FRST Log
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-06-2014
Ran by AnitaHY (administrator) on AHY-ULTBK on 10-06-2014 22:17:15
Running from C:\Users\AnitaHY\Desktop
Platform: Windows 8.1 (Update 1) (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
https://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html
Download link for 64-Bit Version:
https://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\Dragon Assistant\Core\DACore.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ismagent.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\windows\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-08-02] (Intel Corporation)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253952 2013-05-07] (Realtek Semiconductor Corporation)
HKLM\...\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2013-11-05] (Lenovo)
HKLM\...\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2013-11-05] ()
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2013-11-05] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2013-11-05] (Lenovo(beijing) Limited)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [909016 2013-10-21] (Conexant Systems, Inc.)
HKLM-x32\...\Run: [Lenovo App Shop] => C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\ismagent.exe [156000 2013-07-18] (Intel Corporation)
HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [90640 2013-07-09] (Lenovo)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5181456 2014-05-13] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2316213231-900153102-689936460-1001\...\Run: [EPSON NX430 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIHBA.EXE [232448 2011-01-20] (SEIKO EPSON CORPORATION)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo13.msn.com/?pc=LCJB
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://home.lenovo.com
SearchScopes: HKLM - DefaultScope {7FD14275-BA35-4235-9CD9-BFCD1CE3CE59} URL =
http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {7FD14275-BA35-4235-9CD9-BFCD1CE3CE59} URL =
http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
SearchScopes: HKLM-x32 - {7FD14275-BA35-4235-9CD9-BFCD1CE3CE59} URL =
http://www.bing.com/search?q={searchTerms}&form=IE11TR&src=IE11TR&pc=LCJB
SearchScopes: HKCU - {7FD14275-BA35-4235-9CD9-BFCD1CE3CE59} URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\AnitaHY\AppData\Roaming\Mozilla\Firefox\Profiles\5xg9r6le.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: intel.com/AppUp - C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp.dll (Intel)
FF Plugin HKCU: intel.com/AppUpx64 - C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp_x64.dll (Intel)
FF Extension: Adblock Plus - C:\Users\AnitaHY\AppData\Roaming\Mozilla\Firefox\Profiles\5xg9r6le.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-14]
==================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3644432 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [292424 2014-05-13] (AVG Technologies CZ, s.r.o.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [56832 2013-08-28] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2266296 2014-05-16] (Microsoft Corporation)
R2 DACoreService; C:\Program Files (x86)\Nuance\Dragon Assistant\Core\DACore.exe [432528 2013-05-02] (Nuance Communications, Inc.)
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [115632 2013-08-02] (Intel Corporation)
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116656 2013-08-02] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148688 2013-08-02] (Intel Corporation)
R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [124880 2013-08-02] (Intel Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-19] (Intel Corporation)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2013-11-05] (Lenovo)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2013-08-17] (Nitro PDF Software)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [162600 2013-08-30] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [249872 2013-11-05] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [328720 2013-11-05] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2013-11-05] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-23] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-23] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [32528 2013-11-05] (Lenovo)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [236312 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [191768 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [323352 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130328 2014-05-13] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [274712 2014-03-31] (AVG Technologies CZ, s.r.o.)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-12] (Windows (R) Win 7 DDK provider)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [143568 2013-08-02] (Intel Corporation)
