TechSpot

100+ custom firewall entries on a clean install?

By subrectre
Dec 6, 2015
  1. An result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015
    Ran by New (administrator) on NEW-PC (06-12-2015 18:24:13)
    Running from C:\Users\New\Downloads
    Loaded Profiles: New (Available Profiles: New)
    Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Edge)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
    (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Farbar) C:\Windows\mod_frst.exe
    (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
    (Microsoft Corporation) C:\Windows\System32\browser_broker.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corp.)
    HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1332224 2015-10-29] (Microsoft Corporation)
    HKU\S-1-5-21-578399439-2519388439-559220130-1000\...\Policies\Explorer: [NoViewContextMenu] 0
    HKU\S-1-5-21-578399439-2519388439-559220130-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
    HKU\S-1-5-21-578399439-2519388439-559220130-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [150528 2015-10-29] (Microsoft Corporation)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{75504cfb-97e3-431c-886a-9f270b4bcfad}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-578399439-2519388439-559220130-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE03&ocid=UE03DHP
    HKU\S-1-5-21-578399439-2519388439-559220130-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?pc=UE03&ocid=UE03DHP

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-21] (Advanced Micro Devices, Inc.) [File not signed]
    S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2015-12-04] (Microsoft Corporation)
    S4 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corp.)
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-29] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-29] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 DellBIOS; C:\WINDOWS\DellBIOS.Sys [16880 2015-12-03] ()
    S3 PortTalk; C:\Windows\SysWOW64\Drivers\PortTalk.sys [3567 2002-01-12] (Beyond Logic hxxp://www.beyondlogic.org) [File not signed]
    R3 rtwlane_13; C:\Windows\System32\drivers\rtwlane_13.sys [3749888 2015-10-29] (Realtek Semiconductor Corporation )
    R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [45728 2015-08-07] (Toshiba Corporation)
    S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-29] (Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-29] (Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-29] (Microsoft Corporation)
    U4 UxSms; no ImagePath
     
  2. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    -10-29] (Microsoft Corporation)
    U4 UxSms; no ImagePath

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-06 17:52 - 2015-12-06 17:52 - 00130337 _____ C:\Users\New\Downloads\getservices (1).zip
    2015-12-06 17:20 - 2015-12-06 17:20 - 00022865 _____ C:\Users\New\Downloads\Shortcut.txt
    2015-12-06 17:19 - 2015-12-06 17:22 - 00003458 _____ C:\Users\New\Downloads\Addition.txt
    2015-12-06 16:48 - 2015-12-06 18:24 - 00005519 _____ C:\Users\New\Downloads\FRST.txt
    2015-12-06 16:48 - 2015-12-06 18:24 - 00000000 ____D C:\FRST
    2015-12-06 16:46 - 2015-12-06 16:47 - 02369024 _____ (Farbar) C:\Users\New\Downloads\FRST64.exe
    2015-12-06 16:46 - 2015-12-06 16:47 - 02369024 _____ (Farbar) C:\Users\New\Downloads\FRST64 (1).exe
    2015-12-06 16:32 - 2015-12-06 16:32 - 478763534 _____ C:\WINDOWS\MEMORY.DMP
    2015-12-06 16:32 - 2015-12-06 16:32 - 00278972 _____ C:\WINDOWS\Minidump\120615-35296-01.dmp
    2015-12-06 16:32 - 2015-12-06 16:32 - 00000000 ____D C:\WINDOWS\Minidump
    2015-12-06 15:30 - 2015-12-06 15:41 - 00380416 _____ C:\Users\New\Downloads\mnl0px29.exe
    2015-12-06 15:30 - 2015-12-06 15:31 - 00380416 _____ C:\Users\New\Downloads\vjnqsyyw.exe
    2015-12-06 14:48 - 2015-12-06 14:58 - 00000000 ___RD C:\Users\New\Documents\Scanned Documents
    2015-12-06 14:48 - 2015-12-06 14:50 - 00000000 ____D C:\Users\New\Documents\Fax
    2015-12-06 13:23 - 2015-12-06 13:58 - 00000000 ____D C:\getservice
    2015-12-06 13:21 - 2015-12-06 13:28 - 00130337 _____ C:\Users\New\Downloads\getservices.zip
    2015-12-06 12:06 - 2015-12-06 12:08 - 137242392 _____ (Microsoft Corporation) C:\Users\New\Downloads\msert.exe
    2015-12-06 11:26 - 2015-12-06 15:12 - 00000000 ____D C:\ProgramData\TweakBit
    2015-12-06 11:26 - 2015-12-06 11:56 - 00000000 ____D C:\WINDOWS\System32\Tasks\TweakBit
    2015-12-06 11:26 - 2015-12-06 11:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit
    2015-12-06 11:25 - 2015-12-06 11:56 - 00000000 ____D C:\Program Files (x86)\TweakBit
    2015-12-06 11:24 - 2015-12-06 11:24 - 00411792 _____ (TweakBit) C:\Users\New\Downloads\fix_Windows10-setup.exe
    2015-12-06 01:46 - 2015-12-06 01:47 - 04168421 _____ C:\Users\New\Downloads\net-snmp-5.6.1.1-1.x86 (1).exe
    2015-12-06 01:46 - 2015-12-06 01:46 - 04168421 _____ C:\Users\New\Downloads\net-snmp-5.6.1.1-1.x86.exe
    2015-12-06 01:44 - 2015-12-06 01:44 - 07508760 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC-V-92-M_A01_R188086.exe
    2015-12-06 01:43 - 2015-12-06 01:43 - 02522888 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE.exe
    2015-12-06 01:43 - 2015-12-06 01:43 - 02522888 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE (1).exe
    2015-12-06 01:30 - 2015-12-06 01:31 - 07455616 _____ C:\Users\New\Downloads\R191026 (1).exe
    2015-12-06 01:30 - 2015-12-06 01:30 - 13552680 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A03_R301671 (1).exe
    2015-12-06 01:30 - 2015-12-06 01:30 - 05994248 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A04_R301663 (2).exe
    2015-12-05 19:30 - 2015-12-05 19:30 - 41328248 _____ C:\Users\New\Downloads\INTEL_MULTI-DEVICE_A08_R277773.exe
    2015-12-05 19:30 - 2015-12-05 19:30 - 13516744 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A03_R301665 (1).exe
    2015-12-05 19:30 - 2015-12-05 19:30 - 07455616 _____ C:\Users\New\Downloads\R191026.exe
    2015-12-05 19:30 - 2015-12-05 19:30 - 05994248 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A04_R301663 (1).exe
    2015-12-05 19:01 - 2015-12-05 19:02 - 99737784 _____ C:\Users\New\Downloads\R196560.exe
    2015-12-05 19:01 - 2015-12-05 19:02 - 43938128 _____ C:\Users\New\Downloads\INTEL_MULTI-DEVICE_A08_R277771.exe
    2015-12-05 19:01 - 2015-12-05 19:01 - 13552680 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A03_R301671.exe
    2015-12-05 05:07 - 2015-12-05 05:08 - 09826585 _____ C:\Users\New\Downloads\AbstractsDark.themepack
    2015-12-05 04:35 - 2015-12-05 04:35 - 00211832 _____ (Microsoft Corporation) C:\Users\New\Downloads\VSToolsForWindows1C.exe
    2015-12-05 04:34 - 2015-12-05 04:34 - 01147432 _____ (Microsoft Corporation) C:\Users\New\Downloads\wdksetup.exe
    2015-12-05 00:26 - 2015-12-05 00:27 - 75492552 _____ (Dell, Inc.) C:\Users\New\Downloads\VIDEO_DRVR_WIN_R288344.EXE
    2015-12-05 00:26 - 2015-12-05 00:26 - 06174404 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC-V-92-M_A01_R188085.exe
    2015-12-05 00:25 - 2015-12-05 00:26 - 05994248 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A04_R301663.exe
    2015-12-05 00:25 - 2015-12-05 00:25 - 13516744 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A03_R301665.exe
    2015-12-05 00:25 - 2015-12-05 00:25 - 11557320 _____ C:\Users\New\Downloads\DELL_TOUCHPAD----POINTING-ST_A15_R298882.exe
    2015-12-05 00:25 - 2015-12-05 00:25 - 02983912 _____ C:\Users\New\Downloads\E6500A29 (2).exe
    2015-12-05 00:24 - 2015-12-05 00:25 - 21457192 _____ (Dell, Inc.) C:\Users\New\Downloads\DRVR_WIN_R267814 (1).EXE
    2015-12-04 23:23 - 2015-12-04 23:24 - 00002256 ____H C:\Users\New\Documents\Default.rdp
    2015-12-04 22:50 - 2015-12-05 04:54 - 00000000 ____D C:\Users\New\Desktop\New folder
    2015-12-04 22:17 - 2015-12-06 14:13 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2015-12-04 22:13 - 2015-12-04 22:13 - 00001182 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-12-04 22:13 - 2015-12-04 22:13 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-12-04 22:13 - 2015-12-04 22:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2015-12-04 22:13 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2015-12-04 22:13 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2015-12-04 22:13 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2015-12-04 22:11 - 2015-12-04 22:14 - 22908888 _____ (Malwarebytes ) C:\Users\New\Downloads\mbam-setup-2.2.0.1024.exe
    2015-12-04 21:17 - 2015-12-06 11:58 - 00000000 ___HD C:\$SysReset
    2015-12-04 01:53 - 2015-12-04 01:53 - 00984522 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
    2015-12-04 01:48 - 2015-12-04 01:48 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
    2015-12-04 01:47 - 2015-12-04 01:48 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IIS
    2015-12-04 01:47 - 2015-12-04 01:47 - 00000000 ____D C:\WINDOWS\system32\BestPractices
    2015-12-04 01:47 - 2015-12-04 01:47 - 00000000 ____D C:\Program Files\Windows Identity Foundation
    2015-12-04 01:47 - 2015-12-04 01:47 - 00000000 ____D C:\inetpub
    2015-12-03 17:14 - 2015-12-03 17:14 - 00000000 ___HD C:\OneDriveTemp
    2015-12-03 03:50 - 2015-12-03 03:50 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2015-12-03 01:03 - 2015-11-22 02:47 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2015-12-03 01:03 - 2015-11-22 02:47 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll
    2015-12-03 01:03 - 2015-11-22 02:41 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2015-12-03 01:03 - 2015-11-22 02:41 - 01284960 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
    2015-12-03 01:03 - 2015-11-22 02:24 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
    2015-12-03 01:03 - 2015-11-22 02:14 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
    2015-12-03 01:03 - 2015-11-22 01:56 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2015-12-03 01:03 - 2015-11-22 01:54 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
    2015-12-03 01:03 - 2015-11-22 01:52 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2015-12-03 01:03 - 2015-11-22 01:43 - 24604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-12-03 01:03 - 2015-11-22 01:42 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2015-12-03 01:03 - 2015-11-22 01:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
    2015-12-03 01:03 - 2015-11-22 01:41 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
    2015-12-03 01:03 - 2015-11-22 01:39 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
    2015-12-03 01:03 - 2015-11-22 01:39 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2015-12-03 01:03 - 2015-11-22 01:38 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2015-12-03 01:03 - 2015-11-22 01:38 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2015-12-03 01:03 - 2015-11-22 01:37 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2015-12-03 01:03 - 2015-11-22 01:36 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
    2015-12-03 01:03 - 2015-11-22 01:34 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
    2015-12-03 01:03 - 2015-11-22 01:33 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2015-12-03 01:03 - 2015-11-22 01:33 - 13380608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2015-12-03 01:03 - 2015-11-22 01:33 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2015-12-03 01:03 - 2015-11-22 01:30 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-12-03 01:03 - 2015-11-22 01:30 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2015-12-03 01:03 - 2015-11-22 01:27 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
    2015-12-03 01:03 - 2015-11-22 01:26 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
    2015-12-03 01:03 - 2015-11-22 01:24 - 12124672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2015-12-03 01:03 - 2015-11-22 01:24 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2015-12-03 01:03 - 2015-11-22 01:19 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2015-12-03 01:03 - 2015-11-22 01:16 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2015-12-03 01:02 - 2015-11-22 02:41 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2015-12-03 01:02 - 2015-11-22 02:35 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
    2015-12-03 01:02 - 2015-11-22 02:34 - 00975200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
    2015-12-03 01:02 - 2015-11-22 02:34 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
    2015-12-03 01:02 - 2015-11-22 02:33 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
    2015-12-03 01:02 - 2015-11-22 02:33 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
    2015-12-03 01:02 - 2015-11-22 02:33 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
    2015-12-03 01:02 - 2015-11-22 02:30 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2015-12-03 01:02 - 2015-11-22 02:30 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2015-12-03 01:02 - 2015-11-22 02:26 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
    2015-12-03 01:02 - 2015-11-22 02:25 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
    2015-12-03 01:02 - 2015-11-22 02:20 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2015-12-03 01:02 - 2015-11-22 02:19 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2015-12-03 01:02 - 2015-11-22 02:00 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
    2015-12-03 01:02 - 2015-11-22 02:00 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
    2015-12-03 01:02 - 2015-11-22 01:57 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
    2015-12-03 01:02 - 2015-11-22 01:57 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
    2015-12-03 01:02 - 2015-11-22 01:57 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
    2015-12-03 01:02 - 2015-11-22 01:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
    2015-12-03 01:02 - 2015-11-22 01:57 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
    2015-12-03 01:02 - 2015-11-22 01:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2015-12-03 01:02 - 2015-11-22 01:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
    2015-12-03 01:02 - 2015-11-22 01:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
    2015-12-03 01:02 - 2015-11-22 01:56 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
    2015-12-03 01:02 - 2015-11-22 01:55 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
    2015-12-03 01:02 - 2015-11-22 01:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
    2015-12-03 01:02 - 2015-11-22 01:55 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
    2015-12-03 01:02 - 2015-11-22 01:54 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
    2015-12-03 01:02 - 2015-11-22 01:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
    2015-12-03 01:02 - 2015-11-22 01:54 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
    2015-12-03 01:02 - 2015-11-22 01:54 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
    2015-12-03 01:02 - 2015-11-22 01:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
    2015-12-03 01:02 - 2015-11-22 01:54 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
    2015-12-03 01:02 - 2015-11-22 01:54 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
    2015-12-03 01:02 - 2015-11-22 01:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
    2015-12-03 01:02 - 2015-11-22 01:52 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
    2015-12-03 01:02 - 2015-11-22 01:52 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
    2015-12-03 01:02 - 2015-11-22 01:52 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2015-12-03 01:02 - 2015-11-22 01:52 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
    2015-12-03 01:02 - 2015-11-22 01:51 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
    2015-12-03 01:02 - 2015-11-22 01:51 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
    2015-12-03 01:02 - 2015-11-22 01:51 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
    2015-12-03 01:02 - 2015-11-22 01:51 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
    2015-12-03 01:02 - 2015-11-22 01:51 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
    2015-12-03 01:02 - 2015-11-22 01:50 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
    2015-12-03 01:02 - 2015-11-22 01:49 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2015-12-03 01:02 - 2015-11-22 01:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
    2015-12-03 01:02 - 2015-11-22 01:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
    2015-12-03 01:02 - 2015-11-22 01:49 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
    2015-12-03 01:02 - 2015-11-22 01:48 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
    2015-12-03 01:02 - 2015-11-22 01:47 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
    2015-12-03 01:02 - 2015-11-22 01:46 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
    2015-12-03 01:02 - 2015-11-22 01:46 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
    2015-12-03 01:02 - 2015-11-22 01:45 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
    2015-12-03 01:02 - 2015-11-22 01:45 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
    2015-12-03 01:02 - 2015-11-22 01:45 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2015-12-03 01:02 - 2015-11-22 01:45 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
    2015-12-03 01:02 - 2015-11-22 01:45 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2015-12-03 01:02 - 2015-11-22 01:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
    2015-12-03 01:02 - 2015-11-22 01:45 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
    2015-12-03 01:02 - 2015-11-22 01:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
    2015-12-03 01:02 - 2015-11-22 01:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
    2015-12-03 01:02 - 2015-11-22 01:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
    2015-12-03 01:02 - 2015-11-22 01:44 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2015-12-03 01:02 - 2015-11-22 01:44 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
    2015-12-03 01:02 - 2015-11-22 01:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
    2015-12-03 01:02 - 2015-11-22 01:43 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
    2015-12-03 01:02 - 2015-11-22 01:43 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
    2015-12-03 01:02 - 2015-11-22 01:43 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2015-12-03 01:02 - 2015-11-22 01:43 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
    2015-12-03 01:02 - 2015-11-22 01:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
    2015-12-03 01:02 - 2015-11-22 01:42 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2015-12-03 01:02 - 2015-11-22 01:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
    2015-12-03 01:02 - 2015-11-22 01:42 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
    2015-12-03 01:02 - 2015-11-22 01:42 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
    2015-12-03 01:02 - 2015-11-22 01:42 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
    2015-12-03 01:02 - 2015-11-22 01:41 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
    2015-12-03 01:02 - 2015-11-22 01:41 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2015-12-03 01:02 - 2015-11-22 01:40 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
    2015-12-03 01:02 - 2015-11-22 01:40 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2015-12-03 01:02 - 2015-11-22 01:40 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
    2015-12-03 01:02 - 2015-11-22 01:40 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
    2015-12-03 01:02 - 2015-11-22 01:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
    2015-12-03 01:02 - 2015-11-22 01:39 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2015-12-03 01:02 - 2015-11-22 01:39 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
    2015-12-03 01:02 - 2015-11-22 01:39 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
    2015-12-03 01:02 - 2015-11-22 01:39 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
    2015-12-03 01:02 - 2015-11-22 01:39 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2015-12-03 01:02 - 2015-11-22 01:39 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
     
