Here's the first one.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Brendan (administrator) on JARVIS on 03-04-2015 19:22:27
Running from C:\Users\Brendan\Desktop
Loaded Profiles: Brendan (Available profiles: Brendan & Torin)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo...very-scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Windows ® Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
() C:\Users\Brendan\AppData\Roaming\68FF34AA-1426526464-E311-9341-28D24490914C\nsy1EBD.tmp
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
() C:\Users\Brendan\AppData\Roaming\68FF34AA-1426526464-E311-9341-28D24490914C\jnsz18E4.tmp
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Innovative Solutions) C:\Program Files (x86)\Innovative Solutions\Advanced Uninstaller PRO\healthcheck.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
() C:\Program Files (x86)\Common Files\Innovative Solutions\Advanced Uninstaller\InnovativeSolutions_monitor_Svr.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\ProgramData\{84436a25-a071-c6b6-8443-36a25a07a896}\civilization 4 game.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\FileManager\PhotosApp.exe
(Netflix, Inc.) C:\Program Files\WindowsApps\4DF9E0F8.Netflix_2.11.0.8_x64__mcm4njqhnhss8\Netflix.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-04] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2014-02-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2014-05-29] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2014-05-29] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2014-05-29] (Lenovo(beijing) Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2015-02-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694320 2015-02-15] (Adobe Systems Incorporated)
HKLM-x32\...\RunOnce: [SpUninstallCleanUp] => REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [134784 2014-02-25] ( (Qualcomm®Atheros®))
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-708214694-1593697130-2342718439-1002\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-02-02] (Electronic Arts)
HKU\S-1-5-21-708214694-1593697130-2342718439-1002\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
HKU\S-1-5-21-708214694-1593697130-2342718439-1002\...\Run: [WindApp] => "C:\Users\Brendan\AppData\Roaming\Store\WindApp\WindApp.exe" /winstartup
HKU\S-1-5-21-708214694-1593697130-2342718439-1002\...\Run: [Selection Tools] => "C:\Users\Brendan\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe" /winstartup
HKU\S-1-5-21-708214694-1593697130-2342718439-1002\...\MountPoints2: {c275275c-e71c-11e3-8254-806e6f6e6963} - "E:\Autorun.exe"
Startup: C:\Users\Brendan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\1AB64RN1.lnk
ShortcutTarget: 1AB64RN1.lnk -> C:\ProgramData\{79927090-4af8-a4eb-7992-270904afc241}\1AB64RN1.exe (Super PC Tools Ltd)
Startup: C:\Users\Brendan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\civilization 4 game.lnk
ShortcutTarget: civilization 4 game.lnk -> C:\ProgramData\{84436a25-a071-c6b6-8443-36a25a07a896}\civilization 4 game.exe ()
Startup: C:\Users\Brendan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Nexon Launcher.lnk
ShortcutTarget: Nexon Launcher.lnk -> C:\Program Files (x86)\Nexon\Nexon Launcher\nexon_launcher.exe ()
Startup: C:\Users\Brendan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PlutoTV.lnk
ShortcutTarget: PlutoTV.lnk -> C:\Program Files (x86)\Pluto TV\PlutoTV.exe (No File)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49853;https=127.0.0.1:49853
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-708214694-1593697130-2342718439-1002\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bing.com/...nlogo=CT3331948HKU\S-1-5-21-708214694-1593697130-2342718439-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo13.msn.com/?pc=LCJBHKU\S-1-5-21-708214694-1593697130-2342718439-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://home.lenovo.comHKU\S-1-5-21-708214694-1593697130-2342718439-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://home.lenovo.comSearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {7F4EFF06-7032-458e-AE16-1C1D8255C28A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-708214694-1593697130-2342718439-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
