Inactive 100+ custom firewall entries on a clean install?

subrectre

Posts: 25   +0
An result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-12-2015
Ran by New (administrator) on NEW-PC (06-12-2015 18:24:13)
Running from C:\Users\New\Downloads
Loaded Profiles: New (Available Profiles: New)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Farbar) C:\Windows\mod_frst.exe
(Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1332224 2015-10-29] (Microsoft Corporation)
HKU\S-1-5-21-578399439-2519388439-559220130-1000\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-578399439-2519388439-559220130-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-578399439-2519388439-559220130-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [150528 2015-10-29] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{75504cfb-97e3-431c-886a-9f270b4bcfad}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-578399439-2519388439-559220130-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE03&ocid=UE03DHP
HKU\S-1-5-21-578399439-2519388439-559220130-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?pc=UE03&ocid=UE03DHP

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-21] (Advanced Micro Devices, Inc.) [File not signed]
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2015-12-04] (Microsoft Corporation)
S4 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corp.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-29] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-29] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 DellBIOS; C:\WINDOWS\DellBIOS.Sys [16880 2015-12-03] ()
S3 PortTalk; C:\Windows\SysWOW64\Drivers\PortTalk.sys [3567 2002-01-12] (Beyond Logic hxxp://www.beyondlogic.org) [File not signed]
R3 rtwlane_13; C:\Windows\System32\drivers\rtwlane_13.sys [3749888 2015-10-29] (Realtek Semiconductor Corporation )
R3 Thotkey; C:\Windows\System32\drivers\Thotkey.sys [45728 2015-08-07] (Toshiba Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-29] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-29] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-29] (Microsoft Corporation)
U4 UxSms; no ImagePath
 
-10-29] (Microsoft Corporation)
U4 UxSms; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-06 17:52 - 2015-12-06 17:52 - 00130337 _____ C:\Users\New\Downloads\getservices (1).zip
2015-12-06 17:20 - 2015-12-06 17:20 - 00022865 _____ C:\Users\New\Downloads\Shortcut.txt
2015-12-06 17:19 - 2015-12-06 17:22 - 00003458 _____ C:\Users\New\Downloads\Addition.txt
2015-12-06 16:48 - 2015-12-06 18:24 - 00005519 _____ C:\Users\New\Downloads\FRST.txt
2015-12-06 16:48 - 2015-12-06 18:24 - 00000000 ____D C:\FRST
2015-12-06 16:46 - 2015-12-06 16:47 - 02369024 _____ (Farbar) C:\Users\New\Downloads\FRST64.exe
2015-12-06 16:46 - 2015-12-06 16:47 - 02369024 _____ (Farbar) C:\Users\New\Downloads\FRST64 (1).exe
2015-12-06 16:32 - 2015-12-06 16:32 - 478763534 _____ C:\WINDOWS\MEMORY.DMP
2015-12-06 16:32 - 2015-12-06 16:32 - 00278972 _____ C:\WINDOWS\Minidump\120615-35296-01.dmp
2015-12-06 16:32 - 2015-12-06 16:32 - 00000000 ____D C:\WINDOWS\Minidump
2015-12-06 15:30 - 2015-12-06 15:41 - 00380416 _____ C:\Users\New\Downloads\mnl0px29.exe
2015-12-06 15:30 - 2015-12-06 15:31 - 00380416 _____ C:\Users\New\Downloads\vjnqsyyw.exe
2015-12-06 14:48 - 2015-12-06 14:58 - 00000000 ___RD C:\Users\New\Documents\Scanned Documents
2015-12-06 14:48 - 2015-12-06 14:50 - 00000000 ____D C:\Users\New\Documents\Fax
2015-12-06 13:23 - 2015-12-06 13:58 - 00000000 ____D C:\getservice
2015-12-06 13:21 - 2015-12-06 13:28 - 00130337 _____ C:\Users\New\Downloads\getservices.zip
2015-12-06 12:06 - 2015-12-06 12:08 - 137242392 _____ (Microsoft Corporation) C:\Users\New\Downloads\msert.exe
2015-12-06 11:26 - 2015-12-06 15:12 - 00000000 ____D C:\ProgramData\TweakBit
2015-12-06 11:26 - 2015-12-06 11:56 - 00000000 ____D C:\WINDOWS\System32\Tasks\TweakBit
2015-12-06 11:26 - 2015-12-06 11:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit
2015-12-06 11:25 - 2015-12-06 11:56 - 00000000 ____D C:\Program Files (x86)\TweakBit
2015-12-06 11:24 - 2015-12-06 11:24 - 00411792 _____ (TweakBit) C:\Users\New\Downloads\fix_Windows10-setup.exe
2015-12-06 01:46 - 2015-12-06 01:47 - 04168421 _____ C:\Users\New\Downloads\net-snmp-5.6.1.1-1.x86 (1).exe
2015-12-06 01:46 - 2015-12-06 01:46 - 04168421 _____ C:\Users\New\Downloads\net-snmp-5.6.1.1-1.x86.exe
2015-12-06 01:44 - 2015-12-06 01:44 - 07508760 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC-V-92-M_A01_R188086.exe
2015-12-06 01:43 - 2015-12-06 01:43 - 02522888 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE.exe
2015-12-06 01:43 - 2015-12-06 01:43 - 02522888 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE (1).exe
2015-12-06 01:30 - 2015-12-06 01:31 - 07455616 _____ C:\Users\New\Downloads\R191026 (1).exe
2015-12-06 01:30 - 2015-12-06 01:30 - 13552680 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A03_R301671 (1).exe
2015-12-06 01:30 - 2015-12-06 01:30 - 05994248 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A04_R301663 (2).exe
2015-12-05 19:30 - 2015-12-05 19:30 - 41328248 _____ C:\Users\New\Downloads\INTEL_MULTI-DEVICE_A08_R277773.exe
2015-12-05 19:30 - 2015-12-05 19:30 - 13516744 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A03_R301665 (1).exe
2015-12-05 19:30 - 2015-12-05 19:30 - 07455616 _____ C:\Users\New\Downloads\R191026.exe
2015-12-05 19:30 - 2015-12-05 19:30 - 05994248 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A04_R301663 (1).exe
2015-12-05 19:01 - 2015-12-05 19:02 - 99737784 _____ C:\Users\New\Downloads\R196560.exe
2015-12-05 19:01 - 2015-12-05 19:02 - 43938128 _____ C:\Users\New\Downloads\INTEL_MULTI-DEVICE_A08_R277771.exe
2015-12-05 19:01 - 2015-12-05 19:01 - 13552680 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A03_R301671.exe
2015-12-05 05:07 - 2015-12-05 05:08 - 09826585 _____ C:\Users\New\Downloads\AbstractsDark.themepack
2015-12-05 04:35 - 2015-12-05 04:35 - 00211832 _____ (Microsoft Corporation) C:\Users\New\Downloads\VSToolsForWindows1C.exe
2015-12-05 04:34 - 2015-12-05 04:34 - 01147432 _____ (Microsoft Corporation) C:\Users\New\Downloads\wdksetup.exe
2015-12-05 00:26 - 2015-12-05 00:27 - 75492552 _____ (Dell, Inc.) C:\Users\New\Downloads\VIDEO_DRVR_WIN_R288344.EXE
2015-12-05 00:26 - 2015-12-05 00:26 - 06174404 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC-V-92-M_A01_R188085.exe
2015-12-05 00:25 - 2015-12-05 00:26 - 05994248 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A04_R301663.exe
2015-12-05 00:25 - 2015-12-05 00:25 - 13516744 _____ C:\Users\New\Downloads\INTEL_825XX-GIGABIT-PLATFORM_A03_R301665.exe
2015-12-05 00:25 - 2015-12-05 00:25 - 11557320 _____ C:\Users\New\Downloads\DELL_TOUCHPAD----POINTING-ST_A15_R298882.exe
2015-12-05 00:25 - 2015-12-05 00:25 - 02983912 _____ C:\Users\New\Downloads\E6500A29 (2).exe
2015-12-05 00:24 - 2015-12-05 00:25 - 21457192 _____ (Dell, Inc.) C:\Users\New\Downloads\DRVR_WIN_R267814 (1).EXE
2015-12-04 23:23 - 2015-12-04 23:24 - 00002256 ____H C:\Users\New\Documents\Default.rdp
2015-12-04 22:50 - 2015-12-05 04:54 - 00000000 ____D C:\Users\New\Desktop\New folder
2015-12-04 22:17 - 2015-12-06 14:13 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-04 22:13 - 2015-12-04 22:13 - 00001182 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-04 22:13 - 2015-12-04 22:13 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-04 22:13 - 2015-12-04 22:13 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-04 22:13 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-12-04 22:13 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-12-04 22:13 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-12-04 22:11 - 2015-12-04 22:14 - 22908888 _____ (Malwarebytes ) C:\Users\New\Downloads\mbam-setup-2.2.0.1024.exe
2015-12-04 21:17 - 2015-12-06 11:58 - 00000000 ___HD C:\$SysReset
2015-12-04 01:53 - 2015-12-04 01:53 - 00984522 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-12-04 01:48 - 2015-12-04 01:48 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2015-12-04 01:47 - 2015-12-04 01:48 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IIS
2015-12-04 01:47 - 2015-12-04 01:47 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2015-12-04 01:47 - 2015-12-04 01:47 - 00000000 ____D C:\Program Files\Windows Identity Foundation
2015-12-04 01:47 - 2015-12-04 01:47 - 00000000 ____D C:\inetpub
2015-12-03 17:14 - 2015-12-03 17:14 - 00000000 ___HD C:\OneDriveTemp
2015-12-03 03:50 - 2015-12-03 03:50 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-12-03 01:03 - 2015-11-22 02:47 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-12-03 01:03 - 2015-11-22 02:47 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-03 01:03 - 2015-11-22 02:41 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-12-03 01:03 - 2015-11-22 02:41 - 01284960 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-12-03 01:03 - 2015-11-22 02:24 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2015-12-03 01:03 - 2015-11-22 02:14 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2015-12-03 01:03 - 2015-11-22 01:56 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-12-03 01:03 - 2015-11-22 01:54 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2015-12-03 01:03 - 2015-11-22 01:52 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-12-03 01:03 - 2015-11-22 01:43 - 24604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-12-03 01:03 - 2015-11-22 01:42 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-12-03 01:03 - 2015-11-22 01:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
2015-12-03 01:03 - 2015-11-22 01:41 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2015-12-03 01:03 - 2015-11-22 01:39 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-12-03 01:03 - 2015-11-22 01:39 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-12-03 01:03 - 2015-11-22 01:38 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-12-03 01:03 - 2015-11-22 01:38 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-12-03 01:03 - 2015-11-22 01:37 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2015-12-03 01:03 - 2015-11-22 01:36 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2015-12-03 01:03 - 2015-11-22 01:34 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2015-12-03 01:03 - 2015-11-22 01:33 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-12-03 01:03 - 2015-11-22 01:33 - 13380608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-12-03 01:03 - 2015-11-22 01:33 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-12-03 01:03 - 2015-11-22 01:30 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-12-03 01:03 - 2015-11-22 01:30 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-12-03 01:03 - 2015-11-22 01:27 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-12-03 01:03 - 2015-11-22 01:26 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-12-03 01:03 - 2015-11-22 01:24 - 12124672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-12-03 01:03 - 2015-11-22 01:24 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-12-03 01:03 - 2015-11-22 01:19 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-12-03 01:03 - 2015-11-22 01:16 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2015-12-03 01:02 - 2015-11-22 02:41 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-12-03 01:02 - 2015-11-22 02:35 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-12-03 01:02 - 2015-11-22 02:34 - 00975200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-12-03 01:02 - 2015-11-22 02:34 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2015-12-03 01:02 - 2015-11-22 02:33 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2015-12-03 01:02 - 2015-11-22 02:33 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2015-12-03 01:02 - 2015-11-22 02:33 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
2015-12-03 01:02 - 2015-11-22 02:30 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-12-03 01:02 - 2015-11-22 02:30 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-12-03 01:02 - 2015-11-22 02:26 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-12-03 01:02 - 2015-11-22 02:25 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2015-12-03 01:02 - 2015-11-22 02:20 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-12-03 01:02 - 2015-11-22 02:19 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-12-03 01:02 - 2015-11-22 02:00 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2015-12-03 01:02 - 2015-11-22 02:00 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2015-12-03 01:02 - 2015-11-22 01:57 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2015-12-03 01:02 - 2015-11-22 01:57 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2015-12-03 01:02 - 2015-11-22 01:57 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
2015-12-03 01:02 - 2015-11-22 01:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2015-12-03 01:02 - 2015-11-22 01:57 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2015-12-03 01:02 - 2015-11-22 01:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-12-03 01:02 - 2015-11-22 01:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2015-12-03 01:02 - 2015-11-22 01:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
2015-12-03 01:02 - 2015-11-22 01:56 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
2015-12-03 01:02 - 2015-11-22 01:55 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2015-12-03 01:02 - 2015-11-22 01:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2015-12-03 01:02 - 2015-11-22 01:55 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2015-12-03 01:02 - 2015-11-22 01:54 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2015-12-03 01:02 - 2015-11-22 01:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-12-03 01:02 - 2015-11-22 01:54 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2015-12-03 01:02 - 2015-11-22 01:54 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
2015-12-03 01:02 - 2015-11-22 01:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-12-03 01:02 - 2015-11-22 01:54 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2015-12-03 01:02 - 2015-11-22 01:54 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2015-12-03 01:02 - 2015-11-22 01:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2015-12-03 01:02 - 2015-11-22 01:52 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2015-12-03 01:02 - 2015-11-22 01:52 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2015-12-03 01:02 - 2015-11-22 01:52 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2015-12-03 01:02 - 2015-11-22 01:52 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2015-12-03 01:02 - 2015-11-22 01:51 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-12-03 01:02 - 2015-11-22 01:51 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2015-12-03 01:02 - 2015-11-22 01:51 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2015-12-03 01:02 - 2015-11-22 01:51 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2015-12-03 01:02 - 2015-11-22 01:51 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2015-12-03 01:02 - 2015-11-22 01:50 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2015-12-03 01:02 - 2015-11-22 01:49 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2015-12-03 01:02 - 2015-11-22 01:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2015-12-03 01:02 - 2015-11-22 01:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2015-12-03 01:02 - 2015-11-22 01:49 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2015-12-03 01:02 - 2015-11-22 01:48 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2015-12-03 01:02 - 2015-11-22 01:47 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2015-12-03 01:02 - 2015-11-22 01:46 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-12-03 01:02 - 2015-11-22 01:46 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-12-03 01:02 - 2015-11-22 01:45 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-12-03 01:02 - 2015-11-22 01:45 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2015-12-03 01:02 - 2015-11-22 01:45 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-12-03 01:02 - 2015-11-22 01:45 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
2015-12-03 01:02 - 2015-11-22 01:45 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-12-03 01:02 - 2015-11-22 01:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2015-12-03 01:02 - 2015-11-22 01:45 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-12-03 01:02 - 2015-11-22 01:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
2015-12-03 01:02 - 2015-11-22 01:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2015-12-03 01:02 - 2015-11-22 01:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2015-12-03 01:02 - 2015-11-22 01:44 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2015-12-03 01:02 - 2015-11-22 01:44 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-12-03 01:02 - 2015-11-22 01:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2015-12-03 01:02 - 2015-11-22 01:43 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-12-03 01:02 - 2015-11-22 01:43 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-12-03 01:02 - 2015-11-22 01:43 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-12-03 01:02 - 2015-11-22 01:43 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-12-03 01:02 - 2015-11-22 01:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2015-12-03 01:02 - 2015-11-22 01:42 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-12-03 01:02 - 2015-11-22 01:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-12-03 01:02 - 2015-11-22 01:42 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-12-03 01:02 - 2015-11-22 01:42 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2015-12-03 01:02 - 2015-11-22 01:42 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2015-12-03 01:02 - 2015-11-22 01:41 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-12-03 01:02 - 2015-11-22 01:41 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-12-03 01:02 - 2015-11-22 01:40 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-12-03 01:02 - 2015-11-22 01:40 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-12-03 01:02 - 2015-11-22 01:40 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-12-03 01:02 - 2015-11-22 01:40 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2015-12-03 01:02 - 2015-11-22 01:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2015-12-03 01:02 - 2015-11-22 01:39 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-12-03 01:02 - 2015-11-22 01:39 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2015-12-03 01:02 - 2015-11-22 01:39 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2015-12-03 01:02 - 2015-11-22 01:39 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-12-03 01:02 - 2015-11-22 01:39 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-12-03 01:02 - 2015-11-22 01:39 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
 
