[RESOLVED] Infected with Bochrome virus!
Page 1 of 3 123 LastLast
Results 1 to 15 of 44

Thread: [RESOLVED] Infected with Bochrome virus!

  1. #1
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91

    Resolved [RESOLVED] Infected with Bochrome virus!

    Hi

    I downloaded something whilst browsing and ended up getting the bochrome virus. I followed instructions from how to geek on removal, but I think there are other malicous programs which have been installed as I noticed something called "charity engine" was also appearing under programs. I haven't deleted that yet as I don't see the point.

    I am unable to connect to the internet on the pc which is infected so I am writing this on my laptop just now.

    The pc is running windows 7 ultimate.

    I will paste the frst and addition logs below.

    Thanks Dash.

  2. #2
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-11-2015
    Ran by Graeme (administrator) on GRAEME-PC (22-11-2015 11:50:53)
    Running from C:\Users\Graeme\Desktop
    Loaded Profiles: Graeme (Available Profiles: Graeme)
    Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
    (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
    (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    (AMD) C:\Windows\System32\atiesrxx.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (cFos Software GmbH) C:\Program Files\ASRock\XFast LAN\spd.exe
    (Comodo) C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe
    (Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
    (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
    () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
    (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
    (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
    (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
    (COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
    (Intel Corporation) C:\Windows\System32\igfxpers.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (cFos Software GmbH) C:\Program Files\ASRock\XFast LAN\cfosspeed.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
    (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
    (Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe
    (Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe
    (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
    (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
    (Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit_manager.exe
    (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
    (FNet Co., Ltd.) C:\Program Files (x86)\XFastUsb\XFastUsb.exe
    (Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe
    (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
    (CANON INC.) C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
    (Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    (Charity Engine) C:\Program Files (x86)\BOINC\boinctray.exe
    (Charity Engine) C:\Program Files (x86)\BOINC\charityengine.exe
    (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
    (Charity Engine) C:\Program Files (x86)\BOINC\boinc.exe
    (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
    (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor)
    HKLM\...\Run: [XFast LAN] => C:\Program Files\ASRock\XFast LAN\cFosSpeed.exe [1441152 2011-07-04] (cFos Software GmbH)
    HKLM\...\Run: [THXCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
    HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2710856 2009-11-01] (CANON INC.)
    HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-09-03] (CANON INC.)
    HKLM\...\Run: [Cm108Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
    HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
    HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1757520 2014-12-08] (Bitdefender)
    HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1427648 2015-08-05] (COMODO)
    HKLM-x32\...\Run: [XFastUsb] => C:\Program Files (x86)\XFastUsb\XFastUsb.exe [4942336 2012-12-11] (FNet Co., Ltd.)
    HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909824 2011-05-19] (Creative Technology Ltd)
    HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [IJNetworkScanUtility] => C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2009-09-28] (CANON INC.)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [267792 2013-01-17] (Research In Motion Limited)
    HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
    HKLM-x32\...\Run: [boinctray] => C:\Program Files (x86)\BOINC\boinctray.exe [71312 2014-03-07] (Charity Engine)
    HKLM-x32\...\Run: [boincmgr] => C:\Program Files (x86)\BOINC\charityengine.exe [3757712 2014-03-07] (Charity Engine)
    HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-01-30] (Comodo Security Solutions, Inc.)
    Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
    HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2010-07-23] (Acresso Corporation)
    HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\...\Run: [AdobeBridge] => [X]
    HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-12-08] (Bitdefender)
    HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-08-13] (Bitdefender)
    HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\...\Run: [Bitdefender Wallet Application Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [615256 2014-08-13] (Bitdefender)
    HKU\S-1-5-18\...\Run: [Bitdefender Wallet Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-12-08] (Bitdefender)
    HKU\S-1-5-18\...\Run: [Bitdefender Wallet] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-08-13] (Bitdefender)
    HKU\S-1-5-18\...\Run: [Bitdefender Wallet Application Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [615256 2014-08-13] (Bitdefender)
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2015-11-21]
    ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-11-21]
    ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
    Startup: C:\Users\Graeme\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk [2015-11-21]
    ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100
    Tcpip\..\Interfaces\{017A0DDE-A8C3-4376-B42B-5DDDD88AFC4A}: [NameServer] 104.197.191.4
    Tcpip\..\Interfaces\{017A0DDE-A8C3-4376-B42B-5DDDD88AFC4A}: [DhcpNameServer] 194.168.4.100 194.168.8.100
    Tcpip\..\Interfaces\{701A80CF-1E6B-4529-BE11-E412315A4B2B}: [NameServer] 104.197.191.4
    Tcpip\..\Interfaces\{701A80CF-1E6B-4529-BE11-E412315A4B2B}: [DhcpNameServer] 192.168.9.1 192.168.9.1
    Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer] 104.197.191.4

    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKLM-x32 -> DefaultScope value is missing
    SearchScopes: HKU\S-1-5-21-4177724317-3960994671-2067847833-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLEP1&pc=SPLH
    SearchScopes: HKU\S-1-5-21-4177724317-3960994671-2067847833-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLEP1&pc=SPLH
    SearchScopes: HKU\S-1-5-21-4177724317-3960994671-2067847833-1000 -> {57C3C521-79F9-4717-8851-4E24769FF60F} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A4107735745&ie=UTF-8&q=&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A4107735745&q={searchTerms}
    BHO: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll [2014-08-13] (Bitdefender)
    BHO: avast! Online Security -> {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-19] (AVAST Software)
    BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-02-01] (Oracle Corporation)
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-19] (AVAST Software)
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-02-01] (Oracle Corporation)
    BHO-x32: Bitdefender Wallet -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll [2014-08-13] (Bitdefender)
    BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08] (CANON INC.)
    BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-02-01] (Oracle Corporation)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-02-01] (Oracle Corporation)
    Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-19] (AVAST Software)
    Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-19] (AVAST Software)
    Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)

    FireFox:
    ========
    FF ProfilePath: C:\Users\Graeme\AppData\Roaming\Mozilla\Firefox\Profiles\9jr28qyr.default
    FF NewTab: www.google.com
    FF DefaultSearchEngine: Yahoo!
    FF SearchEngineOrder.1: Google
    FF SelectedSearchEngine: Yahoo!
    FF Homepage: hxxps://www.malwarebytes.org/restorebrowser/yhp-ff
    www.google.com
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
    FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-02-01] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-02-01] (Oracle Corporation)
    FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2012-12-13] (Microsoft Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
    FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-02-04] (CANON INC.)
    FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-02-01] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-02-01] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2012-12-13] (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
    FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2012-12-13] ()
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-12-09] (VideoLAN)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-4177724317-3960994671-2067847833-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Graeme\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-11-14] (Citrix Online)
    FF user.js: detected! => C:\Users\Graeme\AppData\Roaming\Mozilla\Firefox\Profiles\9jr28qyr.default\user.js [2015-11-21]
    FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman
    FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman [2014-05-22] [not signed]

    Chrome:
    =======
    CHR HomePage: Default -> hxxps://www.google.com/
    CHR StartupUrls: Default -> "hxxp://www.google.com/"
    CHR Profile: C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Google Docs) - C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
    CHR Extension: (Google Drive) - C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25]
    CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-11-20]
    CHR Extension: (YouTube) - C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
    CHR Extension: (Google Search) - C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
    CHR Extension: (Google Docs Offline) - C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-20]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24]
    CHR Extension: (Gmail) - C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
    CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx [2014-12-08]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 Blackberry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [577536 2013-01-18] (Research In Motion Limited) [File not signed]
    R2 cFosSpeedS; C:\Program Files\ASRock\XFast LAN\spd.exe [395136 2011-07-04] (cFos Software GmbH)
    R2 ChromodoUpdater; C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [1995448 2015-05-25] (Comodo)
    R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70872 2015-03-05] (Comodo Security Solutions, Inc.)
    R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5542472 2015-09-03] (COMODO)
    S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-08-05] (COMODO)
    R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-01-30] (Comodo Security Solutions, Inc.)
    R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2009-09-08] ()
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)
    S3 OpenVPNService; C:\Program Files (x86)\HMA! Pro VPN\bin\openvpnserv.exe [36352 2012-11-19] () [File not signed]
    R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
    R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
    S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
    R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2014-08-13] (Bitdefender)
    R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1538672 2014-12-08] (Bitdefender)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
    S2 SmartViewService; C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [X]

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1288472 2014-12-08] (BitDefender)
    S3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [263032 2014-12-08] (BitDefender)
    R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [647752 2014-08-13] (BitDefender)
    R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
    S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
    R1 bsdriver; C:\Windows\system32\drivers\bsdriver.sys [34720 2015-11-21] ()
    R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21184 2015-11-18] (COMODO)
    R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [806032 2015-11-18] (COMODO)
    R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45856 2015-08-05] (COMODO)
    S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R3 FNETTBOH_305; C:\Windows\System32\drivers\FNETTBOH_305.SYS [31808 2013-01-14] (FNet Co., Ltd.)
    R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2012-12-11] (FNet Co., Ltd.)
    R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
    R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [105096 2015-08-05] (COMODO)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
    S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
    R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
    R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [452040 2014-12-08] (BitDefender S.R.L.)
    S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
    S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
    S3 VGPU; System32\drivers\rdvgkmd.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