http://www.bing.com/...rc=IE-SearchBoxSearchScopes: HKU\S-1-5-21-708214694-1593697130-2342718439-1002 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
http://www.trovi.com...&D=040315&SSPV=SearchScopes: HKU\S-1-5-21-708214694-1593697130-2342718439-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
http://www.bing.com/...rc=IE-SearchBoxSearchScopes: HKU\S-1-5-21-708214694-1593697130-2342718439-1002 -> {ABDAE76F-7F4D-4D96-8974-D0DF805DD6F3} URL =
Winsock: Catalog9 01 C:\windows\SysWOW64\VCL.dll [335064] (VC Corporation)
Winsock: Catalog9 02 C:\windows\SysWOW64\VCL.dll [335064] (VC Corporation)
Winsock: Catalog9 03 C:\windows\SysWOW64\VCL.dll [335064] (VC Corporation)
Winsock: Catalog9 04 C:\windows\SysWOW64\VCL.dll [335064] (VC Corporation)
Winsock: Catalog9 16 C:\windows\SysWOW64\VCL.dll [335064] (VC Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.29.1
Tcpip\..\Interfaces\{8AEF7E3B-F48F-4FA1-A4E3-C0F459E63706}: [NameServer] 192.168.1.1,208.67.220.220
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Brendan\AppData\Roaming\Mozilla\Firefox\Profiles\mc4mmp7v.default
FF DefaultSearchEngine: Trovi
FF SelectedSearchEngine: Trovi
FF Homepage: hxxp://www.trovi.com/?gd=&ctid=CT3333531&octid=EB_ORIGINAL_CTID&ISID=M15D18B3C-B481-47C6-8CAF-1827BC06D7D7&SearchSource=55&CUI=&UM=8&UP=SP72707F87-9D5F-4DE3-958B-41D6F16D8D40&D=031715&SSPV=
FF NewTab: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-04] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-02-15] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-04] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll [2013-08-17] (Nitro PDF)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-11-12] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll [2014-11-12] (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-02-15] (Adobe Systems)
FF Plugin HKU\S-1-5-21-708214694-1593697130-2342718439-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Brendan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-08-08] (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Brendan\AppData\Roaming\Mozilla\Firefox\Profiles\mc4mmp7v.default\user.js [2015-03-16]
FF SearchPlugin: C:\Users\Brendan\AppData\Roaming\Mozilla\Firefox\Profiles\mc4mmp7v.default\searchplugins\trovi.xml [2015-04-03]
FF Extension: PCCpnApp - C:\Users\Brendan\AppData\Roaming\Mozilla\Firefox\Profiles\mc4mmp7v.default\Extensions\
[email protected] [2015-03-16]
FF Extension: youtubeadblocker - C:\Users\Brendan\AppData\Roaming\Mozilla\Firefox\Profiles\mc4mmp7v.default\Extensions\
[email protected] [2015-03-16]
FF Extension: UniDealsi - C:\Users\Brendan\AppData\Roaming\Mozilla\Firefox\Profiles\mc4mmp7v.default\Extensions\
[email protected] [2015-03-16]
FF Extension: UniDDealsi - C:\Users\Brendan\AppData\Roaming\Mozilla\Firefox\Profiles\mc4mmp7v.default\Extensions\
[email protected] [2015-03-16]
FF Extension: Firefox Helper - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\dc7e1fc06102a3bcf3378056dd092d9d [2015-01-31]
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\Program Files (x86)\DAP\daplinkchecker
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Brendan\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Docs) - C:\Users\Brendan\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-23]
CHR HKU\S-1-5-21-708214694-1593697130-2342718439-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] -
https://clients2.goo...ice/update2/crx==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-18] (Advanced Micro Devices, Inc.) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [319104 2014-02-25] (Windows ® Win 7 DDK provider) [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 cutufono; C:\Users\Brendan\AppData\Roaming\68FF34AA-1426526464-E311-9341-28D24490914C\nsy1EBD.tmp [118784 2015-03-25] () [File not signed]
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.)
