Im not sure I notice a difference now although it does seem much faster, its hard to tell but here are the logs you asked for.
# AdwCleaner v5.022 - Logfile created 22/11/2015 at 16:47:46
# Updated 22/11/2015 by Xplode
# Database : 2015-11-22.2 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Dirtbag - DIRTBAG-PC
# Running from : C:\\Users\\Dirtbag\\Desktop\\AdwCleaner.exe
# Option : Cleaning
# Support :
http://toolslib.net/forum\'>
http://toolslib.net/forum***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\\Program Files\\WebBar
[-] Folder Deleted : C:\\Program Files (x86)\\DriverTuner
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.0 (11.12.2015)
Operating System: Windows 7 Professional x64
Ran by Dirtbag (Administrator) on Sun 11/22/2015 at 16:54:26.93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 1
Successfully deleted: C:\\Users\\Dirtbag\\AppData\\Local\\crashrpt (Folder)
Registry: 2
Successfully deleted: HKLM\\SYSTEM\\CurrentControlSet\\services\\DrvAgent64 (Registry Key)
Successfully deleted: HKLM\\Software\\Microsoft\\Internet Explorer\\Search\\\\SearchAssistant (Registry Value)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 11/22/2015 at 16:57:04.13
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
***** [ Files ] *****
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
[-] Task Deleted : LaunchSignup
***** [ Registry ] *****
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\CLSID\\{21FA44EF-376D-4D53-9B0F-8A89D3229068}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{C1F5E799-B218-4C32-B189-3C389BA140BB}
[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\Interface\\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
[-] Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{21FA44EF-376D-4D53-9B0F-8A89D3229068}
[-] Key Deleted : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{21FA44EF-376D-4D53-9B0F-8A89D3229068}
[-] Value Deleted : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Toolbar [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{C1F5E799-B218-4C32-B189-3C389BA140BB}
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\Classes\\Interface\\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
[-] Key Deleted : HKCU\\Software\\APN PIP
[-] Key Deleted : HKCU\\Software\\Define Ext
[-] Key Deleted : HKLM\\SOFTWARE\\Define Ext
[-] Key Deleted : HKLM\\SOFTWARE\\DriverTuner_Init
[-] Key Deleted : HKLM\\SOFTWARE\\DriverTuner
[-] Key Deleted : HKLM\\SOFTWARE\\W3I
[-] Key Deleted : [x64] HKLM\\SOFTWARE\\WebBar
[-] Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes [DefaultScope]
[-] Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\DOMStorage\\plarium.com
[-] Key Deleted : HKCU\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\DOMStorage\\shopathome.com
***** [ Web browsers ] *****
[-] [C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data] [Search Provider] Deleted : Email Removed
[-] [C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data] [Search Provider] Deleted : ask.com
*************************
:: \"Tracing\" keys removed
:: Winsock settings cleared
########## EOF - C:\\AdwCleaner\\AdwCleaner[C1].txt - [3817 bytes] ##########
Getting user folders.
Stopping running processes.
Emptying Temp folders.
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 313336 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Dirtbag
->Temp folder emptied: 121607210 bytes
->Temporary Internet Files folder emptied: 1707755903 bytes
->Java cache emptied: 31329 bytes
->Google Chrome cache emptied: 423168542 bytes
->Flash cache emptied: 203273 bytes
User: Public
->Temp folder emptied: 0 bytes
User: TEMP
->Temp folder emptied: 0 bytes
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: UpdatusUser.Dirtbag-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1524669 bytes
%systemroot%\\System32 .tmp files removed: 0 bytes
%systemroot%\\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\\System32\\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 326479796 bytes
%systemroot%\\system32\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files folder emptied: 128 bytes
%systemroot%\\system32\\config\\systemprofile\\AppData\\LocalLow\\Sun\\Java\\Deployment folder emptied: 755 bytes
%systemroot%\\sysnative\\config\\systemprofile\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files folder emptied: 128 bytes
Emptying RecycleBin. Do not interrupt.
RecycleBin emptied: 0 bytes
Process complete!
