1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved IE Some settings are managed by your system administrator

Discussion in 'Malware and Virus Removal Archive' started by Anguisette, 2015/07/16.

  1. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    [Solved] IE Some settings are managed by your system administrator

    I received this after using the windows 8.1 refresh. My computer will not fully reset IE to factory and my work from home tech team states I need to do a 0 out of my computer to resolve it. Help!
     
  2. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
    Ran by Rosa (administrator) on ROSA on 16-07-2015 07:57:03
    Running from C:\Users\Rosa\Downloads
    Loaded Profiles: Rosa (Available Profiles: Rosa & sdcfalcon & Administrator)
    Platform: Windows 8.1 (X64) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
    (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
    (IntraNext Systems) C:\Program Files (x86)\CSG\Softphone 9\CTIHub.exe
    (Microsoft Corporation) C:\Windows\System32\dasHost.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Avaya Inc.) C:\Windows\SysWOW64\QosServM.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (Support.com) C:\Program Files (x86)\Support.com\SDCWB_Helper_Service\SDCWB_Service.exe
    (Support.com) C:\Program Files (x86)\Support.com\SDCWB_Helper_Service\sdcwbServiceUpdater.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
    (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
    (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
    (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
    (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
    (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
    (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
    (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
    (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor)
    HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll ",TrayApp
    HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90832 2012-06-07] (ASUS)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-04-29] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
    HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1056976 2014-06-27] (Carbonite, Inc.)
    HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707496 2014-06-10] (Cisco Systems, Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
    HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated)
    Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\...\Run: [GoogleChromeAutoLaunch_4F4C99A09FCA90488F664860022AA70B] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-07-13] (Google Inc.)
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.)
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\...\Run: [AdobeBridge] => [X]
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-12-12]
    ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NAC Assessment Agent.lnk [2015-07-12]
    ShortcutTarget: NAC Assessment Agent.lnk -> C:\Program Files (x86)\Extreme Networks\NAC Agent\NacAgent.exe (Extreme Networks, Inc)
    ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
    SearchScopes: HKU\S-1-5-21-526706507-2563106057-1816975683-1001 -> DefaultScope {280BEABE-A425-4906-B1C0-5B800289D9B7} URL = https://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
    SearchScopes: HKU\S-1-5-21-526706507-2563106057-1816975683-1001 -> {280BEABE-A425-4906-B1C0-5B800289D9B7} URL = https://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-07-12] (Oracle Corporation)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-12] (Oracle Corporation)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
    Tcpip\..\Interfaces\{C692156E-AF27-4CA2-8B68-D864E07B431A}: [DhcpNameServer] 75.75.75.75 75.75.76.76
    Tcpip\..\Interfaces\{F47131B4-841B-4AD4-A754-E3F38BD9561C}: [DhcpNameServer] 75.75.75.75 75.75.76.76

    FireFox:
    ========
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
    FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-12] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-12] (Oracle Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
    FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
    FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)

    Chrome:
    =======
    CHR Profile: C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (iStoryBooks) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\anbmgijcnihjphndkjglleofcnohhkkl [2015-07-12]
    CHR Extension: (Google Drive) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-12]
    CHR Extension: (YouTube) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-12]
    CHR Extension: (HelloFax: 50 Free Fax Pages) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm [2015-07-12]
    CHR Extension: (Google Search) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-12]
    CHR Extension: (Post To Tumblr) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbpicbbcpanckagpdjflgojlknomoiah [2015-07-12]
    CHR Extension: (Logitech Smooth Scrolling) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2015-07-12]
    CHR Extension: (The Godfather: Five Families) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\edfkoljdeffeedleidebkmmamepgbnbl [2015-07-12]
    CHR Extension: (Ponyhoof) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\efjjgphedlaihnlgaibiaihhmhaejjdd [2015-07-12]
    CHR Extension: (Google Calendar) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-07-12]
    CHR Extension: (Google Sheets) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-12]
    CHR Extension: (AdBlock) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-07-12]
    CHR Extension: (Pictico "” Coloring for Kids) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gndkeamlgkegbmmoheplcndpopglacgf [2015-07-12]
    CHR Extension: (Pin It Button) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-07-12]
    CHR Extension: (World of Solitaire) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn [2015-07-12]
    CHR Extension: (MOG Music) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgljcanfdcmdnncaneopdlcgjlkgpenj [2015-07-12]
    CHR Extension: (MeeGenius! Children's Books) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhfhmaajajcjoijfaceafiembkmhcddc [2015-07-12]
    CHR Extension: (TARDIS) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjifgneioddlgbglnkppcblkccmninme [2015-07-12]
    CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-12]
    CHR Extension: (Zombie Drop) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhmhllfgcoopjdmcmdeobhgimokcabmc [2015-07-12]
    CHR Extension: (Listube - Free Online On-Demand Music Player) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlelfeaeehmpkbcfjmjcbilahepgcjgk [2015-07-12]
    CHR Extension: (Google Wallet) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-12]
    CHR Extension: (Atari - Missile Command) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\oobnopfjjndfekinfcddimnjbhjdgmbg [2015-07-12]
    CHR Extension: (Gmail) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-12]
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
    S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-11-21] (Microsoft Corporation)
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
    R2 CTIHub; C:\Program Files (x86)\CSG\Softphone 9\CTIHub.exe [31744 2014-09-12] (IntraNext Systems) [File not signed]
    R2 iClarityQoSService; C:\WINDOWS\SysWOW64\\QosServM.exe [233472 2010-11-09] (Avaya Inc.) [File not signed]
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
    R2 SDCWB_Service; C:\Program Files (x86)\Support.com\SDCWB_Helper_Service\SDCWB_Service.exe [15680 2015-04-27] (Support.com)
    R2 SDCWB_UpdaterService; C:\Program Files (x86)\Support.com\SDCWB_Helper_Service\sdcwbServiceUpdater.exe [13632 2015-04-27] (Support.com)
    S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-07-12] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-07-12] (Microsoft Corporation)
    R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-11-21] (Microsoft Corporation)
    R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-10-15] (Motorola Solutions, Inc.)
    R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-01] ( )
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-16] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
    R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
    S3 ssmirrdr; C:\Windows\system32\DRIVERS\ssmirrdr.sys [10112 2015-06-09] (support.com, Inc)
    S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-06-10] (Cisco Systems, Inc.)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-07-12] (Microsoft Corporation)
    S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider)

    ========================== Drivers MD5 =======================

    C:\Windows\System32\drivers\1394ohci.sys E1832BD9FD7E0FC2DC9FA5935DE3E8C1
    C:\Windows\System32\drivers\3ware.sys AD508A1A46EC21B740AB31C28EFDFDB1
    C:\Windows\System32\drivers\ACPI.sys E796AE43DDD1844281DB4D57294D17C0
    C:\Windows\System32\Drivers\acpiex.sys AC8279D229398BCF05C3154ADCA86813
    C:\Windows\System32\drivers\acpipagr.sys A8970D9BF23CD309E0403978A1B58F3F
    C:\Windows\System32\drivers\acpipmi.sys 111A89C99C5B4F1A7BCE5F643DD86F65
    C:\Windows\System32\drivers\acpitime.sys 5758387D68A20AE7D3245011B07E36E7
    C:\Windows\system32\DRIVERS\acsock64.sys D0B11E40EA74A98A5E133DF1F5276240
    C:\Windows\System32\drivers\ADP80XX.SYS 7C1FDF1B48298CBA7CE4BDD4978951AD
    C:\Windows\system32\drivers\afd.sys 374E27295F0A9DCAA8FC96370F9BEEA5
    C:\Windows\System32\drivers\agp440.sys 7DFAEBA9AD62D20102B576D5CAC45EC8
    C:\Windows\System32\DRIVERS\ahcache.sys FE14D249D39368CA62D8DA6BC94AC694
    C:\Windows\system32\DRIVERS\AiCharger.sys 16F6F6B7903B913AB41AB848C8BB5658
    C:\Windows\System32\drivers\amdk8.sys 7589DE749DB6F71A68489DCE04158729
    C:\Windows\System32\drivers\amdppm.sys B46D2D89AFF8A9490FA8C98C7A5616E3
    C:\Windows\System32\drivers\amdsata.sys D2BF2F94A47D332814910FD47C6BBCD2
    C:\Windows\System32\drivers\amdsbs.sys A8E04943C7BBA7219AA50400272C3C6E
    C:\Windows\System32\drivers\amdxata.sys CEA5F4F27CFC08E3A44D576811B35F50
    C:\Windows\System32\drivers\AMPPAL.sys B716710EEE22D85EE26FB5EB26FC5C67
    C:\Windows\system32\drivers\appid.sys 415DD71628795197F7AFC176CBADC74E
    C:\Windows\System32\drivers\arcsas.sys 65045784366F7EC5FB4E71BCF923187B
    C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys 4C016FD76ED5C05E84CA8CAB77993961
    C:\Windows\System32\drivers\atapi.sys 74B14192CF79A72F7536B27CB8814FBD
    C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys 41CEAFFCF3550785E59E3EC9BEE8D97A
    C:\Windows\System32\drivers\AsusTP.sys 437EB91CB20144375DDE145149778405
    C:\Windows\System32\drivers\bxvbda.sys A4A73F631FE2AA2826FBE4A399B04DEF
    C:\Windows\System32\drivers\BasicDisplay.sys 8CC7F7E4AFCBA605921B137ED7992C68
    C:\Windows\System32\drivers\BasicRender.sys 38A82F4EE8C416A6744B6D30381ED768
    C:\Windows\System32\drivers\bcmfn2.sys C1ABB0F7E3BEA48A0417BDF6FF14AB21
    C:\Windows\System32\Drivers\Beep.sys EC19013E4CF87609534165DF897274D6
    C:\Windows\System32\DRIVERS\bowser.sys 6B4FFFDDC618FCF64473CAA86E305697
    C:\Windows\System32\drivers\BthAvrcpTg.sys A8F23D453A424FF4DE04989C4727ECC7
    C:\Windows\System32\drivers\BthEnum.sys 1104A31260CCF4318C884E0AE6C513BF
    C:\Windows\System32\drivers\bthhfenum.sys 272A62B660A48AEF366F8A1836CED19F
    C:\Windows\System32\drivers\BthHFHid.sys 71FE2A48E4C93DDB9798C024880B6C07
    C:\Windows\system32\DRIVERS\BthLEEnum.sys D30C67473A2E229662D21F27EAA9AAA5
    C:\Windows\System32\drivers\bthmodem.sys EF4B9E7C9AD88C00C18A12B0D22D1894
    C:\Windows\system32\DRIVERS\bthpan.sys 25BB93167DEF270188072603F92A1EF5
    C:\Windows\System32\Drivers\BTHport.sys 0CC00ADC1B84C93FB46E1A0974E956E1
    C:\Windows\System32\Drivers\BTHUSB.sys 08EA90955AED2D959EE67DF6EDF0E2B6
    C:\Windows\system32\DRIVERS\btmhsf.sys 7B31A8A9DC95B3634D896FD0F2814F19
    C:\Windows\System32\DRIVERS\cdfs.sys 2FA6510E33F7DEFEC03658B74101A9B9
    C:\Windows\System32\drivers\cdrom.sys C6796EA22B513E3457514D92DCDB1A3D
    C:\Windows\System32\drivers\circlass.sys BE9936EDD3267FAAFF94A7835867F00B
    C:\Windows\System32\drivers\CLFS.sys 8EB7E70C2D348FE2476A2E3F2D585E3D
    C:\Windows\System32\drivers\CmBatt.sys EF6EF85DADC3184A10D8F2F7159973CB
    C:\Windows\System32\Drivers\cng.sys 5E5AB950693F2C6D6ACBEE3A74697ED7
    C:\Windows\System32\drivers\CompositeBus.sys 03AAED827C36F35D70900558B8274905
    C:\Windows\System32\drivers\condrv.sys A1FF7DFBFBE164CF92603C651D304DD2
    C:\Windows\System32\drivers\dam.sys 389C998C64319CD97625B0550E52ECFA
    C:\Windows\System32\Drivers\dfsc.sys A03F362C5557E238CBFA914689C77248
    C:\Windows\System32\drivers\disk.sys 4D40C9B33F738797CF50E77CB7C53E85
    C:\Windows\System32\drivers\dmvsc.sys EB70A894708D1BC176AFD690FF06085F
    C:\Windows\system32\drivers\drmkaud.sys 00C594D5A1DBD22AD8B2902B9F6EFF94
    C:\Windows\System32\drivers\dxgkrnl.sys E1BB0B6F00F470B451AB45EA13EBA0B3
    C:\Windows\System32\drivers\evbda.sys 114BCFDF367FF37C3F1B0A96AF542E4D
    C:\Windows\System32\drivers\EhStorClass.sys 43531A5993380CC5113242C29D265FD9
    C:\Windows\System32\drivers\EhStorTcgDrv.sys 6F8E738A9505A388B1157FDDE7B3101B
    C:\Windows\System32\drivers\errdev.sys DFFFAE1442BA4076E18EED5E406FA0D3
    C:\Windows\System32\Drivers\exfat.sys 7729D294A555C7AEB281ED8E4D0E01E4
    C:\Windows\System32\Drivers\fastfat.sys 7C4E0D5900B2A1D11EDD626D6DDB937B
    C:\Windows\System32\drivers\fdc.sys 5D8402613E778B3BD45E687A8372710B
    C:\Windows\System32\drivers\fileinfo.sys BCFD8B149B3ADF92D0DB1E909CAF0265
    C:\Windows\System32\drivers\filetrace.sys A1A66C4FDAFD6B0289523232AFB7D8AF
    C:\Windows\System32\drivers\flpydisk.sys BE743083CF7063C486A4398E3AEFE59A
    C:\Windows\System32\drivers\fltmgr.sys C1FB505A73FA2E9019D32444AB33B75A
    C:\Windows\System32\drivers\FsDepends.sys A7C31B168F371E8E6796219F23E354DB
    C:\Windows\System32\Drivers\Fs_Rec.sys 09F460AFEDCA03F3BF6E07D1CCC9AC42
    C:\Windows\System32\DRIVERS\fvevol.sys F152D55E497E12256290C43B31C7D0CE
    C:\Windows\System32\drivers\fxppm.sys 9591D0B9351ED489EAFD9D1CE52A8015
    C:\Windows\System32\drivers\gagp30kx.sys FC3EF65EE20D39F8749C2218DBA681CA
    C:\Windows\System32\drivers\vmgencounter.sys 0BF5CAD281E25F1418E5B8875DC5ADD1
    C:\Windows\System32\Drivers\msgpioclx.sys 8DF1254093B5C354CE725EB6B9B0DE19
    C:\Windows\System32\drivers\HDAudBus.sys D4B7ED39C7900384D9E5C1283F1E7926
    C:\Windows\System32\drivers\HidBatt.sys 10A70BC1871CD955D85CD88372724906
    C:\Windows\System32\drivers\hidbth.sys 42F88B57CAE42FC10059C887B3FCFCEA
    C:\Windows\System32\drivers\hidi2c.sys C241A8BAFBBFC90176EA0F5240EACC17
    C:\Windows\System32\drivers\hidir.sys 9BDDEE26255421017E161CCB9D5EDA95
    C:\Windows\System32\drivers\AsHIDSwitch64.sys 894D982CEAB8CD45A56AE2C9988E86C0
    C:\Windows\System32\drivers\hidusb.sys 8DB8EAB9D0C6A5DF0BDCADEA239220B4
    C:\Windows\System32\drivers\HpSAMD.sys A6AACEA4C785789BDA5912AD1FEDA80D
    C:\Windows\System32\drivers\HTTP.sys E87A6D3B8FECD5B93BC0CFBB48C27970
    C:\Windows\System32\drivers\hwpolicy.sys 90656C0B3864804B090434EFC582404F
    C:\Windows\System32\drivers\hyperkbd.sys 6D6F9E3BF0484967E52F7E846BFF1CA1
    C:\Windows\system32\DRIVERS\HyperVideo.sys 907C870F8C31F8DDD6F090857B46AB25
    C:\Windows\System32\drivers\i8042prt.sys 49EE0AE9E5B64FFBBD06D55C4984B598
    C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 5D90E32E36CE5D4C535D17CE08AEAF05
    C:\Windows\System32\drivers\iaLPSSi_I2C.sys DD05E7E80F52ADE9AEB292819920F32C
    C:\Windows\System32\drivers\iaStorA.sys 0FE66A51D81A25AACEAAE4C26308121D
    C:\Windows\System32\drivers\iaStorAV.sys 08BFE413B0B4AA8DFA4B5684CE06D3DC
    C:\Windows\System32\drivers\iaStorV.sys A2200C3033FA4EF249FC096A7A7D02A2
    C:\Windows\system32\DRIVERS\iBtFltCoex.sys 23E22B130EFE5A225E279467BE146317
    C:\Windows\system32\DRIVERS\igdkmd64.sys 16D939A13CFB82DEE0B9DB12E45C7B4E
    C:\Windows\system32\drivers\intelaud.sys DB65573521AB51941F4FA799D0968136
    C:\Windows\system32\drivers\RTKVHD64.sys 6BDCC85422817FA53CD705ADE312CE6A
    C:\Windows\system32\DRIVERS\IntcDAud.sys F5495B38BFB9149925F54F65AB40EFBF
    C:\Windows\System32\drivers\intelide.sys 4E448FCFFD00E8D657CD9E48D3E47157
    C:\Windows\System32\drivers\intelpep.sys 7AA01AB1C110916825E6E1389F1B9AF2
    C:\Windows\System32\drivers\intelppm.sys 47E74A8E53C7C24DCE38311E1451C1D9
    C:\Windows\System32\DRIVERS\ipfltdrv.sys 9DB76D7F9E4E53EFE5DD8C53DE837514
    C:\Windows\System32\drivers\IPMIDrv.sys 9C096BF5E10CA8BFA56F32522A89FAF1
    C:\Windows\System32\drivers\ipnat.sys B7342B3C58E91107F6E946A93D9D4EFD
    C:\Windows\System32\drivers\irenum.sys AE44C526AB5F8A487D941CEB57B10C97
    C:\Windows\System32\drivers\isapnp.sys 8AFEEA3955AA43616A60F133B1D25F21
    C:\Windows\System32\drivers\msiscsi.sys D90AB68D0FAC9F357F663670FDBB511E
    C:\Windows\System32\drivers\iwdbus.sys 2C04ACF9070282AC9AA837C52CA3C128
    C:\Windows\System32\drivers\kbdclass.sys 5917AFE4A3F695A54B99C1849C8207FE
    C:\Windows\System32\drivers\kbdhid.sys 8CD840A062F6BDF41DDE3ACB96164B72
    C:\Windows\System32\drivers\kbfiltr.sys A8080BEBCDB7A16495CE1205921DCAC5
    C:\Windows\system32\DRIVERS\kdnic.sys 813871C7D402A05F2E3A7075F9584A05
    C:\Windows\System32\Drivers\ksecdd.sys 4E829B18D5BAEC29893792A3C671A847
    C:\Windows\System32\Drivers\ksecpkg.sys 46711F40D0F9E63F786ED23F9BD5215E
    C:\Windows\system32\drivers\ksthunk.sys 11AFB527AA370B1DAFD5C36F35F6D45F
    C:\Windows\system32\DRIVERS\lltdio.sys C09010B3680860131631F53E8FE7BAD8
    C:\Windows\System32\drivers\lsi_sas.sys C755AE4635457AA2A11F79C0DF857ABC
    C:\Windows\System32\drivers\lsi_sas2.sys ADAC09CBE7A2040B7F68B5E5C9A75141
    C:\Windows\System32\drivers\lsi_sas3.sys 04D1274BB9BBCCF12BD12374002AA191
    C:\Windows\System32\drivers\lsi_sss.sys 327469EEF3833D0C584B7E88A76AEC0C
    C:\Windows\system32\drivers\luafv.sys DDEE191AB32DFC22C6465002ECDF5EE4
    C:\WINDOWS\system32\drivers\mbam.sys A8D28D5B3E2A528D1EF0E338E44F2820
    C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys 8F22037D3F5A6BB676525D825A1388B9
    C:\WINDOWS\system32\drivers\mwac.sys 85CFE7AB85B43B6B7AC7961AA3983A9F
    C:\Windows\System32\drivers\megasas.sys EB5C03A070F30D64A6DF80E53B22F53F
    C:\Windows\System32\drivers\megasr.sys F6F13533196DE7A582D422B0241E4363
    C:\Windows\System32\drivers\HECIx64.sys 772A1DEEDFDBC244183B5C805D1B7D85
    C:\Windows\System32\drivers\modem.sys 8B38C44F69259987C95135C9627E2378
    C:\Windows\System32\drivers\monitor.sys 601589000CC90F0DF8DA2CC254A3CCC9
    C:\Windows\System32\drivers\mouclass.sys 08374E4E5B8914DE6067CBA99F61E930
     

  3. to hide this advert.

