Hi. Totally stuck. Malwarebytes, Adwcleaner, windows defender... doesn't work. Finds it, but it returns quickly. Chrome, Mozilla are affected. Thank you geek gods.
~~~~~~~
Here is my Farbar FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-03-2017
Ran by jsilver (administrator) on NCP-SAMSUNG-01 (14-03-2017 20:49:55)
Running from C:\Users\Jess Silver\Desktop\kt spyware
Loaded Profiles: jsilver (Available Profiles: jsilver)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET\EMET_Service.exe
() C:\Windows\System32\GManager.exe
(Code 42 Software) C:\Program Files\CrashPlan\CrashPlanService.exe
() C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe
() C:\Windows\System32\mlpatch.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET\EMET_Agent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Magic Control Technology Corporation) C:\Program Files (x86)\Common Files\DesktopUtil\MCTDUtil.exe
(Magic Control Technology Corporation) C:\Program Files (x86)\Common Files\DesktopUtil\FDispPos.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Blue Jeans) C:\Users\Jess Silver\AppData\Local\Blue Jeans\App\BlueJeans.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(IBM Corp.) C:\Program Files (x86)\BigFix Enterprise\BES Client\BESClient.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(IBM Corp.) C:\Program Files (x86)\BigFix Enterprise\BES Client\BESClientUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\ProgramData\{47588EC2-F0F3-3969-E64D-3EE7F03676D5}\9131DE82-269A-6929-A402-9F238384706B.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040296 2015-09-18] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242200 2016-11-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [MCTDUtil] => C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe [195200 2011-05-03] ()
HKLM\...\Run: [FDispPos] => C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe [195200 2011-05-03] ()
HKLM\...\Run: [TUCCDUtil] => C:\Program Files (x86)\Mct Corp\UVTP100\Driver\TUCCDUTIL\TUCCD.exe [1896568 2016-10-12] (Magic Control Technology Corporation)
HKLM\...\Run: [CrashPlanTray] => C:\Program Files\CrashPlan\CrashPlanTray.exe [461192 2016-12-01] (Code 42 Software, Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [684024 2012-10-17] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [30264 2009-08-04] (Hewlett-Packard Company)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKU\S-1-5-21-2854528859-1650723732-3483195984-1004\...\Run: [Google Update] => C:\Users\Jess Silver\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKU\S-1-5-21-2854528859-1650723732-3483195984-1004\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29494400 2016-07-13] (Skype Technologies S.A.)
Startup: C:\Users\Jess Silver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bluejeans-helper.vbs [2017-01-05] ()
Startup: C:\Users\Jess Silver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-12-29]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.137.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{07d97036-84de-4cd0-a878-05cb2b30ec68}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{bd0545c3-5535-4672-99c4-e24f1ff5d4a4}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{bd0545c3-5535-4672-99c4-e24f1ff5d4a4}: [DhcpNameServer] 192.168.137.1
ManualProxies:
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\ssv.dll [2016-08-16] (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\jp2ssv.dll [2016-08-16] (Oracle Corporation)
IE Session Restore: HKU\S-1-5-21-2854528859-1650723732-3483195984-1004 -> is enabled.
FireFox:
========
FF DefaultProfile: pa4wbl01.default
FF ProfilePath: C:\Users\Jess Silver\AppData\Roaming\Mozilla\Firefox\Profiles\pa4wbl01.default [2017-03-08]
FF Homepage: Mozilla\Firefox\Profiles\pa4wbl01.default -> hxxp://google.com/
FF Extension: (Zotero) - C:\Users\Jess Silver\AppData\Roaming\Mozilla\Firefox\Profiles\pa4wbl01.default\Extensions\zotero@chnm.gmu.edu.xpi [2017-01-20]
FF Extension: (Zotero Word for Windows Integration) - C:\Users\Jess Silver\AppData\Roaming\Mozilla\Firefox\Profiles\pa4wbl01.default\Extensions\zoteroWinWordIntegration@zotero.org [2017-01-20]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-24] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-24] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.102.2 -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\dtplugin\npDeployJava1.dll [2016-08-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.102.2 -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\plugin2\npjp2.dll [2016-08-16] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @citrixonline.com/appdetectorplugin -> C:\Users\Jess Silver\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-12-08] (Citrix Online)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @talk.google.com/GoogleTalkPlugin -> C:\Users\Jess Silver\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @talk.google.com/O1DPlugin -> C:\Users\Jess Silver\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @tools.google.com/Google Update;version=3 -> C:\Users\Jess Silver\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @tools.google.com/Google Update;version=9 -> C:\Users\Jess Silver\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: bluejeans.com/bjninstallplugin -> C:\Users\Jess Silver\AppData\Roaming\Blue Jeans\bjnplugin\2.160.63.8\npbjninstallplugin_2.160.63.8.dll [2016-07-05] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: bluejeans.com/bjnplugin -> C:\Users\Jess Silver\AppData\Roaming\Blue Jeans\bjnplugin\2.160.63.8\npbjnplugin_2.160.63.8.dll [2016-07-05] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: bluejeans.com/rbjninstallplugin -> C:\Users\Jess Silver\AppData\Roaming\Blue Jeans\rbjnplugin\2.160.66.8\nprbjninstallplugin_2.160.66.8.dll [2016-07-18] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: bluejeans.com/rbjnplugin -> C:\Users\Jess Silver\AppData\Roaming\Blue Jeans\rbjnplugin\2.160.66.8\nprbjnplugin_2.160.66.8.dll [2016-07-18] (Blue Jeans)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Jess Silver\AppData\Roaming\mozilla\plugins\npatgpc.dll [2016-02-24] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Jess Silver\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Jess Silver\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Default [2017-03-10]
CHR Profile: C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-14]
CHR Extension: (Google Slides) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-09]
CHR Extension: (Google Docs) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-09]
CHR Extension: (Google Drive) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-09]
CHR Extension: (YouTube) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-09]
CHR Extension: (Adobe Acrobat) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-09]
CHR Extension: (Google Sheets) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-09]
CHR Extension: (Google Docs Offline) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Blue Jeans Meeting) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nodamnmigpadbnfioofpbacngdlcidgn [2017-03-09]
CHR Extension: (Gmail) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-09]
CHR Extension: (Chrome Media Router) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-09]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BESClient; C:\Program Files (x86)\BigFix Enterprise\BES Client\BESClient.exe [9594864 2016-12-02] (IBM Corp.)