2015-12-03 01:02 - 2015-11-22 01:39 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2015-12-03 01:02 - 2015-11-22 01:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2015-12-03 01:02 - 2015-11-22 01:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2015-12-03 01:02 - 2015-11-22 01:38 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-12-03 01:02 - 2015-11-22 01:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2015-12-03 01:02 - 2015-11-22 01:38 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2015-12-03 01:02 - 2015-11-22 01:37 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-12-03 01:02 - 2015-11-22 01:37 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-12-03 01:02 - 2015-11-22 01:34 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2015-12-03 01:02 - 2015-11-22 01:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2015-12-03 01:02 - 2015-11-22 01:34 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-12-03 01:02 - 2015-11-22 01:34 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2015-12-03 01:02 - 2015-11-22 01:34 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2015-12-03 01:02 - 2015-11-22 01:33 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
2015-12-03 01:02 - 2015-11-22 01:32 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-12-03 01:02 - 2015-11-22 01:32 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2015-12-03 01:02 - 2015-11-22 01:32 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-12-03 01:02 - 2015-11-22 01:31 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-12-03 01:02 - 2015-11-22 01:31 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-12-03 01:02 - 2015-11-22 01:31 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-12-03 01:02 - 2015-11-22 01:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-12-03 01:02 - 2015-11-22 01:28 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2015-12-03 01:02 - 2015-11-22 01:27 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-12-03 01:02 - 2015-11-22 01:27 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2015-12-03 01:02 - 2015-11-22 01:27 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-12-03 01:02 - 2015-11-22 01:27 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2015-12-03 01:02 - 2015-11-22 01:27 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-12-03 01:02 - 2015-11-22 01:26 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-12-03 01:02 - 2015-11-22 01:26 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2015-12-03 01:02 - 2015-11-22 01:26 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-12-03 01:02 - 2015-11-22 01:25 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-12-03 01:02 - 2015-11-22 01:25 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-12-03 01:02 - 2015-11-22 01:25 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-12-03 01:02 - 2015-11-22 01:24 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-12-03 01:02 - 2015-11-22 01:24 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-12-03 01:02 - 2015-11-22 01:24 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2015-12-03 01:02 - 2015-11-22 01:24 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2015-12-03 01:02 - 2015-11-22 01:23 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-12-03 01:02 - 2015-11-22 01:20 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2015-12-03 01:02 - 2015-11-22 01:18 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-12-03 01:02 - 2015-11-22 01:18 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-12-03 01:02 - 2015-11-22 01:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2015-12-03 01:02 - 2015-11-22 01:17 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-12-03 01:02 - 2015-11-22 01:17 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-12-03 01:02 - 2015-11-22 01:11 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-12-03 00:29 - 2015-12-03 00:29 - 00000000 ____D C:\Users\New\AppData\Local\Dell
2015-12-03 00:28 - 2015-12-03 00:28 - 00000409 _____ C:\Users\New\Desktop\BIOS Launcher.lnk
2015-12-03 00:28 - 2015-12-03 00:28 - 00000000 ____D C:\Users\New\AppData\Roaming\WinBatch
2015-12-03 00:28 - 2015-12-03 00:28 - 00000000 ____D C:\sc16v180
2015-12-03 00:15 - 2015-12-03 00:15 - 00016880 _____ C:\WINDOWS\DellBIOS.Sys
2015-12-02 22:33 - 2015-12-03 00:26 - 21457192 _____ (Dell, Inc.) C:\Users\New\Downloads\DRVR_WIN_R267814.EXE
2015-12-02 22:33 - 2015-12-02 22:34 - 94933216 ____R (Dell, Inc.) C:\Users\New\Downloads\VIDEO_DRVR_WIN_R288480.EXE
2015-12-02 22:31 - 2015-12-03 00:29 - 20351952 _____ (Dell Inc.) C:\Users\New\Downloads\APP_WIN_R312259.EXE
2015-12-02 22:31 - 2015-12-02 22:38 - 03126456 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC_JF0K3_A01_SETUP_ZPE.exe
2015-12-02 22:31 - 2015-12-02 22:31 - 01391360 _____ C:\Users\New\Downloads\CONEXANT_D330-HDA-MDC_PXPXR_A03_SETUP_ZPE.exe
2015-12-02 22:30 - 2015-12-03 00:18 - 02983912 _____ C:\Users\New\Downloads\E6500A29 (1).exe
2015-12-02 22:30 - 2015-12-02 22:31 - 04949384 _____ C:\Users\New\Downloads\Intel_AMT-SOL--LMS_A03_R279203.exe
2015-12-02 22:30 - 2015-12-02 22:30 - 05100920 _____ C:\Users\New\Downloads\Ricoh_multi-device_A01_R230630_setup_ZPE.exe
2015-12-02 22:30 - 2015-12-02 22:30 - 01852992 _____ C:\Users\New\Downloads\Intel_AMT-HECI_A03_R279202.exe
2015-12-02 22:25 - 2015-12-02 22:25 - 04617264 _____ C:\Users\New\Downloads\Dell_ControlVault_A00_R270677.exe
2015-12-02 22:24 - 2015-12-03 00:16 - 05831896 _____ C:\Users\New\Downloads\CV_Setup_TJ9CD_A29_ZPE.exe
2015-12-02 22:10 - 2015-12-03 00:17 - 04282512 _____ C:\Users\New\Downloads\CW1384A0.exe
2015-12-02 22:10 - 2015-12-02 22:10 - 04327121 _____ C:\Users\New\Downloads\CL1384A0.bin
2015-12-02 22:09 - 2015-12-03 00:15 - 02983912 _____ C:\Users\New\Downloads\E6500A29.exe
2015-12-02 22:00 - 2015-12-02 22:00 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-12-02 08:58 - 2015-11-16 10:32 - 00919040 _____ (Farbar) C:\WINDOWS\mod_frst.exe
2015-12-01 21:46 - 2015-12-01 22:25 - 2564476928 _____ C:\Users\New\Downloads\Win7_Pro_SP1_English_COEM_x32.iso
2015-12-01 21:33 - 2015-12-01 22:41 - 3320903680 _____ C:\Users\New\Downloads\Win7_Pro_SP1_English_COEM_x64.iso
2015-11-30 18:31 - 2015-11-30 18:31 - 00000000 ____D C:\Users\New\Downloads\Hirens.BootCD.15.2
2015-11-30 18:23 - 2015-12-05 00:23 - 00000000 ____D C:\Users\New\AppData\Local\Deployment
2015-11-30 18:23 - 2015-11-30 18:23 - 00000000 ____D C:\Users\New\AppData\Local\Apps\2.0
2015-11-30 00:05 - 2015-12-03 00:16 - 00113192 _____ C:\Users\New\Downloads\Installer.exe
2015-11-29 23:49 - 2015-11-29 23:49 - 00000000 ____D C:\Users\New\AppData\Roaming\Macromedia
2015-11-27 21:49 - 2002-01-12 07:30 - 00003567 _____ (Beyond Logic hxxp://www.beyondlogic.org) C:\WINDOWS\SysWOW64\Drivers\PortTalk.sys
2015-11-27 21:38 - 2015-11-30 17:51 - 03809184 _____ C:\Users\New\Downloads\3DP_Chip_v1510.exe
2015-11-27 21:29 - 2015-11-27 21:29 - 00000366 _____ C:\Users\New\Documents\reggy.txt
2015-11-27 20:33 - 2015-11-27 20:33 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-11-27 20:33 - 2015-11-27 20:33 - 00000000 ____D C:\Program Files\MSBuild
2015-11-27 20:33 - 2015-11-27 20:33 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-11-27 20:33 - 2015-11-27 20:33 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-11-27 20:31 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-11-27 20:31 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-11-27 20:31 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-11-27 20:31 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-11-27 20:31 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-11-27 20:31 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-11-27 17:47 - 2015-11-27 17:47 - 00000000 ____D C:\Users\New\AppData\Local\AMD
2015-11-27 17:46 - 2015-11-27 17:46 - 00000000 ____D C:\Users\New\AppData\Roaming\ATI
2015-11-27 17:46 - 2015-11-27 17:46 - 00000000 ____D C:\Users\New\AppData\Local\ATI
2015-11-27 17:46 - 2015-11-27 17:46 - 00000000 ____D C:\ProgramData\ATI
2015-11-27 13:36 - 2015-11-12 22:41 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-11-27 13:36 - 2015-11-05 00:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-27 13:35 - 2015-11-12 22:18 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-11-27 13:35 - 2015-11-12 21:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-11-27 13:35 - 2015-11-12 21:29 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-11-27 13:34 - 2015-11-20 22:21 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-11-27 13:34 - 2015-11-20 22:02 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-11-27 13:34 - 2015-11-20 21:44 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-11-27 13:34 - 2015-11-20 21:29 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2015-11-27 13:34 - 2015-11-20 21:07 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2015-11-27 13:34 - 2015-11-12 22:55 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2015-11-27 13:34 - 2015-11-12 22:51 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-11-27 13:34 - 2015-11-12 22:51 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-11-27 13:34 - 2015-11-12 22:51 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2015-11-27 13:34 - 2015-11-12 22:43 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-11-27 13:34 - 2015-11-12 22:43 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-11-27 13:34 - 2015-11-12 22:43 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-11-27 13:34 - 2015-11-12 22:43 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-11-27 13:34 - 2015-11-12 22:43 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-11-27 13:34 - 2015-11-12 22:43 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-11-27 13:34 - 2015-11-12 22:43 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2015-11-27 13:34 - 2015-11-12 22:42 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-11-27 13:34 - 2015-11-12 22:42 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-11-27 13:34 - 2015-11-12 22:42 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-11-27 13:34 - 2015-11-12 22:41 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-27 13:34 - 2015-11-12 22:33 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2015-11-27 13:34 - 2015-11-12 22:33 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-11-27 13:34 - 2015-11-12 22:33 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-11-27 13:34 - 2015-11-12 22:32 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2015-11-27 13:34 - 2015-11-12 22:21 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-11-27 13:34 - 2015-11-12 22:21 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-11-27 13:34 - 2015-11-12 22:21 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-11-27 13:34 - 2015-11-12 22:21 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-11-27 13:34 - 2015-11-12 22:21 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-11-27 13:34 - 2015-11-12 22:21 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2015-11-27 13:34 - 2015-11-12 22:21 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-11-27 13:34 - 2015-11-12 22:21 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2015-11-27 13:34 - 2015-11-12 22:19 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-27 13:34 - 2015-11-12 22:09 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2015-11-27 13:34 - 2015-11-12 22:07 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-11-27 13:34 - 2015-11-12 22:06 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-11-27 13:34 - 2015-11-12 22:05 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-11-27 13:34 - 2015-11-12 22:05 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-11-27 13:34 - 2015-11-12 22:05 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-11-27 13:34 - 2015-11-12 22:05 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2015-11-27 13:34 - 2015-11-12 22:04 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-11-27 13:34 - 2015-11-12 22:04 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2015-11-27 13:34 - 2015-11-12 22:04 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-11-27 13:34 - 2015-11-12 22:03 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2015-11-27 13:34 - 2015-11-12 22:03 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-11-27 13:34 - 2015-11-12 22:02 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-11-27 13:34 - 2015-11-12 22:02 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-11-27 13:34 - 2015-11-12 22:01 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-11-27 13:34 - 2015-11-12 22:00 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2015-11-27 13:34 - 2015-11-12 22:00 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2015-11-27 13:34 - 2015-11-12 21:59 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2015-11-27 13:34 - 2015-11-12 21:58 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-11-27 13:34 - 2015-11-12 21:57 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2015-11-27 13:34 - 2015-11-12 21:57 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-11-27 13:34 - 2015-11-12 21:56 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-11-27 13:34 - 2015-11-12 21:56 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-11-27 13:34 - 2015-11-12 21:56 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-11-27 13:34 - 2015-11-12 21:55 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-11-27 13:34 - 2015-11-12 21:55 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2015-11-27 13:34 - 2015-11-12 21:54 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-11-27 13:34 - 2015-11-12 21:53 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2015-11-27 13:34 - 2015-11-12 21:53 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-11-27 13:34 - 2015-11-12 21:50 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-27 13:34 - 2015-11-12 21:49 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-27 13:34 - 2015-11-12 21:40 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2015-11-27 13:34 - 2015-11-12 21:40 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2015-11-27 13:34 - 2015-11-12 21:39 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-11-27 13:34 - 2015-11-12 21:37 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2015-11-27 13:34 - 2015-11-12 21:34 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2015-11-27 13:34 - 2015-11-12 21:33 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-11-27 13:34 - 2015-11-12 21:32 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2015-11-27 13:34 - 2015-11-12 21:30 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-11-27 13:34 - 2015-11-12 21:30 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-11-27 13:34 - 2015-11-12 21:28 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-11-27 13:34 - 2015-11-12 21:27 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2015-11-27 13:34 - 2015-11-12 21:23 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-27 13:34 - 2015-11-12 21:19 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-11-27 13:34 - 2015-11-05 04:05 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-27 13:34 - 2015-11-05 02:40 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-27 13:34 - 2015-11-05 02:25 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-27 13:34 - 2015-11-05 02:08 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2015-11-27 13:34 - 2015-11-05 02:08 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2015-11-27 13:34 - 2015-11-05 02:05 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-11-27 13:34 - 2015-11-05 02:04 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-11-27 13:34 - 2015-11-05 02:00 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2015-11-27 13:34 - 2015-11-05 01:44 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-11-27 13:34 - 2015-11-05 01:41 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-27 13:34 - 2015-11-05 01:13 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-27 13:34 - 2015-11-05 01:10 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-27 13:34 - 2015-11-05 01:08 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-27 13:34 - 2015-11-05 01:03 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2015-11-27 13:34 - 2015-11-05 01:02 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2015-11-27 13:34 - 2015-11-05 00:59 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-11-27 13:34 - 2015-11-05 00:55 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2015-11-27 13:34 - 2015-11-05 00:42 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-11-27 13:34 - 2015-11-05 00:18 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-27 13:34 - 2015-11-05 00:15 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-27 13:31 - 2015-07-05 02:08 - 00300704 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-11-27 13:21 - 2015-11-27 13:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-11-27 13:20 - 2015-11-27 13:20 - 00000000 ____D C:\ProgramData\AMD
2015-11-27 13:20 - 2015-11-27 13:20 - 00000000 ____D C:\Program Files\ATI Technologies
2015-11-27 13:19 - 2015-11-27 13:20 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-11-27 13:19 - 2015-11-27 13:19 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-27 13:17 - 2015-11-27 13:17 - 00000000 ____D C:\AMD
2015-11-27 13:16 - 2015-11-27 13:16 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2015-11-27 12:33 - 2015-11-27 12:36 - 00000000 ____D C:\Program Files\AMD
2015-11-27 12:19 - 2015-12-06 17:41 - 00004142 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{59F34359-515D-4EB1-990D-6C1571E6461D}
2015-11-27 11:23 - 2015-11-27 11:23 - 00000000 ____D C:\Users\New\AppData\Local\MicrosoftEdge
2015-11-27 10:39 - 2015-12-05 00:03 - 00000000 ___RD C:\Users\New\OneDrive
2015-11-27 10:39 - 2015-11-27 10:42 - 00002339 _____ C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-11-27 10:34 - 2015-11-27 10:34 - 00000000 ____D C:\Users\New\AppData\Local\Comms
2015-11-27 10:32 - 2015-11-27 10:32 - 00000000 ____D C:\Program Files\Elantech
2015-11-27 10:31 - 2015-11-27 10:31 - 00000000 ____D C:\Users\New\AppData\Local\Publishers
2015-11-27 10:31 - 2015-11-27 10:31 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-11-27 10:30 - 2015-11-27 10:30 - 00000000 ____D C:\Users\New\AppData\Local\NetworkTiles
2015-11-27 10:24 - 2015-11-27 10:24 - 00000000 ____D C:\Users\New\AppData\Local\ActiveSync
2015-11-27 10:22 - 2015-11-27 20:29 - 00000000 ____D C:\Users\New\AppData\Local\Packages
2015-11-27 10:22 - 2015-11-27 17:45 - 00000000 __RHD C:\Users\Public\AccountPictures
2015-11-27 10:22 - 2015-11-27 10:22 - 00000000 ____D C:\Users\New\AppData\Roaming\Adobe
2015-11-27 10:22 - 2015-11-27 10:22 - 00000000 ____D C:\Users\New\AppData\Local\VirtualStore
2015-11-27 10:22 - 2015-11-27 10:22 - 00000000 ____D C:\Users\New\AppData\Local\TileDataLayer
2015-11-27 10:21 - 2015-11-27 10:21 - 00000020 ___SH C:\Users\New\ntuser.ini
2015-11-27 10:11 - 2015-11-27 10:11 - 00000000 ____D C:\ProgramData\USOShared
2015-11-27 10:10 - 2015-12-06 16:32 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default\My Documents
2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2015-11-27 10:10 - 2015-11-27 10:10 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2015-11-27 10:09 - 2015-12-05 17:23 - 01008152 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-27 10:09 - 2015-11-27 10:09 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2015-11-27 10:09 - 2015-11-27 10:09 - 00007623 _____ C:\WINDOWS\diagerr.xml
2015-11-27 10:05 - 2015-12-06 16:33 - 00000000 ____D C:\Users\New
2015-11-27 10:05 - 2015-11-27 10:05 - 00000000 _SHDL C:\Users\New\My Documents
2015-11-27 10:05 - 2015-11-27 10:05 - 00000000 _SHDL C:\Users\New\Documents\My Videos
2015-11-27 10:05 - 2015-11-27 10:05 - 00000000 _SHDL C:\Users\New\Documents\My Pictures
2015-11-27 10:05 - 2015-11-27 10:05 - 00000000 _SHDL C:\Users\New\Documents\My Music
2015-11-27 09:58 - 2015-10-29 23:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-11-27 09:55 - 2015-11-27 14:00 - 00189240 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-27 09:54 - 2015-11-27 12:00 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-27 09:50 - 2015-11-27 09:50 - 00000000 ____D C:\Windows.old
2015-11-27 09:49 - 2015-11-27 09:49 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-11-27 08:59 - 2015-11-30 17:52 - 05194776 _____ C:\Users\New\Downloads\sc16v180.exe
2015-11-27 08:43 - 2015-11-27 09:24 - 00000000 ___HD C:\$WINDOWS.~BT
2015-11-27 08:22 - 2015-11-27 08:22 - 00000000 ____D C:\ESD
2015-11-27 07:56 - 2015-11-27 07:56 - 00000000 ___HD C:\$Windows.~WS
2015-11-27 07:50 - 2015-11-27 07:51 - 07635472 _____ (Microsoft Corporation) C:\Users\New\Downloads\GetWindows10-Web_Default_Attr.exe
2015-11-27 07:17 - 2015-11-27 07:17 - 00000000 __SHD C:\found.000
2015-11-26 09:50 - 2015-11-26 09:50 - 00000000 ____D C:\15af99c3d1380f78e926fe5fd456
2015-11-25 22:08 - 2015-11-25 22:08 - 00000000 ____D C:\Users\New\Documents\Corel DVD MovieFactory
 
