Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-05-2015
Ran by Shade (administrator) on LINUX on 10-05-2015 16:54:37
Running from C:\Users\Shade\Downloads
Loaded Profiles: Shade (Available profiles: UpdatusUser & 102 & Shade & newadmin & Guest)
Platform: Microsoft Windows 8 Pro (X86) OS Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(Foxit Corporation) D:\Almost ALl Softwares\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Razer Inc.) C:\Program Files\Razer\Razer Game Booster\RzKLService.exe
(@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
(CyberGhost S.R.L) C:\Program Files\CyberGhost 5\Service.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Valve Corporation) D:\Steam\Steam.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe
(Krzysztof Kowalczyk) C:\Program Files\SumatraPDF\SumatraPDF.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5088456 2014-10-01] (ESET)
HKLM\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe [2618680 2015-04-08] (Malwarebytes Corporation)
HKLM\...\Winlogon: [Shell] C:\Windows\explorer.exe, c:\windows\system32\explorer.exe [x ] ()
HKU\S-1-5-21-3171145056-229118582-1774830325-1010\...\Run: [PeerBlock] => C:\Program Files\PeerBlock\peerblock.exe [2124360 2014-01-14] (PeerBlock, LLC)
HKU\S-1-5-21-3171145056-229118582-1774830325-1010\...\Run: [Steam] => D:\Steam\steam.exe [2889408 2015-04-14] (Valve Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2014-02-22]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2014-02-22]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\Shade\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk [2014-06-20]
ShortcutTarget: MagicDisc.lnk -> C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3171145056-229118582-1774830325-1010\Software\Microsoft\Internet Explorer\Main,Start Page =
http://jbh/
BHO: GetGo URLCatch -> {0315AA2C-10C7-4504-A1C4-F552ABA8A095} -> C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll [2014-09-22] (GetGo Software)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre8\bin\ssv.dll [2014-07-19] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files\LastPass\LPToolbar.dll [2014-02-22] (LastPass)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre8\bin\jp2ssv.dll [2014-07-19] (Oracle Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPToolbar.dll [2014-02-22] (LastPass)
Toolbar: HKLM - GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll [2014-09-22] (GetGo Software)
Toolbar: HKU\S-1-5-21-3171145056-229118582-1774830325-1010 -> GetGo Toolbar - {075BBE29-FEC0-404A-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll [2014-09-22] (GetGo Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{84F4B37D-668D-4506-ABB1-70FA9D5696E0}: [NameServer] 8.8.8.8,8.8.4.4
FireFox:
========
FF ProfilePath: C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default
FF Homepage:
https://duckduckgo.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_14_0_0_125.dll [2014-06-18] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\Almost ALl Softwares\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\Almost ALl Softwares\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin: @java.com/DTPlugin,version=11.11.2 -> C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll [2014-07-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.11.2 -> C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll [2014-07-19] (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files\LastPass\nplastpass.dll [2014-02-22] (LastPass)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2013-10-23] (NVIDIA Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF SearchPlugin: C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\searchplugins\duckduckgo.xml [2014-01-15]
FF Extension: Xmarks - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\
foxmarks@kei.com [2014-04-06]
