Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by Joanna (administrator) on NEWBIE on 03-02-2015 17:38:45
Running from C:\Users\Joanna\Desktop
Loaded Profiles: Joanna (Available profiles: Joanna)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(HP) C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Windows\System32\valWBFPolicyService.exe
(AuthenTec Inc.) C:\Program Files (x86)\HP SimplePass\TouchControl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
() C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Lee-Soft.com) C:\Users\Joanna\AppData\Roaming\ViStart\Plugins\MetroProvider.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteUser.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Lee-Soft.com) C:\Users\Joanna\AppData\Roaming\ViStart\ViStart.exe
(Lee Chantrey) C:\Users\Joanna\AppData\Roaming\ViStart\Plugins\SearchProvider.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-22] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-04-26] (IDT, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581024 2012-09-07] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-01-20] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-04-03] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2015-01-28] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [Google Update] => C:\Users\Joanna\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-04-28] (Google Inc.)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2014-10-14] (Microsoft Corporation)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-11-21] (Apple Inc.)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [GoogleChromeAutoLaunch_B50826638171B982A76266700AE576E6] => C:\Users\Joanna\AppData\Local\Google\Chrome\Application\chrome.exe [843592 2015-01-26] (Google Inc.)
HKU\S-1-5-21-2802446628-2056013772-2352947291-1001\...\Run: [ViStart] => C:\Users\Joanna\AppData\Roaming\ViStart\ViStart.exe [1306624 2013-04-17] (Lee-Soft.com)
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2802446628-2056013772-2352947291-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
http://www.google.com/search?q={sea...tartIndex={startIndex?}&startPage={startPage}
SearchScopes: HKU\S-1-5-21-2802446628-2056013772-2352947291-1001 -> {C5546EA0-70B0-4F91-8C65-A61C602DEF1C} URL =
https://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=667671&p={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKU\S-1-5-21-2802446628-2056013772-2352947291-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect1259.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default
FF SelectedSearchEngine: Yahoo!
FF Keyword.URL:
https://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=667671&p=
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @authentec.com/ffwloplugin -> C:\Program Files (x86)\HP SimplePass\npffwloplugin.dll ( HP)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF Plugin HKU\S-1-5-21-2802446628-2056013772-2352947291-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Joanna\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-2802446628-2056013772-2352947291-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Joanna\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF Extension: ActiveGS - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\
activegs@freetoolsassociation.com [2013-06-18]
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\
artur.dubovoy@gmail.com [2015-01-11]
FF Extension: LogMeIn, Inc. Remote Access Plugin - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\
LogMeInClient@logmein.com [2014-11-04]
FF Extension: privateTabinfocatcher - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\privateTab@infocatcher [2015-01-28]
FF Extension: Classic Theme Restorer - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\
ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-05-11]