R3 DptfDevGen; C:\Windows\system32\DRIVERS\DptfDevGen.sys [76432 2013-08-02] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [114680 2013-08-02] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [287160 2013-08-02] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494272 2013-08-02] (Intel Corporation)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-09] (Intel Corporation)
R0 IntelHSWPcc; C:\Windows\System32\drivers\IntelPcc.sys [74344 2013-07-02] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-10] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-19] (Intel Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [547032 2013-07-03] (Realtek Semiconductor Corporation)
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [2968280 2013-11-15] (Realtek Semiconductor Corporation )
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8247640 2013-07-19] (Realtek Semiconductor Corp.)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
R3 SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [230912 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-25] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-20] (Synaptics Incorporated)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-23] (Microsoft Corporation)
R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-10 22:17 - 2014-06-10 22:17 - 00019144 _____ () C:\Users\AnitaHY\Desktop\FRST.txt
2014-06-10 22:17 - 2014-06-10 22:17 - 00000000 ____D () C:\FRST
2014-06-10 22:16 - 2014-06-10 22:16 - 02081792 _____ (Farbar) C:\Users\AnitaHY\Desktop\FRST64.exe
2014-06-10 22:14 - 2014-06-10 22:14 - 00000757 _____ () C:\Users\AnitaHY\Desktop\JRT.txt
2014-06-10 22:09 - 2014-06-10 22:09 - 00000821 _____ () C:\Users\AnitaHY\Desktop\AdwCleaner[S0].txt
2014-06-10 22:08 - 2014-06-10 22:08 - 00000000 ____D () C:\windows\ERUNT
2014-06-10 22:05 - 2014-06-10 22:06 - 01016261 _____ (Thisisu) C:\Users\AnitaHY\Desktop\JRT.exe
2014-06-10 21:58 - 2014-06-10 22:01 - 00000000 ____D () C:\AdwCleaner
2014-06-10 21:57 - 2014-06-10 21:57 - 01333465 _____ () C:\Users\AnitaHY\Desktop\adwcleaner_3.212.exe
2014-06-10 21:29 - 2014-06-10 21:46 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-06-10 21:28 - 2014-06-10 21:46 - 00000000 ____D () C:\Users\AnitaHY\Desktop\mbar
2014-06-10 21:28 - 2014-06-10 21:28 - 14349744 _____ (Malwarebytes Corp.) C:\Users\AnitaHY\Desktop\mbar-1.07.0.1012.exe
2014-06-10 21:05 - 2014-06-10 21:05 - 04686336 _____ () C:\Users\AnitaHY\Desktop\RogueKiller.exe
2014-06-10 21:05 - 2014-06-10 21:05 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-06-10 19:54 - 2014-06-10 22:01 - 00003964 _____ () C:\windows\PFRO.log
2014-06-10 19:45 - 2014-06-10 22:04 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-10 19:45 - 2014-06-10 21:28 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-06-10 19:45 - 2014-06-10 19:45 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-10 19:45 - 2014-06-10 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-10 19:45 - 2014-06-10 19:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-10 19:45 - 2014-06-10 19:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-10 19:45 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-06-10 19:45 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-06-10 19:43 - 2014-06-10 19:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\AnitaHY\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-10 19:29 - 2014-06-10 19:30 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Meyccyas
2014-06-10 16:09 - 2014-06-10 16:09 - 00147456 _____ () C:\Users\AnitaHY\AppData\Local\tkugjqsr.exe
2014-06-10 13:52 - 2014-06-10 13:54 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Paekzooq
2014-06-10 13:37 - 2014-06-10 13:38 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Weigatg