  3. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    2015-12-03 01:02 - 2015-11-22 01:39 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
    2015-12-03 01:02 - 2015-11-22 01:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
    2015-12-03 01:02 - 2015-11-22 01:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2015-12-03 01:02 - 2015-11-22 01:38 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
    2015-12-03 01:02 - 2015-11-22 01:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
    2015-12-03 01:02 - 2015-11-22 01:38 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
    2015-12-03 01:02 - 2015-11-22 01:37 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
    2015-12-03 01:02 - 2015-11-22 01:37 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2015-12-03 01:02 - 2015-11-22 01:34 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2015-12-03 01:02 - 2015-11-22 01:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2015-12-03 01:02 - 2015-11-22 01:34 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
    2015-12-03 01:02 - 2015-11-22 01:34 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
    2015-12-03 01:02 - 2015-11-22 01:34 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
    2015-12-03 01:02 - 2015-11-22 01:33 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
    2015-12-03 01:02 - 2015-11-22 01:32 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
    2015-12-03 01:02 - 2015-11-22 01:32 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
    2015-12-03 01:02 - 2015-11-22 01:32 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2015-12-03 01:02 - 2015-11-22 01:31 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2015-12-03 01:02 - 2015-11-22 01:31 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
    2015-12-03 01:02 - 2015-11-22 01:31 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
    2015-12-03 01:02 - 2015-11-22 01:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2015-12-03 01:02 - 2015-11-22 01:28 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
    2015-12-03 01:02 - 2015-11-22 01:27 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2015-12-03 01:02 - 2015-11-22 01:27 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2015-12-03 01:02 - 2015-11-22 01:27 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
    2015-12-03 01:02 - 2015-11-22 01:27 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
    2015-12-03 01:02 - 2015-11-22 01:27 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
    2015-12-03 01:02 - 2015-11-22 01:26 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
    2015-12-03 01:02 - 2015-11-22 01:26 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
    2015-12-03 01:02 - 2015-11-22 01:26 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
    2015-12-03 01:02 - 2015-11-22 01:25 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2015-12-03 01:02 - 2015-11-22 01:25 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2015-12-03 01:02 - 2015-11-22 01:25 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2015-12-03 01:02 - 2015-11-22 01:24 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2015-12-03 01:02 - 2015-11-22 01:24 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
    2015-12-03 01:02 - 2015-11-22 01:24 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
    2015-12-03 01:02 - 2015-11-22 01:24 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
    2015-12-03 01:02 - 2015-11-22 01:23 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2015-12-03 01:02 - 2015-11-22 01:20 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2015-12-03 01:02 - 2015-11-22 01:18 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2015-12-03 01:02 - 2015-11-22 01:18 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
    2015-12-03 01:02 - 2015-11-22 01:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
    2015-12-03 01:02 - 2015-11-22 01:17 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2015-12-03 01:02 - 2015-11-22 01:17 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2015-12-03 01:02 - 2015-11-22 01:11 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
    2015-12-03 00:29 - 2015-12-03 00:29 - 00000000 ____D C:\Users\New\AppData\Local\Dell
    2015-12-03 00:28 - 2015-12-03 00:28 - 00000409 _____ C:\Users\New\Desktop\BIOS Launcher.lnk
    2015-12-03 00:28 - 2015-12-03 00:28 - 00000000 ____D C:\Users\New\AppData\Roaming\WinBatch
    2015-12-03 00:28 - 2015-12-03 00:28 - 00000000 ____D C:\sc16v180
    2015-12-03 00:15 - 2015-12-03 00:15 - 00016880 _____ C:\WINDOWS\DellBIOS.Sys
    2015-12-02 22:33 - 2015-12-03 00:26 - 21457192 _____ (Dell, Inc.) C:\Users\New\Downloads\DRVR_WIN_R267814.EXE
    2015-12-02 22:33 - 2015-12-02 22:34 - 94933216 ____R (Dell, Inc.) C:\Users\New\Downloads\VIDEO_DRVR_WIN_R288480.EXE
    2015-12-02 22:31 - 2015-12-03 00:29 - 20351952 _____ (Dell Inc.) C:\Users\New\Downloads\APP_WIN_R312259.EXE
    2015-12-02 22:31 - 2015-12-02 22:38 - 03126456 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC_JF0K3_A01_SETUP_ZPE.exe
    2015-12-02 22:31 - 2015-12-02 22:31 - 01391360 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC_PXPXR_A03_SETUP_ZPE.exe
    2015-12-02 22:30 - 2015-12-03 00:18 - 02983912 _____ C:\Users\New\Downloads\E6500A29 (1).exe
    2015-12-02 22:30 - 2015-12-02 22:31 - 04949384 _____ C:\Users\New\Downloads\Intel_AMT-SOL--LMS_A03_R279203.exe
    2015-12-02 22:30 - 2015-12-02 22:30 - 05100920 _____ C:\Users\New\Downloads\Ricoh_multi-device_A01_R230630_setup_ZPE.exe
    2015-12-02 22:30 - 2015-12-02 22:30 - 01852992 _____ C:\Users\New\Downloads\Intel_AMT-HECI_A03_R279202.exe
    2015-12-02 22:25 - 2015-12-02 22:25 - 04617264 _____ C:\Users\New\Downloads\Dell_ControlVault_A00_R270677.exe
    2015-12-02 22:24 - 2015-12-03 00:16 - 05831896 _____ C:\Users\New\Downloads\CV_Setup_TJ9CD_A29_ZPE.exe
    2015-12-02 22:10 - 2015-12-03 00:17 - 04282512 _____ C:\Users\New\Downloads\CW1384A0.exe
    2015-12-02 22:10 - 2015-12-02 22:10 - 04327121 _____ C:\Users\New\Downloads\CL1384A0.bin
    2015-12-02 22:09 - 2015-12-03 00:15 - 02983912 _____ C:\Users\New\Downloads\E6500A29.exe
    2015-12-02 22:00 - 2015-12-02 22:00 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2015-12-02 08:58 - 2015-11-16 10:32 - 00919040 _____ (Farbar) C:\WINDOWS\mod_frst.exe
    2015-12-01 21:46 - 2015-12-01 22:25 - 2564476928 _____ C:\Users\New\Downloads\Win7_Pro_SP1_English_COEM_x32.iso
    2015-12-01 21:33 - 2015-12-01 22:41 - 3320903680 _____ C:\Users\New\Downloads\Win7_Pro_SP1_English_COEM_x64.iso
    2015-11-30 18:31 - 2015-11-30 18:31 - 00000000 ____D C:\Users\New\Downloads\Hirens.BootCD.15.2
    2015-11-30 18:23 - 2015-12-05 00:23 - 00000000 ____D C:\Users\New\AppData\Local\Deployment
    2015-11-30 18:23 - 2015-11-30 18:23 - 00000000 ____D C:\Users\New\AppData\Local\Apps\2.0
    2015-11-30 00:05 - 2015-12-03 00:16 - 00113192 _____ C:\Users\New\Downloads\Installer.exe
    2015-11-29 23:49 - 2015-11-29 23:49 - 00000000 ____D C:\Users\New\AppData\Roaming\Macromedia
    2015-11-27 21:49 - 2002-01-12 07:30 - 00003567 _____ (Beyond Logic hxxp://www.beyondlogic.org) C:\WINDOWS\SysWOW64\Drivers\PortTalk.sys
    2015-11-27 21:38 - 2015-11-30 17:51 - 03809184 _____ C:\Users\New\Downloads\3DP_Chip_v1510.exe
    2015-11-27 21:29 - 2015-11-27 21:29 - 00000366 _____ C:\Users\New\Documents\reggy.txt
    2015-11-27 20:33 - 2015-11-27 20:33 - 00000000 ____D C:\Program Files\Reference Assemblies
    2015-11-27 20:33 - 2015-11-27 20:33 - 00000000 ____D C:\Program Files\MSBuild
    2015-11-27 20:33 - 2015-11-27 20:33 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2015-11-27 20:33 - 2015-11-27 20:33 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2015-11-27 20:31 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2015-11-27 20:31 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-11-27 20:31 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2015-11-27 20:31 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2015-11-27 20:31 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2015-11-27 20:31 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-11-27 17:47 - 2015-11-27 17:47 - 00000000 ____D C:\Users\New\AppData\Local\AMD
    2015-11-27 17:46 - 2015-11-27 17:46 - 00000000 ____D C:\Users\New\AppData\Roaming\ATI
    2015-11-27 17:46 - 2015-11-27 17:46 - 00000000 ____D C:\Users\New\AppData\Local\ATI
    2015-11-27 17:46 - 2015-11-27 17:46 - 00000000 ____D C:\ProgramData\ATI
    2015-11-27 13:36 - 2015-11-12 22:41 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2015-11-27 13:36 - 2015-11-05 00:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2015-11-27 13:35 - 2015-11-12 22:18 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2015-11-27 13:35 - 2015-11-12 21:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2015-11-27 13:35 - 2015-11-12 21:29 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2015-11-27 13:34 - 2015-11-20 22:21 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2015-11-27 13:34 - 2015-11-20 22:02 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2015-11-27 13:34 - 2015-11-20 21:44 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
    2015-11-27 13:34 - 2015-11-20 21:29 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2015-11-27 13:34 - 2015-11-20 21:07 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2015-11-27 13:34 - 2015-11-12 22:55 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
    2015-11-27 13:34 - 2015-11-12 22:51 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
    2015-11-27 13:34 - 2015-11-12 22:51 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
    2015-11-27 13:34 - 2015-11-12 22:51 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2015-11-27 13:34 - 2015-11-12 22:43 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2015-11-27 13:34 - 2015-11-12 22:43 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2015-11-27 13:34 - 2015-11-12 22:43 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2015-11-27 13:34 - 2015-11-12 22:43 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2015-11-27 13:34 - 2015-11-12 22:43 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2015-11-27 13:34 - 2015-11-12 22:43 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
    2015-11-27 13:34 - 2015-11-12 22:43 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
    2015-11-27 13:34 - 2015-11-12 22:42 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2015-11-27 13:34 - 2015-11-12 22:42 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2015-11-27 13:34 - 2015-11-12 22:42 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2015-11-27 13:34 - 2015-11-12 22:41 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-11-27 13:34 - 2015-11-12 22:33 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
    2015-11-27 13:34 - 2015-11-12 22:33 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
    2015-11-27 13:34 - 2015-11-12 22:33 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2015-11-27 13:34 - 2015-11-12 22:32 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2015-11-27 13:34 - 2015-11-12 22:21 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2015-11-27 13:34 - 2015-11-12 22:21 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2015-11-27 13:34 - 2015-11-12 22:21 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2015-11-27 13:34 - 2015-11-12 22:21 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2015-11-27 13:34 - 2015-11-12 22:21 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2015-11-27 13:34 - 2015-11-12 22:21 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2015-11-27 13:34 - 2015-11-12 22:21 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2015-11-27 13:34 - 2015-11-12 22:21 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
    2015-11-27 13:34 - 2015-11-12 22:19 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-11-27 13:34 - 2015-11-12 22:09 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
    2015-11-27 13:34 - 2015-11-12 22:07 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
    2015-11-27 13:34 - 2015-11-12 22:06 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
    2015-11-27 13:34 - 2015-11-12 22:05 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
    2015-11-27 13:34 - 2015-11-12 22:05 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
    2015-11-27 13:34 - 2015-11-12 22:05 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
    2015-11-27 13:34 - 2015-11-12 22:05 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
    2015-11-27 13:34 - 2015-11-12 22:04 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
    2015-11-27 13:34 - 2015-11-12 22:04 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2015-11-27 13:34 - 2015-11-12 22:04 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
    2015-11-27 13:34 - 2015-11-12 22:03 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2015-11-27 13:34 - 2015-11-12 22:03 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
    2015-11-27 13:34 - 2015-11-12 22:02 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2015-11-27 13:34 - 2015-11-12 22:02 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2015-11-27 13:34 - 2015-11-12 22:01 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2015-11-27 13:34 - 2015-11-12 22:00 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
    2015-11-27 13:34 - 2015-11-12 22:00 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2015-11-27 13:34 - 2015-11-12 21:59 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2015-11-27 13:34 - 2015-11-12 21:58 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
    2015-11-27 13:34 - 2015-11-12 21:57 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2015-11-27 13:34 - 2015-11-12 21:57 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2015-11-27 13:34 - 2015-11-12 21:56 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2015-11-27 13:34 - 2015-11-12 21:56 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2015-11-27 13:34 - 2015-11-12 21:56 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2015-11-27 13:34 - 2015-11-12 21:55 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2015-11-27 13:34 - 2015-11-12 21:55 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2015-11-27 13:34 - 2015-11-12 21:54 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2015-11-27 13:34 - 2015-11-12 21:53 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2015-11-27 13:34 - 2015-11-12 21:53 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2015-11-27 13:34 - 2015-11-12 21:50 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2015-11-27 13:34 - 2015-11-12 21:49 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2015-11-27 13:34 - 2015-11-12 21:40 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2015-11-27 13:34 - 2015-11-12 21:40 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
    2015-11-27 13:34 - 2015-11-12 21:39 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2015-11-27 13:34 - 2015-11-12 21:37 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2015-11-27 13:34 - 2015-11-12 21:34 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
    2015-11-27 13:34 - 2015-11-12 21:33 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2015-11-27 13:34 - 2015-11-12 21:32 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2015-11-27 13:34 - 2015-11-12 21:30 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
    2015-11-27 13:34 - 2015-11-12 21:30 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2015-11-27 13:34 - 2015-11-12 21:28 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2015-11-27 13:34 - 2015-11-12 21:27 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2015-11-27 13:34 - 2015-11-12 21:23 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2015-11-27 13:34 - 2015-11-12 21:19 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2015-11-27 13:34 - 2015-11-05 04:05 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
    2015-11-27 13:34 - 2015-11-05 02:40 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2015-11-27 13:34 - 2015-11-05 02:25 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2015-11-27 13:34 - 2015-11-05 02:08 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
    2015-11-27 13:34 - 2015-11-05 02:08 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
    2015-11-27 13:34 - 2015-11-05 02:05 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2015-11-27 13:34 - 2015-11-05 02:04 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2015-11-27 13:34 - 2015-11-05 02:00 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
    2015-11-27 13:34 - 2015-11-05 01:44 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2015-11-27 13:34 - 2015-11-05 01:41 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2015-11-27 13:34 - 2015-11-05 01:13 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2015-11-27 13:34 - 2015-11-05 01:10 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2015-11-27 13:34 - 2015-11-05 01:08 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2015-11-27 13:34 - 2015-11-05 01:03 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
    2015-11-27 13:34 - 2015-11-05 01:02 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
    2015-11-27 13:34 - 2015-11-05 00:59 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2015-11-27 13:34 - 2015-11-05 00:55 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
    2015-11-27 13:34 - 2015-11-05 00:42 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2015-11-27 13:34 - 2015-11-05 00:18 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2015-11-27 13:34 - 2015-11-05 00:15 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2015-11-27 13:31 - 2015-07-05 02:08 - 00300704 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
    2015-11-27 13:21 - 2015-11-27 13:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
    2015-11-27 13:20 - 2015-11-27 13:20 - 00000000 ____D C:\ProgramData\AMD
    2015-11-27 13:20 - 2015-11-27 13:20 - 00000000 ____D C:\Program Files\ATI Technologies
    2015-11-27 13:19 - 2015-11-27 13:20 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
    2015-11-27 13:19 - 2015-11-27 13:19 - 00000000 ____D C:\ProgramData\Package Cache
    2015-11-27 13:17 - 2015-11-27 13:17 - 00000000 ____D C:\AMD
    2015-11-27 13:16 - 2015-11-27 13:16 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
    2015-11-27 12:33 - 2015-11-27 12:36 - 00000000 ____D C:\Program Files\AMD
    2015-11-27 12:19 - 2015-12-06 17:41 - 00004142 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{59F34359-515D-4EB1-990D-6C1571E6461D}
    2015-11-27 11:23 - 2015-11-27 11:23 - 00000000 ____D C:\Users\New\AppData\Local\MicrosoftEdge
    2015-11-27 10:39 - 2015-12-05 00:03 - 00000000 ___RD C:\Users\New\OneDrive
    2015-11-27 10:39 - 2015-11-27 10:42 - 00002339 _____ C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2015-11-27 10:34 - 2015-11-27 10:34 - 00000000 ____D C:\Users\New\AppData\Local\Comms
    2015-11-27 10:32 - 2015-11-27 10:32 - 00000000 ____D C:\Program Files\Elantech
    2015-11-27 10:31 - 2015-11-27 10:31 - 00000000 ____D C:\Users\New\AppData\Local\Publishers
    2015-11-27 10:31 - 2015-11-27 10:31 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
    2015-11-27 10:30 - 2015-11-27 10:30 - 00000000 ____D C:\Users\New\AppData\Local\NetworkTiles
    2015-11-27 10:24 - 2015-11-27 10:24 - 00000000 ____D C:\Users\New\AppData\Local\ActiveSync
    2015-11-27 10:22 - 2015-11-27 20:29 - 00000000 ____D C:\Users\New\AppData\Local\Packages
    2015-11-27 10:22 - 2015-11-27 17:45 - 00000000 __RHD C:\Users\Public\AccountPictures
    2015-11-27 10:22 - 2015-11-27 10:22 - 00000000 ____D C:\Users\New\AppData\Roaming\Adobe
    2015-11-27 10:22 - 2015-11-27 10:22 - 00000000 ____D C:\Users\New\AppData\Local\VirtualStore
    2015-11-27 10:22 - 2015-11-27 10:22 - 00000000 ____D C:\Users\New\AppData\Local\TileDataLayer
    2015-11-27 10:21 - 2015-11-27 10:21 - 00000020 ___SH C:\Users\New\ntuser.ini
    2015-11-27 10:11 - 2015-11-27 10:11 - 00000000 ____D C:\ProgramData\USOShared
    2015-11-27 10:10 - 2015-12-06 16:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default\My Documents
    2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
    2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
    2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default\Documents\My Music
    2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
    2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
    2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
    2015-11-27 10:09 - 2015-12-05 17:23 - 01008152 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2015-11-27 10:09 - 2015-11-27 10:09 - 00007623 _____ C:\WINDOWS\diagwrn.xml
    2015-11-27 10:09 - 2015-11-27 10:09 - 00007623 _____ C:\WINDOWS\diagerr.xml
    2015-11-27 10:05 - 2015-12-06 16:33 - 00000000 ____D C:\Users\New
    2015-11-27 10:05 - 2015-11-27 10:05 - 00000000 _SHDL C:\Users\New\My Documents
    2015-11-27 10:05 - 2015-11-27 10:05 - 00000000 _SHDL C:\Users\New\Documents\My Videos
    2015-11-27 10:05 - 2015-11-27 10:05 - 00000000 _SHDL C:\Users\New\Documents\My Pictures
    2015-11-27 10:05 - 2015-11-27 10:05 - 00000000 _SHDL C:\Users\New\Documents\My Music
    2015-11-27 09:58 - 2015-10-29 23:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2015-11-27 09:55 - 2015-11-27 14:00 - 00189240 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2015-11-27 09:54 - 2015-11-27 12:00 - 00000000 ___DC C:\WINDOWS\Panther
    2015-11-27 09:50 - 2015-11-27 09:50 - 00000000 ____D C:\Windows.old
    2015-11-27 09:49 - 2015-11-27 09:49 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
    2015-11-27 08:59 - 2015-11-30 17:52 - 05194776 _____ C:\Users\New\Downloads\sc16v180.exe
    2015-11-27 08:43 - 2015-11-27 09:24 - 00000000 ___HD C:\$WINDOWS.~BT
    2015-11-27 08:22 - 2015-11-27 08:22 - 00000000 ____D C:\ESD
    2015-11-27 07:56 - 2015-11-27 07:56 - 00000000 ___HD C:\$Windows.~WS
    2015-11-27 07:50 - 2015-11-27 07:51 - 07635472 _____ (Microsoft Corporation) C:\Users\New\Downloads\GetWindows10-Web_Default_Attr.exe
    2015-11-27 07:17 - 2015-11-27 07:17 - 00000000 __SHD C:\found.000
    2015-11-26 09:50 - 2015-11-26 09:50 - 00000000 ____D C:\15af99c3d1380f78e926fe5fd456
    2015-11-25 22:08 - 2015-11-25 22:08 - 00000000 ____D C:\Users\New\Documents\Corel DVD MovieFactory
     
