Here is the frst.txt (The addition,txt did not generate this time...???)
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2015 01
Ran by Neal (administrator) on HOMESCHOOL1 on 08-05-2015 17:04:27
Running from C:\Users\Neal\Desktop
Loaded Profiles: Neal (Available profiles: Neal & Sean & Noelle & Administrator)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581024 2012-09-07] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2012-09-14] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [77824 2014-08-18] (Apple Computer, Inc.)
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\...\Run: [BluetoothManager] => rundll32.exe "%appdata%\Microsoft\bstack.dll",bs_init
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPNOT13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPNOT13/1
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\Software\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPNOT13/1
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPNOT13/1
SearchScopes: HKLM -> {72A94EC8-3F90-47F1-9886-E2A151F94BD1} URL =
http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {72A94EC8-3F90-47F1-9886-E2A151F94BD1} URL =
http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4105420370-3369507210-3028615837-1002 -> {72A94EC8-3F90-47F1-9886-E2A151F94BD1} URL =
http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-4105420370-3369507210-3028615837-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Neal\AppData\Roaming\Mozilla\Firefox\Profiles\hjieooub.default
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-28] (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-14] ()
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373312 2015-04-14] (WildTangent)
S2 HPConnectedRemote; C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35744 2012-10-12] (Hewlett-Packard)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-09-11] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-03] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-05-08] ()
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-08 16:34 - 2015-05-08 16:34 - 00001607 _____ () C:\Users\Neal\Desktop\JRT.txt
2015-05-08 16:32 - 2015-05-08 16:50 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4105420370-3369507210-3028615837-1002
2015-05-08 16:30 - 2015-05-08 16:30 - 00000207 _____ () C:\WINDOWS\tweaking.com-regbackup-HOMESCHOOL1-Windows-8.1-(64-bit).dat
2015-05-08 16:29 - 2015-05-08 16:29 - 00000000 ____D () C:\RegBackup
2015-05-08 16:29 - 2015-05-08 16:26 - 02716843 _____ (Thisisu) C:\Users\Neal\Desktop\JRT.exe
2015-05-08 16:24 - 2015-05-08 16:26 - 00000000 ____D () C:\AdwCleaner
2015-05-08 16:23 - 2015-05-08 15:49 - 02204160 _____ () C:\Users\Neal\Desktop\adwcleaner_4.203.exe
2015-05-08 15:21 - 2015-05-08 16:22 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-08 15:21 - 2015-05-08 15:21 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-08 15:21 - 2015-05-08 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-08 15:21 - 2015-05-08 15:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-08 15:21 - 2015-05-08 15:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-08 15:21 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-05-08 15:21 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-05-08 15:21 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-05-08 15:20 - 2015-05-08 15:18 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Neal\Desktop\mbam-setup-2.1.6.1022.exe
2015-05-08 15:07 - 2015-05-08 15:17 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-05-08 15:07 - 2015-05-08 15:07 - 00035064 _____ () C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-05-08 15:06 - 2015-05-08 15:05 - 16937048 _____ () C:\Users\Neal\Desktop\RogueKiller.exe
2015-05-08 14:47 - 2015-05-08 14:49 - 00008068 _____ () C:\Users\Neal\Desktop\ESETPoweliksCleaner.exe_20150508.144750.2644.log
2015-05-08 14:47 - 2015-05-08 14:47 - 00000022 _____ () C:\Users\Neal\Desktop\ESETPoweliksCleaner.exe_20150508.144750.2644.zip
2015-05-08 14:47 - 2015-05-08 14:46 - 00221384 _____ (ESET) C:\Users\Neal\Desktop\ESETPoweliksCleaner.exe
2015-05-08 13:32 - 2015-05-08 13:51 - 00042640 _____ () C:\Users\Neal\Desktop\Addition.txt
2015-05-08 12:55 - 2015-05-08 17:04 - 00008565 _____ () C:\Users\Neal\Desktop\FRST.txt
2015-05-08 12:54 - 2015-05-08 12:49 - 02102272 _____ (Farbar) C:\Users\Neal\Desktop\FRST64.exe
2015-05-08 12:49 - 2015-05-08 12:53 - 00000000 ____D () C:\Users\Neal\AppData\Roaming\Local Store
