Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-02-2015 Ran by SYSTEM on MININT-30QT9O3 on 08-02-2015 12:54:30 Running from H:\ Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 [b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b] Tutorial for Farbar Recovery Scan Tool: ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2461504 2014-09-16] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7284328 2011-08-22] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-15] (Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ASUS ShellProcess Execute] => C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe [252544 2010-11-25] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe [286720 2011-09-14] () HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-24] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => E:\adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-14] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1934744 2015-01-30] (APN) HKU\Greg\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.) HKU\Greg\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.) HKU\Greg\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.) HKU\Greg\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6482200 2014-09-26] (Piriform Ltd) HKU\Greg\...\Run: [Spotify] => C:\Users\Greg\AppData\Roaming\Spotify\Spotify.exe [6737976 2015-01-22] (Spotify Ltd) HKU\Greg\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3890768 2015-01-26] (Tonec Inc.) Startup: C:\Users\Greg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BUFFALO NAS Navigator2.lnk ShortcutTarget: BUFFALO NAS Navigator2.lnk -> C:\Program Files (x86)\BUFFALO\NASNAVI\NasNavi.exe (Buffalo Inc.) Startup: C:\Users\Greg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> (No File) Startup: C:\Users\Greg\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NAS Scheduler.lnk ShortcutTarget: NAS Scheduler.lnk -> C:\Program Files (x86)\BUFFALO\NASNAVI\nassche.exe (BUFFALO INC.) ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [177560 2015-01-30] (APN LLC.) S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2014-10-05] () S2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2014-10-05] (ASUSTeK Computer Inc.) S2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2014-10-05] (ASUSTeK Computer Inc.) S2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.22\AsusFanControlService.exe [399744 2014-10-05] (ASUSTeK Computer Inc.) S3 Backup Client Agent Service; C:\Program Files (x86)\NovaStor\NovaStor NovaBACKUP\ManagementServer.Agent.Service.exe [403240 2014-01-03] (NovaStor Corporation) S2 Disaster Recovery Imaging; C:\Program Files (x86)\NovaStor\NovaStor NovaBACKUP\DR\x64\drdiag.exe [6256936 2014-01-03] (NovaStor Corporation) S2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc) S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-09-16] (NVIDIA Corporation) S2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe [7168 2011-09-14] () S2 NasPmService; C:\Program Files (x86)\BUFFALO\NASNAVI\nassvc.exe [245760 2013-09-13] (BUFFALO INC.) S2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe [276376 2014-09-21] (Symantec Corporation) S2 Northern Themes Service; C:\Users\Greg\AppData\NTSFile\NTS.exe [227840 2015-01-20] (NTS Co., Ltd.") S2 nsService; C:\Program Files (x86)\NovaStor\NovaStor NovaBACKUP\nsService.exe [613008 2014-01-03] (NovaStor Corporation) S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-09-16] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-09-16] (NVIDIA Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) S3 WinRM; C:\Windows\system32\WsmSvc.dll [2018304 2010-11-20] () S2 winzipersvc; C:\Program Files (x86)\WinZipper\winzipersvc.exe [424624 2015-01-12] (Taiwan Shui Mu Chih Ching Technology Limited.) <==== ATTENTION S3 WPCSvc; C:\Windows\System32\wpcsvc.dll [12288 2009-07-13] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 