Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by harri_000 (administrator) on HARRYSPC (19-03-2016 12:11:45)
Running from C:\Users\harri_000\Desktop
Loaded Profiles: harri_000 (Available Profiles: harri_000 & ukbub_000 & Administrator)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(Amazon Inc.) C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_filter.exe
(Sophos Limited) C:\Program Files (x86)\Common Files\Sophos\Web Intelligence\swi_fc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
() C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo) C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSYNC.EXE
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\Lenovo PhoneCompanion\adb.exe
(Microsoft Corporation) C:\Windows\System32\MRT.exe
(Microsoft Corporation) C:\Windows\System32\MRT.exe
(Microsoft Corporation) C:\Windows\System32\MRT.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\MRT.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Camtasia Studio 8\TscHelp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Pokki) C:\Users\harri_000\AppData\Local\Pokki\Engine\HostAppService.exe
(Pokki) C:\Users\harri_000\AppData\Local\Pokki\Engine\HostAppService.exe
(Pokki) C:\Users\harri_000\AppData\Local\Pokki\Engine\StartMenuIndexer.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_182.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_21_0_0_182.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-27] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [PhoneCompanion] => C:\Program Files\Lenovo PhoneCompanion\Phone Companion.exe [836592 2015-03-10] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16094704 2015-03-10] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [10842096 2015-03-10] (Lenovo(beijing) Limited)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2856616 2014-12-22] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-04-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [110344 2014-09-09] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [492808 2014-09-09] (CyberLink Corp.)
HKLM-x32\...\Run: [snp2uvc] => C:\windows\vsnp2uvc.exe
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1592104 2015-06-30] (Sophos Limited)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596016 2016-01-29] (Oracle Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [134784 2014-02-26] (Qualcomm®Atheros®)
HKU\S-1-5-21-2715607831-444694372-1136969816-1002\...\Run: [Pokki] => C:\Users\harri_000\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe [6513480 2014-10-11] (Pokki)
HKU\S-1-5-21-2715607831-444694372-1136969816-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3014224 2016-02-05] (Valve Corporation)
HKU\S-1-5-21-2715607831-444694372-1136969816-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2715607831-444694372-1136969816-1002\...\RunOnce: [Application Restart #2] => C:\Users\harri_000\AppData\Local\Pokki\Engine\HostAppService.exe [7770440 2014-10-11] (Pokki)
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll [217672 2015-01-20] (Sophos Limited)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL => C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll [275352 2015-01-20] (Sophos Limited)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{15F46E5E-5060-428B-ABAF-C29644503F73}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{661DD5AC-E1B2-4100-A37D-0ED4DADA12F5}: [DhcpNameServer] 150.204.1.2
Internet Explorer:
==================
HKU\S-1-5-21-2715607831-444694372-1136969816-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://
www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase=bds-p17&tbrId=v1_abb-channel-17_0_1201_1403_20160227_AU_ie_sp_
HKU\S-1-5-21-2715607831-444694372-1136969816-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-2715607831-444694372-1136969816-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://mystart.lenovo.com
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2715607831-444694372-1136969816-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2715607831-444694372-1136969816-1002 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://
www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ie_us_display?ie=UTF8&tagbase=bds-p17&tbrId=v1_abb-channel-17_0_1201_1403_20160227_AU_ie_ds_&tag=bds-p17-serp-us-ie-20&query={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-02-05] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_74\bin\ssv.dll [2016-03-01] (Oracle Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-02-04] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-03-01] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-27] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-27] (Oracle Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-04] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-04] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-04] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-04] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\harri_000\AppData\Roaming\Mozilla\Firefox\Profiles\1bwdz6kn.default
FF NewTab: hxxps://
www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p17_serp_ff_us_display?ie=UTF8&tagbase=bds-p17&tbrId=v1_abb-channel-17_0_1201_1403_20160227_AU_ff_nt_
FF SearchEngineOrder.1: Amazon
FF Homepage: hxxps://
www.google.com.au/?gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-11] ()
FF Plugin: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-03-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-03-01] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-02-04] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-13] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-10] (Google Inc.)