2015-05-08 12:45 - 2015-05-08 12:49 - 02102272 _____ (Farbar) C:\Users\Neal\Downloads\FRST64.exe
2015-05-08 12:40 - 2015-05-08 12:40 - 01141248 _____ (Farbar) C:\Users\Neal\Downloads\FRST.exe
2015-05-08 11:48 - 2015-05-08 11:48 - 00000288 _____ () C:\Users\Neal\Desktop\test.txt
2015-05-08 11:45 - 2015-05-08 11:45 - 00000000 ____D () C:\HP
2015-05-07 15:19 - 2015-05-08 17:04 - 00000000 ____D () C:\FRST
2015-05-07 14:06 - 2015-05-07 14:06 - 00000000 ____D () C:\WINDOWS\pss
2015-05-05 02:17 - 2015-05-07 15:53 - 00000000 ____D () C:\ProgramData\BlueStacks
2015-05-04 22:12 - 2015-05-04 22:12 - 00000000 ____D () C:\Users\Noelle\Documents\julius caesar
2015-04-17 09:45 - 2015-04-17 09:45 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-04-14 19:50 - 2015-03-23 16:59 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-04-14 19:50 - 2015-03-23 16:59 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-04-14 19:50 - 2015-03-23 16:59 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2015-04-14 19:50 - 2015-03-23 16:58 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-04-14 19:50 - 2015-03-23 16:45 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2015-04-14 19:50 - 2015-03-19 23:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2015-04-14 19:50 - 2015-03-19 23:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-04-14 19:50 - 2015-03-19 23:10 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-04-14 19:50 - 2015-03-19 22:17 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
2015-04-14 19:50 - 2015-03-19 21:41 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
2015-04-14 19:50 - 2015-03-19 21:40 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-04-14 19:50 - 2015-03-19 21:16 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-04-14 19:50 - 2015-03-14 03:20 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-04-14 19:50 - 2015-03-14 03:13 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2015-04-14 19:50 - 2015-03-12 23:32 - 24980480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-04-14 19:50 - 2015-03-12 22:50 - 06025216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-04-14 19:50 - 2015-03-12 22:42 - 19695616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-04-14 19:50 - 2015-03-12 22:00 - 14397440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-04-14 19:50 - 2015-03-12 21:58 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2015-04-14 19:50 - 2015-03-12 21:49 - 04305408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-04-14 19:50 - 2015-03-12 21:37 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2015-04-14 19:50 - 2015-02-20 18:49 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2015-04-14 19:49 - 2015-03-22 17:45 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 01111552 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-04-14 19:49 - 2015-03-14 03:54 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-04-14 19:49 - 2015-03-13 20:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-04-14 19:49 - 2015-03-13 20:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-04-14 19:49 - 2015-03-13 20:51 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-04-14 19:49 - 2015-03-13 20:37 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-04-14 19:49 - 2015-03-13 20:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-04-14 19:49 - 2015-03-13 19:22 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-04-14 19:49 - 2015-03-13 19:12 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-04-14 19:49 - 2015-03-13 19:12 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-04-14 19:49 - 2015-03-13 19:09 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-04-14 19:49 - 2015-03-13 19:08 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-04-14 19:49 - 2015-03-13 19:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-04-14 19:49 - 2015-03-13 19:06 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-04-14 19:49 - 2015-03-13 19:06 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-04-14 19:49 - 2015-03-13 19:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-04-14 19:49 - 2015-03-13 19:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-04-14 19:49 - 2015-03-13 18:59 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-04-14 19:49 - 2015-03-13 18:59 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-04-14 19:49 - 2015-03-12 23:08 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-04-14 