Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2015
Ran by owner (administrator) on OWNER-HP on 11-05-2015 12:09:04
Running from G:\AV Softwares
Loaded Profiles: owner (Available profiles: owner)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(KSIN Luxembourg II Sarl.) C:\Program Files (x86)\VSMSoftware\5DEmbroidery\EmbMachineComms.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
(CLICK YES BELOW LP) C:\Program Files (x86)\Ninja Loader\Ninja Loader.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
() C:\Program Files (x86)\Nova Development\Photo Explosion\Project Studio\ReminderApp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Verizon) C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(Ninja Soft Inc.) C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\AMSP\AMSP_LogServer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Verizon) C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\VzDetectAgent.exe
() C:\Users\owner\AppData\Roaming\58400D07-1431353817-7BC0-1DB7-EC9A74FE1D24\nsh3C7C.tmpfs
() C:\Users\owner\AppData\Roaming\58400D07-1431353817-7BC0-1DB7-EC9A74FE1D24\jnsm6CC5.tmp
(PastaLeads) C:\Program Files\Common Files\PastaLeads\PastaLeads Client\pastaleadss.exe
() C:\Users\owner\AppData\Local\58400D07-1431339683-7BC0-1DB7-EC9A74FE1D24\snso457A.tmp
() C:\Users\owner\AppData\Local\58400D07-1431339682-7BC0-1DB7-EC9A74FE1D24\cnsz6C1F.tmp
(Cinema PlusV11.05) C:\Program Files (x86)\CinemaPlus-3.2cV11.05-ntf\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-10.exe
(Cinema PlusV11.05) C:\Program Files (x86)\CinemaPlus-3.2cV11.05\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-6.exe
(Cinema PlusV11.05) C:\Program Files (x86)\CinemaPlus-3.2cV11.05\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-1-6.exe
() C:\Users\owner\AppData\Local\58400D07-1431339682-7BC0-1DB7-EC9A74FE1D24\ansj518C.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(The Chromium Authors) C:\Users\owner\AppData\Local\Ninja Loader\Discover\Discover.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7466600 2011-09-14] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2832168 2011-10-01] (Synaptics Incorporated)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [44880 2011-12-20] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Trend Micro Titanium] => C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe [1382568 2013-09-16] (Trend Micro Inc.)
HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [216928 2013-08-29] (Trend Micro Inc.)
HKLM\...\Run: [Windesk Winsearch] => C:\Program Files (x86)\WindeskWinsearch\Windesk Winsearch.exe
HKLM\...\Run: [3D BubbleSound] => "C:\Program Files\BubbleSound\3D BubbleSound.exe"
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-08-10] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HPQuickWebProxy] => C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [169528 2011-09-29] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [577408 2012-02-15] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [106496 2014-01-22] (LeapFrog Enterprises, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2688920 2014-05-26] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ReminderApp_EEAC3053-7055-4143-B8A0-306758055099] => C:\Program Files (x86)\Nova Development\Photo Explosion\Project Studio\ReminderApp.exe [145856 2012-10-12] ()
HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [571392 2011-10-30] (Nikon Corporation)
HKLM-x32\...\Run: [ospd_us_1051] => [X]
HKLM-x32\...\Run: [gmsd_us_540] => [X]
HKLM-x32\...\Run: [WinCheck] => C:\Users\owner\AppData\Local\58400D07-1431339524-7BC0-1DB7-EC9A74FE1D24\bnssE8CB.exe [205824 2015-05-10] ()
HKLM-x32\...\RunOnce: [Update] => C:\Users\owner\AppData\Roaming\ASPackage\ASPackage.exe [290143 2015-05-11] ( )
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Run: [EmbMachineComms.exe] => C:\Program Files (x86)\VSMSoftware\5DEmbroidery\EmbMachineComms.exe [91136 2012-12-10] (KSIN Luxembourg II Sarl.)
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Run: [com.apple.dav.bookmarks.daemon] => C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1326408 2013-11-15] (Apple Inc.)
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Run: [GoogleChromeAutoLaunch_9DC6A3FA5A513049C13F56C6619C332A] => "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Run: [NinjaLoader] => C:\Program Files (x86)\Ninja Loader\Ninja Loader.exe [1603176 2015-05-05] (CLICK YES BELOW LP)
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-06] (SUPERAntiSpyware)
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\RunOnce: [Adobe Speed Launcher] => 1431352775
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Policies\Explorer: [NoDesktopCleanupWizard] 1
AppInit_DLLs-x32: c:\progra~3\{962a7~1\1170~1.1\lica.dll => "c:\progra~3\{962a7~1\1170~1.1\lica.dll" File Not Found
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2012-01-08]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2013-03-28]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-05-25]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-05-09]
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{bb91ccda-e84e-76bc-bb91-1ccdae84336b}\hqghumeaylnlf.exe (PC Utilities Software Limited)
Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2012-05-12]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2014-05-23] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2014-05-23] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2014-05-23] ()
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.trovi.com/?gd=&ctid=CT33...61-633F-48AA-8F80-E0CE9432416B&D=051015&SSPV=
HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPNOT/1
URLSearchHook: HKU\S-1-5-21-2551946670-2892123830-3617700209-1001 - (No Name) - {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - No File
SearchScopes: HKLM -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL =
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM -> {F6FC6BD0-AD54-49D5-87F5-95C42D9F4AB7} URL =
http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\.DEFAULT -> {39FCB729-63B0-465E-A4C6-448745C0B582} URL =
http://websearch.ask.com/redirect?c...pn_sauid=6CEA1B72-D86C-4DA5-9840-78D01A1B1223
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2551946670-2892123830-3617700209-1001 -> DefaultScope {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
http://www.trovi.com/Results.aspx?g...0-E0CE9432416B&D=051015&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-2551946670-2892123830-3617700209-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
http://www.trovi.com/Results.aspx?g...0-E0CE9432416B&D=051015&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-2551946670-2892123830-3617700209-1001 -> {734F50C9-6392-43A4-851D-8C30C9E52824} URL =
http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2551946670-2892123830-3617700209-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-3...://www.ebay.com/sch/i.html?_nkw={searchTerms}
BHO: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> C:\Program Files\Trend Micro\AMSP\Module\20004\2.5.1331\6.8.1094\TmIEPlg.dll [2012-05-08] (Trend Micro Inc.)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-10] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05] (Google Inc.)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2012-08-13] (Skype Technologies S.A.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1137\7.5.1137\TmBpIe64.dll [2013-08-20] (Trend Micro Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: TmIEPlugInBHO Class -> {1CA1377B-DC1D-4A52-9585-6E06050FAC53} -> C:\Program Files\Trend Micro\AMSP\Module\20004\2.5.1331\6.8.1094\TmIEPlg32.dll [2012-05-08] (Trend Micro Inc.)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-03-04] (Microsoft Corporation)
BHO-x32: TSToolbarBHO -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2013-09-16] (Trend Micro Inc.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05] (Google Inc.)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-08-13] (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO-x32: TmBpIeBHO Class -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1137\7.5.1137\TmBpIe32.dll [2013-08-20] (Trend Micro Inc.)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05] (Google Inc.)
