Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-05-2015 01
Ran by Theodore Abramowitz (administrator) on LPIV on 23-05-2015 16:01:49
Running from C:\Users\Theodore Abramowitz\Desktop
Loaded Profiles: Theodore Abramowitz (Available Profiles: Theodore Abramowitz)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Emsisoft Ltd) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
() C:\Program Files (x86)\Coupoon\UpdateCheck.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
() C:\Program Files (x86)\Garena Plus\ggdllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Spotify Ltd) C:\Users\Theodore Abramowitz\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Emsisoft Ltd) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Lenovo) C:\Program Files\lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-30] (Intel Corporation)
HKLM-x32\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [391128 2013-09-11] (Intel Corporation)
HKLM-x32\...\Run: [HotKeysCmds] => C:\windows\system32\hkcmd.exe [771032 2013-09-11] (Intel Corporation)
HKLM-x32\...\Run: [Persistence] => C:\windows\system32\igfxpers.exe [769496 2013-09-11] (Intel Corporation)
HKLM-x32\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [903384 2013-07-24] (Conexant Systems, Inc.)
HKLM-x32\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-12] (Conexant Systems, Inc.)
HKLM-x32\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2015-03-20] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2015-03-20] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [552960 2013-05-14] (Vimicro)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4923832 2015-05-10] (Emsisoft Ltd)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] (Qualcomm®Atheros®)
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7451928 2015-03-13] (Piriform Ltd)
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2888384 2015-05-14] (Valve Corporation)
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\...\Run: [Spotify Web Helper] => C:\Users\Theodore Abramowitz\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1964088 2015-03-29] (Spotify Ltd)
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [25700400 2015-04-28] (Google)
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\...\Run: [GoogleChromeAutoLaunch_9B877D55BAEDE70EAFA646B7293AA6B2] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-05-13] (Google Inc.)
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\...\Run: [Google Update] => C:\Users\Theodore Abramowitz\AppData\Local\Google\Update\GoogleUpdate.exe [107848 2015-05-10] (Google Inc.)
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\...\Run: [Spotify] => C:\Users\Theodore Abramowitz\AppData\Roaming\Spotify\Spotify.exe [6701624 2015-03-29] (Spotify Ltd)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?pc=MSE1
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?pc=MSE1
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://home.lenovo.com
HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://go.microsoft.com/fwlink/?Lin...&hid=7606990432693628018&lg=EN&cc=US&unqvl=86
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2285157681-2606125537-3038485319-1001 -> DefaultScope {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
FireFox:
========
FF ProfilePath: C:\Users\Theodore Abramowitz\AppData\Roaming\Mozilla\Firefox\Profiles\k99pgjvi.default
FF DefaultSearchEngine.US: Google
FF Homepage: google.com
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-08] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-18] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2285157681-2606125537-3038485319-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Theodore Abramowitz\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-2285157681-2606125537-3038485319-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Theodore Abramowitz\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Extension: PrIceLeSse - C:\Users\Theodore Abramowitz\AppData\Roaming\Mozilla\Firefox\Profiles\k99pgjvi.default\Extensions\
MP@aqS.com [2015-05-16]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-29]
CHR Extension: (Google Docs) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-29]
CHR Extension: (Google Drive) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-29]
CHR Extension: (YouTube) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-29]
CHR Extension: (Google Cast) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2015-03-29]