arcsas; C:\Windows\system32\drivers\arcsas.sys [97856 2009-07-13] () S0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) S1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] () S1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2013-01-15] () S3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation) S1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\BASHDefs\20150106.001\BHDrvx64.sys [1622744 2015-01-06] (Symantec Corporation) S1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1506000.020\ccSetx64.sys [162392 2014-02-20] (Symantec Corporation) S3 circlass; C:\Windows\system32\drivers\circlass.sys [45568 2009-07-13] () S1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-11] (Symantec Corporation) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [18528 2014-11-18] () S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [15968 2014-11-18] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10848 2014-11-18] () S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [10208 2014-11-18] () S0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [23832 2011-09-14] (Intel Corporation) S1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\IPSDefs\20150206.001\IDSvia64.sys [669400 2015-02-06] (Symantec Corporation) S3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation) S3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\VirusDefs\20150206.016\ENG64.SYS [129752 2015-01-23] (Symantec Corporation) S3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\VirusDefs\20150206.016\EX64.SYS [2137304 2015-01-23] (Symantec Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-09-16] (NVIDIA Corporation) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation) S0 oodisr; C:\Windows\System32\DRIVERS\oodisr.sys [117960 2014-01-03] (NovaStor Corporation) S0 oodisrh; C:\Windows\System32\DRIVERS\oodisrh.sys [42184 2014-01-03] (NovaStor Corporation) S0 oodivd; C:\Windows\System32\DRIVERS\oodivd.sys [256712 2014-01-03] (NovaStor Corporation) S0 oodivdh; C:\Windows\System32\DRIVERS\oodivdh.sys [45768 2014-01-03] (NovaStor Corporation) S0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-09] (Corel Corporation) S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [46592 2009-07-13] () S1 SRTSP; C:\Windows\system32\drivers\NISx64\1506000.020\SRTSP64.SYS [876248 2014-08-25] (Symantec Corporation) S1 SRTSPX; C:\Windows\system32\drivers\NISx64\1506000.020\SRTSPX64.SYS [37592 2014-08-25] (Symantec Corporation) S0 SymDS; C:\Windows\System32\drivers\NISx64\1506000.020\SYMDS64.SYS [493656 2014-08-25] (Symantec Corporation) S0 SymEFA; C:\Windows\System32\drivers\NISx64\1506000.020\SYMEFA64.SYS [1148120 2014-08-25] (Symantec Corporation) S3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-10-19] (Symantec Corporation) S1 SymIRON; C:\Windows\system32\drivers\NISx64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation) S1 SymNetS; C:\Windows\system32\drivers\NISx64\1506000.020\SYMNETS.SYS [593112 2014-08-25] (Symantec Corporation) S0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2014-10-05] (Acronis International GmbH) S0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2014-10-05] (Acronis) S0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [117024 2014-10-05] (Acronis International GmbH) S3 vwifibus; C:\Windows\System32\drivers\vwifibus.sys [24576 2009-07-13] () S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-08 12:54 - 2015-02-08 12:54 - 00000000 ____D () C:\FRST 2015-02-08 03:00 - 2015-02-08 03:00 - 00000000 ____D () C:\.Trashes 2015-02-08 03:00 - 2015-02-08 03:00 - 00000000 ____D () C:\.fseventsd 2015-02-07 16:32 - 2015-02-07 16:32 - 00003608 ____N () C:\bootsqm.dat 2015-02-07 16:31 - 2015-02-07 16:31 - 00000000 __SHD () C:\found.000 2015-02-06 11:28 - 2015-02-06 11:28 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\chc 2015-02-04 13:18 - 2015-02-04 13:20 - 00155234 _____ () C:\Users\Greg\Documents\ceremonia sobota.pe3 2015-02-03 12:30 - 2015-02-03 12:30 - 06853833 _____ () C:\Users\Greg\Desktop\sinthya 2015-02-03 11:46 - 2015-02-03 11:46 - 00000000 ____D () C:\Users\Greg\Desktop\HD MOMENTS 2015-02-03 11:45 - 2015-02-03 11:45 - 01133886 _____ () C:\Users\Greg\Desktop\HD 2015-02-03 11:07 - 2015-02-03 12:40 - 00000370 _____ () C:\Users\Greg\AppData\Roaming\burnaware.ini 2015-02-03 09:22 - 2015-02-03 09:22 - 00000081 _____ () C:\Users\Greg\Documents\tor.txt 2015-02-03 09:22 - 2015-02-03 09:22 - 00000081 _____ () C:\Users\Greg\Desktop\tor.txt 2015-02-03 08:52 - 2015-02-03 08:52 - 00000625 _____ () C:\Users\Public\Desktop\BurnAware Professional.lnk 2015-02-03 05:25 - 2015-02-03 05:25 - 00003151 _____ () C:\Users\Greg\Desktop\BurnAware_Premium_7.2_Final_Multilanguage_-_SceneDL.torrent 2015-02-03 04:00 - 2015-02-03 04:00 - 00000328 _____ () C:\Windows\PFRO.log 2015-02-02 13:48 - 2015-02-02 14:35 - 00000000 ____D () C:\Users\Greg\Desktop\uploads 2015-02-02 13:42 - 2015-02-02 13:42 - 06372800 _____ (Tim Kosse) C:\Users\Greg\Downloads\FileZilla_3.10.1.1_win32-setup.exe 2015-02-02 06:02 - 2015-02-06 09:42 - 00000000 ____D () C:\Program Files (x86)\WinZipper 2015-02-02 06:02 - 2015-02-02 06:02 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\WinZipper 2015-01-30 05:23 - 2015-01-30 05:23 - 02299766 _____ () C:\Users\Greg\Downloads\stock-footage-stockholm-sweden-june-park-area-in-stockholm-sweden.mp4 2015-01-30 04:31 - 2015-01-30 04:31 - 00707227 _____ () C:\Users\Greg\Downloads\stock-footage-stockholm-sweden-june-people-walkin-in-a-walkway-in-a-park-in-stockholm-sweden.mp4 2015-01-30 04:23 - 2015-01-30 04:23 - 00087465 _____ () C:\Users\Greg\Downloads\Shutterstock_PD_v3.1.rar 2015-01-30 04:23 - 2015-01-30 04:23 - 00000000 ____D () C:\Users\Greg\Downloads\Shutterstock_PD_v3.1 2015-01-29 14:53 - 2015-02-06 22:42 - 00000000 ____D () C:\Program Files (x86)\Internet Download Manager 2015-01-29 14:53 - 2015-01-30 09:36 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\IDM 2015-01-29 14:53 - 2015-01-29 14:53 - 00001022 _____ () C:\Users\Greg\Desktop\Internet Download Manager.lnk 2015-01-29 14:52 - 2015-01-29 14:52 - 113376786 _____ () C:\Users\Greg\Desktop\clip1_plasko.mp4 2015-01-29 14:51 - 2015-01-29 14:52 - 06361280 _____ (Tonec Inc.) C:\Users\Greg\Downloads\idman621build19.exe 2015-01-29 11:31 - 2015-01-29 11:31 - 101893831 _____ () C:\Users\Greg\Desktop\sinthya_2.mp4 2015-01-28 14:23 - 2015-01-28 14:23 - 00332893 _____ () C:\Users\Greg\Downloads\ujecia_1.mp4 2015-01-28 04:56 - 2015-01-28 04:56 - 34257655 _____ () C:\Users\Greg\Downloads\Sobota_sikh_tysia.prproj 2015-01-27 15:32 - 2015-02-06 09:39 - 00002946 _____ () C:\Windows\setupact.log 2015-01-27 15:32 - 2015-01-27 15:32 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-27 15:13 - 2015-01-27 15:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-27 04:31 - 2015-01-27 04:32 - 16292140 _____ () C:\Users\Greg\Desktop\311706601.mp4 2015-01-26 16:44 - 2015-01-26 16:44 - 00002852 _____ () C:\Users\Greg\Documents\FCP Translation Results 2015-01-27 00-44.txt 2015-01-26 16:43 - 2015-01-26 16:43 - 00038522 _____ () C:\Users\Greg\Documents\spicze .pe3 2015-01-26 15:42 - 2015-01-26 15:42 - 00024261 _____ () C:\Users\Greg\Documents\ceremonia niedziela cywilny.pe3 2015-01-26 13:27 - 2015-01-26 13:27 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-01-26 13:17 - 2015-01-26 13:17 - 00002028 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk 2015-01-26 12:15 - 2015-01-26 12:15 - 00078075 _____ () C:\Users\Greg\Documents\s3.pe3 2015-01-26 04:32 - 2014-11-28 16:37 - 00180648 _____ (Tonec Inc.) C:\Windows\System32\Drivers\idmwfp.sys 2015-01-25 15:20 - 2015-01-25 15:20 - 06235667 _____ () C:\Users\Greg\Desktop\sinthya.mp4 2015-01-25 14:34 - 2014-12-12 21:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2015-01-25 14:34 - 2014-12-12 19:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-01-25 14:28 - 2015-01-25 14:28 - 07336364 _____ () C:\Users\Greg\Desktop\audio.wav 2015-01-25 13:45 - 2015-01-25 13:45 - 00000000 ____D () C:\Users\Greg\AppData\OICE_15_974FA576_32C1D314_1CD7 2015-01-25 09:06 - 2015-01-25 09:06 - 00000000 ____D () C:\Users\Greg\AppData\OICE_15_974FA576_32C1D314_28BE 2015-01-25 09:05 - 2015-01-25 09:05 - 00000000 ____D () C:\Users\Greg\AppData\OICE_15_974FA576_32C1D314_81A 2015-01-25 09:05 - 2015-01-25 09:05 - 00000000 ____D () C:\Users\Greg\AppData\OICE_15_974FA576_32C1D314_1F97 2015-01-25 07:15 - 2015-01-25 07:17 - 35707185 _____ () C:\Users\Greg\Downloads\Intel RSTe 4.1 GD Windows 2015-01-24 19:05 - 2015-01-24 19:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET 2015-01-24 16:33 - 2015-01-24 16:33 - 00000000 ____D () C:\Users\Greg\Desktop\Tor Browser 2015-01-24 16:32 - 2015-01-24 16:33 - 34324222 _____ () C:\Users\Greg\Downloads\torbrowser-install-4.0.3_en-US.exe 2015-01-24 11:29 - 2014-12-18 19:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\System32\profsvc.dll 2015-01-24 11:29 - 2014-12-18 17:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\mrxdav.sys 2015-01-24 11:29 - 2014-12-11 09:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe 2015-01-24 11:29 - 2014-12-05 20:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\System32\nlasvc.dll 2015-01-24 11:29 - 2014-12-05 19:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2015-01-24 11:29 - 2014-12-05 19:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2015-01-24 11:29 - 2014-11-10 19:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2015-01-24 11:29 - 2014-11-10 18:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-01-24 11:29 - 2012-10-03 09:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\System32\ncsi.dll 2015-01-24 11:29 - 2012-10-03 09:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\System32\nlaapi.dll 2015-01-24 11:15 - 2014-11-26 17:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2015-01-24 11:15 - 2014-11-26 17:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-01-24 11:15 - 2014-11-21 19:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2015-01-24 11:15 - 2014-11-21 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2015-01-24 11:15 - 2014-11-21 19:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2015-01-24 11:15 - 2014-11-21 18:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2015-01-24 11:15 - 2014-11-21 18:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2015-01-24 11:15 - 2014-11-21 18:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2015-01-24 11:15 - 2014-11-21 18:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2015-01-24 11:15 - 2014-11-21 18:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2015-01-24 11:15 - 2014-11-21 18:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2015-01-24 11:15 - 2014-11-21 18:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2015-01-24 11:15 - 2014-11-21 18:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2015-01-24 11:15 - 2014-11-21 18:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2015-01-24 11:15 - 2014-11-21 18:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2015-01-24 11:15 - 2014-11-21 18:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2015-01-24 11:15 - 2014-11-21 18:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2015-01-24 11:15 - 2014-11-21 18:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-01-24 11:15 - 2014-11-21 18:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2015-01-24 11:15 - 2014-11-21 18:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-01-24 11:15 - 2014-11-21 18:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2015-01-24 11:15 - 2014-11-21 18:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2015-01-24 11:15 - 2014-11-21 18:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2015-01-24 11:15 - 2014-11-21 18:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-01-24 11:15 - 2014-11-21 18:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-01-24 11:15 - 2014-11-21 18:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-01-24 11:15 - 2014-11-21 18:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2015-01-24 11:15 - 2014-11-21 18:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-01-24 11:15 - 2014-11-21 18:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-01-24 11:15 - 2014-11-21 17:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-01-24 11:15 - 2014-11-21 17:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-01-24 11:15 - 2014-11-21 17:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-01-24 11:15 - 2014-11-21 17:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-01-24 11:15 - 2014-11-21 17:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2015-01-24 11:15 - 2014-11-21 17:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2015-01-24 11:15 - 2014-11-21 17:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2015-01-24 11:15 - 2014-11-21 17:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2015-01-24 11:15 - 2014-11-21 17:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-01-24 11:15 - 2014-11-21 17:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2015-01-24 11:15 - 2014-11-21 17:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-01-24 11:15 - 2014-11-21 17:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-01-24 11:15 - 2014-11-21 17:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-01-24 11:15 - 2014-11-21 17:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-01-24 11:15 - 2014-11-21 17:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-01-24 11:15 - 2014-11-21 17:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2015-01-24 11:15 - 2014-11-21 17:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-01-24 11:15 - 2014-11-21 17:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-01-24 11:15 - 2014-11-21 17:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-01-24 11:15 - 2014-11-21 17:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2015-01-24 11:15 - 2014-11-21 17:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-01-24 11:15 - 2014-11-21 17:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2015-01-24 11:15 - 2014-11-21 17:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-01-24 11:15 - 2014-11-21 16:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-01-24 11:15 - 2014-11-21 16:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-01-24 11:04 - 2015-02-08 01:24 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll 2015-01-24 11:04 - 2014-12-11 21:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2015-01-24 11:04 - 2014-12-11 21:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll 2015-01-24 11:04 - 2014-12-11 21:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe 2015-01-24 11:04 - 2014-12-11 21:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-01-24 11:04 - 2014-12-11 21:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-01-24 11:04 - 2014-12-11 21:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-01-24 10:22 - 2015-01-24 10:24 - 57591752 _____ () C:\Users\Greg\Downloads\ 2015-01-24 07:09 - 2015-01-24 07:10 - 05403248 _____ () C:\Windows\PE_Rom.dll 2015-01-24 05:54 - 2015-01-24 05:54 - 00000020 _____ () C:\Users\Greg\Downloads\Text.txt 2015-01-23 13:04 - 2015-01-23 13:23 - 00087338 _____ () C:\Users\Greg\Documents\spicze day 2 mess.pe3 2015-01-23 12:52 - 2015-01-25 07:11 - 106071254 _____ () C:\Users\Greg\Downloads\stochlolm aerial.mp4 2015-01-23 04:36 - 2015-01-23 04:36 - 11408076 _____ () C:\Users\Greg\Desktop\sinthya_1.mp4 2015-01-23 03:00 - 2015-01-23 03:00 - 06220854 _____ () C:\Users\Greg\Desktop\MVI_6228.MOV.Still001.bmp 2015-01-22 13:39 - 2015-01-22 13:39 - 00184584 _____ () C:\Users\Greg\Documents\cer2.pe3 