Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by Pete_2 (administrator) on LIZZIE on 01-02-2015 23:26:03
Running from C:\Users\Pete_2\Desktop
Loaded Profiles: UpdatusUser & Pete_2 (Available profiles: UpdatusUser & Pete_2)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Decor8\Decor8Srv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Stardock Software, Inc) C:\Program Files (x86)\Stardock\Decor8\Decor8_64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Flux Software LLC) C:\Users\Pete_2\AppData\Local\FluxSoftware\Flux\flux.exe
() C:\Program Files (x86)\AutoHotkey\AutoHotkey.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-17] (NVIDIA Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [216064 2014-01-06] (Realtek Semiconductor Corporation)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2014-10-22] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-10-22] (Lenovo(beijing) Limited)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\platform\McUICnt.exe [642040 2014-08-05] (McAfee, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1174857057-1915675840-1477825445-1005\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30877280 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-1174857057-1915675840-1477825445-1005\...\Run: [Spotify] => C:\Users\Pete_2\AppData\Roaming\Spotify\spotify.exe [6737976 2014-12-29] (Spotify Ltd)
HKU\S-1-5-21-1174857057-1915675840-1477825445-1005\...\Run: [f.lux] => C:\Users\Pete_2\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-1174857057-1915675840-1477825445-1005\...\Run: [Spotify Web Helper] => C:\Users\Pete_2\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-29] (Spotify Ltd)
IFEO\CNC3.exe: [Debugger]
IFEO\CNC3EP1.exe: [Debugger]
IFEO\generals.exe: [Debugger]
IFEO\RA3.exe: [Debugger] C:\Program Files (x86)\Revora\CNCOnline\cnconline.exe
Startup: C:\Users\Pete_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutoHotkey.ahk - Shortcut.lnk
ShortcutTarget: AutoHotkey.ahk - Shortcut.lnk -> C:\Users\Pete_2\Documents\AutoHotkey.ahk ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1174857057-1915675840-1477825445-1005\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1174857057-1915675840-1477825445-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-1174857057-1915675840-1477825445-1005\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com
HKU\S-1-5-21-1174857057-1915675840-1477825445-1005\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com
URLSearchHook: [S-1-5-21-1174857057-1915675840-1477825445-1001] ATTENTION ==> Default URLSearchHook is missing.
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default
FF Homepage: news.bbc.co.uk
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1215155.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKU\S-1-5-21-1174857057-1915675840-1477825445-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Pete_2\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: British English Dictionary (Forked by Marco Pinto) - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
marcoagpinto@mail.telepac.pt [2015-01-31]
FF Extension: OpenDownload² - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\{210249CE-F888-11DD-B868-4CB456D89593} [2014-12-31]
FF Extension: Add to Amazon Wish List Button - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
amznUWL2@amazon.com.xpi [2014-12-28]
FF Extension: Bookmark Deduplicator - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
bookmarkdeduplicator@foxhatdev.xpi [2015-01-17]
FF Extension: Gif Delayer - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
jid1-mqCpKcAruymyAA@jetpack.xpi [2014-12-28]
FF Extension: Gmail™ Notifier Plus - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
jid1-sqmEAwSoa3FZPc@jetpack.xpi [2014-12-28]
FF Extension: Hide Fedora - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
jid1-tg9TKUYM47PZpg@jetpack.xpi [2014-12-28]
FF Extension: Reddit Enhancement Suite - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