R2 hycetuje; C:\Users\Brendan\AppData\Roaming\68FF34AA-1426526464-E311-9341-28D24490914C\jnsz18E4.tmp [124416 2015-03-16] () [File not signed]
R3 InnovativeSolutions_monitor; C:\Program Files (x86)\Common Files\Innovative Solutions\Advanced Uninstaller\InnovativeSolutions_monitor_Svr.exe [1064880 2015-03-17] ()
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1662424 2014-02-19] ()
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [38896 2014-02-17] (Lenovo(beijing) Limited)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2013-08-17] (Nitro PDF Software)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910640 2015-03-02] (Electronic Arts)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2014-05-29] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2014-05-29] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-24] (Advanced Micro Devices, Inc.)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-05-29] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-02-25] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-24] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-12] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-24] (Advanced Micro Devices, Inc. )
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3892224 2014-03-06] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-25] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-24] (Malwarebytes Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 xusb22; C:\Windows\system32\DRIVERS\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X]
R1 mwiynzm4ndy1yjz; system32\drivers\mwiynzm4ndy1yjz.sys [X]
S1 qrnfd_1_10_0_9; system32\drivers\qrnfd_1_10_0_9.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-03 19:22 - 2015-04-03 19:23 - 00019764 _____ () C:\Users\Brendan\Desktop\FRST.txt
2015-04-03 19:21 - 2015-04-03 19:21 - 02095616 _____ (Farbar) C:\Users\Brendan\Desktop\FRST64.exe
2015-04-03 19:18 - 2015-04-03 19:22 - 00000000 ____D () C:\FRST
2015-03-24 13:01 - 2015-03-10 19:38 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-03-24 13:01 - 2015-03-10 15:08 - 01107456 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-03-24 13:01 - 2015-03-10 15:08 - 00943104 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-03-24 13:01 - 2015-03-10 15:08 - 00760320 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-03-24 13:01 - 2015-03-10 15:08 - 00677888 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-03-24 13:01 - 2015-03-10 15:08 - 00414208 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-03-24 13:01 - 2015-03-10 15:08 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-03-23 18:22 - 2015-04-03 19:22 - 00000296 _____ () C:\windows\Tasks\PC-Mechanic Maintenance.job
2015-03-23 18:22 - 2015-03-31 01:20 - 00000296 _____ () C:\windows\Tasks\PC-Mechanic Subscription.job
2015-03-23 18:22 - 2015-03-31 01:20 - 00000290 _____ () C:\windows\Tasks\PC-Mechanic Startup.job
2015-03-23 18:22 - 2015-03-23 18:22 - 00003198 _____ () C:\windows\System32\Tasks\PC-Mechanic Maintenance
2015-03-23 18:22 - 2015-03-23 18:22 - 00002568 _____ () C:\windows\System32\Tasks\PC-Mechanic Subscription
2015-03-23 18:22 - 2015-03-23 18:22 - 00002502 _____ () C:\windows\System32\Tasks\PC-Mechanic Startup
2015-03-23 18:22 - 2015-03-23 18:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
2015-03-23 18:21 - 2015-03-26 22:58 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\Uniblue
2015-03-23 18:21 - 2015-03-26 22:58 - 00000000 ____D () C:\Program Files (x86)\Uniblue