Total Files Cleaned = 2,462.00 mb
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:22-11-2015
Ran by Dirtbag (administrator) on DIRTBAG-PC (22-11-2015 17:05:36)
Running from C:\\Users\\Dirtbag\\Desktop
Loaded Profiles: Dirtbag (Available Profiles: Dirtbag & UpdatusUser)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/\'>
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\\Program Files\\AVAST Software\\Avast\\AvastSvc.exe
(Adobe Systems Incorporated) C:\\Program Files (x86)\\Adobe\\Elements Organizer 8.0\\PhotoshopElementsFileAgent.exe
() C:\\Program Files\\DAZ 3D\\Content Management Service\\ContentManagementServer.exe
(Fitbit, Inc.) C:\\Program Files (x86)\\Fitbit Connect\\FitbitConnectService.exe
() C:\\Windows\\SysWOW64\\PnkBstrA.exe
() C:\\Program Files (x86)\\Real\\UpdateService\\RealPlayerUpdateSvc.exe
(RealNetworks, Inc.) C:\\Program Files (x86)\\Real\\RealPlayer\\RPDS\\Bin\\rpdsvc.exe
(Microsoft Corp.) C:\\Program Files (x86)\\Microsoft\\Search Enhancement Pack\\SeaPort\\SeaPort.exe
(AVAST Software) C:\\Program Files\\AVAST Software\\Avast\\avastui.exe
(Microsoft Corporation) C:\\Windows\\System32\\dllhost.exe
(Adobe Systems Incorporated) C:\\Windows\\System32\\Macromed\\Flash\\FlashUtil64_19_0_0_185_ActiveX.exe
(Microsoft Corporation) C:\\Windows\\System32\\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\\Program Files\\Internet Explorer\\iexplore.exe
(Microsoft Corporation) C:\\Windows\\System32\\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\\...\\Run: [RtHDVCpl] => C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\\...\\Run: [NvBackend] => C:\\Program Files (x86)\\NVIDIA Corporation\\Update Core\\NvBackend.exe [1797064 2014-03-20] (NVIDIA Corporation)
HKLM-x32\\...\\Run: [JMB36X IDE Setup] => C:\\Windows\\RaidTool\\xInsIDE.exe
HKLM-x32\\...\\Run: [Adobe Reader Speed Launcher] => C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\\...\\Run: [Adobe ARM] => C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\\...\\Run: [DivXMediaServer] => C:\\Program Files (x86)\\DivX\\DivX Media Server\\DivXMediaServer.exe [448856 2014-08-18] (DivX, LLC)
HKLM-x32\\...\\Run: [DivXUpdate] => C:\\Program Files (x86)\\DivX\\DivX Update\\DivXUpdate.exe [1861968 2014-01-09] ()
HKLM-x32\\...\\Run: [AvastUI.exe] => C:\\Program Files\\AVAST Software\\Avast\\AvastUI.exe [6133520 2015-11-14] (AVAST Software)
HKLM-x32\\...\\Run: [Fitbit Connect] => C:\\Program Files (x86)\\Fitbit Connect\\Fitbit Connect.exe [4369952 2014-11-07] (Fitbit, Inc.)
HKLM-x32\\...\\Run: [TkBellExe] => c:\\program files (x86)\\real\\realplayer\\Update\\realsched.exe [286784 2015-09-08] (RealNetworks, Inc.)
HKLM-x32\\...\\Run: [RealDownloader] => C:\\Program Files (x86)\\RealNetworks\\RealDownloader\\downloader2.exe [614464 2015-07-27] ()
HKLM-x32\\...\\Run: [QuickTime Task] => C:\\Program Files (x86)\\QuickTime\\QTTask.exe [421888 2015-08-06] (Apple Inc.)
HKLM-x32\\...\\Run: [SunJavaUpdateSched] => C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM Group Policy restriction on software: *.pub*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\LocalLow\\*\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\\Users\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\LocalLow\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\\*\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Local\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\LocalLow\\*\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\\*\\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\\*\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\\*\\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\\*\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *:\\$Recycle.Bin <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Local\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\LocalLow\\*\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <====== ATTENTION
HKLM Group Policy restriction on software: ** <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\*\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\*\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\LocalLow\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\*\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\LocalLow\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\\*\\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\LocalLow\\*\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\\*\\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\*\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <====== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\\Users\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Local\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\LocalLow\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Local\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\\*\\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\Appdata\\Roaming\\Microsoft\\Windows\\IEUpdate\\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: C:\\Users\\*.exe <====== ATTENTION
HKLM\\...\\Policies\\Explorer: [RestrictRun] 0
HKU\\S-1-5-21-2787044202-2378965189-2633346745-1001\\...\\Run: [Web Companion] => C:\\Program Files (x86)\\Lavasoft\\Web Companion\\Application\\WebCompanion.exe --minimize
HKU\\S-1-5-21-2787044202-2378965189-2633346745-1001\\...\\Run: [Fitbit Connect] => C:\\Program Files (x86)\\Fitbit Connect\\Fitbit Connect.exe [4369952 2014-11-07] (Fitbit, Inc.)
HKU\\S-1-5-21-2787044202-2378965189-2633346745-1001\\...\\Run: [NETGEARGenie] => C:\\Program Files (x86)\\NETGEAR Genie\\bin\\NETGEARGenie.exe [603392 2015-08-26] (NETGEAR Inc.)