jid1-xUfzOsOFlzSOXg@jetpack.xpi [2014-12-28]
FF Extension: English (GB) Language Pack - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
langpack-en-GB@firefox.mozilla.org.xpi [2015-01-01]
FF Extension: New Tab Tools - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
newtabtools@darktrojan.net.xpi [2014-12-28]
FF Extension: Social Fixer - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\
socialfixer@mattkruse.com.xpi [2015-01-28]
FF Extension: YouTube High Definition - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2014-12-28]
FF Extension: Adblock Plus - C:\Users\Pete_2\AppData\Roaming\Mozilla\Firefox\Profiles\zebsl4s7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-12-28]
FF HKLM-x32\...\Thunderbird\Extensions: [
msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-10-22]
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.bbc.co.uk/news/
CHR StartupUrls: Default -> "hxxp://mysearch.avg.com?cid={B68DF417-4FD1-4919-837D-E8CC09E2B893}&mid=6c5b91fda3b747d28a2d8d6f4ce7b111-162f0072ab62a34f7a017f5ed3faa1aafe9b21be&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-04-18 21:23:46&v=18.0.5.292&pid=safeguard&sg=&sap=hp", "hxxp://mysearch.avg.com?cid={B68DF417-4FD1-4919-837D-E8CC09E2B893}&mid=6c5b91fda3b747d28a2d8d6f4ce7b111-162f0072ab62a34f7a017f5ed3faa1aafe9b21be&lang=en&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-04-18 21:23:46&v=18.1.5.512&pid=safeguard&sg=&sap=hp"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google

ageClassification}{google:searchVersion}{google:sessionToken}{google

refetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-31]
CHR Extension: (Google Docs) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-31]
CHR Extension: (Google Drive) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-31]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-01]
CHR Extension: (YouTube) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-31]
CHR Extension: (Google Search) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-31]
CHR Extension: (Google Sheets) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-31]
CHR Extension: (Marlies Dekkers) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\fepnljgdbelppefncogilfbjikmnbhjm [2015-01-01]
CHR Extension: (AVG Secure Search) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2015-01-16]
CHR Extension: (Google Wallet) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-31]
CHR Extension: (Gmail) - C:\Users\Pete_2\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-31]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [79872 2014-01-06] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
R2 Decor8; C:\Program Files (x86)\Stardock\Decor8\Decor8Srv.exe [74864 2014-06-06] (Stardock Software, Inc)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [335064 2014-07-30] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584960 2014-05-22] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-10-22] (Lenovo(beijing) Limited)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [562200 2014-09-04] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [332528 2014-03-12] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [335064 2014-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [335064 2014-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [601864 2014-08-01] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [335064 2014-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [335064 2014-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [335064 2014-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-07-24] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-07-18] (McAfee, Inc.)
