... and the next one:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-09-2014
Ran by Mike Bailey (administrator) on WILLIAMBAILEY on 18-09-2014 17:27:26
Running from C:\Users\Mike Bailey.WilliamBailey\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe
() C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe
(Nalpeiron Ltd.) C:\Windows\System32\NLSSRV32.EXE
() C:\Program Files\Generic\Network Printer Wizard\NPWService.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dropbox, Inc.) C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\System Update\SUService.exe
(Lenovo Group Limited) C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7612960 2009-07-10] (Realtek Semiconductor)
HKLM\...\Run: [TPHOTKEY] => C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [68976 2009-03-13] (Lenovo Group Limited)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-08-07] (Intel Corporation)
HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [337184 2009-07-09] (Lenovo.)
HKLM\...\Run: [Message Center Plus] => C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe [49976 2009-05-28] ()
HKLM\...\Run: [RoxWatchTray] => C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe [244208 2009-08-05] (Sonic Solutions)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [995184 2013-07-18] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://uk.msn.com/?ocid=oa-skypegb-2014-MSNO&O
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/welcome/thinkpad
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
https://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Winsock: Catalog5 08 C:\Program Files\Generic\Network Printer Wizard\NPWprint.DLL [151552] (Elite Silicon Technology Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF ProfilePath: C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Mozilla\Firefox\Profiles\wk2k96mn.default
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin: @Citrix.com/npican -> C:\Program Files\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @citrixonline.com/appdetectorplugin -> C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin -> C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin -> C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazon-en-GB.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\chambers-en-GB.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-en-GB.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-en-GB.xml
FF HKLM\...\Firefox\Extensions: [
bkmrksync@nokia.com] - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync
FF Extension: PC Sync 2 Synchronisation Extension - C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync [2013-10-28]
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.google.com/
CHR StartupUrls: Default -> "hxxp://
www.google.com/"
CHR CustomProfile: C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Awesome Screenshot: Capture & Annotate) - C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce [2013-10-10]
CHR Extension: (Google Docs) - C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-08]
CHR Extension: (Google Drive) - C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-08]
CHR Extension: (YouTube) - C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-08]
CHR Extension: (Google Search) - C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-08]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2013-10-10]
CHR Extension: (Google Wallet) - C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-08]
CHR Extension: (Gmail) - C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-08]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION) [File not signed]
R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION) [File not signed]
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-03-13] (Hewlett-Packard Co.) [File not signed]
R2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [45424 2009-07-03] (Lenovo Group Limited)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2013-07-18] (Microsoft Corporation)
S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [45408 2008-11-25] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [295376 2013-07-18] (Microsoft Corporation)
R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9.exe [197128 2014-08-01] (Nitro PDF Software)
R2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [392712 2014-08-01] ()
R2 NPWService; C:\Program Files\Generic\Network Printer Wizard\NPWService.exe [462848 2009-02-05] () [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
S3 Roxio UPnP Renderer 10; C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [313840 2009-08-05] (Sonic Solutions)
S2 Roxio Upnp Server 10; C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe [362992 2009-08-05] (Sonic Solutions)
S2 RoxLiveShare10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [309744 2009-08-05] (Sonic Solutions)
R2 SUService; c:\Program Files\Lenovo\System Update\SUService.exe [15872 2009-09-04] (Lenovo Group Limited) [File not signed]
R2 ThinkVantage Registry Monitor Service; C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe [1019904 2009-08-28] (Lenovo Group Limited) [File not signed]