R2 CrashPlanService; C:\Program Files\CrashPlan\CrashPlanService.exe [266120 2016-12-01] (Code 42 Software)
R2 EMET_Service; C:\Program Files (x86)\EMET\EMET_Service.exe [31880 2014-11-09] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [129752 2016-11-11] (ELAN Microelectronics Corp.)
R2 GManager; C:\WINDOWS\system32\GManager.exe [2572408 2016-09-29] ()
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 MCTDesktopSvr; C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe [199296 2011-05-03] ()
R2 MlPatch; C:\WINDOWS\system32\MlPatch.exe [2244912 2014-08-22] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ETDSMBus; C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys [32328 2015-09-25] (ELAN Microelectronic Corp.)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-03-14] (Malwarebytes)
R3 mctkmd; C:\WINDOWS\system32\drivers\mctkmd64.sys [174712 2016-09-29] (Magic Control Technology Corporation)
R0 mctkmdldr; C:\WINDOWS\System32\drivers\mctkmdldr64.sys [19584 2011-04-08] (Magic Control Technology Corporation)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [20480 2012-09-25] (Marvell Semiconductor, Inc.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3343872 2016-07-16] (Intel Corporation)
R3 RadioHIDMini; C:\WINDOWS\System32\drivers\RadioHIDMini.sys [23408 2012-07-30] (Windows (R) Win 7 DDK provider)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R3 SensorsAlsDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
S3 t2usb64; C:\WINDOWS\system32\drivers\t2usb64.sys [329328 2016-11-23] (Magic Control Technology Corp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 20:49 - 2017-03-14 20:49 - 00000000 ____D C:\Users\Jess Silver\Desktop\kt spyware
2017-03-14 20:49 - 2017-03-14 20:49 - 00000000 ____D C:\FRST
2017-03-14 13:48 - 2017-03-14 13:48 - 00126474 _____ C:\Users\Jess Silver\Downloads\40copies_bw_CoastalResilience_AppsSession_HRA-hands-on.pdf
2017-03-14 10:49 - 2017-03-14 10:49 - 00003976 _____ C:\WINDOWS\System32\Tasks\{5B95D032-EC3E-6799-7EFA-6DF88A4A577F}
2017-03-14 10:49 - 2017-03-14 10:49 - 00000000 ____D C:\ProgramData\{47588EC2-F0F3-3969-E64D-3EE7F03676D5}
2017-03-14 10:27 - 2017-03-14 10:27 - 00103173 _____ C:\Users\Jess Silver\Downloads\daeb9835768da67aa79b56a440a087.xlsx
2017-03-10 11:49 - 2017-03-14 10:49 - 00000000 ____D C:\ProgramData\5419a1a
2017-03-10 11:13 - 2017-03-10 11:13 - 04486911 _____ C:\Users\Jess Silver\Downloads\DB_SB_nyas_ecb_b4_13322_1715006_rev.pdf
2017-03-09 15:01 - 2017-03-09 15:01 - 00240336 _____ C:\Users\Jess Silver\Downloads\Blue Jeans Launcher.exe
2017-03-09 12:34 - 2017-03-09 12:34 - 00002348 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-09 12:34 - 2017-03-09 12:34 - 00002336 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-03-09 12:33 - 2017-03-09 12:33 - 01129376 _____ (Google Inc.) C:\Users\Jess Silver\Downloads\ChromeSetup.exe
2017-03-09 11:24 - 2017-03-09 11:25 - 00017000 _____ C:\Users\Jess Silver\Downloads\ShellfishAquacultureInterviews_ForNatCap.xlsx
2017-03-08 21:44 - 2017-03-08 21:47 - 00000000 ____D C:\Users\Jess Silver\AppData\LocalLow\Mozilla
2017-03-08 21:26 - 2017-03-08 21:26 - 00000000 _____ C:\autoexec.bat
2017-03-08 21:25 - 2017-03-08 22:19 - 00000000 ____D C:\Users\Jess Silver\AppData\Roaming\Enigma Software Group
2017-03-08 21:25 - 2017-03-08 21:25 - 00000000 ____D C:\sh4ldr
2017-03-08 21:24 - 2017-03-08 22:19 - 00000000 ____D C:\Program Files\Enigma Software Group
2017-03-08 16:53 - 2017-03-08 16:53 - 00035847 _____ C:\Users\Jess Silver\Downloads\bhs_grumpv1_ppoints_shp.zip
2017-03-08 16:30 - 2017-03-08 16:30 - 00016746 _____ C:\Users\Jess Silver\AppData\Local\recently-used.xbel
2017-03-08 16:18 - 2017-03-08 16:18 - 00697656 _____ C:\Users\Jess Silver\Downloads\Development_ID-sm-scaled.tif
2017-03-08 15:38 - 2017-03-08 15:38 - 00000000 ____D C:\Users\Jess Silver\Desktop\Presentation1
2017-03-08 14:10 - 2017-03-08 14:10 - 01161721 _____ C:\Users\Jess Silver\Downloads\Graphic 2_v3.pptx
2017-03-08 13:37 - 2017-03-09 13:44 - 00000000 ____D C:\Users\Jess Silver\Desktop\Katies_Project
2017-03-08 13:34 - 2017-03-08 16:30 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\gtk-2.0
2017-03-08 13:34 - 2017-03-08 13:34 - 00000000 ____D C:\Users\Jess Silver\.thumbnails
2017-03-08 13:32 - 2017-03-08 22:19 - 00000000 ____D C:\Users\Jess Silver\.gimp-2.8
2017-03-08 13:32 - 2017-03-08 13:32 - 00000939 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2017-03-08 13:32 - 2017-03-08 13:32 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\gegl-0.2
2017-03-08 13:31 - 2017-03-08 13:32 - 00000000 ____D C:\Program Files\GIMP 2
2017-03-08 13:09 - 2017-03-08 13:09 - 02226715 _____ C:\Users\Jess Silver\Downloads\Arkema and Ruckelshaus_proofs.pdf