FF Plugin HKU\S-1-5-21-2715607831-444694372-1136969816-1002: @nsroblox.roblox.com/launcher -> C:\Users\harri_000\AppData\Local\Roblox\Versions\version-0ce38a2c538e4023\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-2715607831-444694372-1136969816-1002: @nsroblox.roblox.com/launcher64 -> C:\Users\harri_000\AppData\Local\Roblox\Versions\version-0ce38a2c538e4023\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Extension: Adblock Plus Pop-up Addon - C:\Users\harri_000\AppData\Roaming\Mozilla\Firefox\Profiles\1bwdz6kn.default\extensions\adblockpopups@jessehakanen.net.xpi [2016-01-28]
FF Extension: Amazon Assistant for Firefox - C:\Users\harri_000\AppData\Roaming\Mozilla\Firefox\Profiles\1bwdz6kn.default\Extensions\abb@amazon.com.xpi [2016-02-27]
FF Extension: YouTube™ AdBlock - C:\Users\harri_000\AppData\Roaming\Mozilla\Firefox\Profiles\1bwdz6kn.default\Extensions\jid1-w4wG5nJhx4LJZr@jetpack.xpi [2016-01-28]
FF Extension: Adblock Plus - C:\Users\harri_000\AppData\Roaming\Mozilla\Firefox\Profiles\1bwdz6kn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-02-24]
FF Extension: Adblock Edge - C:\Users\harri_000\AppData\Roaming\Mozilla\Firefox\Profiles\1bwdz6kn.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2016-01-28]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
Chrome:
=======
CHR HomePage: Default -> amazon.com/websearch/?ie=UTF8__PARAM__
CHR StartupUrls: Default -> "hxxps://
www.google.com.au/"
CHR Profile: C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-28]
CHR Extension: (Google Docs) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-28]
CHR Extension: (Google Drive) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-28]
CHR Extension: (Link All) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbplhdcnpcenkdciibplnkgmiffjfnni [2016-01-30]
CHR Extension: (YouTube) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-28]
CHR Extension: (Adblock Plus) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-05]
CHR Extension: (Google Search) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-28]
CHR Extension: (Agar.io Powerups) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\efedcgdhahoncejkihgfnecicebndbhc [2016-01-30]
CHR Extension: (Google Sheets) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-28]
CHR Extension: (Supernova) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gegpgpjbmbggplclldecdbpcmopmlbll [2016-02-05]
CHR Extension: (Google Docs Offline) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-05]
CHR Extension: (AdBlock) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-09]
CHR Extension: (ArcadeCake) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\iehadeafgjbogbeghjncelieafmgmcnn [2016-02-05]
CHR Extension: (Omnibox Twitter) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijepoopnmhdclmamigdibjmdpmdmmmfe [2016-01-30]
CHR Extension: (KingsRoad) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbcbablgmkkdnioiekpgjfacejkfomlg [2016-01-30]
CHR Extension: (Skype) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-01-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-28]
CHR Extension: (Amazon Smart Search) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf [2016-03-09]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2016-03-09]
CHR Extension: (Gmail) - C:\Users\harri_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-28]
CHR HKU\S-1-5-21-2715607831-444694372-1136969816-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ooebgdicanjhnamfmdlmlbcnkgehkkmf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2715607831-444694372-1136969816-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Amazon 1Button App Service; C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe [436032 2016-02-17] (Amazon Inc.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-19] (Advanced Micro Devices, Inc.) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [319104 2014-02-26] (Windows (R) Win 7 DDK provider) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [592880 2014-07-10] ()
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2804976 2016-02-04] (Microsoft Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [561408 2014-09-23] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584664 2015-12-14] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-03-10] (Lenovo(beijing) Limited)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [272776 2014-09-04] ()
R2 LUService; C:\Program Files (x86)\Lenovo\Lenovo Updates\LUService.exe [38896 2014-02-18] (Lenovo(beijing) Limited)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [2451880 2016-03-10] (Maxthon)
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-13] (Nitro PDF Software)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionPusher.exe [288240 2015-03-10] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo PhoneCompanion\PhoneCompanionVap.exe [308720 2015-03-10] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-25] ()
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [288552 2014-09-16] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [208168 2014-09-16] (Sophos Limited)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [340264 2015-06-30] (Sophos Limited)
R2 swi_filter; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_filter.exe [300840 2015-01-20] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3274536 2015-01-20] (Sophos Limited)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [220840 2014-12-22] (Synaptics Incorporated)
R2 tbaseprovisioning; C:\Windows\SysWOW64\tbaseprovisioning.exe [51712 2014-02-25] (Advanced Micro Devices, Inc.)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [68880 2015-03-10] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-02-26] (Atheros) [File not signed]
S2 CltMngSvc; C:\PROGRA~2\LenovoBrowserGuard\Main\bin\CltMngSvc.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 amdkmcsp; C:\Windows\system32\DRIVERS\amdkmcsp.sys [85704 2014-02-25] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-13] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\Windows\System32\DRIVERS\amdpsp.sys [230088 2014-02-25] (Advanced Micro Devices, Inc. )
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [224992 2013-11-01] (AppEx Networks Corporation)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3892224 2014-03-07] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-12] (Advanced Micro Devices)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-26] (Qualcomm Atheros)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-13] (CyberLink)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-19] (Intel Corporation)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [161024 2014-09-16] (Sophos Limited)
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [2853400 2014-01-24] (Sonix Co. Ltd.)
