Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-02-2015 Ran by username2 (administrator) on ABC on 17-02-2015 21:19:12 Running from C:\Users\username\Desktop Loaded Profiles: username2 (Available profiles: username2 & username_2) Platform: Windows 8.1 (X64) OS Language: English (United Kingdom) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe () C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SandboxieRpcSs.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\32\SbieSvc.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-04-24] ( (Qualcomm Atheros Commnucations)) HKU\S-1-5-21-2448385805-1358340357-1453317947-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784904 2014-10-14] (Sandboxie Holdings, LLC) HKU\S-1-5-21-2448385805-1358340357-1453317947-1001\...\Run: [] => [X] HKU\S-1-5-21-2448385805-1358340357-1453317947-1001\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1090912 2014-12-15] (Nokia) ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2448385805-1358340357-1453317947-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com/ HKU\S-1-5-21-2448385805-1358340357-1453317947-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) Tcpip\Parameters: [DhcpNameServer] 193.229.0.40 193.229.0.42 FireFox: ======== FF ProfilePath: C:\Users\username\AppData\Roaming\Mozilla\Firefox\Profiles\xwh3t8w4.default FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Widevine Media Optimizer - C:\Users\username\AppData\Roaming\Mozilla\Firefox\Profiles\xwh3t8w4.default\Extensions\{2d3fbcf7-be69-4433-8858-c621a8d0e58d} [2014-09-15] FF Extension: NoScript - C:\Users\username\AppData\Roaming\Mozilla\Firefox\Profiles\xwh3t8w4.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-04-03] FF Extension: Adblock Plus - C:\Users\username\AppData\Roaming\Mozilla\Firefox\Profiles\xwh3t8w4.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-03] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS) R3 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] () [File not signed] R3 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [310400 2013-04-24] (Windows (R) Win 7 DDK provider) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [7618952 2015-02-04] (COMODO) R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265304 2015-02-04] (COMODO) R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2370240 2014-11-27] (Comodo Security Solutions, Inc.) R3 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R3 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [174600 2014-10-14] (Sandboxie Holdings, LLC) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) R3 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-04-24] (Atheros) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [69392 2013-08-08] (ASUS Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-04-24] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20184 2015-01-30] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [807568 2015-01-30] (COMODO) R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [35080 2015-01-30] (COMODO) R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [126208 2015-01-30] (COMODO) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) S0 raeehd; No ImagePath R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [185352 2014-10-14] (Sandboxie Holdings, LLC) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-12 11:31 - 2015-02-12 11:31 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-02-12 11:31 - 2015-01-23 06:41 - 06041600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-02-11 21:15 - 2015-02-17 20:43 - 02085888 _____ (Farbar) C:\Users\username\Desktop\FRST64.exe 2015-02-11 21:14 - 2015-02-11 21:14 - 00602112 _____ (OldTimer Tools) C:\Users\username\Downloads\OTL(1).exe 2015-02-11 21:13 - 2015-02-11 21:13 - 02134016 _____ (Farbar) C:\Users\username\Downloads\FRST64(1).exe 2015-02-11 20:40 - 2015-02-11 20:42 - 00037145 _____ () C:\Users\username\Desktop\Addition2.txt 2015-02-11 20:38 - 2015-02-17 21:19 - 00012945 _____ () C:\Users\username\Desktop\FRST.txt 2015-02-11 20:37 - 2015-02-17 21:19 - 00000000 ____D () C:\Users\username\Desktop\FRST 2015-02-11 14:02 - 2015-02-11 14:02 - 00000718 _____ () C:\Users\username\Desktop\sandboxie dcomm launch.txt 2015-02-11 12:42 - 2015-02-11 12:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2015-02-11 12:41 - 2014-12-09 01:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml 2015-02-11 11:26 - 2015-02-11 11:26 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-02-11 11:26 - 2015-02-11 11:26 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-02-11 11:26 - 2015-02-11 11:26 