CHR Extension: (Add to Amazon Wish List) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced [2015-03-29]
CHR Extension: (
http://www.youtube-mp3.org/) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjhmdjffbkdmddmdmmbabiaclojaomeg [2015-03-29]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2015-03-29]
CHR Extension: (Spotify - Music for every moment) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2015-03-29]
CHR Extension: (
http://www.amazon.com/) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\eicbgcfajfmpllmbdfmnnpomnnedfbop [2015-03-29]
CHR Extension: (Google Sheets) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-29]
CHR Extension: (AdBlock) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-03-29]
CHR Extension: (
http://www.hulu.com/) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhgbkjbpjkpdkbbalmaggmmlcffjaaae [2015-03-29]
CHR Extension: (Keep My Opt-Outs) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhnjdplhmcnkiecampfdgfjilccfpfoe [2015-03-29]
CHR Extension: (
http://www.oocities.org/csroberts/light.htm) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijnflnbkpleohkcejljpgdllaebcncme [2015-03-29]
CHR Extension: (
http://www.free-tv-video-online.me/internet/) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcmehnlndgfecnjkhlnnnlahaopiaefp [2015-03-29]
CHR Extension: (
http://nerdbusiness.com/blog/777-hd-wallpaper) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghcncncdcfmbaighpgnohajkehjeoof [2015-03-29]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-03-29]
CHR Extension: (Netflix) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nemhnkphjkppgiobkmjaogfelbecnohf [2015-03-29]
CHR Extension: (Google Wallet) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-29]
CHR Extension: (Gmail) - C:\Users\Theodore Abramowitz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR HKLM\...\Chrome\Extension: [aaaaahaeginbdcckocjkhbciadcafnep] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaahaeginbdcckocjkhbciadcafnep.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [aaaaahlfahldnilidgnlikdckbfehhca] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaahlfahldnilidgnlikdckbfehhca.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [aaaaaiabcopkplhgaedhbloeejhhankf] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaiabcopkplhgaedhbloeejhhankf.crx [Not Found]
CHR HKU\S-1-5-21-2285157681-2606125537-3038485319-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] -
https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [aaaaahaeginbdcckocjkhbciadcafnep] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaahaeginbdcckocjkhbciadcafnep.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [aaaaahlfahldnilidgnlikdckbfehhca] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaahlfahldnilidgnlikdckbfehhca.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [aaaaaiabcopkplhgaedhbloeejhhankf] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaiabcopkplhgaedhbloeejhhankf.crx [Not Found]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [5164328 2015-05-10] (Emsisoft Ltd)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider) []
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-04-04] (BitRaider, LLC)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1429504 2015-03-04] (Microsoft Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-30] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) []
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-21] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-03-20] (Lenovo(beijing) Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1663880 2014-05-06] ()
S2 MakerBot Conveyor Service; C:\Program Files\MakerBot\MakerWare\conveyor-svc.exe [85504 2015-03-04] (MakerBot) []
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [1872152 2015-05-09] (Maxthon)
R2 UpdateCheck; C:\Program Files (x86)\Coupoon\UpdateCheck.exe [53040 2015-05-20] ()
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2015-03-20] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-07] (Atheros) []
S2 fc472c22; "C:\windows\system32\rundll32.exe" "c:\Program Files (x86)\IncrementModule\IncrementModule.dll",serv
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-04-05] (BitRaider)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R1 epp64; C:\Windows\System32\DRIVERS\epp64.sys [135800 2015-03-24] (Emsisoft GmbH)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2015-04-02] (NetFilterSDK.com)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-09-13] (Synaptics Incorporated)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [1065344 2013-09-10] (Vimicro Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-23 16:01 - 2015-05-23 16:01 - 00021114 _____ () C:\Users\Theodore Abramowitz\Desktop\FRST.txt