S4 SophosBootDriver; C:\Windows\system32\DRIVERS\SophosBootDriver.sys [27904 2014-09-16] (Sophos Limited)
R1 swi_callout; C:\Windows\system32\DRIVERS\swi_callout.sys [32512 2015-11-20] (Sophos Limited)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-19 12:11 - 2016-03-19 12:13 - 00026471 _____ C:\Users\harri_000\Desktop\FRST.txt
2016-03-19 12:10 - 2016-03-19 12:11 - 00000000 ____D C:\FRST
2016-03-19 12:08 - 2016-03-19 12:08 - 02374144 _____ (Farbar) C:\Users\harri_000\Desktop\FRST64.exe
2016-03-19 00:13 - 2016-03-19 00:13 - 09711784 _____ C:\Users\harri_000\Downloads\BungeeCord.jar
2016-03-18 12:42 - 2016-03-18 12:42 - 00000000 ____D C:\Users\harri_000\AppData\Local\UWKProcess
2016-03-18 12:41 - 2016-03-18 12:41 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-03-18 12:37 - 2016-03-18 12:38 - 00000000 ____D C:\Users\harri_000\AppData\Local\GeometryDash
2016-03-18 08:34 - 2016-03-18 08:34 - 00000000 ____D C:\WINDOWS\A7E07C2B2220441587E3784D5814BC93.TMP
2016-03-15 14:55 - 2016-03-19 02:43 - 00002100 _____ C:\Users\harri_000\Desktop\NoPlugins.jar
2016-03-15 10:31 - 2016-01-11 02:41 - 01707008 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2016-03-15 10:31 - 2016-01-11 02:31 - 01344512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2016-03-15 10:30 - 2016-01-16 02:56 - 02487296 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2016-03-15 10:30 - 2016-01-16 02:45 - 01482240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2016-03-15 10:30 - 2015-12-21 00:56 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msra.exe
2016-03-15 09:12 - 2016-02-07 04:08 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-15 09:12 - 2016-02-05 03:24 - 00603648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-15 09:12 - 2016-02-05 03:02 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-15 06:31 - 2016-03-17 01:03 - 00001730 _____ C:\Users\harri_000\Desktop\Plugin1.jar
2016-03-15 05:18 - 2016-03-15 05:19 - 20103125 _____ C:\Users\harri_000\Downloads\spigot-1.8.8.jar
2016-03-15 04:41 - 2016-03-15 04:41 - 00000000 ____D C:\Users\harri_000\.tooling
2016-03-15 04:36 - 2016-03-15 04:36 - 00006098 _____ C:\Users\harri_000\Downloads\ItemCommand(1).jar
2016-03-15 04:35 - 2016-03-19 01:09 - 00000000 ____D C:\Users\harri_000\AppData\Local\Eclipse
2016-03-15 04:32 - 2016-03-15 04:32 - 00001025 _____ C:\Users\harri_000\Desktop\Eclipse Java Mars.lnk
2016-03-15 04:32 - 2016-03-15 04:32 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Eclipse
2016-03-15 04:26 - 2016-03-15 04:26 - 00000000 ____D C:\Users\harri_000\eclipse
2016-03-15 04:23 - 2016-03-19 01:10 - 00000000 ____D C:\Users\harri_000\.p2
2016-03-15 04:23 - 2016-03-15 05:54 - 00000000 ____D C:\Users\harri_000\.eclipse
2016-03-15 04:21 - 2016-03-15 04:22 - 46881880 _____ C:\Users\harri_000\Desktop\eclipse-inst-win64.exe
2016-03-15 03:08 - 2016-03-15 03:08 - 00000000 ____D C:\Users\harri_000\AppData\Local\ElevatedDiagnostics
2016-03-14 18:09 - 2016-03-14 18:09 - 00000053 _____ C:\Users\harri_000\Downloads\google2814be1caad83019.html
2016-03-13 10:58 - 2016-03-13 11:01 - 00000000 ____D C:\Users\harri_000\Desktop\Wanted Laptops
2016-03-09 21:16 - 2016-03-09 21:17 - 05635440 _____ (MY.COM B.V.) C:\Users\harri_000\Downloads\ArmoredWarfareMycomLoader_bdc11d15b62785984415decda4bc8cdc_A_en.exe