FF Extension: LastPass - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\
support@lastpass.com [2014-04-06]
FF Extension: WOT - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-04-06]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\
adblockpopups@jessehakanen.net.xpi [2014-04-06]
FF Extension: ImageBlock - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\
imageblock@hemantvats.com.xpi [2014-04-06]
FF Extension: DuckDuckGo Plus - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\
jid1-ZAdIEUB7XOzOJw@jetpack.xpi [2014-04-06]
FF Extension: NoScript - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-06]
FF Extension: SEO Global For Google Search™ - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\{B97F57B9-1B42-4aed-9475-0022600C62DC}.xpi [2014-04-06]
FF Extension: Adblock Plus - C:\Users\Shade\AppData\Roaming\Mozilla\Firefox\Profiles\hjnw3cpq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-06]
FF HKLM\...\Firefox\Extensions: [
fiddlerhook@fiddler2.com] - C:\Program Files\Fiddler2\FiddlerHook
FF Extension: FiddlerHook - C:\Program Files\Fiddler2\FiddlerHook [2014-05-28]
FF HKLM\...\Firefox\Extensions: [{0DB87752-EDD2-4ddf-8AE4-A020088EF267}] - C:\Program Files\GetGo Software\GetGo Download Manager\GGMoz
FF Extension: GetGo Firefox Addon - C:\Program Files\GetGo Software\GetGo Download Manager\GGMoz [2014-10-22]
FF HKLM\...\Thunderbird\Extensions: [
eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
Chrome:
=======
CHR Profile: C:\Users\Shade\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (uBlock Origin) - C:\Users\Shade\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2015-05-09]
CHR Extension: (Bookmark Manager) - C:\Users\Shade\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-09]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Shade\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-09]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Shade\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-05-09]
CHR Extension: (Google Wallet) - C:\Users\Shade\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-09]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [1349576 2014-10-01] (ESET)
R2 FoxitCloudUpdateService; D:\Almost ALl Softwares\Foxit Reader\Foxit Cloud\FCUpdateService.exe [242216 2014-06-17] (Foxit Corporation)
R2 MbaeSvc; C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe [656184 2015-04-08] (Malwarebytes Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 RzKLService; C:\Program Files\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.)
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [971968 2015-02-03] (@ByELDI) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14456 2015-01-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [24576 2012-07-26] (Microsoft Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [191928 2014-08-18] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [190368 2014-08-18] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [135296 2014-08-18] (ESET)
R2 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [176448 2014-08-18] (ESET)
R1 EpfwLWF; C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys [37928 2014-08-18] (ESET)
R0 epfwwfp; C:\WINDOWS\System32\DRIVERS\epfwwfp.sys [51288 2014-09-18] (ESET)
R1 ESProtectionDriver; C:\Program Files\Malwarebytes Anti-Exploit\mbae.sys [47928 2015-04-08] ()
R2 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [92888 2015-04-14] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-10] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R3 mcdbus; C:\WINDOWS\System32\drivers\mcdbus.sys [116736 2009-02-24] (MagicISO, Inc.) [File not signed]
S3 MWAC; \??\C:\WINDOWS\system32\drivers\ [0 ] () <==== ATTENTION (zero size file/folder)
S3 Neo_VPN; C:\WINDOWS\system32\DRIVERS\Neo_VPN.sys [26208 2013-12-29] (SoftEther Project at University of Tsukuba, Japan.)