Toolbar: HKLM-x32 - Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2013-09-16] (Trend Micro Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05] (Google Inc.)
Toolbar: HKU\.DEFAULT -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Handler: crawler - {4545C96B-15D0-4E22-8DDE-6F2CAF531281} - No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2012-08-13] (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-08-13] (Skype Technologies S.A.)
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1137\7.5.1137\TmBpIe64.dll [2013-08-20] (Trend Micro Inc.)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1137\7.5.1137\TmBpIe32.dll [2013-08-20] (Trend Micro Inc.)
Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\2.5.1331\6.8.1094\TmIEPlg.dll [2012-05-08] (Trend Micro Inc.)
Handler-x32: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\2.5.1331\6.8.1094\TmIEPlg32.dll [2012-05-08] (Trend Micro Inc.)
Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2013-09-16] (Trend Micro Inc.)
Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll [2013-09-16] (Trend Micro Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2014-05-26] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-02-17] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-12-06] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-05-11] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-05-11] (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @TrendMicro.com/FFExtension -> C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll [2012-10-19] (Trend Micro Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-07] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2014-05-26] (Adobe Systems)
FF HKLM\...\Firefox\Extensions: [
tmbepff-7.5@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1137\7.5.1137\firefoxextension
FF Extension: Trend Micro BEP Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1137\7.5.1137\firefoxextension [2013-10-12]
FF HKLM-x32\...\Firefox\Extensions: [
tmbepff-7.5@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\Module\20002\7.5.1137\7.5.1137\firefoxextension
FF HKLM-x32\...\Firefox\Extensions: [{22181a4d-af90-4ca3-a569-faed9118d6bc}] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension
FF Extension: Trend Micro Toolbar - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2013-01-04]
FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension
FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\module\20004\FxExt\firefoxextension [2013-10-12]
FF HKLM-x32\...\Firefox\Extensions: [
smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-03-28]
FF HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Firefox\Extensions: [
smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\...\Firefox\Extensions: [
ninjaloader@mail.com] - C:\Program Files (x86)\Ninja Loader\FireFox
FF Extension: NinjaLoader - C:\Program Files (x86)\Ninja Loader\FireFox [2015-05-10]
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.trovi.com/?gd=&ctid=CT3321542&octid=EB_ORIGINAL_CTID&ISID=MF632D241-211E-4C25-BBF4-6E4F8C80E644&SearchSource=55&CUI=&UM=8&UP=SPA0115161-633F-48AA-8F80-E0CE9432416B&D=051015&SSPV=
CHR StartupUrls: Default -> "hxxp://
www.trovi.com/?gd=&ctid=CT3321542&octid=EB_ORIGINAL_CTID&ISID=MF632D241-211E-4C25-BBF4-6E4F8C80E644&SearchSource=55&CUI=&UM=8&UP=SPA0115161-633F-48AA-8F80-E0CE9432416B&D=051015&SSPV="
CHR DefaultSearchKeyword: Default -> trovi.search
CHR DefaultSearchURL: Default ->
http://www.trovi.com/Results.aspx?g...0-E0CE9432416B&D=051015&q={searchTerms}&SSPV=
CHR DefaultSuggestURL: Default ->
http://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}
CHR Profile: C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-11]
CHR Extension: (Google Docs) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-11]
CHR Extension: (Google Drive) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-11]
CHR Extension: (YouTube) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-11]
CHR Extension: (NinjaLoader) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmlhbjpgeogifjnmlajdaealbdlfonah [2015-05-11]
CHR Extension: (Google Search) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-11]
CHR Extension: (Google Sheets) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-11]
CHR Extension: (TrendMicro Toolbar) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\heoldelcflnigdllmlopiefhkkobendj [2013-01-14]
CHR Extension: (dregol New Tab) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihokndmjeombjojnfkmapfnjeghjohim [2015-05-11]
CHR Extension: (Skype Click to Call) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-05-11]
CHR Extension: (Mountain Bike) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\loohbpdfmfgkffdhmknkfinigkmhobij [2015-05-11]
CHR Extension: (Google Wallet) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-11]
CHR Extension: (CinemaPlus-3.2cV11.05) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\papbadoldddalgcjcicnikcfenodpghp [2015-05-11]
CHR Extension: (Gmail) - C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-11]
CHR HKLM\...\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] -
https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2551946670-2892123830-3617700209-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] -
https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cmlhbjpgeogifjnmlajdaealbdlfonah] -
https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [heoldelcflnigdllmlopiefhkkobendj] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\chromeextension\chromeextension.crx [2013-01-04]
CHR HKLM-x32\...\Chrome\Extension: [ihokndmjeombjojnfkmapfnjeghjohim] -
https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-08-13]
Opera:
=======
OPR Extension: (Metal Maker) - C:\Users\owner\AppData\Roaming\Opera Software\Opera Stable\Extensions\lhnjflnlgdbbmphgmegdgbbljkjlaooe [2015-05-09]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [144152 2013-10-10] (SUPERAntiSpyware.com)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-07-05] (Advanced Micro Devices, Inc.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2719928 2015-04-22] (Microsoft Corporation)
R2 feditemy; C:\Users\owner\AppData\Local\58400D07-1431339683-7BC0-1DB7-EC9A74FE1D24\snso457A.tmp [244736 2015-05-11] () [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-05-11] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-05-11] (globalUpdate) [File not signed] <==== ATTENTION
R2 hasplms; C:\Windows\system32\hasplms.exe [4683144 2014-05-30] (SafeNet Inc.)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1817088 2010-12-27] (Realsil Microelectronics Inc.) [File not signed]
R2 IHA_MessageCenter; C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe [352248 2012-08-03] (Verizon) [File not signed]
R2 LeapFrog Connect Device Service; C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe [7393280 2014-01-22] (LeapFrog Enterprises, Inc.) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NinjaLoaderService; C:\Program Files (x86)\Ninja Loader\NinjaMaintainer.exe [59496 2015-05-01] (Ninja Soft Inc.)