  4. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-06 17:20 - 2015-10-29 22:28 - 00000000 ____D C:\Windows
    2015-12-06 14:14 - 2015-10-29 23:21 - 00000000 ____D C:\WINDOWS\INF
    2015-12-06 14:11 - 2015-10-29 22:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
    2015-12-05 06:07 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\NDF
    2015-12-04 21:01 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\AppReadiness
    2015-12-04 21:00 - 2015-10-29 23:11 - 00000000 ____D C:\WINDOWS\CbsTemp
    2015-12-04 01:48 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
    2015-12-04 01:48 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\inetsrv
    2015-12-04 01:46 - 2015-10-29 23:19 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
    2015-12-04 01:46 - 2015-10-29 23:19 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
    2015-12-04 01:46 - 2015-10-29 23:19 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
    2015-12-04 01:46 - 2015-10-29 23:19 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
    2015-12-04 01:46 - 2015-10-29 23:19 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
    2015-12-04 01:46 - 2015-10-29 23:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
    2015-12-04 01:46 - 2015-10-29 23:18 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
    2015-12-04 01:46 - 2015-10-29 23:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
    2015-12-04 01:46 - 2015-10-29 23:18 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
    2015-12-04 01:46 - 2015-10-29 23:18 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
    2015-12-04 01:46 - 2015-10-29 23:18 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
    2015-12-04 01:46 - 2015-10-29 23:18 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
    2015-12-03 17:20 - 2015-10-29 23:24 - 00000000 ___HD C:\Program Files\WindowsApps
    2015-12-03 03:55 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\rescache
    2015-12-03 03:32 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2015-11-29 05:25 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\appcompat
    2015-11-27 21:13 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\oobe
    2015-11-27 13:58 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
    2015-11-27 13:58 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2015-11-27 13:58 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2015-11-27 13:58 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\Provisioning
    2015-11-27 13:58 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2015-11-27 13:58 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\system32\Dism
    2015-11-27 10:47 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
    2015-11-27 10:25 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
    2015-11-27 10:25 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\MiracastView
    2015-11-27 10:11 - 2015-10-29 23:24 - 00000000 ____D C:\ProgramData\USOPrivate
    2015-11-27 10:10 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2015-11-27 10:10 - 2015-10-29 22:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
    2015-11-27 10:09 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\spool
    2015-11-27 10:07 - 2015-10-29 23:24 - 00000000 __RHD C:\Users\Public\Libraries
    2015-11-27 10:07 - 2009-07-13 23:44 - 00000000 ___RD C:\Users\Public\Recorded TV
    2015-11-27 10:06 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
    2015-11-27 10:02 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2015-11-27 09:55 - 2015-10-30 01:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
    2015-11-27 09:54 - 2015-10-29 23:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template