2015-01-22 13:19 - 2015-01-22 13:19 - 00006980 _____ () C:\Users\Greg\Documents\FCP Translation Results 2015-01-22 21-19.txt 2015-01-22 13:00 - 2015-01-22 13:00 - 00004376 _____ () C:\Users\Greg\Documents\FCP Translation Results 2015-01-22 21-00.txt 2015-01-22 02:41 - 2015-01-22 02:41 - 00000419 _____ () C:\Users\Greg\Documents\FCP Translation Results 2015-01-22 10-41.txt 2015-01-22 02:29 - 2015-02-04 11:14 - 00000000 ____D () C:\Users\Greg\AppData\Local\Spotify 2015-01-22 02:29 - 2015-01-22 02:29 - 00001771 _____ () C:\Users\Greg\Desktop\Spotify.lnk 2015-01-22 02:27 - 2015-02-06 07:54 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\Spotify 2015-01-22 02:27 - 2015-01-22 02:27 - 00137888 _____ (Spotify Ltd) C:\Users\Greg\Downloads\SpotifySetup.exe 2015-01-21 17:47 - 2015-01-22 02:10 - 00375200 _____ () C:\Users\Greg\Documents\ceremonia mess day 1.pe3 2015-01-21 02:48 - 2015-01-21 02:48 - 00169530 _____ () C:\Users\Greg\Documents\FCP Translation Results 2015-01-21 10-48.txt 2015-01-20 16:12 - 2015-01-25 06:59 - 00000021 _____ () C:\Windows\SurCode.INI 2015-01-20 16:12 - 2015-01-20 16:12 - 00000000 ____D () C:\Program Files\Common Files\PACE Anti-Piracy 2015-01-20 14:56 - 2015-01-20 13:26 - 125553486 _____ () C:\Users\Greg\Desktop\bina Ppro.prproj 2015-01-20 14:37 - 2014-10-10 04:50 - 00318598 _____ () C:\Users\Greg\Desktop\Untitled-2.psd 2015-01-19 15:55 - 2015-01-19 16:20 - 371288732 _____ () C:\Users\Greg\Downloads\317849795.mp4 2015-01-19 14:03 - 2015-01-19 14:20 - 243278625 _____ () C:\Users\Greg\Downloads\mega hindu film.mp4 2015-01-18 16:59 - 2015-01-18 16:59 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2015-01-17 08:18 - 2015-01-17 08:18 - 156237824 _____ () C:\Users\Greg\Downloads\Tale of fairies- Ustad Sultan Khan & Sabir Khan.mp3 2015-01-17 08:18 - 2015-01-17 08:18 - 00610372 _____ () C:\Users\Greg\Downloads\Tale of fairies- Ustad Sultan Khan & Sabir Khan.mp3 44100.pek 2015-01-17 07:24 - 2015-01-17 07:24 - 11041425 _____ () C:\Users\Greg\Downloads\ 2015-01-17 07:24 - 2015-01-17 07:24 - 03453895 _____ () C:\Users\Greg\Downloads\ 2015-01-17 06:32 - 2015-01-17 06:32 - 56623104 _____ () C:\Users\Greg\Downloads\Niraj Chag Surrender.mp3 2015-01-17 06:32 - 2015-01-17 06:32 - 00221252 _____ () C:\Users\Greg\Downloads\Niraj Chag Surrender.mp3 44100.pek 2015-01-17 05:18 - 2015-01-17 05:21 - 118784495 _____ () C:\Users\Greg\Downloads\ 2015-01-17 05:18 - 2015-01-17 05:18 - 00958578 _____ () C:\Users\Greg\Downloads\ 2015-01-16 12:45 - 2015-01-16 12:45 - 101187584 _____ () C:\Users\Greg\Downloads\Pee Loon Lyrics English Translations -HQ-.mp3 2015-01-16 12:45 - 2015-01-16 12:45 - 00395332 _____ () C:\Users\Greg\Downloads\Pee Loon Lyrics English Translations -HQ-.mp3 44100.pek 2015-01-16 05:17 - 2015-01-16 05:17 - 74973184 _____ () C:\Users\Greg\Downloads\Lak 28 Kudi Da( 2015-01-16 05:17 - 2015-01-16 05:17 - 00292932 _____ () C:\Users\Greg\Downloads\Lak 28 Kudi Da( 44100.pek 2015-01-15 09:04 - 2015-01-15 09:04 - 00357111 _____ () C:\Users\Greg\Downloads\agatomaszekweddingphotograper.wordpress.2015-01-15.xml 2015-01-14 01:59 - 2015-01-14 01:59 - 00003896 _____ () C:\Users\Greg\Downloads\www-hdmoments-co-uk_20150114T095900Z_ExternalLinks_LinkingDomains.csv 2015-01-14 01:57 - 2015-01-14 01:57 - 00002396 _____ () C:\Users\Greg\Downloads\www-hdmoments-co-uk_20150114T095730Z_DisavowLinks.csv 2015-01-12 10:52 - 2015-01-12 12:40 - 00000000 ____D () C:\Users\Greg\Desktop\camera roll 2015-01-12 10:39 - 2015-01-12 10:40 - 30330344 _____ () C:\Users\Greg\Downloads\camera 2015-01-10 11:33 - 2015-01-10 11:33 - 00000402 _____ () C:\Users\Greg\Documents\FCP Translation Results 2015-01-10 19-33.txt 2015-01-10 11:28 - 2015-01-10 11:28 - 00156091 _____ () C:\Users\Greg\Documents\sync3.pe3 2015-01-10 11:17 - 2015-01-10 11:17 - 00030222 _____ () C:\Users\Greg\Documents\FCP Translation Results 2015-01-10 19-17.txt 2015-01-10 11:14 - 2015-01-10 