S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [20040 2014-01-14] ()
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [466008 2014-06-20] (Duplex Secure Ltd.)
R3 tap0901; C:\WINDOWS\system32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
S3 WUDFSensorLP; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [155136 2012-07-26] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [155136 2012-07-26] (Microsoft Corporation)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV.sys [X]
S3 cleanhlp; \??\C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [X]
S3 etvspanx; No ImagePath
S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [52224 2012-07-26] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-10 16:54 - 2015-05-10 16:54 - 00014926 _____ () C:\Users\Shade\Downloads\FRST.txt
2015-05-10 16:47 - 2015-05-10 16:48 - 00028885 _____ () C:\Users\Shade\Downloads\Addition.txt
2015-05-10 16:45 - 2015-05-10 16:45 - 01141248 _____ (Farbar) C:\Users\Shade\Downloads\FRST.exe
2015-05-09 12:48 - 2015-05-09 12:48 - 00245248 _____ ([Fix-KB]) C:\Users\Shade\Downloads\DriveTidy.exe
2015-05-09 12:46 - 2015-05-09 12:58 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-05-09 12:46 - 2015-05-09 12:46 - 00035064 _____ () C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-05-09 12:39 - 2015-05-09 12:44 - 16937048 _____ () C:\Users\Shade\Downloads\RogueKiller.exe
2015-05-09 12:39 - 2015-05-09 12:39 - 00243304 _____ () C:\Users\Shade\Downloads\Firefox Setup Stub 37.0.2.exe
2015-05-07 23:30 - 2015-05-07 23:30 - 00880272 _____ () C:\Users\Shade\Downloads\5183832.zip
2015-05-07 23:26 - 2015-05-07 23:28 - 08506106 _____ () C:\Users\Shade\Downloads\7467829 (1).zip
2015-05-07 23:22 - 2015-05-07 23:24 - 08506106 _____ () C:\Users\Shade\Downloads\7467829.zip
2015-05-07 23:13 - 2015-05-07 23:19 - 21204171 _____ () C:\Users\Shade\Downloads\9347966.zip
2015-05-07 22:49 - 2015-05-07 22:50 - 02998091 _____ () C:\Users\Shade\Downloads\8009311.zip
2015-05-05 00:49 - 2015-05-05 00:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
2015-05-05 00:39 - 2015-05-05 00:41 - 03020968 _____ (Malwarebytes ) C:\Users\Shade\Downloads\mbae-setup-1.06.1.1019.exe
2015-05-04 20:21 - 2015-05-04 20:27 - 12618962 _____ () C:\Users\Shade\Downloads\6776237.rar
2015-05-04 20:21 - 2015-05-04 20:22 - 01464992 _____ () C:\Users\Shade\Downloads\4582693.zip
2015-05-04 20:18 - 2015-05-04 20:20 - 04992936 _____ () C:\Users\Shade\Downloads\3213950.zip
2015-05-04 20:15 - 2015-05-04 20:16 - 03360391 _____ () C:\Users\Shade\Downloads\7736572.zip
2015-05-04 20:15 - 2015-05-04 20:16 - 01505316 _____ () C:\Users\Shade\Downloads\9749772.rar
2015-05-04 20:15 - 2015-05-04 20:16 - 01243120 _____ () C:\Users\Shade\Downloads\8107830.rar
2015-05-04 20:13 - 2015-05-04 20:14 - 01901219 _____ () C:\Users\Shade\Downloads\6423029.rar
2015-05-04 20:10 - 2015-05-04 20:13 - 07542958 _____ () C:\Users\Shade\Downloads\997702.rar
2015-05-04 20:04 - 2015-05-04 20:09 - 10788824 _____ () C:\Users\Shade\Downloads\585658.zip
2015-05-04 19:54 - 2015-05-04 19:54 - 01118286 _____ () C:\Users\Shade\Downloads\8372739.rar
2015-05-04 19:46 - 2015-05-04 19:55 - 19729113 _____ () C:\Users\Shade\Downloads\4373875.zip
2015-05-04 19:23 - 2015-05-04 19:23 - 01026210 _____ () C:\Users\Shade\Downloads\1525597.zip
2015-05-04 19:15 - 2015-05-04 19:21 - 12943932 _____ () C:\Users\Shade\Downloads\8211324.zip
2015-05-04 18:33 - 2015-05-04 18:43 - 18376482 _____ () C:\Users\Shade\Downloads\4543353.zip
2015-05-04 01:52 - 2015-05-04 01:52 - 00000000 ____D () C:\Users\102\AppData\Local\CyberGhost
2015-05-03 23:16 - 2015-05-03 23:17 - 02090410 _____ () C:\Users\Shade\Downloads\5853680.zip
2015-05-02 14:02 - 2015-05-10 16:54 - 00000000 ____D () C:\FRST
2015-05-01 18:15 - 2015-05-01 18:24 - 10568854 _____ () C:\Users\Shade\Downloads\2523063.zip