2015-05-23 16:00 - 2015-05-23 16:01 - 02108416 _____ (Farbar) C:\Users\Theodore Abramowitz\Desktop\FRST64.exe
2015-05-23 15:49 - 2015-05-23 16:01 - 00000000 ____D () C:\FRST
2015-05-23 15:38 - 2015-05-23 15:38 - 00000000 ____D () C:\Users\Public\Pokki
2015-05-23 15:20 - 2015-05-23 15:34 - 00002222 _____ () C:\EamClean.log
2015-05-23 15:18 - 2015-05-23 15:18 - 00000000 ____D () C:\ProgramData\Emsisoft
2015-05-23 15:12 - 2015-05-23 15:12 - 00001118 _____ () C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2015-05-23 15:12 - 2015-05-23 15:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2015-05-23 15:11 - 2015-05-23 15:57 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2015-05-23 15:11 - 2015-03-24 00:17 - 00135800 _____ (Emsisoft GmbH) C:\windows\system32\Drivers\epp64.sys
2015-05-23 14:54 - 2015-05-23 15:11 - 161971528 _____ (Emsisoft Ltd. ) C:\Users\Theodore Abramowitz\Desktop\EmsisoftAntiMalwareSetup.exe
2015-05-23 14:09 - 2015-05-23 14:09 - 00003266 _____ () C:\windows\System32\Tasks\Trojan Killer
2015-05-23 14:09 - 2015-05-23 14:09 - 00000000 ____D () C:\ProgramData\GridinSoft
2015-05-23 13:52 - 2015-05-23 15:56 - 00003496 _____ () C:\windows\System32\Tasks\gg_uac_daemon_Theodore Abramowitz
2015-05-17 23:07 - 2015-05-23 15:19 - 00000000 ____D () C:\Program Files (x86)\Symbaloo Bookmarker 0.4
2015-05-17 14:43 - 2015-05-17 14:43 - 00000079 _____ () C:\Program Files (x86)\prefs.js
2015-05-16 08:33 - 2015-05-23 13:48 - 00000112 _____ () C:\ProgramData\BYb8XG.dat
2015-05-15 21:29 - 2015-05-16 09:03 - 00000000 ____D () C:\Users\Theodore Abramowitz\Downloads\Stranded.Deep.Alpha.v0.03
2015-05-15 21:23 - 2015-05-15 21:28 - 228252899 ____R () C:\Users\Theodore Abramowitz\Downloads\Stranded.Deep.Alpha.v0.03.zip
2015-05-15 21:11 - 2015-05-16 09:51 - 00000000 ____D () C:\Program Files (x86)\SafeGuard
2015-05-15 21:10 - 2015-05-15 21:10 - 00004004 _____ () C:\windows\System32\Tasks\LaunchPreSignup
2015-05-15 21:10 - 2015-05-15 21:10 - 00000000 _____ () C:\Users\Theodore Abramowitz\AppData\Local\Temp.dat
2015-05-15 21:09 - 2015-05-15 21:09 - 00000000 ____D () C:\ProgramData\cnnkfdmedggkkcojfdggmfimljglolol
2015-05-15 21:08 - 2015-05-23 15:19 - 00000000 ____D () C:\Program Files (x86)\Priceless
2015-05-15 21:08 - 2015-05-23 13:34 - 00000000 ____D () C:\ProgramData\abc
2015-05-15 21:08 - 2015-05-15 21:08 - 00000000 ____D () C:\Program Files\Coupoon
2015-05-15 21:08 - 2015-05-15 21:08 - 00000000 ____D () C:\Program Files (x86)\app_setup
2015-05-15 21:07 - 2015-05-23 15:19 - 00000000 ____D () C:\Program Files (x86)\Coupoon
2015-05-15 20:25 - 2015-05-15 20:27 - 00000000 ____D () C:\Users\Theodore Abramowitz\Downloads\3DMGAME-Stranded.Deep.Alpha.v0.02.Cracked-3DM
2015-05-15 19:39 - 2015-05-15 19:39 - 00000000 ____D () C:\Users\Theodore Abramowitz\Downloads\Portal.2 - SKIDROW
2015-05-15 17:30 - 2015-05-15 17:30 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Roaming\3909
2015-05-15 17:29 - 2015-05-15 17:29 - 00000000 ___HD () C:\windows\msdownld.tmp
2015-05-15 17:29 - 2015-05-15 17:29 - 00000000 ____D () C:\windows\SysWOW64\directx
2015-05-15 17:29 - 2015-05-15 17:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Papers Please
2015-05-15 17:29 - 2015-05-15 17:29 - 00000000 ____D () C:\Program Files (x86)\Papers Please
2015-05-15 17:28 - 2015-05-15 17:28 - 00000000 ____D () C:\Users\Theodore Abramowitz\Downloads\Papers, Please 1.1.60
2015-05-15 17:23 - 2015-05-23 13:41 - 00000024 _____ () C:\Users\Theodore Abramowitz\AppData\Roaming\appdataFr25.bin
2015-05-14 17:44 - 2015-04-30 13:35 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 17:44 - 2015-04-30 13:35 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 17:01 - 2015-05-23 15:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-14 17:01 - 2015-05-14 17:01 - 00001186 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-14 17:01 - 2015-05-14 17:01 - 00001174 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-05-14 17:01 - 2015-05-14 17:01 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Roaming\Mozilla
2015-05-14 17:01 - 2015-05-14 17:01 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Local\Mozilla
2015-05-14 17:01 - 2015-05-14 17:01 - 00000000 ____D () C:\ProgramData\Mozilla