    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    ==================== BCD ================================

    Windows Boot Manager
    --------------------
    identifier {bootmgr}
    device partition=\Device\HarddiskVolume1
    description Windows Boot Manager
    locale en-US
    inherit {globalsettings}
    default {current}
    resumeobject {4c15d2f4-952f-11e5-a4ed-d97fdceddf51}
    displayorder {current}
    toolsdisplayorder {memdiag}
    timeout 30

    Windows Boot Loader
    -------------------
    identifier {13784cf9-91a8-11e5-90c0-cba8299548af}
    device ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{13784cfa-91a8-11e5-90c0-cba8299548af}
    path \windows\system32\winload.exe
    description Windows Recovery Environment
    inherit {bootloadersettings}
    osdevice ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{13784cfa-91a8-11e5-90c0-cba8299548af}
    systemroot \windows
    nx OptIn
    winpe Yes

    Windows Boot Loader
    -------------------
    identifier {current}
    device partition=C:
    path \WINDOWS\system32\winload.exe
    description Windows 10
    locale en-US
    inherit {bootloadersettings}
    recoverysequence {ca5d4806-952f-11e5-a4ed-d97fdceddf51}
    recoveryenabled Yes
    allowedinmemorysettings 0x15000075
    osdevice partition=C:
    systemroot \WINDOWS
    resumeobject {4c15d2f4-952f-11e5-a4ed-d97fdceddf51}
    nx OptIn
    pae ForceDisable
    bootmenupolicy Standard

    Windows Boot Loader
    -------------------
    identifier {ca5d4806-952f-11e5-a4ed-d97fdceddf51}
    device ramdisk=[\Device\HarddiskVolume3]\Recovery\WindowsRE\Winre.wim,{ca5d4807-952f-11e5-a4ed-d97fdceddf51}
    path \windows\system32\winload.exe
    description Windows Recovery Environment
    locale en-US
    inherit {bootloadersettings}
    displaymessage Recovery
    displaymessageoverride Recovery
    osdevice ramdisk=[\Device\HarddiskVolume3]\Recovery\WindowsRE\Winre.wim,{ca5d4807-952f-11e5-a4ed-d97fdceddf51}
    systemroot \windows
    nx OptIn
    bootmenupolicy Standard
    winpe Yes

    Windows Setup
    -------------
    identifier {cbd971bf-b7b8-4885-951a-fa03044f5d71}
    device ramdisk=[C:]\$WINDOWS.~BT\Sources\SafeOS\winre.wim,{13784cfb-91a8-11e5-90c0-cba8299548af}
    path \windows\system32\winload.exe
    description Windows Rollback
    locale en-US
    inherit {bootloadersettings}
    osdevice ramdisk=[C:]\$WINDOWS.~BT\Sources\SafeOS\winre.wim,{13784cfb-91a8-11e5-90c0-cba8299548af}
    systemroot \windows
    nx OptIn
    bootmenupolicy Standard
    winpe Yes

    Resume from Hibernate
    ---------------------
    identifier {13784cf7-91a8-11e5-90c0-cba8299548af}
    device partition=C:
    path \windows\system32\winresume.exe
    description Windows Resume Application
    locale en-US
    inherit {resumeloadersettings}
    filedevice partition=C:
    filepath \hiberfil.sys
    debugoptionenabled No

    Resume from Hibernate
    ---------------------
    identifier {4c15d2f4-952f-11e5-a4ed-d97fdceddf51}
    device partition=C:
    path \WINDOWS\system32\winresume.exe
    description Windows Resume Application
    locale en-US
    inherit {resumeloadersettings}
    recoverysequence {ca5d4806-952f-11e5-a4ed-d97fdceddf51}
    recoveryenabled Yes
    allowedinmemorysettings 0x15000075
    filedevice partition=C:
    filepath \hiberfil.sys
    bootmenupolicy Standard
    debugoptionenabled No