FF Extension: Gmail Notifier (restartless) - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\
jid0-GjwrPchS3Ugt7xydvqVK4DQk8Ls@jetpack.xpi [2014-02-09]
FF Extension: Tumblr Savior - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\
jid1-W5guVoyeUR0uBg@jetpack.xpi [2014-01-22]
FF Extension: Pin It Button - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\
jid1-YcMV6ngYmQRA2w@jetpack.xpi [2014-11-08]
FF Extension: XKit - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\
xkit@studioxenix.com.xpi [2014-12-27]
FF Extension: Stylish - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2014-11-12]
FF Extension: Greasemonkey - C:\Users\Joanna\AppData\Roaming\Mozilla\Firefox\Profiles\x4ce2o8w.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2014-02-23]
FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\
websitelogon@truesuite.com [2015-02-02]
Chrome:
=======
CHR Profile: C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-28]
CHR Extension: (Google Drive) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-28]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-23]
CHR Extension: (YouTube) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-28]
CHR Extension: (Google Search) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-28]
CHR Extension: (Gmail™ Notifier) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcjichoefijpinlfnjghokpkojhlhkgl [2014-12-04]
CHR Extension: (Tampermonkey) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2014-12-06]
CHR Extension: (Stylish) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2014-11-07]
CHR Extension: (XKit) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfgeeomkfdefkckijiabdbogjkdaecd [2014-12-24]
CHR Extension: (Pin It Button) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2015-01-19]
CHR Extension: (Emoji Input) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\immhpnclomdloikkpcefncmfgjbkojmh [2014-12-16]
CHR Extension: (Website Logon) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanflfepiobnpjbljmngfgegijhdpljm [2014-05-16]
CHR Extension: (FVD Downloader) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2015-01-16]
CHR Extension: (Google Wallet) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-24]
CHR Extension: (Gmail) - C:\Users\Joanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-28]
CHR HKLM-x32\...\Chrome\Extension: [fegekclkdhbnfdcmomlpegkkndgnmfmo] - C:\Program Files (x86)\HP SimplePass\tschrome.crx [2013-04-01]
CHR HKLM-x32\...\Chrome\Extension: [jaaieiajnhcnimjgfmjpccjmmfkploci] - C:\Program Files (x86)\HP SimplePass\tschrome.crx [2013-04-01]
CHR HKLM-x32\...\Chrome\Extension: [kanflfepiobnpjbljmngfgegijhdpljm] - C:\Program Files (x86)\HP SimplePass\tschrome.crx [2013-04-01]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 FPLService; C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [1641768 2013-06-07] (HP)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 HPConnectedRemote; C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35744 2012-10-12] (Hewlett-Packard)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [49464 2014-04-01] (Hewlett-Packard Company)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-22] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
S4 RemoteRegistry; C:\Windows\SysWOW64\regsvc.dll [1556480 2013-08-23] () [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2013-04-26] (IDT, Inc.) [File not signed]
S3 stllssvr; C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [69632 2007-07-11] (MicroVision Development, Inc.) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401856 2013-01-07] (AuthenTec, Inc.)
R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [28160 2012-09-06] () [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-11-20] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-21] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [31920 2013-06-02] (Wondershare)