2015-03-23 18:21 - 2015-03-23 18:27 - 00000000 ____D () C:\Users\Brendan\AppData\Local\PlutoTV
2015-03-23 18:21 - 2015-03-23 18:21 - 00000013 _____ () C:\Users\Brendan\.pluto.tv
2015-03-23 18:20 - 2015-04-03 18:20 - 00000354 _____ () C:\windows\Tasks\Health-Check.job
2015-03-23 18:20 - 2015-04-03 17:20 - 00000362 _____ () C:\windows\Tasks\Health-Check-deep.job
2015-03-23 18:20 - 2015-04-03 04:27 - 00000360 _____ () C:\windows\Tasks\Health-Check-auto.job
2015-03-23 18:20 - 2015-04-03 04:27 - 00000358 _____ () C:\windows\Tasks\UninstallMonitor.job
2015-03-23 18:20 - 2015-03-23 18:20 - 00002922 _____ () C:\windows\System32\Tasks\Health-Check-deep
2015-03-23 18:20 - 2015-03-23 18:20 - 00002914 _____ () C:\windows\System32\Tasks\Health-Check
2015-03-23 18:20 - 2015-03-23 18:20 - 00002618 _____ () C:\windows\System32\Tasks\Health-Check-auto
2015-03-23 18:20 - 2015-03-23 18:20 - 00002616 _____ () C:\windows\System32\Tasks\UninstallMonitor
2015-03-23 18:20 - 2015-03-23 18:20 - 00001628 _____ () C:\Users\Brendan\Desktop\Advanced Uninstaller PRO 11.lnk
2015-03-23 18:20 - 2015-03-23 18:20 - 00001512 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO 11.lnk
2015-03-23 18:20 - 2015-03-23 18:20 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\RHEng
2015-03-23 18:20 - 2015-03-23 18:20 - 00000000 ____D () C:\Users\Brendan\AppData\Local\Innovative Solutions
2015-03-23 18:20 - 2015-03-23 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pluto TV
2015-03-23 18:20 - 2015-03-23 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Uninstaller PRO
2015-03-23 18:20 - 2015-03-23 18:20 - 00000000 ____D () C:\ProgramData\Innovative Solutions
2015-03-23 18:20 - 2015-03-23 18:20 - 00000000 ____D () C:\Program Files (x86)\Innovative Solutions
2015-03-23 18:20 - 2014-03-07 09:25 - 00042496 _____ () C:\windows\SysWOW64\AdvUninstCPL.cpl
2015-03-23 18:15 - 2015-03-23 18:16 - 18131200 _____ (Innovative Solutions ) C:\Users\Brendan\Downloads\Advanced_Uninstaller11.exe
2015-03-23 01:29 - 2015-03-23 01:29 - 02238600 _____ (Microsoft Corporation) C:\Users\Brendan\Downloads\DefaultPack.EXE
2015-03-23 01:28 - 2015-03-23 01:29 - 41840320 _____ (Microsoft Corporation) C:\Users\Brendan\Downloads\Windows-KB890830-x64-V5.22.exe
2015-03-22 03:17 - 2015-03-24 18:56 - 00008768 _____ () C:\windows\SysWOW64\VCLOff.ini
2015-03-22 03:17 - 2015-03-24 18:56 - 00008768 _____ () C:\windows\system32\VCLOff.ini
2015-03-22 03:15 - 2015-03-20 06:54 - 00335064 _____ (VC Corporation) C:\windows\SysWOW64\VCL.dll
2015-03-18 18:22 - 2015-03-24 00:13 - 00000972 ____N () C:\windows\DtcInstall.log
2015-03-17 03:34 - 2014-10-30 21:50 - 00088064 _____
2015-03-17 01:54 - 2015-03-17 01:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-03-17 01:54 - 2015-03-17 01:54 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-03-17 01:54 - 2015-03-17 01:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-03-17 01:52 - 2015-03-17 01:52 - 13087456 _____ (Microsoft Corporation) C:\Users\Brendan\Downloads\Silverlight_x64.exe
2015-03-16 23:13 - 2015-03-25 22:50 - 00000000 ____D () C:\ProgramData\3b347388000055a1
2015-03-16 22:15 - 2015-03-16 23:12 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\BitTorrent
2015-03-16 21:53 - 2015-03-16 21:53 - 00838144 _____ () C:\Users\Brendan\Downloads\Sid Meies Civilization IV Full Download For PC.exe
2015-03-16 21:44 - 2015-03-25 22:50 - 00000000 ____D () C:\ProgramData\a2022b38000075bc
