Frst:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by wills (administrator) on HOME (17-09-2015 10:45:18)
Running from C:\Users\wills\Desktop
Loaded Profiles: wills (Available Profiles: wills)
Platform: Windows 8.1 Pro (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
() C:\ProgramData\MobileBrServ\mbbService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
Startup: C:\Users\wills\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2013-06-16]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{069099DC-4CBE-4446-9B56-194B1E558DDF}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{1206E400-6297-4C54-831C-BA919F239804}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{AE87B87A-3F62-46C1-ACBA-6444E72AC939}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-2328787975-3927773778-2076377496-1004\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKU\S-1-5-21-2328787975-3927773778-2076377496-1004\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll [2015-06-09] ()
BHO-x32: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files (x86)\WOT\WOT.dll [2015-06-09] ()
Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2015-06-09] ()
Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll [2015-06-09] ()
Toolbar: HKU\S-1-5-21-2328787975-3927773778-2076377496-1004 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll [2015-06-09] ()
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll [2015-06-09] ()
Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll [2015-06-09] ()
FireFox:
========
FF ProfilePath: C:\Users\wills\AppData\Roaming\Mozilla\Firefox\Profiles\yhys6o5n.default-1441424448047
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
Chrome:
=======
CHR Profile: C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-17]
CHR Extension: (Google Docs) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-17]
CHR Extension: (Google Drive) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-17]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2015-09-17]
CHR Extension: (YouTube) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-17]
CHR Extension: (Google Search) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-17]
CHR Extension: (Google Sheets) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-17]
CHR Extension: (Google Docs Offline) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-17]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-09-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-17]
CHR Extension: (Gmail) - C:\Users\wills\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-17]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [242256 2014-08-20] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-20] (Electronic Arts)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22128 2012-03-08] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-09-06] ()
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-25] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-17 10:45 - 2015-09-17 10:45 - 00010193 _____ C:\Users\wills\Desktop\FRST.txt
2015-09-17 10:30 - 2015-09-17 10:30 - 00000077 _____ C:\WINDOWS\setupact.log
2015-09-17 10:30 - 2015-09-17 10:30 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-09-17 10:29 - 2015-09-17 10:29 - 00001046 _____ C:\WINDOWS\PFRO.log
2015-09-17 10:21 - 2015-08-11 04:15 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2015-09-17 10:21 - 2015-08-11 04:15 - 00845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2015-09-17 10:21 - 2015-08-11 04:06 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2015-09-17 10:21 - 2015-08-11 03:49 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2015-09-17 10:21 - 2015-08-11 02:56 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2015-09-17 10:21 - 2015-08-11 02:46 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2015-09-17 10:21 - 2015-08-07 05:15 - 01658544 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-09-17 10:21 - 2015-08-07 05:15 - 01519592 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-09-17 10:21 - 2015-08-07 05:15 - 01487008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-09-17 10:21 - 2015-08-07 05:15 - 01355848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-09-17 10:21 - 2015-08-07 02:47 - 04710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2015-09-17 10:21 - 2015-08-07 02:18 - 04068352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2015-09-17 10:20 - 2015-08-08 07:41 - 07460168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-09-17 10:20 - 2015-08-08 07:40 - 01736520 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-09-17 10:20 - 2015-08-08 07:40 - 01499920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-09-17 10:20 - 2015-08-08 07:40 - 01134752 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2015-09-17 10:20 - 2015-08-08 07:40 - 00686960 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2015-09-17 10:20 - 2015-08-08 07:40 - 00507176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2015-09-17 10:20 - 2015-08-08 00:13 - 00862720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2015-09-17 10:20 - 2015-08-07 03:05 - 00669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2015-09-17 10:20 - 2015-08-07 02:37 - 00536576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2015-09-17 10:20 - 2015-07-17 04:58 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NcdAutoSetup.