2014-06-08 14:59 - 2014-06-08 14:59 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Cimyvo
2014-06-08 14:35 - 2014-06-08 14:35 - 00002776 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2014-06-08 14:35 - 2014-06-08 14:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-08 14:35 - 2014-06-08 14:35 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-08 14:34 - 2014-06-08 14:34 - 04748896 _____ (Piriform Ltd) C:\Users\AnitaHY\Desktop\ccsetup414.exe
2014-06-08 11:04 - 2014-06-08 12:44 - 00385024 _____ () C:\Users\AnitaHY\Desktop\The Book index (updated).xls
2014-06-08 09:56 - 2014-06-08 09:57 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Pyydydc
2014-06-08 09:50 - 2014-06-08 09:50 - 00000992 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-06-08 09:50 - 2014-06-08 09:50 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\TuneUp Software
2014-06-08 09:50 - 2014-06-08 09:50 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\AVG2014
2014-06-08 09:50 - 2014-06-08 09:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-06-08 09:49 - 2014-06-08 09:52 - 00000000 ____D () C:\ProgramData\AVG2014
2014-06-08 09:49 - 2014-06-08 09:49 - 00000000 ___HD () C:\$AVG
2014-06-08 09:49 - 2014-06-08 09:49 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-06-08 09:44 - 2014-06-10 17:03 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-08 09:44 - 2014-06-08 09:54 - 00000000 ____D () C:\Users\AnitaHY\AppData\Local\Avg2014
2014-06-08 09:44 - 2014-06-08 09:44 - 00000000 ____D () C:\Users\AnitaHY\AppData\Local\MFAData
2014-06-08 09:43 - 2014-06-08 09:43 - 04485528 _____ (AVG Technologies) C:\Users\AnitaHY\Desktop\avg_free_stb_all_2014_4577_cnet.exe
2014-06-07 21:53 - 2014-06-08 10:00 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Yfykami
2014-06-07 17:45 - 2014-06-08 11:01 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Aqzibeyt
2014-06-07 16:47 - 2014-06-07 16:47 - 00068782 _____ () C:\Users\AnitaHY\AppData\Local\lhxokxkb
2014-06-07 16:44 - 2014-06-08 09:52 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Suaqbul
2014-05-21 10:26 - 2014-06-10 22:05 - 00004986 _____ () C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for AHY-ULTBK-AnitaHY AHY-ULTBK
2014-05-14 08:58 - 2014-05-14 08:58 - 00001868 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk
2014-05-14 08:58 - 2014-05-14 08:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-05-14 08:58 - 2014-05-14 08:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-14 08:57 - 2014-03-23 22:30 - 00257880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdFilter.sys
2014-05-14 08:57 - 2014-03-23 22:30 - 00123224 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdNisDrv.sys
2014-05-14 08:57 - 2014-03-23 22:27 - 00035856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdBoot.sys
2014-05-14 08:56 - 2014-04-08 18:46 - 00086688 _____ (Microsoft Corporation) C:\windows\system32\mrt_map.dll
2014-05-14 08:56 - 2014-04-08 18:46 - 00028320 _____ (Microsoft Corporation) C:\windows\system32\mrt100.dll
2014-05-14 08:56 - 2014-04-08 14:54 - 00080032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mrt_map.dll
2014-05-14 08:56 - 2014-04-08 14:54 - 00026784 _____ (Microsoft Corporation) C:\windows\SysWOW64\mrt100.dll
2014-05-14 08:56 - 2014-03-13 03:42 - 00308224 _____ (Microsoft Corporation) C:\windows\system32\wusa.exe
2014-05-14 08:56 - 2014-03-13 02:51 - 00305152 _____ (Microsoft Corporation) C:\windows\SysWOW64\wusa.exe
2014-05-13 20:27 - 2014-05-06 00:40 - 23544320 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-13 20:27 - 2014-05-05 23:25 - 17382912 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-13 20:27 - 2014-05-05 23:00 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-13 20:27 - 2014-05-05 22:10 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-13 20:27 - 2014-04-11 06:03 - 00555736 _____ (Microsoft Corporation) C:\windows\system32\twinapi.appcore.dll
2014-05-13 20:27 - 2014-04-11 06:03 - 00054776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2014-05-13 20:27 - 2014-04-11 04:25 - 00419928 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinapi.appcore.dll
2014-05-13 20:27 - 2014-04-11 02:04 - 00056320 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2014-05-13 20:27 - 2014-04-11 01:53 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\WSReset.exe