    Windows Memory Tester
    ---------------------
    identifier {memdiag}
    device partition=\Device\HarddiskVolume1
    path \boot\memtest.exe
    description Windows Memory Diagnostic
    locale en-US
    inherit {globalsettings}
    badmemoryaccess Yes

    EMS Settings
    ------------
    identifier {emssettings}
    bootems No

    Debugger Settings
    -----------------
    identifier {dbgsettings}
    debugtype Serial
    debugport 1
    baudrate 115200

    RAM Defects
    -----------
    identifier {badmemory}

    Global Settings
    ---------------
    identifier {globalsettings}
    inherit {dbgsettings}
    {emssettings}
    {badmemory}

    Boot Loader Settings
    --------------------
    identifier {bootloadersettings}
    inherit {globalsettings}
    {hypervisorsettings}

    Hypervisor Settings
    -------------------
    identifier {hypervisorsettings}
    hypervisordebugtype Serial
    hypervisordebugport 1
    hypervisorbaudrate 115200

    Resume Loader Settings
    ----------------------
    identifier {resumeloadersettings}
    inherit {globalsettings}

    Device options
    --------------
    identifier {13784cfa-91a8-11e5-90c0-cba8299548af}
    description Ramdisk Options
    ramdisksdidevice partition=\Device\HarddiskVolume1
    ramdisksdipath \Recovery\WindowsRE\boot.sdi

    Device options
    --------------
    identifier {13784cfb-91a8-11e5-90c0-cba8299548af}
    description Windows Setup
    ramdisksdidevice partition=C:
    ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi

    Device options
    --------------
    identifier {ca5d4807-952f-11e5-a4ed-d97fdceddf51}
    description Windows Recovery
    ramdisksdidevice partition=\Device\HarddiskVolume3
    ramdisksdipath \Recovery\WindowsRE\boot.sdi



    LastRegBack: 2015-11-27 09:54

    ==================== End of FRST.txt ============================
     
  5. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
    Ran by New (2015-12-06 17:19:04)
    Running from C:\Users\New\Downloads
    Windows 10 Home (X64) (2015-11-27 18:21:10)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-578399439-2519388439-559220130-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-578399439-2519388439-559220130-503 - Limited - Disabled)
    Guest (S-1-5-21-578399439-2519388439-559220130-501 - Limited - Disabled)
    New (S-1-5-21-578399439-2519388439-559220130-1000 - Administrator - Enabled) => C:\Users\New
    new_2 (S-1-5-21-578399439-2519388439-559220130-1006 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
    ELAN Touchpad 11.15.0.18_X64 (HKLM\...\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-578399439-2519388439-559220130-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\New\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)

    ==================== Restore Points =========================

    27-11-2015 10:18:21 Windows Modules Installer
    03-12-2015 01:04:03 Windows Update
    04-12-2015 01:42:08 Windows Modules Installer

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-10-29 23:24 - 2015-10-29 23:21 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {AE8F2690-A8B5-433C-A46C-CA9ABE5CA23F} - System32\Tasks\TweakBit\FixMyPC\Start FixMyPC automatic scanning => C:\Program Files (x86)\TweakBit\FixMyPC\FixMyPC.exe <==== ATTENTION

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)
     
  6. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    Users shortcut scan result (x64) Version:05-12-2015
    Ran by New (2015-12-06 17:20:24)
    Running from C:\Users\New\Downloads
    Boot Mode: Normal

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)





    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk -> C:\Users\New\Documents ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk -> C:\Users\New\Downloads ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk -> C:\Users\New\Music ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk -> C:\Users\New\Pictures ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk -> C:\Users\New\Videos ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk -> C:\Users\New ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk -> C:\Windows\DevicesFlow\DevicesFlow.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk -> C:\Windows\MiracastView\MiracastView.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk -> C:\Windows\PrintDialog\PrintDialog.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk -> C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IIS\IIS Client Manager.lnk -> C:\Windows\System32\inetsrv\InetMgr.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center\AMD Catalyst Control Center.lnk -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Advanced Micro Devices Inc.)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\IIS Manager.lnk -> C:\Windows\System32\inetsrv\InetMgr.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
    Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
    Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\Videos\CD Drive - Shortcut.lnk -> D:\ (No File)
    Shortcut: C:\Users\New\Music\CD Drive - Shortcut.lnk -> D:\ (No File)
    Shortcut: C:\Users\New\Music\Pictures - Shortcut.lnk -> C:\Users\New\Pictures ()
    Shortcut: C:\Users\New\Links\Desktop.lnk -> C:\Users\New\Desktop ()
    Shortcut: C:\Users\New\Links\Downloads.lnk -> C:\Users\New\Downloads ()
    Shortcut: C:\Users\New\Desktop\BIOS Launcher.lnk -> C:\sc16v180\launcher.exe (Toshiba America Information Systems, Inc.)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\New\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth File Transfer.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
    Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
    Shortcut: C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk -> C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes)




    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> -sta {C90FB8CA-3295-4462-A721-2935E83694BA}
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center\Help.lnk -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (Advanced Micro Devices Inc.) -> Start Help -help
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
    ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
    ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
    ShortcutWithArgument: C:\Users\New\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
    ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}


    InternetURL: C:\Users\New\Favorites\Bing.url -> hxxp://go.microsoft.com/fwlink/p/?LinkId=255142
    InternetURL: C:\Users\New\Favorites\How Malware hides and is installed as a Service.url -> hxxp://www.bleepingcomputer.com/tutorials/how-malware-hides-as-a-service/
    InternetURL: C:\Users\New\Favorites\KidZui, The Internet for Kids.url -> hxxp://www.kidzui.com/toshiba
    InternetURL: C:\Users\New\Favorites\WildTangent Games\WildTangent Games.url -> hxxp://toshiba.wildgames.com/?mc=iefav&dp=toshibaus
    InternetURL: C:\Users\New\Favorites\Toshiba\Deals and Offers.url -> hxxp://us.toshiba.com/adps/deals-and-offers
    InternetURL: C:\Users\New\Favorites\Toshiba\Explore Toshiba.url -> hxxp://us.toshiba.com/
    InternetURL: C:\Users\New\Favorites\Toshiba\Find Us on Twitter, Facebook, and YouTube.url -> hxxp://us.toshiba.com/social-media
    InternetURL: C:\Users\New\Favorites\Toshiba\Shop Toshiba.url -> hxxp://www.toshibadirect.com/
    InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba App Place.url -> hxxp://apps.toshiba.com/
    InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Book Place.url -> hxxp://www.toshibabookplace.com/
    InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Corporate Social Responsibility.url -> hxxp://us.toshiba.com/green
    InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Laptop Forums.url -> hxxp://laptopforums.toshiba.com/
    InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Online Backup.url -> hxxp://us.toshiba.com/online-backup
    InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Product Registration.url -> hxxp://toshibaproductregistration.com/
    InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Support.url -> hxxp://pcsupport.toshiba.com/
    InternetURL: C:\Users\New\Favorites\Skype\Skype.url -> hxxp://www.skype.com/go/ToshibaTAIS
    InternetURL: C:\Users\New\Favorites\Norton Internet Security\Symantec Security Center.url -> hxxp://www.yoursecurityresource.com/exploretoshiba/home.html
    InternetURL: C:\Users\New\Favorites\Links for United States\GobiernoUSA.gov.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129792
    InternetURL: C:\Users\New\Favorites\Links for United States\USA.gov.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129791
    InternetURL: C:\Users\New\Favorites\Links\Stay Secure Online.url -> hxxp://www.yoursecurityresource.com/exploretoshiba/home.html#LatestFeature
    InternetURL: C:\Users\New\Favorites\Links\Toshiba App Place.url -> hxxp://apps.toshiba.com/ie8webslice
    InternetURL: C:\Users\New\Favorites\Links\WildTangent Games.url -> hxxp://toshiba.wildgames.com/#ie8WebSlice
    InternetURL: C:\Users\New\Favorites\eMusic\eMusic.url -> hxxp://www.emusic.com/Toshiba
    InternetURL: C:\Users\New\Favorites\Amazon.com\Amazon MP3 – Millions of Music Downloads.url -> hxxp://www.amazon.com/b/?node=163856011&tag=tais2-bookmark-mp3-20
    InternetURL: C:\Users\New\Favorites\Amazon.com\Amazon Video On Demand Movies & TV.url -> hxxp://www.amazon.com/b/?node=16261631&tag=tais2-bookmark-vod-20
    InternetURL: C:\Users\New\Favorites\Amazon.com\Shop at Amazon.com.url -> hxxp://www.amazon.com/?tag=tais2-desktop-20

    ==================== End of Shortcut.txt =============================
     
  7. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ===============================

    Addition.txt log is incomplete.
    Please post complete log.
    Also when running FRST don't checkmark any extra boxes unless asked to do so.
     
  8. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    1st run computer bsod (writing on unwritable data)??


    this is all ive got, should I run it again?


    Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
    Ran by New (2015-12-06 17:19:04)
    Running from C:\Users\New\Downloads
    Windows 10 Home (X64) (2015-11-27 18:21:10)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-578399439-2519388439-559220130-500 - Administrator - Disabled)
    DefaultAccount (S-1-5-21-578399439-2519388439-559220130-503 - Limited - Disabled)
    Guest (S-1-5-21-578399439-2519388439-559220130-501 - Limited - Disabled)
    New (S-1-5-21-578399439-2519388439-559220130-1000 - Administrator - Enabled) => C:\Users\New
    new_2 (S-1-5-21-578399439-2519388439-559220130-1006 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
    ELAN Touchpad 11.15.0.18_X64 (HKLM\...\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-578399439-2519388439-559220130-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\New\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)

    ==================== Restore Points =========================

    27-11-2015 10:18:21 Windows Modules Installer
    03-12-2015 01:04:03 Windows Update
    04-12-2015 01:42:08 Windows Modules Installer

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2015-10-29 23:24 - 2015-10-29 23:21 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {AE8F2690-A8B5-433C-A46C-CA9ABE5CA23F} - System32\Tasks\TweakBit\FixMyPC\Start FixMyPC automatic scanning => C:\Program Files (x86)\TweakBit\FixMyPC\FixMyPC.exe <==== ATTENTION

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)
     
  9. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    Some other info that may help, I get strange messages in german from time to time
     
  10. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    Broni,also this computer has been dead for like 2 years I fixed a power cord issue so any emtry before november 20th 2015 is fabricated and I never ever ran fsrt before today
     
  11. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    [​IMG]

    this is why I'm here, my activation is not genuine anymore either, I don't even know if the iso.s from Microsoft are legitimately burning or if somethings editing them, I have 2 other comps in a bad way too. see, I give ms my coas and to dl 7.1 but.... I mean 1 even has C:\usr dir I cant access that survives formats with dban followed by a real vista businessx32 dell vista oem dvd install.... call me crazy.... and top it all off my google identifies a mac console and sunsystems os login so I dare not connect my phone to this chaos anymore sry just I'm sry
     
  12. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    I don't see anything malicious there. It'd be quite strange after fresh installation anyway.
    I'd suggest new topic in Windows forum.
     
  13. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    Ok so toshi didn't get the nasty from dell, or lenny....by way of usb thumb drive, heres my dell, my favorite, sir.