R2 nugilevu; C:\Users\owner\AppData\Roaming\58400D07-1431353817-7BC0-1DB7-EC9A74FE1D24\jnsm6CC5.tmp [462336 2015-05-11] () [File not signed]
R2 pastaleadsupd; C:\Program Files\Common Files\PastaLeads\PastaLeads Client\pastaleadss.exe [1088000 2015-05-03] (PastaLeads) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 visubyzy; C:\Users\owner\AppData\Local\58400D07-1431339682-7BC0-1DB7-EC9A74FE1D24\cnsz6C1F.tmp [267264 2015-05-11] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad [X]
R2 pujodigi; C:\Users\owner\AppData\Roaming\58400D07-1431353817-7BC0-1DB7-EC9A74FE1D24\nsh3C7C.tmpfs [X]
S2 Update Metal Maker; "C:\Program Files (x86)\Metal Maker\updateMetalMaker.exe" [X]
S2 Util Metal Maker; "C:\Program Files (x86)\Metal Maker\bin\utilMetalMaker.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 akshasp; C:\Windows\System32\DRIVERS\akshasp.sys [60488 2014-05-30] (SafeNet Inc.)
S3 akshhl; C:\Windows\System32\DRIVERS\akshhl.sys [63944 2014-05-30] (SafeNet Inc.)
S3 aksusb; C:\Windows\System32\DRIVERS\aksusb.sys [303624 2014-05-30] (SafeNet Inc.)
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [133672 2011-09-20] (Broadcom Corporation.)
S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-09-20] (Broadcom Corporation.)
R2 hardlock; C:\Windows\system32\drivers\hardlock.sys [331608 2014-05-30] (SafeNet Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 MWAC; \??\C:\Windows\system32\drivers\ [0 ] () <==== ATTENTION (zero size file/folder)
S3 MWAC; \??\C:\Windows\SysWOW64\drivers\ [0 ] () <==== ATTENTION (zero size file/folder)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2012-03-26] (Apple Inc.) [File not signed]
R1 PastaLUpdd; C:\Program Files\Common Files\PastaLeads\PastaLeads Client\pastaldrw.sys [61904 2015-05-03] ()
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [109072 2013-09-04] (Trend Micro Inc.)
R0 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [175528 2013-09-04] (Trend Micro Inc.)
R0 TMEBC; C:\Windows\System32\DRIVERS\TMEBC64.sys [46392 2012-08-23] (Trend Micro Inc.)
R1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [77184 2013-09-04] (Trend Micro Inc.)
R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105744 2012-05-02] (Trend Micro Inc.)
S3 VsmRWDriver; C:\Windows\System32\DRIVERS\VsmRWDriver.sys [14848 2008-03-27] (VSM Group AB)
S1 innfd_1_10_0_14; system32\drivers\innfd_1_10_0_14.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-11 12:09 - 2015-05-11 12:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon
2015-05-11 12:02 - 2015-05-11 12:09 - 00000000 ____D () C:\FRST
2015-05-11 10:29 - 2015-05-11 10:29 - 00000000 ____D () C:\ProgramData\f4e5e34b00006462
2015-05-11 10:23 - 2015-05-11 11:23 - 00005518 _____ () C:\Windows\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-6.job
2015-05-11 10:23 - 2015-05-11 11:23 - 00003138 _____ () C:\Windows\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-1-6.job
2015-05-11 10:23 - 2015-05-11 10:23 - 00008546 _____ () C:\Windows\System32\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-6
2015-05-11 10:23 - 2015-05-11 10:23 - 00008212 _____ () C:\Windows\System32\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-7
2015-05-11 10:23 - 2015-05-11 10:23 - 00006504 _____ () C:\Windows\System32\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-1-7
2015-05-11 10:23 - 2015-05-11 10:23 - 00006166 _____ () C:\Windows\System32\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-1-6
2015-05-11 10:23 - 2015-05-11 10:23 - 00005476 _____ () C:\Windows\System32\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-5
2015-05-11 10:23 - 2015-05-11 10:23 - 00005182 _____ () C:\Windows\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-7.job
2015-05-11 10:23 - 2015-05-11 10:23 - 00004022 _____ () C:\Windows\System32\Tasks\x5LzB43qifbi
2015-05-11 10:23 - 2015-05-11 10:23 - 00003474 _____ () C:\Windows\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-1-7.job
2015-05-11 10:23 - 2015-05-11 10:23 - 00002446 _____ () C:\Windows\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-5_user.job
2015-05-11 10:23 - 2015-05-11 10:23 - 00002446 _____ () C:\Windows\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-5.job
2015-05-11 10:23 - 2015-05-11 10:23 - 00000996 _____ () C:\Windows\Tasks\x5LzB43qifbi.job
2015-05-11 10:23 - 2015-05-11 10:23 - 00000000 ____D () C:\Program Files (x86)\45a7be37-7bc7-46b8-866b-bdede0fd8361
2015-05-11 10:22 - 2015-05-11 11:22 - 00002120 _____ () C:\Windows\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-10_user.job
2015-05-11 10:22 - 2015-05-11 10:27 - 00000974 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-05-11 10:22 - 2015-05-11 10:27 - 00000970 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-05-11 10:22 - 2015-05-11 10:23 - 00000000 ____D () C:\Program Files (x86)\CinemaPlus-3.2cV11.05
2015-05-11 10:22 - 2015-05-11 10:22 - 00007524 _____ () C:\Windows\System32\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-3
2015-05-11 10:22 - 2015-05-11 10:22 - 00004494 _____ () C:\Windows\Tasks\0d1753ef-7f8e-48e2-96ee-31d9794d6b70-3.job
2015-05-11 10:22 - 2015-05-11 10:22 - 00003972 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-05-11 10:22 - 2015-05-11 10:22 - 00003718 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-05-11 10:22 - 2015-05-11 10:22 - 00000000 ____D () C:\Users\owner\AppData\Local\globalUpdate
2015-05-11 10:22 - 2015-05-11 10:22 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-05-11 10:22 - 2015-05-11 10:22 - 00000000 ____D () C:\Program Files (x86)\CinemaPlus-3.2cV11.05-ntf
2015-05-11 10:21 - 2015-05-11 10:26 - 00000000 ____D () C:\Users\owner\AppData\Local\58400D07-1431339683-7BC0-1DB7-EC9A74FE1D24
2015-05-11 10:21 - 2015-05-11 10:21 - 00000000 ____D () C:\Users\owner\AppData\Local\58400D07-1431339682-7BC0-1DB7-EC9A74FE1D24
2015-05-11 10:20 - 2015-05-11 10:20 - 00000000 ____D () C:\Users\owner\Documents\Optimizer Pro