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00901264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00066400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00022368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00016224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00015712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00014176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00013664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:42 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00984448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00063840 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00016224 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00015712 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00014176 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00013664 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-09-17 10:19 - 2015-08-22 23:35 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-09-17 10:12 - 2015-09-17 10:45 - 00201205 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-17 10:12 - 2015-09-17 10:12 - 00002239 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-17 10:12 - 2015-09-17 10:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-09-17 10:10 - 2015-09-17 10:31 - 00000902 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-17 10:10 - 2015-09-17 10:15 - 00000906 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-17 10:10 - 2015-09-17 10:12 - 00000000 ____D C:\Users\wills\AppData\Local\Google
2015-09-17 10:10 - 2015-09-17 10:10 - 00003878 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-17 10:10 - 2015-09-17 10:10 - 00003642 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-13 13:09 - 2015-09-17 10:11 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-13 13:00 - 2015-09-17 10:10 - 00929872 _____ (Google Inc.) C:\Users\wills\Downloads\ChromeSetup.exe
2015-09-13 12:31 - 2015-09-13 12:31 - 00020330 _____ C:\Users\wills\Documents\2015 09 03 Registry Backup cc.reg
2015-09-13 10:55 - 2015-09-17 10:45 - 00000000 ____D C:\FRST
2015-09-13 10:54 - 2015-09-17 09:33 - 02191360 _____ (Farbar) C:\Users\wills\Desktop\FRST64.exe
2015-09-09 12:46 - 2015-09-09 12:46 - 00000000 ____D C:\Users\wills\AppData\Local\Secunia PSI
2015-09-09 12:46 - 2015-09-09 12:46 - 00000000 ____D C:\Program Files (x86)\Secunia
2015-09-09 12:45 - 2015-09-09 12:45 - 01799392 _____ (Malwarebytes Corporation) C:\Users\wills\Desktop\JRT.exe
2015-09-09 12:44 - 2015-09-09 12:44 - 01660416 _____ C:\Users\wills\Desktop\adwcleaner_5.007.exe
2015-09-09 12:43 - 2015-09-09 12:43 - 00448512 _____ (OldTimer Tools) C:\Users\wills\Desktop\TFC.exe
2015-09-09 12:42 - 2015-09-09 12:42 - 05490752 _____ (Secunia) C:\Users\wills\Downloads\PSISetup.exe
2015-09-09 12:38 - 2015-09-09 12:38 - 00000000 ____D C:\Program Files\WOT
2015-09-09 12:38 - 2015-09-09 12:38 - 00000000 ____D C:\Program Files (x86)\WOT
2015-09-09 12:13 - 2015-09-03 12:18 - 02531400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-09-09 12:13 - 2015-09-03 12:17 - 01903848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-09-09 12:13 - 2015-09-03 04:48 - 02345472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-09-09 12:13 - 2015-09-03 03:09 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-09-09 12:13 - 2015-08-23 04:19 - 25188352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-09 12:13 - 2015-08-23 03:35 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-09 12:13 - 2015-08-23 03:34 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-09 12:13 - 2015-08-23 03:22 - 19856384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-09 12:13 - 2015-08-23 03:21 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-09 12:13 - 2015-08-23 03:20 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-09-09 12:13 - 2015-08-23 02:55 - 00504832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-09 12:13 - 2015-08-23 02:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-09 12:13 - 2015-08-23 02:45 - 00665600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-09 12:13 - 2015-08-23 02:41 - 14451712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-09 12:13 - 2015-08-23 02:41 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-09-09 12:13 - 2015-08-23 02:41 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-09-09 12:13 - 2015-08-23 02:39 - 02126336 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-09-09 12:13 - 2015-08-23 02:28 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-09-09 12:13 - 2015-08-23 02:26 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-09-09 12:13 - 2015-08-23 02:22 - 12857344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-09 12:13 - 2015-08-23 02:14 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-09-09 12:13 - 2015-08-23 02:00 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-09-09 12:13 - 2015-08-23 01:56 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-09-09 12:13 - 2015-07-31 03:18 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\InkEd.dll