2017-03-08 12:55 - 2017-03-13 12:00 - 00002302 _____ C:\Users\Jess Silver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IBM BigFix.lnk
2017-03-08 12:47 - 2017-03-08 12:47 - 04031440 _____ C:\Users\Jess Silver\Downloads\adwcleaner_6.044.exe
2017-03-06 17:06 - 2017-03-06 17:06 - 01050315 _____ C:\Users\Jess Silver\Downloads\1_b_geomorphology (3.3.3dev).tif
2017-03-06 17:06 - 2017-03-06 17:06 - 00857187 _____ C:\Users\Jess Silver\Downloads\1_b_geomorphology (3.1.0).tif
2017-03-06 17:05 - 2017-03-06 17:05 - 01050343 _____ C:\Users\Jess Silver\Downloads\1_i_coastal_exposure (3.3.3dev).tif
2017-03-06 17:05 - 2017-03-06 17:05 - 00857215 _____ C:\Users\Jess Silver\Downloads\1_i_coastal_exposure (3.1.0).tif
2017-03-06 13:40 - 2017-03-06 13:40 - 00025061 _____ C:\Users\Jess Silver\Downloads\Copy of SFBay_ScopingReport_MapofOrganizations_Feb17_2017_rls.xlsx
2017-03-02 17:06 - 2017-03-02 17:06 - 454656545 _____ C:\WINDOWS\MEMORY.DMP
2017-03-02 17:06 - 2017-03-02 17:06 - 00313500 _____ C:\WINDOWS\Minidump\030217-4765-01.dmp
2017-03-02 17:06 - 2017-03-02 17:06 - 00000000 ____D C:\WINDOWS\Minidump
2017-03-02 16:08 - 2017-03-02 16:08 - 00040621 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1314 (1).pdf
2017-03-02 15:29 - 2017-03-02 15:29 - 00040873 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1112.pdf
2017-03-02 15:29 - 2017-03-02 15:29 - 00040750 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1213.pdf
2017-03-02 15:29 - 2017-03-02 15:29 - 00040621 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1314.pdf
2017-03-02 15:23 - 2017-03-02 15:23 - 00040235 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1415.pdf
2017-03-02 15:03 - 2017-03-02 15:03 - 00057262 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1516.pdf
2017-03-02 12:44 - 2017-03-02 12:46 - 00000000 ____D C:\Users\Jess Silver\Desktop\Papers
2017-03-01 14:25 - 2017-03-08 22:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-01 12:33 - 2017-03-01 12:33 - 00001108 _____ C:\Users\Jess Silver\Downloads\ArcGISDesktopAdvanced_SingleUse_506633.prvc
2017-02-28 12:49 - 2017-02-28 12:49 - 00549445 _____ C:\Users\Jess Silver\Downloads\Data (2).pdf
2017-02-28 12:22 - 2017-02-28 12:22 - 00017385 _____ C:\Users\Jess Silver\Downloads\GRP_Data_Management_Reporting_MUYNMhW.xlsx
2017-02-28 12:21 - 2017-02-28 12:21 - 00016432 _____ C:\Users\Jess Silver\Downloads\GRP Information Management Reporting.xlsx
2017-02-28 11:42 - 2017-02-28 12:39 - 00000000 ____D C:\Users\Jess Silver\Downloads\Archive
2017-02-28 11:42 - 2017-02-28 11:42 - 00029179 _____ C:\Users\Jess Silver\Downloads\Archive.zip
2017-02-23 15:08 - 2017-02-23 15:08 - 00549445 _____ C:\Users\Jess Silver\Downloads\Data (1).pdf
2017-02-23 15:08 - 2017-02-23 15:08 - 00012709 _____ C:\Users\Jess Silver\Downloads\GRP_Data_and_Info_Management_Reporting_1_lHVtwDh (1).xlsx
2017-02-23 13:34 - 2017-02-23 13:34 - 00613977 _____ C:\Users\Jess Silver\Downloads\Inputs for Liberia.zip
2017-02-17 14:56 - 2017-02-17 14:56 - 00002221 _____ C:\Users\Public\Desktop\Google Earth.lnk
2017-02-17 14:56 - 2017-02-17 14:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2017-02-16 12:15 - 2017-02-17 13:51 - 00022916 _____ C:\Users\Jess Silver\Downloads\SFBay_ScopingReport_MapofOrganizations-2_mr.xlsx
2017-02-16 11:04 - 2017-02-16 11:04 - 00401761 _____ C:\Users\Jess Silver\Downloads\BARC NatCap Partnership Letter 2_16_17.pdf
2017-02-13 12:43 - 2017-02-13 12:43 - 00033128 _____ C:\Users\Jess Silver\Downloads\runs_Mastic.xlsx
2017-02-13 12:35 - 2017-02-13 12:35 - 07597990 _____ C:\Users\Jess Silver\Downloads\CV_BH_112316.zip
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 20:26 - 2015-12-29 23:10 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-14 20:23 - 2015-09-02 19:37 - 01564696 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-14 20:22 - 2016-10-27 12:25 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-14 15:24 - 2015-03-30 11:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-03-14 15:24 - 2015-03-19 11:35 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-14 15:22 - 2015-03-19 11:35 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-03-14 15:21 - 2016-07-16 04:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-14 15:16 - 2015-12-17 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-03-14 15:15 - 2015-12-17 22:16 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-03-14 15:15 - 2015-12-17 22:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-03-14 11:06 - 2015-03-30 12:34 - 00000000 ____D C:\Users\Jess Silver\Desktop\desktop_misc
2017-03-14 11:03 - 2015-03-26 09:07 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\Packages
2017-03-14 10:49 - 2016-10-27 12:36 - 00003882 _____ C:\WINDOWS\System32\Tasks\{8B534575-27ED-F69D-359E-023AFC92252C}
