scan Tool
 

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

 
Download attached fixlist.txt file and save it to the Desktop:
 
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 
 
 
 

adwcleaner_new.png Fix with AdwCleaner
 
Please download AdwCleaner by Xplode and save the file to your desktop.

  • Right-click on adwcleaner_new.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Follow the prompts and click Scan.
  • When finished, please click Clean.
  • Upon completion, click Report. A log (AdwCleaner[s*].txt) will open.

Please include the contents of that file in your reply.

fixlist.txt

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.