  3. #3
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-11-22 11:50 - 2015-11-22 11:51 - 00024241 _____ C:\Users\Graeme\Desktop\FRST.txt
    2015-11-22 11:50 - 2015-11-22 11:50 - 00000000 ____D C:\FRST
    2015-11-22 11:42 - 2015-11-22 11:49 - 02345984 _____ (Farbar) C:\Users\Graeme\Desktop\FRST64.exe
    2015-11-21 18:47 - 2015-11-22 11:46 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat
    2015-11-21 18:47 - 2015-11-21 18:49 - 00000000 ____D C:\Windows\System32\Tasks\COMODO
    2015-11-21 18:47 - 2015-11-21 18:47 - 00001872 _____ C:\Users\Public\Desktop\COMODO Antivirus.lnk
    2015-11-21 18:44 - 2015-11-21 18:44 - 00000000 ____D C:\ProgramData\Shared Space
    2015-11-21 18:42 - 2015-11-21 18:44 - 00000000 ____D C:\Program Files\COMODO
    2015-11-21 18:42 - 2015-11-21 18:42 - 00002013 _____ C:\Users\Public\Desktop\GeekBuddy.lnk
    2015-11-21 18:41 - 2015-11-21 18:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
    2015-11-21 18:41 - 2015-11-21 18:41 - 00001086 _____ C:\Users\Public\Desktop\Internet (Chromodo).lnk
    2015-11-21 18:41 - 2015-11-21 18:41 - 00000000 ____D C:\Users\Graeme\AppData\Local\Comodo
    2015-11-21 18:41 - 2015-11-21 18:41 - 00000000 ____D C:\Program Files (x86)\Comodo
    2015-11-21 18:39 - 2015-11-21 18:47 - 00000000 ____D C:\ProgramData\Comodo
    2015-11-21 18:36 - 2015-11-21 18:38 - 217812536 _____ (COMODO) C:\Users\Graeme\Downloads\cav_installer_3264_29.exe
    2015-11-21 18:02 - 2015-11-21 18:03 - 00000000 ____D C:\AdwCleaner
    2015-11-21 18:01 - 2015-11-21 18:01 - 00001049 _____ C:\Users\Graeme\Desktop\mwb.txt
    2015-11-21 17:42 - 2015-11-21 17:42 - 00004672 _____ C:\Windows\SysWOW64\Jeiiidsu.ini
    2015-11-21 17:42 - 2015-11-21 17:42 - 00002384 _____ C:\Windows\SysWOW64\JeiiidsuOff.ini
    2015-11-21 17:42 - 2015-11-21 17:42 - 00002384 _____ C:\Windows\system32\JeiiidsuOff.ini
    2015-11-21 17:41 - 2015-11-21 18:22 - 00000000 ____D C:\Users\Graeme\AppData\LocalLow\Company
    2015-11-21 17:41 - 2015-11-21 18:22 - 00000000 ____D C:\Program Files\shopperz201120152254
    2015-11-21 17:41 - 2015-11-21 18:01 - 00000000 ____D C:\Users\Graeme\AppData\Roaming\RunDir
    2015-11-21 17:41 - 2015-11-21 17:42 - 00000000 ____D C:\Users\Graeme\AppData\Local\Tempfolder
    2015-11-21 17:41 - 2015-11-21 17:41 - 00034720 _____ () C:\Windows\system32\Drivers\bsdriver.sys
    2015-11-21 17:41 - 2015-11-21 17:41 - 00003342 _____ C:\Windows\System32\Tasks\Kunriij
    2015-11-21 17:41 - 2015-11-21 17:41 - 00000000 ____D C:\Windows\system32\rafr
    2015-11-21 17:41 - 2015-11-21 17:41 - 00000000 ____D C:\uninst
    2015-11-21 17:40 - 2015-11-21 17:40 - 00000008 _____ C:\END
    2015-11-21 17:39 - 2015-11-22 11:47 - 00000344 ____H C:\Windows\Tasks\VAYYQMLPLLUYNYFW.job
    2015-11-21 17:39 - 2015-11-21 18:03 - 00001060 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-11-21 17:39 - 2015-11-21 17:40 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-11-21 17:39 - 2015-11-21 17:39 - 22908888 _____ (Malwarebytes ) C:\Users\Graeme\Downloads\mbam-setup-2.2.0.1024.exe
    2015-11-21 17:39 - 2015-11-21 17:39 - 00003380 _____ C:\Windows\System32\Tasks\VAYYQMLPLLUYNYFW
    2015-11-21 17:39 - 2015-11-21 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2015-11-21 17:39 - 2015-11-21 17:39 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
    2015-11-21 17:39 - 2015-11-21 17:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-11-21 17:39 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-11-21 17:39 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2015-11-21 17:39 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2015-11-21 17:35 - 2015-11-21 18:03 - 00002156 _____ C:\Users\Graeme\Desktop\chrome.lnk
    2015-11-21 17:34 - 2015-11-21 17:34 - 00003112 _____ C:\Windows\System32\Tasks\CGN
    2015-11-21 17:30 - 2015-11-21 17:30 - 00000000 ____D C:\Users\Graeme\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Charity Engine
    2015-11-21 17:30 - 2015-11-21 17:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    2015-11-21 17:30 - 2015-11-21 17:30 - 00000000 ____D C:\Program Files (x86)\7-Zip
    2015-11-21 17:30 - 2014-01-18 16:17 - 00000027 _____ C:\Windows\system32\Drivers\etc\hp.bak
    2015-11-21 17:29 - 2015-11-22 11:50 - 00000000 ____D C:\ProgramData\BOINC
    2015-11-21 17:29 - 2015-11-21 17:30 - 00000000 ____D C:\Program Files (x86)\BOINC
    2015-11-21 17:29 - 2015-11-21 17:29 - 00000000 ____D C:\Windows\Downloaded Installations
    2015-11-21 17:28 - 2015-11-21 17:28 - 00003912 _____ C:\Windows\System32\Tasks\3c91fcc2-ce59-42b3-b901-f68079520898
    2015-11-21 17:27 - 2015-11-21 17:27 - 00000000 ____D C:\Users\Graeme\Desktop\New folder (3)
    2015-11-20 23:10 - 2015-05-22 08:41 - 00000279 _____ C:\Users\Graeme\Desktop\NEW-VERSION-v1.1.txt
    2015-11-20 23:10 - 2014-05-24 06:04 - 02537472 _____ C:\Users\Graeme\Desktop\YIFY-Codec-Pack-v1.0.exe
    2015-11-20 23:09 - 2015-11-20 23:09 - 02538281 _____ C:\Users\Graeme\Downloads\YIFY-Codec-Pack-v1.0.zip
    2015-11-20 22:49 - 2015-11-20 22:49 - 00008718 _____ C:\Users\Graeme\Downloads\[kat.cr]dope.2015.720p.brrip.x264.yify.torrent
    2015-11-20 22:41 - 2015-11-20 22:42 - 00000000 ____D C:\Users\Graeme\Desktop\New folder (2)
    2015-11-20 22:19 - 2015-11-20 22:19 - 00033634 _____ C:\Users\Graeme\Downloads\Suffragette (2015) 720p BluRay x264 YIFY.torrent
    2015-11-20 20:57 - 2015-11-21 17:41 - 00061344 _____ (Cherimoya Ltd) C:\Windows\system32\Drivers\cherimoya.sys
    2015-11-20 18:24 - 2015-11-20 18:24 - 00000058 _____ C:\Users\Graeme\Documents\lottol.txt
    2015-11-18 17:14 - 2015-11-18 17:14 - 00806032 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys
    2015-11-18 17:14 - 2015-11-18 17:14 - 00021184 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys
    2015-11-15 12:19 - 2015-11-03 17:55 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2015-11-11 11:56 - 2015-10-20 18:42 - 03168768 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-11-11 11:56 - 2015-10-20 18:42 - 02608128 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-11-11 11:56 - 2015-10-20 18:42 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-11-11 11:56 - 2015-10-20 18:42 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-11-11 11:56 - 2015-10-20 18:42 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-11-11 11:56 - 2015-10-20 18:42 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-11-11 11:56 - 2015-10-20 18:42 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-11-11 11:56 - 2015-10-20 18:41 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-11-11 11:56 - 2015-10-20 18:41 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-11-11 11:56 - 2015-10-20 18:41 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-11-11 11:56 - 2015-10-20 18:41 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-11-11 11:56 - 2015-10-20 17:46 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-11-11 11:56 - 2015-10-20 17:46 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-11-11 11:56 - 2015-10-20 17:46 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-11-11 11:56 - 2015-10-20 17:46 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-11-11 11:56 - 2015-10-20 17:45 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-11-11 11:55 - 2015-11-03 22:10 - 00390344 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2015-11-11 11:55 - 2015-11-03 21:51 - 00342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2015-11-11 11:55 - 2015-10-30 23:46 - 25818624 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2015-11-11 11:55 - 2015-10-30 23:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2015-11-11 11:55 - 2015-10-30 23:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2015-11-11 11:55 - 2015-10-30 23:25 - 02886656 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2015-11-11 11:55 - 2015-10-30 23:25 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2015-11-11 11:55 - 2015-10-30 23:25 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2015-11-11 11:55 - 2015-10-30 23:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2015-11-11 11:55 - 2015-10-30 23:24 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2015-11-11 11:55 - 2015-10-30 23:24 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2015-11-11 11:55 - 2015-10-30 23:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2015-11-11 11:55 - 2015-10-30 23:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2015-11-11 11:55 - 2015-10-30 23:13 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2015-11-11 11:55 - 2015-10-30 23:12 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2015-11-11 11:55 - 2015-10-30 23:12 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2015-11-11 11:55 - 2015-10-30 23:11 - 05990912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2015-11-11 11:55 - 2015-10-30 23:11 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2015-11-11 11:55 - 2015-10-30 23:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2015-11-11 11:55 - 2015-10-30 23:04 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2015-11-11 11:55 - 2015-10-30 23:01 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2015-11-11 11:55 - 2015-10-30 22:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2015-11-11 11:55 - 2015-10-30 22:53 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2015-11-11 11:55 - 2015-10-30 22:52 - 20331520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2015-11-11 11:55 - 2015-10-30 22:49 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2015-11-11 11:55 - 2015-10-30 22:49 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2015-11-11 11:55 - 2015-10-30 22:47 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2015-11-11 11:55 - 2015-10-30 22:46 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2015-11-11 11:55 - 2015-10-30 22:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2015-11-11 11:55 - 2015-10-30 22:45 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2015-11-11 11:55 - 2015-10-30 22:45 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2015-11-11 11:55 - 2015-10-30 22:44 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2015-11-11 11:55 - 2015-10-30 22:44 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2015-11-11 11:55 - 2015-10-30 22:42 - 02279936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2015-11-11 11:55 - 2015-10-30 22:39 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2015-11-11 11:55 - 2015-10-30 22:39 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2015-11-11 11:55 - 2015-10-30 22:37 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2015-11-11 11:55 - 2015-10-30 22:36 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2015-11-11 11:55 - 2015-10-30 22:36 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2015-11-11 11:55 - 2015-10-30 22:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2015-11-11 11:55 - 2015-10-30 22:34 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2015-11-11 11:55 - 2015-10-30 22:32 - 00720896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2015-11-11 11:55 - 2015-10-30 22:31 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2015-11-11 11:55 - 2015-10-30 22:29 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2015-11-11 11:55 - 2015-10-30 22:29 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2015-11-11 11:55 - 2015-10-30 22:28 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2015-11-11 11:55 - 2015-10-30 22:23 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2015-11-11 11:55 - 2015-10-30 22:22 - 14457856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2015-11-11 11:55 - 2015-10-30 22:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2015-11-11 11:55 - 2015-10-30 22:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2015-11-11 11:55 - 2015-10-30 22:18 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2015-11-11 11:55 - 2015-10-30 22:17 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2015-11-11 11:55 - 2015-10-30 22:17 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2015-11-11 11:55 - 2015-10-30 22:16 - 04527616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2015-11-11 11:55 - 2015-10-30 22:11 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2015-11-11 11:55 - 2015-10-30 22:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2015-11-11 11:55 - 2015-10-30 22:09 - 12854272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2015-11-11 11:55 - 2015-10-30 22:09 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2015-11-11 11:55 - 2015-10-30 22:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2015-11-11 11:55 - 2015-10-30 22:04 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2015-11-11 11:55 - 2015-10-30 21:53 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2015-11-11 11:55 - 2015-10-30 21:51 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2015-11-11 11:55 - 2015-10-30 21:48 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2015-11-11 11:55 - 2015-10-30 21:46 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2015-11-11 11:55 - 2015-10-20 01:12 - 05570496 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2015-11-11 11:55 - 2015-10-20 01:12 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2015-11-11 11:55 - 2015-10-20 01:12 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2015-11-11 11:55 - 2015-10-20 01:09 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2015-11-11 11:55 - 2015-10-20 01:06 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2015-11-11 11:55 - 2015-10-20 01:06 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2015-11-11 11:55 - 2015-10-20 01:06 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2015-11-11 11:55 - 2015-10-20 01:06 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2015-11-11 11:55 - 2015-10-20 01:05 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2015-11-11 11:55 - 2015-10-20 01:05 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2015-11-11 11:55 - 2015-10-20 01:05 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2015-11-11 11:55 - 2015-10-20 01:04 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2015-11-11 11:55 - 2015-10-20 01:04 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2015-11-11 11:55 - 2015-10-20 01:04 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2015-11-11 11:55 - 2015-10-20 01:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2015-11-11 11:55 - 2015-10-20 00:59 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:52 - 03991488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2015-11-11 11:55 - 2015-10-20 00:52 - 03935680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2015-11-11 11:55 - 2015-10-20 00:48 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2015-11-11 11:55 - 2015-10-20 00:45 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2015-11-11 11:55 - 2015-10-20 00:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2015-11-11 11:55 - 2015-10-20 00:44 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2015-11-11 11:55 - 2015-10-20 00:44 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2015-11-11 11:55 - 2015-10-20 00:44 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2015-11-11 11:55 - 2015-10-20 00:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2015-11-11 11:55 - 2015-10-20 00:44 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2015-11-11 11:55 - 2015-10-20 00:44 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2015-11-11 11:55 - 2015-10-20 00:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2015-11-11 11:55 - 2015-10-20 00:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-20 00:35 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-19 23:41 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
    2015-11-11 11:55 - 2015-10-19 23:40 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
    2015-11-11 11:55 - 2015-10-19 23:40 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
    2015-11-11 11:55 - 2015-10-19 23:29 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2015-11-11 11:55 - 2015-10-19 23:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2015-11-11 11:55 - 2015-10-19 23:27 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-19 23:27 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-19 23:27 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2015-11-11 11:55 - 2015-10-19 23:27 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2015-11-11 11:55 - 2015-09-23 13:15 - 00460776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
    2015-11-11 11:55 - 2015-09-23 13:15 - 00299632 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
    2015-11-11 11:55 - 2015-09-23 13:09 - 00251000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
    2015-11-11 11:54 - 2015-10-29 17:50 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
    2015-11-11 11:54 - 2015-10-29 17:50 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
    2015-11-11 11:54 - 2015-10-29 17:50 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
    2015-11-11 11:54 - 2015-10-29 17:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
    2015-11-11 11:54 - 2015-10-29 17:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shimeng.dll
    2015-11-11 11:54 - 2015-10-29 17:49 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apphelp.dll
    2015-11-11 11:54 - 2015-10-29 17:49 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
    2015-11-11 11:54 - 2015-10-13 16:41 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
    2015-11-11 11:54 - 2015-10-13 16:40 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
    2015-11-11 11:54 - 2015-10-13 04:57 - 00950720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
    2015-11-11 11:54 - 2015-10-01 18:00 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
    2015-11-11 11:54 - 2015-10-01 18:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
    2015-11-11 11:54 - 2015-10-01 17:50 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
    2015-11-10 12:19 - 2015-11-10 12:19 - 00272384 _____ C:\Users\Graeme\Downloads\higher_mech2.ppt
    2015-11-08 23:23 - 2015-11-08 23:23 - 01334699 _____ C:\Users\Graeme\Downloads\Lucrative Lists.zip
    2015-11-05 16:28 - 2015-11-05 16:28 - 00000000 __SHD C:\found.001
    2015-11-05 15:53 - 2015-11-05 15:53 - 00000000 _____ C:\Users\Graeme\AppData\Local\{0FFFD749-C39D-43C6-82A4-1F48B263AAF9}
    2015-11-02 21:00 - 2015-11-02 21:00 - 00000575 _____ C:\Users\Graeme\Desktop\optom.txt
    2015-10-25 20:21 - 2015-10-25 20:24 - 00000902 _____ C:\Users\Graeme\Desktop\phil.txt