S3 TVT Backup Service; C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe [1474560 2009-09-04] (Lenovo Group Limited) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 EST_Server; C:\Windows\System32\DRIVERS\GenHC.sys [173056 2009-10-06] ( ) [File not signed]
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [42592 2014-07-06] (
http://libusb-win32.sourceforge.net)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [211560 2013-06-18] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MIKEBA~1.WIL\AppData\Local\Temp\catchme.sys [X]
S3 EST_BusEnum; system32\DRIVERS\GenBus.sys [X]
S1 MpKsla730720c; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{86E64500-17EE-42C8-A044-191E8BBD78C5}\MpKsla730720c.sys [X]
S3 PCDSRVC{3037D694-FD904ACA-06000000}_0; \??\c:\program files\pc-doctor\pcdsrvc.pkms [X]
S3 PCDSRVC{C4B36920-79E24793-06000000}_0; \??\c:\progra~1\pc-doc~1\pcdsrvc.pkms [X]
U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSBXP.SYS [49408 2013-11-22] (Seiko Epson Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-18 17:27 - 2014-09-18 17:28 - 00018128 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\FRST.txt
2014-09-18 17:27 - 2014-09-18 17:27 - 00000000 ____D () C:\FRST
2014-09-18 17:22 - 2014-09-18 17:22 - 00000000 ____D () C:\Windows\ERUNT
2014-09-18 17:09 - 2014-09-18 17:14 - 00000000 ____D () C:\AdwCleaner
2014-09-18 14:49 - 2014-09-18 14:50 - 01097728 _____ (Farbar) C:\Users\Mike Bailey.WilliamBailey\Desktop\FRST.exe
2014-09-18 14:48 - 2014-09-18 14:49 - 01016830 _____ (Thisisu) C:\Users\Mike Bailey.WilliamBailey\Desktop\JRT.exe
2014-09-18 14:47 - 2014-09-18 14:48 - 01373475 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\adwcleaner_3.310.exe
2014-09-17 21:00 - 2014-09-17 21:00 - 00025734 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\17-9-14.odt
2014-09-17 20:58 - 2014-09-17 20:58 - 12514932 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\Art Book Decoration Images.odt
2014-09-17 19:57 - 2014-09-17 19:57 - 00000000 ____D () C:\Program Files\Microsoft Games
2014-09-17 09:17 - 2014-09-17 09:17 - 00024200 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\ComboFix.txt
2014-09-17 09:16 - 2014-09-17 09:16 - 00024200 _____ () C:\ComboFix.txt
2014-09-17 07:28 - 2014-09-17 09:16 - 00000000 ____D () C:\Qoobox
2014-09-17 07:28 - 2014-09-17 09:13 - 00000000 ____D () C:\Windows\erdnt
2014-09-17 07:28 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-17 07:28 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-17 07:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-17 07:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-17 07:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-17 07:28 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-17 07:28 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-17 07:28 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-17 07:18 - 2014-09-17 07:24 - 05579386 ____R (Swearware) C:\Users\Mike Bailey.WilliamBailey\Desktop\ComboFix.exe
2014-09-16 17:16 - 2014-09-16 17:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-16 17:14 - 2014-09-16 17:44 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\Desktop\mbar
2014-09-16 17:10 - 2014-09-16 17:11 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Mike Bailey.WilliamBailey\Desktop\mbar-1.07.0.1012.exe
2014-09-16 15:14 - 2014-09-16 15:14 - 00033512 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-09-16 15:13 - 2014-09-16 15:14 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-09-16 10:40 - 2014-09-16 10:41 - 04859480 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\RogueKiller.exe
2014-09-15 13:27 - 2014-08-19 18:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-15 13:27 - 2014-08-18 23:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-15 13:27 - 2014-08-18 23:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-15 13:27 - 2014-08-18 22:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-15 13:27 - 2014-08-18 22:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-15 13:27 - 2014-08-18 22:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-15 13:27 - 2014-08-18 22:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-15 13:27 - 2014-08-18 22:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-15 13:27 - 2014-08-18 22:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-15 13:27 - 2014-08-18 22:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-15 13:27 - 2014-08-18 22:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-15 13:27 - 2014-08-18 22:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-15 13:27 - 2014-08-18 22:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-15 13:27 - 2014-08-18 22:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-15 13:27 - 2014-08-18 22:36 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-15 13:27 - 2014-08-18 22:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-15 13:27 - 2014-08-18 22:30 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-15 13:27 - 2014-08-18 22:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-15 13:27 - 2014-08-18 22:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-15 13:27 - 2014-08-18 22:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-15 13:27 - 2014-08-18 22:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-15 13:27 - 2014-08-18 22:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-15 