==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-06 17:20 - 2015-10-29 22:28 - 00000000 ____D C:\Windows
2015-12-06 14:14 - 2015-10-29 23:21 - 00000000 ____D C:\WINDOWS\INF
2015-12-06 14:11 - 2015-10-29 22:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-12-05 06:07 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-12-04 21:01 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-04 21:00 - 2015-10-29 23:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-04 01:48 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-12-04 01:48 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-12-04 01:46 - 2015-10-29 23:19 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2015-12-04 01:46 - 2015-10-29 23:19 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2015-12-04 01:46 - 2015-10-29 23:19 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2015-12-04 01:46 - 2015-10-29 23:19 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2015-12-04 01:46 - 2015-10-29 23:19 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2015-12-04 01:46 - 2015-10-29 23:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2015-12-04 01:46 - 2015-10-29 23:18 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-12-04 01:46 - 2015-10-29 23:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-12-04 01:46 - 2015-10-29 23:18 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-12-04 01:46 - 2015-10-29 23:18 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-12-04 01:46 - 2015-10-29 23:18 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-12-04 01:46 - 2015-10-29 23:18 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-12-03 17:20 - 2015-10-29 23:24 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-03 03:55 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\rescache
2015-12-03 03:32 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-11-29 05:25 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\appcompat
2015-11-27 21:13 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-11-27 13:58 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-11-27 13:58 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-11-27 13:58 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-27 13:58 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\Provisioning
2015-11-27 13:58 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-11-27 13:58 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-11-27 10:47 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2015-11-27 10:25 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-11-27 10:25 - 2015-10-29 23:24 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-11-27 10:11 - 2015-10-29 23:24 - 00000000 ____D C:\ProgramData\USOPrivate
2015-11-27 10:10 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-11-27 10:10 - 2015-10-29 22:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-11-27 10:09 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\spool
2015-11-27 10:07 - 2015-10-29 23:24 - 00000000 __RHD C:\Users\Public\Libraries
2015-11-27 10:07 - 2009-07-13 23:44 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-11-27 10:06 - 2015-10-29 23:24 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2015-11-27 10:02 - 2015-10-29 22:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-11-27 09:55 - 2015-10-30 01:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2015-11-27 09:54 - 2015-10-29 23:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== BCD ================================

Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=\Device\HarddiskVolume1
description Windows Boot Manager
locale en-US
inherit {globalsettings}
default {current}
resumeobject {4c15d2f4-952f-11e5-a4ed-d97fdceddf51}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 30

Windows Boot Loader
-------------------
identifier {13784cf9-91a8-11e5-90c0-cba8299548af}
device ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{13784cfa-91a8-11e5-90c0-cba8299548af}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {bootloadersettings}
osdevice ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{13784cfa-91a8-11e5-90c0-cba8299548af}
systemroot \windows
nx OptIn
winpe Yes

Windows Boot Loader
-------------------
identifier {current}
device partition=C:
path \WINDOWS\system32\winload.exe
description Windows 10
locale en-US
inherit {bootloadersettings}
recoverysequence {ca5d4806-952f-11e5-a4ed-d97fdceddf51}
recoveryenabled Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \WINDOWS
resumeobject {4c15d2f4-952f-11e5-a4ed-d97fdceddf51}
nx OptIn
pae ForceDisable
bootmenupolicy Standard

Windows Boot Loader
-------------------
identifier {ca5d4806-952f-11e5-a4ed-d97fdceddf51}
device ramdisk=[\Device\HarddiskVolume3]\Recovery\WindowsRE\Winre.wim,{ca5d4807-952f-11e5-a4ed-d97fdceddf51}
path \windows\system32\winload.exe
description Windows Recovery Environment
locale en-US
inherit {bootloadersettings}
displaymessage Recovery
displaymessageoverride Recovery
osdevice ramdisk=[\Device\HarddiskVolume3]\Recovery\WindowsRE\Winre.wim,{ca5d4807-952f-11e5-a4ed-d97fdceddf51}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes

Windows Setup
-------------
identifier {cbd971bf-b7b8-4885-951a-fa03044f5d71}
device ramdisk=[C:]\$WINDOWS.~BT\Sources\SafeOS\winre.wim,{13784cfb-91a8-11e5-90c0-cba8299548af}
path \windows\system32\winload.exe
description Windows Rollback
locale en-US
inherit {bootloadersettings}
osdevice ramdisk=[C:]\$WINDOWS.~BT\Sources\SafeOS\winre.wim,{13784cfb-91a8-11e5-90c0-cba8299548af}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes

Resume from Hibernate
---------------------
identifier {13784cf7-91a8-11e5-90c0-cba8299548af}
device partition=C:
path \windows\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
filedevice partition=C:
filepath \hiberfil.sys
debugoptionenabled No

Resume from Hibernate
---------------------
identifier {4c15d2f4-952f-11e5-a4ed-d97fdceddf51}
device partition=C:
path \WINDOWS\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {ca5d4806-952f-11e5-a4ed-d97fdceddf51}
recoveryenabled Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No

Windows Memory Tester
---------------------
identifier {memdiag}
device partition=\Device\HarddiskVolume1
path \boot\memtest.exe
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes

EMS Settings
------------
identifier {emssettings}
bootems No

Debugger Settings
-----------------
identifier {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200

RAM Defects
-----------
identifier {badmemory}

Global Settings
---------------
identifier {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}

Boot Loader Settings
--------------------
identifier {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}

Hypervisor Settings
-------------------
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200

Resume Loader Settings
----------------------
identifier {resumeloadersettings}
inherit {globalsettings}