R2 DLABMFSE; C:\Windows\System32\Drivers\DLABMFSE.SYS [46448 2007-07-23] (Roxio)
R2 DLABOIOE; C:\Windows\System32\Drivers\DLABOIOE.SYS [42352 2007-07-23] (Roxio)
R0 DLACDBHE; C:\Windows\System32\Drivers\DLACDBHE.SYS [17776 2007-07-23] (Roxio)
R2 DLADResE; C:\Windows\System32\Drivers\DLADResE.SYS [9968 2007-07-23] (Roxio)
R2 DLAIFS_E; C:\Windows\System32\Drivers\DLAIFS_E.SYS [146672 2007-07-23] (Roxio)
R2 DLAOPIOE; C:\Windows\System32\Drivers\DLAOPIOE.SYS [35056 2007-07-23] (Roxio)
R2 DLAPoolE; C:\Windows\System32\Drivers\DLAPoolE.SYS [19824 2007-07-23] (Roxio)
R1 DLARTL_E; C:\Windows\System32\Drivers\DLARTL_E.SYS [41072 2007-07-23] (Roxio)
R2 DLAUDFAE; C:\Windows\System32\Drivers\DLAUDFAE.SYS [135152 2007-07-23] (Roxio)
R2 DLAUDF_E; C:\Windows\System32\Drivers\DLAUDF_E.SYS [144112 2007-07-23] (Roxio)
R0 DRVECDB; C:\Windows\System32\Drivers\DRVECDB.SYS [124112 2007-07-23] (Sonic Solutions)
R2 DRVEDDM; C:\Windows\System32\Drivers\DRVEDDM.SYS [63984 2007-07-23] (Roxio)
R3 msvad_simple; C:\Windows\system32\drivers\povrtdev.sys [28528 2013-12-17] (MediaMall Technologies, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-03-07] (Synaptics Incorporated)
S3 SndTAudio; C:\Windows\system32\drivers\SndTAudio.sys [34504 2013-12-16] (Windows (R) Win 7 DDK provider)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-02-02] ()
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-21] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-03 17:38 - 2015-02-03 17:39 - 00027326 _____ () C:\Users\Joanna\Desktop\FRST.txt
2015-02-03 17:38 - 2015-02-03 17:38 - 00000000 ____D () C:\FRST
2015-02-03 17:37 - 2015-02-03 17:37 - 02131456 _____ (Farbar) C:\Users\Joanna\Desktop\FRST64.exe
2015-02-03 17:30 - 2015-02-03 17:30 - 00000755 _____ () C:\Users\Joanna\Desktop\JRT.txt
2015-02-03 17:29 - 2015-02-03 17:29 - 00000000 ____D () C:\Users\Joanna\AppData\Local\CrashDumps
2015-02-03 17:28 - 2015-02-03 17:28 - 01388274 _____ (Thisisu) C:\Users\Joanna\Desktop\JRT.exe
2015-02-03 17:27 - 2015-02-03 17:27 - 01388274 _____ (Thisisu) C:\Users\Joanna\Downloads\132C.tmp
2015-02-03 17:17 - 2015-02-03 17:17 - 00002571 _____ () C:\Users\Joanna\Desktop\AdwCleaner[S0].txt
2015-02-02 22:40 - 2015-02-02 22:43 - 275100512 ____R () C:\Users\Joanna\Desktop\castle.713.hdtv.real-lol.mp4
2015-02-02 22:39 - 2015-02-02 22:39 - 00002870 _____ () C:\Users\Joanna\Desktop\Castle.2009.S07E13.HDTV.x264.REAL-LOL.torrent
2015-02-02 20:57 - 2015-02-02 20:57 - 00000995 _____ () C:\Users\Public\Desktop\Mp3tag.lnk
2015-02-02 20:57 - 2015-02-02 20:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2015-02-02 20:56 - 2015-02-02 20:56 - 02707360 _____ () C:\Users\Joanna\Downloads\mp3tagv266setup.exe
2015-02-02 20:25 - 2015-02-02 20:25 - 02004309 _____ () C:\Users\Joanna\Desktop\demoThemeBundleforUpperElementaryrdththgrades.zip
2015-02-02 19:48 - 2015-02-03 08:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-02-02 19:47 - 2015-02-02 20:45 - 00000000 ____D () C:\Users\Joanna\Desktop\mbar
2015-02-02 19:47 - 2015-02-02 19:47 - 16466552 _____ (Malwarebytes Corp.) C:\Users\Joanna\Desktop\mbar-1.08.3.1004.exe
2015-02-02 19:30 - 2015-02-02 19:30 - 00035064 _____ () C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-02-02 19:30 - 2015-02-02 19:30 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-02-02 19:10 - 2015-02-02 19:10 - 15431256 _____ () C:\Users\Joanna\Desktop\RogueKiller.exe
2015-02-02 00:21 - 2015-02-02 00:21 - 00001175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-02 00:21 - 2015-02-02 00:21 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-02 00:21 - 2015-02-02 00:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-02 00:18 - 2015-02-02 00:18 - 00243440 _____ () C:\Users\Joanna\Downloads\Firefox Setup Stub 35.0.1.exe