19:49 - 2015-03-12 23:07 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-04-14 19:49 - 2015-03-12 22:53 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-04-14 19:49 - 2015-03-12 22:28 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-04-14 19:49 - 2015-03-12 22:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-04-14 19:49 - 2015-03-12 22:22 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-04-14 19:49 - 2015-03-12 22:17 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-04-14 19:49 - 2015-03-12 22:16 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-04-14 19:49 - 2015-03-12 22:08 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-04-14 19:49 - 2015-03-12 22:07 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-04-14 19:49 - 2015-03-12 21:50 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-04-14 19:49 - 2015-03-12 21:45 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-04-14 19:49 - 2015-03-12 21:44 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-04-14 19:49 - 2015-03-12 21:34 - 12825600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-04-14 19:49 - 2015-03-12 21:33 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-04-14 19:49 - 2015-03-12 21:22 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-04-14 19:49 - 2015-03-12 21:20 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-04-14 19:49 - 2015-03-12 21:16 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-04-14 19:49 - 2015-03-12 21:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-04-14 19:49 - 2015-03-04 05:25 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2015-04-14 19:49 - 2015-03-03 22:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-04-14 19:49 - 2015-03-03 21:19 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
2015-04-14 19:49 - 2015-02-24 03:32 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2015-04-14 19:49 - 2014-12-02 18:09 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-04-08 12:05 - 2015-04-08 12:06 - 00000000 ___SD () C:\WINDOWS\system32\GWX
2015-04-08 12:05 - 2015-04-08 12:05 - 00000000 ___SD () C:\WINDOWS\SysWOW64\GWX
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-08 17:00 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-08 16:27 - 2014-09-11 17:08 - 00000000 __RDO () C:\Users\Neal\OneDrive
2015-05-08 16:27 - 2014-03-18 04:54 - 00058356 _____ () C:\WINDOWS\PFRO.log
2015-05-08 16:27 - 2013-08-22 09:46 - 00424646 _____ () C:\WINDOWS\setupact.log
2015-05-08 16:27 - 2013-08-22 09:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-08 16:27 - 2013-08-22 08:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-08 15:09 - 2014-03-18 05:03 - 00956480 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-08 14:33 - 2014-09-11 16:28 - 00000000 ____D () C:\Users\Neal
2015-05-08 11:55 - 2014-08-18 12:57 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E6DB391A-67E2-49DF-ADDD-A578345A07FB}
2015-05-08 09:17 - 2014-09-11 16:13 - 01818681 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-08 08:48 - 2014-09-11 16:28 - 00000000 ____D () C:\Users\Noelle
2015-05-08 08:48 - 2014-09-11 16:28 - 00000000 ____D () C:\Users\Administrator
2015-05-08 08:48 - 2013-08-22 08:36 - 00000000 __RHD () C:\Users\Default
2015-05-07 15:54 - 2014-12-22 20:58 - 00000000 ____D () C:\Users\Neal\Documents\CyberLink
2015-05-07 15:54 - 2014-11-05 14:25 - 00000000 ____D () C:\Users\Neal\Desktop\noelle
2015-05-07 15:54 - 2014-09-30 15:50 - 00000000 ____D () C:\Users\Neal\Desktop\Master bath
2015-05-07 15:54 - 2014-09-27 08:39 - 00000000 ____D () C:\Users\Neal\Desktop\RN Liscense
2015-05-07 15:54 - 2014-09-13 14:40 - 00000000 ____D () C:\Users\Neal\Desktop\Hurst Review
2015-05-07 15:54 - 2014-09-03 08:33 - 00000000 ____D () C:\Users\Neal\Desktop\STVE
2015-05-07 15:54 - 2014-08-18 01:43 - 00000000 ____D () C:\Users\Neal\Desktop\General Sciencev2-MP3
2015-05-07 15:54 - 2014-08-18 00:52 - 00000000 ____D () C:\Users\Neal\.javaws
2015-05-07 15:53 - 2014-09-11 19:09 - 00000000 __SHD () C:\Recovery
2015-05-07 15:53 - 2014-09-11 16:17 - 00000000 ____D () C:\ProgramData\AMD
2015-05-07 15:53 - 2014-09-11 16:16 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-07 15:53 - 2014-09-08 07:29 - 00000000 ____D () C:\ProgramData\lx_Cats
2015-05-07 15:53 - 2014-08-18 20:50 - 00000000 ____D () C:\ProgramData\QuickTime
2015-05-07 15:53 - 2014-08-18 13:14 - 00000000 ____D () C:\ProgramData\Mozilla
2015-05-07 15:53 - 2014-07-11 14:35 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\ATI