HKU\\S-1-5-21-2787044202-2378965189-2633346745-1001\\...\\Policies\\Explorer: [RestrictRun] 0
HKU\\S-1-5-21-2787044202-2378965189-2633346745-1001\\Control Panel\\Desktop\\\\SCRNSAVE.EXE -> C:\\Windows\\system32\\Ribbons.scr [241664 2010-11-20] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\\Program Files\\AVAST Software\\Avast\\ashShA64.dll [2015-09-20] (AVAST Software)
Startup: C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\RealTimes.lnk [2015-09-08]
ShortcutTarget: RealTimes.lnk -> C:\\Program Files (x86)\\Real\\RealPlayer\\RPDS\\Bin\\rpsystray.exe (RealNetworks, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] => Proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:52765;https=127.0.0.1:52765
Tcpip\\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\\..\\Interfaces\\{5C735FFA-6AC9-458C-84D7-71BB8BF6FDA3}: [NameServer] 208.67.222.222,208.67.220.220
Tcpip\\..\\Interfaces\\{5C735FFA-6AC9-458C-84D7-71BB8BF6FDA3}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\\SOFTWARE\\Policies\\Microsoft\\Internet Explorer: Restriction <======= ATTENTION
HKU\\S-1-5-21-2787044202-2378965189-2633346745-1001\\SOFTWARE\\Policies\\Microsoft\\Internet Explorer: Restriction <======= ATTENTION
HKLM\\Software\\Wow6432Node\\Microsoft\\Internet Explorer\\Main,Default_Search_URL =
SearchScopes: HKU\\S-1-5-21-2787044202-2378965189-2633346745-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\\Program Files (x86)\\RealNetworks\\RealDownloader\\BrowserPlugins\\IE\\rndlbrowserrecordplugin64.dll [2015-07-27] (RealDownloader)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\\Program Files\\AVAST Software\\Avast\\aswWebRepIE64.dll [2015-07-31] (AVAST Software)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\\Program Files (x86)\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\\Program Files (x86)\\RealNetworks\\RealDownloader\\BrowserPlugins\\IE\\rndlbrowserrecordplugin.dll [2015-07-27] (RealDownloader)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\\Program Files (x86)\\Microsoft\\Search Enhancement Pack\\Search Helper\\SearchHelper.dll [2009-01-14] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\\Program Files (x86)\\Java\\jre1.8.0_66\\bin\\ssv.dll [2015-11-18] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\\Program Files\\AVAST Software\\Avast\\aswWebRepIE.dll [2015-07-31] (AVAST Software)
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\\Program Files (x86)\\Java\\jre1.8.0_66\\bin\\jp2ssv.dll [2015-11-18] (Oracle Corporation)
BHO-x32: Windows Live Toolbar Helper -> {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -> C:\\Program Files (x86)\\Windows Live\\Toolbar\\wltcore.dll [2010-04-16] (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\\Program Files (x86)\\Windows Live\\Messenger\\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\\Program Files (x86)\\Windows Live\\Messenger\\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_18_0_0_232.dll [2015-09-08] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\\Program Files\\Microsoft Silverlight\\5.1.30514.0\\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_18_0_0_232.dll [2015-09-08] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\\Program Files (x86)\\DivX\\DivX OVS Helper\\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\\Program Files (x86)\\DivX\\DivX Web Player\\npdivx32.dll [2014-08-12] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\\Program Files (x86)\\Java\\jre1.8.0_66\\bin\\dtplugin\\npDeployJava1.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\\Program Files (x86)\\Java\\jre1.8.0_66\\bin\\plugin2\\npjp2.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\\Program Files (x86)\\Microsoft Silverlight\\5.1.30514.0\\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll [2010-04-16] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\\Program Files (x86)\\Pando Networks\\Media Booster\\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @real.com/nppl3260;version=18.0.2.59 -> c:\\program files (x86)\\real\\realplayer\\Netscape6\\nppl3260.dll [2015-09-08] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=18.0.2.59 -> c:\\program files (x86)\\real\\realplayer\\Netscape6\\nprpplugin.dll [2015-09-08] (RealTimes)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\\Program Files (x86)\\Google\\Update\\1.3.28.15\\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\\Program Files (x86)\\Google\\Update\\1.3.28.15\\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AIR\\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin HKU\\S-1-5-21-2787044202-2378965189-2633346745-1001: ubisoft.com/uplaypc -> C:\\Program Files (x86)\\Ubisoft\\Ubisoft Game Launcher\\npuplaypc.dll [2014-11-19] ()
FF HKLM-x32\\...\\Firefox\\Extensions: [
[email protected]] - C:\\Program Files\\AVAST Software\\Avast\\WebRep\\FF
FF Extension: Avast Online Security - C:\\Program Files\\AVAST Software\\Avast\\WebRep\\FF [2015-09-20] [not signed]
FF HKLM-x32\\...\\Firefox\\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\\ProgramData\\RealNetworks\\RealDownloader\\BrowserPlugins\\Firefox\\Ext => not found
Chrome:
=======
CHR DefaultSearchKeyword: Default -> yahoo.com
CHR Profile: C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default
CHR Extension: (Google Slides) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-03]
CHR Extension: (Google Docs) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aohghmighlieiainnegkcijnfilokake [2015-08-03]
CHR Extension: (Google Drive) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\apdfllckaahabafndbhieahigkjlhalf [2015-08-03]
CHR Extension: (YouTube) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-03]
CHR Extension: (Google Search) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-03]
CHR Extension: (Google Sheets) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\felcaaldnbdncclmgdcncolpebgiejap [2015-08-03]
CHR Extension: (Google Docs Offline) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03]
CHR Extension: (Avast Online Security) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\gomekmidlodglbbmalcneegieacbdmki [2015-08-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lccekmodgklaepjeofjdjpbminllajkg [2015-08-03]
CHR Extension: (Chrome Web Store Payments) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-03]
CHR Extension: (Gmail) - C:\\Users\\Dirtbag\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-03]
CHR HKLM-x32\\...\\Chrome\\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\\Program Files\\AVAST Software\\Avast\\WebRep\\Chrome\\aswWebRepChrome.crx [2015-03-19]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\\Program Files\\AVAST Software\\Avast\\AvastSvc.exe [146600 2015-09-20] (AVAST Software)
R2 DAZContentManagementService; C:\\Program Files\\DAZ 3D\\Content Management Service\\ContentManagementServer.exe [22528 2011-05-05] () [File not signed]
R2 Fitbit Connect; C:\\Program Files (x86)\\Fitbit Connect\\FitbitConnectService.exe [5738528 2014-11-07] (Fitbit, Inc.) [File not signed]
S3 NETGEARGenieDaemon; C:\\Program Files (x86)\\NETGEAR Genie\\bin\\NETGEARGenieDaemon64.exe [232192 2015-08-26] (NETGEAR)
R2 PnkBstrA; C:\\Windows\\SysWOW64\\PnkBstrA.exe [76888 2014-11-16] ()
R2 RealPlayerUpdateSvc; C:\\Program Files (x86)\\Real\\UpdateService\\RealPlayerUpdateSvc.exe [32880 2015-07-27] ()
R2 RealTimes Desktop Service; c:\\program files (x86)\\real\\realplayer\\RPDS\\Bin\\rpdsvc.exe [1115736 2015-09-08] (RealNetworks, Inc.)