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-11-22 11:51 - 2015-07-08 22:48 - 00000664 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-4177724317-3960994671-2067847833-1000.job
    2015-11-22 11:51 - 2012-12-10 16:44 - 01693642 _____ C:\Windows\WindowsUpdate.log
    2015-11-22 11:51 - 2009-07-14 04:51 - 00314743 _____ C:\Windows\setupact.log
    2015-11-22 11:47 - 2013-01-14 22:11 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-11-22 11:46 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-11-22 11:23 - 2012-12-12 21:26 - 00000000 ____D C:\Users\Graeme\AppData\Local\Adobe
    2015-11-22 11:23 - 2009-07-14 04:45 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-11-22 11:23 - 2009-07-14 04:45 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-11-22 11:12 - 2012-12-13 10:18 - 00699592 _____ C:\Windows\PFRO.log
    2015-11-21 23:45 - 2013-01-14 22:11 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-11-21 23:41 - 2012-12-11 21:22 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-11-21 23:39 - 2014-02-03 19:59 - 00000568 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-4177724317-3960994671-2067847833-1000.job
    2015-11-21 18:28 - 2014-06-11 18:28 - 00000034 _____ C:\Windows\AvastEmUpdate.ini
    2015-11-21 18:26 - 2009-07-14 05:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
    2015-11-21 18:24 - 2012-12-10 17:23 - 00001417 _____ C:\Users\Graeme\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-11-21 18:22 - 2009-07-14 04:45 - 05060488 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-11-21 18:04 - 2014-02-20 21:04 - 00001139 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
    2015-11-21 18:04 - 2014-02-20 21:03 - 00001231 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk
    2015-11-21 18:04 - 2014-02-20 21:02 - 00001193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
    2015-11-21 18:04 - 2014-02-20 21:02 - 00001101 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
    2015-11-21 18:04 - 2014-02-20 21:00 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
    2015-11-21 18:04 - 2014-02-20 21:00 - 00001377 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
    2015-11-21 18:04 - 2014-02-01 17:02 - 00001061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
    2015-11-21 18:04 - 2014-01-11 17:57 - 00000995 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat_com.lnk
    2015-11-21 18:04 - 2013-09-30 20:57 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
    2015-11-21 18:04 - 2012-12-30 22:05 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
    2015-11-21 18:04 - 2012-12-12 21:05 - 00001786 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk
    2015-11-21 18:04 - 2012-12-11 21:20 - 00001151 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    2015-11-21 18:04 - 2012-12-10 16:46 - 00001333 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
    2015-11-21 18:04 - 2012-12-10 16:46 - 00001314 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
    2015-11-21 18:04 - 2009-07-14 04:57 - 00001511 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-11-21 18:04 - 2009-07-14 04:57 - 00001292 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
    2015-11-21 18:04 - 2009-07-14 04:57 - 00001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
    2015-11-21 18:04 - 2009-07-14 04:54 - 00001198 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
    2015-11-21 18:03 - 2015-10-12 18:14 - 00000933 _____ C:\Users\Graeme\Desktop\Plus500.lnk
    2015-11-21 18:03 - 2015-07-18 19:34 - 00002130 _____ C:\Users\Graeme\Desktop\Minecraft.lnk
    2015-11-21 18:03 - 2015-02-15 10:57 - 00001119 _____ C:\Users\Graeme\Desktop\Five Nights at Freddy's 2 v1.0.lnk
    2015-11-21 18:03 - 2015-01-07 18:21 - 00002483 _____ C:\Users\Public\Desktop\inSSIDer Home.lnk
    2015-11-21 18:03 - 2014-09-03 19:19 - 00001045 _____ C:\Users\Public\Desktop\tuxguitar.lnk
    2015-11-21 18:03 - 2014-06-16 12:10 - 00001777 _____ C:\Users\Public\Desktop\iTunes.lnk
    2015-11-21 18:03 - 2014-06-11 18:32 - 00002184 _____ C:\Users\Public\Desktop\Bitdefender Safepay.lnk
    2015-11-21 18:03 - 2014-06-11 18:32 - 00002065 _____ C:\Users\Public\Desktop\Bitdefender Antivirus Plus.lnk
    2015-11-21 18:03 - 2014-03-29 15:30 - 00002691 _____ C:\Users\Public\Desktop\Skype.lnk
    2015-11-21 18:03 - 2014-02-02 17:12 - 00002225 _____ C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
    2015-11-21 18:03 - 2014-01-11 18:25 - 00001086 _____ C:\Users\Graeme\Desktop\Microsoft Expression Web 4.lnk
    2015-11-21 18:03 - 2014-01-11 17:57 - 00000989 _____ C:\Users\Public\Desktop\Acrobat_com.lnk
    2015-11-21 18:03 - 2014-01-11 17:47 - 00001059 _____ C:\Users\Graeme\Desktop\Notepad++.lnk
    2015-11-21 18:03 - 2013-10-29 11:04 - 00002805 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Dragon NaturallySpeaking 11.0.lnk
    2015-11-21 18:03 - 2013-10-29 11:04 - 00002793 _____ C:\Users\Public\Desktop\Dragon NaturallySpeaking 11.0.lnk
    2015-11-21 18:03 - 2013-10-29 11:04 - 00001866 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Software Updates.lnk
    2015-11-21 18:03 - 2013-10-28 19:12 - 00001170 _____ C:\Users\Public\Desktop\Snagit 11 Editor.lnk
    2015-11-21 18:03 - 2013-10-28 19:12 - 00001126 _____ C:\Users\Public\Desktop\Snagit 11.lnk
    2015-11-21 18:03 - 2013-10-26 22:57 - 00001162 _____ C:\Users\Public\Desktop\Camtasia Studio 8.lnk
    2015-11-21 18:03 - 2013-03-23 22:44 - 00000000 ____D C:\Users\Graeme\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
    2015-11-21 18:03 - 2013-03-23 14:30 - 00001149 _____ C:\Users\Public\Desktop\HMA! Pro VPN.lnk
    2015-11-21 18:03 - 2013-02-24 23:06 - 00001193 _____ C:\Users\Graeme\Desktop\FileZilla.lnk
    2015-11-21 18:03 - 2013-02-23 00:05 - 00001222 _____ C:\Users\Graeme\AppData\Roaming\Microsoft\Windows\Start Menu\Audio Converter Uninstall Audio Converter.lnk
    2015-11-21 18:03 - 2013-02-23 00:05 - 00001109 _____ C:\Users\Graeme\AppData\Roaming\Microsoft\Windows\Start Menu\Audio Converter Audio Converter.lnk
    2015-11-21 18:03 - 2013-02-13 14:19 - 00002091 _____ C:\Users\Public\Desktop\Canon Easy-PhotoPrint EX.lnk
    2015-11-21 18:03 - 2013-02-13 14:18 - 00002093 _____ C:\Users\Public\Desktop\Canon MP Navigator EX 3.1.lnk
    2015-11-21 18:03 - 2013-02-04 22:17 - 00002007 _____ C:\Users\Public\Desktop\Canon IJ Network Tool.lnk
    2015-11-21 18:03 - 2013-02-04 20:24 - 00002052 _____ C:\Users\Public\Desktop\Canon MX340 series User Registration.LNK
    2015-11-21 18:03 - 2013-02-04 18:20 - 00002037 _____ C:\Users\Public\Desktop\Canon Solution Menu.lnk
    2015-11-21 18:03 - 2013-02-04 18:18 - 00002180 _____ C:\Users\Public\Desktop\Canon MX340 series On-screen Manual.lnk
    2015-11-21 18:03 - 2013-02-04 18:18 - 00001834 _____ C:\Users\Public\Desktop\Canon My Printer.lnk
    2015-11-21 18:03 - 2013-02-03 20:39 - 00001232 _____ C:\Users\Graeme\Desktop\ConvertXtoDVD 4.lnk
    2015-11-21 18:03 - 2013-02-03 20:25 - 00002909 _____ C:\Users\Public\Desktop\Nero Burning ROM 10.lnk
    2015-11-21 18:03 - 2013-01-29 12:58 - 00001162 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
    2015-11-21 18:03 - 2012-12-30 22:05 - 00002013 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
    2015-11-21 18:03 - 2012-12-25 21:24 - 00000936 _____ C:\Users\Graeme\Desktop\Guitar Pro 5.lnk
    2015-11-21 18:03 - 2012-12-24 15:58 - 00000430 _____ C:\Users\Graeme\Desktop\CD Drive - Shortcut.lnk
    2015-11-21 18:03 - 2012-12-15 20:00 - 00001064 _____ C:\Users\Public\Desktop\VLC media player.lnk
    2015-11-21 18:03 - 2012-12-12 21:05 - 00001780 _____ C:\Users\Public\Desktop\Vuze.lnk
    2015-11-21 18:03 - 2012-12-11 21:20 - 00001145 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2015-11-21 18:03 - 2012-12-11 19:24 - 00001883 _____ C:\Users\Public\Desktop\XFast USB.LNK
    2015-11-21 18:03 - 2012-12-11 19:24 - 00001130 _____ C:\Users\Public\Desktop\ASRock eXtreme Tuner.lnk
    2015-11-21 18:03 - 2012-12-11 19:24 - 00001114 _____ C:\Users\Public\Desktop\ASRock InstantBoot.lnk
    2015-11-21 18:03 - 2009-07-14 05:01 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
    2015-11-21 18:03 - 2009-07-14 04:49 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
    2015-11-21 17:42 - 2013-03-23 22:52 - 00000000 ____D C:\Users\Graeme\AppData\Local\CrashDumps
    2015-11-21 17:34 - 2012-12-11 19:26 - 00117784 _____ C:\Users\Graeme\AppData\Local\GDIPFONTCACHEV1.DAT
    2015-11-21 17:09 - 2009-07-14 05:13 - 00006206 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-11-21 16:10 - 2015-09-20 13:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
    2015-11-21 16:10 - 2012-12-11 21:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
    2015-11-20 23:21 - 2012-12-12 21:05 - 00000000 ____D C:\Users\Graeme\AppData\Roaming\Azureus
    2015-11-20 23:16 - 2012-12-15 22:21 - 00000000 ____D C:\Users\Graeme\AppData\Roaming\vlc
    2015-11-15 23:09 - 2013-01-14 22:37 - 00020899 _____ C:\Users\Graeme\Documents\Slates new school term 2011.txt
    2015-11-11 22:35 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\rescache
    2015-11-11 13:43 - 2013-08-17 01:07 - 00000000 ____D C:\Windows\system32\MRT
    2015-11-11 13:41 - 2012-12-11 21:22 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-11-11 13:41 - 2012-12-11 21:22 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-11-11 13:41 - 2012-12-11 21:22 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2015-11-11 13:37 - 2013-01-15 17:43 - 00000000 ____D C:\ProgramData\Microsoft Help
    2015-11-11 13:37 - 2012-12-11 21:51 - 145617392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2015-11-11 13:29 - 2009-07-14 07:46 - 00000000 ____D C:\Program Files\Windows Journal
    2015-11-10 13:28 - 2015-01-12 19:01 - 00000000 ____D C:\Users\Graeme\Documents\Ucas
    2015-11-07 15:19 - 2015-07-18 19:34 - 00000000 ____D C:\Users\Graeme\AppData\Roaming\.minecraft
    2015-11-05 17:33 - 2015-07-08 22:48 - 00003694 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-4177724317-3960994671-2067847833-1000
    2015-11-05 17:33 - 2014-02-03 19:59 - 00003598 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-4177724317-3960994671-2067847833-1000

  4. #4
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    2015-11-05 17:10 - 2013-02-04 22:18 - 00000000 ____D C:\ProgramData\CanonIJPLM
    2015-11-03 16:31 - 2009-07-14 05:32 - 00000000 ____D C:\Windows\system32\FxsTmp
    2015-11-03 10:37 - 2013-07-02 12:03 - 00000000 ____D C:\ProgramData\CanonIJ
    2015-11-01 19:04 - 2014-12-27 14:43 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
    2015-10-25 20:59 - 2015-08-12 19:47 - 00000000 ____D C:\Users\Graeme\Desktop\Access