2015-05-14 17:01 - 2015-05-14 17:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-13 18:23 - 2015-04-09 17:34 - 02256896 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
2015-05-13 18:23 - 2015-04-09 17:11 - 01943040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2015-05-13 18:23 - 2015-03-19 18:56 - 00080384 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ahcache.sys
2015-05-13 18:23 - 2015-03-17 10:26 - 00467776 ____C (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2015-05-13 18:23 - 2015-03-08 19:02 - 00057856 ____C (Microsoft Corporation) C:\windows\system32\Drivers\bthhfenum.sys
2015-05-13 18:23 - 2015-03-03 18:32 - 00172544 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Input.Inking.dll
2015-05-13 18:23 - 2015-03-03 18:12 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-13 18:23 - 2015-01-29 17:53 - 02819584 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll
2015-05-13 18:23 - 2014-11-13 23:58 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsDatabase.dll
2015-05-13 18:22 - 2015-04-24 14:32 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2015-05-13 18:22 - 2015-04-02 17:35 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\PhotoMetadataHandler.dll
2015-05-13 18:22 - 2015-04-02 17:14 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhotoMetadataHandler.dll
2015-05-13 18:22 - 2015-04-01 15:22 - 02985984 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbgeng.dll
2015-05-13 18:22 - 2015-04-01 15:20 - 04417536 _____ (Microsoft Corporation) C:\windows\system32\dbgeng.dll
2015-05-13 18:22 - 2015-03-31 20:45 - 01491456 _____ (Microsoft Corporation) C:\windows\system32\dbghelp.dll
2015-05-13 18:22 - 2015-03-31 19:31 - 01207296 _____ (Microsoft Corporation) C:\windows\SysWOW64\dbghelp.dll
2015-05-13 18:22 - 2015-03-12 21:03 - 00239424 ____C (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2015-05-13 18:22 - 2015-03-12 21:03 - 00154432 ____C (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2015-05-13 18:22 - 2015-03-12 19:02 - 00316416 _____ (Microsoft Corporation) C:\windows\system32\Drivers\udfs.sys
2015-05-13 18:22 - 2015-03-12 18:11 - 02162176 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
2015-05-13 18:22 - 2015-03-12 17:39 - 01812992 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
2015-05-13 18:22 - 2015-03-12 17:29 - 00410017 _____ () C:\windows\system32\ApnDatabase.xml
2015-05-13 18:22 - 2015-03-10 18:49 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-05-13 18:22 - 2015-03-10 18:09 - 00021504 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-05-13 18:22 - 2015-03-05 20:08 - 02067968 _____ (Microsoft Corporation) C:\windows\system32\wpdshext.dll
2015-05-13 18:22 - 2015-03-05 19:47 - 01696256 _____ (Microsoft Corporation) C:\windows\system32\wevtsvc.dll
2015-05-13 18:22 - 2015-03-05 19:43 - 01969664 _____ (Microsoft Corporation) C:\windows\SysWOW64\wpdshext.dll
2015-05-13 18:22 - 2015-03-04 16:09 - 01429504 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2015-05-13 18:22 - 2015-02-17 16:19 - 00186368 _____ (Microsoft Corporation) C:\windows\system32\dpapisrv.dll
2015-05-13 07:47 - 2015-04-30 16:05 - 00429568 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-05-13 07:47 - 2015-04-30 15:48 - 00358912 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-05-13 07:47 - 2015-04-21 10:14 - 24971776 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-05-13 07:47 - 2015-04-21 09:50 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-05-13 07:47 - 2015-04-21 09:50 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-05-13 07:47 - 2015-04-21 09:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-05-13 07:47 - 2015-04-21 09:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-05-13 07:47 - 2015-04-21 09:35 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-05-13 07:47 - 2015-04-21 09:31 - 06025728 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-05-13 07:47 - 2015-04-21 09:24 - 19691008 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-05-13 07:47 - 2015-04-21 09:13 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2015-05-13 07:47 - 2015-04-21 09:11 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-05-13 07:47 - 2015-04-21 09:09 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-05-13 07:47 - 2015-04-21 09:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-05-13 07:47 - 2015-04-21 09:07 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-05-13 07:47 - 2015-04-21 09:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-05-13 07:47 - 2015-04-21 09:04 