11:14 - 00129333 _____ () C:\Users\Greg\Documents\bina plural.pe3 2015-01-10 10:30 - 2015-01-10 10:30 - 00012788 _____ () C:\Users\Greg\Documents\FCP Translation Results 2015-01-10 18-30.txt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-08 01:26 - 2014-10-05 18:21 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2015-02-08 01:25 - 2014-11-12 00:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2015-02-08 01:24 - 2010-11-20 19:24 - 00145920 _____ (Microsoft Corporation) C:\Windows\System32\IPHLPAPI.DLL 2015-02-08 01:24 - 2010-11-20 19:24 - 00029696 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\scfilter.sys 2015-02-08 01:24 - 2009-07-13 16:10 - 00021504 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ws2ifsl.sys 2015-02-08 01:23 - 2009-07-13 16:08 - 00017920 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\irenum.sys 2015-02-08 01:22 - 2009-07-13 15:26 - 00055376 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\fsdepends.sys 2015-02-07 15:43 - 2014-12-02 03:53 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\DMCache 2015-02-07 15:43 - 2014-10-05 08:27 - 01059008 _____ () C:\Windows\WindowsUpdate.log 2015-02-07 15:43 - 2009-07-13 20:45 - 00026336 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-07 15:43 - 2009-07-13 20:45 - 00026336 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-07 15:27 - 2014-10-05 09:59 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-02-07 15:13 - 2014-04-12 01:53 - 00000000 ___HD () C:\Users\Greg\AppData\Local\5U5BpSwUOdX7X7 2015-02-07 10:12 - 2015-01-04 14:51 - 00003770 _____ () C:\Windows\System32\Tasks\AutoRearm 2015-02-07 02:43 - 2014-10-05 08:54 - 00113728 _____ () C:\Users\Greg\AppData\Local\GDIPFONTCACHEV1.DAT 2015-02-07 02:42 - 2014-10-05 15:13 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-02-06 19:27 - 2014-10-05 09:59 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-02-06 11:27 - 2014-10-05 10:49 - 00000000 ____D () C:\Users\Greg\AppData\Local\Adobe 2015-02-06 10:39 - 2014-12-02 03:53 - 00000000 ____D () C:\Users\Greg\Downloads\Compressed 2015-02-06 10:28 - 2014-10-05 10:01 - 00002376 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-02-06 10:14 - 2014-10-11 05:28 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\Dropbox 2015-02-06 10:13 - 2014-10-19 10:43 - 00000000 ____D () C:\Users\Greg\AppData\Local\CrashDumps 2015-02-06 10:12 - 2014-10-06 13:08 - 00000000 ___RD () C:\Users\Greg\iCloudDrive 2015-02-06 09:46 - 2009-07-13 21:13 - 00788374 _____ () C:\Windows\System32\PerfStringBackup.INI 2015-02-06 09:39 - 2014-10-05 12:41 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-02-06 09:39 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-06 05:52 - 2014-11-26 11:25 - 00000000 ____D () C:\Users\Greg\AppData\NTSFile 2015-02-05 19:22 - 2014-10-05 09:59 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-02-05 19:22 - 2014-10-05 09:59 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-02-05 15:29 - 2014-12-02 03:53 - 00000000 ____D () C:\Users\Greg\Downloads\Video 2015-02-05 14:14 - 2014-11-17 19:14 - 00003904 ____H () C:\ProgramData\nsActivation.act 2015-02-05 02:00 - 2014-10-05 15:13 - 00000000 ____D () C:\Users\Greg\AppData\Local\Microsoft Help 2015-02-04 21:39 - 2014-11-06 05:18 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-02-04 13:05 - 2014-10-14 09:20 - 00000000 ____D () C:\Users\Greg\.gstreamer-0.10 2015-02-04 12:59 - 2014-10-11 09:43 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\vlc 2015-02-04 11:13 - 2009-07-13 20:45 - 05104544 _____ () C:\Windows\System32\FNTCACHE.DAT 2015-02-03 14:51 - 2014-11-09 11:05 - 00007608 _____ () C:\Users\Greg\AppData\Local\Resmon.ResmonCfg 2015-02-03 10:14 - 2014-10-05 12:48 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\uTorrent 2015-02-03 04:00 - 2014-11-15 16:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-02-03 03:58 - 2014-10-15 09:16 