2015-03-16 21:42 - 2015-03-16 21:42 - 00000000 ____D () C:\ProgramData\{cecff20f-c8da-a492-cecf-ff20fc8dc83f}
2015-03-16 20:45 - 2015-03-16 20:45 - 00000000 ____D () C:\Users\Brendan\Desktop\Screenshots
2015-03-16 20:40 - 2015-03-16 21:50 - 00000000 ____D () C:\ProgramData\{84436a25-a071-c6b6-8443-36a25a07a896}
2015-03-16 20:38 - 2015-03-16 20:42 - 00000000 ____D () C:\Program Files (x86)\SectionLogistics
2015-03-16 20:37 - 2015-03-16 20:37 - 00000000 ____D () C:\ProgramData\1403549107226436317
2015-03-16 20:35 - 2015-03-16 20:35 - 00000000 ____D () C:\ProgramData\{3a0c3e94-ebf8-9e2d-3a0c-c3e94ebffa53}
2015-03-16 19:41 - 2015-03-16 19:41 - 00003270 _____ () C:\windows\System32\Tasks\GlobalUpdate-ywy1yzzxn2szbtl
2015-03-16 19:41 - 2015-03-16 19:41 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\ywy1yzzxn2szbtl
2015-03-16 18:11 - 2015-03-16 18:11 - 00000000 ____D () C:\Users\Brendan\Documents\DreamVideoSoft
2015-03-16 18:10 - 2015-03-16 18:53 - 00000000 ____D () C:\Program Files\Common Files\PastaLeads
2015-03-16 18:08 - 2015-03-16 18:11 - 00000000 ____D () C:\Users\Brendan\Documents\ProPCCleaner
2015-03-16 18:08 - 2015-03-16 18:08 - 00003196 _____ () C:\windows\System32\Tasks\ProPCCleaner_Start
2015-03-16 18:08 - 2015-03-16 18:08 - 00000000 ____D () C:\Users\Brendan\AppData\Local\Pro_PC_Cleaner
2015-03-16 17:51 - 2015-03-16 17:51 - 00001675 _____ () C:\windows\SysWOW64\${LOGFILE}
2015-03-16 17:48 - 2015-03-16 17:48 - 00000046 _____ () C:\windows\wininit.ini
2015-03-16 17:43 - 2015-03-20 13:21 - 00005026 _____ () C:\Users\Brendan\Desktop\desmume.ini
2015-03-16 17:39 - 2015-03-25 22:50 - 00000000 ____D () C:\ProgramData\5aa2d5ae000008fe
2015-03-16 17:33 - 2015-03-19 19:16 - 00008720 _____ () C:\windows\SysWOW64\BasementDusterOff.ini
2015-03-16 17:33 - 2015-03-19 19:16 - 00008720 _____ () C:\windows\system32\BasementDusterOff.ini
2015-03-16 17:33 - 2015-03-16 08:21 - 00295808 _____ (BD Inc.) C:\windows\SysWOW64\BDL.dll
2015-03-16 17:31 - 2015-03-16 17:31 - 00000088 _____ () C:\Users\Brendan\AppData\Local\4cd0f59c192a391ef745cc71c87968a5
2015-03-16 17:29 - 2015-03-16 17:29 - 00000000 ____D () C:\ProgramData\COMODO
2015-03-16 17:29 - 2015-03-16 17:29 - 00000000 ____D () C:\Program Files\COMODO
2015-03-16 17:28 - 2015-03-16 18:52 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\WTools
2015-03-16 17:28 - 2015-03-16 17:50 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\Store
2015-03-16 17:28 - 2015-03-16 17:28 - 00000078 _____ () C:\Users\Brendan\AppData\Roaming\WindApp.installation.log
2015-03-16 17:28 - 2015-03-16 17:28 - 00000078 _____ () C:\Users\Brendan\AppData\Roaming\Selection Tools.installation.log
2015-03-16 17:27 - 2015-03-16 17:51 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\Nosibay
2015-03-16 17:27 - 2015-03-16 17:28 - 00005724 _____ () C:\Users\Brendan\AppData\Roaming\Bubble Dock.installation.log
2015-03-16 17:27 - 2015-03-16 17:28 - 00001283 _____ () C:\Users\Brendan\AppData\Roaming\Bubble Dock.boostrap.log
2015-03-16 17:27 - 2015-03-16 17:27 - 00000097 _____ () C:\Users\Brendan\AppData\Roaming\WindApp.boostrap.log
2015-03-16 17:25 - 2015-03-16 17:46 - 00000000 ____D () C:\ProgramData\{79927090-4af8-a4eb-7992-270904afc241}
2015-03-16 17:23 - 2015-03-16 17:31 - 00773928 _____ (Generic ) C:\Users\Brendan\Downloads\3DS1123 - Pokemon Alpha Sapphire.exe
2015-03-16 17:22 - 2015-03-25 22:50 - 00000000 ____D () C:\Users\Brendan\AppData\Local\68FF34AA-1426526533-E311-9341-28D24490914C