2015-05-01 18:14 - 2015-05-01 18:14 - 00496811 _____ () C:\Users\Shade\Downloads\7681690.zip
2015-04-30 11:59 - 2015-04-30 11:59 - 00000199 _____ () C:\Users\Shade\Desktop\Dota 2.url
2015-04-29 23:06 - 2015-04-29 23:44 - 75108964 _____ () C:\Users\Shade\Downloads\TCP-IP 1-3.rar
2015-04-29 22:59 - 2015-04-29 23:05 - 10528829 _____ () C:\Users\Shade\Downloads\8545190 (1).rar
2015-04-29 22:50 - 2015-04-29 22:52 - 02461595 _____ () C:\Users\Shade\Downloads\9475366.rar
2015-04-29 22:40 - 2015-04-29 22:42 - 02611205 _____ () C:\Users\Shade\Downloads\4955320.rar
2015-04-29 22:30 - 2015-04-29 22:31 - 01585959 _____ () C:\Users\Shade\Downloads\1168073.zip
2015-04-29 22:26 - 2015-04-29 22:27 - 02680872 _____ () C:\Users\Shade\Downloads\8975653.rar
2015-04-29 22:25 - 2015-04-29 22:29 - 06363607 _____ () C:\Users\Shade\Downloads\2216738.rar
2015-04-28 01:10 - 2015-04-28 01:10 - 10266810 _____ () C:\Users\102\Downloads\bloomberg.xap
2015-04-28 00:03 - 2015-04-28 00:08 - 11653280 _____ () C:\Users\Shade\Downloads\Game_Engine_Architecture.pdf.crdownload
2015-04-27 20:47 - 2015-04-27 20:49 - 02907680 _____ () C:\Users\Shade\Downloads\9851083.rar
2015-04-27 20:24 - 2015-04-27 20:26 - 02937097 _____ () C:\Users\Shade\Downloads\3641627.zip
2015-04-27 20:22 - 2015-04-27 20:23 - 01463325 _____ () C:\Users\Shade\Downloads\3791426 (1).rar
2015-04-27 19:43 - 2015-04-27 20:07 - 26639952 _____ () C:\Users\Shade\Downloads\2289477.zip
2015-04-27 19:16 - 2015-04-27 19:29 - 05531120 _____ () C:\Users\Shade\Downloads\5709734.zip
2015-04-27 18:46 - 2015-05-06 11:05 - 00000017 _____ () C:\Users\102\Desktop\download.htm
2015-04-27 16:27 - 2015-04-27 16:30 - 06958304 _____ (Microsoft Corporation) C:\Users\102\Downloads\Silverlight (7).exe
2015-04-27 16:26 - 2015-04-27 16:29 - 06958304 _____ (Microsoft Corporation) C:\Users\102\Downloads\Silverlight (6).exe
2015-04-27 16:12 - 2015-04-27 16:12 - 00243304 _____ () C:\Users\102\Downloads\Firefox Setup Stub 37.0.2.exe
2015-04-27 15:55 - 2015-04-27 15:55 - 00880208 _____ (Google Inc.) C:\Users\102\Downloads\ChromeSetup (2).exe
2015-04-27 15:54 - 2015-04-27 15:54 - 00880208 _____ (Google Inc.) C:\Users\102\Downloads\ChromeSetup (1).exe
2015-04-27 13:39 - 2015-04-27 13:40 - 00880208 _____ (Google Inc.) C:\Users\102\Downloads\ChromeSetup.exe
2015-04-26 23:36 - 2015-04-26 23:46 - 17442080 _____ () C:\Users\Shade\Downloads\6824531.zip
2015-04-26 23:33 - 2015-04-26 23:33 - 01463325 _____ () C:\Users\Shade\Downloads\3791426.rar
2015-04-26 23:05 - 2015-04-26 23:32 - 50916235 _____ () C:\Users\Shade\Downloads\Rootkit_Arsenal Complete.zip
2015-04-26 22:12 - 2015-04-26 22:13 - 03666369 _____ () C:\Users\Shade\Downloads\3665826.rar
2015-04-26 21:56 - 2015-04-26 22:09 - 24028100 _____ () C:\Users\Shade\Downloads\9172544.rar
2015-04-26 21:55 - 2015-04-26 21:56 - 01661927 _____ () C:\Users\Shade\Downloads\1164480.zip
2015-04-26 14:42 - 2015-04-26 14:45 - 02184160 _____ () C:\Users\Shade\Downloads\Unconfirmed 610891.crdownload
2015-04-26 14:42 - 2015-04-26 14:43 - 01168193 _____ () C:\Users\Shade\Downloads\6941919.zip
2015-04-26 14:35 - 2015-04-26 14:41 - 06621030 _____ () C:\Users\Shade\Downloads\4356861.rar
2015-04-26 12:40 - 2015-04-26 12:41 - 00508640 _____ () C:\Users\Shade\Downloads\Unconfirmed 256089.crdownload
2015-04-26 12:38 - 2015-04-26 12:41 - 08708997 _____ () C:\Users\Shade\Downloads\Unconfirmed 512035.crdownload
2015-04-26 12:32 - 2015-04-26 12:33 - 03250022 _____ () C:\Users\Shade\Downloads\6546265.zip
2015-04-26 12:26 - 2015-04-26 12:30 - 07263070 _____ () C:\Users\Shade\Downloads\8859378.zip
2015-04-26 12:26 - 2015-04-26 12:29 - 05405401 _____ () C:\Users\Shade\Downloads\3114960.rar
2015-04-26 12:11 - 2015-04-26 12:16 - 10170290 _____ () C:\Users\Shade\Downloads\2270940.rar
2015-04-26 12:11 - 2015-04-26 12:16 - 10103303 _____ () C:\Users\Shade\Downloads\4431890.zip