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-12-2015
    Ran by Subrectre (administrator) on WIN-GZ7SM9CILQR (14-02-2015 19:45:23)
    Running from E:\
    Loaded Profiles: Subrectre & Trusted Ibstallers (Available Profiles: Subrectre & ReadWrite & Trusted Ibstallers)
    Platform: Microsoft® Windows Vista™ Business Service Pack 1 (X86) Language: English (United States)
    Internet Explorer Version 7 (Default browser: IE)
    Boot Mode: Safe Mode (with Networking)
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\Windows\System32\WerFault.exe
    (Microsoft Corporation) C:\Windows\System32\userinit.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
    HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe
    HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
    HKLM\...\Run: [NVHotkey] => rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
    HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [488816 2011-01-04] (Alps Electric Co., Ltd.)
    HKU\S-1-5-21-444405077-440011167-3635889434-1002\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell System Manager.lnk [2015-02-12]
    ShortcutTarget: Dell System Manager.lnk -> C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)


    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 alssvc; C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe [382232 2008-06-03] (Dell Inc.)
    S2 ASFAgent; C:\Program Files\Intel\ASF Agent\ASFAgent.exe [133968 2007-04-19] (Intel Corporation)
    S2 dcpsysmgrsvc; C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe [390000 2011-07-28] (Dell Inc.)
    S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes) [File not signed]
    R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [94936 2015-02-14] (Malwarebytes) [File not signed]
    S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes) [File not signed]
    S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2015-02-14] (Malwarebytes) [File not signed]
    S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation) [File not signed]
    S1 AFD; \SystemRoot\system32\drivers\afd.sys [X]
    S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
    S3 NAL; \??\C:\Windows\system32\Drivers\iqvw32.sys [X]
    S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
    S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
    S3 STHDA; system32\DRIVERS\stwrt.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-02-14 19:44 - 2015-02-14 19:44 - 00156688 _____ C:\Windows\Minidump\Mini021415-05.dmp
    2015-02-14 19:43 - 2015-02-14 19:45 - 00000000 ____D C:\FRST
    2015-02-14 18:43 - 2015-02-14 18:43 - 00156688 _____ C:\Windows\Minidump\Mini021415-04.dmp
    2015-02-14 18:26 - 2015-02-14 18:26 - 00000000 ____D C:\Users\Trusted Ibstallers\.android
    2015-02-14 18:25 - 2015-02-14 18:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZTE Handset USB Driver
    2015-02-14 18:25 - 2015-02-14 18:25 - 00000000 ____D C:\Program Files\ZTE_Handset_USB_Driver
    2015-02-14 18:25 - 2014-03-17 09:59 - 00117960 _____ (ZTE Corporation) C:\Windows\system32\Drivers\zghsser.sys
    2015-02-14 18:25 - 2013-09-11 14:28 - 00149696 _____ (ZTE Corporation) C:\Windows\system32\Drivers\zghsnet.sys
    2015-02-14 18:25 - 2013-03-19 16:38 - 00821544 _____ C:\Windows\adb.exe
    2015-02-14 18:25 - 2012-11-09 15:12 - 00053000 _____ (VIA Telecom) C:\Windows\system32\Drivers\viahsser.sys
    2015-02-14 18:25 - 2012-10-31 16:02 - 00027016 _____ (Via Telecom, Inc.) C:\Windows\system32\Drivers\viahsets.sys
    2015-02-14 18:25 - 2012-06-20 11:51 - 00017672 _____ (HandSet Incorporated) C:\Windows\system32\Drivers\massfilter_hs.sys
    2015-02-14 18:25 - 2012-04-28 15:59 - 00851176 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll
    2015-02-14 18:25 - 2011-10-26 15:31 - 00067608 _____ (Google, inc) C:\Windows\AdbWinUsbApi.dll
    2015-02-14 18:25 - 2011-08-15 16:43 - 00102936 _____ (Google, inc) C:\Windows\AdbWinApi.dll
    2015-02-14 18:10 - 2015-02-14 18:11 - 00156688 _____ C:\Windows\Minidump\Mini021415-03.dmp
    2015-02-14 18:05 - 2015-02-14 18:05 - 00156688 _____ C:\Windows\Minidump\Mini021415-02.dmp
    2015-02-14 18:02 - 2015-02-14 18:02 - 00000949 _____ C:\Users\Trusted Ibstallers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-02-14 18:02 - 2015-02-14 18:02 - 00000944 _____ C:\Users\Trusted Ibstallers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-02-14 18:02 - 2015-02-14 18:02 - 00000915 _____ C:\Users\Trusted Ibstallers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
    2015-02-14 05:37 - 2015-02-14 18:26 - 00000000 ____D C:\Users\Trusted Ibstallers
    2015-02-14 05:37 - 2015-02-14 05:37 - 00000020 ___SH C:\Users\Trusted Ibstallers\ntuser.ini
    2015-02-14 05:37 - 2015-02-14 05:37 - 00000000 _SHDL C:\Users\Trusted Ibstallers\My Documents
    2015-02-14 05:37 - 2015-02-14 05:37 - 00000000 _SHDL C:\Users\Trusted Ibstallers\Documents\My Videos
    2015-02-14 05:37 - 2015-02-14 05:37 - 00000000 _SHDL C:\Users\Trusted Ibstallers\Documents\My Pictures
    2015-02-14 05:37 - 2015-02-14 05:37 - 00000000 _SHDL C:\Users\Trusted Ibstallers\Documents\My Music
    2015-02-14 05:22 - 2015-02-14 19:44 - 00000000 ____D C:\Windows\Minidump
    2015-02-14 05:22 - 2015-02-14 05:22 - 00156688 _____ C:\Windows\Minidump\Mini021415-01.dmp
    2015-02-14 05:21 - 2015-02-14 19:45 - 01156328 _____ C:\Windows\ntbtlog.txt
    2015-02-14 05:21 - 2015-02-14 19:44 - 197665415 _____ C:\Windows\MEMORY.DMP
    2015-02-14 04:57 - 2015-02-14 04:57 - 00000043 _____ C:\Users\Subrectre\Documents\kj.reg
    2015-02-14 04:16 - 2015-02-14 04:23 - 00000000 ___RD C:\Users\ReadWrite\Documents\Notes
    2015-02-14 04:14 - 2015-02-14 04:14 - 00001404 _____ C:\Users\ReadWrite\Desktop\WIN-GZ7SM9CILQR - Shortcut.lnk
    2015-02-14 04:11 - 2015-02-14 04:15 - 00000000 ____D C:\Users\ReadWrite
    2015-02-14 04:11 - 2015-02-14 04:11 - 00000020 ___SH C:\Users\ReadWrite\ntuser.ini
    2015-02-14 04:11 - 2015-02-14 04:11 - 00000000 _SHDL C:\Users\ReadWrite\My Documents
    2015-02-14 04:11 - 2015-02-14 04:11 - 00000000 _SHDL C:\Users\ReadWrite\Documents\My Videos
    2015-02-14 04:11 - 2015-02-14 04:11 - 00000000 _SHDL C:\Users\ReadWrite\Documents\My Pictures
    2015-02-14 04:11 - 2015-02-14 04:11 - 00000000 _SHDL C:\Users\ReadWrite\Documents\My Music
    2015-02-14 03:55 - 2015-02-14 03:55 - 00001846 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Collaboration.lnk
    2015-02-14 03:55 - 2015-02-14 03:55 - 00001583 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
    2015-02-14 03:54 - 2015-02-14 05:16 - 00000000 ____D C:\Windows\system32\FxsTmp
    2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Windows\system32\XPSViewer
    2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Windows\addins
    2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Program Files\Windows Collaboration
    2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Program Files\Reference Assemblies
    2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Program Files\MSBuild
    2015-02-14 03:39 - 2015-02-14 03:39 - 00000000 ____D C:\Users\Subrectre\AppData\Roaming\PeerNetworking
    2015-02-14 03:34 - 2015-02-14 18:01 - 00000000 ____D C:\Windows\pss
    2015-02-14 03:08 - 2015-02-14 04:16 - 00000000 ___RD C:\Users\Subrectre\Documents\Scanned Documents
    2015-02-14 03:08 - 2015-02-14 03:08 - 00000000 ____D C:\Users\Subrectre\Documents\Fax
    2015-02-14 03:05 - 2015-02-14 03:05 - 00000000 ___RD C:\Users\Subrectre\Documents\Notes
    2015-02-14 02:42 - 2015-02-14 02:42 - 00000000 ____D C:\Users\Subrectre\Documents\New Folder
    2015-02-14 02:38 - 2015-02-14 02:38 - 00000000 ____D C:\Program Files\Intel
    2015-02-13 22:44 - 2015-02-13 22:44 - 00000177 _____ C:\Users\Subrectre\Documents\ll.reg
    2015-02-13 22:36 - 2015-02-13 22:36 - 00000932 _____ C:\Users\Subrectre\Documents\jjjj.reg
    2015-02-13 10:22 - 2011-03-23 16:05 - 00223432 _____ (Intel Corporation) C:\Windows\system32\Drivers\e1y6032.sys
    2015-02-13 10:22 - 2009-10-11 00:26 - 00062144 _____ (Intel Corporation) C:\Windows\system32\NicInstY.dll
    2015-02-13 10:22 - 2008-11-12 16:26 - 00002823 _____ C:\Windows\system32\e1y6032.din
    2015-02-13 10:22 - 2007-12-14 13:06 - 00121440 _____ (Intel Corporation) C:\Windows\system32\e1000msg.dll
    2015-02-13 10:22 - 2007-08-24 08:58 - 00028272 _____ (Intel Corporation) C:\Windows\system32\NicCo26.dll
    2015-02-13 10:22 - 2006-01-12 14:52 - 00001904 _____ C:\Windows\system32\SetupBD.din
    2015-02-13 01:38 - 2015-02-14 19:39 - 00000426 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D5C48341-D683-4789-A507-74F24917F7B5}.job
    2015-02-12 17:46 - 2015-02-14 19:39 - 00120881 _____ C:\ProgramData\nvModes.dat
    2015-02-12 17:46 - 2015-02-14 19:39 - 00120881 _____ C:\ProgramData\nvModes.001
    2015-02-12 17:45 - 2015-02-12 17:46 - 00000000 ____D C:\ProgramData\NVIDIA
    2015-02-12 17:43 - 2015-02-12 17:43 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
    2015-02-12 17:43 - 2015-02-12 17:43 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf
    2015-02-12 17:43 - 2015-02-12 17:43 - 00000000 ____D C:\Windows\nview
    2015-02-12 17:43 - 2010-11-19 10:44 - 10676840 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 09936392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
    2015-02-12 17:43 - 2010-11-19 10:44 - 07728744 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 03220584 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 01749096 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 01325672 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 01070184 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 00795104 _____ (Microsoft Corporation) C:\Windows\system32\dpinst.exe
    2015-02-12 17:43 - 2010-11-19 10:44 - 00678504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 00600680 _____ (NVIDIA Corporation) C:\Windows\system32\nvuninst.exe
    2015-02-12 17:43 - 2010-11-19 10:44 - 00600680 _____ (NVIDIA Corporation) C:\Windows\system32\nvudisp.exe
    2015-02-12 17:43 - 2010-11-19 10:44 - 00262248 _____ C:\Windows\system32\nViewSetup.exe
    2015-02-12 17:43 - 2010-11-19 10:44 - 00227944 _____ (NVIDIA Corporation) C:\Windows\system32\nvcod1919.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 00227944 _____ (NVIDIA Corporation) C:\Windows\system32\nvcod.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 00206952 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshim.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 00068712 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll
    2015-02-12 17:43 - 2010-11-19 10:44 - 00023929 _____ C:\Windows\system32\nvdisp.nvu
    2015-02-12 17:43 - 2010-11-19 10:44 - 00010984 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvBridge.kmd
    2015-02-12 17:43 - 2010-05-06 01:59 - 00330344 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSPT.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00326248 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSPTB.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00326248 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSNL.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00322152 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSRU.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00309864 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSTR.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00309864 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSSL.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00305768 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSSK.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00305768 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSNO.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00301672 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSSV.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00301672 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSPL.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00297576 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSTH.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00203368 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSKO.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00174696 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSZHT.dll
    2015-02-12 17:43 - 2010-05-06 01:59 - 00170600 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSZHC.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 01731176 _____ C:\Windows\system32\nvwdmcpl.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 01657448 _____ C:\Windows\system32\nwiz.exe
    2015-02-12 17:43 - 2010-05-06 01:58 - 01612392 _____ C:\Windows\system32\nView.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 01108584 _____ C:\Windows\system32\nvwimg.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00473704 _____ C:\Windows\system32\nvShell.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00342632 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSES.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00342632 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSEL.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00334440 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSFR.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00334440 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSESM.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00330344 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSIT.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00322152 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSHU.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00318056 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSDE.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00309864 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSFI.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00301672 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSDA.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00293480 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSENU.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00293480 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSENG.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00293480 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSCS.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00289384 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSAR.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00285288 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSHE.dll
    2015-02-12 17:43 - 2010-05-06 01:58 - 00267368 _____ C:\Windows\system32\nvTaskbar.exe
    2015-02-12 17:43 - 2010-05-06 01:58 - 00219752 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSJA.dll
    2015-02-12 17:43 - 2010-05-06 01:57 - 00449128 _____ C:\Windows\system32\nvAppBar.exe
    2015-02-12 17:42 - 2015-02-12 17:42 - 00000000 ____D C:\Program Files\NetWaiting
    2015-02-12 17:42 - 2015-02-12 17:42 - 00000000 ____D C:\Program Files\DellTPad
    2015-02-12 17:42 - 2011-01-05 20:42 - 00284792 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Drivers\Apfiltr.sys
    2015-02-12 17:42 - 2010-12-17 02:52 - 00115640 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Vxdif.dll
    2015-02-12 17:42 - 2009-07-13 21:27 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
    2015-02-12 17:17 - 2011-01-28 11:19 - 00266440 _____ (Intel Corporation) C:\Windows\system32\PROUnstl.exe
    2015-02-12 17:16 - 2015-02-12 17:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetWaiting
    2015-02-12 17:14 - 2015-02-12 17:14 - 00000000 ____D C:\Program Files\CONEXANT
    2015-02-12 17:14 - 2008-07-30 01:26 - 00249856 _____ (Conexant Systems, Inc.) C:\Windows\system32\UCI32M34.dll
    2015-02-12 17:14 - 2008-06-24 20:25 - 00980992 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\HSX_DPV.sys
    2015-02-12 17:14 - 2008-06-24 20:23 - 00208384 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\HSXHWAZL.sys
    2015-02-12 17:14 - 2008-06-24 20:22 - 00661504 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\HSX_CNXT.sys
    2015-02-12 17:14 - 2008-03-26 20:33 - 00146146 _____ C:\Windows\system32\Drivers\del1028.cty
    2015-02-12 17:14 - 2007-10-16 16:37 - 00386560 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\XAudio.exe
    2015-02-12 17:14 - 2007-10-16 16:36 - 00008704 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\XAudio.sys
    2015-02-12 17:14 - 2006-06-17 15:26 - 00094208 _____ (Conexant) C:\Windows\system32\mdmxsdk.dll
    2015-02-12 17:14 - 2006-06-17 15:26 - 00012672 _____ (Conexant) C:\Windows\system32\Drivers\mdmxsdk.sys
    2015-02-12 17:13 - 2015-02-12 17:16 - 00000000 ____D C:\Program Files\Dell
    2015-02-12 17:13 - 2015-02-12 17:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell System Manager
    2015-02-12 17:12 - 2015-02-12 17:12 - 00000000 ____D C:\ProgramData\Dell
    2015-02-12 04:24 - 2015-02-12 04:24 - 00008192 ___RS C:\BOOTSECT.BAK
    2015-02-12 04:24 - 2015-02-11 20:31 - 00000000 ____D C:\Windows\Panther
    2015-02-12 04:24 - 2008-01-21 02:25 - 00333203 __RSH C:\bootmgr
    2015-02-12 04:22 - 2008-05-09 21:10 - 00000021 ___RH C:\Windows\dell_version
    2015-02-11 23:31 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2015-02-11 23:31 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2015-02-11 23:31 - 2015-02-14 05:20 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2015-02-11 23:31 - 2015-02-14 05:20 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
    2015-02-11 23:31 - 2015-02-14 05:16 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
    2015-02-11 23:31 - 2015-02-11 23:31 - 00000899 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2015-02-11 23:31 - 2015-02-11 23:31 - 00000000 ____D C:\ProgramData\Malwarebytes
    2015-02-11 20:46 - 2015-02-11 20:46 - 00000000 ____D C:\Intel
    2015-02-11 20:45 - 2015-02-14 02:33 - 00000000 ____D C:\Program Files\IDT
    2015-02-11 20:45 - 2015-02-12 17:16 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
    2015-02-11 20:45 - 2015-02-11 20:45 - 00000000 ____D C:\Windows\system32\SRSLabs
    2015-02-11 20:45 - 2010-04-05 07:56 - 00945664 _____ (IDT, Inc.) C:\Windows\system32\stapo.tmp
    2015-02-11 20:45 - 2010-04-05 07:54 - 00140288 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTACap.tmp
    2015-02-11 20:45 - 2010-04-05 07:54 - 00086016 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTCom.dll
    2015-02-11 20:45 - 2010-04-05 07:54 - 00061440 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTARen.tmp
    2015-02-11 20:44 - 2009-09-02 06:13 - 00131072 _____ (Dell, Inc.) C:\Windows\system32\DellSPMsg.dll
    2015-02-11 20:40 - 2015-02-11 20:40 - 00000000 __RSH C:\MSDOS.SYS
    2015-02-11 20:40 - 2015-02-11 20:40 - 00000000 __RSH C:\IO.SYS
    2015-02-11 20:39 - 2015-02-11 20:44 - 00000000 ____D C:\Dell
    2015-02-11 20:39 - 2015-02-11 20:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_00_00.Wdf
    2015-02-11 20:36 - 2015-02-11 20:36 - 00000949 _____ C:\Users\Subrectre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-02-11 20:36 - 2015-02-11 20:36 - 00000944 _____ C:\Users\Subrectre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-02-11 20:36 - 2015-02-11 20:36 - 00000915 _____ C:\Users\Subrectre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
    2015-02-11 20:35 - 2015-02-14 03:41 - 00000000 ____D C:\Users\Subrectre
    2015-02-11 20:35 - 2015-02-11 20:35 - 00000020 ___SH C:\Users\Subrectre\ntuser.ini
    2015-02-11 20:35 - 2015-02-11 20:35 - 00000000 _SHDL C:\Users\Subrectre\My Documents
    2015-02-11 20:35 - 2015-02-11 20:35 - 00000000 _SHDL C:\Users\Subrectre\Documents\My Videos
    2015-02-11 20:35 - 2015-02-11 20:35 - 00000000 _SHDL C:\Users\Subrectre\Documents\My Pictures
    2015-02-11 20:35 - 2015-02-11 20:35 - 00000000 _SHDL C:\Users\Subrectre\Documents\My Music
    2015-02-11 20:26 - 2015-02-11 20:26 - 00000000 ____D C:\Windows\CSC