2014-05-13 20:27 - 2014-04-11 01:22 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2014-05-13 20:27 - 2014-04-10 23:54 - 00201728 _____ (Microsoft Corporation) C:\windows\system32\ubpm.dll
2014-05-13 20:27 - 2014-04-10 23:36 - 11792384 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2014-05-13 20:27 - 2014-04-10 23:24 - 13288960 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2014-05-13 20:27 - 2014-04-10 23:06 - 00031232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2014-05-13 20:27 - 2014-04-10 23:05 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-13 20:27 - 2014-04-10 23:05 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2014-05-13 20:27 - 2014-04-10 23:02 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-13 20:27 - 2014-04-10 23:02 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2014-05-13 20:27 - 2014-04-10 23:01 - 00137728 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2014-05-13 20:27 - 2014-04-10 23:00 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2014-05-13 20:27 - 2014-04-10 22:59 - 00666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2014-05-13 20:27 - 2014-04-10 22:57 - 00190976 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
2014-05-13 20:27 - 2014-04-10 22:56 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2014-05-13 20:27 - 2014-04-10 22:55 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2014-05-13 20:27 - 2014-04-10 22:53 - 00827392 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2014-05-13 20:27 - 2014-04-10 22:52 - 03464192 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2014-05-13 20:27 - 2014-04-10 22:46 - 01705472 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2014-05-13 20:27 - 2014-04-10 22:36 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.appcore.dll
2014-05-13 20:27 - 2014-04-10 22:34 - 00754688 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2014-05-13 20:27 - 2014-04-10 22:29 - 01054208 _____ (Microsoft Corporation) C:\windows\system32\twinui.appcore.dll
2014-05-13 20:27 - 2014-04-10 22:25 - 00921088 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2014-05-13 20:26 - 2014-03-27 05:12 - 21225584 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-05-13 20:26 - 2014-03-27 03:48 - 18679728 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgrkx64.sys
==================== One Month Modified Files and Folders =======
2014-06-10 22:17 - 2014-06-10 22:17 - 00019144 _____ () C:\Users\AnitaHY\Desktop\FRST.txt
2014-06-10 22:17 - 2014-06-10 22:17 - 00000000 ____D () C:\FRST
2014-06-10 22:17 - 2014-01-14 09:46 - 00000000 ____D () C:\Users\AnitaHY\AppData\Local\Temp
2014-06-10 22:16 - 2014-06-10 22:16 - 02081792 _____ (Farbar) C:\Users\AnitaHY\Desktop\FRST64.exe
2014-06-10 22:14 - 2014-06-10 22:14 - 00000757 _____ () C:\Users\AnitaHY\Desktop\JRT.txt
2014-06-10 22:10 - 2014-01-14 09:46 - 00039213 _____ () C:\Users\AnitaHY\AppData\Local\BTServer.log
2014-06-10 22:09 - 2014-06-10 22:09 - 00000821 _____ () C:\Users\AnitaHY\Desktop\AdwCleaner[S0].txt
2014-06-10 22:08 - 2014-06-10 22:08 - 00000000 ____D () C:\windows\ERUNT
2014-06-10 22:06 - 2014-06-10 22:05 - 01016261 _____ (Thisisu) C:\Users\AnitaHY\Desktop\JRT.exe
2014-06-10 22:06 - 2013-08-28 04:36 - 00865408 _____ () C:\windows\system32\PerfStringBackup.INI
2014-06-10 22:05 - 2014-05-21 10:26 - 00004986 _____ () C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for AHY-ULTBK-AnitaHY AHY-ULTBK
2014-06-10 22:04 - 2014-06-10 19:45 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-10 22:04 - 2014-02-08 09:33 - 00000000 ____D () C:\Users\AnitaHY\Documents\Outlook Files
2014-06-10 22:04 - 2014-01-16 21:42 - 00000000 __RDO () C:\Users\AnitaHY\SkyDrive
2014-06-10 22:01 - 2014-06-10 21:58 - 00000000 ____D () C:\AdwCleaner
2014-06-10 22:01 - 2014-06-10 19:54 - 00003964 _____ () C:\windows\PFRO.log
2014-06-10 22:01 - 2013-11-05 12:42 - 00008704 _____ () C:\windows\system32\VfService.trf
2014-06-10 22:01 - 2013-11-05 12:27 - 07049750 _____ () C:\Users\Public\CAFADEBUG.log
2014-06-10 22:01 - 2013-08-22 10:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-10 22:01 - 2013-08-22 09:25 - 00262144 ___SH () C:\windows\system32\config\BBI
2014-06-10 22:00 - 2013-08-22 11:36 - 00000000 ____D () C:\windows\system32\sru