2015-04-26 12:08 - 2015-04-26 12:10 - 06643947 _____ () C:\Users\Shade\Downloads\2398862.zip
2015-04-26 12:06 - 2015-04-26 12:08 - 03478881 _____ () C:\Users\Shade\Downloads\6756800.zip
2015-04-26 12:05 - 2015-04-26 12:07 - 04545672 _____ () C:\Users\Shade\Downloads\7247648.zip
2015-04-26 00:47 - 2015-04-26 00:49 - 10109071 _____ () C:\Users\Shade\Downloads\2220215.zip
2015-04-26 00:42 - 2015-04-26 00:45 - 10528829 _____ () C:\Users\Shade\Downloads\8545190.rar
2015-04-26 00:17 - 2015-04-26 00:23 - 19498908 _____ () C:\Users\Shade\Downloads\3835377.rar
2015-04-26 00:04 - 2015-04-26 00:04 - 00287646 _____ () C:\Users\Shade\Downloads\5411382.rar
2015-04-25 23:16 - 2015-04-25 23:18 - 02218755 _____ () C:\Users\Shade\Downloads\1860766.rar
2015-04-25 01:05 - 2015-04-25 01:05 - 00000199 _____ () C:\Users\Shade\Desktop\Team Fortress 2.url
2015-04-25 00:12 - 2015-04-25 00:12 - 00001076 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-25 00:12 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-25 00:12 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-04-25 00:12 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-04-24 14:48 - 2015-04-24 14:51 - 06958304 _____ (Microsoft Corporation) C:\Users\102\Downloads\Silverlight (5).exe
2015-04-23 14:02 - 2015-04-23 14:04 - 00000277 _____ () C:\Users\newadmin\Desktop\notifications.txt
2015-04-23 13:58 - 2015-04-23 13:58 - 00000000 ____H () C:\Users\newadmin\Documents\Default.rdp
2015-04-23 13:57 - 2015-04-23 13:57 - 00000000 ____D () C:\Users\newadmin\AppData\Roaming\ESET
2015-04-23 13:57 - 2015-04-23 13:57 - 00000000 ____D () C:\Users\newadmin\AppData\Local\ESET
2015-04-23 13:53 - 2015-04-23 13:53 - 00000000 ____D () C:\Users\newadmin\AppData\Local\Google
2015-04-23 13:52 - 2015-04-23 13:52 - 00001430 _____ () C:\Users\newadmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-23 13:52 - 2015-04-23 13:52 - 00000000 ____D () C:\Users\newadmin\AppData\Roaming\Adobe
2015-04-23 13:52 - 2015-04-23 13:52 - 00000000 ____D () C:\Users\newadmin\AppData\Local\VirtualStore
2015-04-23 13:51 - 2015-04-23 13:53 - 00000000 ____D () C:\Users\newadmin
2015-04-23 13:51 - 2015-04-23 13:51 - 00000020 ___SH () C:\Users\newadmin\ntuser.ini
2015-04-23 13:51 - 2015-04-20 22:27 - 00000000 ___RD () C:\Users\newadmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-04-23 13:51 - 2014-07-14 23:49 - 00000000 ___RD () C:\Users\newadmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-04-23 13:51 - 2014-04-09 12:49 - 00000000 ____D () C:\Users\newadmin\AppData\Roaming\Macromedia
2015-04-23 13:51 - 2014-03-30 00:13 - 00000000 ____D () C:\Users\newadmin\AppData\Roaming\IObit
2015-04-23 13:51 - 2012-07-26 12:23 - 00000000 ___RD () C:\Users\newadmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-23 13:51 - 2012-07-26 12:23 - 00000000 ____D () C:\Users\newadmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-22 18:40 - 2015-04-28 01:11 - 06958304 _____ (Microsoft Corporation) C:\Users\102\Downloads\Silverlight (4).exe
2015-04-22 18:22 - 2015-04-22 18:22 - 00000623 _____ () C:\Users\102\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fallou 3 New Vegas.lnk
2015-04-22 14:56 - 2015-04-22 14:56 - 00281584 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-04-21 23:34 - 2015-04-21 23:34 - 06958304 _____ (Microsoft Corporation) C:\Users\102\Downloads\Silverlight (3).exe
2015-04-21 14:17 - 2015-04-21 14:17 - 06958304 _____ (Microsoft Corporation) C:\Users\102\Downloads\Silverlight (2).exe
2015-04-21 14:17 - 2015-04-21 14:17 - 06958304 _____ (Microsoft Corporation) C:\Users\102\Downloads\Silverlight (1).exe
2015-04-21 14:14 - 2015-04-21 14:15 - 06958304 _____ (Microsoft Corporation) C:\Users\102\Downloads\Silverlight.exe