2015-02-01 23:55 - 2015-02-01 23:55 - 00688992 _____ (Swearware) C:\Users\Joanna\Downloads\dds.com
2015-02-01 23:06 - 2015-02-01 23:06 - 00000000 _____ () C:\autoexec.bat
2015-02-01 23:01 - 2015-02-01 23:01 - 00000000 ____D () C:\Program Files\Enigma Software Group
2015-02-01 23:00 - 2015-02-03 17:15 - 00000000 ____D () C:\AdwCleaner
2015-02-01 23:00 - 2015-02-01 23:00 - 02194432 _____ () C:\Users\Joanna\Downloads\adwcleaner_4.109.exe
2015-02-01 15:45 - 2015-02-01 16:52 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2015-02-01 15:41 - 2015-02-01 15:41 - 03533528 _____ (DVDVideoSoft Ltd. ) C:\Users\Joanna\Downloads\FreeStudio (2).exe
2015-02-01 15:37 - 2015-02-01 15:37 - 03533528 _____ (DVDVideoSoft Ltd. ) C:\Users\Joanna\Downloads\FreeStudio (1).exe
2015-02-01 15:36 - 2015-02-01 16:52 - 00001261 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2015-02-01 15:34 - 2015-02-01 15:34 - 03529744 _____ (DVDVideoSoft Ltd. ) C:\Users\Joanna\Downloads\FreeAVIVideoConverter.exe
2015-02-01 08:58 - 2015-02-01 08:58 - 00001765 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-02-01 08:58 - 2015-02-01 08:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-02-01 08:57 - 2015-02-01 08:58 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-01 08:57 - 2015-02-01 08:58 - 00000000 ____D () C:\Program Files\iTunes
2015-02-01 08:57 - 2015-02-01 08:57 - 00000000 ____D () C:\Program Files\iPod
2015-02-01 08:57 - 2015-02-01 08:57 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-26 16:06 - 2015-02-02 09:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-24 08:39 - 2015-01-24 08:39 - 00247610 _____ () C:\Users\Joanna\Documents\cc_20150124_083915.reg
2015-01-24 00:07 - 2015-01-24 00:07 - 00430973 _____ () C:\Users\Joanna\Downloads\us.zip
2015-01-24 00:06 - 2015-01-24 00:08 - 60498886 _____ () C:\Users\Joanna\Downloads\rockyou.txt.bz2
2015-01-23 23:58 - 2015-02-01 22:54 - 00000000 ____D () C:\Program Files (x86)\RAR Password Unlocker
2015-01-23 23:58 - 2015-01-23 23:58 - 01937696 _____ () C:\Users\Joanna\Downloads\winrar-x64-521b1.exe
2015-01-23 23:58 - 2015-01-23 23:58 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-23 23:58 - 2015-01-23 23:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-01-23 23:56 - 2015-01-23 23:56 - 03221420 _____ () C:\Users\Joanna\Downloads\RAR Password Unlocker by AwesomeTutorials.rar
2015-01-23 23:46 - 2015-01-23 23:46 - 00389754 _____ (dnSoft Research Group) C:\Users\Joanna\Downloads\rpc420_setup.exe
2015-01-23 18:37 - 2015-01-23 19:19 - 2332997625 _____ () C:\Users\Joanna\Desktop\Castle.S07E12.Private.Eye.Caramba.1080p.WEB-DL.DD5.1.H.264-ECI.mp4
2015-01-23 18:18 - 2015-01-23 18:35 - 1804931134 ____R () C:\Users\Joanna\Desktop\Castle.S07E12.Private.Eye.Caramba.1080p.WEB-DL.DD5.1.H.264-ECI.mkv
2015-01-23 17:45 - 2015-01-23 17:45 - 13338017 _____ (RAR Password Unlocker, Inc. ) C:\Users\Joanna\Downloads\rar_password_unlocker_trial.exe
2015-01-22 21:08 - 2015-01-22 21:08 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-22 21:07 - 2015-01-22 21:07 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Joanna\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-19 21:03 - 2015-01-19 21:07 - 295079237 _____ () C:\Users\Joanna\Desktop\castle.2009.712.hdtv-lol.mp4
2015-01-18 23:14 - 2015-01-18 23:16 - 00000000 ____D () C:\Users\Joanna\Desktop\Boy Meets World Season 1 - 7 DVDRip
2015-01-18 21:24 - 2015-02-02 19:30 - 00000000 ____D () C:\Users\Joanna\Desktop\Boy Meets World
2015-01-17 13:44 - 2014-04-15 18:35 - 00028352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
2015-01-17 13:44 - 2014-04-15 18:34 - 00029888 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2015-01-16 07:26 - 2015-01-16 07:26 - 00000860 _____ () C:\Users\Joanna\Desktop\µTorrent.lnk