R2 mfevtp; C:\windows\system32\mfevtps.exe [189912 2014-07-18] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [335064 2014-07-30] (McAfee, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903472 2015-01-24] (Electronic Arts)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [76888 2015-01-25] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-07-18] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-07-18] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313800 2014-07-18] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-07-18] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [526352 2014-07-18] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-07-18] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [444720 2014-07-24] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-07-24] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-07-18] (McAfee, Inc.)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-01-05] (Realtek Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8876248 2013-10-17] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2982104 2013-12-26] (Realtek Semiconductor Corporation )
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-12-24] (Synaptics Incorporated)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-01-27] ()
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-01 23:22 - 2015-02-01 23:22 - 00000000 ____D () C:\Users\Pete_2\Desktop\FRST-OlderVersion
2015-02-01 23:08 - 2015-02-01 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-01-31 22:57 - 2015-01-31 22:57 - 00000000 ____D () C:\Users\Pete_2\Documents\Outlook Files
2015-01-28 16:53 - 2015-01-28 16:54 - 16466552 _____ (Malwarebytes Corp.) C:\Users\Pete_2\Downloads\mbar-1.08.3.1004.exe
2015-01-26 16:43 - 2015-01-26 16:43 - 00013634 _____ () C:\Users\Pete_2\Downloads\Procexp.txt
2015-01-25 14:32 - 2015-01-25 14:32 - 00001225 _____ () C:\Users\Public\Desktop\Battlefield 4.lnk
2015-01-25 14:32 - 2015-01-25 14:32 - 00001201 _____ () C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2015-01-25 14:32 - 2015-01-25 14:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4
2015-01-25 01:13 - 2015-01-25 01:13 - 01121208 _____ () C:\Users\Pete_2\Downloads\ProcessMonitor.zip
2015-01-24 22:21 - 2015-01-25 14:32 - 00281872 _____ () C:\windows\SysWOW64\PnkBstrB.exe
2015-01-24 22:21 - 2015-01-25 14:32 - 00281872 _____ () C:\windows\SysWOW64\PnkBstrB.ex0
2015-01-24 22:21 - 2015-01-25 14:32 - 00076888 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2015-01-24 22:21 - 2015-01-24 22:21 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2015-01-24 01:47 - 2015-01-24 01:48 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2015-01-24 01:37 - 2015-01-24 13:52 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Origin
2015-01-24 01:37 - 2015-01-24 01:47 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\Origin
2015-01-24 01:33 - 2015-01-26 22:46 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-01-24 01:33 - 2015-01-24 13:52 - 00000000 ____D () C:\ProgramData\Origin
2015-01-24 01:33 - 2015-01-24 01:33 - 00001006 _____ () C:\Users\Public\Desktop\Origin.lnk
2015-01-24 01:33 - 2015-01-24 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-01-24 01:33 - 2015-01-24 01:33 - 00000000 ____D () C:\ProgramData\Electronic Arts
2015-01-21 20:51 - 2015-01-21 20:51 - 00000000 ____D () C:\Users\Pete_2\Downloads\addons0
2015-01-19 22:52 - 2015-01-26 23:25 - 00000000 ____D () C:\Users\Pete_2\Downloads\addons
2015-01-19 22:30 - 2015-01-19 22:38 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Curse Advertising
2015-01-19 22:29 - 2015-01-21 19:57 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\Deployment
2015-01-19 22:29 - 2015-01-19 22:29 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\Apps\2.0
2015-01-19 21:44 - 2015-01-19 21:44 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-01-19 01:34 - 2015-01-19 01:34 - 00001037 _____ () C:\Users\Public\Desktop\Tiberian Sun Online - CnCNet 5.lnk
2015-01-19 00:25 - 2015-01-19 01:45 - 00001028 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yuri's Revenge.lnk
2015-01-19 00:05 - 2015-01-19 00:05 - 00000000 ____D () C:\Users\Pete_2\.swt
2015-01-19 00:04 - 2015-01-19 20:33 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Azureus