2015-04-20 22:32 - 2015-04-14 03:37 - 00791520 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-20 22:32 - 2015-04-14 03:37 - 00177632 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-20 22:27 - 2015-04-20 22:27 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-04-16 10:15 - 2015-04-16 10:15 - 00000000 ____D () C:\Users\102\AppData\Local\Steam
2015-04-16 01:48 - 2015-01-09 10:33 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2015-04-16 01:48 - 2015-01-09 05:22 - 00478296 _____ () C:\WINDOWS\system32\locale.nls
2015-04-16 01:23 - 2015-03-10 09:19 - 14373376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-04-16 01:23 - 2015-03-10 09:19 - 02864640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-04-16 01:23 - 2015-03-10 09:19 - 01763328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-04-16 01:23 - 2015-03-10 09:19 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-04-16 01:23 - 2015-03-10 09:19 - 00737280 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-04-16 01:23 - 2015-03-10 09:19 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-04-16 01:23 - 2015-03-10 09:19 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-04-16 01:23 - 2015-03-10 09:19 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-04-16 01:23 - 2015-03-10 09:18 - 13767680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-04-16 01:23 - 2015-02-21 11:01 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-04-16 01:23 - 2015-02-21 11:01 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2015-04-16 01:23 - 2015-02-21 11:01 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-04-16 01:23 - 2015-02-21 11:00 - 02055680 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-04-16 01:23 - 2015-02-21 11:00 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-04-16 01:23 - 2015-02-21 11:00 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2015-04-16 01:23 - 2015-02-21 11:00 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2015-04-16 01:23 - 2015-02-21 11:00 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-04-16 01:23 - 2015-02-21 11:00 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2015-04-16 01:23 - 2015-02-21 11:00 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2015-04-16 01:23 - 2015-02-21 11:00 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2015-04-16 01:23 - 2015-02-21 10:59 - 01441280 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-04-16 01:23 - 2015-02-21 10:59 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-04-16 01:23 - 2015-02-21 10:59 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-04-16 01:23 - 2015-02-21 10:39 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2015-04-16 01:23 - 2015-02-21 10:37 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\INETRES.dll
2015-04-16 01:23 - 2015-02-21 10:12 - 00361984 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-04-16 01:15 - 2015-03-17 10:19 - 05570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-04-16 01:15 - 2015-03-06 11:18 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2015-04-16 01:15 - 2015-02-03 04:48 - 00493256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-04-16 01:15 - 2015-01-15 15:30 - 01026560 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-04-16 01:15 - 2015-01-15 15:30 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2015-04-16 01:14 - 2015-03-17 10:15 - 01474000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-04-16 01:14 - 2015-01-15 14:39 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-04-16 01:12 - 2015-03-23 09:14 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-04-16 01:12 - 2015-03-23 09:14 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-04-16 01:12 - 2015-03-23 09:14 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-04-16 01:12 - 2015-03-23 09:13 - 00859648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-04-16 01:12 - 2015-03-23 09:13 - 00202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-04-16 