2017-03-14 09:37 - 2016-07-16 04:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-14 09:37 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-14 09:33 - 2015-03-31 10:44 - 00002827 _____ C:\WINDOWS\system32\GManager.ini
2017-03-13 11:58 - 2016-10-27 12:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-13 11:57 - 2016-10-27 12:27 - 00000000 ____D C:\Users\Jess Silver
2017-03-13 11:57 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\addins
2017-03-13 11:57 - 2016-07-15 23:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-09 22:17 - 2016-07-16 04:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-03-09 22:17 - 2016-07-16 04:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-09 12:34 - 2015-03-26 13:14 - 00000000 ____D C:\Program Files (x86)\Google
2017-03-09 12:34 - 2015-03-26 13:13 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\Google
2017-03-08 22:19 - 2015-12-16 13:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-08 12:58 - 2015-03-30 12:46 - 00000000 ____D C:\Users\Jess Silver\Desktop\Silverwell Farm
2017-03-08 12:37 - 2015-12-08 11:12 - 00000716 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2854528859-1650723732-3483195984-1004.job
2017-03-08 12:37 - 2015-12-08 11:12 - 00000620 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2854528859-1650723732-3483195984-1004.job
2017-03-08 12:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\vpnplugins
2017-03-08 11:07 - 2016-04-27 13:02 - 00000000 ____D C:\Users\Jess Silver\Desktop\Jess_Stuff
2017-03-06 17:06 - 2015-03-30 12:55 - 00000000 ____D C:\Arc_outputs
2017-03-02 17:06 - 2016-07-16 04:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-02 12:22 - 2016-10-27 12:25 - 00401800 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-03-01 12:14 - 2016-05-23 13:31 - 00000000 ____D C:\Users\Jess Silver\.qgis2
2017-03-01 12:14 - 2015-03-31 12:31 - 00000000 ____D C:\Users\Jess Silver\.matplotlib
2017-02-28 11:25 - 2016-02-12 16:02 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-28 11:24 - 2015-03-30 10:33 - 00000000 ____D C:\Users\Jess Silver\AppData\Roaming\Skype
2017-02-24 21:12 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-24 21:12 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-22 17:08 - 2015-04-29 14:41 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-22 10:51 - 2016-12-09 14:26 - 00003292 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-02-22 10:51 - 2015-09-03 10:26 - 00002385 _____ C:\Users\Jess Silver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-22 10:51 - 2015-04-21 11:06 - 00000000 ___RD C:\Users\Jess Silver\OneDrive
2017-02-13 13:44 - 2015-03-30 11:35 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\Microsoft Help
==================== Files in the root of some directories =======
2017-03-08 16:30 - 2017-03-08 16:30 - 0016746 _____ () C:\Users\Jess Silver\AppData\Local\recently-used.xbel
2016-10-27 12:26 - 2016-10-27 12:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-03-30 11:32 - 2015-03-30 11:46 - 0003589 _____ () C:\ProgramData\StanfordOfficeInstaller.log
Some files in TEMP:
====================
2016-11-02 14:29 - 2017-02-07 11:55 - 43976160 _____ (Skype Technologies S.A.) C:\Users\Jess Silver\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-14 15:14
==================== End of FRST.txt ============================
~~~~~~~
Here is my Farbar FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-03-2017
Ran by jsilver (administrator) on NCP-SAMSUNG-01 (14-03-2017 20:49:55)
Running from C:\Users\Jess Silver\Desktop\kt spyware
Loaded Profiles: jsilver (Available Profiles: jsilver)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET\EMET_Service.exe
() C:\Windows\System32\GManager.exe
(Code 42 Software) C:\Program Files\CrashPlan\CrashPlanService.exe
() C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe
() C:\Windows\System32\mlpatch.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET\EMET_Agent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Magic Control Technology Corporation) C:\Program Files (x86)\Common Files\DesktopUtil\MCTDUtil.exe
(Magic Control Technology Corporation) C:\Program Files (x86)\Common Files\DesktopUtil\FDispPos.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Blue Jeans) C:\Users\Jess Silver\AppData\Local\Blue Jeans\App\BlueJeans.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(IBM Corp.) C:\Program Files (x86)\BigFix Enterprise\BES Client\BESClient.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(IBM Corp.) C:\Program Files (x86)\BigFix Enterprise\BES Client\BESClientUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\ProgramData\{47588EC2-F0F3-3969-E64D-3EE7F03676D5}\9131DE82-269A-6929-A402-9F238384706B.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040296 2015-09-18] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242200 2016-11-11] (ELAN Microelectronics Corp.)