2015-09-09 12:13 - 2015-07-31 02:22 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InkEd.dll
2015-09-09 12:12 - 2015-08-23 02:50 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-09-09 12:12 - 2015-08-23 02:44 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-09-09 12:12 - 2015-08-23 02:41 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-09-09 12:12 - 2015-08-23 02:23 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-09-09 12:12 - 2015-08-23 02:20 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-09-09 12:12 - 2015-08-23 02:18 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-09-09 12:12 - 2015-08-23 02:18 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-09-09 12:12 - 2015-08-23 02:18 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-09-09 12:12 - 2015-08-23 02:01 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-09-09 12:12 - 2015-08-23 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-09-09 12:11 - 2015-09-02 12:56 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-09-09 12:11 - 2015-09-02 12:55 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-09 12:11 - 2015-09-02 12:50 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-09 12:11 - 2015-09-02 12:17 - 00301568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-09 12:11 - 2015-09-02 12:13 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-09 12:11 - 2015-08-04 07:15 - 00074928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2015-09-09 12:11 - 2015-08-04 07:15 - 00065600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2015-09-09 12:11 - 2015-08-02 00:22 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2015-09-09 12:11 - 2015-08-01 13:47 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schtasks.exe
2015-09-09 12:11 - 2015-08-01 13:45 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe
2015-09-09 12:11 - 2015-08-01 13:38 - 01265152 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-09 12:11 - 2015-08-01 13:37 - 00468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskeng.exe
2015-09-09 12:11 - 2015-08-01 13:37 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskeng.exe
2015-09-09 12:11 - 2015-07-23 00:34 - 02775552 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-09 12:11 - 2015-07-23 00:33 - 01728000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 12:11 - 2015-07-23 00:25 - 02461184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-09 12:11 - 2015-07-23 00:25 - 01546752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-09 12:11 - 2015-07-19 04:31 - 00194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-09 12:11 - 2015-07-19 04:29 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-09 12:11 - 2015-07-19 04:29 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-09 12:11 - 2015-07-19 04:27 - 00520192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-09 12:06 - 2015-09-09 12:06 - 00001391 _____ C:\DelFix.txt
2015-09-09 12:06 - 2015-09-09 12:06 - 00000000 ____D C:\WINDOWS\ERUNT
2015-09-08 14:25 - 2015-09-08 14:26 - 00000000 ____D C:\ProgramData\Sophos
2015-09-08 14:21 - 2015-09-08 14:21 - 00002775 _____ C:\Users\Public\Desktop\Sophos Virus Removal Tool.lnk
2015-09-08 14:21 - 2015-09-08 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2015-09-08 14:21 - 2015-09-08 14:21 - 00000000 ____D C:\Program Files (x86)\Sophos
2015-09-08 13:59 - 2015-09-08 14:02 - 132672592 _____ (Sophos Limited) C:\Users\wills\Downloads\Sophos Virus Removal Tool.exe
2015-09-05 19:13 - 2015-09-06 10:18 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-09-05 19:13 - 2015-09-05 19:29 - 00000000 ____D C:\ProgramData\RogueKiller
2015-09-05 15:02 - 2015-09-17 10:41 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2328787975-3927773778-2076377496-1004
2015-09-05 14:53 - 2015-08-27 12:48 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-09-05 14:53 - 2015-08-27 04:00 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-09-05 14:53 - 2015-08-27 04:00 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-09-05 14:53 - 2015-08-27 00:46 - 03705344 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-09-05 14:53 - 2015-08-27 00:29 - 02240512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-09-05 14:53 - 2015-08-27 00:27 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-05 14:53 - 2015-08-27 00:27 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-09-05 14:53 - 2015-08-27 00:26 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-09-05 14:32 - 2015-09-05 14:32 - 00034324 _____ C:\Users\wills\Documents\2015 09 05 Registry Backup cc_20150905_143216.reg