01:12 - 2015-03-23 09:13 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-04-16 01:12 - 2015-03-23 03:33 - 00896000 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-04-16 01:12 - 2014-12-08 10:34 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-04-16 01:12 - 2014-12-03 07:17 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-04-16 01:09 - 2015-03-06 11:18 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-04-16 01:07 - 2015-01-31 15:27 - 00038392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-04-16 01:07 - 2015-01-31 08:45 - 00238304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-04-16 01:06 - 2015-03-04 10:54 - 00011105 _____ () C:\WINDOWS\system32\AutoconfigV2.cab
2015-04-16 01:06 - 2015-03-04 10:53 - 00449848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AutoUpdate.exe
2015-04-16 01:06 - 2015-03-04 10:53 - 00413208 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationUI.exe
2015-04-16 01:06 - 2015-03-04 10:23 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-04-16 01:06 - 2015-03-04 10:23 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-04-16 01:05 - 2014-09-18 04:54 - 02416128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-04-16 01:04 - 2015-01-29 11:49 - 01339392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-04-16 01:03 - 2015-02-13 04:47 - 00396419 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-04-16 01:03 - 2015-01-24 10:30 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2015-04-16 01:02 - 2015-03-14 12:03 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-04-16 01:01 - 2015-02-20 13:40 - 00035328 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-04-16 01:01 - 2015-02-20 12:54 - 00304128 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-04-16 00:58 - 2015-02-24 12:41 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2015-04-16 00:58 - 2015-02-17 10:43 - 17561600 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-04-16 00:58 - 2015-01-24 10:30 - 02801664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2015-04-16 00:58 - 2015-01-24 09:30 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2015-04-16 00:58 - 2014-12-18 12:32 - 00038720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2015-04-16 00:58 - 2014-12-18 11:50 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2015-04-16 00:58 - 2014-12-18 11:49 - 00683520 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2015-04-16 00:58 - 2014-12-18 11:49 - 00473600 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2015-04-16 00:58 - 2014-11-26 10:20 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-04-16 00:57 - 2015-02-26 09:27 - 03401728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-04-16 00:56 - 2015-03-04 10:52 - 00256832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2015-04-16 00:56 - 2015-03-04 10:22 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-04-16 00:56 - 2015-01-24 10:30 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2015-04-10 20:58 - 2015-04-10 20:58 - 00178923 _____ () C:\Users\Shade\Documents\231050
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-10 16:53 - 2014-06-18 21:41 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-10 16:48 - 2015-02-06 11:43 - 00000906 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-10 16:30 - 2012-07-26 12:23 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-10 16:03 - 2014-08-30 16:03 - 01301673 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-10 16:03 - 2014-06-13 23:17 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit
2015-05-10 15:43 - 2015-02-06 11:43 - 00000902 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-10 15:43 - 2014-06-01 08:52 - 00000508 _____ () C:\WINDOWS\Tasks\Malwarebytes Anti-Exploit.job