2015-05-11 10:20 - 2015-05-11 10:20 - 00000000 ____D () C:\ProgramData\PastaLeadsAgent
2015-05-11 10:20 - 2015-05-11 10:20 - 00000000 ____D () C:\Program Files\Common Files\PastaLeads
2015-05-11 10:18 - 2015-05-11 10:19 - 00000000 ____D () C:\Users\owner\AppData\Local\58400D07-1431339524-7BC0-1DB7-EC9A74FE1D24
2015-05-11 10:18 - 2015-05-11 10:18 - 00000000 ____D () C:\ProgramData\{bb91ccda-e84e-76bc-bb91-1ccdae84336b}
2015-05-11 10:17 - 2015-05-11 10:17 - 00000000 ____D () C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
2015-05-11 10:16 - 2015-05-11 10:17 - 00000000 ____D () C:\Users\owner\AppData\Roaming\ASPackage
2015-05-11 10:16 - 2015-05-11 10:17 - 00000000 ____D () C:\Users\owner\AppData\Roaming\58400D07-1431353817-7BC0-1DB7-EC9A74FE1D24
2015-05-11 09:33 - 2015-05-11 09:58 - 00000112 _____ () C:\Windows\setupact.log
2015-05-11 09:33 - 2015-05-11 09:33 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-11 09:32 - 2015-05-11 09:57 - 00001680 _____ () C:\Windows\PFRO.log
2015-05-11 09:20 - 2015-05-11 09:20 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-05-11 09:20 - 2015-05-11 09:20 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-05-11 09:20 - 2015-05-11 09:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-05-11 09:20 - 2015-05-11 09:20 - 00000000 ____D () C:\Program Files\CCleaner
2015-05-11 09:13 - 2015-05-11 09:13 - 00004479 _____ () C:\Users\owner\Desktop\JRT.txt
2015-05-11 08:45 - 2015-05-11 08:45 - 00000000 ____D () C:\Windows\ERUNT
2015-05-11 08:17 - 2015-05-11 08:26 - 00000000 ____D () C:\AdwCleaner
2015-05-11 06:44 - 2015-05-11 06:44 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-11 06:44 - 2015-05-11 06:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-11 06:42 - 2015-05-11 07:11 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 339b991e-1e56-4030-9493-a3e34e1926f8.job
2015-05-11 06:42 - 2015-05-11 07:11 - 00000510 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 066ed6d8-cf08-40e0-b646-b26c90408070.job
2015-05-11 06:42 - 2015-05-11 06:42 - 00003588 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 339b991e-1e56-4030-9493-a3e34e1926f8
2015-05-11 06:42 - 2015-05-11 06:42 - 00003514 _____ () C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 066ed6d8-cf08-40e0-b646-b26c90408070
2015-05-11 06:42 - 2015-05-11 06:42 - 00001808 _____ () C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2015-05-11 06:42 - 2015-05-11 06:42 - 00000000 ____D () C:\Users\owner\AppData\Roaming\SUPERAntiSpyware.com
2015-05-11 06:42 - 2015-05-11 06:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2015-05-11 06:41 - 2015-05-11 06:42 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2015-05-11 06:41 - 2015-05-11 06:41 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2015-05-11 06:29 - 2015-05-11 06:29 - 00000000 ____D () C:\TDSSKiller_Quarantine
2015-05-11 03:37 - 2015-05-11 03:37 - 00829488 _____ () C:\Users\owner\Downloads\Unconfirmed 269845.crdownload
2015-05-11 02:19 - 2015-05-11 02:19 - 00829512 _____ () C:\Users\owner\Downloads\Unconfirmed 273966.crdownload
2015-05-10 22:52 - 2015-05-10 22:53 - 32167704 _____ (VideoLan ) C:\Users\owner\Downloads\Unconfirmed 690113.crdownload
2015-05-10 22:11 - 2015-05-10 22:11 - 00829696 _____ () C:\Users\owner\Downloads\Unconfirmed 647726.crdownload
2015-05-10 18:21 - 2015-05-10 18:23 - 00000000 ____D () C:\Users\owner\AppData\Local\Ninja Loader
2015-05-10 18:21 - 2015-05-10 18:21 - 00000000 ____D () C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ninja Loader
2015-05-10 18:21 - 2015-05-10 18:21 - 00000000 ____D () C:\Program Files (x86)\Ninja Loader
2015-05-10 18:16 - 2015-05-10 18:16 - 00000000 ____D () C:\Program Files (x86)\Setup Support for Consumer Input
2015-05-10 14:45 - 2015-05-11 06:12 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-10 14:44 - 2015-05-10 14:44 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-10 14:44 - 2015-05-10 14:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-10 14:44 - 2015-05-10 14:44 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-10 14:44 - 2015-05-10 14:44 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-10 14:44 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-10 14:44 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-10 14:44 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-10 13:04 - 2015-05-11 10:20 - 00004304 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserM_1_7_22_478699874-4155726479-3780505679-3006UA__333733393534363935362d455b2a34504141454a5a576c
2015-05-10 13:00 - 2015-05-10 13:00 - 00002062 _____ () C:\Users\owner\Desktop\Continue OneSoftperday Uninstaller.lnk
2015-05-10 11:43 - 2015-05-10 11:43 - 00000000 ____D () C:\ZombieNews
2015-05-10 11:19 - 2015-05-10 11:19 - 00004234 _____ () C:\Windows\System32\Tasks\SPBIW_UpdateTask_Time_333733393534363935362d455b2a34504141454a5a576c
2015-05-10 11:18 - 2015-05-10 11:18 - 00000000 ____D () C:\Users\Public\Documents\ShopperPro
2015-05-10 10:55 - 2015-05-10 10:55 - 00004240 _____ () C:\Windows\System32\Tasks\SMW_UpdateTask_Time_333733393534363935362d455b2a34504141454a5a576c
2015-05-10 10:55 - 2015-05-10 10:55 - 00003592 _____ () C:\Windows\System32\Tasks\SMWUpd
2015-05-10 10:54 - 2015-05-10 10:54 - 00000000 ____D () C:\Users\owner\AppData\Local\CrashRpt
2015-05-09 21:54 - 2015-05-09 21:54 - 00002942 _____ () C:\Users\owner\Desktop\Reimage2.lnk
2015-05-09 21:18 - 2015-05-09 21:18 - 00613255 _____ (CMI Limited) C:\Users\owner\AppData\Local\nsp9DC5.tmp
2015-05-09 21:08 - 2015-05-09 21:08 - 00003102 _____ () C:\Windows\System32\Tasks\{76EE93D4-D32F-48AE-A714-67D92E2D6BF4}
2015-05-09 19:39 - 2015-05-09 19:39 - 00000000 ____D () C:\Users\owner\.cache
2015-05-09 19:36 - 2015-05-09 20:39 - 00002060 _____ () C:\Users\owner\Desktop\Continue GamesDesktop Uninstaller.lnk
2015-05-09 18:39 - 2015-05-09 18:38 - 00613255 _____ (CMI Limited) C:\Users\owner\AppData\Local\nshB51A.tmp
2015-05-09 18:34 - 2015-05-09 20:32 - 00000000 ____D () C:\Program Files (x86)\Edu App