HKLM\...\Run: [MCTDUtil] => C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe [195200 2011-05-03] ()
HKLM\...\Run: [FDispPos] => C:\Program Files (x86)\Common Files\DesktopUtil\Util-Desktop.exe [195200 2011-05-03] ()
HKLM\...\Run: [TUCCDUtil] => C:\Program Files (x86)\Mct Corp\UVTP100\Driver\TUCCDUTIL\TUCCD.exe [1896568 2016-10-12] (Magic Control Technology Corporation)
HKLM\...\Run: [CrashPlanTray] => C:\Program Files\CrashPlan\CrashPlanTray.exe [461192 2016-12-01] (Code 42 Software, Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [684024 2012-10-17] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe [30264 2009-08-04] (Hewlett-Packard Company)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598552 2016-06-22] (Oracle Corporation)
HKU\S-1-5-21-2854528859-1650723732-3483195984-1004\...\Run: [Google Update] => C:\Users\Jess Silver\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKU\S-1-5-21-2854528859-1650723732-3483195984-1004\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29494400 2016-07-13] (Skype Technologies S.A.)
Startup: C:\Users\Jess Silver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bluejeans-helper.vbs [2017-01-05] ()
Startup: C:\Users\Jess Silver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-12-29]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.137.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{07d97036-84de-4cd0-a878-05cb2b30ec68}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{bd0545c3-5535-4672-99c4-e24f1ff5d4a4}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{bd0545c3-5535-4672-99c4-e24f1ff5d4a4}: [DhcpNameServer] 192.168.137.1
ManualProxies:
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-12-13] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\ssv.dll [2016-08-16] (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-11-15] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\jp2ssv.dll [2016-08-16] (Oracle Corporation)
IE Session Restore: HKU\S-1-5-21-2854528859-1650723732-3483195984-1004 -> is enabled.
FireFox:
========
FF DefaultProfile: pa4wbl01.default
FF ProfilePath: C:\Users\Jess Silver\AppData\Roaming\Mozilla\Firefox\Profiles\pa4wbl01.default [2017-03-08]
FF Homepage: Mozilla\Firefox\Profiles\pa4wbl01.default -> hxxp://google.com/
FF Extension: (Zotero) - C:\Users\Jess Silver\AppData\Roaming\Mozilla\Firefox\Profiles\pa4wbl01.default\Extensions\zotero@chnm.gmu.edu.xpi [2017-01-20]
FF Extension: (Zotero Word for Windows Integration) - C:\Users\Jess Silver\AppData\Roaming\Mozilla\Firefox\Profiles\pa4wbl01.default\Extensions\zoteroWinWordIntegration@zotero.org [2017-01-20]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-24] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-24] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.102.2 -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\dtplugin\npDeployJava1.dll [2016-08-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.102.2 -> C:\Program Files (x86)\Java\jre1.8.0_102\bin\plugin2\npjp2.dll [2016-08-16] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @citrixonline.com/appdetectorplugin -> C:\Users\Jess Silver\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-12-08] (Citrix Online)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @talk.google.com/GoogleTalkPlugin -> C:\Users\Jess Silver\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @talk.google.com/O1DPlugin -> C:\Users\Jess Silver\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @tools.google.com/Google Update;version=3 -> C:\Users\Jess Silver\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: @tools.google.com/Google Update;version=9 -> C:\Users\Jess Silver\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: bluejeans.com/bjninstallplugin -> C:\Users\Jess Silver\AppData\Roaming\Blue Jeans\bjnplugin\2.160.63.8\npbjninstallplugin_2.160.63.8.dll [2016-07-05] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: bluejeans.com/bjnplugin -> C:\Users\Jess Silver\AppData\Roaming\Blue Jeans\bjnplugin\2.160.63.8\npbjnplugin_2.160.63.8.dll [2016-07-05] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: bluejeans.com/rbjninstallplugin -> C:\Users\Jess Silver\AppData\Roaming\Blue Jeans\rbjnplugin\2.160.66.8\nprbjninstallplugin_2.160.66.8.dll [2016-07-18] (Blue Jeans)
FF Plugin HKU\S-1-5-21-2854528859-1650723732-3483195984-1004: bluejeans.com/rbjnplugin -> C:\Users\Jess Silver\AppData\Roaming\Blue Jeans\rbjnplugin\2.160.66.8\nprbjnplugin_2.160.66.8.dll [2016-07-18] (Blue Jeans)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Jess Silver\AppData\Roaming\mozilla\plugins\npatgpc.dll [2016-02-24] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Jess Silver\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Jess Silver\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Default [2017-03-10]
CHR Profile: C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-14]
CHR Extension: (Google Slides) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-09]
CHR Extension: (Google Docs) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-09]
CHR Extension: (Google Drive) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-09]
CHR Extension: (YouTube) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-09]
CHR Extension: (Adobe Acrobat) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-09]
CHR Extension: (Google Sheets) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-09]
CHR Extension: (Google Docs Offline) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Blue Jeans Meeting) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nodamnmigpadbnfioofpbacngdlcidgn [2017-03-09]
CHR Extension: (Gmail) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-09]
CHR Extension: (Chrome Media Router) - C:\Users\Jess Silver\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-09]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 BESClient; C:\Program Files (x86)\BigFix Enterprise\BES Client\BESClient.exe [9594864 2016-12-02] (IBM Corp.)
