Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-07-2015 01 Ran by RossyC (administrator) on ROSSY on 19-07-2015 12:16:02 Running from C:\Users\RossyC\Downloads Loaded Profiles: RossyC (Available Profiles: RossyC) Platform: Windows 8.1 Single Language (X64) OS Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.6\EMP_UDSA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe (Nitro PDF Software) C:\Program Files (x86)\Nitro\Pro 9\NitroPDFDriverService9x64.exe () C:\Program Files (x86)\Nitro\Pro 9\Nitro_UpdateService.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe () C:\ProgramData\Photon\Huawei\EC156\OnlineUpdate\ouc.exe (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Users\RossyC\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.5.495.0\McCSPServiceHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (http://tortoisesvn.net) E:\Software\Tortoise SVN\bin\TSVNCache.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (Realtek semiconductor) C:\Windows\RTFTrack.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Power Software Ltd) E:\Software\New folder\PowerISO\PWRISOVM.EXE (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\cmd.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2876816 2013-03-05] (ELAN Microelectronics Corp.) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6339656 2013-04-10] (Realtek semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-02-01] (Intel Corporation) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2013-07-09] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2013-07-09] (Lenovo(beijing) Limited) HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2631824 2015-07-15] (NVIDIA Corporation) HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.) HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [909016 2013-10-21] (Conexant Systems, Inc.) HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-10-31] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-19] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [616272 2015-05-13] (McAfee, Inc.) HKLM-x32\...\Run: [Lenovo App Shop] => "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4 HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-05-01] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694048 2014-05-23] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [PWRISOVM.EXE] => E:\Software\New folder\PowerISO\PWRISOVM.EXE [408888 2014-10-08] (Power Software Ltd) HKLM-x32\...\Run: [EPSON_UD_START] => C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.6\EMP_UD.exe [536168 2013-05-31] (SEIKO EPSON CORPORATION) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [133248 2013-05-16] (Qualcomm Atheros Commnucations) HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1 HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-2707771882-331809377-1980215397-1002\...\Run: [SkyDrive] => C:\Users\RossyC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257136 2013-09-10] (Microsoft Corporation) AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [176064 2015-05-12] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [154256 2015-05-12] (NVIDIA Corporation) Startup: C:\Users\RossyC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2014-02-28] ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\RossyC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2014-05-24] ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation) ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\RossyC\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\RossyC\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\RossyC\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\RossyC\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll [2012-05-14] (SugarSync, Inc.) ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll [2011-06-13] (http://tortoisesvn.net) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\RossyC\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\RossyC\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\RossyC\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: [S-1-5-21-2707771882-331809377-1980215397-1002] => 10.10.10.10:1010 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?pc=MSERT1 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?pc=MSERT1 HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://go.microsoft.com/fwlink/?linkid=42826 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = http://go.microsoft.com/fwlink/?linkid=42826 HKU\S-1-5-21-2707771882-331809377-1980215397-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.us.com/c/in/?guid={5E147233-5390-4CA8-B897-BE552910437E}&serpv=5 HKU\S-1-5-21-2707771882-331809377-1980215397-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com HKU\S-1-5-21-2707771882-331809377-1980215397-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.in.msn.com/ HKU\S-1-5-21-2707771882-331809377-1980215397-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=128&systemid=488&v=n13614-460&apn_uid=5320465854854306&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=128&systemid=488&v=n13614-460&apn_uid=5320465854854306&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKU\S-1-5-21-2707771882-331809377-1980215397-1002 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=MA6F14E89-AC91-4A84-A1DA-CAA3E0519AA5&SearchSource=58&CUI=&UM=8&UP=SP0363BE24-C990-42E2-9218-C1C6AAF13476&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-2707771882-331809377-1980215397-1002 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com/Results.aspx?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=MA6F14E89-AC91-4A84-A1DA-CAA3E0519AA5&SearchSource=58&CUI=&UM=8&UP=SP0363BE24-C990-42E2-9218-C1C6AAF13476&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-2707771882-331809377-1980215397-1002 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL = http://dts.search.ask.com/sr?src=ieb&gct=ds&appid=128&systemid=488&v=n13614-460&apn_uid=5320465854854306&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms} SearchScopes: HKU\S-1-5-21-2707771882-331809377-1980215397-1002 -> {A6595CFE-1CF8-4732-B127-2E3E5090F854} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10679 SearchScopes: HKU\S-1-5-21-2707771882-331809377-1980215397-1002 -> {E8A9F45D-2CF4-4E8E-8097-EC2C54825C0E} URL = SearchScopes: HKU\S-1-5-21-2707771882-331809377-1980215397-1002 -> {EE92967E-7CB3-473D-9B4E-FEA4FCB8E02F} URL = http://search.us.com/serp?guid={5E147233-5390-4CA8-B897-BE552910437E}&action=default_search&serpv=5&k={searchTerms} BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-05-19] (Microsoft Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-05-28] (Microsoft Corporation) BHO-x32: Microsoft Web Test Recorder 12.0 Helper -> {432dd630-7e03-4c97-9d62-b99f52df4fc2} -> C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2013-10-05] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-10] (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-10] (Oracle Corporation) DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095} DPF: HKLM-x32 {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-07-03] (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-07-03] (McAfee, Inc.) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-07-03] (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-07-03] (McAfee, Inc.) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2015-05-13] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2015-05-13] (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{96A6076B-4560-4444-AD94-B0A40ED5F137}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{C7738D15-3CF6-48E5-B438-7D93E6A2049A}: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\RossyC\AppData\Roaming\Mozilla\Firefox\Profiles\3jwljvu4.default FF SelectedSearchEngine: Google FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-16] () FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2013-09-14] (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-05-13] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-16] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-11-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-11-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-08-10] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-08-10] (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-05-13] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-09-15] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-08-01] (Nitro PDF) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin HKU\S-1-5-21-2707771882-331809377-1980215397-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\RossyC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-07-28] (Unity Technologies ApS) FF Plugin HKU\S-1-5-21-2707771882-331809377-1980215397-1002: intel.com/AppUpx64 -> C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp_x64.dll No File FF SearchPlugin: C:\Users\RossyC\AppData\Roaming\Mozilla\Firefox\Profiles\3jwljvu4.default\searchplugins\trovi-search.xml [2014-12-29] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\Ask.xml [2014-09-04] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-05-01] FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2015-07-19] FF HKLM-x32\...\Firefox\Extensions: [ext@TrustMediaViewerV1alpha2194.net] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha2194\ff FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2015-07-19] Chrome: ======= CHR Profile: C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-05] CHR Extension: (Google Docs) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-05] CHR Extension: (Google Drive) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-05] CHR Extension: (YouTube) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-05] CHR Extension: (Google Search) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-05] CHR Extension: (Google Sheets) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-05] CHR Extension: (SiteAdvisor) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-07-19] CHR Extension: (IBA Opt-out (by Google)) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb [2014-09-05] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-11] CHR Extension: (Google Wallet) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-05] CHR Extension: (Gmail) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-05] CHR Profile: C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Slides) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-19] CHR Extension: (Google Docs) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-19] CHR Extension: (Google Drive) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-19] CHR Extension: (YouTube) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-19] CHR Extension: (Google Search) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-19] CHR Extension: (Google Sheets) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-19] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-19] CHR Extension: (Skype Click to Call) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-07-19] CHR Extension: (Google Wallet) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-19] CHR Extension: (Gmail) - C:\Users\RossyC\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-19] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-07-19] CHR HKLM-x32\...\Chrome\Extension: [akgbgcgghiehbhjogjdodoahlkmphlnk] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha2194\ch\TrustMediaViewerV1alpha2194.crx [Not Found] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-07-19] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [310912 2013-05-16] (Windows (R) Win 7 DDK provider) [File not signed] S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2739888 2015-05-19] (Microsoft Corporation) R2 EMP_UDSA; C:\Program Files (x86)\EPSON Projector\Epson USB Display V1.6\EMP_UDSA.exe [157696 2013-05-31] (SEIKO EPSON CORPORATION) [File not signed] S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed] R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-15] (NVIDIA Corporation) S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [351824 2014-01-15] () R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-02-01] (Intel Corporation) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe [22768 2014-04-17] (Microsoft Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-11-06] (Intel Corporation) S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [30184 2013-08-08] () R2 McAfee SiteAdvisor Service; c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [155368 2015-07-03] (McAfee, Inc.) S2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [754280 2015-05-13] (McAfee, Inc.) R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.495.0\McCSPServiceHost.exe [207344 2015-06-04] (McAfee, Inc.) S2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) S2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-06-29] (McAfee, Inc.) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [373704 2015-07-06] (McAfee, Inc.) R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [254792 2015-06-29] (McAfee, Inc.) S2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.) R2 NitroDriverReadSpool9; C:\Program Files (x86)\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-08-01] (Nitro PDF Software) R2 NitroUpdateService; C:\Program Files (x86)\Nitro\Pro 9\Nitro_UpdateService.exe [418312 2014-08-01] () R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-15] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-15] (NVIDIA Corporation) S2 Photon. RunOuc; C:\Program Files (x86)\Photon\Huawei\EC156\UpdateDog\ouc.exe [651856 2013-10-26] () S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed] S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation) R2 VSSS; C:\Users\RossyC\AppData\Roaming\Microsoft\SystemCertificates\VSSVC.exe [104991104 2015-06-23] (Microsoft Corporation) [File not signed] <==== ATTENTION R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-05-01] (Western Digital Technologies, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [306552 2015-05-01] (Western Digital Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-05-16] (Atheros) [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S1 809214a3; C:\WINDOWS\system32\drivers\809214a3.sys [94168 2015-07-13] () [File not signed] S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-05-16] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-05] (Microsoft Corporation) S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [77536 2015-07-02] (McAfee, Inc.) S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider) S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider) R3 eppvad_simple; C:\Windows\system32\drivers\EMP_UDAU.sys [23040 2013-05-31] (SEIKO EPSON CORPORATION) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [198448 2015-04-27] (McAfee, Inc.) R2 McPvDrv; C:\Windows\system32\drivers\McPvDrv.sys [76064 2015-05-08] (McAfee, Inc.) R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [412440 2015-07-02] (McAfee, Inc.) S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [156792 2011-03-13] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [347800 2015-07-02] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80920 2015-07-02] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [496888 2015-07-02] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [875928 2015-07-02] (McAfee, Inc.) R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [483240 2015-03-26] (McAfee, Inc.) S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [100720 2015-03-26] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [344704 2015-07-02] (McAfee, Inc.) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-15] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47976 2015-07-03] (NVIDIA Corporation) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8243272 2013-04-10] (Realtek Semiconductor Corp.) R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink) S1 dwyjztak; \??\C:\WINDOWS\system32\drivers\dwyjztak.sys [X] S3 Generalusbserialser20679; \SystemRoot\system32\DRIVERS\CT_U_USBSER.sys [X] R4 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-19 12:16 - 2015-07-19 12:17 - 00040587 _____ C:\Users\RossyC\Downloads\FRST.txt 2015-07-19 12:15 - 2015-07-19 12:16 - 00000000 ____D C:\FRST 2015-07-19 12:11 - 2015-07-19 12:13 - 02134528 _____ (Farbar) C:\Users\RossyC\Downloads\FRST64.exe 2015-07-19 12:09 - 2015-07-19 12:09 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-07-19 12:09 - 2015-07-19 12:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2015-07-19 12:09 - 2015-07-19 12:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-07-19 12:09 - 2015-07-19 12:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2015-07-19 12:09 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys 2015-07-19 12:09 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2015-07-19 12:09 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys 2015-07-19 11:52 - 2015-07-19 12:08 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\RossyC\Downloads\mbam-setup-2.1.8.1057.exe 2015-07-19 11:44 - 2015-07-19 11:44 - 01415680 _____ (wj32) C:\Program Files\K6AFSOTH.exe 2015-07-19 11:34 - 2015-07-19 11:34 - 01415680 _____ (wj32) C:\Program Files\OTHD19GY.exe 2015-07-19 11:33 - 2015-07-19 11:33 - 01415680 _____ (wj32) C:\Program Files\43MLLYRC.exe 2015-07-19 11:25 - 2015-07-19 11:25 - 01415680 _____ (wj32) C:\Program Files\SAEAYMIS.exe 2015-07-19 11:23 - 2015-07-19 11:23 - 01415680 _____ (wj32) C:\Program Files\1MGV8G4S.exe 2015-07-19 11:21 - 2015-07-19 11:21 - 01415680 _____ (wj32) C:\Program Files\C3GKSIKJ.exe 2015-07-19 11:21 - 2015-07-19 11:21 - 01415680 _____ (wj32) C:\Program Files\3U10O4EW.exe 2015-07-19 11:16 - 2015-07-19 11:16 - 01415680 _____ (wj32) C:\Program Files\MTPUZKP4.exe 2015-07-19 11:16 - 2015-07-19 11:16 - 01415680 _____ (wj32) C:\Program Files\K32I95L3.exe 2015-07-19 11:16 - 2015-07-19 11:16 - 01415680 _____ (wj32) C:\Program Files\A9HZK0TS.exe 2015-07-19 09:11 - 2015-07-19 09:11 - 01415680 _____ (wj32) C:\Program Files\2PK1WK0V.exe 2015-07-19 09:09 - 2015-07-19 09:09 - 01415680 _____ (wj32) C:\Program Files\SD9V8K0C.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 01415680 _____ (wj32) C:\Program Files\ML1H5NJZ.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 01415680 _____ (wj32) C:\Program Files\LNJ5784Y.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 01415680 _____ (wj32) C:\Program Files\L5T5TDL5.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 01415680 _____ (wj32) C:\Program Files\F9OKKLKD.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 01415680 _____ (wj32) C:\Program Files\BXLFH571.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 01415680 _____ (wj32) C:\Program Files\782WC5ZT.exe 2015-07-19 09:07 - 2015-07-19 09:07 - 01415680 _____ (wj32) C:\Program Files\JR7ZF3N3.exe 2015-07-19 09:07 - 2015-07-19 09:07 - 01415680 _____ (wj32) C:\Program Files\G8O8O0O4.exe 2015-07-19 08:44 - 2015-07-19 08:44 - 01415680 _____ (wj32) C:\Program Files\MYMAKEYU.exe 2015-07-19 08:14 - 2015-06-16 04:09 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-07-19 08:14 - 2015-06-16 04:08 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2015-07-19 08:14 - 2015-06-16 03:56 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll 2015-07-19 08:14 - 2015-06-16 02:47 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll 2015-07-19 08:14 - 2015-06-16 02:46 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-07-19 08:14 - 2015-06-16 02:45 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-07-19 08:14 - 2015-06-16 02:22 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-07-19 