S3 WinDefend; C:\\Program Files\\Windows Defender\\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\\Windows\\system32\\drivers\\aswHwid.sys [28656 2015-09-20] (AVAST Software)
R2 aswMonFlt; C:\\Windows\\system32\\drivers\\aswMonFlt.sys [90968 2015-09-20] (AVAST Software)
R1 aswRdr; C:\\Windows\\system32\\drivers\\aswRdr2.sys [93528 2015-09-20] (AVAST Software)
R0 aswRvrt; C:\\Windows\\System32\\Drivers\\aswRvrt.sys [65224 2015-09-20] (AVAST Software)
R1 aswSnx; C:\\Windows\\system32\\drivers\\aswSnx.sys [1059656 2015-11-14] (AVAST Software)
R1 aswSP; C:\\Windows\\system32\\drivers\\aswSP.sys [449992 2015-11-14] (AVAST Software)
R2 aswStm; C:\\Windows\\system32\\drivers\\aswStm.sys [153744 2015-09-20] (AVAST Software)
R0 aswVmm; C:\\Windows\\System32\\Drivers\\aswVmm.sys [274808 2015-09-20] (AVAST Software)
S3 busenum; C:\\Windows\\System32\\DRIVERS\\SteelBus64.sys [145408 2014-01-08] (SteelSeries Corporation) [File not signed]
S3 ebdrv; C:\\Windows\\system32\\drivers\\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 hitmanpro37; C:\\Windows\\system32\\drivers\\hitmanpro37.sys [43664 2014-11-02] ()
R2 NPF; C:\\Windows\\system32\\drivers\\npf.sys [35344 2015-11-16] (CACE Technologies, Inc.)
R3 RTCore64; C:\\Program Files (x86)\\EVGA Precision\\RTCore64.sys [14440 2011-08-12] ()
S3 SAlphamHid; C:\\Windows\\System32\\DRIVERS\\SAlpham64.sys [38016 2013-05-31] (SteelSeries Corporation) [File not signed]
U5 VWiFiFlt; C:\\Windows\\System32\\Drivers\\VWiFiFlt.sys [59904 2009-07-13] (Microsoft Corporation)
S3 slb; \\??\\C:\\AeriaGames\\ScarletBlade\\avital\\scarlb64.sys [X]
S3 sxuptp; system32\\DRIVERS\\sxuptp.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-11-22 17:05 - 2015-11-22 17:05 - 00031250 _____ C:\\Users\\Dirtbag\\Desktop\\FRST.txt
2015-11-22 17:05 - 2015-11-22 17:05 - 00000000 ____D C:\\Users\\Dirtbag\\Desktop\\FRST-OlderVersion
2015-11-22 16:59 - 2015-11-22 16:59 - 00448512 _____ (OldTimer Tools) C:\\Users\\Dirtbag\\Desktop\\TFC.exe
2015-11-22 16:59 - 2015-11-22 16:59 - 00000000 _____ C:\\Users\\Dirtbag\\Desktop\\TFC.exe.bdxch21.partial
2015-11-22 16:57 - 2015-11-22 16:57 - 00000833 _____ C:\\Users\\Dirtbag\\Desktop\\JRT.txt
2015-11-22 16:52 - 2015-11-22 16:52 - 01599080 _____ (Malwarebytes) C:\\Users\\Dirtbag\\Desktop\\JRT.exe
2015-11-22 16:45 - 2015-11-22 16:47 - 00000000 ____D C:\\AdwCleaner
2015-11-22 16:43 - 2015-11-22 16:43 - 01733632 _____ C:\\Users\\Dirtbag\\Desktop\\AdwCleaner.exe
2015-11-22 13:55 - 2015-11-22 13:56 - 00291728 _____ C:\\Windows\\Minidump\\112215-13353-01.dmp
2015-11-21 21:07 - 2015-11-22 17:05 - 02346496 _____ (Farbar) C:\\Users\\Dirtbag\\Desktop\\FRST64.exe
2015-11-21 21:07 - 2015-11-22 17:05 - 00000000 ____D C:\\FRST
2015-11-20 22:59 - 2015-11-20 22:59 - 00388608 _____ (Trend Micro Inc.) C:\\Users\\Dirtbag\\Desktop\\HijackThis.exe
2015-11-20 22:59 - 2015-11-20 22:59 - 00010444 _____ C:\\Users\\Dirtbag\\Desktop\\hijackthis.log
2015-11-17 20:46 - 2015-11-17 20:47 - 00000000 ____D C:\\Program Files\\Firestorm-Releasex64
2015-11-17 20:46 - 2015-11-17 20:46 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Firestorm
2015-11-17 20:42 - 2015-11-17 20:43 - 85407072 _____ (The Phoenix Firestorm Project, Inc.) C:\\Users\\Dirtbag\\Downloads\\Phoenix-FirestormOS-Releasex64-4-7-5-47975_Setup.exe
2015-11-16 21:00 - 2015-11-16 21:00 - 00281104 _____ (CACE Technologies, Inc.) C:\\Windows\\SysWOW64\\wpcap.dll
2015-11-16 21:00 - 2015-11-16 21:00 - 00096784 _____ (CACE Technologies, Inc.) C:\\Windows\\SysWOW64\\packet.dll
2015-11-16 21:00 - 2015-11-16 21:00 - 00035344 _____ (CACE Technologies, Inc.) C:\\Windows\\system32\\Drivers\\npf.sys
2015-11-15 16:52 - 2015-11-15 16:52 - 35648512 _____ C:\\Users\\Dirtbag\\Downloads\\PhysX-9.12.0613-SystemSoftware.msi
2015-11-15 13:40 - 2015-11-15 13:40 - 00000222 _____ C:\\Users\\Dirtbag\\Desktop\\Remember Me.url
2015-11-15 11:29 - 2015-11-15 11:31 - 00000000 ____D C:\\Users\\Dirtbag\\California trip 2015
2015-11-12 22:22 - 2015-11-03 13:10 - 00390344 _____ (Microsoft Corporation) C:\\Windows\\system32\\iedkcs32.dll
2015-11-12 22:22 - 2015-11-03 12:51 - 00342728 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\iedkcs32.dll
2015-11-12 22:22 - 2015-11-03 08:55 - 03211264 _____ (Microsoft Corporation) C:\\Windows\\system32\\win32k.sys
2015-11-12 22:22 - 2015-10-30 14:46 - 25818624 _____ (Microsoft Corporation) C:\\Windows\\system32\\mshtml.dll
2015-11-12 22:22 - 2015-10-30 14:40 - 02724864 _____ (Microsoft Corporation) C:\\Windows\\system32\\mshtml.tlb
2015-11-12 22:22 - 2015-10-30 14:40 - 00004096 _____ (Microsoft Corporation) C:\\Windows\\system32\\ieetwcollectorres.dll