  4. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    C:\Windows\System32\drivers\mouhid.sys 5FCBAB60598AE119E02B4C27DE6B99EA
    C:\Windows\System32\drivers\mountmgr.sys D1D82F007A079A4D623DBD1F36EF30A1
    C:\Windows\System32\drivers\mpsdrv.sys 6FC047578785B0435F4E2660946D1ADC
    C:\Windows\system32\drivers\mrxdav.sys DB32958F0E704EFBF7F15161A569E39F
    C:\Windows\System32\DRIVERS\mrxsmb.sys 6FBDF2B1B025A8E6E069234362FFFFB7
    C:\Windows\System32\DRIVERS\mrxsmb10.sys BCBD64220AD85C26823453FF1DC3EFBD
    C:\Windows\System32\DRIVERS\mrxsmb20.sys 57C2473D501331211D6885FD59F3E44B
    C:\Windows\system32\DRIVERS\bridge.sys F3C060444777A59FC63D920719E43CCD
    C:\Windows\System32\Drivers\Msfs.sys D13329FBF8345B28AB30F44CC247DC08
    C:\Windows\System32\drivers\msgpiowin32.sys C6B474E46F9E543B875981ED3FFE6ADD
    C:\Windows\System32\drivers\mshidkmdf.sys 65C92EB9D08DB5C69F28C7FFD4E84E31
    C:\Windows\System32\drivers\mshidumdf.sys 52299F086AC2DAFD100DD5DC4A8614BA
    C:\Windows\System32\drivers\msisadrv.sys 36D92AF3343C3A3E57FEF11C449AEA4C
    C:\Windows\system32\drivers\MSKSSRV.sys A9BBBD2BAE6142253B9195E949AC2E8D
    C:\Windows\system32\DRIVERS\mslldp.sys 51B3AC0560848CD6D65AC2033E293113
    C:\Windows\system32\drivers\MSPCLOCK.sys 7B2128EB875DCBC006E6A913211006D6
    C:\Windows\system32\drivers\MSPQM.sys 1E88171579B218115C7A772F8DE04BD8
    C:\Windows\System32\Drivers\MsRPC.sys BBE2A455053E63BECBF42C2F9B21FAE0
    C:\Windows\System32\drivers\mssmbios.sys 8D6B7D515C5CBCDB75B928A0B73C3C5E
    C:\Windows\system32\drivers\MSTEE.sys 115019AE01E0EB9C048530D2928AB4A2
    C:\Windows\System32\drivers\MTConfig.sys 96D604A35070360F0DD4A7A8AF410B5E
    C:\Windows\System32\Drivers\mup.sys 619CA29326B82372621DB2C0964D8365
    C:\Windows\System32\drivers\mvumis.sys B8C35C94DCB2DFEAF03BB42131F2F77F
    C:\Windows\system32\DRIVERS\nwifi.sys 008F7CED69FD5B30CBDE1E03C6F36A27
    C:\Windows\System32\drivers\ndis.sys 6D3A2565E01B3E4B0F1BEDB0D4B00B3F
    C:\Windows\system32\DRIVERS\ndiscap.sys 8CECC8DA55F3274181FD1EA28AD76664
    C:\Windows\system32\DRIVERS\NdisImPlatform.sys 269882812E9A68FFF1AFE1283D428322
    C:\Windows\system32\DRIVERS\ndistapi.sys DC1D9F692C2AD84C214584C28501C1F7
    C:\Windows\system32\DRIVERS\ndisuio.sys B832B35055BA2B7B4181861FF94D8E59
    C:\Windows\System32\drivers\NdisVirtualBus.sys 1F58E48EF75F34C35D8E93A0DC535CFE
    C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
    C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
    C:\Windows\System32\Drivers\NDProxy.sys 0BBE2FA30BAD58C9ADC01E4F84A3D2A1
    C:\Windows\System32\drivers\Ndu.sys 3083926D1CC5B56EA0786527B557DD1B
    C:\Windows\System32\DRIVERS\netbios.sys 42FF4975D032CAE558AE4BB8448F6E5A
    C:\Windows\System32\DRIVERS\netbt.sys 0217532E19A748F0E5D569307363D5FD
    C:\Windows\System32\drivers\netvsc63.sys D4DCE03870314D3354F3501F9DDD4123
    C:\Windows\system32\DRIVERS\Netwew00.sys 75B9B86878CC159FBC40C4F9202ADBE3
    C:\Windows\System32\Drivers\Npfs.sys 8F44A2F57C9F1A19AC9C6288C10FB351
    C:\Windows\System32\drivers\npsvctrig.sys CBDB4F0871C88DF930FC0E8588CA67FC
    C:\Windows\System32\drivers\nsiproxy.sys 0E046FF5823B95326D10CF1B4AF23541
    C:\Windows\System32\Drivers\Ntfs.sys 7F68063A5A0461E02BC860CE0E6BFDDC
    C:\Windows\System32\Drivers\Null.sys EF1B290FC9F0E47CC0B537292BEE5904
    C:\Windows\System32\drivers\nvraid.sys BC6B5942AFF25EBAF62DE43C3807EDF8
    C:\Windows\System32\drivers\nvstor.sys 1F43ABFFAC3D6CA356851D517392966E
    C:\Windows\System32\drivers\nv_agp.sys 6934A936A7369DFE37B7DBA93F5E5E49
    C:\Windows\System32\drivers\parport.sys 764B1121867B2D9B31C491668AC72B2B
    C:\Windows\System32\drivers\partmgr.sys BAFF6122CFC9F95CA175AD8C348179A4
    C:\Windows\System32\drivers\pci.sys 91ED124E261EA8FAA1C0FFDF2A71B0C4
    C:\Windows\System32\drivers\pciide.sys 346E38FCC6859A727DD28AFAD1F0AFF4
    C:\Windows\System32\drivers\pcmcia.sys 4D3BDCC1C7B40C9D7B6AD990E6DEC397
    C:\Windows\System32\drivers\pcw.sys BF28771D1436C88BE1D297D3098B0F7D
    C:\Windows\System32\drivers\pdc.sys ED54A75050211DC77F9B98C41E026858
    C:\Windows\System32\drivers\peauth.sys 0ECEE590F2E2EF969FB74A6FC583A1E6
    C:\Windows\System32\drivers\processr.sys ECD373F9571C745894367CC2635EA44F
    C:\Windows\system32\DRIVERS\pacer.sys FC0141B4A5AD6D637D883C1A89FC45C5
    C:\Windows\system32\drivers\qwavedrv.sys 83868EB2924E6BC21A54337C65D614D1
    C:\Windows\System32\DRIVERS\rasacd.sys B337B1F1E82A83E20A1743E008E25C0F
    C:\Windows\system32\DRIVERS\raspppoe.sys 5247F308C4103CDC4FE12AE1D235800A
    C:\Windows\System32\DRIVERS\rdbss.sys A1A5E79C0D1352AFDC08328A623DA051
    C:\Windows\System32\drivers\rdpbus.sys 6B21EBF892CD8CACB71669B35AB5DE32
    C:\Windows\System32\drivers\rdpdr.sys 680C1DAE268B6FB67FA21B389A8B79EF
    C:\Windows\System32\drivers\rdpvideominiport.sys BC8A79C625568DDB7DCA49D0C2741A64
    C:\Windows\System32\drivers\rdyboost.sys A26AEC49F318FEE141DDDB2C5F99B3E6
    C:\Windows\System32\Drivers\ReFS.sys 615DFD97DEA56CE1C3A52185A3038FF8
    C:\Windows\System32\drivers\rfcomm.sys DC66AE45816614D2999DCD3834DCCC4E
    C:\Windows\system32\DRIVERS\rspndr.sys 2D05A5508F4685412F2B89E8C2189ABC
    C:\Windows\System32\Drivers\RtsUStor.sys 0E32A8922DCFD28EA00AAEC07CB3F331
    C:\Windows\system32\DRIVERS\Rt630x64.sys 19764658C1468C2C0CEF133D28414A6B
    C:\Windows\System32\drivers\vms3cap.sys 1A063730F221B2746FF00457AE17E4F0
    C:\Windows\System32\drivers\sbp2port.sys C624A1B32211C3166EDB3F4AB02A30B7
    C:\Windows\System32\DRIVERS\scfilter.sys 13BEA6C882D4D877A5A85CA149C86BC1
    C:\Windows\System32\drivers\sdbus.sys C54B6B2170BF628FD42F799A66956D75
    C:\Windows\System32\drivers\sdstor.sys 0B1E929D11A8E358106955603FAC65E8
    C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
    C:\Windows\System32\drivers\SerCx.sys DB2FF24CE0BDD15FE75870AFE312BA89
    C:\Windows\System32\drivers\SerCx2.sys 0044B31F93946D5D41982314381FE431
    C:\Windows\System32\drivers\serenum.sys 3CD600C089C1251BEEB4CD4CD5164F9E
    C:\Windows\System32\drivers\serial.sys D864381BC9C725FAB01D94C060660166
    C:\Windows\System32\drivers\sermouse.sys 148195AE95D9BC7375A08846439FDAC1
    C:\Windows\System32\drivers\sfloppy.sys 472B7A5AC181C050888DB454663DD764
    C:\Windows\System32\drivers\SiSRaid2.sys 2F518D13DD6F3053837FE606F1A2EA1F
    C:\Windows\System32\drivers\sisraid4.sys 1AC9A200A9C49C4508F04AAFFCA34A3F
    C:\Windows\System32\drivers\spaceport.sys D24B1945ED1F9C96DA786DBBF1E983CE
    C:\Windows\System32\drivers\SpbCx.sys F337BE11071818FC3F5DC2940B6BDE34
    C:\Windows\System32\DRIVERS\srv.sys 6416E79A58A8FCC33A447A4DDDD3BF04
    C:\Windows\System32\DRIVERS\srv2.sys 00D8AC8E3053290BDE6EA2FB6810D2FC
    C:\Windows\System32\DRIVERS\srvnet.sys D047CD668E6277FD80F0C613946F034C
    C:\Windows\system32\DRIVERS\ssmirrdr.sys 1100066057FBF612B573EFD3B21383F1
    C:\Windows\System32\drivers\stexstor.sys 366DEA74BBA65B362BCCFC6FC2ADFD8B
    C:\Windows\System32\drivers\storahci.sys 0ED2E318ABB68C1A35A8B8038BDB4C90
    C:\Windows\System32\drivers\vmstorfl.sys 8B9486B64E5FC17FB9CC04CA10B77A34
    C:\Windows\System32\drivers\stornvme.sys 6B06E2D11E604BE2B1A406C4CB3B90DE
    C:\Windows\System32\drivers\storvsc.sys 548759755BC73DAD663250239D7E0B9F
    C:\Windows\System32\drivers\swenum.sys 65454187E0F8B6C0DCECB0287D06EC43
    C:\Windows\System32\drivers\tcpip.sys 3C2DF97A21A9BBE6355B0A51F288EFFF
    C:\Windows\system32\DRIVERS\tcpip.sys 3C2DF97A21A9BBE6355B0A51F288EFFF
    C:\Windows\System32\drivers\tcpipreg.sys 41CF802064F72E55F50CA0A221FD36D4
    C:\Windows\system32\DRIVERS\tdx.sys FFF28F9F6823EB1756C60F1649560BBF
    C:\Windows\System32\drivers\terminpt.sys 232D185D2337F141311D0CF1983E1431
    C:\Windows\system32\drivers\tpm.sys 82F909359600D3603FE852DB7F135626
    C:\Windows\System32\drivers\tsusbflt.sys BF8F54CA37E9C9D6582C31C5761F8C93
    C:\Windows\System32\drivers\TsUsbGD.sys 20185BEB7512EDE4EFECDFA148AC9F99
    C:\Windows\system32\DRIVERS\tunnel.sys C8E0E78B5D284C2FF59BDFFDAF997242
    C:\Windows\System32\drivers\uagp35.sys F6EEAD052943B5A3104C1405BB856C54
    C:\Windows\System32\drivers\uaspstor.sys FE6067B1FD4E63650C667B33D080565B
    C:\Windows\System32\drivers\ucx01000.sys 807F8CF3E973305FC435C61CBBEE2A49
    C:\Windows\System32\DRIVERS\udfs.sys C61EAF8E1E4B2F62BA4FDF457440B2C6
    C:\Windows\System32\drivers\UEFI.sys 9578691F297E1B1F519970FE6D47CB21
    C:\Windows\System32\drivers\uliagpkx.sys 5EAB5117DDB24FC4D39E6FFFCF1837B9
    C:\Windows\System32\drivers\umbus.sys DA34C39A18E60E7C3FA0630566408034
    C:\Windows\System32\drivers\umpass.sys AE8294875E5446E359B1E8035D40C05E
    C:\Windows\system32\drivers\usbaudio.sys DF355EB0199198728027962DCFCDE5FB
    C:\Windows\System32\drivers\usbccgp.sys FF78D053A05E5A394F4E3C1816CC65A8
    C:\Windows\System32\drivers\usbcir.sys 0139248F6B95CF0D837B5B46A2722D40
    C:\Windows\System32\drivers\usbehci.sys 48BA326A3DBA5B5BEB5F2777F4618696
    C:\Windows\System32\drivers\usbhub.sys FEF0BC107812B36849741C3211BA6B60
    C:\Windows\System32\drivers\UsbHub3.sys 95B0179BDA907252025DEEA183699FB3
    C:\Windows\System32\drivers\usbohci.sys 3019097FB6C985EF24C058090FF3BDBD
    C:\Windows\System32\drivers\usbprint.sys 4D655E3B684BE9B0F7FFD8A2935C348C
    C:\Windows\System32\drivers\USBSTOR.SYS 66732C13628BDB1AB0D6FD46027327C2
    C:\Windows\System32\drivers\usbuhci.sys 064260B3A5868AC894A4943543BC7AB7
    C:\Windows\System32\Drivers\usbvideo.sys 5C8F604F6DC74177CDD8372D7B1ADFF0
    C:\Windows\System32\drivers\USBXHCI.SYS 44603DA5A87FB491EF59C889EBBB4DDB
    C:\Windows\System32\drivers\vdrvroot.sys FEB26E3B8345A7E8D62F945C4AE86562
    C:\Windows\System32\drivers\VerifierExt.sys A026EDEAA5EECAE0B08E2748B616D4BD
    C:\Windows\System32\drivers\vhdmp.sys F6ECFD6128A16A4851CFE98D4E01B011
    C:\Windows\System32\drivers\viaide.sys 06D38968028E9AB19DE9B618C7B6D199
    C:\Windows\System32\drivers\vmbus.sys 511AD3FF957A0127E6BD336FF6F89C38
    C:\Windows\System32\drivers\VMBusHID.sys DA40BEA0A863CE768C940CA9723BF81F
    C:\Windows\System32\drivers\volmgr.sys 55D7D963DE85162F1C49721E502F9744
    C:\Windows\System32\drivers\volmgrx.sys CCB9E901F7254BF96D28EB1B0E5329B7
    C:\Windows\System32\drivers\volsnap.sys 64CA2B4A49A8EAF495E435623ECCE7DB
    C:\Windows\System32\drivers\vpci.sys EF31713EE4C7CCFE4049F7E7F15645A2
    C:\Windows\system32\DRIVERS\vpnva64-6.sys 0F42C39016F82F345C0F2DB2D5B90EB4
    C:\Windows\System32\drivers\vsmraid.sys 4539F45F9F4C9757A86A56C949421E07
    C:\Windows\System32\drivers\vstxraid.sys 0849B7260F26FE05EA56DED0672E2F4B
    C:\Windows\System32\drivers\vwifibus.sys BE970C369E43B509C1EDA2B8FA7CECB0
    C:\Windows\system32\DRIVERS\vwififlt.sys 6B26AD573CCDD5209DF4397438B76354
    C:\Windows\system32\DRIVERS\vwifimp.sys 0B48E0DFB44EE475F4FD8A8EE599AF30
    C:\Windows\System32\drivers\wacompen.sys 0910AB9ED404C1434E2D0376C2AD5D8B
    C:\Windows\System32\drivers\WdBoot.sys 1751F6B031ADAC34724511057D2E455D
    C:\Windows\System32\drivers\Wdf01000.sys CB6C63FF8342B467E2EF76E98D5B934D
    C:\Windows\System32\drivers\WdFilter.sys D296D0F0DB2CD1504F90405603664493
    C:\Windows\System32\Drivers\WdNisDrv.sys 9F4DF0043965808973023A9B51A11136
    C:\Windows\System32\DRIVERS\wfplwfs.sys 715ABA3DD164D06457A2A3C92F6EA9D5
    C:\Windows\System32\drivers\wimmount.sys 5F66B7BB330AA80067FC66149A692620
    C:\Windows\System32\drivers\wmiacpi.sys 2834D9D3B4F554A39C72F00EA3F0E128
     
  5. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-11-21] (Microsoft Corporation)
    R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-10-15] (Motorola Solutions, Inc.)
    R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-01] ( )
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-16] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
    R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
    S3 ssmirrdr; C:\Windows\system32\DRIVERS\ssmirrdr.sys [10112 2015-06-09] (support.com, Inc)
    S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-06-10] (Cisco Systems, Inc.)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-07-12] (Microsoft Corporation)
    S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider)

    ========================== Drivers MD5 =======================

    C:\Windows\System32\drivers\1394ohci.sys E1832BD9FD7E0FC2DC9FA5935DE3E8C1
    C:\Windows\System32\drivers\3ware.sys AD508A1A46EC21B740AB31C28EFDFDB1
    C:\Windows\System32\drivers\ACPI.sys E796AE43DDD1844281DB4D57294D17C0
    C:\Windows\System32\Drivers\acpiex.sys AC8279D229398BCF05C3154ADCA86813
    C:\Windows\System32\drivers\acpipagr.sys A8970D9BF23CD309E0403978A1B58F3F
    C:\Windows\System32\drivers\acpipmi.sys 111A89C99C5B4F1A7BCE5F643DD86F65
    C:\Windows\System32\drivers\acpitime.sys 5758387D68A20AE7D3245011B07E36E7
    C:\Windows\system32\DRIVERS\acsock64.sys D0B11E40EA74A98A5E133DF1F5276240
    C:\Windows\System32\drivers\ADP80XX.SYS 7C1FDF1B48298CBA7CE4BDD4978951AD
    C:\Windows\system32\drivers\afd.sys 374E27295F0A9DCAA8FC96370F9BEEA5
    C:\Windows\System32\drivers\agp440.sys 7DFAEBA9AD62D20102B576D5CAC45EC8
    C:\Windows\System32\DRIVERS\ahcache.sys FE14D249D39368CA62D8DA6BC94AC694
    C:\Windows\system32\DRIVERS\AiCharger.sys 16F6F6B7903B913AB41AB848C8BB5658
    C:\Windows\System32\drivers\amdk8.sys 7589DE749DB6F71A68489DCE04158729
    C:\Windows\System32\drivers\amdppm.sys B46D2D89AFF8A9490FA8C98C7A5616E3
    C:\Windows\System32\drivers\amdsata.sys D2BF2F94A47D332814910FD47C6BBCD2
    C:\Windows\System32\drivers\amdsbs.sys A8E04943C7BBA7219AA50400272C3C6E
    C:\Windows\System32\drivers\amdxata.sys CEA5F4F27CFC08E3A44D576811B35F50
    C:\Windows\System32\drivers\AMPPAL.sys B716710EEE22D85EE26FB5EB26FC5C67
    C:\Windows\system32\drivers\appid.sys 415DD71628795197F7AFC176CBADC74E
    C:\Windows\System32\drivers\arcsas.sys 65045784366F7EC5FB4E71BCF923187B
    C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys 4C016FD76ED5C05E84CA8CAB77993961
    C:\Windows\System32\drivers\atapi.sys 74B14192CF79A72F7536B27CB8814FBD
    C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys 41CEAFFCF3550785E59E3EC9BEE8D97A
    C:\Windows\System32\drivers\AsusTP.sys 437EB91CB20144375DDE145149778405
    C:\Windows\System32\drivers\bxvbda.sys A4A73F631FE2AA2826FBE4A399B04DEF
    C:\Windows\System32\drivers\BasicDisplay.sys 8CC7F7E4AFCBA605921B137ED7992C68
    C:\Windows\System32\drivers\BasicRender.sys 38A82F4EE8C416A6744B6D30381ED768
    C:\Windows\System32\drivers\bcmfn2.sys C1ABB0F7E3BEA48A0417BDF6FF14AB21
    C:\Windows\System32\Drivers\Beep.sys EC19013E4CF87609534165DF897274D6
    C:\Windows\System32\DRIVERS\bowser.sys 6B4FFFDDC618FCF64473CAA86E305697
    C:\Windows\System32\drivers\BthAvrcpTg.sys A8F23D453A424FF4DE04989C4727ECC7
    C:\Windows\System32\drivers\BthEnum.sys 1104A31260CCF4318C884E0AE6C513BF
    C:\Windows\System32\drivers\bthhfenum.sys 272A62B660A48AEF366F8A1836CED19F
    C:\Windows\System32\drivers\BthHFHid.sys 71FE2A48E4C93DDB9798C024880B6C07
    C:\Windows\system32\DRIVERS\BthLEEnum.sys D30C67473A2E229662D21F27EAA9AAA5
    C:\Windows\System32\drivers\bthmodem.sys EF4B9E7C9AD88C00C18A12B0D22D1894
    C:\Windows\system32\DRIVERS\bthpan.sys 25BB93167DEF270188072603F92A1EF5
    C:\Windows\System32\Drivers\BTHport.sys 0CC00ADC1B84C93FB46E1A0974E956E1
    C:\Windows\System32\Drivers\BTHUSB.sys 08EA90955AED2D959EE67DF6EDF0E2B6
    C:\Windows\system32\DRIVERS\btmhsf.sys 7B31A8A9DC95B3634D896FD0F2814F19
    C:\Windows\System32\DRIVERS\cdfs.sys 2FA6510E33F7DEFEC03658B74101A9B9
    C:\Windows\System32\drivers\cdrom.sys C6796EA22B513E3457514D92DCDB1A3D
    C:\Windows\System32\drivers\circlass.sys BE9936EDD3267FAAFF94A7835867F00B
    C:\Windows\System32\drivers\CLFS.sys 8EB7E70C2D348FE2476A2E3F2D585E3D
    C:\Windows\System32\drivers\CmBatt.sys EF6EF85DADC3184A10D8F2F7159973CB
    C:\Windows\System32\Drivers\cng.sys 5E5AB950693F2C6D6ACBEE3A74697ED7
    C:\Windows\System32\drivers\CompositeBus.sys 03AAED827C36F35D70900558B8274905
    C:\Windows\System32\drivers\condrv.sys A1FF7DFBFBE164CF92603C651D304DD2
    C:\Windows\System32\drivers\dam.sys 389C998C64319CD97625B0550E52ECFA
    C:\Windows\System32\Drivers\dfsc.sys A03F362C5557E238CBFA914689C77248
    C:\Windows\System32\drivers\disk.sys 4D40C9B33F738797CF50E77CB7C53E85
    C:\Windows\System32\drivers\dmvsc.sys EB70A894708D1BC176AFD690FF06085F
    C:\Windows\system32\drivers\drmkaud.sys 00C594D5A1DBD22AD8B2902B9F6EFF94
    C:\Windows\System32\drivers\dxgkrnl.sys E1BB0B6F00F470B451AB45EA13EBA0B3
    C:\Windows\System32\drivers\evbda.sys 114BCFDF367FF37C3F1B0A96AF542E4D
    C:\Windows\System32\drivers\EhStorClass.sys 43531A5993380CC5113242C29D265FD9
    C:\Windows\System32\drivers\EhStorTcgDrv.sys 6F8E738A9505A388B1157FDDE7B3101B
    C:\Windows\System32\drivers\errdev.sys DFFFAE1442BA4076E18EED5E406FA0D3
    C:\Windows\System32\Drivers\exfat.sys 7729D294A555C7AEB281ED8E4D0E01E4
    C:\Windows\System32\Drivers\fastfat.sys 7C4E0D5900B2A1D11EDD626D6DDB937B
    C:\Windows\System32\drivers\fdc.sys 5D8402613E778B3BD45E687A8372710B
    C:\Windows\System32\drivers\fileinfo.sys BCFD8B149B3ADF92D0DB1E909CAF0265
    C:\Windows\System32\drivers\filetrace.sys A1A66C4FDAFD6B0289523232AFB7D8AF
    C:\Windows\System32\drivers\flpydisk.sys BE743083CF7063C486A4398E3AEFE59A
    C:\Windows\System32\drivers\fltmgr.sys C1FB505A73FA2E9019D32444AB33B75A
    C:\Windows\System32\drivers\FsDepends.sys A7C31B168F371E8E6796219F23E354DB
    C:\Windows\System32\Drivers\Fs_Rec.sys 09F460AFEDCA03F3BF6E07D1CCC9AC42
    C:\Windows\System32\DRIVERS\fvevol.sys F152D55E497E12256290C43B31C7D0CE
    C:\Windows\System32\drivers\fxppm.sys 9591D0B9351ED489EAFD9D1CE52A8015
    C:\Windows\System32\drivers\gagp30kx.sys FC3EF65EE20D39F8749C2218DBA681CA
    C:\Windows\System32\drivers\vmgencounter.sys 0BF5CAD281E25F1418E5B8875DC5ADD1
    C:\Windows\System32\Drivers\msgpioclx.sys 8DF1254093B5C354CE725EB6B9B0DE19
    C:\Windows\System32\drivers\HDAudBus.sys D4B7ED39C7900384D9E5C1283F1E7926
    C:\Windows\System32\drivers\HidBatt.sys 10A70BC1871CD955D85CD88372724906
    C:\Windows\System32\drivers\hidbth.sys 42F88B57CAE42FC10059C887B3FCFCEA
    C:\Windows\System32\drivers\hidi2c.sys C241A8BAFBBFC90176EA0F5240EACC17
    C:\Windows\System32\drivers\hidir.sys 9BDDEE26255421017E161CCB9D5EDA95
    C:\Windows\System32\drivers\AsHIDSwitch64.sys 894D982CEAB8CD45A56AE2C9988E86C0
    C:\Windows\System32\drivers\hidusb.sys 8DB8EAB9D0C6A5DF0BDCADEA239220B4
    C:\Windows\System32\drivers\HpSAMD.sys A6AACEA4C785789BDA5912AD1FEDA80D
    C:\Windows\System32\drivers\HTTP.sys E87A6D3B8FECD5B93BC0CFBB48C27970
    C:\Windows\System32\drivers\hwpolicy.sys 90656C0B3864804B090434EFC582404F
    C:\Windows\System32\drivers\hyperkbd.sys 6D6F9E3BF0484967E52F7E846BFF1CA1
    C:\Windows\system32\DRIVERS\HyperVideo.sys 907C870F8C31F8DDD6F090857B46AB25
    C:\Windows\System32\drivers\i8042prt.sys 49EE0AE9E5B64FFBBD06D55C4984B598
    C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 5D90E32E36CE5D4C535D17CE08AEAF05
    C:\Windows\System32\drivers\iaLPSSi_I2C.sys DD05E7E80F52ADE9AEB292819920F32C
    C:\Windows\System32\drivers\iaStorA.sys 0FE66A51D81A25AACEAAE4C26308121D
    C:\Windows\System32\drivers\iaStorAV.sys 08BFE413B0B4AA8DFA4B5684CE06D3DC
    C:\Windows\System32\drivers\iaStorV.sys A2200C3033FA4EF249FC096A7A7D02A2
    C:\Windows\system32\DRIVERS\iBtFltCoex.sys 23E22B130EFE5A225E279467BE146317
    C:\Windows\system32\DRIVERS\igdkmd64.sys 16D939A13CFB82DEE0B9DB12E45C7B4E
    C:\Windows\system32\drivers\intelaud.sys DB65573521AB51941F4FA799D0968136
    C:\Windows\system32\drivers\RTKVHD64.sys 6BDCC85422817FA53CD705ADE312CE6A
    C:\Windows\system32\DRIVERS\IntcDAud.sys F5495B38BFB9149925F54F65AB40EFBF
    C:\Windows\System32\drivers\intelide.sys 4E448FCFFD00E8D657CD9E48D3E47157
    C:\Windows\System32\drivers\intelpep.sys 7AA01AB1C110916825E6E1389F1B9AF2
    C:\Windows\System32\drivers\intelppm.sys 47E74A8E53C7C24DCE38311E1451C1D9
    C:\Windows\System32\DRIVERS\ipfltdrv.sys 9DB76D7F9E4E53EFE5DD8C53DE837514
    C:\Windows\System32\drivers\IPMIDrv.sys 9C096BF5E10CA8BFA56F32522A89FAF1
    C:\Windows\System32\drivers\ipnat.sys B7342B3C58E91107F6E946A93D9D4EFD
    C:\Windows\System32\drivers\irenum.sys AE44C526AB5F8A487D941CEB57B10C97
    C:\Windows\System32\drivers\isapnp.sys 8AFEEA3955AA43616A60F133B1D25F21
    C:\Windows\System32\drivers\msiscsi.sys D90AB68D0FAC9F357F663670FDBB511E
    C:\Windows\System32\drivers\iwdbus.sys 2C04ACF9070282AC9AA837C52CA3C128
    C:\Windows\System32\drivers\kbdclass.sys 5917AFE4A3F695A54B99C1849C8207FE
    C:\Windows\System32\drivers\kbdhid.sys 8CD840A062F6BDF41DDE3ACB96164B72
    C:\Windows\System32\drivers\kbfiltr.sys A8080BEBCDB7A16495CE1205921DCAC5
    C:\Windows\system32\DRIVERS\kdnic.sys 813871C7D402A05F2E3A7075F9584A05
    C:\Windows\System32\Drivers\ksecdd.sys 4E829B18D5BAEC29893792A3C671A847
    C:\Windows\System32\Drivers\ksecpkg.sys 46711F40D0F9E63F786ED23F9BD5215E
    C:\Windows\system32\drivers\ksthunk.sys 11AFB527AA370B1DAFD5C36F35F6D45F
    C:\Windows\system32\DRIVERS\lltdio.sys C09010B3680860131631F53E8FE7BAD8
    C:\Windows\System32\drivers\lsi_sas.sys C755AE4635457AA2A11F79C0DF857ABC
    C:\Windows\System32\drivers\lsi_sas2.sys ADAC09CBE7A2040B7F68B5E5C9A75141
    C:\Windows\System32\drivers\lsi_sas3.sys 04D1274BB9BBCCF12BD12374002AA191
    C:\Windows\System32\drivers\lsi_sss.sys 327469EEF3833D0C584B7E88A76AEC0C
    C:\Windows\system32\drivers\luafv.sys DDEE191AB32DFC22C6465002ECDF5EE4
    C:\WINDOWS\system32\drivers\mbam.sys A8D28D5B3E2A528D1EF0E338E44F2820
    C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys 8F22037D3F5A6BB676525D825A1388B9
    C:\WINDOWS\system32\drivers\mwac.sys 85CFE7AB85B43B6B7AC7961AA3983A9F
    C:\Windows\System32\drivers\megasas.sys EB5C03A070F30D64A6DF80E53B22F53F
    C:\Windows\System32\drivers\megasr.sys F6F13533196DE7A582D422B0241E4363
    C:\Windows\System32\drivers\HECIx64.sys 772A1DEEDFDBC244183B5C805D1B7D85
    C:\Windows\System32\drivers\modem.sys 8B38C44F69259987C95135C9627E2378
    C:\Windows\System32\drivers\monitor.sys 601589000CC90F0DF8DA2CC254A3CCC9
    C:\Windows\System32\drivers\mouclass.sys 08374E4E5B8914DE6067CBA99F61E930
     
