FIRST TEXT
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01
Ran by Deepthought (administrator) on DEEPTHOUGHT-PC on 16-07-2014 21:00:13
Running from C:\Users\Deepthought\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe
(ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Windows\System32\AppleOSSMgr.exe
(Apple Inc.) C:\Windows\System32\AppleTimeSrv.exe
(Shanghai DS-Mobile Technology Co., Ltd.) C:\Program Files\Micromax 200G USB Modem\EdgeModem-DrvSrv.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(Pandora.TV) C:\Program Files\PANDORA.TV\PanService\PandoraService.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Apple Inc.) C:\Program Files\Boot Camp\Bootcamp.exe
(Shanghai DS-Mobile Technology Co., Ltd.) C:\Program Files\Micromax 200G USB Modem\EdgeModem-Run.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
() C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHLE.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apple_KbdMgr] => C:\Program Files\Boot Camp\Bootcamp.exe [526208 2011-08-15] (Apple Inc.)
HKLM\...\Run: [EdgeModem-AutoRun] => C:\Program Files\Micromax 200G USB Modem\EdgeModem-Run.exe [86016 2010-03-21] (Shanghai DS-Mobile Technology Co., Ltd.)
HKLM\...\Run: [AppleSyncNotifier] => C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [EEventManager] => C:\Program Files\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\Run: [msnmsgr] => C:\Program Files\Windows Live\Messenger\msnmsgr.exe [4280184 2012-03-08] (Microsoft Corporation)
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\Run: [Sony PC Companion] => C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [466656 2014-05-23] (Sony)
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\Run: [Adobe Reader Synchronizer] => C:\Program Files\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe [1104256 2014-05-08] (Adobe Systems Incorporated)
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\Run: [Google Update] => C:\Users\Deepthought\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-02-11] (Google Inc.)
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [4566984 2014-04-25] (Safer-Networking Ltd.)
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: G - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {0b9fe382-e078-11e0-9980-b9f5dbeac1b8} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {472e820d-ecef-11e0-9881-60fb427891ba} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {4e941606-901c-11df-8129-0026bb19f52f} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {4e94160c-901c-11df-8129-0026bb19f52f} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {519c4a63-0abc-11e1-9cfd-64b9e8c20a1e} - H:\LaunchU3.exe -a
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {5a365c4c-f9f3-11e0-b866-64b9e8c20a1e} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {5a365c66-f9f3-11e0-b866-64b9e8c20a1e} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {5d0c3348-a256-11df-a11c-0026bb19f52f} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {674568ac-0bbd-11e1-bb63-64b9e8c20a1e} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {783e0e24-e755-11e0-9906-60fb427891ba} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {783e0e27-e755-11e0-9906-60fb427891ba} - H:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {7916d6a7-0506-11e1-970e-64b9e8c20a1e} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {7ab5aa0f-f9f0-11e0-9922-64b9e8c20a1e} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {b147d10c-0b5c-11e1-9cf6-64b9e8c20a1e} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {b8099156-0bbe-11e1-ba99-8a5373bfbb4d} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {b8099159-0bbe-11e1-ba99-8a5373bfbb4d} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {bb06782e-d874-11e0-9f92-f9a15cfb5b88} - G:\LaunchU3.exe -a
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {ce8d1e6b-e082-11e0-9cf5-a4c418ff82b0} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {e0218f5a-a23e-11df-98cf-0026bb19f52f} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {eea2b1c6-ffeb-11e0-bb16-64b9e8c20a1e} - G:\AutoRun.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {f3cf1638-1326-11e2-af9d-60fb427891ba} - F:\Startme.exe
HKU\S-1-5-21-3687737911-3880605115-1145795470-1000\...\MountPoints2: {f41baf85-f2ff-11e0-b937-64b9e8c20a1e} - G:\AutoRun.exe
AppInit_DLLs: C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll File Not Found
Startup: C:\Users\Deepthought\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JL London Advent Calendar.lnk
ShortcutTarget: JL London Advent Calendar.lnk -> C:\Program Files\JL London Advent Calendar\JL London Advent Calendar.exe ()
Startup: C:\Users\Deepthought\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://uk.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF0D2F95E0707CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://start.mysearchdial.com/resul...GyC0EyCzy0F0FyE0DyB0CyDyE2Q&cr=1958936325&ir=
SearchScopes: HKLM - {80c554b9-c7f8-4a21-9471-06d606da78a2} URL =
http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKCU - {1C489B14-E13B-40F4-ABE4-3470A8BE9B19} URL =
http://websearch.ask.com/redirect?c...pn_sauid=8AB166E5-3A93-4EEA-81C9-AD35D6EE3CF2
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://start.mysearchdial.com/resul...GyC0EyCzy0F0FyE0DyB0CyDyE2Q&cr=1958936325&ir=
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {8C2D1BF0-5364-403C-9968-E6E348C6B4FB}
http://www.iradiopop.com/IRD/pages/VBIRDPlayer.CAB
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Deepthought\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Deepthought\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Deepthought\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Deepthought\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Deepthought\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Deepthought\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
Chrome:
=======
CHR HomePage: hxxp://
www.google.co.uk/
CHR StartupUrls: "hxxp://
www.trovi.com/?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=M514D51D8-2662-4897-BB77-D92EAFFA1BA2&SearchSource=55&CUI=&UM=6&UP=SP24CCD76C-1FA0-44A3-826C-0E119A9E4845&SSPV="
CHR Extension: (Google Docs) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-02-06]
CHR Extension: (Google Drive) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-09]
CHR Extension: (Splendid) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdfkbdkkfmmckaadapdipihjfaacnkgd [2014-05-11]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-24]
CHR Extension: (YouTube) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-09]
CHR Extension: (Google Search) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-09]
CHR Extension: (Wowcher) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjmninpjflmkicjdemjjgoncnaadfflh [2014-05-11]
CHR Extension: (Skype Click to Call) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-02-06]
CHR Extension: (Google Wallet) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-09]
CHR Extension: (Blog This!) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\pengoopmcjnbflcjbmoeodbmoflcgjlk [2014-05-11]
CHR Extension: (Gmail) - C:\Users\Deepthought\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-09]
CHR HKLM\...\Chrome\Extension: [apgjagobplilmcdfelodhgefiidomnfl] - C:\Program Files\Inbox Toolbar\Chrome\ibxtoolbar_chr.crx [2014-05-09]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-04-09]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AppleOSSMgr; C:\Windows\system32\AppleOSSMgr.exe [194432 2011-08-15] ()
R2 AppleTimeSrv; C:\Windows\system32\AppleTimeSrv.exe [99640 2010-01-16] (Apple Inc.)