2015-11-12 22:22 - 2015-10-30 14:25 - 02886656 _____ (Microsoft Corporation) C:\\Windows\\system32\\iertutil.dll
2015-11-12 22:22 - 2015-10-30 14:25 - 00417792 _____ (Microsoft Corporation) C:\\Windows\\system32\\html.iec
2015-11-12 22:22 - 2015-10-30 14:25 - 00066560 _____ (Microsoft Corporation) C:\\Windows\\system32\\iesetup.dll
2015-11-12 22:22 - 2015-10-30 14:25 - 00048640 _____ (Microsoft Corporation) C:\\Windows\\system32\\ieetwproxystub.dll
2015-11-12 22:22 - 2015-10-30 14:24 - 00585728 _____ (Microsoft Corporation) C:\\Windows\\system32\\vbscript.dll
2015-11-12 22:22 - 2015-10-30 14:24 - 00088064 _____ (Microsoft Corporation) C:\\Windows\\system32\\MshtmlDac.dll
2015-11-12 22:22 - 2015-10-30 14:17 - 00054784 _____ (Microsoft Corporation) C:\\Windows\\system32\\jsproxy.dll
2015-11-12 22:22 - 2015-10-30 14:16 - 00034304 _____ (Microsoft Corporation) C:\\Windows\\system32\\iernonce.dll
2015-11-12 22:22 - 2015-10-30 14:13 - 00616960 _____ (Microsoft Corporation) C:\\Windows\\system32\\ieui.dll
2015-11-12 22:22 - 2015-10-30 14:12 - 00144384 _____ (Microsoft Corporation) C:\\Windows\\system32\\ieUnatt.exe
2015-11-12 22:22 - 2015-10-30 14:12 - 00114688 _____ (Microsoft Corporation) C:\\Windows\\system32\\ieetwcollector.exe
2015-11-12 22:22 - 2015-10-30 14:11 - 05990912 _____ (Microsoft Corporation) C:\\Windows\\system32\\jscript9.dll
2015-11-12 22:22 - 2015-10-30 14:11 - 00817664 _____ (Microsoft Corporation) C:\\Windows\\system32\\jscript.dll
2015-11-12 22:22 - 2015-10-30 14:11 - 00814080 _____ (Microsoft Corporation) C:\\Windows\\system32\\jscript9diag.dll
2015-11-12 22:22 - 2015-10-30 14:04 - 00968704 _____ (Microsoft Corporation) C:\\Windows\\system32\\MsSpellCheckingFacility.exe
2015-11-12 22:22 - 2015-10-30 14:01 - 00489984 _____ (Microsoft Corporation) C:\\Windows\\system32\\dxtmsft.dll
2015-11-12 22:22 - 2015-10-30 13:58 - 02724864 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\mshtml.tlb
2015-11-12 22:22 - 2015-10-30 13:53 - 00077824 _____ (Microsoft Corporation) C:\\Windows\\system32\\JavaScriptCollectionAgent.dll
2015-11-12 22:22 - 2015-10-30 13:52 - 20331520 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\mshtml.dll
2015-11-12 22:22 - 2015-10-30 13:49 - 00199680 _____ (Microsoft Corporation) C:\\Windows\\system32\\msrating.dll
2015-11-12 22:22 - 2015-10-30 13:49 - 00092160 _____ (Microsoft Corporation) C:\\Windows\\system32\\mshtmled.dll
2015-11-12 22:22 - 2015-10-30 13:47 - 00504832 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\vbscript.dll
2015-11-12 22:22 - 2015-10-30 13:46 - 00315392 _____ (Microsoft Corporation) C:\\Windows\\system32\\dxtrans.dll
2015-11-12 22:22 - 2015-10-30 13:46 - 00062464 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\iesetup.dll
2015-11-12 22:22 - 2015-10-30 13:45 - 00341504 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\html.iec
2015-11-12 22:22 - 2015-10-30 13:45 - 00047616 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ieetwproxystub.dll
2015-11-12 22:22 - 2015-10-30 13:44 - 00152064 _____ (Microsoft Corporation) C:\\Windows\\system32\\occache.dll
2015-11-12 22:22 - 2015-10-30 13:44 - 00064000 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\MshtmlDac.dll
2015-11-12 22:22 - 2015-10-30 13:42 - 02279936 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\iertutil.dll
2015-11-12 22:22 - 2015-10-30 13:39 - 00047104 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\jsproxy.dll
2015-11-12 22:22 - 2015-10-30 13:39 - 00030720 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\iernonce.dll
2015-11-12 22:22 - 2015-10-30 13:37 - 00480256 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ieui.dll
2015-11-12 22:22 - 2015-10-30 13:36 - 00663552 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\jscript.dll
2015-11-12 22:22 - 2015-10-30 13:36 - 00620032 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\jscript9diag.dll
2015-11-12 22:22 - 2015-10-30 13:36 - 00115712 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ieUnatt.exe
2015-11-12 22:22 - 2015-10-30 13:34 - 00262144 _____ (Microsoft Corporation) C:\\Windows\\system32\\webcheck.dll
2015-11-12 22:22 - 2015-10-30 13:32 - 00720896 _____ (Microsoft Corporation) C:\\Windows\\system32\\ie4uinit.exe
2015-11-12 22:22 - 2015-10-30 13:31 - 00801280 _____ (Microsoft Corporation) C:\\Windows\\system32\\msfeeds.dll
2015-11-12 22:22 - 2015-10-30 13:29 - 02126336 _____ (Microsoft Corporation) C:\\Windows\\system32\\inetcpl.cpl
2015-11-12 22:22 - 2015-10-30 13:29 - 01359360 _____ (Microsoft Corporation) C:\\Windows\\system32\\mshtmlmedia.dll