2015-09-05 13:58 - 2015-09-13 12:28 - 06667640 _____ (Piriform Ltd) C:\Users\wills\Downloads\ccsetup509.exe
2015-09-05 11:51 - 2015-09-05 11:51 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\wills\Downloads\iExplore.exe
2015-09-03 13:11 - 2015-09-05 13:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-31 20:13 - 2015-08-31 20:13 - 00081904 _____ C:\Users\wills\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-26 16:24 - 2015-08-26 16:25 - 00000025 _____ C:\Users\wills\Documents\ebgames carrots.txt
2015-08-20 10:48 - 2015-07-23 00:19 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-08-20 10:48 - 2015-07-22 23:52 - 01633792 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-20 10:48 - 2015-07-18 00:15 - 00951296 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-08-20 10:48 - 2015-07-18 00:10 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-08-20 10:48 - 2015-07-04 07:51 - 01380056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-08-20 10:48 - 2015-07-04 00:00 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-08-20 10:48 - 2015-06-27 21:47 - 00118616 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2015-08-20 10:47 - 2015-07-14 13:27 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzsync.exe
2015-08-20 10:47 - 2015-07-14 05:10 - 00411455 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-08-20 10:47 - 2015-07-10 02:14 - 00228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-08-20 10:47 - 2015-06-20 03:07 - 02819072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-08-19 16:51 - 2015-08-20 15:42 - 00000000 _____ C:\Users\wills\Documents\80 music videos.txt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-17 10:35 - 2014-03-19 01:25 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-17 10:31 - 2014-05-16 18:58 - 00000000 ___DO C:\Users\wills\OneDrive
2015-09-17 10:30 - 2013-08-23 00:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-17 10:30 - 2013-03-03 11:49 - 00000562 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2015-09-17 10:19 - 2012-07-26 17:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-17 10:08 - 2013-03-02 15:11 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-17 10:02 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-17 09:25 - 2014-05-16 20:15 - 00003910 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2A0A3BCF-EF48-4FA9-8CCA-9ACF99987F59}
2015-09-17 03:12 - 2013-08-22 23:25 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2015-09-15 20:50 - 2015-03-10 12:10 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-14 17:09 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-13 12:29 - 2013-03-02 17:54 - 00000834 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-09-13 12:28 - 2013-03-02 17:54 - 00000000 ____D C:\Program Files\CCleaner
2015-09-10 18:39 - 2013-03-02 11:36 - 00000000 ____D C:\Users\wills\Documents\Games
2015-09-10 12:50 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\rescache
2015-09-09 12:26 - 2013-08-23 00:44 - 00377600 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-09 12:23 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-09-09 12:22 - 2013-03-02 16:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-09 12:21 - 2014-03-19 01:10 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-09 12:19 - 2013-07-15 12:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-05 14:55 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\en-GB
2015-09-05 14:33 - 2014-07-25 20:31 - 00000000 ____D C:\Program Files (x86)\Steam
2015-09-05 14:33 - 2014-07-11 22:55 - 00000000 ____D C:\WINDOWS\Minidump
2015-09-05 14:33 - 2013-03-03 15:08 - 00000000 ____D C:\Users\wills\AppData\Roaming\uTorrent
2015-09-05 14:18 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-09-05 14:00 - 2013-03-02 17:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-05 13:55 - 2013-03-02 14:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-05 11:47 - 2014-07-14 19:17 - 00000000 ____D C:\NeverwinterNights
2015-09-05 11:47 - 2013-03-02 08:56 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-03 19:47 - 2014-08-14 12:38 - 00705024 ___SH C:\Users\wills\Downloads\Thumbs.db
2015-09-03 11:12 - 2014-04-03 11:01 - 00000000 ____D C:\Users\wills\AppData\Roaming\vlc
2015-08-26 18:37 - 2013-03-02 11:14 - 134753440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-20 10:49 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-17 10:41
==================== End of FRST.txt ============================