  6. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
    Ran by Rosa (administrator) on ROSA on 16-07-2015 07:57:03
    Running from C:\Users\Rosa\Downloads
    Loaded Profiles: Rosa (Available Profiles: Rosa & sdcfalcon & Administrator)
    Platform: Windows 8.1 (X64) OS Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
    (Microsoft Corporation) C:\Windows\System32\wlanext.exe
    (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
    (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
    (IntraNext Systems) C:\Program Files (x86)\CSG\Softphone 9\CTIHub.exe
    (Microsoft Corporation) C:\Windows\System32\dasHost.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Avaya Inc.) C:\Windows\SysWOW64\QosServM.exe
    (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (Support.com) C:\Program Files (x86)\Support.com\SDCWB_Helper_Service\SDCWB_Service.exe
    (Support.com) C:\Program Files (x86)\Support.com\SDCWB_Helper_Service\sdcwbServiceUpdater.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
    (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
    (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
    (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
    (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
    (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
    (Intel Corporation) C:\Windows\System32\igfxtray.exe
    (Intel Corporation) C:\Windows\System32\hkcmd.exe
    (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
    (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
    (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
    (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
    (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
    (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor)
    HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll ",TrayApp
    HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90832 2012-06-07] (ASUS)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40336 2015-04-29] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
    HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1056976 2014-06-27] (Carbonite, Inc.)
    HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707496 2014-06-10] (Cisco Systems, Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
    HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated)
    Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\...\Run: [GoogleChromeAutoLaunch_4F4C99A09FCA90488F664860022AA70B] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-07-13] (Google Inc.)
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.)
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\...\Run: [AdobeBridge] => [X]
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2012-12-12]
    ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NAC Assessment Agent.lnk [2015-07-12]
    ShortcutTarget: NAC Assessment Agent.lnk -> C:\Program Files (x86)\Extreme Networks\NAC Agent\NacAgent.exe (Extreme Networks, Inc)
    ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)
    ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2014-06-27] (Carbonite, Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
    SearchScopes: HKU\S-1-5-21-526706507-2563106057-1816975683-1001 -> DefaultScope {280BEABE-A425-4906-B1C0-5B800289D9B7} URL = https://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
    SearchScopes: HKU\S-1-5-21-526706507-2563106057-1816975683-1001 -> {280BEABE-A425-4906-B1C0-5B800289D9B7} URL = https://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-07-12] (Oracle Corporation)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-07-12] (Oracle Corporation)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
    Tcpip\..\Interfaces\{C692156E-AF27-4CA2-8B68-D864E07B431A}: [DhcpNameServer] 75.75.75.75 75.75.76.76
    Tcpip\..\Interfaces\{F47131B4-841B-4AD4-A754-E3F38BD9561C}: [DhcpNameServer] 75.75.75.75 75.75.76.76

    FireFox:
    ========
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
    FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
    FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-07-12] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-07-12] (Oracle Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
    FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
    FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)

    Chrome:
    =======
    CHR Profile: C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (iStoryBooks) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\anbmgijcnihjphndkjglleofcnohhkkl [2015-07-12]
    CHR Extension: (Google Drive) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-12]
    CHR Extension: (YouTube) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-12]
    CHR Extension: (HelloFax: 50 Free Fax Pages) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm [2015-07-12]
    CHR Extension: (Google Search) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-12]
    CHR Extension: (Post To Tumblr) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbpicbbcpanckagpdjflgojlknomoiah [2015-07-12]
    CHR Extension: (Logitech Smooth Scrolling) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2015-07-12]
    CHR Extension: (The Godfather: Five Families) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\edfkoljdeffeedleidebkmmamepgbnbl [2015-07-12]
    CHR Extension: (Ponyhoof) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\efjjgphedlaihnlgaibiaihhmhaejjdd [2015-07-12]
    CHR Extension: (Google Calendar) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-07-12]
    CHR Extension: (Google Sheets) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-12]
    CHR Extension: (AdBlock) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-07-12]
    CHR Extension: (Pictico — Coloring for Kids) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gndkeamlgkegbmmoheplcndpopglacgf [2015-07-12]
    CHR Extension: (Pin It Button) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-07-12]
    CHR Extension: (World of Solitaire) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn [2015-07-12]
    CHR Extension: (MOG Music) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgljcanfdcmdnncaneopdlcgjlkgpenj [2015-07-12]
    CHR Extension: (MeeGenius! Children's Books) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhfhmaajajcjoijfaceafiembkmhcddc [2015-07-12]
    CHR Extension: (TARDIS) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjifgneioddlgbglnkppcblkccmninme [2015-07-12]
    CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-12]
    CHR Extension: (Zombie Drop) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhmhllfgcoopjdmcmdeobhgimokcabmc [2015-07-12]
    CHR Extension: (Listube - Free Online On-Demand Music Player) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlelfeaeehmpkbcfjmjcbilahepgcjgk [2015-07-12]
    CHR Extension: (Google Wallet) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-12]
    CHR Extension: (Atari - Missile Command) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\oobnopfjjndfekinfcddimnjbhjdgmbg [2015-07-12]
    CHR Extension: (Gmail) - C:\Users\Rosa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-12]
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
    S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-11-21] (Microsoft Corporation)
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
    R2 CTIHub; C:\Program Files (x86)\CSG\Softphone 9\CTIHub.exe [31744 2014-09-12] (IntraNext Systems) [File not signed]
    R2 iClarityQoSService; C:\WINDOWS\SysWOW64\\QosServM.exe [233472 2010-11-09] (Avaya Inc.) [File not signed]
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
    R2 SDCWB_Service; C:\Program Files (x86)\Support.com\SDCWB_Helper_Service\SDCWB_Service.exe [15680 2015-04-27] (Support.com)
    R2 SDCWB_UpdaterService; C:\Program Files (x86)\Support.com\SDCWB_Helper_Service\sdcwbServiceUpdater.exe [13632 2015-04-27] (Support.com)
    S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-07-12] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-07-12] (Microsoft Corporation)
    R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
     
  7. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
    R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-11-21] (Microsoft Corporation)
    R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1390904 2013-10-15] (Motorola Solutions, Inc.)
    R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-01] ( )
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-16] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
    R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
    S3 ssmirrdr; C:\Windows\system32\DRIVERS\ssmirrdr.sys [10112 2015-06-09] (support.com, Inc)
    S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-06-10] (Cisco Systems, Inc.)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-07-12] (Microsoft Corporation)
    S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider)