2015-11-12 22:22 - 2015-10-30 13:28 - 00416256 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\dxtmsft.dll
2015-11-12 22:22 - 2015-10-30 13:23 - 00060416 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\JavaScriptCollectionAgent.dll
2015-11-12 22:22 - 2015-10-30 13:22 - 14457856 _____ (Microsoft Corporation) C:\\Windows\\system32\\ieframe.dll
2015-11-12 22:22 - 2015-10-30 13:21 - 00168960 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\msrating.dll
2015-11-12 22:22 - 2015-10-30 13:19 - 00076288 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\mshtmled.dll
2015-11-12 22:22 - 2015-10-30 13:18 - 00279040 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\dxtrans.dll
2015-11-12 22:22 - 2015-10-30 13:17 - 02487808 _____ (Microsoft Corporation) C:\\Windows\\system32\\wininet.dll
2015-11-12 22:22 - 2015-10-30 13:17 - 00130048 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\occache.dll
2015-11-12 22:22 - 2015-10-30 13:16 - 04527616 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\jscript9.dll
2015-11-12 22:22 - 2015-10-30 13:11 - 00230400 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\webcheck.dll
2015-11-12 22:22 - 2015-10-30 13:10 - 00689152 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\msfeeds.dll
2015-11-12 22:22 - 2015-10-30 13:09 - 12854272 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ieframe.dll
2015-11-12 22:22 - 2015-10-30 13:09 - 02052608 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\inetcpl.cpl
2015-11-12 22:22 - 2015-10-30 13:09 - 01155072 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\mshtmlmedia.dll
2015-11-12 22:22 - 2015-10-30 13:04 - 01547264 _____ (Microsoft Corporation) C:\\Windows\\system32\\urlmon.dll
2015-11-12 22:22 - 2015-10-30 12:53 - 00800768 _____ (Microsoft Corporation) C:\\Windows\\system32\\ieapfltr.dll
2015-11-12 22:22 - 2015-10-30 12:51 - 02011136 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\wininet.dll
2015-11-12 22:22 - 2015-10-30 12:48 - 01311744 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\urlmon.dll
2015-11-12 22:22 - 2015-10-30 12:46 - 00710144 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ieapfltr.dll
2015-11-12 22:22 - 2015-10-20 09:42 - 03168768 _____ (Microsoft Corporation) C:\\Windows\\system32\\wucltux.dll
2015-11-12 22:22 - 2015-10-20 09:42 - 02608128 _____ (Microsoft Corporation) C:\\Windows\\system32\\wuaueng.dll
2015-11-12 22:22 - 2015-10-20 09:42 - 00696320 _____ (Microsoft Corporation) C:\\Windows\\system32\\wuapi.dll
2015-11-12 22:22 - 2015-10-20 09:42 - 00192512 _____ (Microsoft Corporation) C:\\Windows\\system32\\wuwebv.dll
2015-11-12 22:22 - 2015-10-20 09:42 - 00098816 _____ (Microsoft Corporation) C:\\Windows\\system32\\wudriver.dll
2015-11-12 22:22 - 2015-10-20 09:42 - 00037888 _____ (Microsoft Corporation) C:\\Windows\\system32\\wups2.dll
2015-11-12 22:22 - 2015-10-20 09:42 - 00036864 _____ (Microsoft Corporation) C:\\Windows\\system32\\wups.dll
2015-11-12 22:22 - 2015-10-20 09:41 - 00140288 _____ (Microsoft Corporation) C:\\Windows\\system32\\wuauclt.exe
2015-11-12 22:22 - 2015-10-20 09:41 - 00091136 _____ (Microsoft Corporation) C:\\Windows\\system32\\WinSetupUI.dll
2015-11-12 22:22 - 2015-10-20 09:41 - 00037888 _____ (Microsoft Corporation) C:\\Windows\\system32\\wuapp.exe
2015-11-12 22:22 - 2015-10-20 09:41 - 00012288 _____ (Microsoft Corporation) C:\\Windows\\system32\\wu.upgrade.ps.dll
2015-11-12 22:22 - 2015-10-20 08:46 - 00566784 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\wuapi.dll
2015-11-12 22:22 - 2015-10-20 08:46 - 00174080 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\wuwebv.dll
2015-11-12 22:22 - 2015-10-20 08:46 - 00093696 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\wudriver.dll
2015-11-12 22:22 - 2015-10-20 08:46 - 00030208 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\wups.dll
2015-11-12 22:22 - 2015-10-20 08:45 - 00035328 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\wuapp.exe
2015-11-12 22:22 - 2015-10-19 16:12 - 05570496 _____ (Microsoft Corporation) C:\\Windows\\system32\\ntoskrnl.exe
2015-11-12 22:22 - 2015-10-19 16:12 - 00154560 _____ (Microsoft Corporation) C:\\Windows\\system32\\Drivers\\ksecpkg.sys
2015-11-12 22:22 - 2015-10-19 16:12 - 00095680 _____ (Microsoft Corporation) C:\\Windows\\system32\\Drivers\\ksecdd.sys
2015-11-12 22:22 - 2015-10-19 16:09 - 01730496 _____ (Microsoft Corporation) C:\\Windows\\system32\\ntdll.dll
2015-11-12 22:22 - 2015-10-19 16:06 - 00362496 _____ (Microsoft Corporation) C:\\Windows\\system32\\wow64win.dll
2015-11-12 22:22 - 2015-10-19 16:06 - 00243712 _____ (Microsoft Corporation) C:\\Windows\\system32\\wow64.dll