2015-03-16 17:21 - 2015-03-25 22:50 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\68FF34AA-1426526464-E311-9341-28D24490914C
2015-03-16 17:16 - 2015-03-16 17:16 - 00639496 _____ () C:\Users\Brendan\Downloads\3DS_Emulator.exe
2015-03-15 23:23 - 2015-03-15 23:24 - 00000000 ____D () C:\Users\Brendan\Downloads\VisualBoyAdvanceM1229
2015-03-15 23:23 - 2015-03-15 23:23 - 00992379 _____ () C:\Users\Brendan\Downloads\VisualBoyAdvanceM1229.7z
2015-03-15 23:10 - 2015-03-16 17:43 - 00000000 ____D () C:\Users\Brendan\Desktop\States
2015-03-15 23:10 - 2015-03-15 23:10 - 00000000 ____D () C:\Users\Brendan\Desktop\Cheats
2015-03-15 23:10 - 2015-03-15 23:10 - 00000000 ____D () C:\Users\Brendan\Desktop\Battery
2015-03-15 23:07 - 2015-03-15 23:07 - 01961052 _____ () C:\Users\Brendan\Downloads\desmume-0.9.8-win32.zip
2015-03-15 23:05 - 2015-03-15 23:30 - 00000000 ____D () C:\Users\Brendan\Desktop\ROMS
2015-03-15 22:57 - 2015-03-15 22:58 - 27978403 _____ () C:\Users\Brendan\Downloads\Pokemon Diamond.zip
2015-03-15 22:57 - 2015-03-15 22:58 - 04928003 _____ () C:\Users\Brendan\Downloads\Pokemon - Sapphire Version (U).zip
2015-03-15 22:48 - 2015-03-15 23:06 - 00000000 ____D () C:\Users\Brendan\Downloads\Pokemon - Sapphire Version (USA)
2015-03-15 22:47 - 2015-03-15 22:47 - 00065536 _____ () C:\Users\Brendan\Downloads\Pokemon - Sapphire Version (USA).sav
2015-03-15 22:45 - 2015-03-15 22:45 - 04935261 _____ () C:\Users\Brendan\Downloads\Pokemon - Sapphire Version (USA).zip
2015-03-10 19:55 - 2015-02-06 16:09 - 00396419 _____ () C:\windows\system32\ApnDatabase.xml
2015-03-10 19:55 - 2015-02-03 16:58 - 00264000 _____
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-03 19:19 - 2014-11-11 00:19 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-04-03 19:01 - 2014-08-20 10:57 - 00003926 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{231079AA-DD04-447A-81A8-EC874E389A10}
2015-04-03 19:00 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\sru
2015-04-03 18:30 - 2014-11-12 17:25 - 00000914 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-03 18:13 - 2014-03-18 02:53 - 00863592 _____ () C:\windows\system32\PerfStringBackup.INI
2015-04-03 18:04 - 2014-08-25 01:23 - 01640590 _____ () C:\windows\WindowsUpdate.log
2015-04-03 17:46 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\AppReadiness
2015-04-03 16:30 - 2014-11-12 17:25 - 00000910 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-03 02:00 - 2014-08-20 12:53 - 00000000 ____D () C:\Users\Brendan\AppData\Local\Adobe
2015-04-02 23:48 - 2014-08-20 22:53 - 00000000 ____D () C:\Users\Brendan\AppData\Local\CrashDumps
2015-03-31 03:20 - 2014-08-20 11:11 - 00003598 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-708214694-1593697130-2342718439-1002
2015-03-31 01:23 - 2014-11-25 11:50 - 00001298 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-31 01:23 - 2014-11-25 11:50 - 00001286 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-31 01:23 - 2014-11-12 17:26 - 00002398 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-31 01:23 - 2014-08-20 10:51 - 00001613 _____ () C:\Users\Brendan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-03-31 01:20 - 2014-08-25 20:49 - 00000000 ___DO () C:\Users\Brendan\OneDrive
2015-03-31 01:15 - 2014-05-29 03:49 - 03969516 _____ () C:\windows\SysWOW64\rootpa.e2e
2015-03-31 01:14 - 2014-10-02 20:08 - 00018770 _____ () C:\windows\setupact.log
2015-03-31 01:14 - 2013-08-22 07:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-31 01:13 - 2014-09-22 21:33 - 00170526 _____ () C:\windows\PFRO.log