    ========================== Drivers MD5 =======================

    C:\Windows\System32\drivers\1394ohci.sys E1832BD9FD7E0FC2DC9FA5935DE3E8C1
    C:\Windows\System32\drivers\3ware.sys AD508A1A46EC21B740AB31C28EFDFDB1
    C:\Windows\System32\drivers\ACPI.sys E796AE43DDD1844281DB4D57294D17C0
    C:\Windows\System32\Drivers\acpiex.sys AC8279D229398BCF05C3154ADCA86813
    C:\Windows\System32\drivers\acpipagr.sys A8970D9BF23CD309E0403978A1B58F3F
    C:\Windows\System32\drivers\acpipmi.sys 111A89C99C5B4F1A7BCE5F643DD86F65
    C:\Windows\System32\drivers\acpitime.sys 5758387D68A20AE7D3245011B07E36E7
    C:\Windows\system32\DRIVERS\acsock64.sys D0B11E40EA74A98A5E133DF1F5276240
    C:\Windows\System32\drivers\ADP80XX.SYS 7C1FDF1B48298CBA7CE4BDD4978951AD
    C:\Windows\system32\drivers\afd.sys 374E27295F0A9DCAA8FC96370F9BEEA5
    C:\Windows\System32\drivers\agp440.sys 7DFAEBA9AD62D20102B576D5CAC45EC8
    C:\Windows\System32\DRIVERS\ahcache.sys FE14D249D39368CA62D8DA6BC94AC694
    C:\Windows\system32\DRIVERS\AiCharger.sys 16F6F6B7903B913AB41AB848C8BB5658
    C:\Windows\System32\drivers\amdk8.sys 7589DE749DB6F71A68489DCE04158729
    C:\Windows\System32\drivers\amdppm.sys B46D2D89AFF8A9490FA8C98C7A5616E3
    C:\Windows\System32\drivers\amdsata.sys D2BF2F94A47D332814910FD47C6BBCD2
    C:\Windows\System32\drivers\amdsbs.sys A8E04943C7BBA7219AA50400272C3C6E
    C:\Windows\System32\drivers\amdxata.sys CEA5F4F27CFC08E3A44D576811B35F50
    C:\Windows\System32\drivers\AMPPAL.sys B716710EEE22D85EE26FB5EB26FC5C67
    C:\Windows\system32\drivers\appid.sys 415DD71628795197F7AFC176CBADC74E
    C:\Windows\System32\drivers\arcsas.sys 65045784366F7EC5FB4E71BCF923187B
    C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys 4C016FD76ED5C05E84CA8CAB77993961
    C:\Windows\System32\drivers\atapi.sys 74B14192CF79A72F7536B27CB8814FBD
    C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys 41CEAFFCF3550785E59E3EC9BEE8D97A
    C:\Windows\System32\drivers\AsusTP.sys 437EB91CB20144375DDE145149778405
    C:\Windows\System32\drivers\bxvbda.sys A4A73F631FE2AA2826FBE4A399B04DEF
    C:\Windows\System32\drivers\BasicDisplay.sys 8CC7F7E4AFCBA605921B137ED7992C68
    C:\Windows\System32\drivers\BasicRender.sys 38A82F4EE8C416A6744B6D30381ED768
    C:\Windows\System32\drivers\bcmfn2.sys C1ABB0F7E3BEA48A0417BDF6FF14AB21
    C:\Windows\System32\Drivers\Beep.sys EC19013E4CF87609534165DF897274D6
    C:\Windows\System32\DRIVERS\bowser.sys 6B4FFFDDC618FCF64473CAA86E305697
    C:\Windows\System32\drivers\BthAvrcpTg.sys A8F23D453A424FF4DE04989C4727ECC7
    C:\Windows\System32\drivers\BthEnum.sys 1104A31260CCF4318C884E0AE6C513BF
    C:\Windows\System32\drivers\bthhfenum.sys 272A62B660A48AEF366F8A1836CED19F
    C:\Windows\System32\drivers\BthHFHid.sys 71FE2A48E4C93DDB9798C024880B6C07
    C:\Windows\system32\DRIVERS\BthLEEnum.sys D30C67473A2E229662D21F27EAA9AAA5
    C:\Windows\System32\drivers\bthmodem.sys EF4B9E7C9AD88C00C18A12B0D22D1894
    C:\Windows\system32\DRIVERS\bthpan.sys 25BB93167DEF270188072603F92A1EF5
    C:\Windows\System32\Drivers\BTHport.sys 0CC00ADC1B84C93FB46E1A0974E956E1
    C:\Windows\System32\Drivers\BTHUSB.sys 08EA90955AED2D959EE67DF6EDF0E2B6
    C:\Windows\system32\DRIVERS\btmhsf.sys 7B31A8A9DC95B3634D896FD0F2814F19
    C:\Windows\System32\DRIVERS\cdfs.sys 2FA6510E33F7DEFEC03658B74101A9B9
    C:\Windows\System32\drivers\cdrom.sys C6796EA22B513E3457514D92DCDB1A3D
    C:\Windows\System32\drivers\circlass.sys BE9936EDD3267FAAFF94A7835867F00B
    C:\Windows\System32\drivers\CLFS.sys 8EB7E70C2D348FE2476A2E3F2D585E3D
    C:\Windows\System32\drivers\CmBatt.sys EF6EF85DADC3184A10D8F2F7159973CB
    C:\Windows\System32\Drivers\cng.sys 5E5AB950693F2C6D6ACBEE3A74697ED7
    C:\Windows\System32\drivers\CompositeBus.sys 03AAED827C36F35D70900558B8274905
    C:\Windows\System32\drivers\condrv.sys A1FF7DFBFBE164CF92603C651D304DD2
    C:\Windows\System32\drivers\dam.sys 389C998C64319CD97625B0550E52ECFA
    C:\Windows\System32\Drivers\dfsc.sys A03F362C5557E238CBFA914689C77248
    C:\Windows\System32\drivers\disk.sys 4D40C9B33F738797CF50E77CB7C53E85
    C:\Windows\System32\drivers\dmvsc.sys EB70A894708D1BC176AFD690FF06085F
    C:\Windows\system32\drivers\drmkaud.sys 00C594D5A1DBD22AD8B2902B9F6EFF94
    C:\Windows\System32\drivers\dxgkrnl.sys E1BB0B6F00F470B451AB45EA13EBA0B3
    C:\Windows\System32\drivers\evbda.sys 114BCFDF367FF37C3F1B0A96AF542E4D
    C:\Windows\System32\drivers\EhStorClass.sys 43531A5993380CC5113242C29D265FD9
    C:\Windows\System32\drivers\EhStorTcgDrv.sys 6F8E738A9505A388B1157FDDE7B3101B
    C:\Windows\System32\drivers\errdev.sys DFFFAE1442BA4076E18EED5E406FA0D3
    C:\Windows\System32\Drivers\exfat.sys 7729D294A555C7AEB281ED8E4D0E01E4
    C:\Windows\System32\Drivers\fastfat.sys 7C4E0D5900B2A1D11EDD626D6DDB937B
    C:\Windows\System32\drivers\fdc.sys 5D8402613E778B3BD45E687A8372710B
    C:\Windows\System32\drivers\fileinfo.sys BCFD8B149B3ADF92D0DB1E909CAF0265
    C:\Windows\System32\drivers\filetrace.sys A1A66C4FDAFD6B0289523232AFB7D8AF
    C:\Windows\System32\drivers\flpydisk.sys BE743083CF7063C486A4398E3AEFE59A
    C:\Windows\System32\drivers\fltmgr.sys C1FB505A73FA2E9019D32444AB33B75A
    C:\Windows\System32\drivers\FsDepends.sys A7C31B168F371E8E6796219F23E354DB
    C:\Windows\System32\Drivers\Fs_Rec.sys 09F460AFEDCA03F3BF6E07D1CCC9AC42
    C:\Windows\System32\DRIVERS\fvevol.sys F152D55E497E12256290C43B31C7D0CE
    C:\Windows\System32\drivers\fxppm.sys 9591D0B9351ED489EAFD9D1CE52A8015
    C:\Windows\System32\drivers\gagp30kx.sys FC3EF65EE20D39F8749C2218DBA681CA
    C:\Windows\System32\drivers\vmgencounter.sys 0BF5CAD281E25F1418E5B8875DC5ADD1
    C:\Windows\System32\Drivers\msgpioclx.sys 8DF1254093B5C354CE725EB6B9B0DE19
    C:\Windows\System32\drivers\HDAudBus.sys D4B7ED39C7900384D9E5C1283F1E7926
    C:\Windows\System32\drivers\HidBatt.sys 10A70BC1871CD955D85CD88372724906
    C:\Windows\System32\drivers\hidbth.sys 42F88B57CAE42FC10059C887B3FCFCEA
    C:\Windows\System32\drivers\hidi2c.sys C241A8BAFBBFC90176EA0F5240EACC17
    C:\Windows\System32\drivers\hidir.sys 9BDDEE26255421017E161CCB9D5EDA95
    C:\Windows\System32\drivers\AsHIDSwitch64.sys 894D982CEAB8CD45A56AE2C9988E86C0
    C:\Windows\System32\drivers\hidusb.sys 8DB8EAB9D0C6A5DF0BDCADEA239220B4
    C:\Windows\System32\drivers\HpSAMD.sys A6AACEA4C785789BDA5912AD1FEDA80D
    C:\Windows\System32\drivers\HTTP.sys E87A6D3B8FECD5B93BC0CFBB48C27970
    C:\Windows\System32\drivers\hwpolicy.sys 90656C0B3864804B090434EFC582404F
    C:\Windows\System32\drivers\hyperkbd.sys 6D6F9E3BF0484967E52F7E846BFF1CA1
    C:\Windows\system32\DRIVERS\HyperVideo.sys 907C870F8C31F8DDD6F090857B46AB25
    C:\Windows\System32\drivers\i8042prt.sys 49EE0AE9E5B64FFBBD06D55C4984B598
    C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 5D90E32E36CE5D4C535D17CE08AEAF05
    C:\Windows\System32\drivers\iaLPSSi_I2C.sys DD05E7E80F52ADE9AEB292819920F32C
    C:\Windows\System32\drivers\iaStorA.sys 0FE66A51D81A25AACEAAE4C26308121D
    C:\Windows\System32\drivers\iaStorAV.sys 08BFE413B0B4AA8DFA4B5684CE06D3DC
    C:\Windows\System32\drivers\iaStorV.sys A2200C3033FA4EF249FC096A7A7D02A2
    C:\Windows\system32\DRIVERS\iBtFltCoex.sys 23E22B130EFE5A225E279467BE146317
    C:\Windows\system32\DRIVERS\igdkmd64.sys 16D939A13CFB82DEE0B9DB12E45C7B4E
    C:\Windows\system32\drivers\intelaud.sys DB65573521AB51941F4FA799D0968136
    C:\Windows\system32\drivers\RTKVHD64.sys 6BDCC85422817FA53CD705ADE312CE6A
    C:\Windows\system32\DRIVERS\IntcDAud.sys F5495B38BFB9149925F54F65AB40EFBF
    C:\Windows\System32\drivers\intelide.sys 4E448FCFFD00E8D657CD9E48D3E47157
    C:\Windows\System32\drivers\intelpep.sys 7AA01AB1C110916825E6E1389F1B9AF2
    C:\Windows\System32\drivers\intelppm.sys 47E74A8E53C7C24DCE38311E1451C1D9
    C:\Windows\System32\DRIVERS\ipfltdrv.sys 9DB76D7F9E4E53EFE5DD8C53DE837514
    C:\Windows\System32\drivers\IPMIDrv.sys 9C096BF5E10CA8BFA56F32522A89FAF1
    C:\Windows\System32\drivers\ipnat.sys B7342B3C58E91107F6E946A93D9D4EFD
    C:\Windows\System32\drivers\irenum.sys AE44C526AB5F8A487D941CEB57B10C97
    C:\Windows\System32\drivers\isapnp.sys 8AFEEA3955AA43616A60F133B1D25F21
    C:\Windows\System32\drivers\msiscsi.sys D90AB68D0FAC9F357F663670FDBB511E
    C:\Windows\System32\drivers\iwdbus.sys 2C04ACF9070282AC9AA837C52CA3C128
    C:\Windows\System32\drivers\kbdclass.sys 5917AFE4A3F695A54B99C1849C8207FE
    C:\Windows\System32\drivers\kbdhid.sys 8CD840A062F6BDF41DDE3ACB96164B72
    C:\Windows\System32\drivers\kbfiltr.sys A8080BEBCDB7A16495CE1205921DCAC5
    C:\Windows\system32\DRIVERS\kdnic.sys 813871C7D402A05F2E3A7075F9584A05
    C:\Windows\System32\Drivers\ksecdd.sys 4E829B18D5BAEC29893792A3C671A847
    C:\Windows\System32\Drivers\ksecpkg.sys 46711F40D0F9E63F786ED23F9BD5215E
    C:\Windows\system32\drivers\ksthunk.sys 11AFB527AA370B1DAFD5C36F35F6D45F
    C:\Windows\system32\DRIVERS\lltdio.sys C09010B3680860131631F53E8FE7BAD8
    C:\Windows\System32\drivers\lsi_sas.sys C755AE4635457AA2A11F79C0DF857ABC
    C:\Windows\System32\drivers\lsi_sas2.sys ADAC09CBE7A2040B7F68B5E5C9A75141
    C:\Windows\System32\drivers\lsi_sas3.sys 04D1274BB9BBCCF12BD12374002AA191
    C:\Windows\System32\drivers\lsi_sss.sys 327469EEF3833D0C584B7E88A76AEC0C
    C:\Windows\system32\drivers\luafv.sys DDEE191AB32DFC22C6465002ECDF5EE4
    C:\WINDOWS\system32\drivers\mbam.sys A8D28D5B3E2A528D1EF0E338E44F2820
    C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys 8F22037D3F5A6BB676525D825A1388B9
    C:\WINDOWS\system32\drivers\mwac.sys 85CFE7AB85B43B6B7AC7961AA3983A9F
    C:\Windows\System32\drivers\megasas.sys EB5C03A070F30D64A6DF80E53B22F53F
    C:\Windows\System32\drivers\megasr.sys F6F13533196DE7A582D422B0241E4363
    C:\Windows\System32\drivers\HECIx64.sys 772A1DEEDFDBC244183B5C805D1B7D85
    C:\Windows\System32\drivers\modem.sys 8B38C44F69259987C95135C9627E2378
    C:\Windows\System32\drivers\monitor.sys 601589000CC90F0DF8DA2CC254A3CCC9
    C:\Windows\System32\drivers\mouclass.sys 08374E4E5B8914DE6067CBA99F61E930
    C:\Windows\System32\drivers\mouhid.sys 5FCBAB60598AE119E02B4C27DE6B99EA
    C:\Windows\System32\drivers\mountmgr.sys D1D82F007A079A4D623DBD1F36EF30A1
    C:\Windows\System32\drivers\mpsdrv.sys 6FC047578785B0435F4E2660946D1ADC
    C:\Windows\system32\drivers\mrxdav.sys DB32958F0E704EFBF7F15161A569E39F
    C:\Windows\System32\DRIVERS\mrxsmb.sys 6FBDF2B1B025A8E6E069234362FFFFB7
    C:\Windows\System32\DRIVERS\mrxsmb10.sys BCBD64220AD85C26823453FF1DC3EFBD
    C:\Windows\System32\DRIVERS\mrxsmb20.sys 57C2473D501331211D6885FD59F3E44B
    C:\Windows\system32\DRIVERS\bridge.sys F3C060444777A59FC63D920719E43CCD
    C:\Windows\System32\Drivers\Msfs.sys D13329FBF8345B28AB30F44CC247DC08
    C:\Windows\System32\drivers\msgpiowin32.sys C6B474E46F9E543B875981ED3FFE6ADD
    C:\Windows\System32\drivers\mshidkmdf.sys 65C92EB9D08DB5C69F28C7FFD4E84E31
    C:\Windows\System32\drivers\mshidumdf.sys 52299F086AC2DAFD100DD5DC4A8614BA
    C:\Windows\System32\drivers\msisadrv.sys 36D92AF3343C3A3E57FEF11C449AEA4C
    C:\Windows\system32\drivers\MSKSSRV.sys A9BBBD2BAE6142253B9195E949AC2E8D
    C:\Windows\system32\DRIVERS\mslldp.sys 51B3AC0560848CD6D65AC2033E293113
    C:\Windows\system32\drivers\MSPCLOCK.sys 7B2128EB875DCBC006E6A913211006D6
    C:\Windows\system32\drivers\MSPQM.sys 1E88171579B218115C7A772F8DE04BD8
    C:\Windows\System32\Drivers\MsRPC.sys BBE2A455053E63BECBF42C2F9B21FAE0
    C:\Windows\System32\drivers\mssmbios.sys 8D6B7D515C5CBCDB75B928A0B73C3C5E
    C:\Windows\system32\drivers\MSTEE.sys 115019AE01E0EB9C048530D2928AB4A2
    C:\Windows\System32\drivers\MTConfig.sys 96D604A35070360F0DD4A7A8AF410B5E
    C:\Windows\System32\Drivers\mup.sys 619CA29326B82372621DB2C0964D8365
    C:\Windows\System32\drivers\mvumis.sys B8C35C94DCB2DFEAF03BB42131F2F77F
    C:\Windows\system32\DRIVERS\nwifi.sys 008F7CED69FD5B30CBDE1E03C6F36A27
    C:\Windows\System32\drivers\ndis.sys 6D3A2565E01B3E4B0F1BEDB0D4B00B3F
    C:\Windows\system32\DRIVERS\ndiscap.sys 8CECC8DA55F3274181FD1EA28AD76664
    C:\Windows\system32\DRIVERS\NdisImPlatform.sys 269882812E9A68FFF1AFE1283D428322
    C:\Windows\system32\DRIVERS\ndistapi.sys DC1D9F692C2AD84C214584C28501C1F7
    C:\Windows\system32\DRIVERS\ndisuio.sys B832B35055BA2B7B4181861FF94D8E59
    C:\Windows\System32\drivers\NdisVirtualBus.sys 1F58E48EF75F34C35D8E93A0DC535CFE
    C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
    C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
    C:\Windows\System32\Drivers\NDProxy.sys 0BBE2FA30BAD58C9ADC01E4F84A3D2A1
    C:\Windows\System32\drivers\Ndu.sys 3083926D1CC5B56EA0786527B557DD1B
    C:\Windows\System32\DRIVERS\netbios.sys 42FF4975D032CAE558AE4BB8448F6E5A
    C:\Windows\System32\DRIVERS\netbt.sys 0217532E19A748F0E5D569307363D5FD
    C:\Windows\System32\drivers\netvsc63.sys D4DCE03870314D3354F3501F9DDD4123
    C:\Windows\system32\DRIVERS\Netwew00.sys 75B9B86878CC159FBC40C4F9202ADBE3
    C:\Windows\System32\Drivers\Npfs.sys 8F44A2F57C9F1A19AC9C6288C10FB351
    C:\Windows\System32\drivers\npsvctrig.sys CBDB4F0871C88DF930FC0E8588CA67FC
    C:\Windows\System32\drivers\nsiproxy.sys 0E046FF5823B95326D10CF1B4AF23541
    C:\Windows\System32\Drivers\Ntfs.sys 7F68063A5A0461E02BC860CE0E6BFDDC
    C:\Windows\System32\Drivers\Null.sys EF1B290FC9F0E47CC0B537292BEE5904
    C:\Windows\System32\drivers\nvraid.sys BC6B5942AFF25EBAF62DE43C3807EDF8
    C:\Windows\System32\drivers\nvstor.sys 1F43ABFFAC3D6CA356851D517392966E
    C:\Windows\System32\drivers\nv_agp.sys 6934A936A7369DFE37B7DBA93F5E5E49
    C:\Windows\System32\drivers\parport.sys 764B1121867B2D9B31C491668AC72B2B
    C:\Windows\System32\drivers\partmgr.sys BAFF6122CFC9F95CA175AD8C348179A4
    C:\Windows\System32\drivers\pci.sys 91ED124E261EA8FAA1C0FFDF2A71B0C4
    C:\Windows\System32\drivers\pciide.sys 346E38FCC6859A727DD28AFAD1F0AFF4
    C:\Windows\System32\drivers\pcmcia.sys 4D3BDCC1C7B40C9D7B6AD990E6DEC397
    C:\Windows\System32\drivers\pcw.sys BF28771D1436C88BE1D297D3098B0F7D
    C:\Windows\System32\drivers\pdc.sys ED54A75050211DC77F9B98C41E026858
    C:\Windows\System32\drivers\peauth.sys 0ECEE590F2E2EF969FB74A6FC583A1E6
    C:\Windows\System32\drivers\processr.sys ECD373F9571C745894367CC2635EA44F
    C:\Windows\system32\DRIVERS\pacer.sys FC0141B4A5AD6D637D883C1A89FC45C5
    C:\Windows\system32\drivers\qwavedrv.sys 83868EB2924E6BC21A54337C65D614D1
    C:\Windows\System32\DRIVERS\rasacd.sys B337B1F1E82A83E20A1743E008E25C0F
    C:\Windows\system32\DRIVERS\raspppoe.sys 5247F308C4103CDC4FE12AE1D235800A
    C:\Windows\System32\DRIVERS\rdbss.sys A1A5E79C0D1352AFDC08328A623DA051
    C:\Windows\System32\drivers\rdpbus.sys 6B21EBF892CD8CACB71669B35AB5DE32
    C:\Windows\System32\drivers\rdpdr.sys 680C1DAE268B6FB67FA21B389A8B79EF
    C:\Windows\System32\drivers\rdpvideominiport.sys BC8A79C625568DDB7DCA49D0C2741A64
    C:\Windows\System32\drivers\rdyboost.sys A26AEC49F318FEE141DDDB2C5F99B3E6
    C:\Windows\System32\Drivers\ReFS.sys 615DFD97DEA56CE1C3A52185A3038FF8
    C:\Windows\System32\drivers\rfcomm.sys DC66AE45816614D2999DCD3834DCCC4E
    C:\Windows\system32\DRIVERS\rspndr.sys 2D05A5508F4685412F2B89E8C2189ABC
    C:\Windows\System32\Drivers\RtsUStor.sys 0E32A8922DCFD28EA00AAEC07CB3F331
    C:\Windows\system32\DRIVERS\Rt630x64.sys 19764658C1468C2C0CEF133D28414A6B
    C:\Windows\System32\drivers\vms3cap.sys 1A063730F221B2746FF00457AE17E4F0
    C:\Windows\System32\drivers\sbp2port.sys C624A1B32211C3166EDB3F4AB02A30B7
    C:\Windows\System32\DRIVERS\scfilter.sys 13BEA6C882D4D877A5A85CA149C86BC1
    C:\Windows\System32\drivers\sdbus.sys C54B6B2170BF628FD42F799A66956D75
    C:\Windows\System32\drivers\sdstor.sys 0B1E929D11A8E358106955603FAC65E8
    C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
    C:\Windows\System32\drivers\SerCx.sys DB2FF24CE0BDD15FE75870AFE312BA89
    C:\Windows\System32\drivers\SerCx2.sys 0044B31F93946D5D41982314381FE431
    C:\Windows\System32\drivers\serenum.sys 3CD600C089C1251BEEB4CD4CD5164F9E
    C:\Windows\System32\drivers\serial.sys D864381BC9C725FAB01D94C060660166
    C:\Windows\System32\drivers\sermouse.sys 148195AE95D9BC7375A08846439FDAC1
    C:\Windows\System32\drivers\sfloppy.sys 472B7A5AC181C050888DB454663DD764
    C:\Windows\System32\drivers\SiSRaid2.sys 2F518D13DD6F3053837FE606F1A2EA1F
    C:\Windows\System32\drivers\sisraid4.sys 1AC9A200A9C49C4508F04AAFFCA34A3F
    C:\Windows\System32\drivers\spaceport.sys D24B1945ED1F9C96DA786DBBF1E983CE
    C:\Windows\System32\drivers\SpbCx.sys F337BE11071818FC3F5DC2940B6BDE34
    C:\Windows\System32\DRIVERS\srv.sys 6416E79A58A8FCC33A447A4DDDD3BF04
    C:\Windows\System32\DRIVERS\srv2.sys 00D8AC8E3053290BDE6EA2FB6810D2FC
    C:\Windows\System32\DRIVERS\srvnet.sys D047CD668E6277FD80F0C613946F034C
    C:\Windows\system32\DRIVERS\ssmirrdr.sys 1100066057FBF612B573EFD3B21383F1
    C:\Windows\System32\drivers\stexstor.sys 366DEA74BBA65B362BCCFC6FC2ADFD8B
    C:\Windows\System32\drivers\storahci.sys 0ED2E318ABB68C1A35A8B8038BDB4C90
    C:\Windows\System32\drivers\vmstorfl.sys 8B9486B64E5FC17FB9CC04CA10B77A34
    C:\Windows\System32\drivers\stornvme.sys 6B06E2D11E604BE2B1A406C4CB3B90DE
    C:\Windows\System32\drivers\storvsc.sys 548759755BC73DAD663250239D7E0B9F
    C:\Windows\System32\drivers\swenum.sys 65454187E0F8B6C0DCECB0287D06EC43
    C:\Windows\System32\drivers\tcpip.sys 3C2DF97A21A9BBE6355B0A51F288EFFF
    C:\Windows\system32\DRIVERS\tcpip.sys 3C2DF97A21A9BBE6355B0A51F288EFFF
    C:\Windows\System32\drivers\tcpipreg.sys 41CF802064F72E55F50CA0A221FD36D4
    C:\Windows\system32\DRIVERS\tdx.sys FFF28F9F6823EB1756C60F1649560BBF
    C:\Windows\System32\drivers\terminpt.sys 232D185D2337F141311D0CF1983E1431
    C:\Windows\system32\drivers\tpm.sys 82F909359600D3603FE852DB7F135626
    C:\Windows\System32\drivers\tsusbflt.sys BF8F54CA37E9C9D6582C31C5761F8C93
    C:\Windows\System32\drivers\TsUsbGD.sys 20185BEB7512EDE4EFECDFA148AC9F99
    C:\Windows\system32\DRIVERS\tunnel.sys C8E0E78B5D284C2FF59BDFFDAF997242
    C:\Windows\System32\drivers\uagp35.sys F6EEAD052943B5A3104C1405BB856C54
    C:\Windows\System32\drivers\uaspstor.sys FE6067B1FD4E63650C667B33D080565B
    C:\Windows\System32\drivers\ucx01000.sys 807F8CF3E973305FC435C61CBBEE2A49
    C:\Windows\System32\DRIVERS\udfs.sys C61EAF8E1E4B2F62BA4FDF457440B2C6
    C:\Windows\System32\drivers\UEFI.sys 9578691F297E1B1F519970FE6D47CB21
    C:\Windows\System32\drivers\uliagpkx.sys 5EAB5117DDB24FC4D39E6FFFCF1837B9
    C:\Windows\System32\drivers\umbus.sys DA34C39A18E60E7C3FA0630566408034
    C:\Windows\System32\drivers\umpass.sys AE8294875E5446E359B1E8035D40C05E
    C:\Windows\system32\drivers\usbaudio.sys DF355EB0199198728027962DCFCDE5FB
    C:\Windows\System32\drivers\usbccgp.sys FF78D053A05E5A394F4E3C1816CC65A8
    C:\Windows\System32\drivers\usbcir.sys 0139248F6B95CF0D837B5B46A2722D40
    C:\Windows\System32\drivers\usbehci.sys 48BA326A3DBA5B5BEB5F2777F4618696
    C:\Windows\System32\drivers\usbhub.sys FEF0BC107812B36849741C3211BA6B60
    C:\Windows\System32\drivers\UsbHub3.sys 95B0179BDA907252025DEEA183699FB3
    C:\Windows\System32\drivers\usbohci.sys 3019097FB6C985EF24C058090FF3BDBD
    C:\Windows\System32\drivers\usbprint.sys 4D655E3B684BE9B0F7FFD8A2935C348C
    C:\Windows\System32\drivers\USBSTOR.SYS 66732C13628BDB1AB0D6FD46027327C2
    C:\Windows\System32\drivers\usbuhci.sys 064260B3A5868AC894A4943543BC7AB7
    C:\Windows\System32\Drivers\usbvideo.sys 5C8F604F6DC74177CDD8372D7B1ADFF0
    C:\Windows\System32\drivers\USBXHCI.SYS 44603DA5A87FB491EF59C889EBBB4DDB
    C:\Windows\System32\drivers\vdrvroot.sys FEB26E3B8345A7E8D62F945C4AE86562
    C:\Windows\System32\drivers\VerifierExt.sys A026EDEAA5EECAE0B08E2748B616D4BD
    C:\Windows\System32\drivers\vhdmp.sys F6ECFD6128A16A4851CFE98D4E01B011
     
  8. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    C:\Windows\System32\drivers\viaide.sys 06D38968028E9AB19DE9B618C7B6D199
    C:\Windows\System32\drivers\vmbus.sys 511AD3FF957A0127E6BD336FF6F89C38
    C:\Windows\System32\drivers\VMBusHID.sys DA40BEA0A863CE768C940CA9723BF81F
    C:\Windows\System32\drivers\volmgr.sys 55D7D963DE85162F1C49721E502F9744
    C:\Windows\System32\drivers\volmgrx.sys CCB9E901F7254BF96D28EB1B0E5329B7
    C:\Windows\System32\drivers\volsnap.sys 64CA2B4A49A8EAF495E435623ECCE7DB
    C:\Windows\System32\drivers\vpci.sys EF31713EE4C7CCFE4049F7E7F15645A2
    C:\Windows\system32\DRIVERS\vpnva64-6.sys 0F42C39016F82F345C0F2DB2D5B90EB4
    C:\Windows\System32\drivers\vsmraid.sys 4539F45F9F4C9757A86A56C949421E07
    C:\Windows\System32\drivers\vstxraid.sys 0849B7260F26FE05EA56DED0672E2F4B
    C:\Windows\System32\drivers\vwifibus.sys BE970C369E43B509C1EDA2B8FA7CECB0
    C:\Windows\system32\DRIVERS\vwififlt.sys 6B26AD573CCDD5209DF4397438B76354
    C:\Windows\system32\DRIVERS\vwifimp.sys 0B48E0DFB44EE475F4FD8A8EE599AF30
    C:\Windows\System32\drivers\wacompen.sys 0910AB9ED404C1434E2D0376C2AD5D8B
    C:\Windows\System32\drivers\WdBoot.sys 1751F6B031ADAC34724511057D2E455D
    C:\Windows\System32\drivers\Wdf01000.sys CB6C63FF8342B467E2EF76E98D5B934D
    C:\Windows\System32\drivers\WdFilter.sys D296D0F0DB2CD1504F90405603664493
    C:\Windows\System32\Drivers\WdNisDrv.sys 9F4DF0043965808973023A9B51A11136
    C:\Windows\System32\DRIVERS\wfplwfs.sys 715ABA3DD164D06457A2A3C92F6EA9D5
    C:\Windows\System32\drivers\wimmount.sys 5F66B7BB330AA80067FC66149A692620
    C:\Windows\System32\drivers\wmiacpi.sys 2834D9D3B4F554A39C72F00EA3F0E128
    C:\Windows\System32\Drivers\Wof.sys 7FC5667DF73D4B04AA457CC3A4180E09
    C:\Windows\System32\DRIVERS\wpcfltr.sys A2468CC3509394A33C4C32F99563D845
    C:\Windows\System32\drivers\WpdUpFltr.sys 9F2904B55F6CECCD1A8D986B5CE2609A
    C:\Windows\system32\drivers\ws2ifsl.sys AE072B0339D0A18E455DC21666CAD572
    C:\Windows\System32\drivers\WudfPf.sys 481286719402E4BAEFEA0604AB1B5113
    C:\Windows\System32\drivers\WUDFRd.sys D7B4859227B02BCC1055B279A63C937F
    C:\Windows\system32\DRIVERS\WUDFRd.sys D7B4859227B02BCC1055B279A63C937F
    C:\Windows\System32\drivers\XHCIPort.sys 6FDEE5E0741A3FFA5E5772C6C94E3F64