2016-03-08 23:06 - 2015-11-20 02:55 - 00032512 _____ (Sophos Limited) C:\WINDOWS\system32\Drivers\swi_callout.sys
2016-03-07 00:41 - 2016-03-07 00:41 - 00000894 _____ C:\Users\harri_000\Downloads\Pictures - Shortcut.lnk
2016-03-06 21:47 - 2016-03-06 21:47 - 00009754 _____ C:\Users\harri_000\Downloads\OnslaughtSuite.jar
2016-03-04 15:35 - 2016-03-04 15:35 - 00000000 ____D C:\Users\harri_000\Documents\Universe Sandbox ²
2016-03-02 21:24 - 2016-03-02 21:24 - 00016394 _____ C:\Users\harri_000\Downloads\ItemCommand.jar
2016-03-02 17:24 - 2016-03-02 17:24 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\Blender Foundation
2016-03-02 16:51 - 2016-03-02 16:51 - 00000000 ____D C:\Users\harri_000\.thumbnails
2016-03-02 16:47 - 2016-03-02 16:47 - 00000000 ____D C:\Users\harri_000\Desktop\blender-2.76b-windows64
2016-03-02 07:17 - 2016-03-02 07:17 - 00120002 _____ C:\Users\harri_000\Downloads\CratesPlus-3.1.5.jar
2016-03-01 22:39 - 2016-03-07 01:08 - 00000609 _____ C:\Users\harri_000\AppData\Roaming\jd-gui.cfg
2016-03-01 22:20 - 2016-03-01 22:20 - 08764679 _____ C:\Users\harri_000\Desktop\jd-gui-1.4.0.jar
2016-03-01 22:06 - 2016-03-01 22:06 - 00110176 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2016-03-01 22:04 - 2016-03-01 22:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2016-03-01 22:02 - 2016-03-01 22:05 - 00000000 ____D C:\Program Files\Java
2016-03-01 21:57 - 2016-03-01 21:59 - 196405336 _____ (Oracle Corporation) C:\Users\harri_000\Downloads\jdk-8u74-windows-x64.exe
2016-03-01 17:28 - 2016-03-01 17:28 - 00000392 _____ C:\Users\harri_000\Downloads\public.key
2016-02-27 12:32 - 2016-03-11 07:03 - 00004612 _____ C:\WINDOWS\System32\Tasks\DistromaticSearchProtect-hourly
2016-02-27 12:32 - 2016-02-27 12:32 - 00004488 _____ C:\WINDOWS\System32\Tasks\DistromaticUpdater-periodic
2016-02-27 12:32 - 2016-02-27 12:32 - 00004090 _____ C:\WINDOWS\System32\Tasks\DistromaticSearchProtect-logon
2016-02-27 12:32 - 2016-02-27 12:32 - 00003964 _____ C:\WINDOWS\System32\Tasks\DistromaticUpdater-logon
2016-02-27 12:32 - 2016-02-27 12:32 - 00000000 ____D C:\Users\harri_000\AppData\Local\Amazon Browser Settings
2016-02-27 12:31 - 2016-02-27 12:32 - 00000000 ____D C:\Program Files (x86)\Amazon Browser Settings
2016-02-27 12:09 - 2016-02-27 12:09 - 862817072 _____ C:\WINDOWS\MEMORY.DMP
2016-02-27 12:09 - 2016-02-27 12:09 - 00281584 _____ C:\WINDOWS\Minidump\022716-55703-01.dmp
2016-02-27 12:09 - 2016-02-27 12:09 - 00000000 ____D C:\WINDOWS\Minidump
2016-02-26 20:32 - 2016-02-26 20:41 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\.technic
2016-02-26 20:30 - 2016-02-26 20:30 - 04734664 _____ () C:\Users\harri_000\Desktop\TechnicLauncher.exe
2016-02-25 08:42 - 2016-02-25 08:42 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\TechSmith
2016-02-25 08:41 - 2016-03-13 14:50 - 00000000 ____D C:\Users\harri_000\Documents\Camtasia Studio
2016-02-25 08:41 - 2016-02-25 08:41 - 259967288 _____ C:\Users\harri_000\Downloads\camtasia.exe
2016-02-25 08:41 - 2016-02-25 08:41 - 00000000 ____D C:\Users\harri_000\AppData\Local\TechSmith
2016-02-25 08:40 - 2016-02-25 08:40 - 00001195 _____ C:\Users\Public\Desktop\Camtasia Studio 8.lnk