08:14 - 2015-06-16 01:47 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll 2015-07-19 08:14 - 2015-06-16 01:37 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-07-19 08:13 - 2015-06-16 03:54 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-07-19 08:13 - 2015-06-16 03:32 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx 2015-07-19 08:13 - 2015-06-16 03:28 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll 2015-07-19 08:13 - 2015-06-16 03:27 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-07-19 08:13 - 2015-06-16 03:26 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2015-07-19 08:13 - 2015-06-16 03:25 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2015-07-19 08:13 - 2015-06-16 03:19 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-07-19 08:13 - 2015-06-16 03:11 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2015-07-19 08:13 - 2015-06-16 03:08 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-07-19 08:13 - 2015-06-16 03:06 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-07-19 08:13 - 2015-06-16 02:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2015-07-19 08:13 - 2015-06-16 02:34 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll 2015-07-19 08:13 - 2015-06-16 02:33 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-07-19 08:13 - 2015-06-16 02:17 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx 2015-07-19 08:13 - 2015-06-16 02:14 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll 2015-07-19 08:13 - 2015-06-16 02:13 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2015-07-19 08:13 - 2015-06-16 02:12 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2015-07-19 08:13 - 2015-06-16 02:11 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2015-07-19 08:13 - 2015-06-16 02:07 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-07-19 08:13 - 2015-06-16 02:02 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2015-07-19 08:13 - 2015-06-16 02:01 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-07-19 08:13 - 2015-06-16 02:00 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-07-19 08:13 - 2015-06-16 02:00 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-07-19 08:13 - 2015-06-16 01:32 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-07-19 08:10 - 2015-07-03 09:58 - 00065896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll 2015-07-19 08:10 - 2015-07-03 09:58 - 00047976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys 2015-07-19 08:09 - 2015-07-19 08:09 - 01415680 _____ (wj32) C:\Program Files\4E54UL3U.exe 2015-07-19 08:04 - 2015-07-19 08:04 - 01415680 _____ (wj32) C:\Program Files\UTY3ZVSR.exe 2015-07-19 08:01 - 2015-07-19 12:10 - 00000000 __RSD C:\Users\RossyC\Documents\McAfee Vaults 2015-07-19 08:01 - 2015-07-19 08:01 - 00001945 _____ C:\Users\Public\Desktop\McAfee Total Protection.lnk 2015-07-19 08:01 - 2015-07-19 08:01 - 00000000 ____D C:\Users\RossyC\AppData\Local\McAfee File Lock 2015-07-19 08:01 - 2015-05-08 01:42 - 00076064 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\McPvDrv.sys 2015-07-19 08:01 - 2015-04-27 08:02 - 00198448 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\HipShieldK.sys 2015-07-19 08:00 - 2015-07-19 08:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2015-07-19 08:00 - 2015-07-19 08:00 - 00003080 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon 2015-07-19 08:00 - 2015-07-19 08:00 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee 2015-07-19 07:59 - 2015-07-19 07:59 - 00000000 ____D C:\Program Files (x86)\McAfee.com 2015-07-19 07:56 - 2015-07-19 09:07 - 00000000 ____D C:\Program Files (x86)\McAfee 2015-07-19 07:56 - 2015-07-19 08:01 - 00000000 ____D C:\Program Files\McAfee 2015-07-19 07:56 - 2015-07-19 07:56 - 00003344 _____ C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare) 2015-07-19 07:56 - 2015-07-19 07:56 - 00000000 ____D C:\Program Files\McAfee.com 2015-07-19 07:56 - 2015-07-19 07:56 - 00000000 ____D C:\Program Files\Common Files\AV 2015-07-19 07:28 - 2015-07-03 02:51 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-07-19 07:28 - 2015-07-03 02:20 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-07-19 07:28 - 2015-07-03 02:19 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-07-19 07:28 - 2015-07-03 01:53 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-07-19 07:28 - 2015-07-03 01:49 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-07-19 07:28 - 2015-07-03 01:25 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-07-19 07:28 - 2015-07-03 00:50 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-07-19 07:28 - 2015-07-03 00:29 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-07-19 07:19 - 2015-06-29 10:03 - 00254792 _____ (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe 2015-07-18 20:50 - 2015-07-19 08:04 - 00000000 ____D C:\Quarantine 2015-07-18 20:43 - 2015-07-19 08:01 - 00000000 ____D C:\Program Files\Common Files\McAfee 2015-07-18 20:20 - 2011-03-13 20:50 - 00156792 ____R (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeapfk.sys 2015-07-18 20:08 - 2011-03-13 20:50 - 00156792 ____R (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeapfk.sys.d7f5.deleteme 2015-07-18 20:01 - 2011-03-13 21:15 - 00158832 ____R (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe.b39c.deleteme 2015-07-18 20:01 - 2011-03-13 21:15 - 00158832 ____R (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe.907f.deleteme 2015-07-18 20:01 - 2011-03-13 20:50 - 00639216 ____R (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfehidk.sys.b39c.deleteme 2015-07-18 20:01 - 2011-03-13 20:50 - 00639216 ____R (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfehidk.sys.8ae0.deleteme 2015-07-18 20:01 - 2011-03-13 20:50 - 00156792 ____R (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeapfk.sys.6a48.deleteme 2015-07-18 09:18 - 2015-07-10 01:21 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2015-07-18 09:18 - 2015-07-10 00:10 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll 2015-07-18 09:18 - 2015-07-09 21:33 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2015-07-18 09:18 - 2015-07-09 21:24 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 2015-07-18 09:18 - 2015-07-09 21:23 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 2015-07-18 09:18 - 2015-07-09 21:20 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2015-07-18 09:18 - 2015-07-09 21:20 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2015-07-18 09:18 - 2015-07-09 21:18 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2015-07-18 