Device options
--------------
identifier {13784cfa-91a8-11e5-90c0-cba8299548af}
description Ramdisk Options
ramdisksdidevice partition=\Device\HarddiskVolume1
ramdisksdipath \Recovery\WindowsRE\boot.sdi

Device options
--------------
identifier {13784cfb-91a8-11e5-90c0-cba8299548af}
description Windows Setup
ramdisksdidevice partition=C:
ramdisksdipath \$WINDOWS.~BT\Sources\SafeOS\boot.sdi

Device options
--------------
identifier {ca5d4807-952f-11e5-a4ed-d97fdceddf51}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume3
ramdisksdipath \Recovery\WindowsRE\boot.sdi



LastRegBack: 2015-11-27 09:54

==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
Ran by New (2015-12-06 17:19:04)
Running from C:\Users\New\Downloads
Windows 10 Home (X64) (2015-11-27 18:21:10)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-578399439-2519388439-559220130-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-578399439-2519388439-559220130-503 - Limited - Disabled)
Guest (S-1-5-21-578399439-2519388439-559220130-501 - Limited - Disabled)
New (S-1-5-21-578399439-2519388439-559220130-1000 - Administrator - Enabled) => C:\Users\New
new_2 (S-1-5-21-578399439-2519388439-559220130-1006 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
ELAN Touchpad 11.15.0.18_X64 (HKLM\...\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-578399439-2519388439-559220130-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\New\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)

==================== Restore Points =========================

27-11-2015 10:18:21 Windows Modules Installer
03-12-2015 01:04:03 Windows Update
04-12-2015 01:42:08 Windows Modules Installer

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-29 23:24 - 2015-10-29 23:21 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {AE8F2690-A8B5-433C-A46C-CA9ABE5CA23F} - System32\Tasks\TweakBit\FixMyPC\Start FixMyPC automatic scanning => C:\Program Files (x86)\TweakBit\FixMyPC\FixMyPC.exe <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)
 
Users shortcut scan result (x64) Version:05-12-2015
Ran by New (2015-12-06 17:20:24)
Running from C:\Users\New\Downloads
Boot Mode: Normal

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)





Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk -> C:\Users\New\Documents ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk -> C:\Users\New\Downloads ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk -> C:\Users\New\Music ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk -> C:\Users\New\Pictures ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk -> C:\Users\New\Videos ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk -> C:\Users\New ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk -> C:\Windows\DevicesFlow\DevicesFlow.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk -> C:\Windows\MiracastView\MiracastView.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk -> C:\Windows\PrintDialog\PrintDialog.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk -> C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IIS\IIS Client Manager.lnk -> C:\Windows\System32\inetsrv\InetMgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center\AMD Catalyst Control Center.lnk -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Advanced Micro Devices Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\IIS Manager.lnk -> C:\Windows\System32\inetsrv\InetMgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\New\Videos\CD Drive - Shortcut.lnk -> D:\ (No File)
Shortcut: C:\Users\New\Music\CD Drive - Shortcut.lnk -> D:\ (No File)
Shortcut: C:\Users\New\Music\Pictures - Shortcut.lnk -> C:\Users\New\Pictures ()
Shortcut: C:\Users\New\Links\Desktop.lnk -> C:\Users\New\Desktop ()
Shortcut: C:\Users\New\Links\Downloads.lnk -> C:\Users\New\Downloads ()
Shortcut: C:\Users\New\Desktop\BIOS Launcher.lnk -> C:\sc16v180\launcher.exe (Toshiba America Information Systems, Inc.)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\New\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Windows\SendTo\Bluetooth File Transfer.LNK -> C:\Windows\System32\fsquirt.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc ()
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc ()
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation)
Shortcut: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk -> C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes)




ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> -sta {C90FB8CA-3295-4462-A721-2935E83694BA}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center\Help.lnk -> C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.exe (Advanced Micro Devices Inc.) -> Start Help -help
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
ShortcutWithArgument: C:\Users\New\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0
ShortcutWithArgument: C:\Users\New\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}


InternetURL: C:\Users\New\Favorites\Bing.url -> hxxp://go.microsoft.com/fwlink/p/?LinkId=255142
InternetURL: C:\Users\New\Favorites\How Malware hides and is installed as a Service.url -> hxxp://www.bleepingcomputer.com/tutorials/how-malware-hides-as-a-service/
InternetURL: C:\Users\New\Favorites\KidZui, The Internet for Kids.url -> hxxp://www.kidzui.com/toshiba
InternetURL: C:\Users\New\Favorites\WildTangent Games\WildTangent Games.url -> hxxp://toshiba.wildgames.com/?mc=iefav&dp=toshibaus
InternetURL: C:\Users\New\Favorites\Toshiba\Deals and Offers.url -> hxxp://us.toshiba.com/adps/deals-and-offers
InternetURL: C:\Users\New\Favorites\Toshiba\Explore Toshiba.url -> hxxp://us.toshiba.com/
InternetURL: C:\Users\New\Favorites\Toshiba\Find Us on Twitter, Facebook, and YouTube.url -> hxxp://us.toshiba.com/social-media
InternetURL: C:\Users\New\Favorites\Toshiba\Shop Toshiba.url -> hxxp://www.toshibadirect.com/
InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba App Place.url -> hxxp://apps.toshiba.com/
InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Book Place.url -> hxxp://www.toshibabookplace.com/
InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Corporate Social Responsibility.url -> hxxp://us.toshiba.com/green
InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Laptop Forums.url -> hxxp://laptopforums.toshiba.com/
InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Online Backup.url -> hxxp://us.toshiba.com/online-backup
InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Product Registration.url -> hxxp://toshibaproductregistration.com/
InternetURL: C:\Users\New\Favorites\Toshiba\Toshiba Support.url -> hxxp://pcsupport.toshiba.com/
InternetURL: C:\Users\New\Favorites\Skype\Skype.url -> hxxp://www.skype.com/go/ToshibaTAIS
InternetURL: C:\Users\New\Favorites\Norton Internet Security\Symantec Security Center.url -> hxxp://www.yoursecurityresource.com/exploretoshiba/home.html
InternetURL: C:\Users\New\Favorites\Links for United States\GobiernoUSA.gov.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129792
InternetURL: C:\Users\New\Favorites\Links for United States\USA.gov.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129791
InternetURL: C:\Users\New\Favorites\Links\Stay Secure Online.url -> hxxp://www.yoursecurityresource.com/exploretoshiba/home.html#LatestFeature
InternetURL: C:\Users\New\Favorites\Links\Toshiba App Place.url -> hxxp://apps.toshiba.com/ie8webslice
InternetURL: C:\Users\New\Favorites\Links\WildTangent Games.url -> hxxp://toshiba.wildgames.com/#ie8WebSlice
InternetURL: C:\Users\New\Favorites\eMusic\eMusic.url -> hxxp://www.emusic.com/Toshiba
InternetURL: C:\Users\New\Favorites\Amazon.com\Amazon MP3 – Millions of Music Downloads.url -> hxxp://www.amazon.com/b/?node=163856011&tag=tais2-bookmark-mp3-20
InternetURL: C:\Users\New\Favorites\Amazon.com\Amazon Video On Demand Movies & TV.url -> hxxp://www.amazon.com/b/?node=16261631&tag=tais2-bookmark-vod-20
InternetURL: C:\Users\New\Favorites\Amazon.com\Shop at Amazon.com.url -> hxxp://www.amazon.com/?tag=tais2-desktop-20

==================== End of Shortcut.txt =============================
 
Welcome aboard

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

===============================

Addition.txt log is incomplete.
Please post complete log.
Also when running FRST don't checkmark any extra boxes unless asked to do so.
 
1st run computer bsod (writing on unwritable data)??


this is all ive got, should I run it again?


Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
Ran by New (2015-12-06 17:19:04)
Running from C:\Users\New\Downloads
Windows 10 Home (X64) (2015-11-27 18:21:10)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-578399439-2519388439-559220130-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-578399439-2519388439-559220130-503 - Limited - Disabled)
Guest (S-1-5-21-578399439-2519388439-559220130-501 - Limited - Disabled)
New (S-1-5-21-578399439-2519388439-559220130-1000 - Administrator - Enabled) => C:\Users\New
new_2 (S-1-5-21-578399439-2519388439-559220130-1006 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
ELAN Touchpad 11.15.0.18_X64 (HKLM\...\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-578399439-2519388439-559220130-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\New\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\FileCoAuth.exe (Microsoft Corporation)

==================== Restore Points =========================

27-11-2015 10:18:21 Windows Modules Installer
03-12-2015 01:04:03 Windows Update
04-12-2015 01:42:08 Windows Modules Installer

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-29 23:24 - 2015-10-29 23:21 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {AE8F2690-A8B5-433C-A46C-CA9ABE5CA23F} - System32\Tasks\TweakBit\FixMyPC\Start FixMyPC automatic scanning => C:\Program Files (x86)\TweakBit\FixMyPC\FixMyPC.exe <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)
 
Broni,also this computer has been dead for like 2 years I fixed a power cord issue so any emtry before november 20th 2015 is fabricated and I never ever ran fsrt before today
 
1icspe.jpg


this is why I'm here, my activation is not genuine anymore either, I don't even know if the iso.s from Microsoft are legitimately burning or if somethings editing them, I have 2 other comps in a bad way too. see, I give ms my coas and to dl 7.1 but.... I mean 1 even has C:\usr dir I cant access that survives formats with dban followed by a real vista businessx32 dell vista oem dvd install.... call me crazy.... and top it all off my google identifies a mac console and sunsystems os login so I dare not connect my phone to this chaos anymore sry just I'm sry
 
I don't see anything malicious there. It'd be quite strange after fresh installation anyway.
I'd suggest new topic in Windows forum.
 