2016-02-25 08:40 - 2016-02-25 08:40 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2016-02-25 08:40 - 2016-02-25 08:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2016-02-25 08:39 - 2016-02-25 08:39 - 00000000 ____D C:\ProgramData\TechSmith
2016-02-25 08:39 - 2016-02-25 08:39 - 00000000 ____D C:\Program Files (x86)\TechSmith
2016-02-25 08:39 - 2016-02-25 08:39 - 00000000 ____D C:\Program Files (x86)\QuickTime
2016-02-25 08:22 - 2016-02-25 08:26 - 259967288 _____ C:\Users\harri_000\Desktop\camtasia.exe
2016-02-22 12:00 - 2016-02-22 12:00 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\PeaZip
2016-02-22 11:58 - 2016-02-22 11:58 - 00001002 _____ C:\Users\harri_000\Desktop\PeaZip.lnk
2016-02-22 11:58 - 2016-02-22 11:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeaZip
2016-02-22 11:58 - 2016-02-22 11:58 - 00000000 ____D C:\Program Files (x86)\PeaZip
2016-02-19 16:39 - 2016-02-19 16:45 - 00000000 ____D C:\Users\harri_000\Desktop\Desktop BG
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-19 12:09 - 2016-01-30 07:50 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\Skype
2016-03-19 12:03 - 2015-11-10 21:00 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\.minecraft
2016-03-19 11:53 - 2016-01-28 17:26 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2715607831-444694372-1136969816-1002
2016-03-19 11:51 - 2014-03-18 19:53 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-19 11:51 - 2013-08-22 23:36 - 00000000 ____D C:\WINDOWS\Inf
2016-03-19 11:49 - 2016-02-11 10:04 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-03-19 11:49 - 2016-01-28 17:33 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-19 10:22 - 2016-01-30 15:16 - 00000000 ____D C:\Users\harri_000\AppData\Local\CrashDumps
2016-03-19 10:22 - 2016-01-28 17:30 - 00002134 _____ C:\Users\harri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk
2016-03-19 10:22 - 2016-01-28 17:13 - 00000000 ____D C:\Users\harri_000\AppData\Local\Pokki
2016-03-19 02:49 - 2015-11-10 20:59 - 00000000 ____D C:\Users\harri_000\Desktop\My Server
2016-03-18 15:11 - 2016-01-28 18:37 - 00000000 ____D C:\Program Files (x86)\Steam
2016-03-18 13:45 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\rescache
2016-03-18 11:56 - 2015-11-10 20:59 - 00000000 ____D C:\Users\harri_000\Desktop\TGB yt
2016-03-16 07:58 - 2016-01-28 18:29 - 00003104 _____ C:\WINDOWS\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-2715607831-444694372-1136969816-1002
2016-03-16 07:58 - 2015-11-10 20:55 - 00000000 ___DO C:\Users\harri_000\OneDrive
2016-03-15 12:49 - 2013-08-23 01:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-15 12:49 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-15 12:48 - 2013-08-23 01:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-15 10:02 - 2016-01-28 17:36 - 00002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-15 10:02 - 2016-01-28 17:36 - 00002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-15 04:41 - 2016-01-28 17:13 - 00000000 ____D C:\Users\harri_000
2016-03-15 04:23 - 2015-11-30 14:40 - 00000000 ____D C:\Users\harri_000\.oracle_jre_usage
2016-03-15 03:11 - 2015-11-10 20:51 - 00000000 ____D C:\Users\harri_000\Documents\Bluetooth Folder
2016-03-12 13:09 - 2015-03-10 15:04 - 00000000 ____D C:\ProgramData\Energy Manager