13:27 - 2014-08-18 22:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-15 13:27 - 2014-08-18 22:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-15 13:27 - 2014-08-18 22:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-15 13:27 - 2014-08-18 22:08 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-15 13:27 - 2014-08-18 22:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-15 13:27 - 2014-08-18 21:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-15 13:27 - 2014-08-18 21:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-15 13:27 - 2014-08-18 21:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-15 13:26 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-15 13:10 - 2014-09-05 02:52 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-15 13:10 - 2014-09-05 02:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-15 13:10 - 2014-08-23 02:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-09-15 13:10 - 2014-08-23 01:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-09-15 13:10 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-15 13:10 - 2014-07-07 02:40 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-15 13:10 - 2014-07-07 02:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-15 13:10 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-15 12:56 - 2014-09-15 12:56 - 00688992 ____R (Swearware) C:\Users\Mike Bailey.WilliamBailey\Downloads\dds.com
2014-09-15 12:43 - 2014-09-18 17:26 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\Desktop\CleanUp Sep-2014
2014-09-15 11:54 - 2014-09-16 17:16 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-15 11:54 - 2014-09-15 11:54 - 00001075 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-15 11:54 - 2014-09-15 11:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-15 11:53 - 2014-09-16 17:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-15 11:53 - 2014-09-15 11:54 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-09-15 11:53 - 2014-09-15 11:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-15 11:53 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-15 11:53 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-15 11:48 - 2014-09-15 11:50 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mike Bailey.WilliamBailey\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 22:34 - 2014-09-13 22:34 - 00000008 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\techspot.txt
2014-09-11 21:02 - 2014-09-11 21:03 - 06618541 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\Geography Book Decoration Images.odt
2014-09-11 12:01 - 2014-09-11 12:01 - 00000000 ____D () C:\Program Files\Toggl
2014-09-10 21:46 - 2014-09-10 21:52 - 14096896 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\toggldesktop-7_1_61-2014-09-10-13-15-40.msi
2014-09-10 20:14 - 2014-09-10 20:14 - 06203126 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\French Book Decoration Images.odt
2014-09-10 11:56 - 2014-09-10 11:56 - 10473344 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\SKYBET_PREROLL_3_30sec.flv
2014-09-10 11:47 - 2014-09-10 11:47 - 10462866 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\SKYBET_PREROLL_2_30sec.flv
2014-09-06 12:02 - 2014-09-11 12:01 - 00001994 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\TogglDesktop.lnk
2014-09-06 12:02 - 2014-09-11 12:01 - 00001988 _____ () C:\Users\Public\Desktop\TogglDesktop.lnk
2014-09-04 14:17 - 2014-09-04 14:18 - 14094848 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\toggldesktop-7_1_59-2014-09-03-12-19-11.msi
2014-09-02 21:15 - 2014-09-02 21:16 - 14093312 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\toggldesktop-7_1_54-2014-09-01-13-54-36.msi
2014-09-01 11:54 - 2014-09-01 11:55 - 14093312 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\toggldesktop-7_1_53-2014-09-01-11-39-51.msi
2014-08-31 20:32 - 2014-08-31 20:32 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-23 12:19 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-23 12:19 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-23 12:19 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-23 12:18 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-23 12:06 - 2014-07-16 03:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-23 12:06 - 2014-07-14 02:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-23 12:06 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-23 12:06 - 2014-06-16 02:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-23 12:06 - 2014-06-16 02:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-23 12:06 - 2014-06-16 02:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-23 12:06 - 2014-06-03 10:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-23 12:06 - 2014-06-03 10:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-23 12:06 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-23 12:06 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-22 11:02 - 2014-08-22 11:02 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Adobe