2015-01-19 00:04 - 2015-01-19 00:04 - 00001821 _____ () C:\Users\Public\Desktop\Vuze.lnk
2015-01-19 00:04 - 2015-01-19 00:04 - 00001821 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk
2015-01-19 00:04 - 2015-01-19 00:04 - 00000000 ____D () C:\Program Files\Vuze
2015-01-18 23:26 - 2015-01-19 01:43 - 00001013 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Alert 2.lnk
2015-01-17 21:43 - 2015-01-17 21:44 - 00032339 _____ () C:\Users\Pete_2\Desktop\Addition.txt
2015-01-17 21:41 - 2015-02-01 23:26 - 00023402 _____ () C:\Users\Pete_2\Desktop\FRST.txt
2015-01-17 21:26 - 2015-02-01 23:22 - 02131456 _____ (Farbar) C:\Users\Pete_2\Desktop\FRST64.exe
2015-01-17 17:12 - 2015-01-17 17:12 - 00000000 ____D () C:\Users\Pete_2\Documents\nbgi
2015-01-17 15:56 - 2015-01-17 15:56 - 00000000 ____D () C:\Users\Pete_2\Downloads\CnC_Red_Alert_3___Icon_by_KingAciD
2015-01-17 15:47 - 2015-01-17 15:47 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\CDTPL
2015-01-16 16:54 - 2015-01-30 17:00 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-01-16 16:54 - 2015-01-30 17:00 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-16 16:41 - 2015-01-16 16:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-01-16 08:24 - 2015-01-16 08:24 - 00000000 ____D () C:\Users\Pete_2\Documents\My Bluetooth
2015-01-15 22:33 - 2015-01-15 22:33 - 00012035 _____ () C:\Users\Pete_2\Downloads\Proexp.TXT
2015-01-15 22:31 - 2015-01-15 22:31 - 00000000 ____D () C:\Users\Pete_2\Downloads\ProcessExplorer
2015-01-15 18:29 - 2015-01-15 18:29 - 00000222 _____ () C:\Users\Pete_2\Desktop\Dark Souls Prepare to Die Edition.url
2015-01-15 04:17 - 2015-01-15 04:17 - 00798824 _____ () C:\Users\Pete_2\Desktop\ESETPoweliksCleaner.exe_20150115.041741.6852.log
2015-01-15 04:17 - 2015-01-15 04:17 - 00186568 _____ (ESET) C:\Users\Pete_2\Desktop\ESETPoweliksCleaner.exe
2015-01-15 02:18 - 2015-01-15 02:18 - 00448512 _____ (OldTimer Tools) C:\Users\Pete_2\Downloads\TFC.exe
2015-01-14 16:09 - 2014-12-19 06:26 - 00140800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-01-14 16:09 - 2014-12-12 02:04 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-01-14 16:09 - 2014-12-12 00:51 - 00075776 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ahcache.sys
2015-01-14 16:09 - 2014-12-09 01:50 - 00225280 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-01-14 16:09 - 2014-12-08 19:42 - 00535640 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2015-01-14 16:09 - 2014-12-08 19:42 - 00531616 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2015-01-14 16:09 - 2014-12-08 19:42 - 00448792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2015-01-14 16:09 - 2014-12-08 19:42 - 00413248 _____ (Microsoft Corporation) C:\windows\system32\Faultrep.dll
2015-01-14 16:09 - 2014-12-08 19:42 - 00372408 _____ (Microsoft Corporation) C:\windows\SysWOW64\Faultrep.dll
2015-01-14 16:09 - 2014-12-08 19:42 - 00108944 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2015-01-14 16:09 - 2014-12-08 19:42 - 00038264 _____ (Microsoft Corporation) C:\windows\system32\WerFaultSecure.exe
2015-01-14 16:09 - 2014-12-08 19:42 - 00033584 _____ (Microsoft Corporation) C:\windows\SysWOW64\WerFaultSecure.exe
2015-01-14 16:09 - 2014-12-06 03:17 - 00360448 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll
2015-01-14 16:09 - 2014-12-06 01:41 - 00391680 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
2015-01-14 16:09 - 2014-12-06 01:35 - 00229888 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2015-01-14 16:09 - 2014-10-29 04:00 - 00465320 _____ (Microsoft Corporation) C:\windows\system32\WerFault.exe
2015-01-14 16:09 - 2014-10-29 04:00 - 00139984 _____ (Microsoft Corporation) C:\windows\system32\wermgr.exe