2014-06-10 21:59 - 2013-11-05 12:30 - 01062557 _____ () C:\windows\WindowsUpdate.log
2014-06-10 21:57 - 2014-06-10 21:57 - 01333465 _____ () C:\Users\AnitaHY\Desktop\adwcleaner_3.212.exe
2014-06-10 21:54 - 2014-02-01 15:42 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-06-10 21:46 - 2014-06-10 21:29 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-06-10 21:46 - 2014-06-10 21:28 - 00000000 ____D () C:\Users\AnitaHY\Desktop\mbar
2014-06-10 21:28 - 2014-06-10 21:28 - 14349744 _____ (Malwarebytes Corp.) C:\Users\AnitaHY\Desktop\mbar-1.07.0.1012.exe
2014-06-10 21:28 - 2014-06-10 19:45 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-06-10 21:05 - 2014-06-10 21:05 - 04686336 _____ () C:\Users\AnitaHY\Desktop\RogueKiller.exe
2014-06-10 21:05 - 2014-06-10 21:05 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-06-10 20:27 - 2014-01-14 09:51 - 00003596 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2316213231-900153102-689936460-1001
2014-06-10 19:55 - 2013-11-05 12:29 - 00000000 ____D () C:\ProgramData\Realtek
2014-06-10 19:45 - 2014-06-10 19:45 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-10 19:45 - 2014-06-10 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-10 19:45 - 2014-06-10 19:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-10 19:45 - 2014-06-10 19:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-10 19:43 - 2014-06-10 19:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\AnitaHY\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-10 19:30 - 2014-06-10 19:29 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Meyccyas
2014-06-10 17:23 - 2014-01-14 09:46 - 00000000 ____D () C:\Users\AnitaHY\AppData\Local\Packages
2014-06-10 17:03 - 2014-06-08 09:44 - 00000000 ____D () C:\ProgramData\MFAData
2014-06-10 16:09 - 2014-06-10 16:09 - 00147456 _____ () C:\Users\AnitaHY\AppData\Local\tkugjqsr.exe
2014-06-10 14:47 - 2014-02-05 09:26 - 00000000 ____D () C:\Users\AnitaHY\Desktop\Shine
2014-06-10 13:54 - 2014-06-10 13:52 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Paekzooq
2014-06-10 13:38 - 2014-06-10 13:37 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Weigatg
2014-06-10 08:21 - 2013-08-22 11:36 - 00000000 ____D () C:\windows\AppReadiness
2014-06-09 22:18 - 2014-02-05 09:26 - 00401920 _____ () C:\Users\AnitaHY\Desktop\The Book index.xls
2014-06-09 17:09 - 2014-02-05 09:26 - 00603136 ___SH () C:\Users\AnitaHY\Desktop\Thumbs.db
2014-06-09 13:12 - 2014-02-05 09:26 - 00013899 _____ () C:\Users\AnitaHY\Desktop\Finances.xlsx
2014-06-08 14:59 - 2014-06-08 14:59 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Cimyvo
2014-06-08 14:38 - 2014-02-25 09:02 - 00000000 ____D () C:\windows\Minidump
2014-06-08 14:38 - 2013-08-28 05:31 - 00000000 ____D () C:\windows\Panther
2014-06-08 14:35 - 2014-06-08 14:35 - 00002776 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2014-06-08 14:35 - 2014-06-08 14:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-08 14:35 - 2014-06-08 14:35 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-08 14:34 - 2014-06-08 14:34 - 04748896 _____ (Piriform Ltd) C:\Users\AnitaHY\Desktop\ccsetup414.exe
2014-06-08 14:28 - 2013-08-22 11:36 - 00000000 ____D () C:\windows\system32\NDF
2014-06-08 12:44 - 2014-06-08 11:04 - 00385024 _____ () C:\Users\AnitaHY\Desktop\The Book index (updated).xls
2014-06-08 11:01 - 2014-06-07 17:45 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Aqzibeyt
2014-06-08 10:00 - 2014-06-07 21:53 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Yfykami
2014-06-08 09:58 - 2013-11-05 12:37 - 00000000 ____D () C:\ProgramData\McAfee
2014-06-08 09:57 - 2014-06-08 09:56 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Pyydydc
2014-06-08 09:56 - 2013-08-22 11:36 - 00000000 ___HD () C:\windows\ELAMBKUP
2014-06-08 09:54 - 2014-06-08 09:44 - 00000000 ____D () C:\Users\AnitaHY\AppData\Local\Avg2014
2014-06-08 09:53 - 2013-08-22 09:25 - 00262144 ___SH () C:\windows\system32\config\ELAM
2014-06-08 09:52 - 2014-06-08 09:49 - 00000000 ____D () C:\ProgramData\AVG2014
2014-06-08 09:52 - 2014-06-07 16:44 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Suaqbul
2014-06-08 09:50 - 2014-06-08 09:50 - 00000992 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-06-08 09:50 - 2014-06-08 09:50 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\TuneUp Software