09:18 - 2015-07-09 21:16 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2015-07-18 09:18 - 2015-07-09 21:08 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe 2015-07-18 09:18 - 2015-07-09 21:07 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll 2015-07-18 09:18 - 2015-07-09 21:05 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2015-07-18 09:18 - 2015-07-09 21:04 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2015-07-18 09:18 - 2015-06-27 08:38 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2015-07-18 09:18 - 2015-06-27 08:38 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2015-07-18 09:18 - 2015-06-27 07:44 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2015-07-18 09:17 - 2015-06-28 10:37 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2015-07-18 09:17 - 2015-06-28 10:37 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2015-07-18 09:17 - 2015-06-28 10:36 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2015-07-18 09:17 - 2015-06-28 10:36 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2015-07-18 09:17 - 2015-06-27 22:12 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2015-07-18 09:17 - 2015-06-27 08:43 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2015-07-18 09:17 - 2015-06-27 08:42 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys 2015-07-18 09:17 - 2015-06-27 08:42 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys 2015-07-18 09:17 - 2015-06-27 08:10 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2015-07-18 09:17 - 2015-06-27 07:35 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2015-07-18 09:17 - 2015-06-27 07:30 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2015-07-18 09:17 - 2015-06-27 07:23 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2015-07-18 09:17 - 2015-06-27 06:56 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2015-07-18 09:17 - 2015-06-16 04:11 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe 2015-07-18 09:17 - 2015-06-16 03:54 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2015-07-18 09:17 - 2015-06-16 02:46 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe 2015-07-18 09:17 - 2015-06-16 02:39 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2015-07-18 09:17 - 2015-06-16 02:20 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2015-07-18 09:17 - 2015-06-16 01:27 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2015-07-17 10:12 - 2015-07-17 10:12 - 01415680 _____ (wj32) C:\Program Files\Y6AK6IKU.exe 2015-07-17 10:12 - 2015-07-17 10:12 - 01415680 _____ (wj32) C:\Program Files\O8S4O8G0.exe 2015-07-17 10:12 - 2015-07-17 10:12 - 01415680 _____ (wj32) C:\Program Files\9HRFWJT2.exe 2015-07-17 10:12 - 2015-07-17 10:12 - 01415680 _____ (wj32) C:\Program Files\6MEUEYEY.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 01415680 _____ (wj32) C:\Program Files\TVOKFH4N.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 01415680 _____ (wj32) C:\Program Files\RTHB460T.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 01415680 _____ (wj32) C:\Program Files\PJF93WSM.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 01415680 _____ (wj32) C:\Program Files\K6KEMEUE.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 01415680 _____ (wj32) C:\Program Files\FS5I0D9X.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 01415680 _____ (wj32) C:\Program Files\19TH1H1L.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 01415680 _____ (wj32) C:\Program Files\TX2YV29X.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 01415680 _____ (wj32) C:\Program Files\EJOK5TYD.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 01415680 _____ (wj32) C:\Program Files\DTMGDYLF.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 01415680 _____ (wj32) C:\Program Files\9BZT3SOH.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 01415680 _____ (wj32) C:\Program Files\6ZLV5SM2.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 01415680 _____ (wj32) C:\Program Files\5UNP5A6Z.exe 2015-07-17 10:09 - 2015-07-17 10:09 - 01415680 _____ (wj32) C:\Program Files\IMANSXKX.exe 2015-07-16 11:27 - 2015-05-07 23:20 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2015-07-16 11:27 - 2015-05-07 22:30 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll 2015-07-16 11:27 - 2015-05-07 22:23 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2015-07-16 11:27 - 2015-05-07 21:42 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll 2015-07-16 11:19 - 2015-05-03 20:39 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-07-16 11:19 - 2015-05-03 20:28 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-07-16 11:19 - 2015-05-03 20:25 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2015-07-16 11:19 - 2015-05-03 20:19 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2015-07-16 11:19 - 2015-04-23 21:17 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2015-07-16 11:19 - 2015-04-23 20:46 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2015-07-16 11:15 - 2015-06-30 04:13 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2015-07-16 11:15 - 2015-06-29 20:37 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2015-07-16 11:15 - 2015-06-29 20:37 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-07-16 11:15 - 2015-06-29 20:37 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2015-07-16 11:15 - 2015-06-29 20:37 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2015-07-16 11:15 - 2015-06-29 20:37 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2015-07-16 11:15 - 2015-06-27 04:51 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-07-16 11:15 - 2015-06-27 04:51 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2015-07-16 11:15 - 2015-04-28 18:43 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls 2015-07-16 11:15 - 2015-04-28 18:43 - 00513480 _____ C:\WINDOWS\system32\locale.nls 2015-07-16 11:13 - 2015-05-07 22:17 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll 2015-07-16 11:13 - 2015-05-03 20:37 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2015-07-16 11:13 - 2015-05-03 20:27 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2015-07-16 11:10 - 2015-06-25 08:01 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2015-07-16 11:10 - 2015-05-31 02:48 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2015-07-16 11:10 - 2015-05-31 01:06 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-07-16 11:10 - 2015-05-31 01:05 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-07-16 11:07 - 2015-07-03 19:22 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2015-07-16 