R2 EdgeModem-DrvSrv; C:\Program Files\Micromax 200G USB Modem\EdgeModem-DrvSrv.exe [163840 2010-03-21] (Shanghai DS-Mobile Technology Co., Ltd.) [File not signed]
R2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) [File not signed]
R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION)
R2 EPSON_PM_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [142432 2012-02-21] (SEIKO EPSON CORPORATION)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-08-10] ()
R2 iprip; C:\Windows\System32\iprip.dll [29696 2009-07-14] (Microsoft Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-08-10] ()
R2 PanService; C:\Program Files\PANDORA.TV\PanService\PandoraService.exe [625816 2012-06-22] (Pandora.TV)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155824 2013-02-04] (Avanquest Software)
==================== Drivers (Whitelisted) ====================
R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
R3 AppleBtBc; C:\Windows\System32\DRIVERS\AppleBtBc.sys [18944 2011-06-28] (Apple Inc.)
R0 AppleHFS; C:\Windows\system32\Drivers\AppleHFS.sys [58200 2011-08-15] (Apple Inc.)
R0 AppleMNT; C:\Windows\system32\Drivers\AppleMNT.sys [15320 2011-08-15] (Apple Inc.)
R3 applemtm; C:\Windows\System32\DRIVERS\applemtm.sys [10880 2011-01-31] (Apple Inc.)
R3 applemtp; C:\Windows\System32\DRIVERS\applemtp.sys [29824 2011-01-31] (Apple Inc.)
R3 CirrusFilter; C:\Windows\System32\DRIVERS\CS420x86.sys [14336 2010-10-14] (Cirrus Logic)
S3 cleanhlp; C:\EEK\Run\cleanhlp32.sys [50200 2014-07-15] (Emsisoft GmbH)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [30976 2014-07-15] ()
R3 IRRemoteFlt; C:\Windows\System32\DRIVERS\IRFilter.sys [16512 2009-07-22] (Apple Inc.)
S3 ivusb; C:\Windows\System32\DRIVERS\ivusb.sys [25112 2010-07-29] (Initio Corporation)
R2 KeyAgent; C:\Windows\system32\drivers\KeyAgent.sys [15064 2011-08-15] (Apple Inc.)
R3 KeyMagic; C:\Windows\System32\DRIVERS\KeyMagic.sys [26624 2011-06-02] (Apple Inc.)