R2 CrashPlanService; C:\Program Files\CrashPlan\CrashPlanService.exe [266120 2016-12-01] (Code 42 Software)
R2 EMET_Service; C:\Program Files (x86)\EMET\EMET_Service.exe [31880 2014-11-09] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [129752 2016-11-11] (ELAN Microelectronics Corp.)
R2 GManager; C:\WINDOWS\system32\GManager.exe [2572408 2016-09-29] ()
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 MCTDesktopSvr; C:\Program Files (x86)\Common Files\DesktopUtil\MCTDesktopSvr.exe [199296 2011-05-03] ()
R2 MlPatch; C:\WINDOWS\system32\MlPatch.exe [2244912 2014-08-22] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ETDSMBus; C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys [32328 2015-09-25] (ELAN Microelectronic Corp.)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-03-14] (Malwarebytes)
R3 mctkmd; C:\WINDOWS\system32\drivers\mctkmd64.sys [174712 2016-09-29] (Magic Control Technology Corporation)
R0 mctkmdldr; C:\WINDOWS\System32\drivers\mctkmdldr64.sys [19584 2011-04-08] (Magic Control Technology Corporation)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [20480 2012-09-25] (Marvell Semiconductor, Inc.)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3343872 2016-07-16] (Intel Corporation)
R3 RadioHIDMini; C:\WINDOWS\System32\drivers\RadioHIDMini.sys [23408 2012-07-30] (Windows (R) Win 7 DDK provider)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R3 SensorsAlsDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
S3 t2usb64; C:\WINDOWS\system32\drivers\t2usb64.sys [329328 2016-11-23] (Magic Control Technology Corp.)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 20:49 - 2017-03-14 20:49 - 00000000 ____D C:\Users\Jess Silver\Desktop\kt spyware
2017-03-14 20:49 - 2017-03-14 20:49 - 00000000 ____D C:\FRST
2017-03-14 13:48 - 2017-03-14 13:48 - 00126474 _____ C:\Users\Jess Silver\Downloads\40copies_bw_CoastalResilience_AppsSession_HRA-hands-on.pdf
2017-03-14 10:49 - 2017-03-14 10:49 - 00003976 _____ C:\WINDOWS\System32\Tasks\{5B95D032-EC3E-6799-7EFA-6DF88A4A577F}
2017-03-14 10:49 - 2017-03-14 10:49 - 00000000 ____D C:\ProgramData\{47588EC2-F0F3-3969-E64D-3EE7F03676D5}
2017-03-14 10:27 - 2017-03-14 10:27 - 00103173 _____ C:\Users\Jess Silver\Downloads\daeb9835768da67aa79b56a440a087.xlsx
2017-03-10 11:49 - 2017-03-14 10:49 - 00000000 ____D C:\ProgramData\5419a1a
2017-03-10 11:13 - 2017-03-10 11:13 - 04486911 _____ C:\Users\Jess Silver\Downloads\DB_SB_nyas_ecb_b4_13322_1715006_rev.pdf
2017-03-09 15:01 - 2017-03-09 15:01 - 00240336 _____ C:\Users\Jess Silver\Downloads\Blue Jeans Launcher.exe
2017-03-09 12:34 - 2017-03-09 12:34 - 00002348 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-09 12:34 - 2017-03-09 12:34 - 00002336 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-03-09 12:33 - 2017-03-09 12:33 - 01129376 _____ (Google Inc.) C:\Users\Jess Silver\Downloads\ChromeSetup.exe
2017-03-09 11:24 - 2017-03-09 11:25 - 00017000 _____ C:\Users\Jess Silver\Downloads\ShellfishAquacultureInterviews_ForNatCap.xlsx
2017-03-08 21:44 - 2017-03-08 21:47 - 00000000 ____D C:\Users\Jess Silver\AppData\LocalLow\Mozilla
2017-03-08 21:26 - 2017-03-08 21:26 - 00000000 _____ C:\autoexec.bat
2017-03-08 21:25 - 2017-03-08 22:19 - 00000000 ____D C:\Users\Jess Silver\AppData\Roaming\Enigma Software Group
2017-03-08 21:25 - 2017-03-08 21:25 - 00000000 ____D C:\sh4ldr
2017-03-08 21:24 - 2017-03-08 22:19 - 00000000 ____D C:\Program Files\Enigma Software Group
2017-03-08 16:53 - 2017-03-08 16:53 - 00035847 _____ C:\Users\Jess Silver\Downloads\bhs_grumpv1_ppoints_shp.zip
2017-03-08 16:30 - 2017-03-08 16:30 - 00016746 _____ C:\Users\Jess Silver\AppData\Local\recently-used.xbel
2017-03-08 16:18 - 2017-03-08 16:18 - 00697656 _____ C:\Users\Jess Silver\Downloads\Development_ID-sm-scaled.tif
2017-03-08 15:38 - 2017-03-08 15:38 - 00000000 ____D C:\Users\Jess Silver\Desktop\Presentation1
2017-03-08 14:10 - 2017-03-08 14:10 - 01161721 _____ C:\Users\Jess Silver\Downloads\Graphic 2_v3.pptx
2017-03-08 13:37 - 2017-03-09 13:44 - 00000000 ____D C:\Users\Jess Silver\Desktop\Katies_Project
2017-03-08 13:34 - 2017-03-08 16:30 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\gtk-2.0
2017-03-08 13:34 - 2017-03-08 13:34 - 00000000 ____D C:\Users\Jess Silver\.thumbnails