2014-06-08 09:50 - 2014-06-08 09:50 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\AVG2014
2014-06-08 09:50 - 2014-06-08 09:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-06-08 09:49 - 2014-06-08 09:49 - 00000000 ___HD () C:\$AVG
2014-06-08 09:49 - 2014-06-08 09:49 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-06-08 09:44 - 2014-06-08 09:44 - 00000000 ____D () C:\Users\AnitaHY\AppData\Local\MFAData
2014-06-08 09:43 - 2014-06-08 09:43 - 04485528 _____ (AVG Technologies) C:\Users\AnitaHY\Desktop\avg_free_stb_all_2014_4577_cnet.exe
2014-06-07 16:47 - 2014-06-07 16:47 - 00068782 _____ () C:\Users\AnitaHY\AppData\Local\lhxokxkb
2014-05-30 09:50 - 2014-02-05 09:26 - 00051200 _____ () C:\Users\AnitaHY\Desktop\library database.xls
2014-05-30 08:36 - 2014-02-05 09:26 - 00000000 ____D () C:\Users\AnitaHY\Desktop\Theopoetics
2014-05-29 10:03 - 2014-02-05 09:26 - 00000000 ____D () C:\Users\AnitaHY\Desktop\WRITING in progress
2014-05-28 17:23 - 2014-03-19 21:30 - 00000000 ____D () C:\Users\AnitaHY\Desktop\Ignatian retreat
2014-05-28 11:48 - 2014-02-01 22:01 - 00000000 ____D () C:\Users\AnitaHY\Documents\Notes on Books & Articles
2014-05-28 10:29 - 2014-02-04 08:56 - 00000000 ____D () C:\Users\AnitaHY\AppData\Roaming\Skype
2014-05-27 20:42 - 2014-02-05 09:26 - 00000000 ____D () C:\Users\AnitaHY\Desktop\TO PRINT
2014-05-24 11:08 - 2014-02-04 23:17 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-05-20 13:29 - 2013-08-22 11:36 - 00000000 ____D () C:\windows\rescache
2014-05-16 15:36 - 2014-01-14 11:12 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-15 07:37 - 2014-01-14 09:46 - 00000000 ___RD () C:\Users\AnitaHY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 07:37 - 2014-01-14 09:46 - 00000000 ___RD () C:\Users\AnitaHY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-14 22:53 - 2014-01-14 10:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-14 22:52 - 2013-08-22 11:36 - 00000000 ___RD () C:\windows\ToastData
2014-05-14 22:52 - 2013-08-22 11:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-14 22:52 - 2013-08-22 11:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-14 22:52 - 2013-08-22 11:36 - 00000000 ____D () C:\windows\WinStore
2014-05-14 22:52 - 2013-08-22 11:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-14 22:52 - 2013-08-22 11:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-14 22:51 - 2014-01-13 20:54 - 00000000 ____D () C:\windows\system32\MRT
2014-05-14 22:51 - 2013-08-22 11:20 - 00000000 ____D () C:\windows\CbsTemp
2014-05-14 22:49 - 2014-01-13 20:54 - 93223848 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-05-14 08:58 - 2014-05-14 08:58 - 00001868 _____ () C:\Users\Public\Desktop\QuickTime Player.lnk
2014-05-14 08:58 - 2014-05-14 08:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-05-14 08:58 - 2014-05-14 08:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-05-14 08:56 - 2013-08-22 11:36 - 00000000 ____D () C:\windows\system32\SecureBootUpdates
2014-05-13 20:55 - 2014-02-01 15:42 - 00003718 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-05-13 14:20 - 2014-05-13 14:20 - 00235800 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgldx64.sys
2014-05-13 14:06 - 2014-05-13 14:06 - 00323352 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgloga.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00191768 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgidsha.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00152344 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgdiska.sys
2014-05-13 14:05 - 2014-05-13 14:05 - 00130328 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgmfx64.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00236312 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgidsdrivera.sys
2014-05-13 14:04 - 2014-05-13 14:04 - 00031512 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgrkx64.sys
2014-05-12 07:26 - 2014-06-10 19:45 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-10 19:45 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-05-11 21:58 - 2014-02-05 09:26 - 00000000 ____D () C:\Users\AnitaHY\Desktop\M.Div. Review
Some content of TEMP:
====================
C:\Users\AnitaHY\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-09 10:59
==================== End Of Log ============================