2015-03-31 01:13 - 2014-05-29 04:34 - 00004608 _____ () C:\windows\system32\VfService.trf
2015-03-31 01:13 - 2013-08-22 06:25 - 00524288 ___SH () C:\windows\system32\config\BBI
2015-03-25 22:50 - 2014-10-19 19:26 - 00000000 ____D () C:\Users\Brendan\AppData\Local\Microsoft Help
2015-03-25 22:50 - 2014-10-13 20:51 - 00000000 ____D () C:\ProgramData\tmp
2015-03-25 22:50 - 2014-05-29 03:45 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2015-03-25 22:50 - 2013-08-22 06:36 - 00000000 ___HD () C:\Users\Default
2015-03-25 22:49 - 2014-09-23 19:38 - 00000000 ____D () C:\windows\Minidump
2015-03-24 22:23 - 2013-08-22 08:20 - 00000000 ____D () C:\windows\CbsTemp
2015-03-24 22:22 - 2014-12-10 21:27 - 00000000 ____D () C:\windows\system32\appraiser
2015-03-24 22:22 - 2014-08-23 18:17 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-03-24 18:57 - 2014-08-20 11:28 - 00000000 ____D () C:\ProgramData\Origin
2015-03-24 05:12 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\rescache
2015-03-24 00:06 - 2014-03-18 02:38 - 00000000 ____D () C:\Program Files\Windows Journal
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\windows\ToastData
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\SysWOW64\sppui
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\SysWOW64\setup
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\SysWOW64\Com
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\MediaViewer
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\FileManager
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\Camera
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2015-03-24 00:06 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Common Files\System
2015-03-24 00:06 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\SysWOW64\oobe
2015-03-24 00:06 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\servicing
2015-03-24 00:05 - 2013-08-22 08:36 - 00000000 ___RD () C:\windows\ImmersiveControlPanel
2015-03-24 00:05 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\SysWOW64\migwiz
2015-03-24 00:05 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\WinBioPlugIns
2015-03-24 00:05 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\sppui
2015-03-24 00:05 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\setup
2015-03-24 00:05 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\Com
2015-03-24 00:05 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\IME
2015-03-24 00:05 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\SysWOW64\Dism
2015-03-24 00:05 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\system32\Sysprep
2015-03-24 00:05 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\system32\oobe
2015-03-24 00:04 - 2013-08-22 08:36 - 00000000 ___SD () C:\windows\system32\dsc
2015-03-24 00:04 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\SystemResetPlatform
2015-03-24 00:04 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\migwiz
2015-03-24 00:04 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\system32\Dism
2015-03-24 00:03 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2015-03-24 00:03 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2015-03-24 00:03 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-03-24 00:03 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files (x86)\Windows Multimedia Platform
2015-03-24 00:01 - 2014-08-20 10:50 - 00000000 ____D () C:\Users\Brendan