2015-01-14 16:09 - 2014-10-29 03:52 - 00500016 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2015-01-14 16:09 - 2014-10-29 03:52 - 00482872 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2015-01-14 16:09 - 2014-10-29 03:52 - 00394120 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2015-01-14 16:09 - 2014-10-29 03:52 - 00272248 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2015-01-14 16:09 - 2014-10-29 03:12 - 00413136 _____ (Microsoft Corporation) C:\windows\SysWOW64\WerFault.exe
2015-01-14 16:09 - 2014-10-29 03:12 - 00136296 _____ (Microsoft Corporation) C:\windows\SysWOW64\wermgr.exe
2015-01-14 16:09 - 2014-10-29 03:07 - 00424544 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2015-01-14 16:09 - 2014-10-29 03:07 - 00370424 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2015-01-14 16:09 - 2014-10-29 03:07 - 00344536 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2015-01-14 16:09 - 2014-10-29 02:44 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\werdiagcontroller.dll
2015-01-14 16:09 - 2014-10-29 01:59 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\werdiagcontroller.dll
2015-01-14 16:09 - 2014-10-29 01:24 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll
2015-01-14 16:09 - 2014-10-29 01:02 - 00911360 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-01-14 16:09 - 2014-10-29 01:01 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\nlaapi.dll
2015-01-13 23:06 - 2015-02-01 23:24 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\CrashDumps
2015-01-13 21:57 - 2015-02-01 23:26 - 00000000 ____D () C:\FRST
2015-01-13 21:48 - 2015-01-13 21:48 - 00000000 ____D () C:\windows\ERUNT
2015-01-13 21:40 - 2015-01-13 21:40 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\My Bluetooth
2015-01-13 19:37 - 2015-01-13 19:37 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Unity
2015-01-13 19:35 - 2015-01-13 19:35 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\Unity
2015-01-13 18:52 - 2015-01-28 20:23 - 00000000 ____D () C:\Users\Pete_2\Desktop\mbar
2015-01-13 18:52 - 2015-01-28 20:23 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-13 18:09 - 2015-01-27 16:09 - 00035064 _____ () C:\windows\system32\Drivers\TrueSight.sys
2015-01-13 18:09 - 2015-01-13 18:09 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-01-12 02:12 - 2015-01-28 17:55 - 00136408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-12 02:12 - 2015-01-28 17:54 - 00097496 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-01-12 02:12 - 2015-01-12 02:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-12 02:12 - 2015-01-12 02:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-12 02:12 - 2015-01-12 02:12 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-12 02:12 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-01-12 02:12 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-01-09 01:20 - 2015-01-09 01:20 - 00003050 _____ () C:\windows\System32\Tasks\Microsoft_Hardware_Launch_IType_exe
2015-01-09 01:20 - 2015-01-09 01:20 - 00000000 ____D () C:\windows\PCHEALTH
2015-01-08 18:43 - 2015-01-08 18:43 - 00003094 _____ () C:\windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-1174857057-1915675840-1477825445-1005
2015-01-08 18:43 - 2015-01-08 18:43 - 00000000 ___RD () C:\Users\Pete_2\OneDrive
2015-01-08 18:43 - 2015-01-08 18:43 - 00000000 ____D () C:\ProgramData\Microsoft OneDrive
2015-01-08 18:40 - 2015-01-11 03:13 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-01-08 16:07 - 2015-01-08 16:13 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\FileBoss
2015-01-08 03:23 - 2015-01-08 03:23 - 00000000 ____D () C:\windows\SysWOW64\directx
2015-01-08 03:23 - 2015-01-08 03:23 - 00000000 ____D () C:\Program Files (x86)\Microsoft XNA
2015-01-08 01:22 - 2015-01-08 01:22 - 00466456 _____ (Creative Labs) C:\windows\system32\wrap_oal.dll
2015-01-08 01:22 - 2015-01-08 01:22 - 00444952 _____ (Creative Labs) C:\windows\SysWOW64\wrap_oal.dll
2015-01-08 01:22 - 2015-01-08 01:22 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\windows\system32\OpenAL32.dll
2015-01-08 01:22 - 2015-01-08 01:22 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\windows\SysWOW64\OpenAL32.dll