2015-05-07 15:53 - 2014-07-11 14:35 - 00000000 ____D () C:\Users\Administrator\AppData\Local\ATI
2015-05-07 15:53 - 2014-07-11 14:35 - 00000000 ____D () C:\Users\Administrator\AppData\Local\AMD
2015-05-07 15:53 - 2014-07-11 14:35 - 00000000 ____D () C:\ProgramData\ATI
2015-05-07 15:53 - 2014-07-11 14:24 - 00000000 ____D () C:\ProgramData\Norton
2015-05-07 15:53 - 2014-07-11 14:16 - 00000000 ____D () C:\ProgramData\CyberLink
2015-05-07 15:53 - 2014-07-11 14:00 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Downloaded Installations
2015-05-07 15:53 - 2014-07-11 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Synaptics
2015-05-07 15:53 - 2014-07-11 13:56 - 00000000 ____D () C:\ProgramData\Synaptics
2015-05-07 15:53 - 2014-07-11 13:53 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2015-05-07 15:53 - 2014-07-11 13:52 - 00000000 ____D () C:\ProgramData\Apple
2015-05-07 15:53 - 2012-10-29 21:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\FFSJ
2015-05-07 15:53 - 2012-10-29 21:16 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Hewlett-Packard
2015-05-07 15:53 - 2012-10-29 21:16 - 00000000 ____D () C:\ProgramData\WildTangent
2015-05-07 15:53 - 2012-10-29 21:10 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2015-05-07 15:53 - 2012-10-29 21:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Windows Live
2015-05-07 15:53 - 2012-10-29 21:06 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2015-05-07 15:53 - 2012-10-29 20:58 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\hpqLog
2015-05-07 15:53 - 2012-10-29 20:58 - 00000000 ____D () C:\ProgramData\install_clap
2015-05-07 15:53 - 2012-10-29 20:55 - 00000000 ___HD () C:\Users\Administrator\Documents\hp.system.package.metadata
2015-05-07 15:53 - 2012-08-03 19:02 - 00000000 __RHD () C:\SYSTEM.SAV
2015-05-07 15:53 - 2012-08-03 19:02 - 00000000 ____D () C:\SWSetup
2015-05-07 15:53 - 2012-08-03 17:29 - 00000000 ____D () C:\ProgramData\PRICache
2015-05-07 15:53 - 2012-08-03 17:28 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2015-05-07 15:52 - 2014-09-11 18:59 - 00000000 ____D () C:\inetpub
2015-05-07 15:52 - 2014-09-11 16:12 - 00000000 ____D () C:\AMD
2015-05-07 15:52 - 2014-08-18 14:51 - 00000000 ___HD () C:\$SysReset
2015-05-07 13:54 - 2012-10-29 21:07 - 00000000 ___RD () C:\Users\Administrator\SkyDrive
2015-05-07 13:25 - 2014-09-08 19:54 - 00007332 _____ () C:\Users\Neal\Desktop\double barn doors.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:47 - 00009396 _____ () C:\Users\Neal\Desktop\tile size.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:45 - 00005972 _____ () C:\Users\Neal\Desktop\barn door.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:38 - 00006772 _____ () C:\Users\Neal\Desktop\imagesCAVYFP72.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:35 - 00009460 _____ () C:\Users\Neal\Desktop\imagesCA7CH076.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:30 - 00007556 _____ () C:\Users\Neal\Desktop\imagesCASKJVS5.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:22 - 00008660 _____ () C:\Users\Neal\Desktop\stone shower.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:19 - 00072372 _____ () C:\Users\Neal\Desktop\Nice-Rustic-Wooden-Look-in-Western-Style-Bathroom-Interior.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:14 - 00021940 _____ () C:\Users\Neal\Desktop\stoneshowers3.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:13 - 00126212 _____ () C:\Users\Neal\Desktop\shower-designs_stone.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:11 - 00145892 _____ () C:\Users\Neal\Desktop\bathroom-natural-cream-small-bathroom-renovation-idea-with-cream-stone-wall-colorful-border-and-shower-nice-small-bathroom-renovation-ideas-972x650.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:06 - 00042676 _____ () C:\Users\Neal\Desktop\thumb4_wlshower.jpg.ezz
2015-05-07 13:25 - 2014-08-17 23:39 - 10782340 _____ () C:\Users\Neal\Documents\9781616251185_ApologiaExploringCreationWithG.pdf.ezz
2015-05-07 13:25 - 2014-08-17 23:35 - 24867156 _____ () C:\Users\Neal\Desktop\9781616251345_ApologiaExploringCreationWithB.pdf.ezz
2015-05-07 13:25 - 2014-08-17 21:22 - 10782340 _____ () C:\Users\Neal\Desktop\9781616251185_ApologiaExploringCreationWithG.pdf.ezz
2015-05-07 13:25 - 2014-07-11 16:24 - 01440996 _____ () C:\Users\Neal\Desktop\CRCS Handbook.pdf.ezz
2015-05-07 12:47 - 2015-01-09 01:59 - 00000000 ___RD () C:\Users\Noelle\OneDrive