2015-11-12 22:22 - 2015-10-19 16:06 - 00215040 _____ (Microsoft Corporation) C:\\Windows\\system32\\winsrv.dll
2015-11-12 22:22 - 2015-10-19 16:06 - 00013312 _____ (Microsoft Corporation) C:\\Windows\\system32\\wow64cpu.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 01461760 _____ (Microsoft Corporation) C:\\Windows\\system32\\lsasrv.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 01216512 _____ (Microsoft Corporation) C:\\Windows\\system32\\rpcrt4.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 01164800 _____ (Microsoft Corporation) C:\\Windows\\system32\\kernel32.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00729600 _____ (Microsoft Corporation) C:\\Windows\\system32\\kerberos.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00503808 _____ (Microsoft Corporation) C:\\Windows\\system32\\srcore.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00424960 _____ (Microsoft Corporation) C:\\Windows\\system32\\KernelBase.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00344064 _____ (Microsoft Corporation) C:\\Windows\\system32\\schannel.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00315392 _____ (Microsoft Corporation) C:\\Windows\\system32\\msv1_0.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00312320 _____ (Microsoft Corporation) C:\\Windows\\system32\\ncrypt.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00296960 _____ (Microsoft Corporation) C:\\Windows\\system32\\rstrui.exe
2015-11-12 22:22 - 2015-10-19 16:05 - 00210944 _____ (Microsoft Corporation) C:\\Windows\\system32\\wdigest.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00136192 _____ (Microsoft Corporation) C:\\Windows\\system32\\sspicli.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00112640 _____ (Microsoft Corporation) C:\\Windows\\system32\\smss.exe
2015-11-12 22:22 - 2015-10-19 16:05 - 00086528 _____ (Microsoft Corporation) C:\\Windows\\system32\\TSpkg.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00050176 _____ (Microsoft Corporation) C:\\Windows\\system32\\srclient.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00044032 _____ (Microsoft Corporation) C:\\Windows\\system32\\cryptbase.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00043520 _____ (Microsoft Corporation) C:\\Windows\\system32\\csrsrv.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00029184 _____ (Microsoft Corporation) C:\\Windows\\system32\\sspisrv.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00028160 _____ (Microsoft Corporation) C:\\Windows\\system32\\secur32.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00022016 _____ (Microsoft Corporation) C:\\Windows\\system32\\credssp.dll
2015-11-12 22:22 - 2015-10-19 16:05 - 00016384 _____ (Microsoft Corporation) C:\\Windows\\system32\\ntvdm64.dll
2015-11-12 22:22 - 2015-10-19 16:04 - 00338432 _____ (Microsoft Corporation) C:\\Windows\\system32\\conhost.exe
2015-11-12 22:22 - 2015-10-19 16:04 - 00064000 _____ (Microsoft Corporation) C:\\Windows\\system32\\auditpol.exe
2015-11-12 22:22 - 2015-10-19 16:04 - 00031232 _____ (Microsoft Corporation) C:\\Windows\\system32\\lsass.exe
2015-11-12 22:22 - 2015-10-19 16:00 - 00060416 _____ (Microsoft Corporation) C:\\Windows\\system32\\msobjs.dll
2015-11-12 22:22 - 2015-10-19 15:59 - 00146432 _____ (Microsoft Corporation) C:\\Windows\\system32\\msaudite.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00686080 _____ (Microsoft Corporation) C:\\Windows\\system32\\adtschema.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00006656 _____ (Microsoft Corporation) C:\\Windows\\system32\\apisetschema.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00006144 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-security-base-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00005120 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-file-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00004608 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00004608 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-synch-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-localization-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-misc-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-memory-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-heap-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-xstate-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-util-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-string-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-profile-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-io-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-handle-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-fibers-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-delayload-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-debug-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-datetime-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:53 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\system32\\api-ms-win-core-console-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:52 - 03991488 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ntkrnlpa.exe