2015-01-08 01:22 - 2015-01-08 01:22 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\FEZ
2015-01-08 01:22 - 2015-01-08 01:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FEZ
2015-01-08 01:22 - 2015-01-08 01:22 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2015-01-08 01:21 - 2015-01-08 01:22 - 00000000 ____D () C:\Program Files (x86)\FEZ
2015-01-07 16:13 - 2015-01-07 16:14 - 01324480 _____ () C:\windows\Minidump\010715-24937-01.dmp
2015-01-07 16:13 - 2015-01-07 16:13 - 730079841 _____ () C:\windows\MEMORY.DMP
2015-01-07 16:13 - 2015-01-07 16:13 - 00000000 ____D () C:\windows\Minidump
2015-01-07 01:44 - 2015-01-07 01:44 - 00000000 ____D () C:\Users\Pete_2\Downloads\Stardock
2015-01-07 00:25 - 2015-01-07 00:25 - 00000000 ____D () C:\Users\Pete_2\Documents\Red Alert 3
2015-01-07 00:11 - 2015-01-07 00:11 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CNCOnline
2015-01-07 00:11 - 2015-01-07 00:11 - 00000000 ____D () C:\Program Files (x86)\Revora
2015-01-06 23:56 - 2015-01-07 00:20 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Red Alert 3
2015-01-06 23:56 - 2015-01-06 23:56 - 00000000 __RHD () C:\Users\Pete_2\AppData\Roaming\SecuROM
2015-01-06 23:55 - 2015-01-06 23:55 - 00000040 _____ () C:\ProgramData\ra3.ini
2015-01-06 20:36 - 2015-01-06 20:36 - 00003640 _____ () C:\windows\SysWOW64\ealregsnapshot1.reg
2015-01-06 20:35 - 2015-01-06 20:35 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\Downloaded Installations
2015-01-06 18:47 - 2015-01-06 18:47 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2015-01-05 16:48 - 2015-01-05 16:48 - 00707354 _____ () C:\windows\unins000.exe
2015-01-05 16:48 - 2015-01-05 16:48 - 00001530 _____ () C:\windows\unins000.dat
2015-01-05 16:48 - 2015-01-05 16:48 - 00000000 ____D () C:\windows\SysWOW64\GPBAK
2015-01-05 16:48 - 2008-04-14 02:11 - 00295936 _____ (Microsoft Corporation) C:\windows\SysWOW64\appmgr.dll
2015-01-05 16:48 - 2001-08-23 13:00 - 00034871 _____ () C:\windows\SysWOW64\gpedit.msc
2015-01-05 02:19 - 2015-01-05 02:19 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\NVIDIA
2015-01-05 02:04 - 2015-01-05 02:04 - 00000000 ____D () C:\Users\Pete_2\Downloads\OblyTile exported tiles
2015-01-02 03:10 - 2015-01-02 03:10 - 00000000 ____D () C:\Program Files (x86)\OblyTile
2015-01-02 01:24 - 2015-01-02 01:24 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\vlc
2015-01-02 00:50 - 2015-01-02 00:50 - 00000000 ____D () C:\Users\Pete_2\Downloads\metro_games_icons_by_shiryudragon09-d5klkin
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-01 23:19 - 2014-12-28 23:08 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-02-01 23:12 - 2014-12-29 09:28 - 00003598 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1174857057-1915675840-1477825445-1005
2015-02-01 23:09 - 2014-10-22 08:07 - 01691120 _____ () C:\windows\WindowsUpdate.log
2015-02-01 23:06 - 2014-12-29 09:56 - 00000920 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-01 23:00 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\system32\sru
2015-02-01 22:58 - 2014-12-29 10:01 - 00000916 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore1d0234e7b7e8e33.job
2015-02-01 22:58 - 2014-12-29 09:56 - 00000916 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-01 22:58 - 2014-12-29 09:19 - 00122767 _____ () C:\Users\Pete_2\AppData\Local\BTServer.log
2015-02-01 22:58 - 2014-12-28 20:06 - 00000000 ____D () C:\Users\Pete_2\Documents\BP
2015-02-01 16:03 - 2014-10-22 08:33 - 01981764 _____ () C:\Users\Public\CAFADEBUG.log
2015-02-01 04:29 - 2014-03-18 09:53 - 00865408 _____ () C:\windows\system32\PerfStringBackup.INI
2015-02-01 04:22 - 2014-12-29 09:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-01 04:22 - 2014-10-22 09:09 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-02-01 04:22 - 2013-08-22 14:46 - 00027647 _____ () C:\windows\setupact.log
2015-02-01 04:22 - 2013-08-22 14:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-02-01 04:21 - 2014-12-29 10:00 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Spotify