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-05-13 07:47 - 2015-04-21 08:59 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-05-13 07:47 - 2015-04-21 08:58 - 00664576 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-05-13 07:47 - 2015-04-21 08:52 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-05-13 07:47 - 2015-04-21 08:49 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-05-13 07:47 - 2015-04-21 08:49 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-05-13 07:47 - 2015-04-21 08:49 - 00374272 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-05-13 07:47 - 2015-04-21 08:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-05-13 07:47 - 2015-04-21 08:40 - 14401536 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-05-13 07:47 - 2015-04-21 08:38 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-05-13 07:47 - 2015-04-21 08:37 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-05-13 07:47 - 2015-04-21 08:36 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-05-13 07:47 - 2015-04-21 08:32 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-05-13 07:47 - 2015-04-21 08:31 - 04305920 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-05-13 07:47 - 2015-04-21 08:28 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-05-13 07:47 - 2015-04-21 08:27 - 02352128 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-05-13 07:47 - 2015-04-21 08:26 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-05-13 07:47 - 2015-04-21 08:26 - 00327168 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-05-13 07:47 - 2015-04-21 08:25 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-05-13 07:47 - 2015-04-21 08:17 - 12828672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-05-13 07:47 - 2015-04-21 08:15 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-05-13 07:47 - 2015-04-21 08:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-05-13 07:47 - 2015-04-21 08:02 - 01882112 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-05-13 07:47 - 2015-04-21 07:58 - 01310208 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-05-13 07:47 - 2015-04-21 07:56 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-05-13 07:47 - 2015-04-13 15:48 - 04180480 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-05-13 07:47 - 2015-04-09 18:00 - 01996800 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-05-13 07:47 - 2015-04-09 17:50 - 01387008 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-05-13 07:47 - 2015-04-09 17:26 - 01560576 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-05-13 07:47 - 2015-04-08 15:55 - 00410128 _____ (Microsoft Corporation) C:\windows\system32\services.exe
2015-05-13 07:47 - 2015-03-29 22:47 - 00561928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2015-05-13 07:47 - 2015-03-26 20:27 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2015-05-13 07:47 - 2015-03-26 19:50 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2015-05-13 07:47 - 2015-03-26 19:48 - 01441792 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-05-11 22:23 - 2015-05-11 22:23 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Roaming\googleico
2015-05-10 17:37 - 2015-05-23 15:48 - 00000974 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2285157681-2606125537-3038485319-1001UA.job
2015-05-10 17:37 - 2015-05-23 14:48 - 00000922 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2285157681-2606125537-3038485319-1001Core.job
2015-05-10 17:37 - 2015-05-17 14:43 - 00003948 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2285157681-2606125537-3038485319-1001UA
2015-05-10 17:37 - 2015-05-17 14:43 - 00003568 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2285157681-2606125537-3038485319-1001Core
2015-05-10 17:37 - 2015-05-10 17:37 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromecast
2015-05-09 17:49 - 2015-05-23 15:20 - 00000000 ____D () C:\Program Files (x86)\IncrementModule
2015-05-09 17:48 - 2015-05-23 15:19 - 00000000 ____D () C:\Program Files (x86)\Listen and Download Quran
2015-05-09 17:45 - 2015-05-23 15:19 - 00000000 ____D () C:\Program Files (x86)\PriceMinus
2015-05-09 17:44 - 2015-05-23 15:19 - 00000000 ____D () C:\Program Files (x86)\PriceeMinus
2015-05-09 17:44 - 2015-05-17 23:07 - 00000000 ____D () C:\ProgramData\18015872913480936833
2015-05-09 17:44 - 2015-05-09 17:44 - 00000000 ____D () C:\ProgramData\cknofdkngomdkbcppaopfjmnnkepbdln
2015-05-09 07:35 - 2015-05-09 07:55 - 135853638 ____R () C:\Users\Theodore Abramowitz\Downloads\Besiege v0.05.zip