2014-08-22 10:30 - 2014-05-14 17:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-22 10:30 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-22 10:30 - 2014-05-14 17:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-22 10:30 - 2014-05-14 17:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-22 10:30 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-22 10:30 - 2014-05-14 17:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-22 10:30 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-22 10:30 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-22 10:30 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-21 18:13 - 2014-08-21 18:13 - 00006941 _____ () C:\Users\Mike Bailey.WilliamBailey\AppData\Local\recently-used.xbel
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-18 17:28 - 2014-09-18 17:27 - 00018128 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\FRST.txt
2014-09-18 17:27 - 2014-09-18 17:27 - 00000000 ____D () C:\FRST
2014-09-18 17:26 - 2014-09-15 12:43 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\Desktop\CleanUp Sep-2014
2014-09-18 17:25 - 2014-02-27 18:57 - 00000654 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1345319095-2320924753-3983188208-1007.job
2014-09-18 17:25 - 2009-07-14 05:34 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-18 17:25 - 2009-07-14 05:34 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-18 17:22 - 2014-09-18 17:22 - 00000000 ____D () C:\Windows\ERUNT
2014-09-18 17:22 - 2009-10-31 23:11 - 01944048 _____ () C:\Windows\WindowsUpdate.log
2014-09-18 17:19 - 2013-10-11 09:49 - 00000000 ___RD () C:\Users\Mike Bailey.WilliamBailey\Desktop\Dropbox
2014-09-18 17:18 - 2013-10-11 09:44 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Dropbox
2014-09-18 17:18 - 2013-10-08 21:56 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-18 17:17 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-18 17:17 - 2009-07-14 05:39 - 00127498 _____ () C:\Windows\setupact.log
2014-09-18 17:16 - 2009-11-26 04:21 - 00268162 _____ () C:\Windows\PFRO.log
2014-09-18 17:15 - 2013-10-08 21:56 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-18 17:14 - 2014-09-18 17:09 - 00000000 ____D () C:\AdwCleaner
2014-09-18 17:05 - 2013-10-16 11:46 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-18 17:05 - 2013-10-10 18:47 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Skype
2014-09-18 16:54 - 2014-08-01 09:49 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Kopsik
2014-09-18 16:39 - 2014-03-19 15:16 - 00000960 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1345319095-2320924753-3983188208-1007UA.job
2014-09-18 14:50 - 2014-09-18 14:49 - 01097728 _____ (Farbar) C:\Users\Mike Bailey.WilliamBailey\Desktop\FRST.exe
2014-09-18 14:49 - 2014-09-18 14:48 - 01016830 _____ (Thisisu) C:\Users\Mike Bailey.WilliamBailey\Desktop\JRT.exe
2014-09-18 14:48 - 2014-09-18 14:47 - 01373475 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\adwcleaner_3.310.exe
2014-09-18 12:40 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-09-18 10:45 - 2014-06-09 14:22 - 00001094 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\Dropbox.lnk
2014-09-18 10:45 - 2013-10-11 09:45 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-18 09:39 - 2014-03-19 15:16 - 00000908 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1345319095-2320924753-3983188208-1007Core.job
2014-09-17 21:00 - 2014-09-17 21:00 - 00025734 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\17-9-14.odt
2014-09-17 20:58 - 2014-09-17 20:58 - 12514932 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\Art Book Decoration Images.odt
2014-09-17 20:19 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-17 19:57 - 2014-09-17 19:57 - 00000000 ____D () C:\Program Files\Microsoft Games
2014-09-17 19:57 - 2009-07-14 05:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-09-17 09:44 - 2014-03-22 21:45 - 00000000 ____D () C:\Program Files\Opera
2014-09-17 09:17 - 2014-09-17 09:17 - 00024200 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\ComboFix.txt
2014-09-17 09:16 - 2014-09-17 09:16 - 00024200 _____ () C:\ComboFix.txt
2014-09-17 09:16 - 2014-09-17 07:28 - 00000000 ____D () C:\Qoobox
2014-09-17 09:16 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2014-09-17 09:16 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2014-09-17 09:13 - 2014-09-17 07:28 - 00000000 ____D () C:\Windows\erdnt
2014-09-17 09:10 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2014-09-17 07:44 - 2009-07-14 03:03 - 64487424 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-09-17 07:44 - 2009-07-14 03:03 - 19922944 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-09-17 07:44 - 2009-07-14 03:03 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-09-17 07:44 - 2009-07-14 03:03 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-09-17 07:44 - 2009-07-14 03:03 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-09-17 07:24 - 2014-09-17 07:18 - 05579386 ____R (Swearware) C:\Users\Mike Bailey.WilliamBailey\Desktop\ComboFix.exe
2014-09-16 22:25 - 2013-12-11 13:05 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-16 19:13 - 2009-07-21 06:30 - 00847474 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-16 17:44 - 2014-09-16 17:16 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-09-16 17:44 - 2014-09-16 17:14 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\Desktop\mbar