R2 MacHALDriver; C:\Windows\system32\drivers\MacHALDriver.sys [12928 2010-11-11] (Apple Inc.) [File not signed]
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R1 MpKsl145d4348; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B58D824D-9214-463E-BC6A-DFEC47D15DD2}\MpKsl145d4348.sys [39464 2014-07-16] (Microsoft Corporation)
R1 RapportCerberus_69108; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_69108.sys [358040 2014-07-01] ()
R1 SDHookDriver; C:\Program Files\Spybot - Search & Destroy 2\SDHookDrv32.sys [46336 2014-04-25] ()
S1 utqhtnmu; \??\C:\Windows\system32\drivers\utqhtnmu.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-16 21:00 - 2014-07-16 21:02 - 00025114 _____ () C:\Users\Deepthought\Desktop\FRST.txt
2014-07-16 20:59 - 2014-07-16 21:00 - 00000000 ___DC () C:\FRST
2014-07-16 20:56 - 2014-07-16 20:58 - 01077248 _____ (Farbar) C:\Users\Deepthought\Desktop\FRST.exe
2014-07-16 19:10 - 2014-07-16 19:10 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{31B3CBAF-3860-4837-B99E-07DEF9A173C3}
2014-07-16 01:26 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-07-16 01:00 - 2014-07-16 01:01 - 01348263 _____ () C:\Users\Deepthought\Desktop\adwcleaner_3.215.exe
2014-07-15 23:02 - 2014-07-15 23:02 - 00000554 _____ () C:\Users\Deepthought\Desktop\Emsisoft Emergency Kit.lnk
2014-07-15 23:01 - 2014-07-15 23:02 - 00000000 ___DC () C:\EEK
2014-07-15 22:28 - 2014-07-15 22:40 - 217618512 _____ () C:\Users\Deepthought\Desktop\EmsisoftEmergencyKit.exe
2014-07-15 20:31 - 2014-07-15 20:31 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA%
2014-07-15 20:29 - 2014-07-15 20:29 - 00011666 _____ () C:\Windows\system32\.crusader
2014-07-15 20:25 - 2014-07-15 20:26 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{1CC84C3F-5234-41E3-B877-79A928388AE4}
2014-07-15 18:01 - 2014-07-15 22:02 - 00030976 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys
2014-07-15 18:01 - 2014-07-15 20:52 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-07-15 17:40 - 2014-07-15 17:44 - 10278752 _____ (SurfRight B.V.) C:\Users\Deepthought\Desktop\HitmanPro.exe
2014-07-15 16:58 - 2014-07-15 16:58 - 04770904 _____ () C:\Users\Deepthought\Desktop\RogueKiller.exe
2014-07-15 16:58 - 2014-07-15 16:58 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-15 16:58 - 2014-07-15 16:58 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-15 16:42 - 2014-07-15 16:42 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{77A0E663-7497-4EB3-9F78-AAF3848852C1}
2014-07-15 15:56 - 2014-07-15 15:57 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-15 15:54 - 2014-07-15 15:54 - 00001072 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-15 15:54 - 2014-07-15 15:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-15 15:54 - 2014-07-15 15:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-15 15:54 - 2014-07-15 15:54 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-15 15:54 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-15 15:54 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-15 15:54 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-15 15:51 - 2014-07-15 15:53 - 00000000 ____D () C:\Users\Deepthought\Desktop\PHONEpics
2014-07-15 15:46 - 2014-07-15 15:47 - 00000000 ____D () C:\Users\Deepthought\Desktop\MEETUP
2014-07-15 15:43 - 2014-07-15 15:51 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Deepthought\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-15 15:18 - 2014-07-15 15:21 - 00004106 _____ () C:\Users\Deepthought\Desktop\Rkill.txt
2014-07-15 15:17 - 2014-07-15 15:17 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Deepthought\Desktop\iExplore.exe
2014-07-15 09:32 - 2014-07-15 09:33 - 04161313 _____ () C:\Users\Deepthought\Desktop\tdsskiller.zip
2014-07-14 19:39 - 2014-07-14 19:39 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{6416ACD6-B9A2-4429-872D-32140E2F3BFF}
2014-07-14 10:31 - 2014-07-14 10:31 - 00026431 _____ () C:\Users\Deepthought\Desktop\BenKPJGCIAA0pQ0.jpg-large
2014-07-14 04:24 - 2014-07-14 04:24 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{35A40651-0B1C-47EE-BEE5-AAF34836014D}
2014-07-13 19:39 - 2014-07-13 19:39 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{D35EEFE3-464C-41DC-9208-E6E63E7A061C}
2014-07-13 07:38 - 2014-07-13 07:38 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{FB1D2D8B-9B56-49FA-9ECC-484AB1828572}
2014-07-11 23:11 - 2014-07-11 23:11 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{64A09E20-2241-49F2-B4CB-EE36E91BE3F9}
2014-07-11 11:09 - 2014-07-11 11:10 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{27D684E6-C595-4DEB-B127-8672F91B43EC}
2014-07-10 22:21 - 2014-07-10 22:22 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{EF7F3A1F-D49E-4305-9440-CACD70B4973B}
2014-07-10 10:20 - 2014-07-10 10:20 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{46083193-0907-45F5-8740-5E137371A465}
2014-07-09 12:50 - 2014-07-09 12:51 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{CB307D25-1908-4450-823D-2C5E5DD78EBD}