2015-03-23 04:17 - 2013-08-22 08:36 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\msclmd.dll
2015-03-23 04:17 - 2013-08-22 08:36 - 00195072 _____ (Microsoft Corporation) C:\windows\SysWOW64\msclmd.dll
2015-03-23 01:32 - 2014-12-10 18:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-23 01:23 - 2014-10-19 19:00 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BeamNG-Techdemo-0.3
2015-03-23 01:23 - 2014-10-19 18:59 - 00000000 ____D () C:\Users\Brendan\AppData\Local\BeamNG
2015-03-22 16:09 - 2014-08-20 10:51 - 00000000 ____D () C:\Users\Brendan\AppData\Local\Packages
2015-03-20 13:29 - 2014-08-20 11:10 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\Nitro PDF
2015-03-16 21:51 - 2014-08-21 23:11 - 00000000 __SHD () C:\windows\SysWOW64\AI_RecycleBin
2015-03-16 16:47 - 2014-08-20 18:51 - 00000000 ____D () C:\Users\Brendan\Steam
2015-03-15 23:09 - 2012-04-08 22:37 - 00978432 _____ () C:\Users\Brendan\Desktop\DeSmuME_dev.exe
2015-03-15 23:08 - 2012-04-09 12:17 - 00979456 _____ () C:\Users\Brendan\Desktop\DeSmuME.exe
2015-03-15 23:05 - 2014-08-20 00:30 - 00000000 ____D () C:\Users\Brendan\Documents\My Games
2015-03-15 22:39 - 2005-10-01 14:08 - 01974352 _____ (None) C:\Users\Brendan\Desktop\VisualBoyAdvance.exe
2015-03-15 01:13 - 2014-09-05 18:00 - 00000228 _____ () C:\Users\Brendan\BullseyeCoverageError.txt
2015-03-14 00:34 - 2013-08-22 07:44 - 00493776 _____ () C:\windows\system32\FNTCACHE.DAT
2015-03-14 00:31 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\WinStore
2015-03-14 00:31 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-03-14 00:31 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-03-11 18:48 - 2014-08-26 19:34 - 122905856 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-03-10 21:01 - 2014-08-26 19:34 - 00000000 ____D () C:\windows\system32\MRT
2015-03-05 00:08 - 2014-08-20 10:51 - 00000000 ____D () C:\Users\Brendan\AppData\Roaming\Adobe
2015-03-04 23:54 - 2015-03-01 23:42 - 00000000 ____D () C:\Users\Brendan\Desktop\Food Truck Design
2015-03-04 22:32 - 2015-03-02 00:45 - 00000034 _____ () C:\Users\Brendan\AppData\Roaming\AdobeWLCMCache.dat
2015-03-04 14:24 - 2014-10-16 18:41 - 00792032 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-03-04 14:24 - 2014-10-16 18:41 - 00178144 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2015-03-02 00:45 - 2015-03-04 22:32 - 0000034 _____ () C:\Users\Brendan\AppData\Roaming\AdobeWLCMCache.dat
2015-03-16 17:27 - 2015-03-16 17:28 - 0001283 _____ () C:\Users\Brendan\AppData\Roaming\Bubble Dock.boostrap.log
2015-03-16 17:27 - 2015-03-16 17:28 - 0005724 _____ () C:\Users\Brendan\AppData\Roaming\Bubble Dock.installation.log
2015-03-16 17:28 - 2015-03-16 17:28 - 0000078 _____ () C:\Users\Brendan\AppData\Roaming\Selection Tools.installation.log
2015-03-16 17:27 - 2015-03-16 17:27 - 0000097 _____ () C:\Users\Brendan\AppData\Roaming\WindApp.boostrap.log
2015-03-16 17:28 - 2015-03-16 17:28 - 0000078 _____ () C:\Users\Brendan\AppData\Roaming\WindApp.installation.log
2015-03-16 17:31 - 2015-03-16 17:31 - 0000088 _____ () C:\Users\Brendan\AppData\Local\4cd0f59c192a391ef745cc71c87968a5
2015-03-16 21:42 - 2015-03-16 23:13 - 0011736 _____ () C:\Users\Brendan\AppData\Local\Temp-log.txt
2014-05-29 03:51 - 2014-05-29 03:51 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\Torin\AppData\Local\Temp\oct1F35.tmp.exe
C:\Users\Torin\AppData\Local\Temp\oct9D77.tmp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-02 04:02
==================== End Of Log ============================