2017-03-08 13:32 - 2017-03-08 22:19 - 00000000 ____D C:\Users\Jess Silver\.gimp-2.8
2017-03-08 13:32 - 2017-03-08 13:32 - 00000939 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2017-03-08 13:32 - 2017-03-08 13:32 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\gegl-0.2
2017-03-08 13:31 - 2017-03-08 13:32 - 00000000 ____D C:\Program Files\GIMP 2
2017-03-08 13:09 - 2017-03-08 13:09 - 02226715 _____ C:\Users\Jess Silver\Downloads\Arkema and Ruckelshaus_proofs.pdf
2017-03-08 12:55 - 2017-03-13 12:00 - 00002302 _____ C:\Users\Jess Silver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IBM BigFix.lnk
2017-03-08 12:47 - 2017-03-08 12:47 - 04031440 _____ C:\Users\Jess Silver\Downloads\adwcleaner_6.044.exe
2017-03-06 17:06 - 2017-03-06 17:06 - 01050315 _____ C:\Users\Jess Silver\Downloads\1_b_geomorphology (3.3.3dev).tif
2017-03-06 17:06 - 2017-03-06 17:06 - 00857187 _____ C:\Users\Jess Silver\Downloads\1_b_geomorphology (3.1.0).tif
2017-03-06 17:05 - 2017-03-06 17:05 - 01050343 _____ C:\Users\Jess Silver\Downloads\1_i_coastal_exposure (3.3.3dev).tif
2017-03-06 17:05 - 2017-03-06 17:05 - 00857215 _____ C:\Users\Jess Silver\Downloads\1_i_coastal_exposure (3.1.0).tif
2017-03-06 13:40 - 2017-03-06 13:40 - 00025061 _____ C:\Users\Jess Silver\Downloads\Copy of SFBay_ScopingReport_MapofOrganizations_Feb17_2017_rls.xlsx
2017-03-02 17:06 - 2017-03-02 17:06 - 454656545 _____ C:\WINDOWS\MEMORY.DMP
2017-03-02 17:06 - 2017-03-02 17:06 - 00313500 _____ C:\WINDOWS\Minidump\030217-4765-01.dmp
2017-03-02 17:06 - 2017-03-02 17:06 - 00000000 ____D C:\WINDOWS\Minidump
2017-03-02 16:08 - 2017-03-02 16:08 - 00040621 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1314 (1).pdf
2017-03-02 15:29 - 2017-03-02 15:29 - 00040873 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1112.pdf
2017-03-02 15:29 - 2017-03-02 15:29 - 00040750 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1213.pdf
2017-03-02 15:29 - 2017-03-02 15:29 - 00040621 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1314.pdf
2017-03-02 15:23 - 2017-03-02 15:23 - 00040235 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1415.pdf
2017-03-02 15:03 - 2017-03-02 15:03 - 00057262 _____ C:\Users\Jess Silver\Downloads\Park Attendance FY1516.pdf
2017-03-02 12:44 - 2017-03-02 12:46 - 00000000 ____D C:\Users\Jess Silver\Desktop\Papers
2017-03-01 14:25 - 2017-03-08 22:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-01 12:33 - 2017-03-01 12:33 - 00001108 _____ C:\Users\Jess Silver\Downloads\ArcGISDesktopAdvanced_SingleUse_506633.prvc
2017-02-28 12:49 - 2017-02-28 12:49 - 00549445 _____ C:\Users\Jess Silver\Downloads\Data (2).pdf
2017-02-28 12:22 - 2017-02-28 12:22 - 00017385 _____ C:\Users\Jess Silver\Downloads\GRP_Data_Management_Reporting_MUYNMhW.xlsx
2017-02-28 12:21 - 2017-02-28 12:21 - 00016432 _____ C:\Users\Jess Silver\Downloads\GRP Information Management Reporting.xlsx
2017-02-28 11:42 - 2017-02-28 12:39 - 00000000 ____D C:\Users\Jess Silver\Downloads\Archive
2017-02-28 11:42 - 2017-02-28 11:42 - 00029179 _____ C:\Users\Jess Silver\Downloads\Archive.zip
2017-02-23 15:08 - 2017-02-23 15:08 - 00549445 _____ C:\Users\Jess Silver\Downloads\Data (1).pdf
2017-02-23 15:08 - 2017-02-23 15:08 - 00012709 _____ C:\Users\Jess Silver\Downloads\GRP_Data_and_Info_Management_Reporting_1_lHVtwDh (1).xlsx
2017-02-23 13:34 - 2017-02-23 13:34 - 00613977 _____ C:\Users\Jess Silver\Downloads\Inputs for Liberia.zip
2017-02-17 14:56 - 2017-02-17 14:56 - 00002221 _____ C:\Users\Public\Desktop\Google Earth.lnk
2017-02-17 14:56 - 2017-02-17 14:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2017-02-16 12:15 - 2017-02-17 13:51 - 00022916 _____ C:\Users\Jess Silver\Downloads\SFBay_ScopingReport_MapofOrganizations-2_mr.xlsx
2017-02-16 11:04 - 2017-02-16 11:04 - 00401761 _____ C:\Users\Jess Silver\Downloads\BARC NatCap Partnership Letter 2_16_17.pdf
2017-02-13 12:43 - 2017-02-13 12:43 - 00033128 _____ C:\Users\Jess Silver\Downloads\runs_Mastic.xlsx
2017-02-13 12:35 - 2017-02-13 12:35 - 07597990 _____ C:\Users\Jess Silver\Downloads\CV_BH_112316.zip