2015-05-09 18:34 - 2015-05-09 19:13 - 00002075 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4.3 64-bit.lnk
2015-05-09 18:34 - 2015-05-09 19:13 - 00002055 _____ () C:\Users\Public\Desktop\Lightroom 4.3 64-bit.lnk
2015-05-09 18:34 - 2015-05-09 18:34 - 00613255 _____ (CMI Limited) C:\Users\owner\AppData\Local\nsqA87A.tmp
2015-05-09 18:24 - 2015-01-19 09:17 - 00060728 _____ (NetFilterSDK.com) C:\Windows\system32\Drivers\gfilterdrv.sys
2015-05-09 18:23 - 2015-05-10 15:00 - 00000000 ____D () C:\ProgramData\Optimizer
2015-05-09 18:23 - 2015-05-09 18:24 - 00000000 ____D () C:\Program Files (x86)\Solid YouTube Downloader and Converter
2015-05-09 18:23 - 2015-05-09 18:23 - 00001276 _____ () C:\Users\Public\Desktop\Solid YouTube Downloader and Converter.lnk
2015-05-09 18:23 - 2015-05-09 18:23 - 00000000 ____D () C:\Users\owner\AppData\Roaming\youtube-downloader-and-converter
2015-05-09 18:23 - 2015-05-09 18:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Solid YouTube Downloader and Converter
2015-05-09 18:23 - 2015-05-09 18:23 - 00000000 ____D () C:\Program Files (x86)\Windows Audio
2015-05-09 18:19 - 2015-05-11 09:58 - 00001016 _____ () C:\Windows\Tasks\HOexHy4EPthbUe533xux7j.job
2015-05-09 18:19 - 2015-05-09 18:19 - 00004042 _____ () C:\Windows\System32\Tasks\HOexHy4EPthbUe533xux7j
2015-05-09 18:19 - 2015-05-09 18:19 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf
2015-05-09 18:17 - 2015-05-11 11:22 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-05-09 18:15 - 2015-05-09 18:15 - 00000000 ____D () C:\Users\owner\AppData\Roaming\Opera Software
2015-05-09 18:15 - 2015-05-09 18:15 - 00000000 ____D () C:\Users\owner\AppData\Local\Opera Software
2015-05-09 18:13 - 2015-05-11 09:58 - 00000330 _____ () C:\Windows\Tasks\SMPAMRXBTJ1.job
2015-05-09 18:13 - 2015-05-10 11:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-05-09 18:13 - 2015-05-09 18:13 - 00003558 _____ () C:\Windows\System32\Tasks\BLVCPRVBOV
2015-05-09 18:13 - 2015-05-09 18:13 - 00002852 _____ () C:\Windows\System32\Tasks\SMPAMRXBTJ1
2015-05-09 18:13 - 2015-05-09 18:13 - 00000000 ____D () C:\ProgramData\ef7a28a199c74980a1c30cd11a2d7718
2015-05-09 18:12 - 2015-05-09 18:12 - 00000000 ____D () C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2015-05-09 18:10 - 2015-05-09 18:10 - 00003468 _____ () C:\Windows\System32\Tasks\avabvyxvdy
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D () C:\Users\owner\Desktop\Adobe
2015-05-09 17:43 - 2015-05-11 02:36 - 00000000 ____D () C:\Users\owner\AppData\Local\58400D07-1431193387-7BC0-1DB7-EC9A74FE1D24
2015-05-09 17:43 - 2015-05-09 17:43 - 00000000 ____D () C:\ProgramData\COMODO
2015-05-09 17:41 - 2015-05-09 17:41 - 00000000 ____D () C:\Program Files\COMODO
2015-05-09 17:40 - 2015-05-09 17:41 - 00000000 ____D () C:\Users\owner\Documents\ProPCCleaner
2015-05-09 17:40 - 2015-05-09 17:40 - 00003460 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Popup
2015-05-09 17:40 - 2015-05-09 17:40 - 00003196 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Start
2015-05-09 17:40 - 2015-05-09 17:40 - 00000000 ____D () C:\Users\owner\AppData\Local\Pro_PC_Cleaner
2015-05-09 17:34 - 2015-05-09 17:37 - 808970536 _____ (Adobe Systems Incorporated) C:\Users\owner\Desktop\adobe-photoshop-lightroom-4.3-multi.exe
2015-05-09 17:33 - 2015-05-09 17:41 - 00002758 _____ () C:\Users\owner\Desktop\Continue Adobe Photoshop Lightroom.lnk
2015-05-09 16:41 - 2015-05-09 16:41 - 00001063 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NIKON IMAGE SPACE UPLOADER.lnk
2015-05-09 16:41 - 2015-05-09 16:41 - 00001051 _____ () C:\Users\Public\Desktop\NIKON IMAGE SPACE UPLOADER.lnk
2015-05-09 16:41 - 2015-05-09 16:41 - 00000000 ____D () C:\Users\owner\AppData\Roaming\com.nikonimagespace.uploader
2015-05-09 16:41 - 2015-05-09 16:41 - 00000000 ____D () C:\Program Files (x86)\NIKON IMAGE SPACE UPLOADER
2015-05-09 16:28 - 2015-05-09 16:28 - 00000000 ____D () C:\Users\owner\AppData\Local\PAShell
2015-05-09 16:26 - 2015-05-09 16:26 - 00000000 ____D () C:\ProgramData\Nikon
2015-05-09 02:25 - 2015-05-09 02:25 - 00000000 _____ () C:\Windows\ViewNX2.INI
2015-05-09 02:21 - 2015-05-10 11:07 - 00000000 ____D () C:\Users\owner\AppData\Local\Nikon
2015-05-09 02:21 - 2015-05-09 16:14 - 00000000 ____D () C:\Users\owner\AppData\Roaming\Nikon
2015-05-09 02:19 - 2015-05-09 02:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nikon Message Center 2
2015-05-09 02:17 - 2015-05-09 02:17 - 00000268 ___RH () C:\Users\owner\AppData\Roaming\Folder Actions
2015-05-09 02:17 - 2015-05-09 02:17 - 00000268 ___RH () C:\ProgramData\Framework
2015-05-09 02:17 - 2015-05-09 02:17 - 00000020 ____H () C:\ProgramData\PKP_DLes.DAT
2015-05-09 02:17 - 2015-05-09 02:17 - 00000000 ____D () C:\ProgramData\Images
2015-05-09 02:16 - 2015-05-10 11:07 - 00000000 ____D () C:\Program Files\Common Files\Nikon
2015-05-09 02:16 - 2015-05-09 02:19 - 00000000 ____D () C:\Program Files (x86)\Nikon
2015-05-09 02:16 - 2015-05-09 02:16 - 00000000 ____D () C:\Program Files\Nikon
2015-05-09 02:15 - 2015-05-10 11:06 - 00000000 ____H () C:\ProgramData\PKP_DLev.DAT
2015-05-09 02:15 - 2015-05-10 11:06 - 00000000 ____H () C:\ProgramData\PKP_DLet.DAT
2015-05-09 02:15 - 2015-05-10 11:06 - 00000000 _____ () C:\Users\owner\AppData\Roaming\Folder Actions Handlers
2015-05-09 02:15 - 2015-05-10 11:06 - 00000000 _____ () C:\Users\owner\AppData\Roaming\Flowers
2015-05-09 02:15 - 2015-05-09 02:19 - 00000000 ____D () C:\Users\owner\AppData\Local\Downloaded Installations
2015-05-09 02:15 - 2015-05-09 02:17 - 00000000 ____D () C:\ProgramData\Ultima_T15
2015-05-09 02:15 - 2015-05-09 02:17 - 00000000 ____D () C:\ProgramData\EnterNHelp
2015-05-09 02:13 - 2015-05-09 02:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Link to Nikon
2015-05-09 01:50 - 2015-05-09 01:50 - 00000000 ____D () C:\Users\owner\AppData\Local\Avanquest North America
2015-05-09 01:49 - 2015-05-09 17:27 - 00000000 ____D () C:\Users\owner\AppData\Local\Photo Explosion