2014-09-16 17:16 - 2014-09-15 11:54 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-16 17:14 - 2014-09-15 11:53 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-16 17:11 - 2014-09-16 17:10 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Mike Bailey.WilliamBailey\Desktop\mbar-1.07.0.1012.exe
2014-09-16 15:14 - 2014-09-16 15:14 - 00033512 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-09-16 15:14 - 2014-09-16 15:13 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-09-16 10:41 - 2014-09-16 10:40 - 04859480 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\RogueKiller.exe
2014-09-15 14:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-09-15 13:36 - 2009-07-14 05:33 - 00510608 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-15 13:26 - 2013-10-14 17:34 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-15 13:17 - 2013-10-14 17:34 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-15 13:16 - 2014-05-01 23:36 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-15 12:56 - 2014-09-15 12:56 - 00688992 ____R (Swearware) C:\Users\Mike Bailey.WilliamBailey\Downloads\dds.com
2014-09-15 12:31 - 2014-02-11 13:19 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\DigitalSites
2014-09-15 11:54 - 2014-09-15 11:54 - 00001075 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-15 11:54 - 2014-09-15 11:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-15 11:54 - 2014-09-15 11:53 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-09-15 11:53 - 2014-09-15 11:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-15 11:50 - 2014-09-15 11:48 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Mike Bailey.WilliamBailey\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-15 08:49 - 2013-10-17 14:40 - 00000094 _____ () C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\WB.CFG
2014-09-13 22:34 - 2014-09-13 22:34 - 00000008 _____ () C:\Users\Mike Bailey.WilliamBailey\Desktop\techspot.txt
2014-09-12 18:24 - 2013-10-08 21:59 - 00002140 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-11 21:03 - 2014-09-11 21:02 - 06618541 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\Geography Book Decoration Images.odt
2014-09-11 12:01 - 2014-09-11 12:01 - 00000000 ____D () C:\Program Files\Toggl
2014-09-11 12:01 - 2014-09-06 12:02 - 00001994 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\TogglDesktop.lnk
2014-09-11 12:01 - 2014-09-06 12:02 - 00001988 _____ () C:\Users\Public\Desktop\TogglDesktop.lnk
2014-09-10 21:52 - 2014-09-10 21:46 - 14096896 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\toggldesktop-7_1_61-2014-09-10-13-15-40.msi
2014-09-10 20:14 - 2014-09-10 20:14 - 06203126 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\French Book Decoration Images.odt
2014-09-10 15:18 - 2013-10-29 12:17 - 00000000 ____D () C:\ProgramData\pdf995
2014-09-10 14:18 - 2014-06-17 11:25 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\Documents\Home
2014-09-10 11:56 - 2014-09-10 11:56 - 10473344 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\SKYBET_PREROLL_3_30sec.flv
2014-09-10 11:47 - 2014-09-10 11:47 - 10462866 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\SKYBET_PREROLL_2_30sec.flv
2014-09-05 02:52 - 2014-09-15 13:10 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-05 02:47 - 2014-09-15 13:10 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-04 14:18 - 2014-09-04 14:17 - 14094848 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\toggldesktop-7_1_59-2014-09-03-12-19-11.msi
2014-09-02 21:16 - 2014-09-02 21:15 - 14093312 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\toggldesktop-7_1_54-2014-09-01-13-54-36.msi
2014-09-01 11:55 - 2014-09-01 11:54 - 14093312 _____ () C:\Users\Mike Bailey.WilliamBailey\Downloads\toggldesktop-7_1_53-2014-09-01-11-39-51.msi
2014-08-31 20:32 - 2014-08-31 20:32 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-08-31 20:32 - 2009-11-26 02:49 - 00000000 ____D () C:\ProgramData\Skype
2014-08-28 12:28 - 2014-04-11 11:23 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\Documents\Car Insurance
2014-08-23 02:46 - 2014-09-15 13:10 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 01:42 - 2014-09-15 13:10 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 11:02 - 2014-08-22 11:02 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Local\Adobe
2014-08-22 10:35 - 2014-01-20 16:01 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-08-22 10:35 - 2014-01-20 16:01 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-08-21 18:13 - 2014-08-21 18:13 - 00006941 _____ () C:\Users\Mike Bailey.WilliamBailey\AppData\Local\recently-used.xbel
2014-08-21 18:13 - 2013-10-15 23:14 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Local\gtk-2.0
2014-08-21 18:13 - 2013-10-15 23:00 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\.gimp-2.8
2014-08-21 12:35 - 2014-08-16 15:53 - 00000000 ____D () C:\Users\Mike Bailey.WilliamBailey\AppData\Roaming\Nitro PDF
2014-08-19 18:39 - 2014-09-15 13:27 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
Some content of TEMP:
====================
C:\Users\Mike Bailey.WilliamBailey\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp_t94_m.dll
C:\Users\Mike Bailey.WilliamBailey\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-16 16:30
==================== End Of Log ============================