2015-01-14 06:18 - 2014-12-19 01:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-14 06:18 - 2014-12-11 21:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-14 06:18 - 2014-12-11 19:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-14 06:18 - 2014-12-08 20:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-14 06:18 - 2014-12-08 14:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-14 06:18 - 2014-12-08 14:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-14 06:18 - 2014-12-08 14:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-01-14 06:18 - 2014-12-08 14:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-14 06:18 - 2014-12-08 14:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-01-14 06:18 - 2014-12-08 14:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-14 06:18 - 2014-12-08 14:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-14 06:18 - 2014-12-08 14:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-01-14 06:18 - 2014-12-05 22:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-14 06:18 - 2014-12-05 20:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-14 06:18 - 2014-12-05 20:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-14 06:18 - 2014-10-28 23:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-14 06:18 - 2014-10-28 23:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-14 06:18 - 2014-10-28 22:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-14 06:18 - 2014-10-28 22:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-14 06:18 - 2014-10-28 22:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-14 06:18 - 2014-10-28 22:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-14 06:18 - 2014-10-28 22:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2015-01-14 06:18 - 2014-10-28 22:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2015-01-14 06:18 - 2014-10-28 22:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-01-14 06:18 - 2014-10-28 22:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-01-14 06:18 - 2014-10-28 22:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-01-14 06:18 - 2014-10-28 21:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-14 06:18 - 2014-10-28 20:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2015-01-14 06:18 - 2014-10-28 20:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-14 06:18 - 2014-10-28 20:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-14 06:18 - 2014-10-28 20:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2015-01-10 00:17 - 2015-01-10 00:17 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\LJ-Sec
2015-01-10 00:10 - 2015-01-10 00:10 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LJ-Sec
2015-01-10 00:10 - 2015-01-10 00:10 - 00000000 ____D () C:\Program Files (x86)\LJ-SecInstall
2015-01-05 19:52 - 2015-01-07 19:37 - 00000000 ____D () C:\Users\Joanna\Desktop\Friends.S09.Season.9.720p.BluRay.x264-PublicHD
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-03 17:35 - 2013-04-28 16:03 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\ViStart
2015-02-03 17:16 - 2014-10-27 18:24 - 00000350 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForJoanna.job
2015-02-03 17:16 - 2014-10-02 17:15 - 00034072 _____ () C:\WINDOWS\PFRO.log
2015-02-03 17:16 - 2014-09-27 10:20 - 00005936 _____ () C:\WINDOWS\setupact.log
2015-02-03 17:16 - 2013-08-22 09:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-03 17:14 - 2013-04-26 00:20 - 00003922 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{AC16CF4C-C03E-4E41-9FE2-F9829B69173E}
2015-02-03 17:02 - 2013-04-26 00:26 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2802446628-2056013772-2352947291-1001
2015-02-03 16:55 - 2013-04-26 21:15 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-02-03 16:45 - 2013-04-28 21:31 - 00000926 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2802446628-2056013772-2352947291-1001UA.job