11:07 - 2015-07-03 19:22 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2015-07-16 11:07 - 2015-07-03 19:20 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2015-07-16 11:07 - 2015-07-03 19:20 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2015-07-16 11:07 - 2015-07-02 03:38 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-07-16 11:07 - 2015-07-02 02:44 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-07-16 11:02 - 2015-06-11 09:19 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll 2015-07-16 11:02 - 2015-06-10 21:43 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll 2015-07-16 10:57 - 2015-06-16 11:06 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll 2015-07-16 10:57 - 2015-06-16 11:06 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll 2015-07-16 10:43 - 2015-05-11 22:04 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll 2015-07-16 10:38 - 2015-05-03 06:09 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-07-16 10:38 - 2014-11-05 00:55 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys 2015-07-16 10:38 - 2014-11-05 00:55 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys 2015-07-16 10:38 - 2014-11-04 12:25 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys 2015-07-16 10:38 - 2014-11-04 12:24 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys 2015-07-16 10:38 - 2014-11-04 12:24 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys 2015-07-16 10:38 - 2014-11-04 12:24 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys 2015-07-16 10:33 - 2015-04-30 04:52 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll 2015-07-16 10:31 - 2015-07-16 10:31 - 01415680 _____ (wj32) C:\Program Files\F68Y0ZVO.exe 2015-07-16 10:31 - 2015-07-16 10:31 - 01415680 _____ (wj32) C:\Program Files\EDTH5K8W.exe 2015-07-16 10:27 - 2015-05-11 23:47 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2015-07-16 10:27 - 2015-05-07 20:51 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll 2015-07-16 10:27 - 2015-05-07 20:35 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll 2015-07-16 10:21 - 2015-04-25 07:55 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys 2015-07-15 21:56 - 2015-05-02 05:03 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml 2015-07-15 21:55 - 2015-05-12 18:49 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll 2015-07-15 19:47 - 2015-07-15 19:47 - 01415680 _____ (wj32) C:\Program Files\MJMTCADS.exe 2015-07-15 11:25 - 2015-07-15 11:25 - 01415680 _____ (wj32) C:\Program Files\CUT18WN5.exe 2015-07-14 11:20 - 2015-07-14 11:20 - 01415680 _____ (wj32) C:\Program Files\EU06NOAW.exe 2015-07-14 11:20 - 2015-07-14 11:20 - 01415680 _____ (wj32) C:\Program Files\CYULMI4G.exe 2015-07-14 10:20 - 2015-07-14 10:20 - 01415680 _____ (wj32) C:\Program Files\SJT32VDF.exe 2015-07-14 10:20 - 2015-07-14 10:20 - 01415680 _____ (wj32) C:\Program Files\RTMOD92Z.exe 2015-07-14 10:04 - 2015-07-14 10:04 - 01415680 _____ (wj32) C:\Program Files\713RKGAY.exe 2015-07-13 21:13 - 2015-07-19 09:07 - 00065536 _____ C:\WINDOWS\system32\Ikeext.etl 2015-07-13 21:13 - 2015-07-13 21:13 - 00094168 _____ C:\WINDOWS\system32\Drivers\809214a3.sys 2015-07-08 11:16 - 2015-07-15 21:45 - 00729600 _____ C:\Users\RossyC\Desktop\V2.0_BOY2015_Prithwis Rahul Rossy_Sharanya Lal_7 Tigers_Gumpha Jogeshwari Mumbai.xlsx 2015-07-08 11:16 - 2015-07-08 11:16 - 01762105 _____ C:\Users\RossyC\Downloads\Gumpha Road_6th_Eagles(1).xlsx 2015-07-08 09:59 - 2015-07-08 09:59 - 01415680 _____ (wj32) C:\Program Files\JL93XYSG.exe 2015-07-07 22:32 - 2015-07-15 21:26 - 00729600 _____ C:\Users\RossyC\Desktop\V2.0_BOY2015_Prithwis Rahul Rossy_Sharanya Lal_7 Eagles_Gumpha Jogeshwari Mumbai.xlsx 2015-07-05 22:44 - 2015-07-05 23:04 - 12470777 _____ C:\Users\RossyC\Desktop\Blind Girl Singing.mp4 2015-07-03 23:09 - 2015-07-03 23:09 - 00001095 _____ C:\Users\Public\Desktop\VLC media player.lnk 2015-07-03 23:08 - 2015-07-04 12:46 - 00000000 ____D C:\Users\RossyC\Desktop\EA 2015-07-03 00:34 - 2015-07-03 00:43 - 50139003 _____ C:\Users\RossyC\Desktop\3 States of Matter - Solid, Liquid, Gases -Animation Lesson ( Video for Kids ).mp4 2015-07-03 00:32 - 2015-07-03 00:45 - 32216666 _____ C:\Users\RossyC\Desktop\Water- Water Cycle, Forms of Water and Water Conservation - Something Fishy- Kids Lesson 1.mp4 2015-07-02 15:33 - 2015-07-02 15:33 - 00496888 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfefirek.sys 2015-07-02 15:33 - 2015-07-02 15:33 - 00344704 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfewfpk.sys 2015-07-02 15:33 - 2015-07-02 15:33 - 00080920 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeelamk.sys 2015-07-02 15:33 - 2015-07-02 15:33 - 00077536 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\cfwids.sys 2015-06-26 11:12 - 2015-07-14 23:16 - 00000000 ____D C:\Users\RossyC\Desktop\Assessments 2015-06-24 23:20 - 2015-06-24 23:20 - 01415680 _____ (wj32) C:\Program Files\MI4XZ3XT.exe 2015-06-24 23:20 - 2015-06-24 23:20 - 01415680 _____ (wj32) C:\Program Files\BCBGH0AP.exe 2015-06-22 20:51 - 2015-07-03 09:58 - 00069992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-19 12:14 - 2013-09-10 11:29 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2707771882-331809377-1980215397-1002 2015-07-19 11:57 - 2014-01-11 19:57 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-07-19 11:33 - 2013-11-03 11:35 - 01791024 _____ C:\WINDOWS\WindowsUpdate.log 2015-07-19 11:30 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\system32\sru 2015-07-19 11:15 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\tracing 2015-07-19 11:13 - 2014-01-23 19:18 - 00000000 ____D C:\Users\RossyC\AppData\Local\TSVNCache 2015-07-19 11:13 - 2013-09-10 10:47 - 00000000 ___DO C:\Users\RossyC\SkyDrive 2015-07-19 11:13 - 2013-09-10 10:28 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-19 09:12 - 2013-09-10 10:15 - 52937284 _____ C:\Users\Public\CAFADEBUG.log 2015-07-19 09:09 - 2014-07-14 16:43 - 00008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat 2015-07-19 09:09 - 2013-08-22 20:16 - 00420874 _____ C:\WINDOWS\setupact.log 2015-07-19 09:06 - 2013-09-30 09:32 - 00085560 _____ C:\WINDOWS\PFRO.log 2015-07-19 09:06 - 2013-08-22 20:15 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-07-19 09:03 - 2013-07-09 13:32 - 00000000 ____D C:\ProgramData\McAfee 2015-07-19 08:54 - 2012-07-26 13:29 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-07-19 08:53 - 2013-09-10 13:14 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-07-19 08:52 - 2015-04-05 22:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX 2015-07-19 08:52 - 2015-04-05 22:04 - 00000000 ___SD C:\WINDOWS\system32\GWX 2015-07-19 08:11 - 2013-11-03 11:35 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2015-07-19 07:59 - 2012-07-26 13:42 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2015-07-19 07:11 - 2013-11-06 19:34 - 00003918 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{24888074-F05A-4883-B780-4335325F9EF1} 2015-07-18 15:12 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\rescache 2015-07-18 12:35 - 2013-10-18 20:24 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-07-18 08:56 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\system32\NDF 2015-07-17 11:06 - 2013-08-22 18:55 - 01310720 ___SH C:\WINDOWS\system32\config\BBI 2015-07-17 11:04 - 2013-11-03 11:40 - 00000000 ____D C:\Users\RossyC 2015-07-17 08:57 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\AppReadiness 2015-07-17 08:46 - 2013-09-19 23:19 - 04589568 ___SH C:\Users\RossyC\Desktop\Thumbs.db 2015-07-16 23:50 - 2015-06-11 13:31 - 00000000 ____D C:\Users\RossyC\Desktop\Transition Docs 2015-07-16 23:36 - 2013-09-15 17:17 - 01864192 ___SH C:\Users\RossyC\Downloads\Thumbs.db 2015-07-16 22:26 - 2013-08-22 20:14 - 00511720 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2015-07-16 11:43 - 2014-12-10 14:13 - 00000000 ____D C:\WINDOWS\system32\appraiser 2015-07-16 11:43 - 2014-07-10 15:42 - 00000000 ___SD C:\WINDOWS\system32\CompatTel 2015-07-16 11:43 - 2013-08-22 21:06 - 00000000 ___RD C:\WINDOWS\ToastData 2015-07-16 11:43 - 2013-08-22 21:06 - 00000000 ____D C:\WINDOWS\WinStore 2015-07-16 11:35 - 2015-06-16 23:41 - 00000000 ____D C:\Users\RossyC\Desktop\Gumpha Class 7 2015-07-16 11:02 - 2014-01-11 19:57 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-07-16 10:01 - 2013-09-10 10:28 - 00003890 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2015-07-16 10:01 - 2013-09-10 10:28 - 00003654 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2015-07-16 10:01 - 2013-09-10 10:28 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-15 19:31 - 2013-09-30 09:40 - 00915466 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-07-15 15:28 - 2015-06-15 10:42 - 00000000 ____D C:\Users\RossyC\Desktop\Teach For India 2015-07-15 00:36 - 2014-06-10 18:37 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll 2015-07-15 00:36 - 2013-10-28 21:31 - 01423120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2015-07-15 00:35 - 2014-06-10 18:37 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll 2015-07-15 00:35 - 2013-10-28 21:31 - 01710056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2015-07-14 02:40 - 2015-03-12 09:35 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-07-14 02:40 - 2015-03-12 09:35 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-12 08:33 - 2013-09-10 17:56 - 00000000 ____D C:\ldiag 2015-07-05 15:38 - 2013-10-15 09:19 - 00300704 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2015-07-04 00:22 - 2014-01-07 11:52 - 00000000 ____D C:\Users\RossyC\AppData\Roaming\vlc 2015-07-03 08:43 - 2013-09-10 13:14 - 130333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-07-02 15:33 - 2015-04-08 07:44 - 00412440 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeaack.sys 2015-07-02 15:33 - 2015-04-08 07:41 - 00875928 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfehidk.sys 2015-07-02 15:33 - 2015-04-08 07:40 - 00347800 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeavfk.sys 2015-06-29 10:35 - 2014-07-04 18:32 - 00000000 ____D C:\Users\RossyC\Desktop\Guitar 2015-06-24 23:45 - 2013-09-10 10:42 - 00000000 ____D C:\Program Files\Microsoft Office 15 2015-06-22 20:51 - 2013-12-23 19:17 - 00000000 ____D C:\ProgramData\boost_interprocess 2015-06-20 11:42 - 2014-08-18 02:12 - 00000000 ____D C:\Users\RossyC\Desktop\EBooks ==================== Files in the root of some directories ======= 2015-07-17 10:11 - 2015-07-17 10:11 - 1415680 _____ (wj32) C:\Program Files\19TH1H1L.exe 2015-07-19 11:23 - 2015-07-19 11:23 - 1415680 _____ (wj32) C:\Program Files\1MGV8G4S.exe 2015-07-19 09:11 - 2015-07-19 09:11 - 1415680 _____ (wj32) C:\Program Files\2PK1WK0V.exe 2015-07-19 11:21 - 2015-07-19 11:21 - 1415680 _____ (wj32) C:\Program Files\3U10O4EW.exe 2015-07-19 11:33 - 2015-07-19 11:33 - 1415680 _____ (wj32) C:\Program Files\43MLLYRC.exe 2015-07-19 08:09 - 2015-07-19 08:09 - 1415680 _____ (wj32) C:\Program Files\4E54UL3U.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 1415680 _____ (wj32) C:\Program Files\5UNP5A6Z.exe 2015-07-17 10:12 - 2015-07-17 10:12 - 1415680 _____ (wj32) C:\Program Files\6MEUEYEY.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 1415680 _____ (wj32) C:\Program Files\6ZLV5SM2.exe 2015-07-14 10:04 - 2015-07-14 10:04 - 1415680 _____ (wj32) C:\Program Files\713RKGAY.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 1415680 _____ (wj32) C:\Program Files\782WC5ZT.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 1415680 _____ (wj32) C:\Program Files\9BZT3SOH.exe 2015-07-17 10:12 - 2015-07-17 10:12 - 1415680 _____ (wj32) C:\Program Files\9HRFWJT2.exe 2015-07-19 11:16 - 2015-07-19 11:16 - 1415680 _____ (wj32) C:\Program Files\A9HZK0TS.exe 2015-06-24 23:20 - 2015-06-24 23:20 - 1415680 _____ (wj32) C:\Program Files\BCBGH0AP.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 1415680 _____ (wj32) C:\Program Files\BXLFH571.exe 2015-07-19 11:21 - 2015-07-19 11:21 - 1415680 _____ (wj32) C:\Program Files\C3GKSIKJ.exe 2015-07-15 11:25 - 2015-07-15 11:25 - 1415680 _____ (wj32) C:\Program Files\CUT18WN5.exe 2015-07-14 11:20 - 2015-07-14 11:20 - 1415680 _____ (wj32) C:\Program Files\CYULMI4G.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 1415680 _____ (wj32) C:\Program Files\DTMGDYLF.exe 2015-07-16 10:31 - 2015-07-16 10:31 - 1415680 _____ (wj32) C:\Program Files\EDTH5K8W.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 1415680 _____ (wj32) C:\Program Files\EJOK5TYD.exe 2015-07-14 11:20 - 2015-07-14 11:20 - 1415680 _____ (wj32) C:\Program Files\EU06NOAW.exe 2015-07-16 10:31 - 2015-07-16 10:31 - 1415680 _____ (wj32) C:\Program Files\F68Y0ZVO.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 1415680 _____ (wj32) C:\Program Files\F9OKKLKD.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 1415680 _____ (wj32) C:\Program Files\FS5I0D9X.exe 2015-07-19 09:07 - 2015-07-19 09:07 - 1415680 _____ (wj32) C:\Program Files\G8O8O0O4.exe 2015-07-17 10:09 - 2015-07-17 10:09 - 1415680 _____ (wj32) C:\Program Files\IMANSXKX.exe 2015-07-08 09:59 - 2015-07-08 09:59 - 1415680 _____ (wj32) C:\Program Files\JL93XYSG.exe 2015-07-19 09:07 - 2015-07-19 09:07 - 1415680 _____ (wj32) C:\Program Files\JR7ZF3N3.exe 2015-07-19 11:16 - 2015-07-19 11:16 - 1415680 _____ (wj32) C:\Program Files\K32I95L3.exe 2015-07-19 11:44 - 2015-07-19 11:44 - 1415680 _____ (wj32) C:\Program Files\K6AFSOTH.