2014-07-09 09:23 - 2014-06-18 02:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 09:23 - 2014-06-18 01:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 09:22 - 2014-06-20 20:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 09:22 - 2014-06-19 01:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 09:22 - 2014-06-19 00:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 09:22 - 2014-06-19 00:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 09:22 - 2014-06-19 00:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 09:22 - 2014-06-19 00:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 09:22 - 2014-06-19 00:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 09:22 - 2014-06-19 00:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 09:22 - 2014-06-19 00:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 09:22 - 2014-06-19 00:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 09:22 - 2014-06-19 00:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 09:22 - 2014-06-19 00:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 09:22 - 2014-06-19 00:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 09:22 - 2014-06-19 00:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 09:22 - 2014-06-19 00:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 09:22 - 2014-06-19 00:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 09:22 - 2014-06-19 00:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 09:22 - 2014-06-19 00:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 09:22 - 2014-06-19 00:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 09:22 - 2014-06-18 23:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 09:22 - 2014-06-18 23:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 09:22 - 2014-06-18 23:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 09:22 - 2014-06-18 23:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 09:22 - 2014-06-18 23:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 09:22 - 2014-06-18 23:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 09:22 - 2014-06-18 23:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 09:22 - 2014-06-18 23:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 09:22 - 2014-06-18 23:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 09:22 - 2014-06-18 23:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 09:22 - 2014-06-18 23:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 09:21 - 2014-06-06 10:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 09:21 - 2014-05-30 07:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 09:20 - 2014-06-05 15:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 00:50 - 2014-07-09 00:50 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{E97D9699-FD93-42D8-A0BA-D2197A121887}
2014-07-08 12:48 - 2014-07-08 12:49 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{16A04795-E2C9-46F2-A78D-7B2E6A9EF315}
2014-07-07 23:48 - 2014-07-07 23:48 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{B964613C-EFEA-4D5E-B9C5-8E42917EFEB0}
2014-07-07 09:02 - 2014-07-07 09:03 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{EB8204C1-9A9F-4099-B541-904740D699E1}
2014-07-06 20:12 - 2014-07-06 20:12 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{8A0B1C74-6C83-45DE-8709-58800D3E020D}
2014-07-06 07:27 - 2014-07-06 07:28 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{F23F1E6D-57FE-4793-B1BD-9D97067BA30E}
2014-07-05 15:41 - 2014-07-05 15:41 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{D3440294-5D52-46CB-A7B4-AE9013D8AA35}
2014-07-04 21:24 - 2014-07-04 21:24 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{6F98FD79-1BEB-40F8-90ED-750C0248E870}
2014-07-04 20:57 - 2014-07-04 20:57 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{FC840846-BBC9-488C-9539-C1271A027537}
2014-07-04 11:00 - 2014-07-04 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140704-110010.backup
2014-07-04 02:34 - 2014-07-04 02:34 - 00001005 _____ () C:\Users\Deepthought\Desktop\KMPlayer.lnk
2014-07-04 01:58 - 2014-07-04 01:58 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{513F9C20-8D99-4E79-9D43-861AD1F6C255}
2014-07-03 13:56 - 2014-07-03 13:56 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{8B7BA651-3BC0-4775-A15C-565DF1FF3BF4}
2014-07-03 12:44 - 2014-07-03 12:51 - 00000000 ____D () C:\Users\Deepthought\Desktop\INDIA-FabricRoof
2014-07-03 01:55 - 2014-07-03 01:55 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{B8500B17-BA60-4C4B-9C97-CCF7FF09E5BE}
2014-07-01 18:43 - 2006-10-29 13:47 - 80680414 _____ () C:\Users\Deepthought\Desktop\onegbstickdownload 372.avi
2014-07-01 18:43 - 2006-10-29 13:46 - 65434204 _____ () C:\Users\Deepthought\Desktop\onegbstickdownload 371.avi
2014-07-01 18:04 - 2014-07-15 15:51 - 00000000 ____D () C:\Users\Deepthought\Desktop\INDIA-MalabarCoveAREA
2014-07-01 09:26 - 2014-07-01 09:50 - 00000000 ____D () C:\Users\Deepthought\Desktop\New folder
2014-07-01 08:51 - 2014-07-01 08:52 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{01B29BEC-F855-4652-BEC2-50170D5CEB09}
2014-07-01 08:14 - 2014-07-15 15:47 - 00000000 ____D () C:\Users\Deepthought\Desktop\Ruby
2014-07-01 07:51 - 2014-07-01 01:06 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140701-075131.backup
2014-07-01 01:06 - 2014-07-01 01:00 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140701-010638.backup
2014-06-30 13:36 - 2014-06-30 13:36 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{CEE202D4-29A3-4315-8BB0-C83871FC238F}
2014-06-29 10:20 - 2014-06-29 10:20 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{CCB63173-E9CF-40E0-B6BE-29DC5BD00266}
2014-06-28 01:37 - 2014-06-28 01:38 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{A698F8D0-CEAB-4F0E-BBD6-43217ACEAAF1}
2014-06-27 10:34 - 2014-06-27 10:34 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{12A763A3-A038-4CB4-87EB-C9D114461427}
2014-06-26 11:16 - 2014-06-26 11:16 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{CB532378-AA6D-4325-88EE-2628F259CF79}
2014-06-25 10:38 - 2014-06-25 10:38 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{BB19FA91-21A6-4386-AC48-266875E6D252}
2014-06-24 21:26 - 2014-06-24 21:26 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{8D038CA3-EAC5-4FAC-8975-61B50091F8A1}