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-14 20:26 - 2015-12-29 23:10 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-14 20:23 - 2015-09-02 19:37 - 01564696 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-14 20:22 - 2016-10-27 12:25 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-14 15:24 - 2015-03-30 11:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-03-14 15:24 - 2015-03-19 11:35 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-14 15:22 - 2015-03-19 11:35 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-03-14 15:21 - 2016-07-16 04:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-14 15:16 - 2015-12-17 22:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-03-14 15:15 - 2015-12-17 22:16 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-03-14 15:15 - 2015-12-17 22:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-03-14 11:06 - 2015-03-30 12:34 - 00000000 ____D C:\Users\Jess Silver\Desktop\desktop_misc
2017-03-14 11:03 - 2015-03-26 09:07 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\Packages
2017-03-14 10:49 - 2016-10-27 12:36 - 00003882 _____ C:\WINDOWS\System32\Tasks\{8B534575-27ED-F69D-359E-023AFC92252C}
2017-03-14 09:37 - 2016-07-16 04:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-14 09:37 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-14 09:33 - 2015-03-31 10:44 - 00002827 _____ C:\WINDOWS\system32\GManager.ini
2017-03-13 11:58 - 2016-10-27 12:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-13 11:57 - 2016-10-27 12:27 - 00000000 ____D C:\Users\Jess Silver
2017-03-13 11:57 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\addins
2017-03-13 11:57 - 2016-07-15 23:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-09 22:17 - 2016-07-16 04:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-03-09 22:17 - 2016-07-16 04:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-09 12:34 - 2015-03-26 13:14 - 00000000 ____D C:\Program Files (x86)\Google
2017-03-09 12:34 - 2015-03-26 13:13 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\Google
2017-03-08 22:19 - 2015-12-16 13:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-08 12:58 - 2015-03-30 12:46 - 00000000 ____D C:\Users\Jess Silver\Desktop\Silverwell Farm
2017-03-08 12:37 - 2015-12-08 11:12 - 00000716 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2854528859-1650723732-3483195984-1004.job
2017-03-08 12:37 - 2015-12-08 11:12 - 00000620 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2854528859-1650723732-3483195984-1004.job
2017-03-08 12:37 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\vpnplugins
2017-03-08 11:07 - 2016-04-27 13:02 - 00000000 ____D C:\Users\Jess Silver\Desktop\Jess_Stuff
2017-03-06 17:06 - 2015-03-30 12:55 - 00000000 ____D C:\Arc_outputs
2017-03-02 17:06 - 2016-07-16 04:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-02 12:22 - 2016-10-27 12:25 - 00401800 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-03-01 12:14 - 2016-05-23 13:31 - 00000000 ____D C:\Users\Jess Silver\.qgis2
2017-03-01 12:14 - 2015-03-31 12:31 - 00000000 ____D C:\Users\Jess Silver\.matplotlib
2017-02-28 11:25 - 2016-02-12 16:02 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2017-02-28 11:24 - 2015-03-30 10:33 - 00000000 ____D C:\Users\Jess Silver\AppData\Roaming\Skype
2017-02-24 21:12 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-02-24 21:12 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-22 17:08 - 2015-04-29 14:41 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-22 10:51 - 2016-12-09 14:26 - 00003292 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-02-22 10:51 - 2015-09-03 10:26 - 00002385 _____ C:\Users\Jess Silver\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-02-22 10:51 - 2015-04-21 11:06 - 00000000 ___RD C:\Users\Jess Silver\OneDrive
2017-02-13 13:44 - 2015-03-30 11:35 - 00000000 ____D C:\Users\Jess Silver\AppData\Local\Microsoft Help
==================== Files in the root of some directories =======
2017-03-08 16:30 - 2017-03-08 16:30 - 0016746 _____ () C:\Users\Jess Silver\AppData\Local\recently-used.xbel
2016-10-27 12:26 - 2016-10-27 12:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-03-30 11:32 - 2015-03-30 11:46 - 0003589 _____ () C:\ProgramData\StanfordOfficeInstaller.log
Some files in TEMP:
====================
2016-11-02 14:29 - 2017-02-07 11:55 - 43976160 _____ (Skype Technologies S.A.) C:\Users\Jess Silver\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-14 15:14
==================== End of FRST.txt ============================