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2015-02-11 11:26 - 2015-02-11 11:26 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2015-02-11 11:26 - 2015-02-11 11:26 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2015-02-11 11:26 - 2015-02-11 11:26 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe 2015-02-11 11:26 - 2015-02-11 11:26 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe 2015-02-11 11:26 - 2015-02-11 11:26 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll 2015-02-11 11:26 - 2015-02-11 11:26 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe 2015-02-11 11:26 - 2015-01-10 11:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-02-11 11:26 - 2015-01-10 09:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2015-02-11 11:26 - 2014-12-09 03:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll 2015-02-11 11:25 - 2015-02-11 11:25 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-02-08 11:01 - 2015-02-17 20:36 - 00313092 _____ () C:\WINDOWS\WindowsUpdate.log 2015-02-03 18:43 - 2015-02-03 18:43 - 00003142 _____ () C:\WINDOWS\System32\Tasks\{6D59472C-BC84-4395-AA13-197AC673A2A7} 2015-02-03 18:26 - 2015-02-03 18:26 - 00000797 _____ () C:\Users\Public\Desktop\Baldur's Gate 2 Complete.lnk 2015-02-03 18:26 - 2015-02-03 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baldur's Gate 2 [GOG.com] 2015-02-03 18:19 - 2015-02-03 18:19 - 31212857 _____ () C:\Users\username\Downloads\BG2_Artworks.zip 2015-02-03 18:19 - 2015-02-03 18:19 - 104319790 _____ () C:\Users\username\Downloads\BG2_Wallpapers.zip 2015-02-03 18:19 - 2015-02-03 18:19 - 03609470 _____ () C:\Users\username\Downloads\BG2_Map.zip 2015-02-03 18:19 - 2015-02-03 18:19 - 00642446 _____ () C:\Users\username\Downloads\BG2_TOB_refcard.zip 2015-02-03 18:19 - 2015-02-03 18:19 - 00444899 _____ () C:\Users\username\Downloads\BG2_Avatars.zip 2015-02-03 18:18 - 2015-02-03 18:18 - 17715736 _____ () C:\Users\username\Downloads\BG2_manuals.zip 2015-02-03 18:14 - 2015-02-03 18:17 - 890953627 _____ () C:\Users\username\Downloads\setup_baldurs_gate2_2.0.0.12-2.bin 2015-02-03 18:14 - 2015-02-03 18:17 - 1565097856 _____ () C:\Users\username\Downloads\setup_baldurs_gate2_2.0.0.12-1.bin 2015-02-03 18:14 - 2015-02-03 18:15 - 128448000 _____ () C:\Users\username\Downloads\BG2_soundtrack.zip 2015-02-03 18:13 - 2015-02-03 18:13 - 00909752 _____ (GOG.com ) C:\Users\username\Downloads\setup_baldurs_gate2_2.0.0.12.exe 2015-02-01 17:07 - 2015-02-01 17:08 - 585590942 _____ () C:\Users\username\Downloads\5.mp4 2015-02-01 17:02 - 2015-02-01 17:04 - 776995894 _____ () C:\Users\username\Downloads\4.mp4 2015-02-01 16:43 - 2015-02-01 16:50 - 385758371 _____ () C:\Users\username\Downloads\3.mp4 2015-02-01 16:37 - 2015-02-01 16:38 - 524399358 _____ () C:\Users\username\Downloads\2.mp4 2015-02-01 16:24 - 2015-02-01 16:27 - 912264901 _____ () C:\Users\username\Downloads\1.mp4 2015-01-26 20:05 - 2015-01-26 20:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-21 21:56 - 2015-01-21 21:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Caesar 3 [GOG.com] 2015-01-21 21:48 - 2015-01-21 21:49 - 383262208 _____ (GOG.com ) C:\Users\username\Downloads\setup_caesar3_2.0.0.9.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-17 21:19 - 2014-04-20 14:03 - 00000000 ____D () C:\FRST 2015-02-17 21:16 - 2013-12-20 23:40 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-02-17 21:14 - 2014-01-21 04:14 - 01474832 _____ () C:\WINDOWS\system32\Drivers\sfi.dat 2015-02-17 21:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-02-17 20:58 - 2014-01-21 04:20 - 00200106 _____ () C:\WINDOWS\system32\Drivers\fvstore.dat 2015-02-17 20:43 - 2014-12-06 13:46 - 00000000 ____D () C:\Users\username\Desktop\FRST-OlderVersion 2015-02-17 20:20 - 2013-12-19 09:38 - 00000062 _____ () C:\Users\username\AppData\Roaming\sp_data.sys 2015-02-17 20:19 - 2013-11-14 09:08 - 00003268 _____ () C:\WINDOWS\System32\Tasks\AsusVibeSchedule 2015-02-17 20:19 - 2013-11-14 09:04 - 00003028 _____ () C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus 2015-02-17 20:19 - 2013-11-14 09:04 - 00003004 _____ () C:\WINDOWS\System32\Tasks\ASUS Splendid ColorU 2015-02-17 20:19 - 2013-11-14 09:04 - 00002988 _____ () C:\WINDOWS\System32\Tasks\ASUS Splendid ACMON 2015-02-17 20:19 - 2013-11-14 09:03 - 00003474 _____ () C:\WINDOWS\System32\Tasks\ASUS Live Update1 2015-02-17 20:19 - 2013-11-14 09:03 - 00003464 _____ () C:\WINDOWS\System32\Tasks\ASUS Live Update2 2015-02-17 20:19 - 2013-11-14 09:02 - 00003056 _____ () C:\WINDOWS\System32\Tasks\ASUS P4G 2015-02-17 20:19 - 2013-11-14 08:53 - 00003540 _____ () C:\WINDOWS\System32\Tasks\ASUS