2015-02-03 16:38 - 2014-09-24 17:21 - 01093065 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-03 16:28 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-02-03 08:50 - 2014-10-27 18:24 - 00003166 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForJoanna
2015-02-03 08:50 - 2014-06-03 19:26 - 00003826 _____ () C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1397778706
2015-02-03 08:50 - 2014-04-17 18:51 - 00001057 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-02-03 08:50 - 2014-04-17 18:51 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-02-03 08:43 - 2014-03-07 18:42 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\uTorrent
2015-02-03 07:19 - 2014-08-19 21:19 - 00000000 ____D () C:\Users\Joanna\AppData\Local\Adobe
2015-02-03 00:27 - 2013-11-25 16:10 - 00001704 _____ () C:\Users\Joanna\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-02-02 22:45 - 2014-11-24 17:39 - 00000000 ____D () C:\Users\Joanna\Desktop\Castle Gifs
2015-02-02 22:40 - 2013-04-28 11:09 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\mIRC
2015-02-02 22:35 - 2013-07-16 15:27 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\vlc
2015-02-02 22:07 - 2013-06-25 20:50 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Mp3tag
2015-02-02 20:57 - 2013-04-27 15:29 - 00000000 ____D () C:\Program Files (x86)\Mp3tag
2015-02-02 20:51 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-02-02 20:02 - 2013-09-29 23:04 - 00962424 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-02 19:48 - 2014-07-11 15:42 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-02-02 19:47 - 2014-07-11 15:42 - 00097496 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-02-02 09:17 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\Branding
2015-02-01 16:52 - 2014-06-10 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-02-01 16:49 - 2014-10-27 21:09 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack
2015-02-01 16:49 - 2013-06-19 19:31 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\DVDVideoSoft
2015-02-01 16:01 - 2013-08-22 08:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-02-01 12:52 - 2014-06-30 07:47 - 00000000 ____D () C:\Users\Joanna\Desktop\Friends
2015-02-01 12:51 - 2014-11-26 19:34 - 00000000 ____D () C:\Users\Joanna\Desktop\Friends Gifs
2015-02-01 08:57 - 2013-04-27 18:40 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-01-30 07:27 - 2013-04-26 20:01 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log
2015-01-30 07:27 - 2013-04-26 20:01 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2015-01-28 06:47 - 2012-07-26 02:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-01-27 22:42 - 2014-07-16 20:14 - 00000000 ____D () C:\ProgramData\boost_interprocess
2015-01-26 16:50 - 2013-04-27 06:01 - 00000000 ____D () C:\Users\Joanna\Desktop\Movies
2015-01-24 15:20 - 2014-12-13 20:05 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-01-24 15:20 - 2014-12-13 20:05 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 15:11 - 2013-05-01 19:06 - 00000000 ____D () C:\Program Files\WinRAR
2015-01-24 14:55 - 2013-04-26 21:15 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-01-24 08:31 - 2014-02-28 17:25 - 00000000 ____D () C:\Program Files (x86)\Aimersoft
2015-01-23 16:50 - 2013-05-01 20:12 - 00000000 ____D () C:\Program Files\Adobe
2015-01-23 16:49 - 2013-05-01 20:07 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-01-23 16:37 - 2014-12-14 21:27 - 00000000 ___RD () C:\Users\Joanna\iCloudDrive
2015-01-22 21:08 - 2014-07-11 15:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-22 21:08 - 2014-07-11 15:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-21 06:22 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-19 11:26 - 2013-08-02 08:51 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-01-19 11:12 - 2013-04-27 08:10 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-01-16 07:26 - 2014-04-28 20:04 - 00000840 _____ () C:\Users\Joanna\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2015-01-11 00:36 - 2013-04-26 21:26 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\com.aspexsoftware.Silhouette_Studio