2015-05-09 01:49 - 2015-05-09 01:49 - 00000122 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2015-05-09 01:49 - 2015-05-09 01:49 - 00000000 ____D () C:\Users\owner\AppData\Local\Avanquest
2015-05-09 01:47 - 2015-05-09 16:26 - 00000000 ____D () C:\Users\owner\AppData\Local\Nova Development
2015-05-09 01:46 - 2015-05-09 01:46 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
2015-05-09 01:44 - 2015-05-09 01:44 - 00002945 _____ () C:\Users\Public\Desktop\Project Studio.lnk
2015-05-09 01:44 - 2015-05-09 01:44 - 00002645 _____ () C:\Users\Public\Desktop\Photo Explosion Special Edition.lnk
2015-05-09 01:44 - 2015-05-09 01:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Explosion 5 Special Edition
2015-05-09 01:43 - 2015-05-09 01:43 - 00000000 ____D () C:\Program Files (x86)\Nova Development
2015-05-09 01:33 - 2015-05-09 01:34 - 02453108 _____ () C:\Users\owner\Downloads\Grace2.zip
2015-04-20 10:05 - 2015-04-20 10:05 - 01579520 _____ () C:\Users\owner\AppData\Roaming\x5LzB43qifbi.exe
2015-04-19 08:20 - 2015-04-19 08:20 - 00005872 _____ () C:\Users\owner\AppData\Roaming\x5LzB43qifbi
2015-04-19 08:20 - 2015-04-19 08:20 - 00005872 _____ () C:\Users\owner\AppData\Roaming\HOexHy4EPthbUe533xux7j
2015-04-15 23:27 - 2015-04-15 23:27 - 00000000 ____D () C:\2717230850fe7fb480e98267adc1170a
2015-04-15 21:23 - 2015-04-15 21:23 - 03159200 _____ () C:\Users\owner\Downloads\Upright-Monogram-3inset.zip
2015-04-15 20:14 - 2015-03-24 23:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 20:14 - 2015-03-24 23:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 20:14 - 2015-03-24 23:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 20:14 - 2015-03-24 23:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 20:14 - 2015-03-24 23:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 20:14 - 2015-03-24 23:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 20:14 - 2015-03-24 23:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 20:14 - 2015-03-24 23:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 20:14 - 2015-03-24 23:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 20:14 - 2015-03-24 23:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 20:14 - 2015-03-24 23:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 20:14 - 2015-03-24 23:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-15 20:14 - 2015-03-24 23:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-15 20:14 - 2015-03-24 23:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-15 20:14 - 2015-03-24 23:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-15 20:14 - 2015-03-24 23:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-15 20:13 - 2015-03-22 23:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 20:13 - 2015-03-22 23:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 20:13 - 2015-03-22 23:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 20:13 - 2015-03-22 23:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 20:13 - 2015-03-22 23:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 20:13 - 2015-03-22 23:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 20:13 - 2015-03-22 23:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 20:13 - 2015-03-22 23:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 20:13 - 2015-03-17 01:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 20:12 - 2015-03-17 01:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 20:12 - 2015-03-17 01:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 20:12 - 2015-03-17 01:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 20:12 - 2015-03-17 01:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-04-15 20:12 - 2015-03-17 01:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-04-15 20:12 - 2015-03-17 01:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 20:12 - 2015-03-17 01:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 20:12 - 2015-03-17 01:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 20:12 - 2015-03-17 01:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-04-15 20:12 - 2015-03-17 01:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-04-15 20:12 - 2015-03-17 01:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 20:12 - 2015-03-17 01:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 20:12 - 2015-03-17 01:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 20:12 - 2015-03-17 01:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 01:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-04-15 20:12 - 2015-03-17 01:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-04-15 20:12 - 2015-03-17 00:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-04-15 20:12 - 2015-03-17 00:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-04-15 20:12 - 2015-03-17 00:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-04-15 20:12 - 2015-03-17 00:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-04-15 20:12 - 2015-03-17 00:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-04-15 20:12 - 2015-03-17 00:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-04-15 20:12 - 2015-03-17 00:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-04-15 20:12 - 2015-03-17 00:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-04-15 20:12 - 2015-03-17 00:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-04-15 20:12 - 2015-03-17 00:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-04-15 20:12 - 2015-03-17 00:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-15 20:12 - 2015-03-17 00:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-15 20:12 - 2015-03-16 23:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-04-15 20:12 - 2015-03-16 23:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-04-15 20:12 - 2015-03-16 23:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-15 20:12 - 2015-03-16 23:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-15 20:12 - 2015-03-16 23:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-15 20:12 - 2015-03-16 23:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-15 20:11 - 2015-04-01 20:17 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 20:11 - 2015-04-01 19:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-04-15 20:11 - 2015-03-13 00:32 - 24980480 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 20:11 - 2015-03-13 00:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 20:11 - 2015-03-13 00:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 20:11 - 2015-03-13 00:09 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 20:11 - 2015-03-13 00:08 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 20:11 - 2015-03-13 00:08 - 00417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 20:11 - 2015-03-13 00:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 20:11 - 2015-03-13 00:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 20:11 - 2015-03-13 00:06 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 20:11 - 2015-03-13 00:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 20:11 - 2015-03-12 23:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 20:11 - 2015-03-12 23:55 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 20:11 - 2015-03-12 23:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 20:11 - 2015-03-12 23:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 20:11 - 2015-03-12 23:53 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 20:11 - 2015-03-12 23:50 - 06025216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 20:11 - 2015-03-12 23:44 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 20:11 - 2015-03-12 23:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-04-15 20:11 - 2015-03-12 23:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-04-15 20:11 - 2015-03-12 23:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 20:11 - 2015-03-12 23:32 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 20:11 - 2015-03-12 23:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-04-15 20:11 - 2015-03-12 23:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-04-15 20:11 - 2015-03-12 23:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-04-15 20:11 - 2015-03-12 23:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 20:11 - 2015-03-12 23:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-04-15 20:11 - 2015-03-12 23:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 20:11 - 2015-03-12 23:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-04-15 20:11 - 2015-03-12 23:23 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 20:11 - 2015-03-12 23:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-04-15 20:11 - 2015-03-12 23:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-04-15 20:11 - 2015-03-12 23:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-04-15 20:11 - 2015-03-12 23:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-04-15 20:11 - 2015-03-12 23:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-04-15 20:11 - 2015-03-12 23:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-04-15 20:11 - 2015-03-12 23:08 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 20:11 - 2015-03-12 23:07 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 20:11 - 2015-03-12 23:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-04-15 20:11 - 2015-03-12 23:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 20:11 - 2015-03-12 23:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 20:11 - 2015-03-12 23:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-04-15 20:11 - 2015-03-12 23:00 - 14397440 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 20:11 - 2015-03-12 22:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-04-15 20:11 - 2015-03-12 22:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-04-15 20:11 - 2015-03-12 22:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-04-15 20:11 - 2015-03-12 22:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-04-15 20:11 - 2015-03-12 22:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 20:11 - 2015-03-12 22:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-04-15 20:11 - 2015-03-12 22:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-04-15 20:11 - 2015-03-12 22:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-04-15 20:11 - 2015-03-12 22:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-04-15 20:11 - 2015-03-12 22:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 20:11 - 2015-03-12 22:22 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 20:11 - 2015-03-12 22:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-04-15 20:11 - 2015-03-12 22:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-04-15 20:11 - 2015-03-12 22:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-04-15 20:11 - 2015-03-09 23:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 20:11 - 2015-03-09 23:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-15 20:11 - 2015-03-09 23:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-04-15 20:11 - 2015-03-09 23:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-04-15 20:11 - 2015-03-05 01:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 20:11 - 2015-03-05 00:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-04-15 20:11 - 2015-03-04 00:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 20:11 - 2015-03-04 00:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 20:11 - 2015-03-04 00:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-15 20:11 - 2015-02-24 23:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-11 12:07 - 2009-07-14 00:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-11 12:07 - 2009-07-14 00:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-11 11:37 - 2012-11-11 17:44 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-11 11:28 - 2012-03-31 15:08 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-11 11:27 - 2012-02-11 22:12 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{3AEF314B-DF63-4FD0-BE9D-A71EA952A451}