Smart Gesture Launcher 2015-02-17 20:16 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-02-12 12:57 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2015-02-12 12:49 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-02-12 12:48 - 2013-12-19 19:20 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2448385805-1358340357-1453317947-1001 2015-02-12 11:12 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-02-12 11:12 - 2013-08-22 16:44 - 00337808 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-02-12 01:26 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-02-12 01:24 - 2013-12-19 18:34 - 00000000 ____D () C:\WINDOWS\system32\MRT 2015-02-12 01:17 - 2013-12-19 18:34 - 116773704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-02-11 21:35 - 2014-12-05 23:01 - 00114160 _____ () C:\Users\username\Desktop\OTL.Txt 2015-02-11 21:14 - 2014-04-16 00:32 - 00602112 _____ (OldTimer Tools) C:\Users\username\Desktop\OTL.exe 2015-02-11 15:04 - 2014-04-16 14:11 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-02-10 22:43 - 2014-01-22 13:26 - 00001578 _____ () C:\WINDOWS\Sandboxie.ini 2015-02-06 11:12 - 2013-08-22 17:38 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-02-06 11:12 - 2013-08-22 17:38 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-02-04 21:16 - 2013-12-20 23:40 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-02-04 10:47 - 2014-01-21 04:14 - 00002001 _____ () C:\Users\Public\Desktop\COMODO Internet Security.lnk 2015-02-03 18:58 - 2013-08-22 05:56 - 00377856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll 2015-02-03 18:58 - 2013-08-22 05:56 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe 2015-02-03 18:58 - 2013-08-22 05:51 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll 2015-02-03 18:58 - 2013-08-22 05:51 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll 2015-02-03 18:58 - 2013-08-22 05:51 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll 2015-02-03 18:57 - 2013-08-22 13:22 - 00461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll 2015-02-03 18:57 - 2013-08-22 13:22 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe 2015-02-03 18:57 - 2013-08-22 13:17 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll 2015-02-03 18:57 - 2013-08-22 13:17 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll 2015-02-03 18:57 - 2013-08-22 13:17 - 00009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll 2015-02-03 18:57 - 2013-08-22 06:05 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll 2015-02-03 18:57 - 2013-08-22 06:03 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe 2015-02-03 18:57 - 2013-08-22 05:59 - 00214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll 2015-02-03 18:57 - 2013-08-22 05:51 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll 2015-02-03 18:39 - 2014-01-21 04:20 - 00000000 ___HD () C:\VTRoot 2015-01-30 14:27 - 2013-11-14 11:38 - 00807568 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmdguard.sys 2015-01-30 14:27 - 2013-11-14 11:38 - 00040736 _____ (COMODO) C:\WINDOWS\system32\cmdcsr.dll 2015-01-30 14:27 - 2013-09-24 10:54 - 00126208 _____ (COMODO) C:\WINDOWS\system32\Drivers\inspect.sys 2015-01-30 14:27 - 2013-09-24 10:54 - 00035080 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmdhlp.sys 2015-01-30 14:27 - 2013-09-24 10:54 - 00020184 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmderd.sys 2015-01-30 14:27 - 2013-09-24 10:53 - 00481576 _____ (COMODO) C:\WINDOWS\system32\guard64.dll 2015-01-30 14:27 - 2013-09-24 10:53 - 00386768 _____ (COMODO) C:\WINDOWS\SysWOW64\guard32.dll 2015-01-30 14:27 - 2013-09-24 10:53 - 00354520 _____ (COMODO) C:\WINDOWS\system32\cmdvrt64.dll 2015-01-30 14:27 - 2013-09-24 10:53 - 00286424 _____ (COMODO) C:\WINDOWS\SysWOW64\cmdvrt32.dll 2015-01-30 14:27 - 2013-09-24 10:53 - 00045784 _____ (COMODO) C:\WINDOWS\system32\cmdkbd64.dll 2015-01-30 14:27 - 2013-09-24 10:53 - 00040664 _____ (COMODO) C:\WINDOWS\SysWOW64\cmdkbd32.dll 2015-01-27 10:27 - 2014-04-03 12:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-26 20:09 - 2014-07-20 22:33 - 00000000 ____D () C:\Users\username\AppData\Local\Adobe 2015-01-21 17:48 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF ==================== Files in the root of some directories ======= 2013-12-19 09:38 - 2015-02-17 20:20 - 0000062 _____ () C:\Users\username\AppData\Roaming\sp_data.sys 2013-12-19 20:31 - 2013-12-19 20:31 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2013-05-01 17:32 - 2012-09-07 13:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-09 16:08 ==================== End Of Log ============================