    ==================== Files in the root of some directories =======

    2014-01-18 15:59 - 2014-01-18 15:59 - 0000055 _____ () C:\Users\Graeme\AppData\Roaming\mbam.context.scan
    2014-02-02 17:15 - 2014-02-04 14:06 - 0000308 _____ () C:\Users\Graeme\AppData\Roaming\Rim.Desktop.Exception.log
    2014-02-02 17:12 - 2014-02-02 17:12 - 0001153 _____ () C:\Users\Graeme\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
    2014-02-02 17:15 - 2014-02-04 14:06 - 0000308 _____ () C:\Users\Graeme\AppData\Roaming\Rim.DesktopHelper.Exception.log
    2013-10-17 21:06 - 2014-03-16 17:52 - 0001515 _____ () C:\Users\Graeme\AppData\Roaming\SAS7_000.DAT
    2014-01-18 19:56 - 2015-06-27 22:27 - 0001057 _____ () C:\Users\Graeme\AppData\Roaming\vso_ts_preview.xml
    2013-08-10 23:05 - 2014-01-06 01:05 - 0000128 _____ () C:\Users\Graeme\AppData\Roaming\WB.CFG
    2014-01-01 00:05 - 2014-01-03 00:38 - 0000005 _____ () C:\Users\Graeme\AppData\Roaming\WBPU-Q5-TTL.DAT
    2013-06-18 23:05 - 2014-01-06 01:05 - 0000005 _____ () C:\Users\Graeme\AppData\Roaming\WBPU-TTL.DAT
    2013-03-20 13:24 - 2015-02-23 19:59 - 0004608 _____ () C:\Users\Graeme\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2012-12-11 19:24 - 2012-12-11 19:24 - 0000003 _____ () C:\Users\Graeme\AppData\Local\user_data.ini
    2015-11-05 15:53 - 2015-11-05 15:53 - 0000000 _____ () C:\Users\Graeme\AppData\Local\{0FFFD749-C39D-43C6-82A4-1F48B263AAF9}
    2015-02-22 00:57 - 2015-02-22 00:57 - 0000000 _____ () C:\Users\Graeme\AppData\Local\{4CD20769-BC11-455F-B76A-F1DCBD57F4D2}
    2014-11-27 22:00 - 2014-11-27 22:00 - 0000000 _____ () C:\Users\Graeme\AppData\Local\{93158290-58E7-4B79-82BE-0DFB15EE72F2}
    2015-04-05 17:35 - 2015-04-05 17:35 - 0000000 _____ () C:\Users\Graeme\AppData\Local\{FC63106A-BA7D-43F7-BD09-55D59BCDB789}
    2014-06-11 18:52 - 2014-06-11 18:52 - 0483351 _____ () C:\ProgramData\1402511271.bdinstall.bin

    Some files in TEMP:
    ====================
    C:\Users\Graeme\AppData\Local\Temp\i4jdel0.exe
    C:\Users\Graeme\AppData\Local\Temp\install_flashplayer15x32au_mssa_aaa_aih.exe
    C:\Users\Graeme\AppData\Local\Temp\SpOrder.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10010.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10038.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10290.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10296.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10330.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10351.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10474.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10757.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10829.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite10921.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite11007.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite11039.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite11648.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite11853.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite11948.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite12246.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite12549.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite13107.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite13215.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite13248.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite13515.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite13776.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite13857.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite13868.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite14115.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite14173.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite14318.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite14423.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite14451.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite14617.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite15298.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite15363.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite15700.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite15779.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite15792.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite16615.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite16664.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite16692.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite16767.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite16939.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite16950.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite17172.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite17209.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite17908.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite18000.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite18047.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite18514.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite18794.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite18864.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite19016.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite19025.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite19214.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite19543.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite19597.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite19660.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite19725.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite19811.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite20068.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite20073.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite20236.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite20444.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite20764.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite20821.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite21019.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite21272.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite21408.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite21616.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite21869.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite21958.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite22328.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite22669.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite22833.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite23133.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite23191.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite23315.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite23447.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite23652.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite23724.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite23814.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite24246.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite24418.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite25435.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite25463.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite25732.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite26047.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite26079.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite26355.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite26624.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite26915.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite26951.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite26965.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27010.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27187.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27340.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27435.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27537.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27568.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27610.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27624.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite27637.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite28285.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite28407.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite28693.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite29229.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite29257.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite29981.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite30037.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite30043.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite30070.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite30977.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite31451.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite32017.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite32078.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite32184.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite32387.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite32423.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite32855.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite32890.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite33228.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite33283.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite33334.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite33740.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite33942.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite33962.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite34038.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite34142.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite34147.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite34603.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite34945.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite35242.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite35250.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite35343.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite35561.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite35617.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite35661.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite35942.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite35980.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36133.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36505.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36575.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36608.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36752.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36803.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36850.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36872.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36931.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36934.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36969.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite36981.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite37008.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite37125.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite37602.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite37692.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite37919.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite38047.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite38139.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite38158.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite38588.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite38633.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite38972.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39061.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39066.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39096.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39114.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39211.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39497.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39772.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39913.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite39958.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40030.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40175.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40294.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40416.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40482.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40688.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40693.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40966.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite40994.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite41066.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite41327.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite41438.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite41759.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite41813.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite41927.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42124.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42154.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42197.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42404.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42502.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42504.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42586.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42588.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42921.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42924.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42957.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite42988.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite43041.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite43166.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite43207.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite43782.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite43875.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite43924.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite43937.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite44315.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite44542.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite44576.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite44831.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite44849.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite45032.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite45468.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite45765.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite45768.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite45790.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite45958.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite46254.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite46640.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite46820.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite46897.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite47012.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite47282.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite47504.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite47665.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite47801.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite47834.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite48448.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite48490.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite49195.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite49264.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite49295.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite49448.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite49495.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite49682.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite49878.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite50608.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite50642.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite50767.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite50986.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite51130.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite51417.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite51747.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite52125.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite52300.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite52314.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite52706.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite52884.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite53163.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite53183.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite53261.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite53391.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite53403.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite53611.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite54041.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite54069.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite54564.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite54591.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite54742.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite55258.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite55655.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite56010.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite56194.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite56705.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite56711.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite56733.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57078.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57299.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57317.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57319.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57321.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57538.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57772.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57874.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite57936.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite58427.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite58718.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite58780.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite59005.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite59166.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite59244.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite59336.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite59807.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite59860.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite59963.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite60018.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite60228.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite60829.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite60910.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite61179.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite61279.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite61354.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite61402.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite61635.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62129.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62182.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62193.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62356.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62626.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62640.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62764.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62787.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite62840.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite63540.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite63615.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite63721.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite63793.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite63837.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite63995.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite64045.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite64264.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite64329.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite64709.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite64752.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite65004.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite65173.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite65306.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite65323.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite65533.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite66175.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite66223.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite66450.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite66647.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite66764.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite67084.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite67359.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite67820.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite67936.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite67975.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite68131.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite68201.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite68303.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite68508.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite68866.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite69555.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite70050.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite70084.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite70636.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite71394.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite71603.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite71974.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite72005.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite72042.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite72069.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite72705.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite73299.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite73319.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite74697.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite74760.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite74902.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite74956.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite75063.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite75130.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite75274.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite75499.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite75591.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite75688.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite76038.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite76285.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite76349.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite76351.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite76357.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite76921.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite77248.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite77773.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite77821.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite77926.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78101.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78274ca9-27f7-4d9a-a37c-309aef47e669.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78340.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78423.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78454.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78537.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78582.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78604.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78684.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78782.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite78801.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite79687.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite79829.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite80104.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite80673.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite80720.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite80984.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite81101.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite81251.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite81315.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite81334.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite81831.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite82195.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite82418.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite82426.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite82806.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite82889.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite83332.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite83717.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite84042.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite84051.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite84662.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite84955.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite85284.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite85590.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite86178.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite86234.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite86361.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite86364.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite86550.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite86781.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite87059.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite87430.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite87453.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite87544.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite87555.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite87828.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite87941.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite88105.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite88136.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite88194.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite88436.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite88758.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite88908.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite89017.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite89041.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite89057.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite89083.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite89294.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite90452.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite90646.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite90802.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite90829.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite90877.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite91172.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite91191.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite91510.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite91513.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite91931.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite91963.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite91969.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite92013.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite92354.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite92518.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite92787.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite92796.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite92926.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite92988.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite93145.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite93179.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite93188.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite93818.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite94154.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite94332.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite95629.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite95656.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite96212.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite96613.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite96679.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite96768.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite97423.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite97454.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite97468.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite97551.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite98162.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite98881.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite99023.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite99129.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite99245.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite99342.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite99354.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite99753.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLite99762.dll
    C:\Users\Graeme\AppData\Local\Temp\System.Data.SQLiteaf3875f7-85be-42cf-9f9e-4ce86f2b3fd0.dll


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll
    [2012-12-11 21:32] - [2012-12-11 21:32] - 0357888 ____A (Microsoft Corporation) A8BA0E7F52ACC191F3A00369C05E2468

    C:\Windows\SysWOW64\dnsapi.dll IS MISSING <==== ATTENTION
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-11-20 17:43