2015-05-11 11:17 - 2012-01-08 10:19 - 01058930 _____ () C:\Windows\WindowsUpdate.log
2015-05-11 10:23 - 2012-11-12 00:16 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-05-11 09:59 - 2012-11-11 17:44 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-11 09:58 - 2012-05-13 01:36 - 00000414 _____ () C:\Windows\Tasks\PC Optimizer Pro64 startups.job
2015-05-11 09:58 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-11 09:28 - 2012-02-21 21:30 - 00000000 ____D () C:\Users\owner\AppData\Local\CrashDumps
2015-05-11 09:28 - 2012-02-18 19:02 - 00000000 ____D () C:\Windows\Minidump
2015-05-11 09:28 - 2007-01-01 21:25 - 00000000 ____D () C:\Windows\Panther
2015-05-11 08:25 - 2009-07-13 23:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-05-11 07:21 - 2009-07-13 22:34 - 00000540 _____ () C:\Windows\win.ini
2015-05-11 06:44 - 2012-11-11 17:44 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-10 16:25 - 2009-07-14 01:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-05-10 14:48 - 2009-07-14 01:13 - 00803766 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-10 14:36 - 2009-07-14 00:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-05-10 11:34 - 2013-11-18 16:50 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-05-10 11:34 - 2011-10-14 17:05 - 00000000 ____D () C:\ProgramData\Adobe
2015-05-10 11:28 - 2013-11-18 17:01 - 00000000 ____D () C:\Program Files\Adobe
2015-05-10 10:56 - 2012-02-21 21:28 - 00000000 ____D () C:\Users\owner\AppData\Local\Google
2015-05-10 10:43 - 2012-02-16 01:07 - 00000000 ____D () C:\Users\owner\AppData\Local\Adobe
2015-05-10 10:39 - 2012-02-11 22:12 - 00000000 ____D () C:\Users\owner\AppData\Roaming\hpqLog
2015-05-09 21:07 - 2014-04-06 12:55 - 00000000 ____D () C:\Users\owner\AppData\Roaming\Dropbox
2015-05-09 19:57 - 2014-04-06 12:59 - 00000000 ___RD () C:\Users\owner\Dropbox
2015-05-09 19:39 - 2012-02-11 22:07 - 00000000 ____D () C:\Users\owner
2015-05-09 19:30 - 2014-03-13 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LockLizard
2015-05-09 18:13 - 2012-02-16 05:05 - 00000000 ____D () C:\Users\owner\AppData\Roaming\Adobe
2015-05-09 17:49 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-05-09 16:09 - 2009-07-14 00:45 - 05166464 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-09 02:19 - 2011-10-14 17:12 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-05-09 02:15 - 2003-03-18 22:05 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ATL71.DLL
2015-05-09 02:07 - 2013-12-06 02:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-05-09 02:06 - 2013-12-06 02:07 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-05-09 01:47 - 2012-02-11 22:14 - 00147080 _____ () C:\Users\owner\AppData\Local\GDIPFONTCACHEV1.DAT
2015-05-09 01:46 - 2011-10-14 17:02 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-04-30 20:56 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\AppCompat
2015-04-19 18:11 - 2014-12-12 02:34 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-19 18:11 - 2014-05-01 22:08 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-19 18:11 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-19 17:55 - 2012-02-24 20:53 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-19 17:50 - 2012-05-13 01:39 - 00796380 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-15 23:27 - 2013-08-16 09:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 23:27 - 2012-02-12 02:51 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 21:28 - 2012-03-31 15:08 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-15 21:28 - 2012-03-31 15:08 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-15 21:28 - 2011-10-14 16:36 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2015-05-09 02:15 - 2015-05-10 11:06 - 0000000 _____ () C:\Users\owner\AppData\Roaming\Flowers
2015-05-09 02:17 - 2015-05-09 02:17 - 0000268 ___RH () C:\Users\owner\AppData\Roaming\Folder Actions
2015-05-09 02:15 - 2015-05-10 11:06 - 0000000 _____ () C:\Users\owner\AppData\Roaming\Folder Actions Handlers
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\owner\AppData\Roaming\HOexHy4EPthbUe533xux7j
2012-11-12 00:10 - 2012-11-12 00:21 - 0000180 _____ () C:\Users\owner\AppData\Roaming\hpmirrordriver.log
2015-04-19 08:20 - 2015-04-19 08:20 - 0005872 _____ () C:\Users\owner\AppData\Roaming\x5LzB43qifbi
2015-04-20 10:05 - 2015-04-20 10:05 - 1579520 _____ () C:\Users\owner\AppData\Roaming\x5LzB43qifbi.exe
2013-01-04 22:10 - 2013-01-04 22:10 - 0000036 _____ () C:\Users\owner\AppData\Local\housecall.guid.cache
2015-05-09 18:39 - 2015-05-09 18:38 - 0613255 _____ (CMI Limited) C:\Users\owner\AppData\Local\nshB51A.tmp
2015-05-09 21:18 - 2015-05-09 21:18 - 0613255 _____ (CMI Limited) C:\Users\owner\AppData\Local\nsp9DC5.tmp
2015-05-09 18:34 - 2015-05-09 18:34 - 0613255 _____ (CMI Limited) C:\Users\owner\AppData\Local\nsqA87A.tmp
2012-10-20 11:43 - 2012-10-20 11:43 - 0017408 _____ () C:\Users\owner\AppData\Local\WebpageIcons.db
2015-05-09 02:17 - 2015-05-09 02:17 - 0000268 ___RH () C:\ProgramData\Framework
2013-03-28 22:59 - 2013-03-28 23:20 - 0000778 _____ () C:\ProgramData\hpzinstall.log
2015-05-09 01:49 - 2015-05-09 01:49 - 0000122 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2015-05-09 02:17 - 2015-05-09 02:17 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2015-05-09 02:15 - 2015-05-10 11:06 - 0000000 ____H () C:\ProgramData\PKP_DLet.DAT
2015-05-09 02:15 - 2015-05-10 11:06 - 0000000 ____H () C:\ProgramData\PKP_DLev.DAT
Some content of TEMP:
====================
C:\Users\owner\AppData\Local\Temp\compete.exe
C:\Users\owner\AppData\Local\Temp\cw.exe
C:\Users\owner\AppData\Local\Temp\optprosetup.exe
C:\Users\owner\AppData\Local\Temp\Quarantine.exe
C:\Users\owner\AppData\Local\Temp\sqlite3.dll
C:\Users\owner\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-22 18:05
==================== End Of Log ============================