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Three Months Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-07-16 07:57 - 2015-07-16 07:57 - 00043387 _____ C:\Users\Rosa\Downloads\FRST.txt
    2015-07-16 07:51 - 2015-07-16 07:57 - 00000000 ____D C:\FRST
    2015-07-16 07:51 - 2015-07-16 07:51 - 02133504 _____ (Farbar) C:\Users\Rosa\Downloads\FRST64.exe
    2015-07-16 07:33 - 2015-07-16 07:55 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2015-07-16 07:32 - 2015-07-16 07:32 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Rosa\Downloads\mbam-setup-2.1.8.1057.exe
    2015-07-16 07:32 - 2015-07-16 07:32 - 00001116 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-07-16 07:32 - 2015-07-16 07:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-07-16 07:32 - 2015-07-16 07:32 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-07-16 07:32 - 2015-07-16 07:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-07-16 07:32 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2015-07-16 07:32 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2015-07-16 07:32 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
    2015-07-16 07:29 - 2015-07-16 07:29 - 00000746 _____ C:\Users\Rosa\Downloads\Remove_Windows_Update_Policies.reg
    2015-07-16 07:09 - 2015-07-16 07:09 - 00001181 _____ C:\Users\Administrator\Downloads\Reset_Local_Group_Policy.vbs
    2015-07-16 07:01 - 2015-07-16 07:04 - 00002935 _____ C:\WINDOWS\KB907265.log
    2015-07-16 07:01 - 2015-07-16 07:01 - 01965808 _____ (Microsoft Corporation) C:\Users\Administrator\Downloads\WindowsXP-KB907265-x86-ENU.exe
    2015-07-16 06:53 - 2015-07-16 06:53 - 00588906 _____ C:\Users\Administrator\Downloads\RmsAnalyzer.zip
    2015-07-16 06:53 - 2015-07-16 06:53 - 00000000 ____D C:\Users\Administrator\Downloads\RmsAnalyzer
    2015-07-16 06:48 - 2015-07-16 06:48 - 00000000 ____D C:\Users\Administrator\Downloads\add_gpedit_msc_by_jwils876-d3kh6vm
    2015-07-16 06:45 - 2015-07-16 06:47 - 00707354 _____ C:\WINDOWS\unins000.exe
    2015-07-16 06:45 - 2015-07-16 06:47 - 00002588 _____ C:\WINDOWS\unins000.dat
    2015-07-16 06:45 - 2015-07-16 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\GPBAK
    2015-07-16 06:45 - 2015-07-16 06:45 - 00875012 _____ C:\Users\Administrator\Downloads\add_gpedit_msc_by_jwils876-d3kh6vm.zip
    2015-07-16 06:45 - 2015-07-16 06:45 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\WinRAR
    2015-07-16 06:45 - 2008-04-14 02:11 - 00295936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appmgr.dll
    2015-07-16 06:45 - 2001-08-23 13:00 - 00034871 _____ C:\WINDOWS\SysWOW64\gpedit.msc
    2015-07-16 06:37 - 2015-07-16 06:37 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-526706507-2563106057-1816975683-500
    2015-07-16 06:36 - 2015-07-16 06:36 - 05822464 _____ C:\Users\Administrator\Downloads\gpmc (1).msi
    2015-07-16 06:35 - 2015-07-16 06:35 - 05822464 _____ C:\Users\Administrator\Downloads\gpmc.msi
    2015-07-16 06:34 - 2015-07-16 06:34 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Macromedia
    2015-07-16 06:29 - 2015-07-16 06:29 - 00000352 _____ C:\Users\Administrator\AppData\Roaming\sp_data.sys
    2015-07-16 06:29 - 2015-07-16 06:29 - 00000000 ____D C:\Users\Administrator\AppData\Local\Adobe
    2015-07-16 06:28 - 2015-07-16 06:32 - 00000000 ____D C:\Users\Administrator\AppData\Local\Packages
    2015-07-16 06:28 - 2015-07-16 06:29 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
    2015-07-16 06:28 - 2015-07-16 06:28 - 00001444 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-07-16 06:28 - 2015-07-16 06:28 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
    2015-07-16 06:28 - 2015-07-16 06:28 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Intel
    2015-07-16 06:28 - 2015-07-16 06:28 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
    2015-07-16 06:28 - 2015-07-16 06:28 - 00000000 ____D C:\Users\Administrator\AppData\Local\ASUS
    2015-07-16 06:28 - 2015-07-16 06:28 - 00000000 ____D C:\Users\Administrator
    2015-07-16 06:28 - 2015-07-12 11:12 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2015-07-16 06:28 - 2014-11-21 08:57 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-07-16 06:28 - 2014-11-21 08:57 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    2015-07-16 06:28 - 2014-11-21 01:52 - 00000369 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
    2015-07-16 06:28 - 2014-11-21 01:52 - 00000369 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
    2015-07-16 06:28 - 2013-08-22 08:36 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2015-07-16 06:25 - 2015-07-16 06:25 - 00000000 ____D C:\Users\Rosa\AppData\Local\Microsoft_Corporation
    2015-07-15 20:11 - 2015-07-15 20:11 - 00000000 ____D C:\Users\Rosa\AppData\Local\Topaz Labs
    2015-07-15 19:56 - 2015-07-15 19:56 - 00001336 _____ C:\Users\sdcfalcon\Desktop\photoFXlab (32-bit).lnk
    2015-07-15 19:56 - 2015-07-15 19:56 - 00001336 _____ C:\Users\Rosa\Desktop\photoFXlab (32-bit).lnk
    2015-07-15 19:56 - 2015-07-15 19:56 - 00001318 _____ C:\Users\sdcfalcon\Desktop\photoFXlab (64-bit).lnk
    2015-07-15 19:56 - 2015-07-15 19:56 - 00001318 _____ C:\Users\Rosa\Desktop\photoFXlab (64-bit).lnk
    2015-07-15 19:56 - 2015-07-15 19:56 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Topaz Labs
    2015-07-15 19:56 - 2015-07-15 19:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topaz Labs
    2015-07-15 19:51 - 2015-07-15 19:56 - 00000000 ____D C:\Program Files (x86)\Topaz Labs
    2015-07-15 19:51 - 2015-07-15 19:55 - 00000000 ____D C:\Program Files\Common Files\Topaz Labs
    2015-07-15 19:50 - 2015-07-15 19:50 - 00000000 ____D C:\Users\Rosa\AppData\Local\PackageAware
    2015-07-15 04:01 - 2015-07-15 04:01 - 00000000 ____D C:\Users\Rosa\Desktop\Scripts of Tarnburg
    2015-07-15 01:45 - 2015-07-15 03:34 - 00000256 _____ C:\Users\Rosa\Desktop\New Text Document.txt
    2015-07-15 01:31 - 2015-07-09 12:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2015-07-15 01:31 - 2015-07-09 11:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
    2015-07-15 01:31 - 2015-07-09 09:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2015-07-15 01:31 - 2015-07-09 08:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
    2015-07-15 01:31 - 2015-07-09 08:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
    2015-07-15 01:31 - 2015-07-09 08:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
    2015-07-15 01:31 - 2015-07-09 08:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
    2015-07-15 01:31 - 2015-07-09 08:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
    2015-07-15 01:31 - 2015-07-09 08:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
    2015-07-15 01:31 - 2015-07-09 08:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
    2015-07-15 01:31 - 2015-07-09 08:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
    2015-07-15 01:31 - 2015-07-09 08:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
    2015-07-15 01:31 - 2015-07-09 08:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
    2015-07-15 01:31 - 2015-07-03 06:52 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2015-07-15 01:31 - 2015-07-03 06:52 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2015-07-15 01:31 - 2015-07-03 06:50 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2015-07-15 01:31 - 2015-07-03 06:50 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2015-07-15 01:31 - 2015-07-02 14:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-07-15 01:31 - 2015-07-02 13:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-07-15 01:31 - 2015-07-02 13:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-07-15 01:31 - 2015-07-02 13:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-07-15 01:31 - 2015-07-02 13:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2015-07-15 01:31 - 2015-07-02 12:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2015-07-15 01:31 - 2015-07-02 12:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2015-07-15 01:31 - 2015-07-02 11:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2015-07-15 01:31 - 2015-07-01 15:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2015-07-15 01:31 - 2015-07-01 14:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2015-07-15 01:31 - 2015-06-27 22:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
    2015-07-15 01:31 - 2015-06-27 22:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2015-07-15 01:31 - 2015-06-27 22:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
    2015-07-15 01:31 - 2015-06-27 22:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
    2015-07-15 01:31 - 2015-06-27 09:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
    2015-07-15 01:31 - 2015-06-26 20:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
    2015-07-15 01:31 - 2015-06-26 20:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
    2015-07-15 01:31 - 2015-06-26 20:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
    2015-07-15 01:31 - 2015-06-26 20:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
    2015-07-15 01:31 - 2015-06-26 20:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
    2015-07-15 01:31 - 2015-06-26 19:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
    2015-07-15 01:31 - 2015-06-26 19:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
    2015-07-15 01:31 - 2015-06-26 19:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2015-07-15 01:31 - 2015-06-26 19:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2015-07-15 01:31 - 2015-06-26 18:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
    2015-07-15 01:31 - 2015-06-26 18:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2015-07-15 01:31 - 2015-06-24 19:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2015-07-15 01:31 - 2015-06-15 15:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
    2015-07-15 01:31 - 2015-06-15 15:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
    2015-07-15 01:31 - 2015-06-15 14:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
    2015-07-15 01:31 - 2015-06-15 14:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
    2015-07-15 01:31 - 2015-06-15 13:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2015-07-15 01:31 - 2015-06-15 12:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2015-07-15 01:31 - 2015-05-30 14:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
    2015-07-15 01:31 - 2015-05-30 12:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2015-07-15 01:31 - 2015-05-30 12:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2015-07-15 01:31 - 2015-05-11 11:17 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
    2015-07-15 01:31 - 2015-05-07 10:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2015-07-15 01:31 - 2015-05-07 10:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
    2015-07-15 01:31 - 2015-05-07 09:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2015-07-15 01:31 - 2015-05-07 09:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
    2015-07-15 01:31 - 2015-05-07 08:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
    2015-07-15 01:31 - 2015-05-07 08:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
    2015-07-15 01:31 - 2015-05-03 08:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
    2015-07-15 01:31 - 2015-05-03 07:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
    2015-07-15 01:31 - 2015-05-03 07:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
    2015-07-15 01:31 - 2015-05-03 07:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
    2015-07-15 01:31 - 2015-05-02 17:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
    2015-07-15 01:31 - 2015-04-29 16:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
    2015-07-15 01:31 - 2015-04-24 19:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys
    2015-07-15 01:31 - 2015-01-29 20:01 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
    2015-07-15 01:31 - 2015-01-29 20:00 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys
    2015-07-15 01:30 - 2015-06-15 22:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
    2015-07-15 01:30 - 2015-06-15 22:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
    2015-07-15 01:30 - 2015-06-15 15:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2015-07-15 01:30 - 2015-06-15 15:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
    2015-07-15 01:30 - 2015-06-15 15:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
    2015-07-15 01:30 - 2015-06-15 15:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2015-07-15 01:30 - 2015-06-15 15:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
    2015-07-15 01:30 - 2015-06-15 14:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
    2015-07-15 01:30 - 2015-06-15 14:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
    2015-07-15 01:30 - 2015-06-15 14:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
    2015-07-15 01:30 - 2015-06-15 14:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
    2015-07-15 01:30 - 2015-06-15 14:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
    2015-07-15 01:30 - 2015-06-15 14:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
    2015-07-15 01:30 - 2015-06-15 14:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2015-07-15 01:30 - 2015-06-15 14:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2015-07-15 01:30 - 2015-06-15 14:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
    2015-07-15 01:30 - 2015-06-15 14:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2015-07-15 01:30 - 2015-06-15 14:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2015-07-15 01:30 - 2015-06-15 14:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
    2015-07-15 01:30 - 2015-06-15 14:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
    2015-07-15 01:30 - 2015-06-15 14:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2015-07-15 01:30 - 2015-06-15 13:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
    2015-07-15 01:30 - 2015-06-15 13:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
    2015-07-15 01:30 - 2015-06-15 13:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
    2015-07-15 01:30 - 2015-06-15 13:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
    2015-07-15 01:30 - 2015-06-15 13:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
    2015-07-15 01:30 - 2015-06-15 13:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
    2015-07-15 01:30 - 2015-06-15 13:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
    2015-07-15 01:30 - 2015-06-15 13:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
    2015-07-15 01:30 - 2015-06-15 13:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2015-07-15 01:30 - 2015-06-15 13:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2015-07-15 01:30 - 2015-06-15 13:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2015-07-15 01:30 - 2015-06-15 13:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
    2015-07-15 01:30 - 2015-06-15 13:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2015-07-15 01:30 - 2015-06-15 13:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
    2015-07-15 01:30 - 2015-06-10 20:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
    2015-07-15 01:30 - 2015-06-10 09:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
    2015-07-15 01:30 - 2015-05-12 06:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
    2015-07-15 01:30 - 2015-05-11 09:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
    2015-07-15 01:30 - 2015-05-07 09:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
    2015-07-15 01:30 - 2015-05-03 08:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
    2015-07-15 01:30 - 2015-05-03 07:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
    2015-07-15 01:30 - 2015-05-01 16:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml
    2015-07-15 01:30 - 2015-04-28 06:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls
    2015-07-15 01:30 - 2015-04-28 06:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls
    2015-07-15 01:30 - 2015-04-23 08:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
     
  9. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    2015-07-15 01:30 - 2015-04-23 08:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2015-07-14 23:19 - 2015-07-15 01:15 - 00295936 _____ C:\Users\Rosa\Downloads\adobe.photoshop.cs6-patch.exe
    2015-07-14 02:09 - 2015-07-14 02:09 - 00001560 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
    2015-07-14 02:09 - 2015-07-14 02:09 - 00001548 _____ C:\Users\Public\Desktop\Adobe Application Manager.lnk
    2015-07-14 01:28 - 2015-07-14 01:28 - 00000000 ____D C:\Users\Rosa\Desktop\Tarnburg
    2015-07-14 01:22 - 2015-07-15 22:38 - 00000132 _____ C:\Users\Rosa\AppData\Roaming\Adobe PNG Format CS6 Prefs
    2015-07-14 01:17 - 2015-07-14 01:17 - 00003492 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-chloeoftreve@hotmail.com
    2015-07-14 01:16 - 2015-07-14 01:16 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\PDAppFlex
    2015-07-13 20:19 - 2015-07-13 20:19 - 00000000 ____D C:\Users\Rosa\AppData\Local\GWX
    2015-07-13 20:17 - 2015-07-13 20:17 - 00000000 _____ C:\Users\sdcfalcon\Downloads\FileEraser.fer
    2015-07-13 20:10 - 2015-07-13 20:10 - 01141248 _____ (Dancemammal.com) C:\Users\sdcfalcon\Downloads\ZeroTrace.exe
    2015-07-13 14:22 - 2015-07-13 14:22 - 00002041 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
    2015-07-13 10:45 - 2015-07-16 07:26 - 00000596 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-526706507-2563106057-1816975683-1004.job
    2015-07-13 10:45 - 2015-07-16 06:31 - 00000692 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-526706507-2563106057-1816975683-1004.job
    2015-07-13 10:45 - 2015-07-13 10:45 - 00003692 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-526706507-2563106057-1816975683-1004
    2015-07-13 10:45 - 2015-07-13 10:45 - 00003596 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-526706507-2563106057-1816975683-1004
    2015-07-13 10:45 - 2015-07-13 10:45 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\Citrix
    2015-07-13 08:15 - 2015-07-13 08:15 - 14194305 _____ C:\Users\sdcfalcon\Downloads\Halo4Heroes.themepack
    2015-07-13 08:03 - 2015-07-13 14:18 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\Adobe
    2015-07-13 04:41 - 2015-07-13 04:41 - 07492048 _____ C:\Users\Rosa\Desktop\Restore Report 07-12-2015 05-18-25PM.html
    2015-07-13 04:37 - 2015-07-10 20:50 - 00000287 _____ C:\Users\Rosa_2\Desktop\Restrictions.txt
    2015-07-13 04:37 - 2015-04-06 18:46 - 00001422 _____ C:\Users\Rosa_2\Desktop\topaz keys.txt
    2015-07-12 19:38 - 2015-07-12 19:39 - 840745736 _____ (Topaz Labs ) C:\Users\Rosa\Downloads\topazcollection_setup.exe
    2015-07-12 19:19 - 2015-07-12 19:19 - 00001225 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
    2015-07-12 19:19 - 2015-07-12 19:19 - 00001093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
    2015-07-12 19:19 - 2015-07-12 19:19 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
    2015-07-12 19:18 - 2015-07-14 02:11 - 00000000 ____D C:\Program Files\Adobe
    2015-07-12 19:18 - 2015-07-12 19:18 - 00001055 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
    2015-07-12 19:17 - 2015-07-12 19:17 - 00001187 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
    2015-07-12 19:15 - 2015-07-12 19:15 - 00001371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
    2015-07-12 19:14 - 2015-07-12 19:14 - 00001541 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
    2015-07-12 19:12 - 2015-07-14 02:19 - 00000000 ____D C:\Program Files\Common Files\Adobe
    2015-07-12 19:08 - 2015-07-16 02:00 - 00000000 ____D C:\Users\Rosa\AppData\Local\Adobe
    2015-07-12 18:49 - 2015-07-12 18:51 - 00000000 ____D C:\Users\Rosa\Downloads\Photoshop_13_LS16
    2015-07-12 18:49 - 2015-07-12 18:49 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\WinRAR
    2015-07-12 18:41 - 2015-07-12 18:43 - 1207595878 _____ C:\Users\Rosa\Downloads\Photoshop_13_LS16.7z
    2015-07-12 18:41 - 2015-07-12 18:41 - 00000995 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk
    2015-07-12 18:41 - 2015-07-12 18:41 - 00000989 _____ C:\Users\Public\Desktop\WinRAR.lnk
    2015-07-12 18:41 - 2015-07-12 18:41 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    2015-07-12 18:41 - 2015-07-12 18:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2015-07-12 18:41 - 2015-07-12 18:41 - 00000000 ____D C:\Program Files\WinRAR
    2015-07-12 18:39 - 2015-07-12 18:40 - 01941744 _____ C:\Users\Rosa\Downloads\winrar-x64-521.exe
    2015-07-12 17:23 - 2015-07-13 04:38 - 00000000 ____D C:\Users\Rosa_2\Documents\paystubs
    2015-07-12 17:23 - 2015-07-13 04:37 - 00000000 ____D C:\Users\Rosa_2\Documents\Caption Folder
    2015-07-12 17:23 - 2015-07-13 04:37 - 00000000 ____D C:\Users\Rosa_2\Desktop\paystubs
    2015-07-12 17:23 - 2015-07-12 17:23 - 00000000 ____D C:\Users\Rosa_2
    2015-07-12 17:19 - 2015-07-12 17:52 - 00000000 ___RD C:\Users\Rosa\Dropbox
    2015-07-12 17:19 - 2015-07-12 17:46 - 00000000 ____D C:\Users\Rosa\Documents\rosastaxreturns
    2015-07-12 17:19 - 2015-07-12 17:46 - 00000000 ____D C:\Users\Rosa\Documents\jans tax returns
    2015-07-12 17:18 - 2015-07-12 17:42 - 00000000 ____D C:\Users\Rosa\Documents\Court Stuff
    2015-07-12 17:18 - 2015-07-12 17:41 - 00000000 ____D C:\Users\Rosa\Documents\brushes
    2015-07-12 17:18 - 2015-07-12 17:30 - 00000000 ____D C:\Users\Rosa\Documents\actions
    2015-07-12 17:18 - 2015-07-12 17:28 - 00000000 ____D C:\Users\Rosa\Desktop\Stuff Rev Sends Me
    2015-07-12 17:18 - 2015-07-12 17:27 - 00000000 ____D C:\Users\Rosa\Desktop\Rebellion
    2015-07-12 17:18 - 2015-07-12 17:27 - 00000000 ____D C:\Users\Rosa\Desktop\CTS
    2015-07-12 16:53 - 2015-07-12 16:53 - 00000000 ___HD C:\$SysReset
    2015-07-12 16:39 - 2015-07-12 16:39 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
    2015-07-12 16:34 - 2015-07-12 16:34 - 00000000 __SHD C:\Users\sdcfalcon\AppData\Local\EmieUserList
    2015-07-12 16:34 - 2015-07-12 16:34 - 00000000 __SHD C:\Users\sdcfalcon\AppData\Local\EmieSiteList
    2015-07-12 16:30 - 2015-07-12 16:30 - 00108106 _____ C:\Users\sdcfalcon\Desktop\intback.reg
    2015-07-12 14:59 - 2015-07-12 15:33 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\supportdotcom
    2015-07-12 14:45 - 2015-07-13 17:10 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\IntraNext
    2015-07-12 14:45 - 2015-07-12 14:45 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\Avaya
    2015-07-12 14:35 - 2015-07-12 14:35 - 00000000 ____D C:\Users\sdcfalcon\Documents\skype incoming files
    2015-07-12 14:32 - 2015-07-12 14:32 - 00000000 ____D C:\Users\sdcfalcon\Tracing
    2015-07-12 14:30 - 2015-07-16 05:40 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\Skype
    2015-07-12 14:30 - 2015-07-12 14:30 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\Skype
    2015-07-12 14:21 - 2015-07-16 07:54 - 00003005 _____ C:\WINDOWS\SysWOW64\QosServ.log
    2015-07-12 14:21 - 2015-07-12 14:21 - 00002669 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ONECTI.lnk
    2015-07-12 14:21 - 2015-07-12 14:21 - 00001328 _____ C:\Users\sdcfalcon\Desktop\Avaya Launcher.lnk
    2015-07-12 14:21 - 2015-07-12 14:21 - 00000031 _____ C:\Users\sdcfalcon\AppData\Roaming\mySettings_SDC.txt
    2015-07-12 14:21 - 2015-07-12 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CSG
    2015-07-12 14:21 - 2015-07-12 14:21 - 00000000 ____D C:\Program Files (x86)\IntraNext Systems
    2015-07-12 14:21 - 2015-07-12 14:21 - 00000000 ____D C:\Program Files (x86)\CSG
    2015-07-12 14:20 - 2015-07-12 14:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avaya
    2015-07-12 14:20 - 2010-11-09 07:56 - 00233472 _____ (Avaya Inc.) C:\WINDOWS\SysWOW64\QosServM.exe
    2015-07-12 14:19 - 2015-07-12 14:19 - 00000000 ____D C:\Program Files (x86)\Avaya
    2015-07-12 14:04 - 2015-07-12 14:04 - 00000000 ____D C:\ProgramData\SUPERSetup
    2015-07-12 13:57 - 2015-07-12 13:57 - 22407376 _____ (SUPERAntiSpyware) C:\Users\sdcfalcon\Downloads\SUPERAntiSpyware.exe
    2015-07-12 13:40 - 2015-07-15 18:48 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\.purple
    2015-07-12 13:39 - 2015-07-12 13:39 - 00001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pidgin.lnk
    2015-07-12 13:39 - 2015-07-12 13:39 - 00000993 _____ C:\Users\Public\Desktop\Pidgin.lnk
    2015-07-12 13:39 - 2015-07-12 13:39 - 00000000 ____D C:\Program Files (x86)\Pidgin
    2015-07-12 13:38 - 2015-07-12 13:38 - 09670472 _____ C:\Users\sdcfalcon\Downloads\pidgin-2.10.11.exe
    2015-07-12 13:30 - 2015-07-12 13:30 - 00017084 _____ C:\Users\sdcfalcon\Desktop\Restore Report 07-12-2015 01-28-03PM.html
    2015-07-12 13:13 - 2015-07-12 13:13 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
    2015-07-12 13:13 - 2015-07-12 13:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2015-07-12 13:13 - 2015-07-12 13:13 - 00000000 ____D C:\Program Files (x86)\Java
    2015-07-12 13:09 - 2015-07-12 13:09 - 00000000 ____D C:\ProgramData\Sun
    2015-07-12 13:09 - 2015-07-12 13:09 - 00000000 ____D C:\ProgramData\Oracle
    2015-07-12 13:08 - 2015-07-12 13:08 - 00562272 _____ (Oracle Corporation) C:\Users\sdcfalcon\Downloads\chromeinstall-8u45.exe
    2015-07-12 12:56 - 2015-07-12 12:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
    2015-07-12 12:51 - 2015-07-12 12:51 - 00000000 ____D C:\ProgramData\NAC Assessment Agent
    2015-07-12 12:51 - 2015-07-12 12:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extreme Networks
    2015-07-12 12:51 - 2015-07-12 12:51 - 00000000 ____D C:\Program Files (x86)\Extreme Networks
    2015-07-12 12:49 - 2015-07-12 12:56 - 00000000 ____D C:\ProgramData\Cisco
    2015-07-12 12:49 - 2015-07-12 12:49 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\Cisco
    2015-07-12 12:49 - 2014-06-10 20:15 - 00112496 ____R (Cisco Systems, Inc.) C:\WINDOWS\system32\Drivers\acsock64.sys
    2015-07-12 12:39 - 2015-07-12 12:39 - 00000000 ____D C:\Program Files (x86)\Support.com
    2015-07-12 12:37 - 2015-07-16 04:58 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\SDCWB
    2015-07-12 12:37 - 2015-07-16 04:57 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\Deployment
    2015-07-12 12:37 - 2015-07-12 12:37 - 00431936 _____ () C:\Users\sdcfalcon\Downloads\sdcwb_setup.exe
    2015-07-12 12:37 - 2015-07-12 12:37 - 00000346 _____ C:\Users\sdcfalcon\Desktop\SDC Workbench.appref-ms
    2015-07-12 12:37 - 2015-07-12 12:37 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Support.com
    2015-07-12 12:37 - 2015-07-12 12:37 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\Apps\2.0
    2015-07-12 12:35 - 2015-07-14 11:50 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-526706507-2563106057-1816975683-1004
    2015-07-12 12:32 - 2015-07-12 12:32 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\Google
    2015-07-12 12:31 - 2015-07-12 12:31 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\Macromedia
    2015-07-12 12:30 - 2015-07-16 04:55 - 00000352 _____ C:\Users\sdcfalcon\AppData\Roaming\sp_data.sys
    2015-07-12 12:29 - 2015-07-14 07:14 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\Packages
    2015-07-12 12:29 - 2015-07-13 14:18 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\Adobe
    2015-07-12 12:29 - 2015-07-12 14:59 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\VirtualStore
    2015-07-12 12:29 - 2015-07-12 14:32 - 00000000 ____D C:\Users\sdcfalcon
    2015-07-12 12:29 - 2015-07-12 12:29 - 00001444 _____ C:\Users\sdcfalcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-07-12 12:29 - 2015-07-12 12:29 - 00000020 ___SH C:\Users\sdcfalcon\ntuser.ini
    2015-07-12 12:29 - 2015-07-12 12:29 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\Intel
    2015-07-12 12:29 - 2015-07-12 12:29 - 00000000 ____D C:\Users\sdcfalcon\AppData\Local\ASUS
    2015-07-12 12:29 - 2015-07-12 11:12 - 00000000 ___RD C:\Users\sdcfalcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2015-07-12 12:29 - 2014-11-21 08:57 - 00000000 ___RD C:\Users\sdcfalcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-07-12 12:29 - 2014-11-21 08:57 - 00000000 ___RD C:\Users\sdcfalcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    2015-07-12 12:29 - 2014-11-21 01:52 - 00000369 _____ C:\Users\sdcfalcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
    2015-07-12 12:29 - 2014-11-21 01:52 - 00000369 _____ C:\Users\sdcfalcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
    2015-07-12 12:29 - 2013-08-22 08:36 - 00000000 ____D C:\Users\sdcfalcon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2015-07-12 12:22 - 2015-07-12 12:22 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2015-07-12 12:21 - 2015-07-12 12:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2015-07-12 12:21 - 2015-07-12 12:21 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2015-07-12 12:21 - 2015-07-12 12:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2015-07-12 12:20 - 2015-06-29 15:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
    2015-07-12 12:20 - 2015-06-29 08:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
    2015-07-12 12:20 - 2015-06-29 08:07 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
    2015-07-12 12:20 - 2015-06-29 08:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
    2015-07-12 12:20 - 2015-06-29 08:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
    2015-07-12 12:20 - 2015-06-29 08:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2015-07-12 12:20 - 2015-06-26 16:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2015-07-12 12:20 - 2015-06-26 16:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
    2015-07-12 12:20 - 2015-05-21 06:08 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
    2015-07-12 11:57 - 2015-07-16 07:56 - 00000000 ___RD C:\Users\Rosa\OneDrive
    2015-07-12 11:35 - 2015-07-12 11:35 - 00001444 _____ C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-07-12 11:34 - 2015-07-12 11:34 - 00000020 ___SH C:\Users\Rosa\ntuser.ini
    2015-07-12 11:21 - 2015-07-13 08:17 - 00000000 ___DC C:\WINDOWS\Panther
    2015-07-12 11:21 - 2015-07-12 11:21 - 00000000 __SHD C:\Recovery
    2015-07-12 11:20 - 2015-07-12 11:20 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 18823168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 15158784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 04837376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 02485056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 01574400 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 01454080 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
    2015-07-12 11:19 - 2015-07-12 11:19 - 01154048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
    2015-07-12 11:19 - 2015-07-12 11:19 - 01142272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 01084416 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
    2015-07-12 11:19 - 2015-07-12 11:19 - 01027584 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00962216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00952896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00885760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
    2015-07-12 11:19 - 2015-07-12 11:19 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
    2015-07-12 11:19 - 2015-07-12 11:19 - 00801584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00786120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00733696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00658432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00551232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00473408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00465408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
    2015-07-12 11:19 - 2015-07-12 11:19 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
    2015-07-12 11:19 - 2015-07-12 11:19 - 00420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
    2015-07-12 11:19 - 2015-07-12 11:19 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\QSHVHOST.DLL
    2015-07-12 11:19 - 2015-07-12 11:19 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QSHVHOST.DLL
    2015-07-12 11:19 - 2015-07-12 11:19 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00136512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
    2015-07-12 11:19 - 2015-07-12 11:19 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\QSVRMGMT.DLL
    2015-07-12 11:19 - 2015-07-12 11:19 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QSVRMGMT.DLL
    2015-07-12 11:19 - 2015-07-12 11:19 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdiag.dll
     