    ==================== End of FRST.txt ============================

  5. #5
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    Additional scan result of Farbar Recovery Scan Tool (x64) Version:20-11-2015
    Ran by Graeme (2015-11-22 11:52:22)
    Running from C:\Users\Graeme\Desktop
    Windows 7 Ultimate Service Pack 1 (X64) (2012-12-10 16:53:22)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-4177724317-3960994671-2067847833-500 - Administrator - Disabled)
    Graeme (S-1-5-21-4177724317-3960994671-2067847833-1000 - Administrator - Enabled) => C:\Users\Graeme
    Guest (S-1-5-21-4177724317-3960994671-2067847833-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-4177724317-3960994671-2067847833-1251 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Bitdefender Antivirus (Disabled - Out of date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
    AV: COMODO Antivirus (Enabled - Up to date) {F25D0092-CDBE-B303-ADB7-88DE8CDECCF5}
    AV: avast! Internet Security (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    AS: Bitdefender Antispyware (Disabled - Out of date) {2169F23C-E8EC-F7E5-3D9E-13A0D4A2E280}
    AS: Comodo Defense+ (Enabled - Up to date) {493CE176-EB84-BC8D-9707-B3ACF7598648}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: avast! Internet Security (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
    FW: avast! Internet Security (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    7-Zip 9.38 beta (HKLM-x32\...\7-Zip) (Version: - )
    Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
    Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
    Adobe Flash Player 19 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
    Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.245 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.13) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
    Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
    AMD Catalyst Install Manager (HKLM\...\{5E03A267-415E-5383-FA8F-3CE4145663B9}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
    Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    ASRock App Charger v1.0.4 (HKLM\...\ASRock App Charger_is1) (Version: - ASRock Inc.)
    ASRock eXtreme Tuner v0.1.98 (HKLM-x32\...\ASRock eXtreme Tuner_is1) (Version: - )
    ASRock InstantBoot v1.26 (HKLM-x32\...\ASRock InstantBoot_is1) (Version: - )
    Bitdefender Antivirus Plus (HKLM\...\Bitdefender) (Version: 17.28.0.1191 - Bitdefender)
    BlackBerry Desktop Software 7.1 (HKLM-x32\...\BlackBerry_Desktop) (Version: 7.1.0.41 - Research In Motion Ltd.)
    BlackBerry Desktop Software 7.1 (x32 Version: 7.1.0.41 - Research In Motion Ltd.) Hidden
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Broadcom Gigabit NetLink Controller (HKLM\...\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.6.1.3 - Broadcom Corporation)
    Camtasia Studio 8 (HKLM-x32\...\{BFA04EE0-8240-4667-8D53-45496A901C33}) (Version: 8.1.2.1327 - TechSmith Corporation)
    Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: - )
    Canon IJ Network Scan Utility (HKLM-x32\...\Canon_IJ_Network_Scan_UTILITY) (Version: - )
    Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: - )
    Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - )
    Canon MP Navigator EX 3.1 (HKLM-x32\...\MP Navigator EX 3.1) (Version: - )
    Canon MX340 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX340_series) (Version: - )
    Canon MX340 series User Registration (HKLM-x32\...\Canon MX340 series User Registration) (Version: - )
    Canon Speed Dial Utility (HKLM-x32\...\Speed Dial Utility) (Version: - )
    Canon Utilities Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )
    Canon Utilities My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
    Canon Utilities Solution Menu (HKLM-x32\...\CanonSolutionMenu) (Version: - )
    Charity Engine (HKLM-x32\...\{7309D717-F38D-436D-9537-066AA0AC7639}) (Version: 7.0.80 - Charity Engine)
    Chromodo (HKLM-x32\...\Chromodo) (Version: 42.1.2.91 - Comodo)
    Citrix Online Launcher (HKLM-x32\...\{DB014C85-A264-4BCA-A66F-6DD1FCF8EC36}) (Version: 1.0.335 - Citrix)
    COMODO Antivirus (HKLM\...\{04833277-EE61-4251-9273-0CF86C0FE710}) (Version: 8.2.0.4792 - COMODO Security Solutions Inc.)
    ConvertXtoDVD 4.1.19.365 (HKLM-x32\...\{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1) (Version: 4.1.19.365 - )
    CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1611_37043 - CyberLink Corp.)
    Dragon NaturallySpeaking 11 (HKLM-x32\...\{EFFA53BC-8C04-2E21-3D90-A13B1697B0CA}) (Version: 11.50.100 - Nuance Communications Inc.)
    Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.96 - Etron Technology)
    Etron USB3.0 Host Controller (x32 Version: 0.96 - Etron Technology) Hidden
    FileZilla Client 3.7.3 (HKLM-x32\...\FileZilla Client) (Version: 3.7.3 - Tim Kosse)
    Five Nights at Freddy's 2 v1.0 (HKLM-x32\...\Five Nights at Freddy's 2 v1.0_is1) (Version: - )
    GeekBuddy (HKLM\...\{266FA04F-F0FA-4F7A-AA1E-387A57F579F2}) (Version: 4.19.131 - Comodo Security Solutions Inc)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 46.0.2490.86 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
    GoToMeeting 7.4.1.3770 (HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\...\GoToMeeting) (Version: 7.4.1.3770 - CitrixOnline)
    Guitar Pro 5.2 (HKLM-x32\...\Guitar Pro 5_is1) (Version: - Arobas Music)
    HMA! Pro VPN 2.7.1.7 (HKLM-x32\...\HMA! Pro VPN) (Version: 2.7.1.7 - )
    inSSIDer Home (HKLM-x32\...\{9E54E4AE-B67A-4925-8E92-0E1F9817FD73}) (Version: 3.1.2.1 - MetaGeek, LLC)
    Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2372 - Intel Corporation)
    iTunes (HKLM\...\{5A68A656-979F-4168-8795-E2E368AA4DC2}) (Version: 11.2.2.3 - Apple Inc.)
    Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
    Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    marvell 91xx driver (HKLM-x32\...\MagniDriver) (Version: 1.2.0.1003 - Marvell)
    McAfee Security Scan Plus (HKLM-x32\...\McAfee Security Scan) (Version: 3.0.285.6 - McAfee, Inc.)
    Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
    Microsoft Expression Web 4 (HKLM-x32\...\Web_4.0.1460.0) (Version: 4.0.1460.0 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
    Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)
    Minecraft1.8 (HKLM-x32\...\Minecraft1.8) (Version: - )
    Mozilla Firefox 40.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 40.0.3 (x86 en-US)) (Version: 40.0.3 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
    Nero Burning ROM 10 (HKLM-x32\...\{7A5D731D-B4B3-490E-B339-75685712BAAB}) (Version: 10.2.11000.12.100 - Nero AG)
    Nero Burning ROM 10 (HKLM-x32\...\{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}) (Version: 10.5.10300 - Nero AG)
    Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10300.0.102 - Nero AG)
    Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
    Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.3 - Notepad++ Team)
    OpenOffice.org 3.4.1 (HKLM-x32\...\{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}) (Version: 3.41.9593 - Apache Software Foundation)
    PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
    Plus500 (HKLM-x32\...\Plus500) (Version: - )
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6392 - Realtek Semiconductor Corp.)
    Rome - Total War (HKLM-x32\...\{2E97F7E8-ABDE-4E0D-B0AD-B6B4BAD89E24}) (Version: 1.5 - The Creative Assembly)
    Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
    Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
    Snagit 11 (HKLM-x32\...\{7CA5C4DF-8327-4035-AE2B-CA76336A04FD}) (Version: 11.0.0 - TechSmith Corporation)
    Strongvault Online Backup (x32 Version: 5.0.2.34 - Strongvault Online Backup) Hidden <==== ATTENTION
    swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    THX TruStudio (HKLM-x32\...\{AFB907F5-C0E6-4753-8284-DE955EF86AC2}) (Version: 1.00.01 - Creative Technology Limited)
    TuxGuitar 1.2 (HKLM-x32\...\TuxGuitar_0) (Version: - )
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
    USB PnP Sound Device (HKLM\...\C-Media CM108 Like Sound Driver) (Version: - )
    USB PnP Sound Device (HKLM-x32\...\Generic USB 108 Sound) (Version: - )
    Visual C++ 9.0 Runtime for Dragon NaturallySpeaking 64bit (x64) (HKLM\...\{4A5A427F-BA39-4BF0-7777-9A47FBE60C9F}) (Version: 11.0.0 - Nuance Communications Inc.)
    VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN)
    Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.6.2.0 - Azureus Software, Inc.)
    WinRAR 4.20 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
    XAMPP (HKLM-x32\...\xampp) (Version: 1.8.2-3 - BitNami)
    XFast LAN v6.61 (HKLM\...\XFast LAN) (Version: 6.61 - cFos Software GmbH, Bonn)
    XFastUsb (HKLM-x32\...\XFastUsb) (Version: - )

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-4177724317-3960994671-2067847833-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Graeme\AppData\Local\Citrix\GoToMeeting\3019\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)

    ==================== Restore Points =========================

    07-11-2015 14:37:21 Windows Update
    11-11-2015 11:50:59 Windows Update
    11-11-2015 13:26:10 Windows Update
    15-11-2015 12:19:16 Windows Update
    15-11-2015 13:03:58 Windows Update
    20-11-2015 15:27:22 Windows Update
    21-11-2015 17:45:28 Removed Charity Engine.
    21-11-2015 18:28:50 Removed Charity Engine.
    21-11-2015 18:31:59 Removed Charity Engine.
    21-11-2015 18:43:57 Installing COMODO Antivirus
    21-11-2015 18:46:08 Device Driver Package Install: COMODO Network Service

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-03-12 19:50 - 2014-01-18 16:17 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts

    127.0.0.1 localhost

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {073FE9E0-5485-4F97-A285-E11A2542587E} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-05] (COMODO)
    Task: {17A7D2A7-58D0-4EA6-850C-9059468FAA43} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender\bdproductdata.exe [2015-07-29] (Bitdefender)
    Task: {23A48680-8E49-4054-BB70-228E977BA56F} - System32\Tasks\Kunriij => C:\PROGRA~1\SHOPPE~1\Igatgub.bat
    Task: {2A50CFAC-70C5-4C2D-A50C-0DF156DD5EC9} - \RocketTab Update Task -> No File <==== ATTENTION
    Task: {3F71FB64-3C06-40B1-9CD0-B7499A941281} - \SwiftSearch Auto Updater 1.10.0.25 Core -> No File <==== ATTENTION
    Task: {4251987B-06B8-4B0D-8CF1-B5A7E1FEBC91} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-05] (COMODO)
    Task: {503A965F-F048-4FFE-B162-E5AA2DB64EF3} - \crash_service -> No File <==== ATTENTION
    Task: {6D0AEDB9-D9EE-4E79-9FA1-949A3A796935} - \Run_Bobby_Browser -> No File <==== ATTENTION
    Task: {76EB7027-EAE1-4002-BC5A-2A330F5F0E18} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
    Task: {83053D08-4B94-40A3-B5D5-A5A8E2B77C83} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-02-19] (AVAST Software)
    Task: {91EFDC31-DFE8-4B4A-9E91-964DD3FD9A28} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-11-11] (Adobe Systems Incorporated)
    Task: {9352FAEA-4CE0-473E-9D2C-B47EBF97E21D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {993F7E7C-41EA-45DC-A8E5-C798371072D1} - System32\Tasks\VAYYQMLPLLUYNYFW => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
    Task: {9A98B2CA-0C46-495D-B236-FD5ADD6E409C} - System32\Tasks\CGN => C:\Program Files (x86)\Common Files\ClaraUpdater\ClaraUpdater.exe
    Task: {9F3BE0EB-CD76-4DA4-B0C6-A3AB76601BB1} - \CGINCVL1 -> No File <==== ATTENTION
    Task: {A62C6C4C-2A8C-4A66-91F3-157686B0098E} - System32\Tasks\AdobeAAMUpdater-1.0-Graeme-PC-Graeme => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated)
    Task: {B0F06A56-EE25-4246-A5E3-6CC0E58D3AB7} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-05] (COMODO)
    Task: {BE085556-7288-4CC2-85F1-0D61A47F802A} - System32\Tasks\G2MUpdateTask-S-1-5-21-4177724317-3960994671-2067847833-1000 => C:\Users\Graeme\AppData\Local\Citrix\GoToMeeting\3770\g2mupdate.exe [2015-11-05] (Citrix Online, a division of Citrix Systems, Inc.)
    Task: {CF1780B3-3C10-47C7-A987-E4C11E2AC06F} - \RocketTab -> No File <==== ATTENTION
    Task: {D419925E-585F-47F7-8767-34BF573B50AC} - \c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5 -> No File <==== ATTENTION
    Task: {D5D8E520-F775-4335-B6EC-C63A903CBBBA} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-08-05] (COMODO)
    Task: {D5FE29C3-985A-4880-8C0D-35868C11EC22} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-04-11] (CyberLink)
    Task: {D92CCAE2-4F6B-492A-8EC9-BA1F7DE98F70} - \c1bf95b7-9d21-4302-bbde-c1ab4ab9ccf5-5_user -> No File <==== ATTENTION
    Task: {E892F628-881C-4A80-B3A1-E06FD5586E9B} - System32\Tasks\3c91fcc2-ce59-42b3-b901-f68079520898 => C:\Users\Graeme\AppData\Local\Temp\ce98ac2e-20c0-4a93-86f6-bdb3e61caf55.exe <==== ATTENTION
    Task: {EB6BDD7D-3965-404B-8163-BEB9F4120504} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
    Task: {F1BFFB8D-B269-4B79-8D82-01BC44CC2EA5} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-05] (COMODO)
    Task: {F47ED277-801C-4A17-950B-B5C49887A2E9} - System32\Tasks\G2MUploadTask-S-1-5-21-4177724317-3960994671-2067847833-1000 => C:\Users\Graeme\AppData\Local\Citrix\GoToMeeting\3770\g2mupload.exe [2015-11-05] (Citrix Online, a division of Citrix Systems, Inc.)
    Task: {F7F52FA7-5DE5-4257-BB81-83400A2F8633} - \SwiftSearch Auto Updater 1.10.0.25 Pending Update -> No File <==== ATTENTION
    Task: {FFCA4688-2189-4A5E-A69F-D1FB1FB3C0BA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-4177724317-3960994671-2067847833-1000.job => C:\Users\Graeme\AppData\Local\Citrix\GoToMeeting\3770\g2mupdate.exe
    Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-4177724317-3960994671-2067847833-1000.job => C:\Users\Graeme\AppData\Local\Citrix\GoToMeeting\3770\g2mupload.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\VAYYQMLPLLUYNYFW.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION

    ==================== Loaded Modules (Whitelisted) ==============

    2014-08-13 14:12 - 2014-10-14 12:35 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender\txmlutil.dll
    2014-08-13 14:12 - 2014-08-13 14:12 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender\UI\accessl.ui
    2015-05-07 11:12 - 2015-05-07 11:12 - 00790368 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00350_009\ashttpbr.mdl
    2015-05-07 11:12 - 2015-05-07 11:12 - 00711064 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00350_009\ashttpdsp.mdl
    2015-05-07 11:12 - 2015-05-07 11:12 - 02683520 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00350_009\ashttpph.mdl
    2015-05-07 11:12 - 2015-05-07 11:12 - 01326504 _____ () C:\Program Files\Bitdefender\Bitdefender\otengines_00350_009\ashttprbl.mdl
    2013-02-04 22:18 - 2009-09-08 12:12 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
    2015-01-08 22:02 - 2015-01-08 22:02 - 00067808 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav
    2010-01-02 14:42 - 2010-01-02 14:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
    2012-12-11 19:16 - 2011-04-15 02:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
    2012-12-11 19:29 - 2011-05-19 09:58 - 00246784 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL
    2015-03-05 15:28 - 2015-03-05 15:28 - 01283800 _____ () C:\Program Files\COMODO\GeekBuddy\QtNetwork4.dll
    2015-03-05 15:28 - 2015-03-05 15:28 - 02875608 _____ () C:\Program Files\COMODO\GeekBuddy\QtCore4.dll
    2015-03-05 15:28 - 2015-03-05 15:28 - 10451672 _____ () C:\Program Files\COMODO\GeekBuddy\QtGui4.dll
    2015-03-05 15:28 - 2015-03-05 15:28 - 00039128 _____ () C:\Program Files\COMODO\GeekBuddy\imageformats\qgif4.dll
    2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-01-20 13:16 - 2014-01-20 13:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2014-10-14 12:35 - 2014-10-14 12:35 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender\antispam32\txmlutil.dll
    2012-08-10 16:51 - 2012-08-10 16:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
    2012-10-19 13:18 - 2012-10-19 13:18 - 00081920 _____ () C:\Program Files (x86)\BOINC\zlib1.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\ProgramData\Temp:0FF263E8
    AlternateDataStreams: C:\Users\Graeme\Desktop\FiveNightsatFreddys.exe:AGC
    AlternateDataStreams: C:\Users\Graeme\Desktop\FRST64.exe:$CmdTcID
    AlternateDataStreams: C:\Users\Graeme\Downloads\cav_installer_3264_29.exe:BDU
    AlternateDataStreams: C:\Users\Graeme\Downloads\ChromeSetup(1).exe:BDU
    AlternateDataStreams: C:\Users\Graeme\Downloads\FlDesktopHelpInstall.exe:BDU
    AlternateDataStreams: C:\Users\Graeme\Downloads\InstallPlus500.exe:BDU
    AlternateDataStreams: C:\Users\Graeme\Downloads\install_reader11_en_mssd_aaa_aih(1).exe:BDU
    AlternateDataStreams: C:\Users\Graeme\Downloads\mbam-setup-2.2.0.1024.exe:BDU
    AlternateDataStreams: C:\Users\Graeme\Downloads\Silverlight_x64.exe:BDU

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Jeiiidsu => ""="service"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\Control Panel\Desktop\\Wallpaper ->
    DNS Servers: 104.197.191.4
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [TCP Query User{06880039-5E4D-41A4-8122-4522D6754BEC}C:\program files\vuze\azureus.exe] => (Allow) C:\program files\vuze\azureus.exe
    FirewallRules: [UDP Query User{DF50B473-28E6-4279-ADC5-74DA7813664B}C:\program files\vuze\azureus.exe] => (Allow) C:\program files\vuze\azureus.exe
    FirewallRules: [{EC5B7519-E7E8-4840-9713-0183AB505073}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{57794611-7C27-4FBE-ABF4-B93E63FCC66B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{E6015DC2-F40D-4C9F-AC12-016CF55C784E}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{FF36CE9B-3128-46BF-A115-5FAD572B6417}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{1991753C-BE1E-4913-8483-DF35C75F4D83}] => (Allow) LPort=51001
    FirewallRules: [{015029F1-B876-4862-A000-CC2DD83BC070}] => (Allow) C:\Users\Graeme\AppData\Local\Temp\7zS25BC.tmp\SymNRT.exe
    FirewallRules: [{72289DB9-8C7D-48E7-952E-AAB0882737E4}] => (Allow) C:\Users\Graeme\AppData\Local\Temp\7zS25BC.tmp\SymNRT.exe
    FirewallRules: [{0BFB6582-9C1B-4D95-A6B0-083B1AA42618}] => (Allow) C:\Users\Graeme\AppData\Local\Temp\7zSD07C.tmp\SymNRT.exe
    FirewallRules: [{181DC390-4E47-4E37-B865-70E9C8C4285C}] => (Allow) C:\Users\Graeme\AppData\Local\Temp\7zSD07C.tmp\SymNRT.exe
    FirewallRules: [TCP Query User{DA511C7E-546E-499A-86C5-AEF5F4EF4F92}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
    FirewallRules: [UDP Query User{49167371-5CC0-4CF0-9763-5F182887443E}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
    FirewallRules: [TCP Query User{C6BC61C4-EA0D-4444-B9D6-F6B1C142FAB3}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
    FirewallRules: [UDP Query User{81BC555E-A75E-46FA-84AE-A9E96650CA0F}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe
    FirewallRules: [{E7B31604-3C97-4C67-AA2A-0EA1C8D14A77}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{F4F47625-C8B3-4B35-A4BC-04C252B352FD}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
    FirewallRules: [{5DA40B2F-0662-4D10-B960-30A82552B8F9}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
    FirewallRules: [{73C72D25-D22F-4DF3-9A4B-7F7C74C1F185}] => (Allow) LPort=4481
    FirewallRules: [{90A343FB-6EAE-489C-B1DA-73452307FCA9}] => (Allow) LPort=4481
    FirewallRules: [{EC508540-72A7-41E6-9BDF-997F1F211897}] => (Allow) LPort=4482
    FirewallRules: [{99AD59D3-3A54-49A5-9D8B-F4ECAB637067}] => (Allow) LPort=4482
    FirewallRules: [{196CBE08-E13F-4BA7-94DD-9DAC1CB5873B}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
    FirewallRules: [{2AD6E3B7-5315-4E49-9DE7-DD598844BF96}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [{E01BE7D5-4156-40ED-8551-C3F829BE16F8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [TCP Query User{697F50B7-494D-43AF-A0B1-8130E78E80BD}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
    FirewallRules: [UDP Query User{543599D9-F794-4FA6-8336-68394F660539}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
    FirewallRules: [{95D2FFBB-C5EB-4263-A072-6550EDAD47A8}] => (Allow) C:\Program Files\Vuze\Azureus.exe
    FirewallRules: [{3FC87A66-A4DD-4CBE-B122-FEA19D7366D3}] => (Allow) C:\Program Files\Vuze\Azureus.exe
    FirewallRules: [{F691E834-38A2-41B7-932D-3B1CF94CFF48}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    ==================== Faulty Device Manager Devices =============

    Name: Teredo Tunneling Pseudo-Interface
    Description: Microsoft Teredo Tunneling Adapter
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: Microsoft
    Service: tunnel
    Problem: : This device cannot start. (Code10)
    Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

    Name: TAP-Win32 Adapter V9
    Description: TAP-Win32 Adapter V9
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: TAP-Win32 Provider V9
    Service: tap0901
    Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
    Resolution: A registry problem was detected.
    This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
    Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: CisWmiSELECT * FROM CisFileRatingChangeCisFileRatingChange//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: CisWmiSELECT * FROM CisStatusChangeCisStatusChange//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: CisWmiSELECT * FROM CisNotificationCisNotification//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: CisWmiSELECT * FROM FwAlertFwAlert//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: CisWmiSELECT * FROM DfAlertDfAlert//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: CisWmiSELECT * FROM AvAlertAvAlert//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: CisWmiSELECT * FROM CisAlertCisAlert//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: CisWmiSELECT * FROM CisEventCisEvent//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: SELECT * FROM CisFileRatingChangeCisFileRatingChange//./root/cis

    Error: (11/21/2015 06:47:32 PM) (Source: WinMgmt) (EventID: 24) (User: )
    Description: SELECT * FROM CisStatusChangeCisStatusChange//./root/cis


    System errors:
    =============
    Error: (11/22/2015 11:51:43 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
    Description: There was an error while attempting to read the local hosts file.

    Error: (11/22/2015 11:51:28 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
    Description: There was an error while attempting to read the local hosts file.

    Error: (11/22/2015 11:51:25 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
    Description: There was an error while attempting to read the local hosts file.

    Error: (11/22/2015 11:51:24 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
    Description: There was an error while attempting to read the local hosts file.

    Error: (11/22/2015 11:50:32 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Intel(R) Management and Security Application User Notification Service service depends on the Intel(R) Management and Security Application Local Management Service service which failed to start because of the following error:
    %%1053

    Error: (11/22/2015 11:50:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Intel(R) Management and Security Application Local Management Service service failed to start due to the following error:
    %%1053

    Error: (11/22/2015 11:50:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
    Description: A timeout was reached (30000 milliseconds) while waiting for the Intel(R) Management and Security Application Local Management Service service to connect.

    Error: (11/22/2015 11:49:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: The Intel(R) Management and Security Application Local Management Service service failed to start due to the following error:
    %%1053

    Error: (11/22/2015 11:49:04 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
    Description: A timeout was reached (30000 milliseconds) while waiting for the Intel(R) Management and Security Application Local Management Service service to connect.

    Error: (11/22/2015 11:46:49 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
    Description: There was an error while attempting to read the local hosts file.


    CodeIntegrity:
    ===================================
    Date: 2015-11-21 17:46:27.000
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:46:26.900
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:45:13.384
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:45:13.321
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:44:32.227
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:44:32.165
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:44:32.085
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:44:32.022
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:44:31.942
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

    Date: 2015-11-21 17:44:31.880
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz
    Percentage of memory in use: 31%
    Total physical RAM: 8104.58 MB
    Available physical RAM: 5534.5 MB
    Total Virtual: 16207.37 MB
    Available Virtual: 13357.83 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:1862.92 GB) (Free:1620.97 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: A4A1717F)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

  6. #6
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Please, observe following rules:

    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.



    ===================================

    Uninstall following unwanted program: Strongvault Online Backup.

    You're running three AV programs:

    AV: Bitdefender Antivirus (Disabled - Out of date) {9A0813D8-CED6-F86B-072E-28D2AF25A83D}
    AV: COMODO Antivirus (Enabled - Up to date) {F25D0092-CDBE-B303-ADB7-88DE8CDECCF5}
    AV: avast! Internet Security (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}

    You must uninstall TWO of them.

    There is an issue with couple of system files, possibly infected.

    Re-run FRST again.
    Type the following in the edit box after "Search:".

    dnsapi.dll

    Click Search files button and post the log (Search.txt) it makes in your reply.

  7. #7
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    Hi thanks for your prompt reply Broni it is very much appreciated!

    I have uninstalled Bitdefender Antivirus.

    For the avast! Internet Security & Strongvault Online Backup I could not see these in my programs in control panel so I used ccleaner, but I am not sure if it has removed them? Sorry I maybe should have asked you before doing this!

    I have posted the log (Search.txt) below..

    Farbar Recovery Scan Tool (x64) Version:20-11-2015
    Ran by Graeme (2015-11-22 21:19:12)
    Running from C:\Users\Graeme\Desktop
    Boot Mode: Normal

    ================== Search Files: "dnsapi.dll" =============

    C:\Windows.old\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.21673_none_e431a3c1f9eaaa8f\dnsapi.dll
    [2012-10-27 17:53][2011-03-03 05:12] 0270336 ____A (Microsoft Corporation) 1F79F611109C2B97260B68FD6B4FC7DD [File is digitally signed]

    C:\Windows.old\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17570_none_e3a50618e0cfbec0\dnsapi.dll
    [2012-10-27 17:53][2011-03-03 05:38] 0270336 ____A (Microsoft Corporation) B40420876B9288E0A1C8CCA8A84E5DC9 [File is digitally signed]

    C:\Windows.old\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.20914_none_e28d2873fc92ad7b\dnsapi.dll
    [2012-10-27 17:53][2011-03-03 05:50] 0270336 ____A (Microsoft Corporation) 11DD7EB4446F25C132D0D8527DDCAF4D [File is digitally signed]

    C:\Windows.old\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.16772_none_e1c0a9a6e3a78582\dnsapi.dll
    [2012-10-27 17:53][2011-03-03 05:29] 0269824 ____A (Microsoft Corporation) 62390F4ACE9E2B63E3CA26B7F7497897 [File is digitally signed]

    C:\Windows.old\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.16385_none_e1b8d300e3acf8dc\dnsapi.dll
    [2009-07-13 23:12][2009-07-14 01:15] 0269824 ____A (Microsoft Corporation) 6D5A49D6479EB753C7879F73A4C35E0F [File is digitally signed]

    C:\Windows.old\Windows\System32\dnsapi.dll
    [2012-10-27 17:53][2011-03-03 05:29] 0269824 ____A (Microsoft Corporation) 62390F4ACE9E2B63E3CA26B7F7497897 [File is digitally signed]

    C:\Windows.old\Windows\SoftwareDistribution\Download\4a7f49b3f65af6828820068e5dd598c8\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_e3e9e6c8e09b7c76\dnsapi.dll
    [2012-11-09 18:52][2010-11-20 12:18] 0270336 ____A (Microsoft Corporation) 59DF156711A76BCB993253EC6C9BBF41 [File is digitally signed]

    C:\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.21673_none_4aa4e997e6a8ddc0\dnsapi.dll
    [2012-12-11 21:32][2011-03-03 05:12] 0270336 ____A (Microsoft Corporation) 1F79F611109C2B97260B68FD6B4FC7DD [File is digitally signed]

    C:\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17570_none_4a184beecd8df1f1\dnsapi.dll
    [2012-12-11 21:32][2011-03-03 05:38] 0270336 ____A (Microsoft Corporation) B40420876B9288E0A1C8CCA8A84E5DC9 [File is digitally signed]