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 1415680 _____ (wj32) C:\Program Files\K6KEMEUE.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 1415680 _____ (wj32) C:\Program Files\L5T5TDL5.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 1415680 _____ (wj32) C:\Program Files\LNJ5784Y.exe 2015-06-24 23:20 - 2015-06-24 23:20 - 1415680 _____ (wj32) C:\Program Files\MI4XZ3XT.exe 2015-07-15 19:47 - 2015-07-15 19:47 - 1415680 _____ (wj32) C:\Program Files\MJMTCADS.exe 2015-07-19 09:08 - 2015-07-19 09:08 - 1415680 _____ (wj32) C:\Program Files\ML1H5NJZ.exe 2015-07-19 11:16 - 2015-07-19 11:16 - 1415680 _____ (wj32) C:\Program Files\MTPUZKP4.exe 2015-07-19 08:44 - 2015-07-19 08:44 - 1415680 _____ (wj32) C:\Program Files\MYMAKEYU.exe 2015-07-17 10:12 - 2015-07-17 10:12 - 1415680 _____ (wj32) C:\Program Files\O8S4O8G0.exe 2015-07-19 11:34 - 2015-07-19 11:34 - 1415680 _____ (wj32) C:\Program Files\OTHD19GY.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 1415680 _____ (wj32) C:\Program Files\PJF93WSM.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 1415680 _____ (wj32) C:\Program Files\RTHB460T.exe 2015-07-14 10:20 - 2015-07-14 10:20 - 1415680 _____ (wj32) C:\Program Files\RTMOD92Z.exe 2015-07-19 11:25 - 2015-07-19 11:25 - 1415680 _____ (wj32) C:\Program Files\SAEAYMIS.exe 2015-07-19 09:09 - 2015-07-19 09:09 - 1415680 _____ (wj32) C:\Program Files\SD9V8K0C.exe 2015-07-14 10:20 - 2015-07-14 10:20 - 1415680 _____ (wj32) C:\Program Files\SJT32VDF.exe 2015-07-17 10:11 - 2015-07-17 10:11 - 1415680 _____ (wj32) C:\Program Files\TVOKFH4N.exe 2015-07-17 10:10 - 2015-07-17 10:10 - 1415680 _____ (wj32) C:\Program Files\TX2YV29X.exe 2015-07-19 08:04 - 2015-07-19 08:04 - 1415680 _____ (wj32) C:\Program Files\UTY3ZVSR.exe 2015-07-17 10:12 - 2015-07-17 10:12 - 1415680 _____ (wj32) C:\Program Files\Y6AK6IKU.exe 2014-10-16 21:57 - 2014-10-16 21:57 - 0007597 _____ () C:\Users\RossyC\AppData\Local\Resmon.ResmonCfg 2014-06-08 14:28 - 2014-06-08 14:28 - 0000000 _____ () C:\Users\RossyC\AppData\Local\{B624D5F5-C932-4214-AC34-F209AAF8A653} 2013-07-09 13:09 - 2013-07-09 13:09 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2013-09-14 15:44 - 2013-09-14 15:47 - 0000606 _____ () C:\ProgramData\hpzinstall.log Some files in TEMP: ==================== C:\Users\RossyC\AppData\Local\Temp\appinstal1.exe C:\Users\RossyC\AppData\Local\Temp\appinstaly.exe C:\Users\RossyC\AppData\Local\Temp\applinstall.exe C:\Users\RossyC\AppData\Local\Temp\cdo1172898418.dll C:\Users\RossyC\AppData\Local\Temp\cdo1305105039.dll C:\Users\RossyC\AppData\Local\Temp\cdo1505454750.dll C:\Users\RossyC\AppData\Local\Temp\cdo1507310984.dll C:\Users\RossyC\AppData\Local\Temp\cdo1552780007.dll C:\Users\RossyC\AppData\Local\Temp\cdo1703618868.dll C:\Users\RossyC\AppData\Local\Temp\cdo1937149997.dll C:\Users\RossyC\AppData\Local\Temp\cdo2121504905.dll C:\Users\RossyC\AppData\Local\Temp\cdo2252988555.dll C:\Users\RossyC\AppData\Local\Temp\cdo241976058.dll C:\Users\RossyC\AppData\Local\Temp\cdo2513781765.dll C:\Users\RossyC\AppData\Local\Temp\cdo2523410590.dll C:\Users\RossyC\AppData\Local\Temp\cdo2552745570.dll C:\Users\RossyC\AppData\Local\Temp\cdo259893916.dll C:\Users\RossyC\AppData\Local\Temp\cdo2675154464.dll C:\Users\RossyC\AppData\Local\Temp\cdo2731307488.dll C:\Users\RossyC\AppData\Local\Temp\cdo2740879868.dll C:\Users\RossyC\AppData\Local\Temp\cdo2835025751.dll C:\Users\RossyC\AppData\Local\Temp\cdo2970843762.dll C:\Users\RossyC\AppData\Local\Temp\cdo3035105576.dll C:\Users\RossyC\AppData\Local\Temp\cdo306648955.dll C:\Users\RossyC\AppData\Local\Temp\cdo319674452.dll C:\Users\RossyC\AppData\Local\Temp\cdo3248531341.dll C:\Users\RossyC\AppData\Local\Temp\cdo3303734716.dll C:\Users\RossyC\AppData\Local\Temp\cdo3339189208.dll C:\Users\RossyC\AppData\Local\Temp\cdo341512140.dll C:\Users\RossyC\AppData\Local\Temp\cdo3852557829.dll C:\Users\RossyC\AppData\Local\Temp\cdo4164066498.dll C:\Users\RossyC\AppData\Local\Temp\cdo422102773.dll C:\Users\RossyC\AppData\Local\Temp\cdo703804379.dll C:\Users\RossyC\AppData\Local\Temp\cdo75900079.dll C:\Users\RossyC\AppData\Local\Temp\cdo818536113.dll C:\Users\RossyC\AppData\Local\Temp\cdo822414873.dll C:\Users\RossyC\AppData\Local\Temp\cdo877335197.dll C:\Users\RossyC\AppData\Local\Temp\cdo943115888.dll C:\Users\RossyC\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp_xbrnu.dll C:\Users\RossyC\AppData\Local\Temp\drvinst-1.exe C:\Users\RossyC\AppData\Local\Temp\drvinst001.exe C:\Users\RossyC\AppData\Local\Temp\drvinstal.exe C:\Users\RossyC\AppData\Local\Temp\drvinstal1.exe C:\Users\RossyC\AppData\Local\Temp\htmlayout.dll C:\Users\RossyC\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe C:\Users\RossyC\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe C:\Users\RossyC\AppData\Local\Temp\McCSPInstall.dll C:\Users\RossyC\AppData\Local\Temp\mcitinfo_1437247173.exe C:\Users\RossyC\AppData\Local\Temp\Nokia_Suite_WU.exe C:\Users\RossyC\AppData\Local\Temp\nsc6CA3.exe C:\Users\RossyC\AppData\Local\Temp\nsi5495.exe C:\Users\RossyC\AppData\Local\Temp\nss609C.exe C:\Users\RossyC\AppData\Local\Temp\nswF234.tmp.exe C:\Users\RossyC\AppData\Local\Temp\Quarantine.exe C:\Users\RossyC\AppData\Local\Temp\safeguard.exe C:\Users\RossyC\AppData\Local\Temp\set-app.exe C:\Users\RossyC\AppData\Local\Temp\setapp.exe C:\Users\RossyC\AppData\Local\Temp\Setup-a.exe C:\Users\RossyC\AppData\Local\Temp\Setup1.exe C:\Users\RossyC\AppData\Local\Temp\setup__4212.exe C:\Users\RossyC\AppData\Local\Temp\toolbar1131288251.exe C:\Users\RossyC\AppData\Local\Temp\toolbar1131288715.exe C:\Users\RossyC\AppData\Local\Temp\toolbar1131316425.exe C:\Users\RossyC\AppData\Local\Temp\uninstall1131998057.exe C:\Users\RossyC\AppData\Local\Temp\uninstall1132011417.exe C:\Users\RossyC\AppData\Local\Temp\uninstall1132044415.exe C:\Users\RossyC\AppData\Local\Temp\uninstall1132044431.exe C:\Users\RossyC\AppData\Local\Temp\utt7690.tmp.exe C:\Users\RossyC\AppData\Local\Temp\vlc-2.1.2-win32.exe C:\Users\RossyC\AppData\Local\Temp\vlc-2.1.3-win32.exe C:\Users\RossyC\AppData\Local\Temp\vlc-2.1.5-win32.exe C:\Users\RossyC\AppData\Local\Temp\vlc-2.2.1-win32.exe C:\Users\RossyC\AppData\Local\Temp\vp.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-07-19 12:03 ==================== End of log ============================