  10. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    2015-07-12 11:19 - 2015-07-12 11:19 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00058176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vsstrace.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\kmddsp.tsp
    2015-07-12 11:19 - 2015-07-12 11:19 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmxs.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00039744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kmddsp.tsp
    2015-07-12 11:19 - 2015-07-12 11:19 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasmxs.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasser.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
    2015-07-12 11:19 - 2015-07-12 11:19 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasser.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\eventcls.dll
    2015-07-12 11:19 - 2015-07-12 11:19 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eventcls.dll
    2015-07-12 11:19 - 2015-05-25 06:23 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
    2015-07-12 11:19 - 2015-05-25 06:07 - 01430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
    2015-07-12 11:19 - 2014-06-09 15:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2015-07-12 11:19 - 2014-06-09 15:13 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2015-07-12 11:18 - 2015-07-12 11:18 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
    2015-07-12 11:18 - 2015-07-12 11:18 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
    2015-07-12 11:18 - 2015-07-12 11:18 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
    2015-07-12 11:18 - 2015-01-19 11:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
    2015-07-12 11:18 - 2014-07-23 20:20 - 00875688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
    2015-07-12 11:18 - 2014-07-23 20:20 - 00869544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
    2015-07-12 11:17 - 2015-07-12 11:17 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
    2015-07-12 11:17 - 2015-07-12 11:17 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
    2015-07-12 11:17 - 2015-07-12 11:17 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
    2015-07-12 11:17 - 2015-07-12 11:17 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
    2015-07-12 11:17 - 2015-07-12 11:17 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
    2015-07-12 11:16 - 2015-07-12 11:16 - 02171904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
    2015-07-12 11:16 - 2015-07-12 11:16 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
    2015-07-12 11:16 - 2015-07-12 11:16 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
    2015-07-12 11:16 - 2015-07-12 11:16 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
    2015-07-12 11:16 - 2015-07-12 11:16 - 00672984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
    2015-07-12 11:16 - 2015-07-12 11:16 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
    2015-07-12 11:16 - 2015-07-12 11:16 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
    2015-07-12 11:16 - 2015-07-12 11:16 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
    2015-07-12 11:16 - 2015-07-12 11:16 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2015-07-12 11:16 - 2015-07-12 11:16 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
    2015-07-12 11:16 - 2015-07-12 11:16 - 00273240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
    2015-07-12 11:16 - 2015-07-12 11:16 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsDatabase.dll
    2015-07-12 11:15 - 2015-07-12 11:15 - 01763352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
    2015-07-12 11:15 - 2015-07-12 11:15 - 01488040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
    2015-07-12 11:15 - 2015-07-12 11:15 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
    2015-07-12 11:15 - 2015-07-12 11:15 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
    2015-07-12 11:15 - 2015-07-12 11:15 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
    2015-07-12 11:15 - 2015-07-12 11:15 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
    2015-07-12 11:14 - 2015-07-12 11:14 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
    2015-07-12 11:14 - 2015-07-12 11:14 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-07-12 11:14 - 2015-07-12 11:14 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-07-12 11:13 - 2015-07-12 11:13 - 01113920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
    2015-07-12 11:13 - 2015-07-12 11:13 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
    2015-07-12 11:13 - 2015-07-12 11:13 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
    2015-07-12 11:13 - 2015-07-12 11:13 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
    2015-07-12 11:13 - 2015-07-12 11:13 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
    2015-07-12 11:13 - 2015-07-12 11:13 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
    2015-07-12 11:12 - 2015-07-12 12:05 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
    2015-07-12 11:12 - 2015-07-12 12:05 - 00000000 ___SD C:\WINDOWS\system32\GWX
    2015-07-12 11:12 - 2015-07-12 11:12 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 01970432 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 01612992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00264000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
    2015-07-12 11:12 - 2015-07-12 11:12 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
    2015-07-12 11:12 - 2015-07-12 11:12 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00046456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContentServer.exe
    2015-07-12 11:12 - 2015-07-12 11:12 - 00044024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
    2015-07-12 11:12 - 2015-07-12 11:12 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
    2015-07-12 11:12 - 2015-07-12 11:12 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2015-07-12 11:11 - 2015-07-12 11:11 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00561928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2015-07-12 11:11 - 2015-07-12 11:11 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
    2015-07-12 11:11 - 2015-07-12 11:11 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
    2015-07-12 11:11 - 2015-07-12 11:11 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
    2015-07-12 11:11 - 2015-07-12 11:11 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00239424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
    2015-07-12 11:11 - 2015-07-12 11:11 - 00154432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
    2015-07-12 11:11 - 2015-07-12 11:11 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
    2015-07-12 11:11 - 2015-07-12 11:11 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
    2015-07-12 11:11 - 2015-07-12 11:11 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
    2015-07-12 11:11 - 2015-07-12 11:11 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 03551744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 01488896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 01464832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42u.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 01204224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
    2015-07-12 11:10 - 2015-07-12 11:10 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 00410128 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2015-07-12 11:09 - 2015-07-12 11:09 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
    2015-07-12 11:09 - 2015-07-12 11:09 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rgb9rast.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageContextHandler.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StorageContextHandler.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
    2015-07-12 11:09 - 2015-07-12 11:09 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceSetupStatusProvider.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00933888 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
    2015-07-12 11:08 - 2015-07-12 11:08 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
    2015-07-12 11:08 - 2015-07-12 11:08 - 00723072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00560392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
    2015-07-12 11:08 - 2015-07-12 11:08 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
    2015-07-12 11:08 - 2015-07-12 11:08 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
    2015-07-12 11:07 - 2015-07-12 11:07 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
    2015-07-12 11:07 - 2015-07-12 11:07 - 01560576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
    2015-07-12 11:07 - 2015-07-12 11:07 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 03633664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 02749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 02551808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 01920000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
    2015-07-12 11:06 - 2015-07-12 11:06 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
    2015-07-12 11:06 - 2015-07-12 11:06 - 00699392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 00467776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
    2015-07-12 11:06 - 2015-07-12 11:06 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
    2015-07-12 11:06 - 2015-07-12 11:06 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
    2015-07-12 11:06 - 2015-07-12 11:06 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
    2015-07-12 11:06 - 2015-07-12 11:06 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
    2015-07-12 11:05 - 2015-07-12 11:05 - 02501368 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
    2015-07-12 11:05 - 2015-07-12 11:05 - 02207488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
    2015-07-12 11:05 - 2015-07-12 11:05 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
    2015-07-12 11:05 - 2015-07-12 11:05 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
    2015-07-12 11:05 - 2015-07-12 11:05 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
    2015-07-12 11:05 - 2015-07-12 11:05 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
    2015-07-12 11:04 - 2015-07-12 11:04 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
    2015-07-12 11:04 - 2015-07-12 11:04 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2015-07-12 11:04 - 2015-07-12 11:04 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
    2015-07-12 11:04 - 2015-07-12 11:04 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
    2015-07-12 11:04 - 2015-07-12 11:04 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
    2015-07-12 11:03 - 2015-07-12 11:03 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\photowiz.dll
    2015-07-12 11:03 - 2015-07-12 11:03 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\photowiz.dll
    2015-07-12 11:03 - 2015-07-12 11:03 - 00000000 ____D C:\iBTWU
    2015-07-12 11:02 - 2015-07-12 11:02 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
    2015-07-12 11:02 - 2015-07-12 11:02 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
    2015-07-12 11:02 - 2015-07-12 11:02 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
    2015-07-12 11:02 - 2015-07-12 11:02 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
    2015-07-12 11:02 - 2015-07-12 11:02 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
    2015-07-12 11:02 - 2015-07-12 11:02 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
    2015-07-12 11:02 - 2015-07-12 11:02 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
    2015-07-12 11:00 - 2015-07-12 11:00 - 00000000 ____D C:\Program Files\Reference Assemblies
    2015-07-12 11:00 - 2015-07-12 11:00 - 00000000 ____D C:\Program Files\MSBuild
    2015-07-12 11:00 - 2015-07-12 11:00 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2015-07-12 11:00 - 2015-07-12 11:00 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2015-07-12 11:00 - 2013-08-02 21:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2015-07-12 10:59 - 2015-07-12 10:59 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
    2015-07-12 10:59 - 2015-07-12 10:59 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe
    2015-07-12 10:59 - 2013-08-02 21:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2015-07-12 10:57 - 2014-04-15 16:35 - 00028352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
    2015-07-12 10:57 - 2014-04-15 16:34 - 00029888 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
    2015-07-12 10:53 - 2015-07-12 10:53 - 00003906 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1922D42B-6A0E-478F-A6EA-04FD198CF9AA}
    2015-07-12 10:49 - 2015-07-12 11:30 - 00000000 ____D C:\Users\TEMP
    2015-07-12 10:47 - 2015-07-16 07:28 - 01287913 _____ C:\WINDOWS\WindowsUpdate.log
    2015-07-12 10:47 - 2015-07-12 10:47 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
    2015-07-12 10:37 - 2015-07-12 10:37 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-07-12 10:35 - 2015-07-12 10:35 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2015-07-12 10:34 - 2015-07-13 08:08 - 00000000 ____D C:\Users\Rosa
    2015-07-12 10:34 - 2015-07-12 10:47 - 00020958 _____ C:\WINDOWS\diagwrn.xml
    2015-07-12 10:34 - 2015-07-12 10:47 - 00020958 _____ C:\WINDOWS\diagerr.xml
    2015-07-12 10:34 - 2015-07-12 10:35 - 00000000 ___RD C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2015-07-12 10:34 - 2014-11-21 08:57 - 00000000 ___RD C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-07-12 10:34 - 2014-11-21 08:57 - 00000000 ___RD C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    2015-07-12 10:34 - 2014-11-21 01:52 - 00000369 _____ C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
    2015-07-12 10:34 - 2014-11-21 01:52 - 00000369 _____ C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
    2015-07-12 10:34 - 2013-08-22 08:36 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2015-07-12 10:26 - 2015-07-12 10:35 - 00000000 ____D C:\Program Files (x86)\Intel
    2015-07-12 10:26 - 2015-07-12 10:26 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_iBtFltCoex_01009.Wdf
    2015-07-12 10:26 - 2015-07-12 10:26 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2015-07-12 10:26 - 2015-07-12 10:26 - 00000000 ____D C:\Program Files\Realtek
    2015-07-12 10:26 - 2013-10-01 13:02 - 00064000 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
    2015-07-12 10:26 - 2013-10-01 13:02 - 00060416 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
    2015-07-12 09:36 - 2015-07-12 10:47 - 00006650 _____ C:\WINDOWS\comsetup.log
    2015-07-12 09:17 - 2015-07-12 09:17 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
    2015-07-12 08:23 - 2015-07-05 03:08 - 00300704 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2015-07-12 07:42 - 2015-07-15 04:06 - 00000000 ____D C:\WINDOWS\system32\MRT
    2015-07-12 07:42 - 2015-07-03 08:43 - 130333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2015-07-12 05:10 - 2015-07-12 05:10 - 00000117 _____ C:\WINDOWS\system32\netcfg-1613171.txt
    2015-07-12 05:10 - 2015-07-12 05:10 - 00000117 _____ C:\WINDOWS\system32\netcfg-1610062.txt
    2015-07-12 05:10 - 2015-07-12 05:10 - 00000117 _____ C:\WINDOWS\system32\netcfg-1606359.txt
    2015-07-12 05:10 - 2015-07-12 05:10 - 00000117 _____ C:\WINDOWS\system32\netcfg-1605968.txt
    2015-07-12 05:06 - 2013-05-03 21:51 - 00014848 ____N (Microsoft) C:\WINDOWS\system32\rars.rs
    2015-07-12 05:06 - 2013-05-03 21:10 - 00014848 ____N (Microsoft) C:\WINDOWS\SysWOW64\rars.rs
    2015-07-12 04:56 - 2015-07-12 10:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Carbonite
    2015-07-12 04:56 - 2015-07-12 04:56 - 00004134 _____ C:\WINDOWS\System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}
    2015-07-12 04:56 - 2015-07-12 04:56 - 00002134 _____ C:\Users\Public\Desktop\Carbonite InfoCenter.lnk
    2015-07-12 04:56 - 2015-07-12 04:56 - 00000000 ____D C:\ProgramData\Carbonite
    2015-07-12 04:56 - 2015-07-12 04:56 - 00000000 ____D C:\Program Files\Carbonite
    2015-07-12 04:56 - 2015-07-12 04:56 - 00000000 ____D C:\Program Files (x86)\Carbonite
    2015-07-12 04:44 - 2015-07-12 04:44 - 00000117 _____ C:\WINDOWS\system32\netcfg-91250.txt
    2015-07-12 04:44 - 2015-07-12 04:44 - 00000117 _____ C:\WINDOWS\system32\netcfg-69546.txt
    2015-07-12 04:40 - 2015-07-12 04:40 - 00000000 ____D C:\Users\Rosa\Tracing
    2015-07-12 04:39 - 2015-07-16 07:57 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\Skype
    2015-07-12 04:39 - 2015-07-12 14:30 - 00002713 _____ C:\Users\Public\Desktop\Skype.lnk
    2015-07-12 04:39 - 2015-07-12 14:30 - 00000000 ____D C:\ProgramData\Skype
    2015-07-12 04:39 - 2015-07-12 14:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2015-07-12 04:39 - 2015-07-12 04:45 - 00000000 ___RD C:\Program Files (x86)\Skype
    2015-07-12 04:39 - 2015-07-12 04:39 - 00000000 ____D C:\Users\Rosa\AppData\Local\Skype
    2015-07-12 04:38 - 2015-07-12 04:38 - 01384576 _____ (Skype Technologies S.A.) C:\Users\Rosa\Downloads\SkypeSetup.exe
    2015-07-12 04:35 - 2015-07-12 04:35 - 00003542 _____ C:\WINDOWS\System32\Tasks\ASUS Touchpad Launcher (x64)
    2015-07-12 04:22 - 2015-07-16 07:55 - 00000912 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2015-07-12 04:22 - 2015-07-16 07:39 - 00000916 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2015-07-12 04:22 - 2015-07-15 13:34 - 00003888 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
     