Ok so toshi didn't get the nasty from dell, or lenny....by way of usb thumb drive, heres my dell, my favorite, sir.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-12-2015
Ran by Subrectre (administrator) on WIN-GZ7SM9CILQR (14-02-2015 19:45:23)
Running from E:\
Loaded Profiles: Subrectre & Trusted Ibstallers (Available Profiles: Subrectre & ReadWrite & Trusted Ibstallers)
Platform: Microsoft® Windows Vista™ Business Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 7 (Default browser: IE)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(Microsoft Corporation) C:\Windows\System32\userinit.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe
HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
HKLM\...\Run: [NVHotkey] => rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [488816 2011-01-04] (Alps Electric Co., Ltd.)
HKU\S-1-5-21-444405077-440011167-3635889434-1002\...\Run: [CollaborationHost] => C:\Windows\system32\p2phost.exe [192000 2008-01-21] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell System Manager.lnk [2015-02-12]
ShortcutTarget: Dell System Manager.lnk -> C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe (Dell Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)


Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 alssvc; C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe [382232 2008-06-03] (Dell Inc.)
S2 ASFAgent; C:\Program Files\Intel\ASF Agent\ASFAgent.exe [133968 2007-04-19] (Intel Corporation)
S2 dcpsysmgrsvc; C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe [390000 2011-07-28] (Dell Inc.)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [94936 2015-02-14] (Malwarebytes) [File not signed]
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes) [File not signed]
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2015-02-14] (Malwarebytes) [File not signed]
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation) [File not signed]
S1 AFD; \SystemRoot\system32\drivers\afd.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NAL; \??\C:\Windows\system32\Drivers\iqvw32.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 STHDA; system32\DRIVERS\stwrt.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-02-14 19:44 - 2015-02-14 19:44 - 00156688 _____ C:\Windows\Minidump\Mini021415-05.dmp
2015-02-14 19:43 - 2015-02-14 19:45 - 00000000 ____D C:\FRST
2015-02-14 18:43 - 2015-02-14 18:43 - 00156688 _____ C:\Windows\Minidump\Mini021415-04.dmp
2015-02-14 18:26 - 2015-02-14 18:26 - 00000000 ____D C:\Users\Trusted Ibstallers\.android
2015-02-14 18:25 - 2015-02-14 18:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZTE Handset USB Driver
2015-02-14 18:25 - 2015-02-14 18:25 - 00000000 ____D C:\Program Files\ZTE_Handset_USB_Driver
2015-02-14 18:25 - 2014-03-17 09:59 - 00117960 _____ (ZTE Corporation) C:\Windows\system32\Drivers\zghsser.sys
2015-02-14 18:25 - 2013-09-11 14:28 - 00149696 _____ (ZTE Corporation) C:\Windows\system32\Drivers\zghsnet.sys
2015-02-14 18:25 - 2013-03-19 16:38 - 00821544 _____ C:\Windows\adb.exe
2015-02-14 18:25 - 2012-11-09 15:12 - 00053000 _____ (VIA Telecom) C:\Windows\system32\Drivers\viahsser.sys
2015-02-14 18:25 - 2012-10-31 16:02 - 00027016 _____ (Via Telecom, Inc.) C:\Windows\system32\Drivers\viahsets.sys
2015-02-14 18:25 - 2012-06-20 11:51 - 00017672 _____ (HandSet Incorporated) C:\Windows\system32\Drivers\massfilter_hs.sys
2015-02-14 18:25 - 2012-04-28 15:59 - 00851176 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll
2015-02-14 18:25 - 2011-10-26 15:31 - 00067608 _____ (Google, inc) C:\Windows\AdbWinUsbApi.dll
2015-02-14 18:25 - 2011-08-15 16:43 - 00102936 _____ (Google, inc) C:\Windows\AdbWinApi.dll
2015-02-14 18:10 - 2015-02-14 18:11 - 00156688 _____ C:\Windows\Minidump\Mini021415-03.dmp
2015-02-14 18:05 - 2015-02-14 18:05 - 00156688 _____ C:\Windows\Minidump\Mini021415-02.dmp
2015-02-14 18:02 - 2015-02-14 18:02 - 00000949 _____ C:\Users\Trusted Ibstallers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-14 18:02 - 2015-02-14 18:02 - 00000944 _____ C:\Users\Trusted Ibstallers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-02-14 18:02 - 2015-02-14 18:02 - 00000915 _____ C:\Users\Trusted Ibstallers\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-02-14 05:37 - 2015-02-14 18:26 - 00000000 ____D C:\Users\Trusted Ibstallers
2015-02-14 05:37 - 2015-02-14 05:37 - 00000020 ___SH C:\Users\Trusted Ibstallers\ntuser.ini
2015-02-14 05:37 - 2015-02-14 05:37 - 00000000 _SHDL C:\Users\Trusted Ibstallers\My Documents
2015-02-14 05:37 - 2015-02-14 05:37 - 00000000 _SHDL C:\Users\Trusted Ibstallers\Documents\My Videos
2015-02-14 05:37 - 2015-02-14 05:37 - 00000000 _SHDL C:\Users\Trusted Ibstallers\Documents\My Pictures
2015-02-14 05:37 - 2015-02-14 05:37 - 00000000 _SHDL C:\Users\Trusted Ibstallers\Documents\My Music
2015-02-14 05:22 - 2015-02-14 19:44 - 00000000 ____D C:\Windows\Minidump
2015-02-14 05:22 - 2015-02-14 05:22 - 00156688 _____ C:\Windows\Minidump\Mini021415-01.dmp
2015-02-14 05:21 - 2015-02-14 19:45 - 01156328 _____ C:\Windows\ntbtlog.txt
2015-02-14 05:21 - 2015-02-14 19:44 - 197665415 _____ C:\Windows\MEMORY.DMP
2015-02-14 04:57 - 2015-02-14 04:57 - 00000043 _____ C:\Users\Subrectre\Documents\kj.reg
2015-02-14 04:16 - 2015-02-14 04:23 - 00000000 ___RD C:\Users\ReadWrite\Documents\Notes
2015-02-14 04:14 - 2015-02-14 04:14 - 00001404 _____ C:\Users\ReadWrite\Desktop\WIN-GZ7SM9CILQR - Shortcut.lnk
2015-02-14 04:11 - 2015-02-14 04:15 - 00000000 ____D C:\Users\ReadWrite
2015-02-14 04:11 - 2015-02-14 04:11 - 00000020 ___SH C:\Users\ReadWrite\ntuser.ini
2015-02-14 04:11 - 2015-02-14 04:11 - 00000000 _SHDL C:\Users\ReadWrite\My Documents
2015-02-14 04:11 - 2015-02-14 04:11 - 00000000 _SHDL C:\Users\ReadWrite\Documents\My Videos
2015-02-14 04:11 - 2015-02-14 04:11 - 00000000 _SHDL C:\Users\ReadWrite\Documents\My Pictures
2015-02-14 04:11 - 2015-02-14 04:11 - 00000000 _SHDL C:\Users\ReadWrite\Documents\My Music
2015-02-14 03:55 - 2015-02-14 03:55 - 00001846 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Collaboration.lnk
2015-02-14 03:55 - 2015-02-14 03:55 - 00001583 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2015-02-14 03:54 - 2015-02-14 05:16 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Windows\system32\XPSViewer
2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Windows\addins
2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Program Files\Windows Collaboration
2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-02-14 03:54 - 2015-02-14 03:54 - 00000000 ____D C:\Program Files\MSBuild
2015-02-14 03:39 - 2015-02-14 03:39 - 00000000 ____D C:\Users\Subrectre\AppData\Roaming\PeerNetworking
2015-02-14 03:34 - 2015-02-14 18:01 - 00000000 ____D C:\Windows\pss
2015-02-14 03:08 - 2015-02-14 04:16 - 00000000 ___RD C:\Users\Subrectre\Documents\Scanned Documents
2015-02-14 03:08 - 2015-02-14 03:08 - 00000000 ____D C:\Users\Subrectre\Documents\Fax
2015-02-14 03:05 - 2015-02-14 03:05 - 00000000 ___RD C:\Users\Subrectre\Documents\Notes
2015-02-14 02:42 - 2015-02-14 02:42 - 00000000 ____D C:\Users\Subrectre\Documents\New Folder
2015-02-14 02:38 - 2015-02-14 02:38 - 00000000 ____D C:\Program Files\Intel
2015-02-13 22:44 - 2015-02-13 22:44 - 00000177 _____ C:\Users\Subrectre\Documents\ll.reg
2015-02-13 22:36 - 2015-02-13 22:36 - 00000932 _____ C:\Users\Subrectre\Documents\jjjj.reg
2015-02-13 10:22 - 2011-03-23 16:05 - 00223432 _____ (Intel Corporation) C:\Windows\system32\Drivers\e1y6032.sys
2015-02-13 10:22 - 2009-10-11 00:26 - 00062144 _____ (Intel Corporation) C:\Windows\system32\NicInstY.dll
2015-02-13 10:22 - 2008-11-12 16:26 - 00002823 _____ C:\Windows\system32\e1y6032.din
2015-02-13 10:22 - 2007-12-14 13:06 - 00121440 _____ (Intel Corporation) C:\Windows\system32\e1000msg.dll
2015-02-13 10:22 - 2007-08-24 08:58 - 00028272 _____ (Intel Corporation) C:\Windows\system32\NicCo26.dll
2015-02-13 10:22 - 2006-01-12 14:52 - 00001904 _____ C:\Windows\system32\SetupBD.din
2015-02-13 01:38 - 2015-02-14 19:39 - 00000426 ____H C:\Windows\Tasks\User_Feed_Synchronization-{D5C48341-D683-4789-A507-74F24917F7B5}.job
2015-02-12 17:46 - 2015-02-14 19:39 - 00120881 _____ C:\ProgramData\nvModes.dat
2015-02-12 17:46 - 2015-02-14 19:39 - 00120881 _____ C:\ProgramData\nvModes.001
2015-02-12 17:45 - 2015-02-12 17:46 - 00000000 ____D C:\ProgramData\NVIDIA
2015-02-12 17:43 - 2015-02-12 17:43 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2015-02-12 17:43 - 2015-02-12 17:43 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf
2015-02-12 17:43 - 2015-02-12 17:43 - 00000000 ____D C:\Windows\nview
2015-02-12 17:43 - 2010-11-19 10:44 - 10676840 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 09936392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-02-12 17:43 - 2010-11-19 10:44 - 07728744 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 03220584 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 01749096 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 01325672 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 01070184 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 00795104 _____ (Microsoft Corporation) C:\Windows\system32\dpinst.exe
2015-02-12 17:43 - 2010-11-19 10:44 - 00678504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 00600680 _____ (NVIDIA Corporation) C:\Windows\system32\nvuninst.exe
2015-02-12 17:43 - 2010-11-19 10:44 - 00600680 _____ (NVIDIA Corporation) C:\Windows\system32\nvudisp.exe
2015-02-12 17:43 - 2010-11-19 10:44 - 00262248 _____ C:\Windows\system32\nViewSetup.exe
2015-02-12 17:43 - 2010-11-19 10:44 - 00227944 _____ (NVIDIA Corporation) C:\Windows\system32\nvcod1919.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 00227944 _____ (NVIDIA Corporation) C:\Windows\system32\nvcod.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 00206952 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshim.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 00068712 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll
2015-02-12 17:43 - 2010-11-19 10:44 - 00023929 _____ C:\Windows\system32\nvdisp.nvu
2015-02-12 17:43 - 2010-11-19 10:44 - 00010984 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvBridge.kmd
2015-02-12 17:43 - 2010-05-06 01:59 - 00330344 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSPT.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00326248 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSPTB.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00326248 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSNL.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00322152 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSRU.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00309864 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSTR.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00309864 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSSL.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00305768 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSSK.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00305768 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSNO.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00301672 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSSV.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00301672 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSPL.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00297576 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSTH.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00203368 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSKO.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00174696 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSZHT.dll
2015-02-12 17:43 - 2010-05-06 01:59 - 00170600 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSZHC.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 01731176 _____ C:\Windows\system32\nvwdmcpl.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 01657448 _____ C:\Windows\system32\nwiz.exe
2015-02-12 17:43 - 2010-05-06 01:58 - 01612392 _____ C:\Windows\system32\nView.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 01108584 _____ C:\Windows\system32\nvwimg.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00473704 _____ C:\Windows\system32\nvShell.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00342632 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSES.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00342632 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSEL.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00334440 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSFR.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00334440 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSESM.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00330344 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSIT.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00322152 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSHU.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00318056 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSDE.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00309864 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSFI.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00301672 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSDA.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00293480 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSENU.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00293480 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSENG.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00293480 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSCS.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00289384 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSAR.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00285288 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSHE.dll
2015-02-12 17:43 - 2010-05-06 01:58 - 00267368 _____ C:\Windows\system32\nvTaskbar.exe
2015-02-12 17:43 - 2010-05-06 01:58 - 00219752 _____ (NVIDIA Corporation) C:\Windows\system32\NVWRSJA.dll
2015-02-12 17:43 - 2010-05-06 01:57 - 00449128 _____ C:\Windows\system32\nvAppBar.exe
2015-02-12 17:42 - 2015-02-12 17:42 - 00000000 ____D C:\Program Files\NetWaiting
2015-02-12 17:42 - 2015-02-12 17:42 - 00000000 ____D C:\Program Files\DellTPad
2015-02-12 17:42 - 2011-01-05 20:42 - 00284792 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Drivers\Apfiltr.sys
2015-02-12 17:42 - 2010-12-17 02:52 - 00115640 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Vxdif.dll
2015-02-12 17:42 - 2009-07-13 21:27 - 01461992 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2015-02-12 17:17 - 2011-01-28 11:19 - 00266440 _____ (Intel Corporation) C:\Windows\system32\PROUnstl.exe
2015-02-12 17:16 - 2015-02-12 17:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetWaiting
2015-02-12 17:14 - 2015-02-12 17:14 - 00000000 ____D C:\Program Files\CONEXANT
2015-02-12 17:14 - 2008-07-30 01:26 - 00249856 _____ (Conexant Systems, Inc.) C:\Windows\system32\UCI32M34.dll
2015-02-12 17:14 - 2008-06-24 20:25 - 00980992 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\HSX_DPV.sys
2015-02-12 17:14 - 2008-06-24 20:23 - 00208384 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\HSXHWAZL.sys
2015-02-12 17:14 - 2008-06-24 20:22 - 00661504 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\HSX_CNXT.sys
2015-02-12 17:14 - 2008-03-26 20:33 - 00146146 _____ C:\Windows\system32\Drivers\del1028.cty
2015-02-12 17:14 - 2007-10-16 16:37 - 00386560 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\XAudio.exe
2015-02-12 17:14 - 2007-10-16 16:36 - 00008704 _____ (Conexant Systems, Inc.) C:\Windows\system32\Drivers\XAudio.sys
2015-02-12 17:14 - 2006-06-17 15:26 - 00094208 _____ (Conexant) C:\Windows\system32\mdmxsdk.dll
2015-02-12 17:14 - 2006-06-17 15:26 - 00012672 _____ (Conexant) C:\Windows\system32\Drivers\mdmxsdk.sys
2015-02-12 17:13 - 2015-02-12 17:16 - 00000000 ____D C:\Program Files\Dell
2015-02-12 17:13 - 2015-02-12 17:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell System Manager
2015-02-12 17:12 - 2015-02-12 17:12 - 00000000 ____D C:\ProgramData\Dell
2015-02-12 04:24 - 2015-02-12 04:24 - 00008192 ___RS C:\BOOTSECT.BAK
2015-02-12 04:24 - 2015-02-11 20:31 - 00000000 ____D C:\Windows\Panther
2015-02-12 04:24 - 2008-01-21 02:25 - 00333203 __RSH C:\bootmgr
2015-02-12 04:22 - 2008-05-09 21:10 - 00000021 ___RH C:\Windows\dell_version
2015-02-11 23:31 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-11 23:31 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-02-11 23:31 - 2015-02-14 05:20 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-11 23:31 - 2015-02-14 05:20 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-11 23:31 - 2015-02-14 05:16 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-02-11 23:31 - 2015-02-11 23:31 - 00000899 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-11 23:31 - 2015-02-11 23:31 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-02-11 20:46 - 2015-02-11 20:46 - 00000000 ____D C:\Intel
2015-02-11 20:45 - 2015-02-14 02:33 - 00000000 ____D C:\Program Files\IDT
2015-02-11 20:45 - 2015-02-12 17:16 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-02-11 20:45 - 2015-02-11 20:45 - 00000000 ____D C:\Windows\system32\SRSLabs
2015-02-11 20:45 - 2010-04-05 07:56 - 00945664 _____ (IDT, Inc.) C:\Windows\system32\stapo.tmp
2015-02-11 20:45 - 2010-04-05 07:54 - 00140288 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTACap.tmp
2015-02-11 20:45 - 2010-04-05 07:54 - 00086016 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTCom.dll
2015-02-11 20:45 - 2010-04-05 07:54 - 00061440 _____ (Andrea Electronics Corporation) C:\Windows\system32\AESTARen.tmp
2015-02-11 20:44 - 2009-09-02 06:13 - 00131072 _____ (Dell, Inc.) C:\Windows\system32\DellSPMsg.dll
2015-02-11 20:40 - 2015-02-11 20:40 - 00000000 __RSH C:\MSDOS.SYS
2015-02-11 20:40 - 2015-02-11 20:40 - 00000000 __RSH C:\IO.SYS
2015-02-11 20:39 - 2015-02-11 20:44 - 00000000 ____D C:\Dell
2015-02-11 20:39 - 2015-02-11 20:39 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_00_00.Wdf
2015-02-11 20:36 - 2015-02-11 20:36 - 00000949 _____ C:\Users\Subrectre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-11 20:36 - 2015-02-11 20:36 - 00000944 _____ C:\Users\Subrectre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-02-11 20:36 - 2015-02-11 20:36 - 00000915 _____ C:\Users\Subrectre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
2015-02-11 20:35 - 2015-02-14 03:41 - 00000000 ____D C:\Users\Subrectre
2015-02-11 20:35 - 2015-02-11 20:35 - 00000020 ___SH C:\Users\Subrectre\ntuser.ini
2015-02-11 20:35 - 2015-02-11 20:35 - 00000000 _SHDL C:\Users\Subrectre\My Documents
2015-02-11 20:35 - 2015-02-11 20:35 - 00000000 _SHDL C:\Users\Subrectre\Documents\My Videos
2015-02-11 20:35 - 2015-02-11 20:35 - 00000000 _SHDL C:\Users\Subrectre\Documents\My Pictures
2015-02-11 20:35 - 2015-02-11 20:35 - 00000000 _SHDL C:\Users\Subrectre\Documents\My Music
2015-02-11 20:26 - 2015-02-11 20:26 - 00000000 ____D C:\Windows\CSC