2015-11-12 22:22 - 2015-10-19 15:52 - 03935680 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ntoskrnl.exe
2015-11-12 22:22 - 2015-10-19 15:48 - 01311768 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ntdll.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00552960 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\kerberos.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00259584 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\msv1_0.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00251392 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\schannel.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00223232 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ncrypt.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00172032 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\wdigest.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00065536 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\TSpkg.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00043008 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\srclient.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00036864 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\cryptbase.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00025600 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\setup16.exe
2015-11-12 22:22 - 2015-10-19 15:45 - 00022016 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\secur32.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00017408 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\credssp.dll
2015-11-12 22:22 - 2015-10-19 15:45 - 00014336 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\ntvdm64.dll
2015-11-12 22:22 - 2015-10-19 15:44 - 01114112 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\kernel32.dll
2015-11-12 22:22 - 2015-10-19 15:44 - 00665088 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\rpcrt4.dll
2015-11-12 22:22 - 2015-10-19 15:44 - 00274944 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\KernelBase.dll
2015-11-12 22:22 - 2015-10-19 15:44 - 00096768 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\sspicli.dll
2015-11-12 22:22 - 2015-10-19 15:44 - 00050176 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\auditpol.exe
2015-11-12 22:22 - 2015-10-19 15:44 - 00005120 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\wow32.dll
2015-11-12 22:22 - 2015-10-19 15:39 - 00146432 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\msaudite.dll
2015-11-12 22:22 - 2015-10-19 15:39 - 00060416 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\msobjs.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00686080 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\adtschema.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00006656 _____ (Microsoft Corporation) C:\\Windows\\SysWOW64\\apisetschema.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00005120 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-file-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00004608 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-synch-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-misc-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00004096 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-localization-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-memory-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003584 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-heap-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-string-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-profile-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-io-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-handle-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-fibers-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-delayload-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-debug-l1-1-0.dll
2015-11-12 22:22 - 2015-10-19 15:35 - 00003072 ____H (Microsoft Corporation) C:\\Windows\\SysWOW64\\api-ms-win-core-datetime-l1-1-0.dll
2015-11-12 22:22 - 2015-10-