  11. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    2015-07-12 04:22 - 2015-07-15 13:34 - 00003652 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-07-12 04:22 - 2015-07-14 07:34 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2015-07-12 04:22 - 2015-07-12 10:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-07-12 04:22 - 2015-07-12 04:22 - 00000000 ____D C:\Program Files (x86)\Google
    2015-07-12 04:21 - 2015-07-12 04:22 - 00000000 ____D C:\Users\Rosa\AppData\Local\Google
    2015-07-12 04:21 - 2015-07-12 04:21 - 00001058 _____ C:\WINDOWS\system32\netcfg-1285562.txt
    2015-07-12 04:21 - 2015-07-12 04:21 - 00001057 _____ C:\WINDOWS\system32\netcfg-1268468.txt
    2015-07-12 04:21 - 2015-07-12 04:21 - 00000000 ____D C:\Users\Rosa\AppData\Local\Apps\2.0
    2015-07-12 04:14 - 2015-07-16 07:35 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-526706507-2563106057-1816975683-1001
    2015-07-12 04:13 - 2015-07-12 12:56 - 00000000 ____D C:\Program Files (x86)\Cisco
    2015-07-12 04:13 - 2015-07-12 10:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
    2015-07-12 04:13 - 2015-07-12 04:13 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\Macromedia
    2015-07-12 04:12 - 2015-07-12 04:20 - 00000000 ____D C:\ProgramData\Package Cache
    2015-07-12 04:12 - 2015-07-12 04:12 - 00000347 _____ C:\WINDOWS\system32\netcfg-746171.txt
    2015-07-12 04:12 - 2015-07-12 04:12 - 00000117 _____ C:\WINDOWS\system32\netcfg-743218.txt
    2015-07-12 04:07 - 2015-07-16 07:55 - 00000352 _____ C:\Users\Rosa\AppData\Roaming\sp_data.sys
    2015-07-12 04:07 - 2015-07-16 06:29 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
    2015-07-12 04:06 - 2015-07-15 19:51 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\Adobe
    2015-07-12 04:06 - 2015-07-12 04:06 - 00000188 _____ C:\WINDOWS\FixPatch.log
    2015-07-12 04:05 - 2015-07-13 05:03 - 00000000 ____D C:\Users\Rosa\AppData\Local\Packages
    2015-07-12 04:05 - 2015-07-12 09:51 - 01815256 _____ C:\WINDOWS\WindowsUpdate (1).log
    2015-07-12 04:05 - 2015-07-12 04:06 - 00000000 ____D C:\Users\Rosa\AppData\Local\ASUS
    2015-07-12 04:05 - 2015-07-12 04:05 - 00000000 ____D C:\Users\Rosa\AppData\Roaming\Intel
    2015-07-12 04:05 - 2015-07-12 04:05 - 00000000 ____D C:\Users\Rosa\AppData\Local\VirtualStore
    2015-07-12 04:05 - 2015-07-12 04:05 - 00000000 ____D C:\ProgramData\USBChargerPlus
    2015-07-12 04:04 - 2015-07-12 04:04 - 00000117 _____ C:\WINDOWS\system32\netcfg-270265.txt
    2015-07-12 04:04 - 2015-07-12 04:04 - 00000117 _____ C:\WINDOWS\system32\netcfg-262046.txt
    2015-07-11 11:51 - 2015-07-14 11:43 - 00000200 _____ C:\Users\sdcfalcon\Desktop\password.txt
    2015-07-11 11:51 - 2015-07-11 11:51 - 00000000 _____ C:\Users\Rosa_2\Desktop\password.txt
    2015-07-11 11:51 - 2015-07-11 11:51 - 00000000 _____ C:\Users\Rosa\Desktop\password.txt
    2015-07-11 08:50 - 2015-07-11 08:50 - 00000346 _____ C:\Users\Rosa_2\Desktop\SDC Workbench.appref-ms
    2015-07-10 20:50 - 2015-07-10 20:50 - 00000287 _____ C:\Users\Rosa\Desktop\Restrictions.txt
    2015-07-10 10:54 - 2015-07-10 10:54 - 00010081 _____ C:\Users\Rosa_2\Desktop\cathy1.txt
    2015-07-10 10:40 - 2015-07-10 10:40 - 00000000 _____ C:\Users\Rosa_2\Desktop\New Text Document (3).txt
    2015-07-07 17:01 - 2015-07-07 17:01 - 43982848 _____ C:\Users\Rosa_2\Downloads\HipChat-2.2.1388-win32.msi
    2015-07-06 03:53 - 2015-07-06 03:53 - 00023654 _____ C:\Users\Rosa_2\Desktop\marsangst0706.txt
    2015-07-01 01:28 - 2015-07-01 01:28 - 00004648 _____ C:\Users\Rosa_2\Desktop\solus.txt
    2015-06-30 14:08 - 2015-06-30 14:08 - 05174751 _____ C:\Users\Rosa_2\Downloads\Dons XH Pro Tips n Docs.zip
    2015-06-30 14:08 - 2015-05-15 11:39 - 00030208 _____ C:\Users\Rosa_2\Desktop\Transfer Matrix.xls
    2015-06-29 12:13 - 2015-06-29 12:13 - 00012626 _____ C:\Users\Rosa_2\Desktop\SDC CX notes Template.xlsx
    2015-06-28 12:56 - 2015-06-28 12:56 - 00000302 _____ C:\Users\Rosa_2\Desktop\list.txt
    2015-06-25 19:07 - 2015-06-25 19:07 - 00012059 _____ C:\Users\Rosa_2\Desktop\dontbestupidlesson.txt
    2015-06-23 12:20 - 2015-06-23 12:20 - 00002690 _____ C:\Users\Rosa_2\Desktop\script.txt
    2015-06-21 21:50 - 2015-06-21 21:50 - 00015484 _____ C:\Users\Rosa_2\Desktop\alibeingacunt.txt
    2015-06-20 22:50 - 2015-07-11 09:06 - 00000214 _____ C:\Users\Rosa_2\Desktop\Visit MediaHuman Website.url
    2015-06-15 14:58 - 2015-06-15 14:58 - 02846272 _____ C:\Users\Rosa_2\Desktop\CO Sensor Remediation - SDC Playbook (6.15.15).pptx
    2015-06-09 21:06 - 2015-06-09 21:06 - 00032128 _____ (support.com, Inc) C:\WINDOWS\system32\ssmirrdr.dll
    2015-06-09 21:06 - 2015-06-09 21:06 - 00010112 _____ (support.com, Inc) C:\WINDOWS\system32\Drivers\ssmirrdr.sys
    2015-05-28 14:11 - 2015-05-28 14:11 - 01558166 _____ C:\Users\Rosa_2\Desktop\CO Sensor Remediation - SDC Playbook (5.27.15).pptx
    2015-05-06 11:46 - 2015-05-06 11:46 - 00005373 _____ C:\Users\Rosa_2\Desktop\Res.txt

    ==================== Three Months Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-07-16 07:54 - 2013-08-22 07:46 - 00295015 _____ C:\WINDOWS\setupact.log
    2015-07-16 07:54 - 2013-08-22 07:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2015-07-16 07:53 - 2014-11-21 01:34 - 00005396 _____ C:\WINDOWS\PFRO.log
    2015-07-16 07:53 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\MediaViewer
    2015-07-16 07:53 - 2013-08-22 06:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
    2015-07-16 07:00 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\sru
    2015-07-16 06:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\AppReadiness
    2015-07-16 05:30 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
    2015-07-16 02:22 - 2012-07-26 00:59 - 00000000 ____D C:\WINDOWS\CbsTemp
    2015-07-15 18:56 - 2013-08-22 07:44 - 04958944 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2015-07-15 18:52 - 2013-08-22 08:36 - 00000000 ___RD C:\WINDOWS\ToastData
    2015-07-15 18:52 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\WinStore
    2015-07-14 02:12 - 2012-08-21 22:06 - 00000000 ____D C:\Program Files (x86)\Adobe
    2015-07-14 02:00 - 2012-08-21 22:06 - 00000000 ____D C:\ProgramData\Adobe
    2015-07-13 14:22 - 2012-08-21 22:06 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
    2015-07-13 14:10 - 2014-11-21 09:03 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2015-07-13 14:10 - 2014-11-21 09:03 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2015-07-13 08:07 - 2014-11-21 01:44 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2015-07-13 01:13 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\AppCompat
    2015-07-12 12:22 - 2014-11-21 08:56 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
    2015-07-12 12:09 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-RS
    2015-07-12 12:09 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-CS
    2015-07-12 11:21 - 2013-08-22 08:36 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
    2015-07-12 11:20 - 2013-08-22 08:36 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2015-07-12 11:19 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
    2015-07-12 11:19 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\setup
    2015-07-12 11:16 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
    2015-07-12 11:12 - 2014-11-21 01:39 - 02473472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2015-07-12 11:12 - 2013-08-22 08:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2015-07-12 11:12 - 2013-08-22 08:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    2015-07-12 11:12 - 2013-08-22 08:36 - 00000000 ____D C:\Program Files\Windows Defender
    2015-07-12 11:12 - 2013-08-22 08:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
    2015-07-12 11:08 - 2013-08-22 08:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
    2015-07-12 11:04 - 2014-11-21 01:25 - 00000000 ____D C:\Program Files\Windows Journal
    2015-07-12 11:03 - 2013-08-22 07:46 - 00000262 _____ C:\WINDOWS\setuperr.log
    2015-07-12 11:02 - 2013-08-22 06:36 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
    2015-07-12 10:56 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\restore
    2015-07-12 10:49 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\rescache
    2015-07-12 10:47 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\Registration
    2015-07-12 10:47 - 2013-08-22 06:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
    2015-07-12 10:43 - 2013-08-22 08:36 - 00000000 __RSD C:\WINDOWS\Media
    2015-07-12 10:42 - 2013-08-22 08:36 - 00000000 __RHD C:\Users\Public\Libraries
    2015-07-12 10:37 - 2014-11-21 01:00 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
    2015-07-12 10:37 - 2014-11-21 01:00 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
    2015-07-12 10:37 - 2014-11-21 01:00 - 00000000 ____D C:\WINDOWS\system32\WCN
    2015-07-12 10:37 - 2013-08-22 08:37 - 00005217 _____ C:\WINDOWS\DtcInstall.log
    2015-07-12 10:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
    2015-07-12 10:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
    2015-07-12 10:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
    2015-07-12 10:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\spool
    2015-07-12 10:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\MUI
    2015-07-12 10:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\IME
    2015-07-12 10:37 - 2013-08-22 06:36 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
    2015-07-12 10:37 - 2013-08-22 06:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2015-07-12 10:37 - 2013-08-22 06:36 - 00000000 ____D C:\WINDOWS\system32\oobe
    2015-07-12 10:37 - 2012-12-12 17:14 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
    2015-07-12 10:37 - 2012-08-21 22:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
    2015-07-12 10:37 - 2012-07-25 22:37 - 00000000 ____D C:\Users\Default.migrated
    2015-07-12 10:36 - 2013-08-22 08:43 - 00000000 ____D C:\WINDOWS\DigitalLocker
    2015-07-12 10:36 - 2013-08-22 08:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
    2015-07-12 10:36 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\Help
    2015-07-12 10:36 - 2012-12-12 17:22 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUSDVD
    2015-07-12 10:36 - 2012-12-12 17:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Corporation
    2015-07-12 10:36 - 2012-08-01 18:24 - 00000000 ____D C:\ProgramData\PRICache
    2015-07-12 10:35 - 2013-08-22 08:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
    2015-07-12 10:35 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\Recovery
    2015-07-12 10:35 - 2013-08-22 08:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2015-07-12 10:23 - 2013-08-22 06:36 - 00000000 __RHD C:\Users\Default
    2015-07-12 09:20 - 2012-07-26 01:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
    2015-07-12 04:35 - 2012-12-12 17:14 - 00016862 _____ C:\WINDOWS\DPINST.LOG
    2015-07-12 04:35 - 2012-08-21 22:06 - 00000000 ____D C:\Program Files (x86)\ASUS
    2015-07-12 04:33 - 2012-12-12 17:05 - 00000000 ____D C:\Intel
    2015-07-12 04:21 - 2012-12-12 17:08 - 00000000 ____D C:\Program Files\Intel
    2015-07-12 04:14 - 2012-12-12 17:08 - 00000000 ____D C:\ProgramData\Intel
    2015-07-12 04:13 - 2012-12-12 17:16 - 00000000 ____D C:\ProgramData\Intel.sav
    2015-07-12 04:13 - 2012-12-12 17:11 - 00000000 ____D C:\Program Files\Common Files\Intel
    2015-07-12 04:06 - 2012-08-21 22:06 - 02258198 _____ C:\WINDOWS\AsDebug.log
    2015-07-12 04:06 - 2012-08-21 22:06 - 00280654 _____ C:\WINDOWS\AsCDProc.log
    2015-07-12 04:06 - 2012-08-21 22:05 - 00001836 _____ C:\WINDOWS\PQArecord.log
    2015-07-12 04:06 - 2012-08-01 18:36 - 00000000 ____D C:\WINDOWS\Log
    2015-06-21 23:32 - 2014-11-26 14:15 - 00000065 _____ C:\Users\Rosa_2\Desktop\New Text Document.txt

    ==================== Files in the root of some directories =======

    2015-07-14 01:22 - 2015-07-15 22:38 - 0000132 _____ () C:\Users\Rosa\AppData\Roaming\Adobe PNG Format CS6 Prefs
    2015-07-12 04:07 - 2015-07-16 07:55 - 0000352 _____ () C:\Users\Rosa\AppData\Roaming\sp_data.sys
    2012-08-21 22:06 - 2012-07-29 23:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd
    2012-08-21 22:06 - 2009-07-22 03:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe

    Some files in TEMP:
    ====================
    C:\Users\Administrator\AppData\Local\Temp\ShutdownGuardian.dll
    C:\Users\Rosa\AppData\Local\Temp\topazfusion2_setup.exe
    C:\Users\sdcfalcon\AppData\Local\Temp\avaya_Installer.exe
    C:\Users\sdcfalcon\AppData\Local\Temp\ShutdownGuardian.dll
    C:\Users\sdcfalcon\AppData\Local\Temp\ShutdownGuardian228039042299098849.dll
    C:\Users\sdcfalcon\AppData\Local\Temp\vpnInstaller.exe


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

    ==================== BCD ================================

    Firmware Boot Manager
    ---------------------
    identifier {fwbootmgr}
    displayorder {bootmgr}
    {440d3a4f-44bc-11e2-be73-806e6f6e6963}
    {6f43464e-2bc4-11e5-be8b-806e6f6e6963}
    timeout 2

    Windows Boot Manager
    --------------------
    identifier {bootmgr}
    device partition=\Device\HarddiskVolume1
    path \EFI\Microsoft\Boot\bootmgfw.efi
    description Windows Boot Manager
    locale en-US
    inherit {globalsettings}
    integrityservices Enable
    default {current}
    resumeobject {49577042-44c0-11e2-876f-c72642043e43}
    displayorder {current}
    toolsdisplayorder {memdiag}
    timeout 30

    Firmware Application (101fffff)
    -------------------------------
    identifier {440d3a4f-44bc-11e2-be73-806e6f6e6963}
    description CD/DVD Drive

    Firmware Application (101fffff)
    -------------------------------
    identifier {6f43464e-2bc4-11e5-be8b-806e6f6e6963}
    description Network Card

    Windows Boot Loader
    -------------------
    identifier {4957702a-44c0-11e2-876f-c72642043e43}
    device ramdisk=[\Device\HarddiskVolume2]\sources\boot.wim,{ramdiskoptions}
    path \windows\system32\boot\winload.efi
    description WinPE
    osdevice ramdisk=[\Device\HarddiskVolume2]\sources\boot.wim,{ramdiskoptions}
    systemroot \windows
    nx OptIn
    detecthal Yes
    winpe Yes

    Windows Boot Loader
    -------------------
    identifier {4957702b-44c0-11e2-876f-c72642043e43}
    device ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{4957702c-44c0-11e2-876f-c72642043e43}
    path \windows\system32\winload.efi
    description Windows Recovery Environment
    locale en-us
    inherit {bootloadersettings}
    displaymessage Recovery
    displaymessageoverride Recovery
    osdevice ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{4957702c-44c0-11e2-876f-c72642043e43}
    systemroot \windows
    nx OptIn
    bootmenupolicy Standard
    winpe Yes

    Windows Boot Loader
    -------------------
    identifier {49577036-44c0-11e2-876f-c72642043e43}
    device ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{49577037-44c0-11e2-876f-c72642043e43}
    path \windows\system32\winload.efi
    description Windows Recovery Environment
    locale en-US
    inherit {bootloadersettings}
    displaymessage Recovery
    displaymessageoverride Recovery
    osdevice ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{49577037-44c0-11e2-876f-c72642043e43}
    systemroot \windows
    nx OptIn
    bootmenupolicy Standard
    winpe Yes

    Windows Boot Loader
    -------------------
    identifier {4957703f-44c0-11e2-876f-c72642043e43}
    device ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{49577040-44c0-11e2-876f-c72642043e43}
    path \windows\system32\winload.efi
    description Windows Recovery Environment
    locale en-US
    inherit {bootloadersettings}
    displaymessage Recovery
    displaymessageoverride Recovery
    osdevice ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{49577040-44c0-11e2-876f-c72642043e43}
    systemroot \windows
    nx OptIn
    bootmenupolicy Standard
    winpe Yes

    Windows Boot Loader
    -------------------
    identifier {current}
    device partition=C:
    path \WINDOWS\system32\winload.efi
    description Windows 8.1
    locale en-US
    inherit {bootloadersettings}
    recoverysequence {49577044-44c0-11e2-876f-c72642043e43}
    integrityservices Enable
    recoveryenabled Yes
    isolatedcontext Yes
    allowedinmemorysettings 0x15000075
    osdevice partition=C:
    systemroot \WINDOWS
    resumeobject {49577042-44c0-11e2-876f-c72642043e43}
    nx OptIn
    bootmenupolicy Standard

    Windows Boot Loader
    -------------------
    identifier {49577044-44c0-11e2-876f-c72642043e43}
    device ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{49577045-44c0-11e2-876f-c72642043e43}
    path \windows\system32\winload.efi
    description Windows Recovery Environment
    locale en-US
    inherit {bootloadersettings}
    displaymessage Recovery
    displaymessageoverride Recovery
    osdevice ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{49577045-44c0-11e2-876f-c72642043e43}
    systemroot \windows
    nx OptIn
    bootmenupolicy Standard
    winpe Yes

    Resume from Hibernate
    ---------------------
    identifier {49577028-44c0-11e2-876f-c72642043e43}
    device partition=C:
    path \Windows\system32\winresume.efi
    description Windows Resume Application
    locale en-US
    inherit {resumeloadersettings}
    recoverysequence {4957702b-44c0-11e2-876f-c72642043e43}
    recoveryenabled Yes
    isolatedcontext Yes
    allowedinmemorysettings 0x15000075
    filedevice partition=C:
    filepath \hiberfil.sys
    bootmenupolicy Standard
    debugoptionenabled No

    Resume from Hibernate
    ---------------------
    identifier {4957702d-44c0-11e2-876f-c72642043e43}
    device partition=C:
    path \Windows\system32\winresume.efi
    description Windows Resume Application
    locale en-US
    inherit {resumeloadersettings}
    recoverysequence {4957702b-44c0-11e2-876f-c72642043e43}
    recoveryenabled Yes
    isolatedcontext Yes
    allowedinmemorysettings 0x15000075
    filedevice partition=C:
    filepath \hiberfil.sys
    bootmenupolicy Standard
    debugoptionenabled No

    Resume from Hibernate
    ---------------------
    identifier {49577034-44c0-11e2-876f-c72642043e43}
    device partition=C:
    path \WINDOWS\system32\winresume.efi
    description Windows Resume Application
    locale en-US
    inherit {resumeloadersettings}
    recoverysequence {49577036-44c0-11e2-876f-c72642043e43}
    recoveryenabled Yes
    isolatedcontext Yes
    allowedinmemorysettings 0x15000075
    filedevice partition=C:
    filepath \hiberfil.sys
    bootmenupolicy Standard
    debugoptionenabled No

    Resume from Hibernate
    ---------------------
    identifier {4957703d-44c0-11e2-876f-c72642043e43}
    device partition=C:
    path \WINDOWS\system32\winresume.efi
    description Windows Resume Application
    locale en-US
    inherit {resumeloadersettings}
    recoverysequence {4957703f-44c0-11e2-876f-c72642043e43}
    recoveryenabled Yes
    isolatedcontext Yes
    allowedinmemorysettings 0x15000075
    filedevice partition=C:
    filepath \hiberfil.sys
    bootmenupolicy Standard
    debugoptionenabled No

    Resume from Hibernate
    ---------------------
    identifier {49577042-44c0-11e2-876f-c72642043e43}
    device partition=C:
    path \WINDOWS\system32\winresume.efi
    description Windows Resume Application
    locale en-US
    inherit {resumeloadersettings}
    recoverysequence {49577044-44c0-11e2-876f-c72642043e43}
    recoveryenabled Yes
    isolatedcontext Yes
    allowedinmemorysettings 0x15000075
    filedevice partition=C:
    filepath \hiberfil.sys
    bootmenupolicy Standard
    debugoptionenabled No

    Windows Memory Tester
    ---------------------
    identifier {memdiag}
    device partition=\Device\HarddiskVolume1
    path \EFI\Microsoft\Boot\memtest.efi
    description Windows Memory Diagnostic
    locale en-US
    inherit {globalsettings}
    badmemoryaccess Yes

    EMS Settings
    ------------
    identifier {emssettings}
    bootems No

    Debugger Settings
    -----------------
    identifier {dbgsettings}
    debugtype Serial
    debugport 1
    baudrate 115200

    RAM Defects
    -----------
    identifier {badmemory}

    Global Settings
    ---------------
    identifier {globalsettings}
    inherit {dbgsettings}
    {emssettings}
    {badmemory}

    Boot Loader Settings
    --------------------
    identifier {bootloadersettings}
    inherit {globalsettings}
    {hypervisorsettings}

    Hypervisor Settings
    -------------------
    identifier {hypervisorsettings}
    hypervisordebugtype Serial
    hypervisordebugport 1
    hypervisorbaudrate 115200

    Resume Loader Settings
    ----------------------
    identifier {resumeloadersettings}
    inherit {globalsettings}

    Device options
    --------------
    identifier {4957702c-44c0-11e2-876f-c72642043e43}
    description Windows Recovery
    ramdisksdidevice partition=\Device\HarddiskVolume2
    ramdisksdipath \Recovery\WindowsRE\boot.sdi

    Device options
    --------------
    identifier {4957702f-44c0-11e2-876f-c72642043e43}
    description Windows Setup
    ramdisksdidevice partition=C:
    ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi

    Device options
    --------------
    identifier {49577037-44c0-11e2-876f-c72642043e43}
    description Windows Recovery
    ramdisksdidevice partition=\Device\HarddiskVolume2
    ramdisksdipath \Recovery\WindowsRE\boot.sdi

    Device options
    --------------
    identifier {49577038-44c0-11e2-876f-c72642043e43}
    description Windows Setup
    ramdisksdidevice partition=C:
    ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi

    Device options
    --------------
    identifier {49577040-44c0-11e2-876f-c72642043e43}
    description Windows Recovery
    ramdisksdidevice partition=\Device\HarddiskVolume2
    ramdisksdipath \Recovery\WindowsRE\boot.sdi

    Device options
    --------------
    identifier {49577041-44c0-11e2-876f-c72642043e43}
    description Windows Setup
    ramdisksdidevice partition=C:
    ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi

    Device options
    --------------
    identifier {49577045-44c0-11e2-876f-c72642043e43}
    description Windows Recovery
    ramdisksdidevice partition=\Device\HarddiskVolume5
    ramdisksdipath \Recovery\WindowsRE\boot.sdi

    Setup Ramdisk Options
    ---------------------
    identifier {ramdiskoptions}
    description Ramdisk options
    ramdisksdidevice partition=\Device\HarddiskVolume2
    ramdisksdipath \boot\boot.sdi



    LastRegBack: 2015-07-12 10:23

    ==================== End of log ============================
     
  12. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
    Ran by Rosa at 2015-07-16 07:59:54
    Running from C:\Users\Rosa\Downloads
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-526706507-2563106057-1816975683-500 - Administrator - Enabled) => C:\Users\Administrator
    Guest (S-1-5-21-526706507-2563106057-1816975683-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-526706507-2563106057-1816975683-1006 - Limited - Enabled)
    Rosa (S-1-5-21-526706507-2563106057-1816975683-1001 - Administrator - Enabled) => C:\Users\Rosa
    rosaf_000 (S-1-5-21-526706507-2563106057-1816975683-1007 - Administrator - Enabled)
    sdcfalcon (S-1-5-21-526706507-2563106057-1816975683-1004 - Administrator - Enabled) => C:\Users\sdcfalcon

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
    Adobe Reader X (10.1.14) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.14 - Adobe Systems Incorporated)
    ASUS InstantOn (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.1 - ASUS)
    ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.3 - ASUS)
    ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.7 - ASUS)
    ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.0.3 - ASUS)
    ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 1.0.35 - ASUS)
    ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0002 - ASUS)
    ASUS Tutor (HKLM-x32\...\{58172D66-2F69-4215-9AEC-ED8196023736}) (Version: 1.0.7 - ASUS)
    ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.4 - ASUS)
    ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4126.52 - CyberLink Corp.)
    ASUSDVD (x32 Version: 10.0.4126.52 - CyberLink Corp.) Hidden
    AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.10.168 - ASUSTEK)
    ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0022 - ASUS)
    Avaya one-X Agent R2.5 SP1 (HKLM-x32\...\{1135FC2D-B35A-4D4F-90F6-ED63378D2A6E}) (Version: 2.5.1072.11082 - Avaya)
    Carbonite (HKLM-x32\...\Carbonite Backup) (Version: 5.5.5 build 4151 (Jun-27-2014) - Carbonite)
    Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05170 - Cisco Systems, Inc.)
    Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05170 - Cisco Systems, Inc.) Hidden
    Citrix Online Launcher (HKLM-x32\...\{DB014C85-A264-4BCA-A66F-6DD1FCF8EC36}) (Version: 1.0.335 - Citrix)
    Extreme NAC Assessment Agent (HKLM-x32\...\{10FDE9CC-2B8D-4DBA-89A5-24A7B08A60AD}) (Version: 1.13.0.0 - Extreme Networks)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
    gpedt.msc 1.0 (HKLM-x32\...\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version: - Richard)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3308 - Intel Corporation)
    Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7854AA22-A2F0-4F29-A2E9-D0C5A2B685E7}) (Version: 2.5.0.0236 - Motorola Solutions, Inc)
    Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
    Intel(R) WiDi (HKLM\...\{EDBA2433-0910-4C72-8C5B-8FEDAE3EF18E}) (Version: 3.5.34.0 - Intel Corporation)
    Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
    Internet Explorer (Enable DEP) (HKLM\...\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version: - )
    Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
    Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
    Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    ONECTI (HKLM-x32\...\{03D32F12-30EC-4707-84BB-1BF146DD04CE}) (Version: 10.2.7 - IntraNext Systems)
    PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
    photoFXlab (HKLM-x32\...\photoFXlab) (Version: 1.2.8 - Topaz Labs)
    Pidgin (HKLM-x32\...\Pidgin) (Version: 2.10.11 - )
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6690 - Realtek Semiconductor Corp.)
    Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.)
    SDCWB_Helper_Service (HKLM-x32\...\{B857AB3E-F772-44FC-A251-13BAB58FD07C}) (Version: 1.0.0 - Support.com)
    Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
    Skype™ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
    Softphone 9 (HKLM-x32\...\{89836BB0-08E1-4397-9116-B3040C8482C8}) (Version: 9.2.20 - IntraNext)
    Topaz Adjust 5 (HKLM-x32\...\Topaz Adjust 5) (Version: 5.1.0 - Topaz Labs, LLC)
    Topaz B&W Effects (HKLM-x32\...\Topaz BW Effects 2) (Version: 2.1.0 - Topaz Labs, LLC)
    Topaz Clarity (HKLM-x32\...\Topaz Clarity) (Version: 1.0.0 - Topaz Labs, LLC)
    Topaz Clean 3 (HKLM-x32\...\Topaz Clean 3) (Version: 3.1.0 - Topaz Labs, LLC)
    Topaz DeJpeg 4 (HKLM-x32\...\Topaz DeJpeg 4) (Version: 4.0.2 - Topaz Labs, LLC)
    Topaz DeNoise 5 (HKLM-x32\...\Topaz DeNoise 5) (Version: 5.1.0 - Topaz Labs, LLC)
    Topaz Detail 3 (HKLM-x32\...\Topaz Detail 3) (Version: 3.2.0 - Topaz Labs, LLC)
    Topaz Fusion Express 2 (HKLM-x32\...\Topaz Fusion Express 2) (Version: 2.1.3 - Topaz Labs, LLC)
    Topaz InFocus (HKLM-x32\...\Topaz InFocus) (Version: 1.0.0 - Topaz Labs, LLC)
    Topaz Lens Effects (HKLM-x32\...\Topaz Lens Effects) (Version: 1.2.0 - Topaz Labs, LLC)
    Topaz ReMask 4 (HKLM-x32\...\Topaz ReMask 4) (Version: 4.0.0 - Topaz Labs, LLC)
    Topaz ReStyle (HKLM-x32\...\Topaz ReStyle) (Version: 1.0.0 - Topaz Labs, LLC)
    Topaz Simplify 4 (HKLM-x32\...\Topaz Simplify 4) (Version: 4.1.1 - Topaz Labs, LLC)
    Topaz Star Effects (HKLM-x32\...\Topaz Star Effects) (Version: 1.1.0 - Topaz Labs, LLC)
    Windows Driver Package - ASUS (ATP) Mouse (10/29/2012 1.0.0.148) (HKLM\...\C01F56FBD9B141017E63E2A1A141E59934D4DC67) (Version: 10/29/2012 1.0.0.148 - ASUS)
    WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS)
    WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Restore Points =========================

    16-07-2015 02:21:58 Windows Update

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-08-22 06:25 - 2015-07-16 04:59 - 00000946 ____A C:\WINDOWS\system32\Drivers\etc\hosts
    23.253.14.141 partnervpn1.support.com
    23.253.14.141 partnervpn2.support.com
    23.253.14.141 partnervpn.support.com
     
  13. 2015/07/16
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {1268EB6D-228C-43BB-8C37-644321DCB826} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-chloeoftreve@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated)
    Task: {53BC251E-4D3A-4D92-993E-6101BDECB9B7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-07-03] (Microsoft Corporation)
    Task: {6A0C9D81-FCA6-4648-872F-78E3AEFEBF17} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-12] (Google Inc.)
    Task: {74259ABE-AD09-43D5-94A1-17F5993C2B8D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-12] (Google Inc.)
    Task: {7C7BAA7A-0EF1-4545-AAB2-34A8ED33A314} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-04] (ASUS)
    Task: {8B820C26-3A09-48E9-8FB4-DDA2FBABB579} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe
    Task: {9716F23A-BD9B-4984-A2AD-4821E285C072} - System32\Tasks\G2MUpdateTask-S-1-5-21-526706507-2563106057-1816975683-1004 => C:\Users\sdcfalcon\AppData\Local\Citrix\GoToMeeting\2759\g2mupdate.exe [2015-07-13] (Citrix Online, a division of Citrix Systems, Inc.)
    Task: {B6593AB6-0A34-4076-BF9C-FD083B11C0AF} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-07-24] (ASUSTek Computer Inc.)
    Task: {C8091CF6-B384-445C-AA13-0CAE014C61DA} - System32\Tasks\G2MUploadTask-S-1-5-21-526706507-2563106057-1816975683-1004 => C:\Users\sdcfalcon\AppData\Local\Citrix\GoToMeeting\2759\g2mupload.exe [2015-07-13] (Citrix Online, a division of Citrix Systems, Inc.)
    Task: {CD1B5128-C1FE-42ED-B66C-68FA8245103F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-06-20] (ASUSTeK Computer Inc.)
    Task: {ED7B6F7A-46A0-4433-AE08-A37386F50E8E} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2012-10-31] (AsusTek)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-526706507-2563106057-1816975683-1004.job => C:\Users\sdcfalcon\AppData\Local\Citrix\GoToMeeting\2759\g2mupdate.exe
    Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-526706507-2563106057-1816975683-1004.job => C:\Users\sdcfalcon\AppData\Local\Citrix\GoToMeeting\2759\g2mupload.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Loaded Modules (Whitelisted) ==============

    2012-08-04 11:34 - 2012-08-04 11:34 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
    2013-10-01 13:02 - 2013-10-01 13:02 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
    2014-06-10 20:34 - 2014-06-10 20:34 - 00063400 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
    2012-06-07 15:12 - 2012-06-07 15:12 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
    2015-07-14 07:33 - 2015-07-13 14:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
    2015-07-14 07:33 - 2015-07-13 14:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll
    2012-12-12 17:08 - 2012-06-24 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\Users\Rosa\OneDrive:ms-properties

    ==================== Safe Mode (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE restricted site: HKU\S-1-5-21-526706507-2563106057-1816975683-1001\...\skype.com -> hxxps://apps.skype.com

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Rosa\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
    DNS Servers: 75.75.75.75 - 75.75.76.76

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [UDP Query User{14BC952A-4D69-41AE-A9F9-71E7375DAA9D}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [TCP Query User{401B872D-35FB-4240-A45B-AE20002B7258}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [{9D08F8B9-DA66-45FE-8592-7744DE5B92F6}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    FirewallRules: [{68BA4E4C-5F7C-4851-8A8A-E64D2AC1EAB7}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
    FirewallRules: [{AA45D685-87A5-465A-BB2D-542681868543}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
    FirewallRules: [{07B3CCE8-17E5-4174-8D4B-E33CED9D0C66}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
    FirewallRules: [TCP Query User{404DEA93-4258-4D5A-806C-E280160EF7A5}C:\program files (x86)\avaya\avaya one-x agent\sparkemulator.exe] => (Allow) C:\program files (x86)\avaya\avaya one-x agent\sparkemulator.exe
    FirewallRules: [UDP Query User{4F877644-2EFD-4169-BEB3-AA9536A40C36}C:\program files (x86)\avaya\avaya one-x agent\sparkemulator.exe] => (Allow) C:\program files (x86)\avaya\avaya one-x agent\sparkemulator.exe
    FirewallRules: [{EF9A1E7F-0F29-41F7-B77B-6D67F52367B8}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    ==================== Faulty Device Manager Devices =============

    Name: USB-IF xHCI USB Host Controller
    Description: USB-IF xHCI USB Host Controller
    Class Guid: {8a2edc79-c759-46f2-88af-9d4efe3b5eee}
    Manufacturer: Intel Corporation
    Service: XHCIPort
    Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
    Resolution: Update the driver

    Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
    Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: Cisco Systems
    Service: vpnva
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action ", and then click "Enable Device ". This starts the Enable Device wizard. Follow the instructions.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (07/16/2015 07:04:18 AM) (Source: NtServicePack) (EventID: 4373) (User: )
    Description: WindowsNot enough storage is available to process this command.

    Error: (07/16/2015 07:02:27 AM) (Source: NtServicePack) (EventID: 4373) (User: )
    Description: WindowsNot enough storage is available to process this command.

    Error: (07/16/2015 07:01:53 AM) (Source: NtServicePack) (EventID: 4373) (User: )
    Description: WindowsNot enough storage is available to process this command.

    Error: (07/16/2015 06:51:43 AM) (Source: MsiInstaller) (EventID: 1018) (User: Rosa)
    Description: The application 'Microsoft Group Policy Management Console with SP1' cannot be installed because it is not compatible with this version of Windows. Contact the application vendor for an update.

    Error: (07/16/2015 06:49:21 AM) (Source: MsiInstaller) (EventID: 1018) (User: Rosa)
    Description: The application 'Microsoft Group Policy Management Console with SP1' cannot be installed because it is not compatible with this version of Windows. Contact the application vendor for an update.

    Error: (07/16/2015 06:36:41 AM) (Source: MsiInstaller) (EventID: 1018) (User: Rosa)
    Description: The application 'Microsoft Group Policy Management Console with SP1' cannot be installed because it is not compatible with this version of Windows. Contact the application vendor for an update.

    Error: (07/16/2015 06:35:58 AM) (Source: MsiInstaller) (EventID: 1018) (User: Rosa)
    Description: The application 'Microsoft Group Policy Management Console with SP1' cannot be installed because it is not compatible with this version of Windows. Contact the application vendor for an update.

    Error: (07/15/2015 08:23:25 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: tlrestyle_x64.exe, version: 0.0.0.0, time stamp: 0x527ad44b
    Faulting module name: tlrestyle_x64.exe, version: 0.0.0.0, time stamp: 0x527ad44b
    Exception code: 0xc0000005
    Fault offset: 0x000000000005ade9
    Faulting process id: 0xd70
    Faulting application start time: 0xtlrestyle_x64.exe0
    Faulting application path: tlrestyle_x64.exe1
    Faulting module path: tlrestyle_x64.exe2
    Report Id: tlrestyle_x64.exe3
    Faulting package full name: tlrestyle_x64.exe4
    Faulting package-relative application ID: tlrestyle_x64.exe5

    Error: (07/15/2015 05:34:35 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program ONECTI.exe version 10.2.12.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 1e30

    Start Time: 01d0bf245bbbc5cf

    Termination Time: 4294967295

    Application Path: C:\Program Files (x86)\IntraNext Systems\ONECTI\ONECTI.exe

    Report Id: 6e38209f-2b52-11e5-be88-685d43aefd93

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (07/15/2015 10:33:19 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program ONECTI.exe version 10.2.12.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 1ee0

    Start Time: 01d0bf242d296dc8

    Termination Time: 4294967295

    Application Path: C:\Program Files (x86)\IntraNext Systems\ONECTI\ONECTI.exe

    Report Id: 94663f8a-2b17-11e5-be88-685d43aefd93

    Faulting package full name:

    Faulting package-relative application ID:


    System errors:
    =============
    Error: (07/16/2015 02:23:09 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: The CarboniteService service terminated with the following error:
    %%2147549183

    Error: (07/16/2015 02:20:30 AM) (Source: DCOM) (EventID: 10010) (User: ROSA)
    Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

    Error: (07/16/2015 02:20:30 AM) (Source: DCOM) (EventID: 10010) (User: ROSA)
    Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

    Error: (07/15/2015 04:43:32 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The CarboniteService service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

    Error: (07/15/2015 04:06:42 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
    Description: Installation Failure: Windows failed to install the following update with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3065988).

    Error: (07/15/2015 04:06:42 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
    Description: Installation Failure: Windows failed to install the following update with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3053863).

    Error: (07/15/2015 04:06:41 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
    Description: Installation Failure: Windows failed to install the following update with error 0x8007045b: Security Update for Windows 8.1 for x64-based Systems (KB3070102).

    Error: (07/15/2015 04:06:41 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
    Description: Installation Failure: Windows failed to install the following update with error 0x8007045b: Security Update for Windows 8.1 for x64-based Systems (KB3067505).

    Error: (07/15/2015 04:06:41 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
    Description: Installation Failure: Windows failed to install the following update with error 0x8007045b: Security Update for Windows 8.1 for x64-based Systems (KB3004365).

    Error: (07/15/2015 04:06:41 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
    Description: Installation Failure: Windows failed to install the following update with error 0x8007045b: Update for Windows 8.1 for x64-based Systems (KB3029438).


    Microsoft Office:
    =========================
    Error: (07/16/2015 07:04:18 AM) (Source: NtServicePack) (EventID: 4373) (User: )
    Description: WindowsNot enough storage is available to process this command.

    Error: (07/16/2015 07:02:27 AM) (Source: NtServicePack) (EventID: 4373) (User: )
    Description: WindowsNot enough storage is available to process this command.

    Error: (07/16/2015 07:01:53 AM) (Source: NtServicePack) (EventID: 4373) (User: )
    Description: WindowsNot enough storage is available to process this command.

    Error: (07/16/2015 06:51:43 AM) (Source: MsiInstaller) (EventID: 1018) (User: Rosa)
    Description: Microsoft Group Policy Management Console with SP1(NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (07/16/2015 06:49:21 AM) (Source: MsiInstaller) (EventID: 1018) (User: Rosa)
    Description: Microsoft Group Policy Management Console with SP1(NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (07/16/2015 06:36:41 AM) (Source: MsiInstaller) (EventID: 1018) (User: Rosa)
    Description: Microsoft Group Policy Management Console with SP1(NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (07/16/2015 06:35:58 AM) (Source: MsiInstaller) (EventID: 1018) (User: Rosa)
    Description: Microsoft Group Policy Management Console with SP1(NULL)(NULL)(NULL)(NULL)(NULL)

    Error: (07/15/2015 08:23:25 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: tlrestyle_x64.exe0.0.0.0527ad44btlrestyle_x64.exe0.0.0.0527ad44bc0000005000000000005ade9d7001d0bf75934a6ec8C:\Program Files\Common Files\Topaz Labs\tlrestyle_x64.exeC:\Program Files\Common Files\Topaz Labs\tlrestyle_x64.exe0456beb7-2b6a-11e5-be89-685d43aefd93

    Error: (07/15/2015 05:34:35 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: ONECTI.exe10.2.12.01e3001d0bf245bbbc5cf4294967295C:\Program Files (x86)\IntraNext Systems\ONECTI\ONECTI.exe6e38209f-2b52-11e5-be88-685d43aefd93

    Error: (07/15/2015 10:33:19 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: ONECTI.exe10.2.12.01ee001d0bf242d296dc84294967295C:\Program Files (x86)\IntraNext Systems\ONECTI\ONECTI.exe94663f8a-2b17-11e5-be88-685d43aefd93


    CodeIntegrity Errors:
    ===================================
    Date: 2015-07-16 06:46:03.736
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:03.572
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:03.291
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:03.128
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:02.814
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:02.648
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:02.232
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:02.062
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:01.785
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2015-07-16 06:46:01.616
    Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz
    Percentage of memory in use: 39%
    Total physical RAM: 6033.75 MB
    Available physical RAM: 3676.3 MB
    Total Virtual: 6993.75 MB
    Available Virtual: 3839.45 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:676.85 GB) (Free:617.36 GB) NTFS ==>[system with boot components (obtained from reading drive)]
    Drive d: (15.0.4433.1508) (CDROM) (Total:2.05 GB) (Free:0 GB) UDF

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 698.6 GB) (Disk ID: CC1AD6D4)

    Partition: GPT Partition Type.

    ==================== End of log ============================
     
  14. 2015/07/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ==============================

    When running FRST please don't check any extra boxes unless I ask you to do so.

    I don't see anything malicious there so...

    See if the fix listed below will take care of your error.

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
     

    Attached Files:

  15. 2015/07/17
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    Fix result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
    Ran by Rosa at 2015-07-17 13:05:38 Run:1
    Running from C:\Users\Rosa\Downloads
    Loaded Profiles: Rosa (Available Profiles: Rosa & sdcfalcon & Administrator)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\...\Run: [AdobeBridge] => [X]
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    2015-07-14 01:22 - 2015-07-15 22:38 - 0000132 _____ () C:\Users\Rosa\AppData\Roaming\Adobe PNG Format CS6 Prefs
    2015-07-12 04:07 - 2015-07-16 07:55 - 0000352 _____ () C:\Users\Rosa\AppData\Roaming\sp_data.sys
    2012-08-21 22:06 - 2012-07-29 23:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd
    2012-08-21 22:06 - 2009-07-22 03:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
    C:\Users\Administrator\AppData\Local\Temp\ShutdownGuardian.dll
    C:\Users\Rosa\AppData\Local\Temp\topazfusion2_setup.exe
    C:\Users\sdcfalcon\AppData\Local\Temp\avaya_Installer.exe
    C:\Users\sdcfalcon\AppData\Local\Temp\ShutdownGuardian.dll
    C:\Users\sdcfalcon\AppData\Local\Temp\ShutdownGuardian228039042299098849.dl l
    C:\Users\sdcfalcon\AppData\Local\Temp\vpnInstaller.exe
    AlternateDataStreams: C:\Users\Rosa\OneDrive:ms-properties

    *****************

    HKU\S-1-5-21-526706507-2563106057-1816975683-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully
    "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
    C:\Users\Rosa\AppData\Roaming\Adobe PNG Format CS6 Prefs => moved successfully.
    C:\Users\Rosa\AppData\Roaming\sp_data.sys => moved successfully.
    C:\ProgramData\SetStretch.cmd => moved successfully.
    C:\ProgramData\SetStretch.exe => moved successfully.
    C:\Users\Administrator\AppData\Local\Temp\ShutdownGuardian.dll => moved successfully.
    C:\Users\Rosa\AppData\Local\Temp\topazfusion2_setup.exe => moved successfully.
    C:\Users\sdcfalcon\AppData\Local\Temp\avaya_Installer.exe => moved successfully.
    C:\Users\sdcfalcon\AppData\Local\Temp\ShutdownGuardian.dll => moved successfully.
    "C:\Users\sdcfalcon\AppData\Local\Temp\ShutdownGuardian228039042299098849.dl l" => File/Folder not found.
    C:\Users\sdcfalcon\AppData\Local\Temp\vpnInstaller.exe => moved successfully.
    C:\Users\Rosa\OneDrive => ":ms-properties" ADS removed successfully.

    ==== End of Fixlog 13:05:39 ====
     
  16. 2015/07/17
    Anguisette

    Anguisette Inactive Thread Starter

    Joined:
    2015/07/16
    Messages:
    14
    Likes Received:
    0
    Its fixed! Thank you!
     
  17. 2015/07/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome [​IMG]
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.