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-02-14 19:44 - 2006-11-02 12:47 - 00064512 _____ C:\Windows\system32\umstartup.etl
2015-02-14 19:44 - 2006-11-02 11:18 - 00000000 ____D C:\Windows
2015-02-14 19:43 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\inf
2015-02-14 19:43 - 2006-11-02 10:33 - 00690960 _____ C:\Windows\system32\PerfStringBackup.INI
2015-02-14 19:38 - 2006-11-02 13:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-02-14 19:38 - 2006-11-02 12:47 - 00039936 _____ C:\Windows\system32\umstartup000.etl
2015-02-14 19:38 - 2006-11-02 12:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-14 19:38 - 2006-11-02 12:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-14 18:01 - 2006-11-02 13:01 - 00008084 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-14 05:22 - 2006-11-02 12:47 - 00228720 _____ C:\Windows\system32\FNTCACHE.DAT
2015-02-14 04:10 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\rescache
2015-02-14 03:54 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\system32\setup
2015-02-14 03:08 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\ModemLogs
2015-02-14 02:52 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\Registration
2015-02-12 17:44 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\Help
2015-02-12 17:19 - 2006-11-02 11:18 - 00000000 ____D C:\Windows\system32\NDF
2015-02-12 04:24 - 2006-11-02 12:37 - 00262144 _____ C:\Windows\system32\config\BCD-Template

==================== Files in the root of some directories =======

2015-02-14 03:39 - 2015-02-14 03:40 - 0029239 _____ () C:\Users\Subrectre\AppData\Roaming\UserTile.png
2015-02-11 20:35 - 2015-02-11 20:53 - 0000680 _____ () C:\Users\Subrectre\AppData\Local\d3d9caps.dat
2015-02-14 02:43 - 2015-02-14 02:43 - 0004608 _____ () C:\Users\Subrectre\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-02-12 17:46 - 2015-02-14 19:39 - 0120881 _____ () C:\ProgramData\nvModes.001
2015-02-12 17:46 - 2015-02-14 19:39 - 0120881 _____ () C:\ProgramData\nvModes.dat

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-14 19:01

==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version:05-12-2015
Ran by Subrectre (2015-02-14 19:45:43)
Running from E:\
Microsoft® Windows Vista™ Business Service Pack 1 (X86) (2015-02-11 20:30:25)
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-444405077-440011167-3635889434-500 - Administrator - Disabled)
Guest (S-1-5-21-444405077-440011167-3635889434-501 - Limited - Enabled)
ReadWrite (S-1-5-21-444405077-440011167-3635889434-1001 - Limited - Enabled) => C:\Users\ReadWrite
Subrectre (S-1-5-21-444405077-440011167-3635889434-1000 - Administrator - Enabled) => C:\Users\Subrectre
Trusted Ibstallers (S-1-5-21-444405077-440011167-3635889434-1002 - Administrator - Enabled) => C:\Users\Trusted Ibstallers