2014-06-24 09:19 - 2014-06-24 09:19 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{4CCC6915-995B-40AB-A6C7-EB155F65C8BC}
2014-06-24 07:40 - 2014-06-24 07:40 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{975C687B-156F-4315-A763-F69FAD29F6E4}
2014-06-23 20:44 - 2014-07-16 20:49 - 00000932 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3687737911-3880605115-1145795470-1000UA1cf8f1b84915640.job
2014-06-23 20:44 - 2014-07-16 20:49 - 00000880 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3687737911-3880605115-1145795470-1000Core1cf8f1b8079ab20.job
2014-06-23 12:15 - 2014-06-23 12:15 - 00123544 _____ (Trusteer Ltd.) C:\Windows\system32\Drivers\RapportKELL.sys
2014-06-23 10:50 - 2014-06-23 10:50 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{FEA04448-B587-4194-82EA-EDD494E471AC}
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.003
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.002
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.000
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL
2014-06-23 10:47 - 2013-12-13 00:45 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL\AppData\Local\Trusteer
2014-06-23 10:47 - 2013-12-13 00:45 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.003\AppData\Local\Trusteer
2014-06-23 10:47 - 2013-12-13 00:45 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.002\AppData\Local\Trusteer
2014-06-23 10:47 - 2013-12-13 00:45 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001\AppData\Local\Trusteer
2014-06-23 10:47 - 2013-12-13 00:45 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.000\AppData\Local\Trusteer
2014-06-23 02:00 - 2009-06-10 22:39 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.20140623-020043.backup
2014-06-23 01:38 - 2014-07-04 02:27 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-23 01:38 - 2014-06-23 01:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-23 01:38 - 2014-06-23 01:38 - 00002143 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-23 01:38 - 2014-06-23 01:38 - 00002131 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-23 01:38 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2014-06-23 01:36 - 2014-06-23 02:05 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2014-06-23 01:34 - 2014-06-23 01:34 - 00560976 _____ (Safer-Networking Ltd. ) C:\Users\Deepthought\Desktop\spybot2-license.exe
2014-06-22 22:20 - 2014-06-22 22:20 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{23B059E2-3329-473D-B955-20B74F8DB45C}
2014-06-22 10:18 - 2014-06-22 10:18 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{DD2ECD8C-7AE2-48CA-BB50-CB34F6FB093D}
2014-06-21 19:47 - 2014-06-21 19:47 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{56B89618-DF86-4CC0-BBF2-913245DCFD95}
2014-06-21 07:48 - 2014-06-21 07:48 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{36F1CC58-7B3F-49A6-9BAC-965C374511E1}
2014-06-20 19:47 - 2014-06-20 19:48 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{DDBA49F2-2322-479D-8F9C-515893E8A51D}
2014-06-20 05:03 - 2014-06-20 05:03 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{27FFA68F-8A24-458F-9639-A3E834846A6E}
2014-06-18 13:50 - 2014-06-18 15:27 - 00000000 ____D () C:\Users\Deepthought\Desktop\SeaBreeze-PHILIP
2014-06-18 11:35 - 2014-06-18 11:35 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{11769BB7-B731-4480-B2A9-D5E654165529}
2014-06-18 08:55 - 2014-07-16 20:47 - 00000000 ____D () C:\Users\Deepthought\Desktop\QUICKpics
2014-06-17 23:33 - 2014-06-17 23:33 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{300F6281-E828-46E1-9802-77B4EB28F76A}
2014-06-17 11:32 - 2014-06-17 11:32 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{5AF02409-6533-47F0-95B4-EA0D4C73EC34}
2014-06-16 23:31 - 2014-06-16 23:31 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{D2462926-68E7-4492-91A4-A0F0498BBCAA}
2014-06-16 11:29 - 2014-06-16 11:29 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{B0706808-988B-4925-B6EF-C0BEB6BA4DF0}
2014-06-16 10:35 - 2014-06-16 10:35 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{8A7C9E06-8126-455B-ACB5-5CFF26C81071}
==================== One Month Modified Files and Folders =======
2014-07-16 21:02 - 2014-07-16 21:00 - 00025114 _____ () C:\Users\Deepthought\Desktop\FRST.txt
2014-07-16 21:00 - 2014-07-16 20:59 - 00000000 ___DC () C:\FRST
2014-07-16 20:58 - 2014-07-16 20:56 - 01077248 _____ (Farbar) C:\Users\Deepthought\Desktop\FRST.exe
2014-07-16 20:49 - 2014-06-23 20:44 - 00000932 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3687737911-3880605115-1145795470-1000UA1cf8f1b84915640.job
2014-07-16 20:49 - 2014-06-23 20:44 - 00000880 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3687737911-3880605115-1145795470-1000Core1cf8f1b8079ab20.job
2014-07-16 20:47 - 2014-06-18 08:55 - 00000000 ____D () C:\Users\Deepthought\Desktop\QUICKpics
2014-07-16 20:42 - 2014-02-11 15:25 - 00000932 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3687737911-3880605115-1145795470-1000UA.job
2014-07-16 20:38 - 2011-05-23 18:38 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-16 20:28 - 2012-07-28 23:47 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-16 19:58 - 2010-01-03 18:19 - 01254977 _____ () C:\Windows\WindowsUpdate.log
2014-07-16 19:10 - 2014-07-16 19:10 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{31B3CBAF-3860-4837-B99E-07DEF9A173C3}
2014-07-16 18:38 - 2011-05-23 18:38 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-16 09:00 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-07-16 02:05 - 2009-07-14 05:34 - 00013984 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-16 02:05 - 2009-07-14 05:34 - 00013984 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-16 01:58 - 2010-08-31 19:55 - 00000000 ____D () C:\Users\Deepthought\Tracing