2015-05-10 15:43 - 2014-03-29 23:10 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-10 12:24 - 2013-12-24 08:34 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-05-10 12:24 - 2012-07-26 11:34 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-09 21:41 - 2012-07-26 12:23 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2015-05-09 13:15 - 2015-04-04 14:28 - 00002201 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-09 12:53 - 2015-04-04 14:07 - 00000000 ____D () C:\Users\Shade\AppData\Local\Deployment
2015-05-09 01:51 - 2012-07-26 12:13 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-05-09 01:50 - 2012-07-26 12:23 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-05-08 23:52 - 2015-01-24 00:22 - 00000000 ____D () C:\Users\Shade\Desktop\Programming
2015-05-06 23:18 - 2015-03-27 00:52 - 00000000 ____D () C:\Program Files\HxD
2015-05-05 00:49 - 2014-01-05 22:36 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit
2015-05-02 14:02 - 2014-07-19 19:30 - 00000000 ____D () C:\Users\102\Documents\Fiddler2
2015-04-30 13:50 - 2014-06-27 09:33 - 00000000 ____D () C:\The Elder Scrolls III Morrowind GOTY
2015-04-30 11:59 - 2014-04-06 14:58 - 00000000 ____D () C:\Users\Shade\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-04-28 09:02 - 2012-07-26 12:23 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2015-04-28 01:09 - 2012-07-26 12:23 - 00000000 ____D () C:\WINDOWS\AppCompat
2015-04-27 18:39 - 2014-07-31 17:20 - 00000000 ____D () C:\Oblivion Elder Scrolls
2015-04-27 18:39 - 2014-06-24 00:37 - 00000000 ____D () C:\Users\102\Documents\Nexus Mod Manager
2015-04-26 14:27 - 2013-12-24 00:46 - 00848230 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-04-26 14:25 - 2014-09-25 11:47 - 00009714 _____ () C:\WINDOWS\setupact.log
2015-04-25 14:53 - 2014-09-08 12:08 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-25 00:12 - 2014-09-08 12:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-25 00:04 - 2013-12-26 18:22 - 00000000 ____D () C:\Program Files\Steam
2015-04-22 16:45 - 2015-04-06 01:34 - 00001430 _____ () C:\Users\102\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-22 16:25 - 2015-04-04 14:02 - 00001430 _____ () C:\Users\Shade\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-20 22:33 - 2014-04-06 14:40 - 00000000 ____D () C:\Users\Shade
2015-04-20 22:27 - 2014-07-14 23:49 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-04-20 22:27 - 2012-07-26 12:23 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-04-20 22:27 - 2012-07-26 12:23 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-04-20 22:27 - 2012-07-26 12:23 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-04-20 22:27 - 2012-07-26 12:23 - 00000000 ____D () C:\WINDOWS\WinStore
2015-04-20 22:27 - 2012-07-26 12:23 - 00000000 ____D () C:\Program Files\Windows Defender
2015-04-19 14:38 - 2014-12-27 14:44 - 00000000 ____D () C:\Users\Shade\Desktop\Shubham
2015-04-16 01:42 - 2014-07-19 19:26 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-14 17:46 - 2013-12-26 18:22 - 00000000 ____D () C:\Program Files\Common Files\Steam
==================== Files in the root of some directories =======
2014-01-27 14:04 - 2014-01-27 14:23 - 50053120 _____ () C:\Program Files\GUT73BA.tmp
2014-02-22 14:58 - 2014-02-22 14:58 - 11149312 _____ (LastPass) C:\Program Files\Common Files\lpuninstall.exe
2015-03-23 18:14 - 2015-03-23 18:14 - 0003317 _____ () C:\Users\Shade\AppData\Local\recently-used.xbel
2014-04-23 17:54 - 2014-04-23 17:54 - 0007605 _____ () C:\Users\Shade\AppData\Local\Resmon.ResmonCfg
2014-04-11 15:05 - 2014-04-11 15:05 - 0000003 _____ () C:\Users\Shade\AppData\Local\updater.log
2014-04-11 15:05 - 2014-09-28 17:00 - 0000059 _____ () C:\Users\Shade\AppData\Local\UserProducts.xml
Some content of TEMP:
====================
C:\Users\Shade\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-09 21:43
==================== End Of Log ============================