2015-01-05 20:20 - 2013-04-27 18:42 - 00000000 ____D () C:\Users\Joanna\AppData\Roaming\Apple Computer
2015-01-05 18:55 - 2014-05-18 17:04 - 00000000 ____D () C:\Users\Joanna\Desktop\Gilmore.Girls.COMPLETE.DVDRip.XviD
2015-01-05 18:32 - 2014-12-21 20:52 - 01054912 _____ (Adobe) C:\Users\Joanna\Downloads\install_flashplayer16x32au_mssd_aaa_aih.exe
2015-01-05 18:27 - 2013-11-19 21:41 - 00000000 ____D () C:\Users\Joanna
2015-01-04 18:18 - 2014-12-26 16:00 - 00000000 ____D () C:\Users\Joanna\Desktop\Pics
==================== Files in the root of some directories =======
2013-05-20 20:51 - 2014-02-12 17:26 - 0000132 _____ () C:\Users\Joanna\AppData\Roaming\Adobe BMP Format CS6 Prefs
2013-11-25 15:41 - 2014-03-04 10:07 - 0000132 _____ () C:\Users\Joanna\AppData\Roaming\Adobe GIF Format CS6 Prefs
2014-10-14 19:02 - 2014-10-14 19:02 - 0000132 _____ () C:\Users\Joanna\AppData\Roaming\Adobe IllExport Filter CS6 Prefs
2013-10-15 20:05 - 2014-09-26 09:48 - 0000132 _____ () C:\Users\Joanna\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-01-31 16:05 - 2014-01-31 16:05 - 0000046 _____ () C:\Users\Joanna\AppData\Roaming\Camdata.ini
2014-01-31 16:05 - 2014-01-31 16:05 - 0000408 _____ () C:\Users\Joanna\AppData\Roaming\CamLayout.ini
2014-01-31 16:05 - 2014-01-31 16:05 - 0000408 _____ () C:\Users\Joanna\AppData\Roaming\CamShapes.ini
2014-01-31 16:05 - 2014-01-31 16:05 - 0004535 _____ () C:\Users\Joanna\AppData\Roaming\CamStudio.cfg
2014-04-22 05:43 - 2014-04-28 17:05 - 0099384 _____ () C:\Users\Joanna\AppData\Roaming\inst.exe
2014-04-22 05:43 - 2014-04-28 17:05 - 0007859 _____ () C:\Users\Joanna\AppData\Roaming\pcouffin.cat
2014-04-22 05:43 - 2014-04-28 17:05 - 0001167 _____ () C:\Users\Joanna\AppData\Roaming\pcouffin.inf
2014-04-22 05:43 - 2014-04-28 17:05 - 0000055 _____ () C:\Users\Joanna\AppData\Roaming\pcouffin.log
2014-04-22 05:43 - 2014-04-28 17:05 - 0082816 _____ (VSO Software) C:\Users\Joanna\AppData\Roaming\pcouffin.sys
2014-06-09 15:51 - 2014-06-09 15:51 - 0000097 _____ () C:\Users\Joanna\AppData\Roaming\settings.xml
2014-01-31 15:57 - 2014-01-31 15:57 - 0000096 _____ () C:\Users\Joanna\AppData\Roaming\version2.xml
2013-11-25 16:10 - 2015-02-03 00:27 - 0001704 _____ () C:\Users\Joanna\AppData\Local\Adobe Save for Web 13.0 Prefs
2013-04-28 21:13 - 2014-05-31 21:54 - 0042496 _____ () C:\Users\Joanna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-03-02 09:04 - 2014-03-02 09:04 - 0000218 _____ () C:\Users\Joanna\AppData\Local\recently-used.xbel
2013-04-26 00:20 - 2013-04-26 00:20 - 0000141 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
Some content of TEMP:
====================
C:\Users\Joanna\AppData\Local\Temp\bitool.dll
C:\Users\Joanna\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Joanna\AppData\Local\Temp\EsgInstallerx64Stub.exe
C:\Users\Joanna\AppData\Local\Temp\Extract.exe
C:\Users\Joanna\AppData\Local\Temp\FreeAVIVideoConverter.exe
C:\Users\Joanna\AppData\Local\Temp\FreeMP4VideoConverter.exe
C:\Users\Joanna\AppData\Local\Temp\FreeStudio.exe
C:\Users\Joanna\AppData\Local\Temp\mirc738.exe
C:\Users\Joanna\AppData\Local\Temp\Quarantine.exe
C:\Users\Joanna\AppData\Local\Temp\RSPUpgradeInstaller.exe
C:\Users\Joanna\AppData\Local\Temp\SearchProtectionSetup.exe
C:\Users\Joanna\AppData\Local\Temp\SP63259.exe
C:\Users\Joanna\AppData\Local\Temp\sqlite3.dll
C:\Users\Joanna\AppData\Local\Temp\tmd_34012003.exe
C:\Users\Joanna\AppData\Local\Temp\tmd_34014077.exe
C:\Users\Joanna\AppData\Local\Temp\tmd_34016468.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-03 17:02
==================== End Of Log ============================