2016-03-11 21:49 - 2016-02-11 10:04 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-03-11 07:11 - 2015-03-10 14:47 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2016-03-11 07:04 - 2015-11-26 17:32 - 00000000 ____D C:\Users\harri_000\Desktop\Pranks, Hacks, Coding
2016-03-11 07:01 - 2016-01-28 17:21 - 00001279 _____ C:\Users\harri_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wi-FiHotspotChgToast.lnk
2016-03-11 07:01 - 2016-01-28 17:21 - 00000000 ____D C:\ProgramData\LU
2016-03-10 19:11 - 2015-03-10 14:11 - 00387834 _____ C:\WINDOWS\SysWOW64\rootpa.e2e
2016-03-10 19:11 - 2013-08-23 00:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-10 18:01 - 2015-11-10 20:59 - 00000000 ____D C:\Users\harri_000\Desktop\Kimberley College Stuff
2016-03-09 02:54 - 2013-08-23 01:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-03-03 11:10 - 2016-01-28 18:43 - 00000000 ____D C:\Users\harri_000\AppData\Local\Steam
2016-03-01 22:06 - 2016-01-28 18:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-27 16:53 - 2016-02-05 17:28 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2016-02-27 16:53 - 2016-02-05 17:28 - 00000000 ___SD C:\WINDOWS\system32\GWX
2016-02-27 16:51 - 2016-01-29 11:08 - 00000000 ____D C:\Windows.old
2016-02-27 12:52 - 2013-08-23 01:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-02-27 12:48 - 2015-03-10 14:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-02-27 12:29 - 2016-01-28 18:55 - 00000000 ____D C:\ProgramData\Oracle
2016-02-27 12:29 - 2016-01-28 18:55 - 00000000 ____D C:\Program Files (x86)\Java
2016-02-27 12:25 - 2016-01-28 18:55 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-02-26 10:32 - 2015-03-10 14:03 - 00000000 ____D C:\ProgramData\Package Cache
2016-02-25 08:43 - 2016-01-28 18:47 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\Minecraft
2016-02-24 01:53 - 2016-01-30 07:50 - 00000000 ____D C:\ProgramData\Skype
2016-02-22 18:58 - 2016-01-31 13:00 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-22 18:48 - 2016-01-31 13:00 - 146614896 ____N (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-22 01:22 - 2016-01-28 18:08 - 00000000 ____D C:\Users\harri_000\AppData\Roaming\Notepad++
2016-02-19 16:49 - 2015-12-27 13:04 - 00000000 ____D C:\Users\harri_000\Desktop\DS4Windows
==================== Files in the root of some directories =======
2016-03-01 22:39 - 2016-03-07 01:08 - 0000609 _____ () C:\Users\harri_000\AppData\Roaming\jd-gui.cfg
2015-03-10 14:07 - 2015-03-10 14:07 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\Users\harri_000\Firefox Setup Stub 42.0.exe
Some files in TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\Lenovo.TVT.CustomerFeedback.Agent.exe
C:\Users\Administrator\AppData\Local\Temp\PokkiPlatform.exe
C:\Users\harri_000\AppData\Local\Temp\bdfilters.dll
C:\Users\harri_000\AppData\Local\Temp\jansi-64-1158764983418586976.dll
C:\Users\harri_000\AppData\Local\Temp\jansi-64-4986555475716331892.dll
C:\Users\harri_000\AppData\Local\Temp\jansi-64-6621651041921177134.dll
C:\Users\harri_000\AppData\Local\Temp\jansi-64-8924181900122600197.dll
C:\Users\harri_000\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\harri_000\AppData\Local\Temp\npp.6.9.Installer.exe
C:\Users\harri_000\AppData\Local\Temp\xmlUpdater.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-10 19:22
==================== End of FRST.txt ============================