2015-05-08 20:41 - 2015-05-08 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Democracy 3 [GOG.com]
2015-05-08 20:41 - 2015-05-08 20:41 - 00000000 ____D () C:\GOG Games
2015-05-08 20:19 - 2015-05-08 20:33 - 148013192 ____R (GOG.com ) C:\Users\Theodore Abramowitz\Downloads\setup_democracy3_2.0.0.3.exe
2015-05-08 07:40 - 2015-05-08 07:40 - 00000000 ____D () C:\Users\Default\AppData\Local\Google
2015-05-08 07:40 - 2015-05-08 07:40 - 00000000 ____D () C:\Users\Default User\AppData\Local\Google
2015-04-30 16:07 - 2015-04-30 16:08 - 23315064 _____ (Popcorn Official) C:\Users\Theodore Abramowitz\Downloads\Popcorn-Time-0.3.7.2-Setup.exe
2015-04-24 20:36 - 2015-04-24 20:36 - 00000324 ____N () C:\windows\DtcInstall.log
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-23 16:01 - 2015-03-29 11:33 - 00003598 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2285157681-2606125537-3038485319-1001
2015-05-23 16:00 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\sru
2015-05-23 15:57 - 2015-03-29 15:22 - 00000000 ___RD () C:\Users\Theodore Abramowitz\Google Drive
2015-05-23 15:56 - 2015-03-29 14:49 - 00000000 ___DO () C:\Users\Theodore Abramowitz\OneDrive
2015-05-23 15:56 - 2015-03-29 11:33 - 00000912 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-23 15:55 - 2015-03-29 11:50 - 09334456 _____ () C:\Users\Public\CAFADEBUG.log
2015-05-23 15:55 - 2015-03-29 11:37 - 00027568 _____ () C:\windows\setupact.log
2015-05-23 15:55 - 2015-03-20 07:58 - 00006656 _____ () C:\windows\system32\VfService.trf
2015-05-23 15:55 - 2013-08-22 07:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-05-23 15:55 - 2013-08-22 06:25 - 00524288 ___SH () C:\windows\system32\config\BBI
2015-05-23 15:46 - 2015-03-29 11:33 - 00000916 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-23 15:45 - 2015-03-29 11:32 - 00003966 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{CE14E2CC-8996-4195-AA0B-EFB5C8B2906B}
2015-05-23 15:34 - 2015-03-20 07:02 - 01364656 _____ () C:\windows\WindowsUpdate.log
2015-05-23 15:20 - 2015-03-29 11:48 - 00017128 _____ () C:\windows\PFRO.log
2015-05-23 13:49 - 2015-03-29 12:40 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-21 16:01 - 2015-03-29 11:34 - 00002214 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-19 19:56 - 2013-08-22 08:20 - 00000000 ____D () C:\windows\CbsTemp
2015-05-19 19:55 - 2015-04-04 14:19 - 00000000 ___SD () C:\windows\SysWOW64\GWX
2015-05-19 19:55 - 2015-04-04 14:19 - 00000000 ___SD () C:\windows\system32\GWX
2015-05-19 08:00 - 2015-04-03 11:03 - 00000000 ____D () C:\Users\Theodore Abramowitz\Desktop\Random Applications
2015-05-17 20:48 - 2015-03-29 11:27 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Local\Packages
2015-05-17 20:48 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\AppReadiness
2015-05-17 20:36 - 2015-03-30 10:54 - 00000000 ____D () C:\Users\Theodore Abramowitz\Desktop\Various Files
2015-05-17 20:35 - 2015-03-29 12:17 - 00426496 ___SH () C:\Users\Theodore Abramowitz\Desktop\Thumbs.db
2015-05-16 18:41 - 2015-03-29 11:33 - 00003888 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-16 18:41 - 2015-03-29 11:33 - 00003652 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-16 11:52 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\rescache
2015-05-16 11:14 - 2015-03-30 12:01 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Roaming\uTorrent
2015-05-16 09:50 - 2015-04-01 09:57 - 00000000 ____D () C:\Users\Theodore Abramowitz\Desktop\Game Library
2015-05-16 08:29 - 2014-03-18 02:53 - 00865408 _____ () C:\windows\system32\PerfStringBackup.INI
2015-05-15 21:09 - 2015-03-20 07:50 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-15 21:08 - 2015-04-04 21:27 - 00000005 _____ () C:\end
2015-05-15 19:37 - 2015-04-07 18:48 - 00000483 _____ () C:\windows\system32\conveyor-svc.log
2015-05-15 19:36 - 2013-08-22 07:44 - 00346744 _____ () C:\windows\system32\FNTCACHE.DAT
2015-05-14 19:17 - 2013-08-22 08:36 - 00000000 ___RD () C:\windows\ImmersiveControlPanel
2015-05-14 19:17 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\system32\AdvancedInstallers
2015-05-14 18:46 - 2015-03-30 18:20 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Local\wf-launcher
2015-05-14 18:46 - 2015-03-30 18:20 - 00000000 ____D () C:\ProgramData\GFACE
2015-05-14 15:54 - 2015-04-04 15:11 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-14 15:54 - 2015-04-04 15:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-05-14 15:53 - 2015-03-31 08:32 - 00000000 ____D () C:\windows\system32\MRT