2014-07-16 01:57 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-16 01:56 - 2012-08-02 17:59 - 00052429 _____ () C:\Windows\setupact.log
2014-07-16 01:56 - 2010-01-03 18:37 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-16 01:56 - 2010-01-03 18:36 - 00250138 _____ () C:\Windows\PFRO.log
2014-07-16 01:39 - 2013-10-06 12:29 - 00000000 ___DC () C:\AdwCleaner
2014-07-16 01:01 - 2014-07-16 01:00 - 01348263 _____ () C:\Users\Deepthought\Desktop\adwcleaner_3.215.exe
2014-07-15 23:02 - 2014-07-15 23:02 - 00000554 _____ () C:\Users\Deepthought\Desktop\Emsisoft Emergency Kit.lnk
2014-07-15 23:02 - 2014-07-15 23:01 - 00000000 ___DC () C:\EEK
2014-07-15 22:44 - 2014-02-11 15:25 - 00000880 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3687737911-3880605115-1145795470-1000Core.job
2014-07-15 22:40 - 2014-07-15 22:28 - 217618512 _____ () C:\Users\Deepthought\Desktop\EmsisoftEmergencyKit.exe
2014-07-15 22:02 - 2014-07-15 18:01 - 00030976 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys
2014-07-15 20:52 - 2014-07-15 18:01 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-07-15 20:31 - 2014-07-15 20:31 - 00000000 ____D () C:\Windows\system32\%LOCALAPPDATA%
2014-07-15 20:29 - 2014-07-15 20:29 - 00011666 _____ () C:\Windows\system32\.crusader
2014-07-15 20:26 - 2014-07-15 20:25 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{1CC84C3F-5234-41E3-B877-79A928388AE4}
2014-07-15 17:44 - 2014-07-15 17:40 - 10278752 _____ (SurfRight B.V.) C:\Users\Deepthought\Desktop\HitmanPro.exe
2014-07-15 16:58 - 2014-07-15 16:58 - 04770904 _____ () C:\Users\Deepthought\Desktop\RogueKiller.exe
2014-07-15 16:58 - 2014-07-15 16:58 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-15 16:58 - 2014-07-15 16:58 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-15 16:42 - 2014-07-15 16:42 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{77A0E663-7497-4EB3-9F78-AAF3848852C1}
2014-07-15 16:37 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\registration
2014-07-15 15:57 - 2014-07-15 15:56 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-15 15:54 - 2014-07-15 15:54 - 00001072 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-15 15:54 - 2014-07-15 15:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-15 15:54 - 2014-07-15 15:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-15 15:54 - 2014-07-15 15:54 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-15 15:53 - 2014-07-15 15:51 - 00000000 ____D () C:\Users\Deepthought\Desktop\PHONEpics
2014-07-15 15:53 - 2014-02-24 16:19 - 00000000 ____D () C:\Users\Deepthought\Desktop\DARTFORD
2014-07-15 15:51 - 2014-07-15 15:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Deepthought\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-15 15:51 - 2014-07-01 18:04 - 00000000 ____D () C:\Users\Deepthought\Desktop\INDIA-MalabarCoveAREA
2014-07-15 15:50 - 2014-06-11 17:44 - 00000000 ____D () C:\Users\Deepthought\Desktop\CHESTERFIELDandNEAR-property
2014-07-15 15:47 - 2014-07-15 15:46 - 00000000 ____D () C:\Users\Deepthought\Desktop\MEETUP
2014-07-15 15:47 - 2014-07-01 08:14 - 00000000 ____D () C:\Users\Deepthought\Desktop\Ruby
2014-07-15 15:21 - 2014-07-15 15:18 - 00004106 _____ () C:\Users\Deepthought\Desktop\Rkill.txt
2014-07-15 15:17 - 2014-07-15 15:17 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Deepthought\Desktop\iExplore.exe
2014-07-15 15:11 - 2011-12-31 13:35 - 16832512 ___SH () C:\Users\Deepthought\Desktop\Thumbs.db
2014-07-15 09:33 - 2014-07-15 09:32 - 04161313 _____ () C:\Users\Deepthought\Desktop\tdsskiller.zip
2014-07-15 00:35 - 2014-05-08 22:35 - 00000069 _____ () C:\Users\Deepthought\AppData\Roaming\WB.CFG
2014-07-14 22:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-14 19:39 - 2014-07-14 19:39 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{6416ACD6-B9A2-4429-872D-32140E2F3BFF}
2014-07-14 10:31 - 2014-07-14 10:31 - 00026431 _____ () C:\Users\Deepthought\Desktop\BenKPJGCIAA0pQ0.jpg-large
2014-07-14 04:24 - 2014-07-14 04:24 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{35A40651-0B1C-47EE-BEE5-AAF34836014D}
2014-07-13 19:39 - 2014-07-13 19:39 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{D35EEFE3-464C-41DC-9208-E6E63E7A061C}
2014-07-13 17:08 - 2013-11-12 11:05 - 00000000 ____D () C:\Users\Deepthought\Desktop\CALENDARS-2013-2014
2014-07-13 07:38 - 2014-07-13 07:38 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{FB1D2D8B-9B56-49FA-9ECC-484AB1828572}
2014-07-11 23:11 - 2014-07-11 23:11 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{64A09E20-2241-49F2-B4CB-EE36E91BE3F9}
2014-07-11 11:10 - 2014-07-11 11:09 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{27D684E6-C595-4DEB-B127-8672F91B43EC}
2014-07-10 22:22 - 2014-07-10 22:21 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{EF7F3A1F-D49E-4305-9440-CACD70B4973B}
2014-07-10 10:20 - 2014-07-10 10:20 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{46083193-0907-45F5-8740-5E137371A465}
2014-07-09 15:29 - 2014-02-19 20:45 - 00000000 ____D () C:\Windows\rescache
2014-07-09 15:29 - 2012-07-28 23:47 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-09 15:29 - 2012-07-28 23:47 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 13:42 - 2009-07-14 05:33 - 00308528 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 13:33 - 2009-07-14 08:50 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 13:29 - 2013-07-15 22:41 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 13:24 - 2010-07-15 17:17 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 12:51 - 2014-07-09 12:50 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{CB307D25-1908-4450-823D-2C5E5DD78EBD}