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-02-14 19:44 - 2006-11-02 12:47 - 00064512 _____ C:\Windows\system32\umstartup.etl
    2015-02-14 19:44 - 2006-11-02 11:18 - 00000000 ____D C:\Windows
    2015-02-14 19:43 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\inf
    2015-02-14 19:43 - 2006-11-02 10:33 - 00690960 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-02-14 19:38 - 2006-11-02 13:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-02-14 19:38 - 2006-11-02 12:47 - 00039936 _____ C:\Windows\system32\umstartup000.etl
    2015-02-14 19:38 - 2006-11-02 12:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    2015-02-14 19:38 - 2006-11-02 12:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    2015-02-14 18:01 - 2006-11-02 13:01 - 00008084 _____ C:\Windows\Tasks\SCHEDLGU.TXT
    2015-02-14 05:22 - 2006-11-02 12:47 - 00228720 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-02-14 04:10 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\rescache
    2015-02-14 03:54 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\system32\setup
    2015-02-14 03:08 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\ModemLogs
    2015-02-14 02:52 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\Registration
    2015-02-12 17:44 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\Help
    2015-02-12 17:19 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\system32\NDF
    2015-02-12 04:24 - 2006-11-02 12:37 - 00262144 _____ C:\Windows\system32\config\BCD-Template

    ==================== Files in the root of some directories =======

    2015-02-14 03:39 - 2015-02-14 03:40 - 0029239 _____ () C:\Users\Subrectre\AppData\Roaming\UserTile.png
    2015-02-11 20:35 - 2015-02-11 20:53 - 0000680 _____ () C:\Users\Subrectre\AppData\Local\d3d9caps.dat
    2015-02-14 02:43 - 2015-02-14 02:43 - 0004608 _____ () C:\Users\Subrectre\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2015-02-12 17:46 - 2015-02-14 19:39 - 0120881 _____ () C:\ProgramData\nvModes.001
    2015-02-12 17:46 - 2015-02-14 19:39 - 0120881 _____ () C:\ProgramData\nvModes.dat

    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-02-14 19:01

    ==================== End of FRST.txt ============================
     
  14. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

    Additional scan result of Farbar Recovery Scan Tool (x86) Version:05-12-2015
    Ran by Subrectre (2015-02-14 19:45:43)
    Running from E:\
    Microsoft® Windows Vista™ Business Service Pack 1 (X86) (2015-02-11 20:30:25)
    Boot Mode: Safe Mode (with Networking)
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-444405077-440011167-3635889434-500 - Administrator - Disabled)
    Guest (S-1-5-21-444405077-440011167-3635889434-501 - Limited - Enabled)
    ReadWrite (S-1-5-21-444405077-440011167-3635889434-1001 - Limited - Enabled) => C:\Users\ReadWrite
    Subrectre (S-1-5-21-444405077-440011167-3635889434-1000 - Administrator - Enabled) => C:\Users\Subrectre
    Trusted Ibstallers (S-1-5-21-444405077-440011167-3635889434-1002 - Administrator - Enabled) => C:\Users\Trusted Ibstallers