2015-05-14 15:45 - 2015-04-04 15:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-14 15:42 - 2014-03-18 02:38 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-13 19:23 - 2015-03-29 11:29 - 00000000 ____D () C:\Users\Theodore Abramowitz\Documents\Bluetooth Folder
2015-05-11 20:43 - 2015-03-29 12:14 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Local\CrashDumps
2015-05-11 07:09 - 2015-03-29 14:32 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Local\Spotify
2015-05-11 07:09 - 2015-03-29 14:31 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Roaming\Spotify
2015-05-10 17:37 - 2015-03-29 11:33 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Local\Google
2015-05-09 07:31 - 2015-04-11 17:40 - 00000000 ____D () C:\Users\Theodore Abramowitz\AppData\Local\MDF Open File Tool
2015-05-08 20:43 - 2015-04-01 20:32 - 00000000 ____D () C:\Users\Theodore Abramowitz\Documents\My Games
2015-05-08 20:43 - 2015-04-01 20:07 - 00062966 _____ () C:\windows\DirectX.log
2015-05-08 07:40 - 2015-03-29 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-05-05 10:59 - 2015-03-31 08:52 - 00792568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-05-05 10:59 - 2015-03-31 08:52 - 00178168 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-30 10:07 - 2015-03-31 08:32 - 140425016 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\windows\ToastData
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\SysWOW64\sppui
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\SysWOW64\setup
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\SysWOW64\migwiz
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\SysWOW64\Com
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\MediaViewer
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\FileManager
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\Camera
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2015-04-24 20:30 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-24 20:30 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\SysWOW64\oobe
2015-04-24 20:30 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\SysWOW64\Dism
2015-04-24 20:30 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\servicing
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ___SD () C:\windows\system32\dsc
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\WinBioPlugIns
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\SystemResetPlatform
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\sppui
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\setup
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\migwiz
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\system32\Com
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\windows\IME
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer
2015-04-24 20:29 - 2013-08-22 08:36 - 00000000 ____D () C:\Program Files (x86)\Windows Multimedia Platform
2015-04-24 20:29 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\system32\Sysprep
2015-04-24 20:29 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\system32\oobe
2015-04-24 20:29 - 2013-08-22 06:36 - 00000000 ____D () C:\windows\system32\Dism
==================== Files in the root of some directories =======
2015-05-17 14:43 - 2015-05-17 14:43 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2015-05-15 17:23 - 2015-05-23 13:41 - 0000024 _____ () C:\Users\Theodore Abramowitz\AppData\Roaming\appdataFr25.bin
2015-04-12 14:07 - 2015-04-12 14:07 - 0000880 _____ () C:\Users\Theodore Abramowitz\AppData\Local\recently-used.xbel
2015-05-15 21:10 - 2015-05-15 21:10 - 0000000 _____ () C:\Users\Theodore Abramowitz\AppData\Local\Temp.dat
2015-05-16 08:33 - 2015-05-23 13:48 - 0000112 _____ () C:\ProgramData\BYb8XG.dat
2015-03-20 07:16 - 2015-03-20 07:16 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\ProgramData\BYb8XG.dat
Some files in TEMP:
====================
C:\Users\Theodore Abramowitz\AppData\Local\Temp\APNSetup.exe
C:\Users\Theodore Abramowitz\AppData\Local\Temp\CloudBackup4845.exe
C:\Users\Theodore Abramowitz\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\Theodore Abramowitz\AppData\Local\Temp\MYPCBU.exe
C:\Users\Theodore Abramowitz\AppData\Local\Temp\nst17A3.exe
C:\Users\Theodore Abramowitz\AppData\Local\Temp\StrandedDeepTorrentOyunindir__11652_il176720.exe
C:\Users\Theodore Abramowitz\AppData\Local\Temp\VOPackage.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-21 18:07
==================== End of log ============================