2014-07-09 00:50 - 2014-07-09 00:50 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{E97D9699-FD93-42D8-A0BA-D2197A121887}
2014-07-08 12:49 - 2014-07-08 12:48 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{16A04795-E2C9-46F2-A78D-7B2E6A9EF315}
2014-07-07 23:48 - 2014-07-07 23:48 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{B964613C-EFEA-4D5E-B9C5-8E42917EFEB0}
2014-07-07 09:03 - 2014-07-07 09:02 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{EB8204C1-9A9F-4099-B541-904740D699E1}
2014-07-06 20:12 - 2014-07-06 20:12 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{8A0B1C74-6C83-45DE-8709-58800D3E020D}
2014-07-06 07:28 - 2014-07-06 07:27 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{F23F1E6D-57FE-4793-B1BD-9D97067BA30E}
2014-07-05 15:41 - 2014-07-05 15:41 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{D3440294-5D52-46CB-A7B4-AE9013D8AA35}
2014-07-05 01:48 - 2009-07-14 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140709-015546.backup
2014-07-05 01:42 - 2010-01-03 18:25 - 00000000 ____D () C:\Users\Deepthought
2014-07-04 21:24 - 2014-07-04 21:24 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{6F98FD79-1BEB-40F8-90ED-750C0248E870}
2014-07-04 20:57 - 2014-07-04 20:57 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{FC840846-BBC9-488C-9539-C1271A027537}
2014-07-04 13:49 - 2010-01-03 18:28 - 00849992 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-04 11:00 - 2009-07-14 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140705-014832.backup
2014-07-04 03:04 - 2014-07-04 11:00 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140704-110010.backup
2014-07-04 02:34 - 2014-07-04 02:34 - 00001005 _____ () C:\Users\Deepthought\Desktop\KMPlayer.lnk
2014-07-04 02:27 - 2014-06-23 01:38 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-07-04 01:58 - 2014-07-04 01:58 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{513F9C20-8D99-4E79-9D43-861AD1F6C255}
2014-07-03 13:56 - 2014-07-03 13:56 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{8B7BA651-3BC0-4775-A15C-565DF1FF3BF4}
2014-07-03 12:51 - 2014-07-03 12:44 - 00000000 ____D () C:\Users\Deepthought\Desktop\INDIA-FabricRoof
2014-07-03 01:55 - 2014-07-03 01:55 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{B8500B17-BA60-4C4B-9C97-CCF7FF09E5BE}
2014-07-02 00:46 - 2009-07-14 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140704-030425.backup
2014-07-01 09:50 - 2014-07-01 09:26 - 00000000 ____D () C:\Users\Deepthought\Desktop\New folder
2014-07-01 08:54 - 2013-10-07 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2014-07-01 08:52 - 2014-07-01 08:51 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{01B29BEC-F855-4652-BEC2-50170D5CEB09}
2014-07-01 07:51 - 2009-07-14 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140702-004654.backup
2014-07-01 01:06 - 2014-07-01 07:51 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140701-075131.backup
2014-07-01 01:00 - 2014-07-01 01:06 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140701-010638.backup
2014-06-30 13:36 - 2014-06-30 13:36 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{CEE202D4-29A3-4315-8BB0-C83871FC238F}
2014-06-29 10:20 - 2014-06-29 10:20 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{CCB63173-E9CF-40E0-B6BE-29DC5BD00266}
2014-06-28 01:38 - 2014-06-28 01:37 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{A698F8D0-CEAB-4F0E-BBD6-43217ACEAAF1}
2014-06-27 10:34 - 2014-06-27 10:34 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{12A763A3-A038-4CB4-87EB-C9D114461427}
2014-06-26 11:16 - 2014-06-26 11:16 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{CB532378-AA6D-4325-88EE-2628F259CF79}
2014-06-25 10:38 - 2014-06-25 10:38 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{BB19FA91-21A6-4386-AC48-266875E6D252}
2014-06-24 21:28 - 2014-05-27 13:50 - 00001980 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-06-24 21:28 - 2012-12-21 15:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-06-24 21:28 - 2010-01-03 18:32 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-06-24 21:28 - 2010-01-03 18:29 - 00906264 _____ () C:\Windows\DPINST.LOG
2014-06-24 21:26 - 2014-06-24 21:26 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{8D038CA3-EAC5-4FAC-8975-61B50091F8A1}
2014-06-24 10:54 - 2009-07-14 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140701-010054.backup
2014-06-24 09:19 - 2014-06-24 09:19 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{4CCC6915-995B-40AB-A6C7-EB155F65C8BC}
2014-06-24 07:46 - 2009-07-14 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140624-105445.backup
2014-06-24 07:40 - 2014-06-24 07:40 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{975C687B-156F-4315-A763-F69FAD29F6E4}
2014-06-23 23:04 - 2013-05-15 15:27 - 00000000 ____D () C:\Users\DefaultAppPool
2014-06-23 12:15 - 2014-06-23 12:15 - 00123544 _____ (Trusteer Ltd.) C:\Windows\system32\Drivers\RapportKELL.sys
2014-06-23 10:50 - 2014-06-23 10:50 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{FEA04448-B587-4194-82EA-EDD494E471AC}
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.003
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.002
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.001
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL.000
2014-06-23 10:47 - 2014-06-23 10:47 - 00000000 ____D () C:\Users\TEMP.IIS APPPOOL
2014-06-23 10:43 - 2009-07-14 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140624-074626.backup
2014-06-23 02:16 - 2014-05-08 21:35 - 00000000 ____D () C:\Program Files\004
2014-06-23 02:05 - 2014-06-23 01:36 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2014-06-23 02:00 - 2009-07-14 03:04 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140623-104341.backup
2014-06-23 01:39 - 2014-06-23 01:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-23 01:38 - 2014-06-23 01:38 - 00002143 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-23 01:38 - 2014-06-23 01:38 - 00002131 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-23 01:34 - 2014-06-23 01:34 - 00560976 _____ (Safer-Networking Ltd. ) C:\Users\Deepthought\Desktop\spybot2-license.exe
2014-06-22 22:20 - 2014-06-22 22:20 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{23B059E2-3329-473D-B955-20B74F8DB45C}
2014-06-22 10:18 - 2014-06-22 10:18 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{DD2ECD8C-7AE2-48CA-BB50-CB34F6FB093D}
2014-06-21 19:47 - 2014-06-21 19:47 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{56B89618-DF86-4CC0-BBF2-913245DCFD95}
2014-06-21 07:48 - 2014-06-21 07:48 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{36F1CC58-7B3F-49A6-9BAC-965C374511E1}
2014-06-20 20:39 - 2014-07-09 09:22 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-20 19:48 - 2014-06-20 19:47 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{DDBA49F2-2322-479D-8F9C-515893E8A51D}
2014-06-20 05:03 - 2014-06-20 05:03 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{27FFA68F-8A24-458F-9639-A3E834846A6E}
2014-06-19 01:16 - 2014-07-09 09:22 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-19 00:56 - 2014-07-09 09:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-19 00:56 - 2014-07-09 09:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-19 00:38 - 2014-07-09 09:22 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-19 00:37 - 2014-07-09 09:22 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-19 00:36 - 2014-07-09 09:22 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-19 00:35 - 2014-07-09 09:22 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-19 00:32 - 2014-07-09 09:22 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-19 00:28 - 2014-07-09 09:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-19 00:28 - 2014-07-09 09:22 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-19 00:25 - 2014-07-09 09:22 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-19 00:23 - 2014-07-09 09:22 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-19 00:23 - 2014-07-09 09:22 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-19 00:22 - 2014-07-09 09:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-19 00:16 - 2014-07-09 09:22 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-19 00:12 - 2014-07-09 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-19 00:06 - 2014-07-09 09:22 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-19 00:01 - 2014-07-09 09:22 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-18 23:59 - 2014-07-09 09:22 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-18 23:58 - 2014-07-09 09:22 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-18 23:52 - 2014-07-09 09:22 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-18 23:52 - 2014-07-09 09:22 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-18 23:49 - 2014-07-09 09:22 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-18 23:46 - 2014-07-09 09:22 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-18 23:45 - 2014-07-09 09:22 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-18 23:35 - 2014-07-09 09:22 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-18 23:13 - 2014-07-09 09:22 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-18 23:09 - 2014-07-09 09:22 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-18 23:07 - 2014-07-09 09:22 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-18 15:27 - 2014-06-18 13:50 - 00000000 ____D () C:\Users\Deepthought\Desktop\SeaBreeze-PHILIP
2014-06-18 11:35 - 2014-06-18 11:35 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{11769BB7-B731-4480-B2A9-D5E654165529}
2014-06-18 02:51 - 2014-07-09 09:23 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-06-18 01:52 - 2014-07-09 09:23 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-06-17 23:33 - 2014-06-17 23:33 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{300F6281-E828-46E1-9802-77B4EB28F76A}
2014-06-17 11:32 - 2014-06-17 11:32 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{5AF02409-6533-47F0-95B4-EA0D4C73EC34}
2014-06-16 23:31 - 2014-06-16 23:31 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{D2462926-68E7-4492-91A4-A0F0498BBCAA}
2014-06-16 11:29 - 2014-06-16 11:29 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{B0706808-988B-4925-B6EF-C0BEB6BA4DF0}
2014-06-16 10:35 - 2014-06-16 10:35 - 00000000 ____D () C:\Users\Deepthought\AppData\Local\{8A7C9E06-8126-455B-ACB5-5CFF26C81071}
Some content of TEMP:
====================
C:\Users\Deepthought\AppData\Local\Temp\DataCard_Setup.exe
C:\Users\Deepthought\AppData\Local\Temp\ose00000.exe
C:\Users\Deepthought\AppData\Local\Temp\Quarantine.exe
C:\Users\Deepthought\AppData\Local\Temp\ResetDevice.exe
C:\Users\Deepthought\AppData\Local\Temp\SymcPCCUInstaller.exe
C:\Users\Deepthought\AppData\Local\Temp\_is78F6.exe
C:\Users\Deepthought\AppData\Local\Temp\_is7F3D.exe
C:\Users\Deepthought\AppData\Local\Temp\_isE9F0.exe
C:\Users\Deepthought\AppData\Local\Temp\_isF5B3.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-08 15:18
==================== End Of Log ============================