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\FileZilla 2015-02-02 05:59 - 2014-11-15 16:05 - 00001344 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-02-01 14:29 - 2014-10-06 10:31 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2015-01-30 06:41 - 2009-07-13 21:32 - 00000000 ____D () C:\Windows\System32\FxsTmp 2015-01-30 06:30 - 2014-10-07 00:06 - 00000000 ____D () C:\Program Files (x86)\ImgBurn 2015-01-26 13:36 - 2014-10-10 11:15 - 00000000 ____D () C:\Windows\Minidump 2015-01-26 13:17 - 2014-10-05 10:52 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-01-26 13:17 - 2014-10-05 08:54 - 00000000 ____D () C:\ProgramData\Adobe 2015-01-25 19:02 - 2009-07-13 18:34 - 00000478 _____ () C:\Windows\win.ini 2015-01-25 06:59 - 2009-07-13 19:20 - 00000000 ____D () C:\Program Files\Common Files\System 2015-01-24 20:00 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\rescache 2015-01-24 19:33 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-01-24 19:07 - 2015-01-07 10:55 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works 2015-01-24 19:05 - 2014-10-07 15:03 - 00000000 ____D () C:\Windows\System32\MRT 2015-01-22 12:27 - 2014-10-06 13:08 - 00000000 ____D () C:\Users\Greg\AppData\Local\24DA50EF-5B24-4EF7-B680-27AF79B3FDFA.aplzod 2015-01-22 12:25 - 2014-10-05 08:50 - 00000000 ____D () C:\Windows\System32\Tasks\ASUS 2015-01-22 09:37 - 2014-10-05 15:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2015-01-20 17:31 - 2014-11-05 14:14 - 00000000 ____D () C:\Windows\AutoRearm 2015-01-20 17:31 - 2014-10-19 10:06 - 00000000 ____D () C:\ProgramData\Norton 2015-01-20 17:31 - 2014-10-10 10:51 - 00000000 ____D () C:\Users\Greg\AppData\Roaming\IrfanView 2015-01-20 17:31 - 2014-10-05 15:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server 2015-01-20 17:31 - 2010-11-20 23:16 - 00000000 ____D () C:\Windows\ShellNew 2015-01-20 17:31 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\AppCompat 2015-01-20 17:30 - 2014-10-05 15:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services 2015-01-20 17:30 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\registration 2015-01-20 16:12 - 2009-07-13 19:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2015-01-20 14:37 - 2014-10-05 08:27 - 00000000 ____D () C:\users\Greg 2015-01-20 10:26 - 2014-10-06 13:25 - 00000000 ____D () C:\Program Files (x86)\CD-LabelPrint 2015-01-18 16:59 - 2014-10-15 04:14 - 00000000 ____D () C:\Users\Public\Documents\Adobe 2015-01-09 08:18 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\System32\NDF Some content of TEMP: ==================== C:\Users\Greg\AppData\Local\Temp\a9utipp8.dll C:\Users\Greg\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgpssls.dll ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2015-02-06 10:03:57 Restore point made on: 2015-02-06 12:18:46 Restore point made on: 2015-02-06 15:00:59 Restore point made on: 2015-02-07 15:00:24 ==================== Memory info =========================== Percentage of memory in use: 4% Total physical RAM: 65476.55 MB Available physical RAM: 62220.99 MB Total Pagefile: 65474.75 MB Available Pagefile: 62215.88 MB Total Virtual: 8192 MB Available Virtual: 8191.88 MB ==================== Drives ================================ Drive c: (WINDOWS 7) (Fixed) (Total:232.79 GB) (Free:31.76 GB) NTFS Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (Programy) (Fixed) (Total:55.8 GB) (Free:11.1 GB) NTFS Drive h: (UNTITLED) (Removable) (Total:29.44 GB) (Free:28 GB) NTFS Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 55.9 GB) (Disk ID: 7D8A9516) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=55.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 7819FCE9) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 29.4 GB) (Disk ID: 00000000) Partition: GPT Partition Type. LastRegBack: 2015-02-02 16:32 ==================== End Of Log ============================