2015-02-01 04:09 - 2014-12-29 09:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-01 04:09 - 2014-12-29 08:46 - 00000000 ____D () C:\Users\Pete
2015-02-01 02:45 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\AppReadiness
2015-01-31 23:38 - 2014-12-28 20:07 - 00000000 ____D () C:\Users\Pete_2\Documents\DPP3
2015-01-31 15:36 - 2014-12-29 09:58 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-29 02:48 - 2014-12-30 14:18 - 00000000 ____D () C:\Users\Pete_2\Documents\Stardock
2015-01-27 21:26 - 2013-08-22 15:20 - 00000000 ____D () C:\windows\CbsTemp
2015-01-27 00:01 - 2013-08-22 13:25 - 00262144 ___SH () C:\windows\system32\config\ELAM
2015-01-26 16:14 - 2014-12-29 10:06 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\Spotify
2015-01-25 14:32 - 2015-01-01 03:56 - 00081247 _____ () C:\windows\DirectX.log
2015-01-25 14:28 - 2014-12-29 09:19 - 00000000 ____D () C:\Users\Pete_2
2015-01-25 14:27 - 2014-03-18 09:44 - 00010438 _____ () C:\windows\PFRO.log
2015-01-24 22:27 - 2014-10-22 08:30 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-24 20:20 - 2013-08-22 15:38 - 00714720 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-01-24 20:20 - 2013-08-22 15:38 - 00106976 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 20:19 - 2014-12-28 23:08 - 00003718 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-01-21 21:14 - 2013-08-22 13:25 - 00262144 ___SH () C:\windows\system32\config\BBI
2015-01-21 21:11 - 2013-08-22 14:44 - 00494832 _____ () C:\windows\system32\FNTCACHE.DAT
2015-01-19 21:58 - 2014-12-30 13:45 - 00000000 ____D () C:\Program Files\OblyTile
2015-01-19 00:10 - 2014-12-29 10:02 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\ClassicShell
2015-01-18 16:55 - 2014-12-29 00:05 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\.minecraft
2015-01-16 00:27 - 2014-12-28 20:06 - 00000000 ____D () C:\Users\Pete_2\Documents\Group and Teamwork Unit
2015-01-15 02:53 - 2014-12-29 09:57 - 00000000 ____D () C:\ProgramData\Oracle
2015-01-14 16:31 - 2014-12-29 09:46 - 00000000 ____D () C:\windows\system32\MRT
2015-01-14 16:28 - 2014-12-29 09:45 - 113365784 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-01-12 17:18 - 2014-12-28 19:44 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Skype
2015-01-12 02:47 - 2014-12-28 20:06 - 00000000 ____D () C:\Users\Pete_2\Documents\DPP2
2015-01-11 00:40 - 2014-12-29 00:04 - 00000000 ____D () C:\Program Files (x86)\Minecraft
2015-01-10 17:40 - 2014-12-28 20:06 - 00000000 ____D () C:\Users\Pete_2\Documents\DPP2 (new)
2015-01-10 15:43 - 2014-12-29 09:19 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\Packages
2015-01-09 01:20 - 2013-08-22 15:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-01-08 18:40 - 2014-12-29 09:19 - 00000000 ____D () C:\Users\Pete_2\AppData\Local\VirtualStore
2015-01-05 16:53 - 2013-08-22 15:36 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2015-01-05 16:48 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2015-01-04 21:22 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\rescache
2015-01-02 02:13 - 2014-12-28 23:19 - 00000000 ____D () C:\Users\Pete_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
==================== Files in the root of some directories =======
2014-12-29 09:19 - 2015-02-01 22:58 - 0122767 _____ () C:\Users\Pete_2\AppData\Local\BTServer.log
2014-10-22 08:33 - 2014-10-22 08:33 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-01-06 23:55 - 2015-01-06 23:55 - 0000040 _____ () C:\ProgramData\ra3.ini
Some content of TEMP:
====================
C:\Users\Pete_2\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Pete_2\AppData\Local\Temp\drm_dyndata_7400006.dll
C:\Users\Pete_2\AppData\Local\Temp\i4jdel0.exe
C:\Users\Pete_2\AppData\Local\Temp\sonarinst.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-31 21:19
==================== End Of Log ============================