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Ambient Light Sensor (HKLM\...\{5AF4F4C5-C71C-418F-B0B1-3903A345BD71}) (Version: 1.0.7 - Dell Inc.)
Conexant HDA D330 MDC V.92 Modem (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F) (Version: 7.75.00.51 - Conexant)
Dell System Manager (HKLM\...\{3EC64C00-4BBC-4C0A-9F95-40E3EDA72837}) (Version: 1.7.10000 - Dell Inc.)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1207.101.108 - ALPS ELECTRIC CO., LTD.)
IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6274.0 - IDT)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.1 - Intel)
Intel(R) PRO Alerting Agent (HKLM\...\{6EA8A52B-8EA1-4A59-85AB-48132299061A}) (Version: 12.0.3 - Intel Corporation)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
NetWaiting (HKLM\...\{3F92ABBB-6BBF-11D5-B229-002078017FBF}) (Version: 2.5.53 - BVRP Software, Inc)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.61.39 - NVIDIA Corporation)
NVIDIA nView Desktop Manager (HKLM\...\NVIDIA nView Desktop Manager) (Version: 6.14.10.12154 - NVIDIA Corporation)
RICOH Media Driver ver.2.07.01.01 (HKLM\...\{2B818257-E6C7-4841-8C29-C5C9A982BCE5}) (Version: 2.07.01.01 - RICOH)
ZTE Handset USB Driver (HKLM\...\{01D42BF0-ED08-463f-8A28-99EB6FEE962B}) (Version: - ZTE Corporation)
ZTE Handset USB Driver (HKLM\...\{D2D77DC2-8299-11D1-8949-444553540000}_is1) (Version: 5.2104.1.02B04 - ZTE Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

11-02-2015 20:45:10 Device Driver Package Install: IDT Sound, video and game controllers
11-02-2015 20:45:38 Installed IDT Audio
11-02-2015 20:46:46 Installed RICOH Media Driver ver.2.07.01.01
11-02-2015 20:46:52 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
11-02-2015 20:47:08 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
11-02-2015 20:47:22 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
11-02-2015 20:47:38 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
11-02-2015 20:47:51 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
11-02-2015 20:48:05 Device Driver Package Install: Ricoh Company IDE ATA/ATAPI controllers
12-02-2015 14:22:19 Scheduled Checkpoint
12-02-2015 17:13:00 Installed Dell System Manager.
12-02-2015 17:14:19 Device Driver Package Install: Conexant Modems
12-02-2015 17:15:42 Installed NetWaiting
12-02-2015 17:15:56 Installed NetWaiting
12-02-2015 17:16:40 Installed Ambient Light Sensor.
12-02-2015 17:17:34 Installed Intel(R) Network Connections.
12-02-2015 17:42:06 Installed NetWaiting
12-02-2015 17:42:17 Installed NetWaiting
12-02-2015 17:42:38 Device Driver Package Install: Alps Mice and other pointing devices
13-02-2015 10:22:21 Device Driver Package Install: Intel Network adapters
14-02-2015 03:45:47 Windows Modules Installer

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 10:23 - 2006-09-18 21:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0D5045B3-A82F-4293-8529-AE3E787D00B5} - System32\Tasks\{858C497E-D077-4BD1-8E6E-1420A6C79753} => pcalua.exe -a E:\vista32\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE.exe -d E:\vista32
Task: {251DDF51-D3D8-47C0-830D-CE9632A1A58D} - System32\Tasks\{9B870F81-7915-47AF-A64E-3C96FFC1F362} => pcalua.exe -a C:\Windows\system32\AlertApp.cpl -c Intel(R) ASF Agent Console
Task: {2DB651F6-52E2-4C4B-A106-201DDDA36D54} - System32\Tasks\{A9C0BCDC-2084-4F6B-8526-3FA375191D1A} => pcalua.exe -a E:\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE.exe -d E:\
Task: {4D72741E-769C-45DB-8604-CB8EBDADAA29} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {4F8E5E12-4AB7-487A-9AF8-A6AE9CBCF11C} - System32\Tasks\{1B339E34-6073-4019-9189-802EA4A757B2} => pcalua.exe -a E:\CONEXANT_D330-HDA-MDC_JF0K3_A01_SETUP_ZPE.exe -d E:\
Task: {CB6508EC-C43C-4C51-84CA-A6367ED7932B} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)
Task: {E73100E3-19C7-46B2-B7BE-9AD188531CF4} - System32\Tasks\{865EEE86-F6E1-4285-AC2C-879C64C92A65} => pcalua.exe -a "E:\CONEXANT_D330-HDA-MDC_XG81H_A05_SETUP_ZPE (1).exe" -d E:\

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\User_Feed_Synchronization-{D5C48341-D683-4789-A507-74F24917F7B5}.job => C:\Windows\system32\msfeedssync.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============


==================== Alternate Data Streams (Whitelisted) =========

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-444405077-440011167-3635889434-1000\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\Wallpaper\img23.jpg
HKU\S-1-5-21-444405077-440011167-3635889434-1002\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SLSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\slsvc.exe
FirewallRules: [SLSVC-In-TCP] => (Allow) %SystemRoot%\system32\slsvc.exe
FirewallRules: [TCP Query User{9B73C88C-C823-431D-B0B0-6358C934A283}C:\windows\system32\wfs.exe] => (Allow) C:\windows\system32\wfs.exe
FirewallRules: [UDP Query User{6E0EDADE-89EA-4EC8-81BF-DF4E6BD37BEF}C:\windows\system32\wfs.exe] => (Allow) C:\windows\system32\wfs.exe
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe

==================== Faulty Device Manager Devices =============

Name: Broadcom USH
Description: Broadcom USH
Class Guid:
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: IDT High Definition Audio CODEC
Description: IDT High Definition Audio CODEC
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: IDT
Service: STHDA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Network Controller
Description: Network Controller
Class Guid:
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name:
Description:
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer:
Service: i8042prt
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: SM Bus Controller
Description: SM Bus Controller
Class Guid:
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/14/2015 07:45:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/14/2015 07:45:09 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: d:\rtm\com\complus\src\events\tier1\eventsystemobj.cpp458007043c

Error: (02/14/2015 07:44:54 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: d:\rtm\com\complus\src\events\tier1\eventsystemobj.cpp458007043c

Error: (02/14/2015 07:39:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/14/2015 06:45:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/14/2015 06:28:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/14/2015 06:25:59 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point on volume (Process = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Trusted Ibstallers\{fdbc1eea-d2c6-4f42-891c-073ad12fab99}\zghsser.inf" "0" "6f7356acf" "00000420" "WinSta0\Default" "00000274" "208" "C:\Program Files\ZTE_Handset_USB_Driver\Drivers"; Descripton = Device Driver Package Install: ZTE Corporation Ports (COM & LPT); Hr = 0x8007043c).

Error: (02/14/2015 06:25:59 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point on volume (Process = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Trusted Ibstallers\{d9e1478a-6af4-4267-a519-4f1a037fa6e6}\zghsrndis.inf" "0" "6f731b1ab" "00000530" "WinSta0\Default" "00000420" "208" "C:\Program Files\ZTE_Handset_USB_Driver\Drivers"; Descripton = Device Driver Package Install: ZTE Corporation Network adapters; Hr = 0x8007043c).

Error: (02/14/2015 06:25:58 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point on volume (Process = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Trusted Ibstallers\{0a6a90fd-ae19-4d9d-899e-182431f64816}\zghsnet.inf" "0" "66d4b695b" "000002F0" "WinSta0\Default" "00000530" "208" "C:\Program Files\ZTE_Handset_USB_Driver\Drivers"; Descripton = Device Driver Package Install: ZTE Corporation Network adapters; Hr = 0x8007043c).

Error: (02/14/2015 06:25:58 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point on volume (Process = C:\Windows\system32\DrvInst.exe "4" "0" "C:\Users\Trusted Ibstallers\{be0da2cd-4f0d-49de-baf9-6c0d2174f3c8}\zghsmtp.inf" "0" "6b1181f67" "00000274" "WinSta0\Default" "000002F0" "208" "C:\Program Files\ZTE_Handset_USB_Driver\Drivers"; Descripton = Device Driver Package Install: ZTE Corporation Portable Devices; Hr = 0x8007043c).


System errors:
=============
Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: WinHTTP Web Proxy Auto-Discovery ServiceDHCP Client%%1068

Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: DHCP ClientAncilliary Function Driver for Winsock%%2

Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Ancilliary Function Driver for Winsock%%2

Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: AFD
spldr
Wanarpv6

Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: IPsec Policy Agent%%10050

Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: IKE and AuthIP IPsec Keying Modules%%13876

Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Computer BrowserServer%%1068

Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: TCP/IP NetBIOS HelperAncilliary Function Driver for Winsock%%31

Error: (02/14/2015 07:45:51 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: DHCP ClientAncilliary Function Driver for Winsock%%31

Error: (02/14/2015 07:45:09 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}


CodeIntegrity:
===================================
Date: 2015-02-14 19:45:40.516
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:40.501
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:40.485
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:40.470
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:40.360
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:40.345
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:40.345
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:40.329
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:30.080
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.

Date: 2015-02-14 19:45:30.049
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz
Percentage of memory in use: 12%
Total physical RAM: 3571.19 MB
Available physical RAM: 3126.8 MB
Total Virtual: 7325.4 MB
Available Virtual: 7025.58 MB

==================== Drives ================================

Drive c: (/) (Fixed) (Total:298.09 GB) (Free:278.29 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (VISTA_SP1_BUSINESS) (CDROM) (Total:3.01 GB) (Free:0 GB) UDF
Drive e: () (Removable) (Total:29.8 GB) (Free:23.61 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298.1 GB) (Disk ID: 27D027CF)
Partition 1: (Active) - (Size=298.1 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 29.8 GB) (Disk ID: 3C393DA6)
Partition 1: (Active) - (Size=29.8 GB) - (Type=0C)

==================== End of Addition.txt ============================
 
I don't see anything malicious there. It'd be quite strange after fresh installation anyway.
I'd suggest new topic in Windows forum.
 
Back