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Ambient Light Sensor (HKLM\...\{5AF4F4C5-C71C-418F-B0B1-3903A345BD71}) (Version: 1.0.7 - Dell Inc.)
    Conexant HDA D330 MDC V.92 Modem (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F) (Version: 7.75.00.51 - Conexant)
    Dell System Manager (HKLM\...\{3EC64C00-4BBC-4C0A-9F95-40E3EDA72837}) (Version: 1.7.10000 - Dell Inc.)
    Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1207.101.108 - ALPS ELECTRIC CO., LTD.)
    IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6274.0 - IDT)
    Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.1 - Intel)
    Intel(R) PRO Alerting Agent (HKLM\...\{6EA8A52B-8EA1-4A59-85AB-48132299061A}) (Version: 12.0.3 - Intel Corporation)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    NetWaiting (HKLM\...\{3F92ABBB-6BBF-11D5-B229-002078017FBF}) (Version: 2.5.53 - BVRP Software, Inc)
    NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.61.39 - NVIDIA Corporation)
    NVIDIA nView Desktop Manager (HKLM\...\NVIDIA nView Desktop Manager) (Version: 6.14.10.12154 - NVIDIA Corporation)
    RICOH Media Driver ver.2.07.01.01 (HKLM\...\{2B818257-E6C7-4841-8C29-C5C9A982BCE5}) (Version: 2.07.01.01 - RICOH)
    ZTE Handset USB Driver (HKLM\...\{01D42BF0-ED08-463f-8A28-99EB6FEE962B}) (Version: - ZTE Corporation)
    ZTE Handset USB Driver (HKLM\...\{D2D77DC2-8299-11D1-8949-444553540000}_is1) (Version: 5.2104.1.02B04 - ZTE Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Restore Points =========================

    11-02-2015 20:45:10 Device Driver Package Install: IDT Sound, video and game controllers
    11-02-2015 20:45:38 Installed IDT Audio
    11-02-2015 20:46:46 Installed RICOH Media Driver ver.2.07.01.01
    11-02-2015 20:46:52 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
    11-02-2015 20:47:08 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
    11-02-2015 20:47:22 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
    11-02-2015 20:47:38 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
    11-02-2015 20:47:51 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
    11-02-2015 20:48:05 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
    12-02-2015 14:22:19 Scheduled Checkpoint
    12-02-2015 17:13:00 Installed Dell System Manager.
    12-02-2015 17:14:19 Device Driver Package Install: Conexant Modems
    12-02-2015 17:15:42 Installed NetWaiting
    12-02-2015 17:15:56 Installed NetWaiting
    12-02-2015 17:16:40 Installed Ambient Light Sensor.
    12-02-2015 17:17:34 Installed Intel(R) Network Connections.
    12-02-2015 17:42:06 Installed NetWaiting
    12-02-2015 17:42:17 Installed NetWaiting
    12-02-2015 17:42:38 Device Driver Package Install: Alps Mice and other pointing devices
    13-02-2015 10:22:21 Device Driver Package Install: Intel Network adapters
    14-02-2015 03:45:47 Windows Modules Installer

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2006-11-02 10:23 - 2006-09-18 21:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts

    127.0.0.1 localhost
    ::1 localhost

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {0D5045B3-A82F-4293-8529-AE3E787D00B5} - System32\Tasks\{858C497E-D077-4BD1-8E6E-1420A6C79753} => pcalua.exe -a E:\vista32\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE.exe -d E:\vista32
    Task: {251DDF51-D3D8-47C0-830D-CE9632A1A58D} - System32\Tasks\{9B870F81-7915-47AF-A64E-3C96FFC1F362} => pcalua.exe -a C:\Windows\system32\AlertApp.cpl -c Intel(R) ASF Agent Console
    Task: {2DB651F6-52E2-4C4B-A106-201DDDA36D54} - System32\Tasks\{A9C0BCDC-2084-4F6B-8526-3FA375191D1A} => pcalua.exe -a E:\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE.exe -d E:\
    Task: {4D72741E-769C-45DB-8604-CB8EBDADAA29} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
    Task: {4F8E5E12-4AB7-487A-9AF8-A6AE9CBCF11C} - System32\Tasks\{1B339E34-6073-4019-9189-802EA4A757B2} => pcalua.exe -a E:\CONEXANT_D330-HDA-MDC_JF0K3_A01_SETUP_ZPE.exe -d E:\
    Task: {CB6508EC-C43C-4C51-84CA-A6367ED7932B} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
    Task: {E73100E3-19C7-46B2-B7BE-9AD188531CF4} - System32\Tasks\{865EEE86-F6E1-4285-AC2C-879C64C92A65} => pcalua.exe -a "E:\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE (1).exe" -d E:\

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\User_Feed_Synchronization-{D5C48341-D683-4789-A507-74F24917F7B5}.job => C:\Windows\system32\msfeedssync.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============


    ==================== Alternate Data Streams (Whitelisted) =========

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-444405077-440011167-3635889434-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\Wallpaper\img23.jpg
    HKU\S-1-5-21-444405077-440011167-3635889434-1002\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
    DNS Servers: Media is not connected to internet.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
    Windows Firewall is disabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [SLSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\slsvc.exe
    FirewallRules: [SLSVC-In-TCP] => (Allow) %SystemRoot%\system32\slsvc.exe
    FirewallRules: [TCP Query User{9B73C88C-C823-431D-B0B0-6358C934A283}C:\windows\system32\wfs.exe] => (Allow) C:\windows\system32\wfs.exe
    FirewallRules: [UDP Query User{6E0EDADE-89EA-4EC8-81BF-DF4E6BD37BEF}C:\windows\system32\wfs.exe] => (Allow) C:\windows\system32\wfs.exe
    FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
    FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
    FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
    FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
    FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
    FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

    ==================== Faulty Device Manager Devices =============

    Name: Broadcom USH
    Description: Broadcom USH
    Class Guid:
    Manufacturer:
    Service:
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    Name: IDT High Definition Audio CODEC
    Description: IDT High Definition Audio CODEC
    Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
    Manufacturer: IDT
    Service: STHDA
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    Name: Network Controller
    Description: Network Controller
    Class Guid:
    Manufacturer:
    Service:
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    Name:
    Description:
    Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
    Manufacturer:
    Service: i8042prt
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    Name: SM Bus Controller
    Description: SM Bus Controller
    Class Guid:
    Manufacturer:
    Service:
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (02/14/2015 07:45:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (02/14/2015 07:45:09 PM) (Source: EventSystem) (EventID: 4609) (User: )
    Description: d:\rtm\com\complus\src\events\tier1\eventsystemobj.cpp458007043c

    Error: (02/14/2015 07:44:54 PM) (Source: EventSystem) (EventID: 4609) (User: )
    Description: d:\rtm\com\complus\src\events\tier1\eventsystemobj.cpp458007043c

    Error: (02/14/2015 07:39:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (02/14/2015 06:45:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (02/14/2015 06:28:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

    Error: (02/14/2015 06:25:59 PM) (Source: System Restore) (EventID: 8193) (User: )
    Description: Failed to create restore point on volume (Process = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Trusted Ibstallers\{fdbc1eea-d2c6-4f42-891c-073ad12fab99}\zghsser.inf" "0" "6f7356acf" "00000420" "WinSta0\Default" "00000274" "208" "C:\Program Files\ZTE_Handset_USB_Driver\Drivers"; Descripton = Device Driver Package Install: ZTE Corporation Ports (COM & LPT); Hr = 0x8007043c).

    Error: (02/14/2015 06:25:59 PM) (Source: System Restore) (EventID: 8193) (User: )
    Description: Failed to create restore point on volume (Process = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Trusted Ibstallers\{d9e1478a-6af4-4267-a519-4f1a037fa6e6}\zghsrndis.inf" "0" "6f731b1ab" "00000530" "WinSta0\Default" "00000420" "208" "C:\Program Files\ZTE_Handset_USB_Driver\Drivers"; Descripton = Device Driver Package Install: ZTE Corporation Network adapters; Hr = 0x8007043c).

    Error: (02/14/2015 06:25:58 PM) (Source: System Restore) (EventID: 8193) (User: )
    Description: Failed to create restore point on volume (Process = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Trusted Ibstallers\{0a6a90fd-ae19-4d9d-899e-182431f64816}\zghsnet.inf" "0" "66d4b695b" "000002F0" "WinSta0\Default" "00000530" "208" "C:\Program Files\ZTE_Handset_USB_Driver\Drivers"; Descripton = Device Driver Package Install: ZTE Corporation Network adapters; Hr = 0x8007043c).

    Error: (02/14/2015 06:25:58 PM) (Source: System Restore) (EventID: 8193) (User: )
    Description: Failed to create restore point on volume (Process = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Trusted Ibstallers\{be0da2cd-4f0d-49de-baf9-6c0d2174f3c8}\zghsmtp.inf" "0" "6b1181f67" "00000274" "WinSta0\Default" "000002F0" "208" "C:\Program Files\ZTE_Handset_USB_Driver\Drivers"; Descripton = Device Driver Package Install: ZTE Corporation Portable Devices; Hr = 0x8007043c).


    System errors:
    =============
    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: WinHTTP Web Proxy Auto-Discovery ServiceDHCP Client%%1068

    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: DHCP ClientAncilliary Function Driver for Winsock%%2

    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
    Description: Ancilliary Function Driver for Winsock%%2

    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
    Description: AFD
    spldr
    Wanarpv6

    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: IPsec Policy Agent%%10050

    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: IKE and AuthIP IPsec Keying Modules%%13876

    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: Computer BrowserServer%%1068

    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: TCP/IP NetBIOS HelperAncilliary Function Driver for Winsock%%31

    Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: DHCP ClientAncilliary Function Driver for Winsock%%31

    Error: (02/14/2015 07:45:09 PM) (Source: DCOM) (EventID: 10005) (User: )
    Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}


    CodeIntegrity:
    ===================================
    Date: 2015-02-14 19:45:40.516
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:40.501
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:40.485
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:40.470
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:40.360
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:40.345
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:40.345
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:40.329
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:30.080
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

    Date: 2015-02-14 19:45:30.049
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz
    Percentage of memory in use: 12%
    Total physical RAM: 3571.19 MB
    Available physical RAM: 3126.8 MB
    Total Virtual: 7325.4 MB
    Available Virtual: 7025.58 MB

    ==================== Drives ================================

    Drive c: (/) (Fixed) (Total:298.09 GB) (Free:278.29 GB) NTFS ==>[drive with boot components (obtained from BCD)]
    Drive d: (VISTA_SP1_BUSINESS) (CDROM) (Total:3.01 GB) (Free:0 GB) UDF
    Drive e: () (Removable) (Total:29.8 GB) (Free:23.61 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 27D027CF)
    Partition 1: (Active) - (Size=298.1 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 29.8 GB) (Disk ID: 3C393DA6)
    Partition 1: (Active) - (Size=29.8 GB) - (Type=0C)

    ==================== End of Addition.txt ============================
     
  15. Broni

    Broni Malware Annihilator Posts: 52,898   +344

    I don't see anything malicious there. It'd be quite strange after fresh installation anyway.
    I'd suggest new topic in Windows forum.
     
  16. subrectre

    subrectre TS Rookie Topic Starter Posts: 25

  17. Broni

    Broni Malware Annihilator Posts: 52,898   +344

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...