    C:\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_4a5d2c9ecd59afa7\dnsapi.dll
    [2012-12-15 20:10][2010-11-20 12:18] 0270336 ____A (Microsoft Corporation) 59DF156711A76BCB993253EC6C9BBF41 [File is digitally signed]

    C:\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.20914_none_49006e49e950e0ac\dnsapi.dll
    [2012-12-11 21:32][2011-03-03 05:50] 0270336 ____A (Microsoft Corporation) 11DD7EB4446F25C132D0D8527DDCAF4D [File is digitally signed]

    C:\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.16772_none_4833ef7cd065b8b3\dnsapi.dll
    [2012-12-11 21:32][2011-03-03 05:29] 0269824 ____A (Microsoft Corporation) 62390F4ACE9E2B63E3CA26B7F7497897 [File is digitally signed]

    C:\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.16385_none_482c18d6d06b2c0d\dnsapi.dll
    [2009-07-13 23:12][2009-07-14 01:15] 0269824 ____A (Microsoft Corporation) 6D5A49D6479EB753C7879F73A4C35E0F [File is digitally signed]

    C:\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.21673_none_40503f45b2481bc5\dnsapi.dll
    [2012-12-11 21:32][2011-03-03 06:12] 0357888 ____A (Microsoft Corporation) DCC0888655823103F19EF8FFD330080D [File is digitally signed]

    C:\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17570_none_3fc3a19c992d2ff6\dnsapi.dll
    [2012-12-11 21:32][2011-03-03 06:24] 0357888 ____A (Microsoft Corporation) 492D07D79E7024CA310867B526D9636D [File is digitally signed]

    C:\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_4008824c98f8edac\dnsapi.dll
    [2012-12-15 20:10][2010-11-20 13:26] 0357888 ____A (Microsoft Corporation) A52B6CC24063CC83C78C0E6F24DEEC01 [File is digitally signed]

    C:\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.20914_none_3eabc3f7b4f01eb1\dnsapi.dll
    [2012-12-11 21:32][2011-03-03 06:23] 0356864 ____A (Microsoft Corporation) B538E393F7FD85A054106FF21A4240EA [File is digitally signed]

    C:\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.16772_none_3ddf452a9c04f6b8\dnsapi.dll
    [2012-12-11 21:32][2011-03-03 06:17] 0356352 ____A (Microsoft Corporation) E247E7DEB20C0CF0801A8AC39E9CE1DF [File is digitally signed]

    C:\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7600.16385_none_3dd76e849c0a6a12\dnsapi.dll
    [2009-07-13 23:21][2009-07-14 01:40] 0356352 ____A (Microsoft Corporation) 05A2D26ACF0939A4E97160315F1FA12E [File is digitally signed]

    C:\Windows\System32\dnsapi.dll
    [2012-12-11 21:32][2012-12-11 21:32] 0357888 ____A (Microsoft Corporation) A8BA0E7F52ACC191F3A00369C05E2468 [File not signed]

    ====== End of Search ======

  8. #8
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
    Attached Files Attached Files

  9. #9
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    Hi please see below;

    Fix result of Farbar Recovery Scan Tool (x64) Version:22-11-2015
    Ran by Graeme (2015-11-23 17:34:06) Run:1
    Running from C:\Users\Graeme\Desktop
    Loaded Profiles: Graeme (Available Profiles: Graeme)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    Replace: C:\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.21673_none_40503f45b2481bc5\dnsapi.dll C:\Windows\System32\dnsapi.dll
    Replace: C:\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_4a5d2c9ecd59afa7\dnsapi.dll C:\Windows\SysWOW64\dnsapi.dll
    *****************

    C:\Windows\System32\dnsapi.dll => moved successfully
    C:\Windows\winsxs\amd64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.21673_none_40503f45b2481bc5\dnsapi.dll copied successfully to C:\Windows\System32\dnsapi.dll
    "C:\Windows\SysWOW64\dnsapi.dll" => not found
    C:\Windows\winsxs\wow64_microsoft-windows-dns-client_31bf3856ad364e35_6.1.7601.17514_none_4a5d2c9ecd59afa7\dnsapi.dll copied successfully to C:\Windows\SysWOW64\dnsapi.dll

    ==== End of Fixlog 17:34:06 ====

  10. #10
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Last scans...

    Download Security Check from here or here and save it to your Desktop.

    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
    NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


    Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    Make sure the following options are checked:

    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services



    Press "Scan".
    It will create a log (FSS.txt) in the same directory the tool is run.
    Please copy and paste the log to your reply.


    Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe

    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.




    Download Sophos Free Virus Removal Tool and save it to your desktop.

    • Double click the icon and select Run
    • Click Next
    • Select I accept the terms in this license agreement, then click Next twice
    • Click Install
    • Click Finish to launch the program
    • Once the virus database has been updated click Start Scanning
    • If any threats are found click Details, then View log file... (bottom left hand corner)
    • Copy and paste the results in your reply
    • Close the Notepad document, close the Threat Details screen, then click Start cleanup
    • Click Exit to close the program

  11. #11
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    Hi here are the logs you require pasted below, Thanks;

    Results of screen317's Security Check version 1.009
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 11
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    COMODO Antivirus
    avast! Internet Security
    Antivirus up to date! (On Access scanning disabled!)
    `````````Anti-malware/Other Utilities Check:`````````
    Secunia PSI (3.0.0.9016)
    Java 7 Update 51
    Java version 32-bit out of Date!
    Adobe Flash Player 19.0.0.245
    Adobe Reader XI
    Mozilla Firefox (40.0.3)
    Google Chrome (46.0.2490.80)
    Google Chrome (46.0.2490.86)
    ````````Process Check: objlist.exe by Laurent````````
    Comodo Firewall cmdagent.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0%
    ````````````````````End of Log``````````````````````


    Farbar Service Scanner Version: 10-06-2014
    Ran by Graeme (administrator) on 24-11-2015 at 21:57:53
    Running from "C:\Users\Graeme\Desktop"
    Microsoft Windows 7 Ultimate Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Action Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is set to Demand. The default start type is Auto.
    The ImagePath of WinDefend service is OK.
    The ServiceDll of WinDefend service is OK.


    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => File is digitally signed
    C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
    C:\Windows\System32\dhcpcore.dll => File is digitally signed
    C:\Windows\System32\drivers\afd.sys => File is digitally signed
    C:\Windows\System32\drivers\tdx.sys => File is digitally signed
    C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
    C:\Windows\System32\dnsrslvr.dll => File is digitally signed
    C:\Windows\System32\mpssvc.dll => File is digitally signed
    C:\Windows\System32\bfe.dll => File is digitally signed
    C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
    C:\Windows\System32\SDRSVC.dll => File is digitally signed
    C:\Windows\System32\vssvc.exe => File is digitally signed
    C:\Windows\System32\wscsvc.dll => File is digitally signed
    C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
    C:\Windows\System32\wuaueng.dll => File is digitally signed
    C:\Windows\System32\qmgr.dll => File is digitally signed
    C:\Windows\System32\es.dll => File is digitally signed
    C:\Windows\System32\cryptsvc.dll => File is digitally signed
    C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
    C:\Windows\System32\ipnathlp.dll => File is digitally signed
    C:\Windows\System32\iphlpsvc.dll => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed


    **** End of log ****


    2015-11-24 22:25:34.473 Sophos Virus Removal Tool version 2.5.5
    2015-11-24 22:25:34.473 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

    2015-11-24 22:25:34.473 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

    2015-11-24 22:25:34.473 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
    2015-11-24 22:25:34.483 Checking for updates...
    2015-11-24 22:25:41.786 Option all = no
    2015-11-24 22:25:41.786 Option recurse = yes
    2015-11-24 22:25:41.786 Option archive = no
    2015-11-24 22:25:48.107 Option service = yes
    2015-11-24 22:25:48.107 Option confirm = yes
    2015-11-24 22:25:48.107 Option sxl = yes
    2015-11-24 22:25:48.107 Option max-data-age = 35
    2015-11-24 22:25:48.107 Option EnableSafeClean = yes
    2015-11-24 22:25:48.437 Option vdl-logging = yes
    2015-11-24 22:25:48.457 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2015-11-24 22:25:48.457 Machine ID: 5e9d7e49b4594a9aaf4f76c68cdb566d
    2015-11-24 22:25:48.457 Component SVRTcli.exe version 2.5.5
    2015-11-24 22:25:48.457 Component control.dll version 2.5.5
    2015-11-24 22:25:48.457 Component SVRTservice.exe version 2.5.5
    2015-11-24 22:25:48.457 Component engine\osdp.dll version 1.44.1.2230
    2015-11-24 22:25:48.457 Component engine\veex.dll version 3.63.0.2230
    2015-11-24 22:25:48.457 Component engine\savi.dll version 9.0.0.2230
    2015-11-24 22:25:48.457 Component rkdisk.dll version 1.5.30.0
    2015-11-24 22:25:48.457 Version info: Product version 2.5.5
    2015-11-24 22:25:48.457 Version info: Detection engine 3.63.0
    2015-11-24 22:25:48.457 Version info: Detection data 5.21
    2015-11-24 22:25:48.457 Version info: Build date 10/11/2015
    2015-11-24 22:25:48.457 Version info: Data files added 197
    2015-11-24 22:25:48.457 Version info: Last successful update (not yet updated)
    2015-11-24 22:25:48.868 Update progress: proxy server not available
    2015-11-24 22:26:13.653 Update error: failed to read remote metadata (error 4)
    Cannot locate server for http://d1.sophosupd.com/update/catal...ds.svrt_10.xml
    2015-11-24 22:26:30.660 Error level 1

    2015-11-24 22:26:30.660 Scan completed.
    2015-11-24 22:26:30.660

    ------------------------------------------------------------

    2015-11-24 22:27:02.787 Sophos Virus Removal Tool version 2.5.5
    2015-11-24 22:27:02.787 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

    2015-11-24 22:27:02.787 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

    2015-11-24 22:27:02.787 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
    2015-11-24 22:27:02.787 Checking for updates...
    2015-11-24 22:27:08.365 Option all = no
    2015-11-24 22:27:08.365 Option recurse = yes
    2015-11-24 22:27:08.365 Option archive = no
    2015-11-24 22:27:08.365 Option service = yes
    2015-11-24 22:27:08.365 Option confirm = yes
    2015-11-24 22:27:08.365 Option sxl = yes
    2015-11-24 22:27:08.365 Option max-data-age = 35
    2015-11-24 22:27:08.365 Option EnableSafeClean = yes
    2015-11-24 22:27:08.385 Option vdl-logging = yes
    2015-11-24 22:27:08.395 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2015-11-24 22:27:08.395 Machine ID: 5e9d7e49b4594a9aaf4f76c68cdb566d
    2015-11-24 22:27:08.395 Component SVRTcli.exe version 2.5.5
    2015-11-24 22:27:08.395 Component control.dll version 2.5.5
    2015-11-24 22:27:08.395 Component SVRTservice.exe version 2.5.5
    2015-11-24 22:27:08.395 Component engine\osdp.dll version 1.44.1.2230
    2015-11-24 22:27:08.395 Component engine\veex.dll version 3.63.0.2230
    2015-11-24 22:27:08.395 Component engine\savi.dll version 9.0.0.2230
    2015-11-24 22:27:08.395 Component rkdisk.dll version 1.5.30.0
    2015-11-24 22:27:08.395 Version info: Product version 2.5.5
    2015-11-24 22:27:08.395 Version info: Detection engine 3.63.0
    2015-11-24 22:27:08.395 Version info: Detection data 5.21
    2015-11-24 22:27:08.395 Version info: Build date 10/11/2015
    2015-11-24 22:27:08.395 Version info: Data files added 197
    2015-11-24 22:27:08.395 Version info: Last successful update (not yet updated)
    2015-11-24 22:27:16.634 Update progress: proxy server not available
    2015-11-24 22:28:08.647 Downloading updates...
    2015-11-24 22:28:08.647 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
    2015-11-24 22:28:08.647 Update progress: [I49502] Found supplement SAVIW32 LATEST
    2015-11-24 22:28:08.647 Update progress: [I49502] Found supplement IDE522 LATEST
    2015-11-24 22:28:08.647 Update progress: [I49502] Found supplement IDE523 LATEST
    2015-11-24 22:28:08.647 Update progress: [I49502] Found supplement IDE524 LATEST
    2015-11-24 22:28:08.647 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
    2015-11-24 22:28:08.647 Update progress: [I19463] Syncing product SAVIW32 62
    2015-11-24 22:28:09.657 Update progress: [I19463] Syncing product IDE522 134
    2015-11-24 22:28:09.993 Update progress: [I19463] Syncing product IDE523 66
    2015-11-24 22:28:10.233 Installing updates...
    2015-11-24 22:28:10.833 Error level 1
    2015-11-24 22:28:10.843 Update progress: [I19463] Syncing product IDE524 1
    2015-11-24 22:28:45.368 Update successful
    2015-11-24 22:30:40.065 Option all = no
    2015-11-24 22:30:40.065 Option recurse = yes
    2015-11-24 22:30:40.065 Option archive = no
    2015-11-24 22:30:40.065 Option service = yes
    2015-11-24 22:30:40.065 Option confirm = yes
    2015-11-24 22:30:40.065 Option sxl = yes
    2015-11-24 22:30:40.065 Option max-data-age = 35
    2015-11-24 22:30:40.065 Option EnableSafeClean = yes
    2015-11-24 22:30:40.655 Option vdl-logging = yes
    2015-11-24 22:30:40.655 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2015-11-24 22:30:40.655 Machine ID: 5e9d7e49b4594a9aaf4f76c68cdb566d
    2015-11-24 22:30:40.655 Component SVRTcli.exe version 2.5.5
    2015-11-24 22:30:40.655 Component control.dll version 2.5.5
    2015-11-24 22:30:40.655 Component SVRTservice.exe version 2.5.5
    2015-11-24 22:30:40.655 Component engine\osdp.dll version 1.44.1.2230
    2015-11-24 22:30:40.655 Component engine\veex.dll version 3.63.0.2230
    2015-11-24 22:30:40.655 Component engine\savi.dll version 9.0.0.2230
    2015-11-24 22:30:40.655 Component rkdisk.dll version 1.5.30.0
    2015-11-24 22:30:40.655 Version info: Product version 2.5.5
    2015-11-24 22:30:40.665 Version info: Detection engine 3.63.0
    2015-11-24 22:30:40.665 Version info: Detection data 5.21
    2015-11-24 22:30:40.665 Version info: Build date 10/11/2015
    2015-11-24 22:30:40.665 Version info: Data files added 198
    2015-11-24 22:30:40.665 Version info: Last successful update 24/11/2015 22:28:45