2015-05-07 01:07 - 2015-01-09 01:55 - 00003942 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C556DA80-233A-4939-81B7-D4F612CB4826}
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 14:31 - 2012-10-29 20:58 - 00000000 ____D () C:\ProgramData\Temp
2015-05-05 14:22 - 2014-09-13 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-05 14:22 - 2014-09-11 16:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-05-05 14:22 - 2014-08-18 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-05-05 14:22 - 2014-08-18 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Web Start
2015-05-05 14:22 - 2014-08-18 20:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Rosetta Stone
2015-05-05 14:22 - 2014-08-18 13:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TT Algebra 1
2015-05-05 14:22 - 2014-08-18 12:56 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
2015-05-05 14:22 - 2014-07-11 14:08 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2015-05-05 14:22 - 2014-07-11 14:00 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2015-05-05 14:22 - 2014-03-18 04:45 - 00000000 __RHD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
2015-05-05 14:22 - 2013-08-22 10:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-05 14:22 - 2013-08-22 10:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 14:22 - 2013-08-22 10:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-05 14:22 - 2013-08-22 10:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 14:22 - 2012-10-29 21:17 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-05 14:22 - 2012-10-29 21:13 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2015-05-05 14:22 - 2012-10-29 21:02 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2015-05-05 14:21 - 2014-09-11 16:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-05 14:21 - 2014-09-11 16:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 14:21 - 2014-09-11 16:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-05 14:21 - 2014-09-11 16:28 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 14:21 - 2012-08-03 17:28 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Packages
2015-05-05 14:18 - 2014-03-18 04:45 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-05-05 14:17 - 2014-09-11 16:12 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2015-05-05 14:17 - 2014-07-11 13:52 - 00000000 ____D () C:\Program Files\Bonjour
2015-05-05 14:17 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\Services
2015-05-05 14:17 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-05-05 14:17 - 2012-09-18 21:56 - 00000000 ____D () C:\Program Files\Hewlett-Packard
2015-05-05 02:16 - 2012-10-29 21:16 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2015-05-04 15:46 - 2014-08-15 09:06 - 00000000 ____D () C:\Users\Public\Documents\TT Algebra 1
2015-05-03 15:12 - 2015-03-16 12:27 - 00000000 ____D () C:\Users\Noelle\AppData\Roaming\Mozilla
2015-05-03 15:12 - 2015-01-21 13:05 - 00000000 ____D () C:\Users\Noelle\Documents\CyberLink
2015-05-03 15:12 - 2015-01-09 01:57 - 00000000 ____D () C:\Users\Noelle\AppData\Local\AMD
2015-05-03 15:12 - 2015-01-09 01:55 - 00000000 ____D () C:\Users\Noelle\AppData\Roaming\Adobe
2015-05-03 15:10 - 2014-08-18 13:15 - 00000000 ____D () C:\Users\Neal\AppData\Roaming\Mozilla
2015-05-03 15:10 - 2014-08-18 13:00 - 00000000 ____D () C:\Users\Neal\AppData\Local\AMD
2015-05-03 15:10 - 2014-08-18 12:58 - 00000000 ____D () C:\Users\Neal\AppData\Roaming\Hewlett-Packard
2015-05-03 15:10 - 2014-08-18 12:56 - 00000000 ____D () C:\Users\Neal\AppData\Roaming\Adobe
2015-05-03 15:10 - 2014-08-18 12:53 - 00000000 ____D () C:\Users\Neal\AppData\Local\Power2Go8
2015-04-20 13:56 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-04-18 20:18 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\AppCompat
2015-04-17 09:45 - 2015-03-29 21:04 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-04-14 20:35 - 2014-08-23 00:19 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-14 20:33 - 2014-08-23 00:19 - 128913832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-14 20:33 - 2012-07-26 02:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
Some content of TEMP:
====================
C:\Users\Neal\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Neal\AppData\Local\Temp\Quarantine.exe
C:\Users\Neal\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-08 14:59
==================== End Of Log ============================