    2015-11-24 22:58:46.906 SafeClean bin directory is empty.
    2015-11-24 22:58:46.946 Error level 0

    2015-11-24 22:58:47.736 Scan cancelled by user.
    2015-11-24 22:58:47.736

    ------------------------------------------------------------

    2015-11-25 17:21:03.811 Sophos Virus Removal Tool version 2.5.5
    2015-11-25 17:21:03.811 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

    2015-11-25 17:21:03.811 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

    2015-11-25 17:21:03.811 Windows version 6.1 SP 1.0 Service Pack 1 build 7601 SM=0x100 PT=0x1 WOW64
    2015-11-25 17:21:03.812 Checking for updates...
    2015-11-25 17:21:17.658 Update progress: proxy server not available
    2015-11-25 17:21:45.797 Option all = no
    2015-11-25 17:21:45.798 Option recurse = yes
    2015-11-25 17:21:45.798 Option archive = no
    2015-11-25 17:21:45.798 Option service = yes
    2015-11-25 17:21:45.798 Option confirm = yes
    2015-11-25 17:21:45.798 Option sxl = yes
    2015-11-25 17:21:45.799 Option max-data-age = 35
    2015-11-25 17:21:45.799 Option EnableSafeClean = yes
    2015-11-25 17:21:45.843 Option vdl-logging = yes
    2015-11-25 17:21:45.847 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2015-11-25 17:21:45.847 Machine ID: 5e9d7e49b4594a9aaf4f76c68cdb566d
    2015-11-25 17:21:45.907 Component SVRTcli.exe version 2.5.5
    2015-11-25 17:21:45.907 Component control.dll version 2.5.5
    2015-11-25 17:21:45.907 Component SVRTservice.exe version 2.5.5
    2015-11-25 17:21:45.907 Component engine\osdp.dll version 1.44.1.2230
    2015-11-25 17:21:45.907 Component engine\veex.dll version 3.63.0.2230
    2015-11-25 17:21:45.907 Component engine\savi.dll version 9.0.0.2230
    2015-11-25 17:21:45.962 Component rkdisk.dll version 1.5.30.0
    2015-11-25 17:21:45.962 Version info: Product version 2.5.5
    2015-11-25 17:21:45.962 Version info: Detection engine 3.63.0
    2015-11-25 17:21:45.962 Version info: Detection data 5.21
    2015-11-25 17:21:45.962 Version info: Build date 10/11/2015
    2015-11-25 17:21:45.962 Version info: Data files added 198
    2015-11-25 17:21:45.962 Version info: Last successful update 24/11/2015 22:28:45
    2015-11-25 17:22:18.895 Downloading updates...
    2015-11-25 17:22:18.896 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
    2015-11-25 17:22:18.896 Update progress: [I49502] Found supplement SAVIW32 LATEST
    2015-11-25 17:22:18.896 Update progress: [I49502] Found supplement IDE522 LATEST
    2015-11-25 17:22:18.896 Update progress: [E59264] Cannot locate server for http://d2.sophosupd.com/update/catal...s.data0910.xml
    2015-11-25 17:22:18.896 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
    2015-11-25 17:22:18.896 Update progress: [I49502] Found supplement SAVIW32 LATEST
    2015-11-25 17:22:18.896 Update progress: [I49502] Found supplement IDE522 LATEST
    2015-11-25 17:22:18.896 Update progress: [I49502] Found supplement IDE523 LATEST
    2015-11-25 17:22:18.896 Update progress: [I49502] Found supplement IDE524 LATEST
    2015-11-25 17:22:18.896 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
    2015-11-25 17:22:18.896 Update progress: [I19463] Syncing product SAVIW32 62
    2015-11-25 17:22:18.896 Update progress: [I19463] Syncing product IDE522 134
    2015-11-25 17:22:21.276 Update progress: [I19463] Syncing product IDE523 69
    2015-11-25 17:22:22.709 Installing updates...
    2015-11-25 17:22:23.311 Error level 1
    2015-11-25 17:22:23.471 Update progress: [I19463] Syncing product IDE524 1
    2015-11-25 17:22:23.513 Update successful
    2015-11-25 17:22:30.522 Option all = no
    2015-11-25 17:22:30.522 Option recurse = yes
    2015-11-25 17:22:30.522 Option archive = no
    2015-11-25 17:22:30.522 Option service = yes
    2015-11-25 17:22:30.522 Option confirm = yes
    2015-11-25 17:22:30.522 Option sxl = yes
    2015-11-25 17:22:30.523 Option max-data-age = 35
    2015-11-25 17:22:30.523 Option EnableSafeClean = yes
    2015-11-25 17:22:30.550 Option vdl-logging = yes
    2015-11-25 17:22:30.552 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
    2015-11-25 17:22:30.553 Machine ID: 5e9d7e49b4594a9aaf4f76c68cdb566d
    2015-11-25 17:22:30.553 Component SVRTcli.exe version 2.5.5
    2015-11-25 17:22:30.553 Component control.dll version 2.5.5
    2015-11-25 17:22:30.553 Component SVRTservice.exe version 2.5.5
    2015-11-25 17:22:30.554 Component engine\osdp.dll version 1.44.1.2230
    2015-11-25 17:22:30.554 Component engine\veex.dll version 3.63.0.2230
    2015-11-25 17:22:30.554 Component engine\savi.dll version 9.0.0.2230
    2015-11-25 17:22:30.554 Component rkdisk.dll version 1.5.30.0
    2015-11-25 17:22:30.554 Version info: Product version 2.5.5
    2015-11-25 17:22:30.554 Version info: Detection engine 3.63.0
    2015-11-25 17:22:30.554 Version info: Detection data 5.21
    2015-11-25 17:22:30.554 Version info: Build date 10/11/2015
    2015-11-25 17:22:30.554 Version info: Data files added 201
    2015-11-25 17:22:30.554 Version info: Last successful update 25/11/2015 17:22:23

    2015-11-25 19:07:40.215 Could not open C:\hiberfil.sys
    2015-11-25 19:07:46.394 Could not open C:\pagefile.sys
    2015-11-25 19:10:13.284 >>> Virus 'Mal/Generic-S' found in file C:\Program Files\shopperz201120152254\unins000.exe\FILE:0004
    2015-11-25 19:10:13.284 Disinfection not offered
    2015-11-25 19:21:53.684 Could not open C:\ProgramData\BOINC\slots\0\boinc_lockfile
    2015-11-25 19:22:18.596 >>> Virus 'Troj/Patched-BM' found in file C:\ProgramData\Comodo\Cis\Quarantine\data\{361D8F4C-5E48-46F1-8A20-FD03775B4EE4}
    2015-11-25 19:22:23.290 >>> Virus 'Mal/Generic-S' found in file C:\ProgramData\Comodo\Cis\Quarantine\data\{9C511482-17DB-4582-870C-7BB7FB175848}
    2015-11-25 19:22:23.290 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-11-25 19:22:23.290 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-11-25 19:22:23.290 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-11-25 19:22:26.748 >>> Virus 'Mal/Generic-S' found in file C:\ProgramData\Comodo\Cis\Quarantine\data\{CA7CFF32-B63B-43CD-9169-7FADA9F1D17B}
    2015-11-25 19:22:26.748 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-11-25 19:22:26.748 >>> Virus 'Mal/Generic-S' found in file HKU\S-1-5-21-4177724317-3960994671-2067847833-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-11-25 19:22:26.748 >>> Virus 'Mal/Generic-S' found in file HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnPostRedirect
    2015-11-25 19:23:35.243 Could not open C:\System Volume Information\{0bd40904-8b91-11e5-aa32-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.243 Could not open C:\System Volume Information\{0bd40928-8b91-11e5-aa32-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.243 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.244 Could not open C:\System Volume Information\{8ccd96dd-92f3-11e5-a3aa-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.244 Could not open C:\System Volume Information\{8dd0a0d8-9071-11e5-9501-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.244 Could not open C:\System Volume Information\{bedda206-8f99-11e5-a9d3-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.244 Could not open C:\System Volume Information\{c033ca00-907c-11e5-aa92-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.244 Could not open C:\System Volume Information\{c033ca04-907c-11e5-aa92-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.245 Could not open C:\System Volume Information\{c033ca4c-907c-11e5-aa92-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:23:35.245 Could not open C:\System Volume Information\{c033ca50-907c-11e5-aa92-bc5ff419b61e}{3808876b-c176-4e48-b7ae-04046e6cc752}
    2015-11-25 19:25:24.782 Could not open C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Current Session
    2015-11-25 19:25:24.782 Could not open C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
    2015-11-25 19:25:24.973 Could not check C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOCK (virus scan failed)
    2015-11-25 19:25:25.217 Could not check C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK (virus scan failed)
    2015-11-25 19:25:26.868 Could not check C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\LOCK (virus scan failed)
    2015-11-25 19:26:25.535 Could not check C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOCK (virus scan failed)
    2015-11-25 19:26:25.609 Could not check C:\Users\Graeme\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK (virus scan failed)
    2015-11-25 19:43:30.740 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
    2015-11-25 19:43:30.759 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
    2015-11-25 19:43:51.145 Could not open C:\Windows\System32\config\RegBack\DEFAULT
    2015-11-25 19:43:51.146 Could not open C:\Windows\System32\config\RegBack\SAM
    2015-11-25 19:43:51.147 Could not open C:\Windows\System32\config\RegBack\SECURITY
    2015-11-25 19:43:51.147 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
    2015-11-25 19:43:51.148 Could not open C:\Windows\System32\config\RegBack\SYSTEM
    2015-11-25 20:36:14.278 The following items will be cleaned up:
    2015-11-25 20:36:14.287 Mal/Generic-S
    2015-11-25 20:36:14.287 Mal/Generic-S
    2015-11-25 20:36:14.287 Troj/Patched-BM

  12. #12
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Update Firefox to the latest version.

    Update your Java version here: http://www.java.com/en/download/manual.jsp
    Alternate download: http://www.filehippo.com/search?q=java

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
    Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

    =====================================

    Your computer is clean

    1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:

    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore
    • Reset system settings


    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.

    2. Make sure Windows Updates are current.

    3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    4. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Scan without installing plugin" and then on "Scan now")

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    11. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tuto...r-safe-online/
    About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/foru.../#entry3187642

    12. Please, let me know, how your computer is doing.

  13. #13
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    Hi thanks for all your help.

    I have done what you asked above.

    But there is still a problem!

    When on the infected pc If I am on this website (virtual dr) there is a search bar at the top of the webpage saying powered by sagittarius (It said powered by serpens yesterday). If I log into my virtual dr account its preventing me from replying to threads or posting.

    Can you help thanks again, Dash
    Last edited by DASHBOY; November 30th, 2015 at 01:26 PM.

  14. #14
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Which browser?
    Did you try different browser to see if it has same issue?

  15. #15
    Join Date
    Jun 2003
    Location
    Scotland
    Posts
    91
    Hi just tested all 3 have it, chrome, ie and firefox.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •